Discordia is paused: in the meantime this domain hosts my portfolio.

All projects
personal

School web server

I ran the multi-user server where my class published its websites, and I carried out its security audit.

Context

I ran the web server where the students in my class published their websites and projects. A real server, with real users, in production: not an exercise.

What I managed

An Ubuntu environment with Apache, MariaDB and PHP, shared by the whole class. Every student had their own space, isolated from the others with chrooted SFTP access: each person saw and edited only their own folder, never their classmates’ or the system files. A WordPress install used by about twenty people ran on top.

Running a multi-user environment means thinking about permissions, isolation and what happens when someone makes a mistake: the system has to absorb errors without one person breaking another’s work.

The security audit

At some point I decided to look at the server the way an outsider would, starting from zero information. Real problems came up: directory listing was open, some data was exposed where it shouldn’t have been, and everything travelled without HTTPS.

I fixed them: closed the listing, moved what shouldn’t be reachable, turned on encryption. What matters isn’t the list of problems but the method: looking at your own infrastructure from the outside is what keeps it secure over time.

What it taught me

That security isn’t a separate phase from administration: it’s the same job, seen from the other side of the wall.