Hardening

Harden your Linux server without locking yourself out

Your AI reviews a server that is already in use, gives you a short list of findings ordered by risk, and fixes them one by one with your say-so. /etc is saved first, and SSH is changed only after you confirm a key works.

Works with Claude, Claude Code, ChatGPT and Cursor.

How your AI does it

  1. STEP 1

    A read-only review

    Open ports, firewall rules, SSH settings, users with shells and sudo rights, pending security updates, automatic updates, fail2ban, SELinux or AppArmor mode, world-writable files under web roots, databases and caches listening on public addresses, and certificate expiry.

  2. STEP 2

    Findings ordered by risk

    Each finding comes with the fix your AI proposes. Nothing changes until you agree, and anything that could cut your access or break a site is called out.

  3. STEP 3

    Fixes, one at a time

    Databases, Redis and OpenSearch bound to 127.0.0.1 and closed in the firewall, the firewall on with only the ports really used, security updates applied and automatic from then on, fail2ban for SSH and for login pages under attack, web roots owned by the site user and no PHP in upload folders.

  4. STEP 4

    SSH last, and carefully

    Keys only and no root password login, only after you confirm a key works, as its own step, with sshd -t before the reload. SELinux and AppArmor stay enforcing; contexts are fixed instead.

  5. STEP 5

    A report

    What was found, what changed, what is left and why, so you know where the server stands.

What gets checked

  • Open ports and what listens on them (ss -tlnp)
  • firewalld, ufw or nftables rules
  • SSH: root login, password login, port, keys
  • Users with a shell, sudo rights and authorized_keys
  • Pending security updates and automatic updates
  • fail2ban jails
  • SELinux or AppArmor mode
  • MySQL, Redis, OpenSearch or Memcached open to the internet
  • World-writable files and PHP in upload folders
  • Certificates close to expiry

Start with this prompt

Paste it into your AI with SudoWhizzy connected. It fetches the matching playbook and explains its plan before changing anything.

Using SudoWhizzy, review my server's security with the hardening playbook (get_playbook). Look first and show me the findings ordered by risk with the fix for each. Then fix them one at a time after I agree, snapshotting /etc first. Never change SSH and the firewall in the same step, and never lock me out.

Lock down my server · all prompts

Which plan

Free gets you the full read-only review. Starter and up let your AI apply the fixes, with approvals for SSH and firewall changes. Pricing.

Questions

Will it lock me out of SSH?

It is built not to. The firewall always allows the SSH port in use before it is switched on, SSH is never changed in the same step as the firewall, keys-only login is offered only after you confirm your key works, and every SSH or firewall change needs your approval.

Does it disable SELinux to make things work?

No. SELinux and AppArmor stay enforcing; your AI sets the right file contexts and booleans instead.

How often should I run it?

Once after setup, then whenever the server changes a lot. SudoWhizzy's daily health check and Monday report flag pending security updates and expiring certificates in between.

What does it cost to just get the review?

Nothing. On the Free plan your AI can do the whole read-only review and give you the list; you can apply the fixes yourself or upgrade to let it do them.

Safety on every task: destructive actions wait for your approval, /etc is saved before changes, and every action is logged. How it works.

Connect your first server

Start free with one server in read-only mode. Upgrade when you want your AI to fix things.

Get started