Introduction to the Linux Terminal
Why Linux for Security?
Almost everything a security professional works with runs on Linux:
- Servers: most web servers, cloud machines (AWS, Azure, Google Cloud) and the servers behind banks, telcos and fintechs in Lagos, London and New York run Linux.
- Security tools: Nmap, Wireshark, Metasploit, Burp Suite and John the Ripper are built for Linux. Kali Linux ships hundreds of them ready to use.
- Automation: the terminal lets you search a million log lines, scan a network or check a hundred servers with one command or a short script.
- Incident response: when a server is compromised, you usually have a terminal, not a mouse and windows. Analysts who are quick on the command line find evidence faster.
The terminal (or shell) is a text window where you type commands and the computer types back. It looks old-fashioned, but it is faster, scriptable and works over a slow connection, which is exactly how you manage a remote server.
Practise safely: the lab below is a simulated machine. Nothing you type can harm a real computer, so experiment freely.
Reading the Prompt
kali@careerex:~$
kaliis your username.careerexis the hostname (the machine's name).~is your current directory (~means your home folder).$means you are a normal user. A#means you are root, the all-powerful administrator.
Basic Navigation
Linux files live in one tree that starts at / (called root). Some folders you will visit often:
| Path | What it holds |
|---|---|
/home | Users' personal files |
/etc | System configuration |
/var/log | Log files (login attempts, errors, web traffic) |
/opt | Optional, add-on software |
/root | The root user's home folder |
The essential commands
pwd # print working directory: where am I?
ls # list files in this folder
ls -l # long listing: permissions, owner, size, date
ls -a # show hidden files (names that start with a dot)
cd Documents # move into a folder
cd .. # go up one level
cd ~ # go back to your home folder
cat notes.txt # print a file's contents
head -n 5 file # first 5 lines
tail -n 5 file # last 5 lines
whoami # which user am I?
Hidden files matter. In Linux, a file or folder whose name starts with . is hidden from a normal ls. Attackers hide tools this way, and administrators keep configuration there. Always try ls -a.
Searching
grep "Failed" auth.log # lines containing "Failed"
grep -i "error" app.log # ignore upper/lower case
find / -name "*.txt" # find files by name
cat auth.log | grep Failed # pipe: send one command's output into another
The pipe (|) is one of the most powerful ideas in Linux. A security analyst checking a server for brute-force attempts might run cat /var/log/auth.log | grep Failed and instantly see every failed login.
File Permissions
Every file has an owner and a set of permissions. You see them with ls -l:
-rwxr-xr-- 1 kali users 1204 Mar 3 10:12 backup.sh
Read the first block, -rwxr-xr--, as four parts:
| Part | Characters | Meaning |
|---|---|---|
| Type | - | A regular file (d means directory) |
| Owner | rwx | The owner can read, write and execute |
| Group | r-x | The group can read and execute, not write |
| Others | r-- | Everyone else can only read |
Permissions are also written as numbers: r = 4, w = 2, x = 1, added together for each of owner, group and others. So rwxr-xr-- is 754.
chmod 754 backup.sh # set permissions using numbers
chmod +x script.sh # make a file executable
chmod 600 id_rsa # private key: only the owner can read/write
Why permissions matter for security
- A file that is world-writable (
rw-rw-rw-, or 666/777) lets anyone modify it. Attackers look for these. - A private key or a config file holding a database password should be 600, readable by its owner only.
- Privilege escalation often means finding a file or program with weak permissions that runs as root.
- Apply least privilege: give each user and program only the access they need.
Root and sudo
The root user can do anything. Good practice is to work as a normal user and use sudo to run a single command with root power:
cat /root/flag_root.txt # Permission denied
sudo cat /root/flag_root.txt # works, because sudo runs it as root
Try It in the Lab
The terminal on the right is a simulated Kali Linux machine. Your mission: a sysadmin hid a flag on this machine. Find it.
Things to try:
- Type
helpto see the supported commands. - Run
pwdandls, thenls -landls -a. - Read
~/Documents/notes.txtwithcat. It may give you a clue. - Explore
/var/logand usegrepto search the logs. - Look for hidden folders in
/opt. - For the bonus flag, remember that some files need root.
Stuck? Use the Hint button. Tab completes names, and Up/Down arrows browse your command history.
Note: the simulator focuses on navigating, reading and searching. Commands that change files (such as chmod, rm and mkdir) are not active here, so practise those in Kali or a free environment like TryHackMe.
Try it yourself
Key Takeaways
- Linux runs most servers and security tools, and the terminal is the fastest, most scriptable way to work with them.
- Core navigation: pwd, ls (-l, -a), cd, cat, head, tail. Always check for hidden files with ls -a.
- grep, find and the pipe (|) let you search huge logs and file trees in seconds.
- Permissions are read as owner, group, others (r=4, w=2, x=1). 754 means rwxr-xr--.
- Apply least privilege: sensitive files should be 600, world-writable files are a red flag, and use sudo for single commands rather than working as root.
Quick Quiz
1.Which command shows hidden files (names beginning with a dot) in the current folder?
2.A file shows the permissions -rwxr-xr--. What can 'others' (everyone who is not the owner or in the group) do?
3.What does the command cat /var/log/auth.log | grep Failed do?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx