ºìÁªLinuxÃÅ»§
Linux°ïÖú

Solarisϵͳ°²È«Ö®Éó¼Æ

·¢²¼Ê±¼ä:2006-08-26 05:19:02À´Ô´:ºìÁª×÷Õß:love601
ΪC2°²È«µÈ¼¶²Ù×÷ϵͳ£¨¹«°²²¿¶þ¼¶£©£¬Solaris×îÖ÷ÒªµÄ°²È«¹¦ÄÜÖ®Ò»¾ÍÊÇÉó¼Æ¹¦ÄÜ£¬±¾ÎĽ«¼òµ¥½éÉÜSolarisÉó¼Æ¹¦ÄܵÄʹÓúÍÆô¶¯¡£
Ä¿µÄ£º¼Í¼ϵͳºÍÓû§Ê¼þ£¬²¢¶ÔÉó¼Æ¹ý³Ì×ÔÉí½øÐб£»¤¡£ÕâÀïÖµµÃ×¢ÒâµÄ¾ÍÊǼͼʼþµÄϸ¶È¡£SolarisÌṩÁ˺ÜÇ¿´óµÄÉó¼Æ¹¦ÄÜ£¬ÉõÖÁ¿ÉÒԼͼÿһÌõµ÷ÊÔÐÅÏ¢£¬µ«ÊÇÕâÑù×öÊDz»Ã÷Öǵģ¬ÒòΪºÜ¶àÐÅÏ¢¶ÔÓû§Ã»Ó㬶øÇÒ»áʹϵͳÐÔÄÜϽµ¡£Éó¼Æϸ¶ÈÐèÒª¹ÜÀíÔ±¸ù¾ÝÓÃ;ºÍÐèÒª×ÔÐж©ÖÆ¡£
ʵÏÖ£º
1. ²é¿´ÈÕÖ¾
1) historyÎļþ
ͨ³£ÔÚ¸ùĿ¼Ï£¬Òþ²ØÎļþ£¬¼Ç¼ÁËrootÖ´ÐеÄÃüÁî
2) /var/adm
sulog£º¼ÇÔØ×ÅÆÕͨÓû§³¢ÊÔsu³ÉΪÆäËüÓû§µÄ¼Í¼¡£ËüµÄ¸ñʽΪ£º ·¢Éúʱ¼ä +/-(³É¹¦/ʧ°Ü) ptsºÅ
utmpx£ºÕâÁ½¸öÎļþÊDz»¾ß¿É¶ÁÐԵģ¬ËüÃǼǼ×ŵ±Ç°µÇ¼ÔÚÖ÷»úÉϵÄÓû§£¬¹ÜÀíÔ±¿ÉÒÔÓÃw£¬whoµÈÃüÁîÀ´¿´
wtmpx£ºÏ൱ÓÚÀúÊ·¼Í¼£¬¼Ç¼×ÅËùÓеǼ¹ýÖ÷»úµÄÓû§£¬Ê±¼ä£¬À´Ô´µÈÄÚÈÝ£¬¿ÉÓÃlastÃüÁîÀ´¿´
3) /var/log
syslogÎļþ£¬Õâ¸öÎļþµÄÄÚÈÝÒ»°ãÊǼͼmailʼþµÄ
2. syslog
1) ʵʱ´íÎó¼ì²é£º
tail -f /var/adm/messages
-fÔÚ¼àÊÓÆ÷ÉÏÔÊÐí¿´¼ûÿÌõ¼Ç¼ /var/adm/messages¼Ç¼Ê¼þ·¾¶
*.err;kern.debug;deamon.notice;mail.crit /var/adm/messages
¹¤¾ßÈϿɵÄÖµ
Öµ ÃèÊö
user Óû§½ø³Ì²úÉúµÄÏûÏ¢¡£ÕâÊÇÀ´×ÔûÓÐÔÚÎļþÁбíÖеÄÉ豸µÄÏûÏ¢µÄĬÈÏÓÅÏȼ¶
kern ÓÉÄں˲úÉúµÄÏûÏ¢
mail Óʼþϵͳ
daemon ϵͳÊØ»¤½ø³Ì
auth ÊÚȨϵͳ£¬Èçlogin¡¢su
lpr ÐÐʽ´òÓ¡»ú¼ÙÍÑ»úϵͳ
news ÍøÂçÐÂÎÅϵͳUSENET±£ÁôÖµ
uucp ΪUUCPϵͳ±£ÁôÖµ£¬Ä¿Ç°UUCP²»Ê¹ÓÃsyslog»úÖÆ
cron Cron/at¹¤¾ß£»crontab¡¢at¡¢cron
local0-7 Ϊ±¾µØʹÓñ£Áô
mark ÄÚ²¿ÓÃÓÚÓÉsyslog²úÉúµÄʱ¼ä´ÁÏûÏ¢
* ³ý±ê¼Ç¹¤¾ßÖ®ÍâµÄËùÓй¤¾ß
¼¶±ðÈϿɵÄÖµ£¨°´ÖØÒªÐÔ½µÐòÅÅÁУ©
emerg ÓÃÓÚͨ³£±ØÐë¹ã²¥¸øËùÓÐÓû§µÄ¿Ö»ÅÇé¿ö
alert ±ØÐëÁ¢¼´±»ÐÞÕýµÄÇé¿ö£¬ÀýÈç±»Ë𻵵ÄϵͳÊý¾Ý¿â
crit Óû§¶Ô¹Ø¼üÇé¿öµÄ¸æ¾¯£¬ÀýÈçÉ豸´íÎó
err ÓÃÓÚÆäËû´íÎó
warning ÓÃÓÚËùÓеľ¯¸æÐÅÏ¢
notice ÓÃÓÚûÓдíÎóµ«ÊÇ¿ÉÄÜÐèÒªÌرð´¦ÀíµÄÇé¿ö¡£
info ֪ͨÏûÏ¢
debug ÓÃÓÚͨ³£Ö»ÔÚµ÷ÊÔʱ²ÅʹÓõÄÏûÏ¢
none ²»·¢ËÍ´ÓÖ¸³öµÄÉ豸·¢À´µÄÏûÏ¢µ½Ñ¡¶¨ÎļþÖÐ
3) ÀýÈçÈç¹ûÒª¼Í¼µÇ¼ÐÅÏ¢£¨telnet£©£¬¿ÉÒÔÕâÑù×ö£º
/etc/default/loginÖУºSYSLOG=YES
£¨°ÑÈÕÖ¾¼Ç¼ÔÚ/export/home/wangyu/logÎļþÖУ¬Öм䲻ÊÇ¿Õ¸ñ£¬ÊÇTab£©
ÖØÐÂÆô¶¯syslogÊØ»¤½ø³Ì
µ±telnetÉÏÈ¥µÄʱºò£¬ÎÒÃÇ¿´µ½/export/home/wangyu/logÖÐÓУº
Sep 11 10:07:25 hlstar login: [ID 254462 auth.notice] ROOT LOGIN /dev/pts/1 FROM 192.168.0.9
3. Loghost
*.err;kern.debug;deamon.notice;mail.crit @loghost
£¨¼Ç¼µÇ¼ÐÅÏ¢£©
ÖØÐÂÆô¶¯syslogÊØ»¤½ø³Ì
¼ÙÉèÕâ´ÎÎÒÃÇʹÓÃlinux×öÈÕÖ¾Ö÷»ú£º
[root@wangyu root]#/sbin/setup
´ò¿ªÅäÖýçÃæ-->firewall configuration-->custom-->other ports:
дÈë syslog:udp
ÖØÐÂÆô¶¯·À»ðǽ
/etc/init.d/iptables restart»òÕß/etc/init.d/ipchains restart
ÉèÖÃloghost½ÓÊÕÍøÂçÈÕÖ¾Êý¾Ý£¬ÐÞ¸Ä/etc/sysconfig/syslogÅäÖÃÎļþ£º
ÐÞ¸Ä SYSLOGD_OPTIONS="-m 0" Ϊ SYSLOGD_OPTIONS="-r -m 0"
ÖØÐÂÆô¶¯syslogÊØ»¤½ø³Ì
´Ëʱ/var/log/messages×î϶˸½½ü»á¿´µ½ÀàËÆÏÂÃæµÄÐÅÏ¢
Aug 11 21:20:30 logserver syslogd 1.3-3: restart. (remote reception)
µ±telnetÉÏÈ¥µÄʱºò£¬ÎÒÃÇ¿´µ½/var/log/messagesÖÐÓÐÀàËÆÏÂÃæµÄÐÅÏ¢£º
Sep 5 11:08:31 mastadon login: [ID 507249 auth.notice] Login failure on /dev/pts/3 from 192.168.0.9, root
4. ¼ÇÕÊ
Solaris²Ù×÷ϵͳ¿ÉÒÔͨ¹ýÉèÖÃÈÕÖ¾Îļþ¿ÉÒÔ¶Ôÿ¸öÓû§µÄÿһÌõÃüÁî½øÐмͼ£¬ÕâÒ»¹¦ÄÜĬÈÏÊDz»¿ª·ÅµÄ
ÔËÐÐ/usr/lib/acct/accton [·¾¶][ÎļþÃû]
£¨Èç/usr/lib/acct/accton /export/home/wangyu/test£¬½«ÈÕÖ¾¼Ç¼µ½testÖУ©
²é¿´µÄʱºò½«ÎļþÒƶ¯µ½/var/admĿ¼Ï£¬¸ÄÃûΪpacct
Ö´Ðв鿴ÃüÁîlastcomm£¨±ÈÈç²é¿´Óû§root£¬ÓÃÃüÁîlastcomm root£©
1) ¿ªÆôBSM£º
# init 1 (ÖØÐÂÒýµ¼»ò¸Ä±äÔËÐм¶±ðµ½µ¥Óû§×´Ì¬)
#/etc/security/bsmconv (ÔËÐÐBSM³õʼ»¯½Å±¾£¬¿ªÆôÉó¼Æ¹¦ÄÜ)
# reboot (ÖØÐÂÆô¶¯ÏµÍ³£¬»òÕßCtrl+D¸Ä±äµ½¶àÓû§×´Ì¬)
2) ¹Ø±ÕBSMÉó¼Æ¹¦ÄÜ£º
# init 1
# /etc/security/bsmunconv
# reboot
3) ÅäÖÃÎļþµÄ¹¦ÄÜ£º
BSMËùÓеÄÅäÖÃÎļþ¶¼´æ·ÅÔÚ/etc/securityĿ¼ÏÂ( (4)´ú±íÏêϸÐÅÏ¢²ì¿´man (4) )£º
? audit_class(4)
Éó¼ÆÀà±ð¶¨Òå
? audit_control(4)
Éó¼Æ½ø³Ì¿ØÖÆÐÅÏ¢
? audit_data(4)
Éó¼Æ½ø³Ìµ±Ç°ÐÅÏ¢
? audit.log(4)Éó¼ÆÈÕÖ¾¸ñʽ
? audit_event(4)
ʱ¼ä¶¨Òåµ½Àà±ðµÄÓ³ÉäÎļþ
? audit_user(4)
°´Óû§Éó¼ÆʱµÄÓû§¶¨ÒåÎļþ
³ýÁËÉÏÃæµÄÅäÖÃÎļþÖ®Í⣬ϵͳÖл¹ÓÐһЩÓÃÓÚBSM¹ÜÀíµÄ½Å±¾¡£
? audit_startup(1M)
Æô¶¯BSM½ø³ÌÔËÐС£
? auditconfig(1M)
¶ÁÈ¡ÅäÖÃÎļþ£¬ÖØÐÂÅäÖÃaudit½ø³Ì¡£
? auditd(1M)
Éó¼Æ¼à¿Ø·þÎñ¡£
? auditreduce(1M)
Éó¼ÆʼþÈÕÖ¾¹ÜÀí£¬¿ÉÒÔµ÷ÕûÈÕÖ¾¸ñʽ£¬Éú³Éʱ¼äÖÜÆÚµÈÐÅÏ¢¡£
? auditstat(1M)
ÏÈÊÇÄÚºËÉó¼Æ½ø³Ì״̬¡£
? bsmconv(1M)
¿ªÆôBSM¹¦ÄÜ¡£
? bsmunconv(1M)
¹Ø±ÕBSM¹¦ÄÜ¡£
? praudit(1M)
´òÓ¡BSMÉó¼ÆÈÕÖ¾ÄÚÈÝ¡£
4) BSMÓ¦ÓÃ
? ÔÚĬÈÏÅäÖÃÇé¿öÏ£¬BSMÿÌì(24Сʱ)»áÉú³ÉÒ»¸öÒÔµ±ÌìÈÕÆÚΪÃû×ÖµÄÉó¼ÆÈÕÖ¾£¬´æ·ÅÔÚ/var/auditĿ¼Ï£¬Õâ¸öÎļþ¾ßÓÐ×Ô¼ºµÄÊý¾Ý½á¹¹£¬ËùÒÔÖ±½Ó²é¿´Ê±ÊÇÂÒÂ룬±ØÐëʹÓÃϵͳÃüÁî prauditÀ´²é¿´¡£
# praudit /var/audit/xxxxxx.xxxxxx.log
? ÁíÒ»¸ö¿ÉÄÜÓõ½µÄÃüÁîÊÇauditreduce £¬Õâ¸öÃüÁîÔÊÐí¹ÜÀíÔ±¶ÔÉó¼ÆÈÕÖ¾×öһЩÉèÖã¬ÀýÈçµ÷ÕûÉó¼Æʼþ¼¯»òµ÷ÕûÉó¼ÆÈÕÖ¾Éú³ÉÖÜÆڵȵȡ£auditreduceºÍprauditÊÇϵͳÖÐBSM¹ÜÀí×î»ù±¾µÄÁ½¸öÃüÁ×éºÏÆðÀ´¿ÉÒÔÍê³ÉÏ൱¶àµÄ¹¦ÄÜ£º
ÓùܵÀÁªºÏÁ½¸öÃüÁ»áÏÔʾϵͳÖÐËùÓеÄÀúÊ·Éó¼Æʼþ¡£
# auditreduce | praudit
ÔÙ¼ÓÉÏlp£¬½«°ÑËùÓÐÉó¼ÆʼþÖ±½Ó´òÓ¡³öÀ´¡£
# auditreduce | praudit | lp
Èç¹ûϵͳÖÐÓÐÏ൱¶àµÄÉó¼ÆÐÅÏ¢µÄ»°£¬²éÕÒ½«ÊǷdz£À§ÄѵÄÊÂÇ飬ÕâÌõÃüÁî¿ÉÒÔ°´ÕÕyymmddµÄʱ¼ä¸ñʽÏÔʾĿ±êʱ¼ä¶ÎÄÚµÄÉó¼Æʼþ£¬·¶ÀýΪÏÔʾApril 13, 1990, Óû§fredµÄ µÇ¼Àà±ð Éó¼Æʼþ¼¯¡£
# auditreduce -d 900413 -u fred -c lo | praudit
¹ýÂËÄ¿±êʱ¼äËùÓеĵǼÈÕÖ¾ÐÅÏ¢(Class:lo)£¬²¢ÇÒÊä³öµ½Ò»¸öµ¥¶ÀµÄÈÕÖ¾ÎļþÖУº
# auditreduce -c lo -d 870413 -O /usr/audit_summary/logins
auditreduceµÄ -b ºÍ -a Ñ¡ÏîÔÊÐíÓû§°´ÕÕ yyyymmdd00:00:00 µÄʱ¼ä¸ñʽÖƶ¨Ò»¸öʱ¼ä¶Î(Before & After)¡£
# auditreduce -a 91071500:00:00 | praudit
# auditreduce -b 91071500:00:00 | praudit
5) ¹ÜÀí¹¤¾ß£º
? eXpert-BSMTM
Ò»¸öºÜÇ¿´óµÄÉÌÒµBSM·ÖÎö¹¤¾ß£¬²»¹ýÄ¿Ç°Ò²¿ÉÒÔÃâ·ÑʹÓã¬Ö§³ÖSolaris 7/8 (Sparc|Intel)ƽ̨£¬¿ÉÒÔÔÚÏÂÃæµØÖ·ÏÂÔØ¡£
? Sun WBEM
SolarisÄÚÖõÄͼÐνçÃæ¹ÜÀí¹¤¾ß£¬Ò²¾ÍÊÇAdminConsole£¬ÔÚWBEM 2.3Ö®ºóµÄ°æ±¾Ö§³Ö¶ÔBSMÐÅÏ¢µÄ¹ÜÀí¡£¿ÉÒÔÓÃÏÂÃæÃüÁÆô£º
# /usr/sadm/bin/wbemadmin (µÚÒ»´ÎÔËÐÐʱ»á°²×°Ò»ÏµÁеĹÜÀí½Å±¾)
# /usr/sadm/bin/smc (¿ªÆô¹ÜÀíÖÕ¶Ë)
ÒÔÉÏ£¬¶ÔSolarisÉó¼Æϵͳ½øÐÐÁËÅäÖã¬ÏàÐŴ󲿷ÖÓû§ÐÐΪºÍÈëÇÖÐÐΪ¶¼±»¼Ç¼ÏÂÀ´ÁË£¬²¢ÇÒ¶ÔÈÕÖ¾×ÔÉíÒ²½øÐÐÁËÒ»¶¨±£»¤¡£Èç¹û¹ÜÀíÔ±Äܼ°Ê±·ÖÎöÈÕÖ¾£¬ÏàÐÅ¿ÉÒÔ²¶»ñ´ó²¿·ÖÈëÇÖÆóͼºÍÐÐΪ¡£
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ