ºìÁªLinuxÃÅ»§
Linux°ïÖú

LinuxÖа²È«ÐÔ¸ÅÊö

·¢²¼Ê±¼ä:2006-10-02 21:32:55À´Ô´:ºìÁª×÷Õß:àÖવδð
¼ò½é

ά»¤Ò»¸öÍêÈ«°²È«µÄϵͳÊDz»¿ÉÄܵġ£È»¶ø£¬Ö»ÒªÇÚ·Ü£¬ÔòÓпÉÄÜʹ Linux »úÆ÷×ã¹»°²È«£¬²¢Èôó¶àÊýż¶û³öÏֵĺ§¿Í¡¢½Å±¾Ð¡×Ó£¨script-kiddies£©ÒÔ¼°ÆäËüµÄ¡°»µ¼Ò»ï¡±Ö¹²½¶øÈ¥É§ÈÅÆäËûÈË¡£Çë¼Çס£º½ö½ö×ñÑ­±¾½Ì³Ì²»»á²úÉúÒ»¸ö°²È«µÄϵͳ¡£Ïà·´£¬ÎÒÃÇÏ£ÍûÄú½Ó´¥µ½Ö÷ÒªÖ÷ÌâµÄ¶à¸ö·½Ã棬²¢ÏòÄúÌṩһЩÓйØÈçºÎÈëÃŵÄÓÐÓÃʾÀý¡£

Linux ϵͳ°²È«ÐÔ¿É·ÖΪÁ½¸ö²¿·Ö£ºÄÚ²¿°²È«ÐÔºÍÍⲿ°²È«ÐÔ¡£ÄÚ²¿°²È«ÐÔÖ¸Ô¤·ÀÓû§ÎÞÒâ»ò¶ñÒâµØÆÆ»µÏµÍ³¡£Íⲿ°²È«ÐÔÖ¸·ÀֹδÊÚȨÓû§»ñµÃ¶ÔϵͳµÄ·ÃÎÊ¡£

±¾Õ½«Ê×ÏȽéÉÜÄÚ²¿°²È«ÐÔ£¬È»ºó½éÉÜÍⲿ°²È«ÐÔ£¬×îºó½éÉÜһЩ³£¹æÖ¸µ¼Ô­ÔòºÍ¼¼ÇÉ¡£
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 19 ÌõÆÀÂÛ

  1. àÖવδð ÓÚ 2006-10-02 21:41:48·¢±í:

    ³£¹æÖ¸ÄÏ£º²âÊÔ°²È«ÐÔ

    ²âÊÔϵͳµÄ°²È«ÐÔºÜÖØÒª£¬µ«²»ÒªÈÃÒ»´Î³É¹¦µÄ²âÊÔʹÄú²úÉú°²È«ÐԵĴíÎó¸Ð¾õ¡£ÕâЩ²âÊÔ¹¤¾ßÕÒ²»µ½Â©¶´²¢²»Äܱ£Ö¤Ò»Ð©¾ßÓÐ֪ʶºÍÏëÏóÁ¦µÄÈË -- ²¢ÇÒËûÃÇÓÐÒ»´ó¶Ñʱ¼ä -- Ò²»áʧ°Ü¡£

    ÎÒÃÇÒѾ­Ìáµ½ÁË nmap ºÍ netcat ¿ÉÓÃÓÚ²âÊÔÍøÂ簲ȫÐÔ¡£»¹Ó¦¸Ã¼ì²é±¡ÈõµÄÃÜÂë£¬ÌØ±ðµ±ÏµÍ³Óжà¸öÓû§Ê±£¬¸üÊÇÈç´Ë¡£ÓÐÐí¶à¹¤¾ß¿ÉÒÔʹÓã¬ÈçÎÒÃÇÔÚ±¾½Ì³ÌĩβµÄ¡°²Î¿¼×ÊÁÏ¡±ÖÐÌáµ½µÄÄÇЩ¹¤¾ß¡£

  2. àÖવδð ÓÚ 2006-10-02 21:41:29·¢±í:

    ³£¹æÖ¸ÄÏ£º¸ßÖÊÁ¿ÃÜÂë

    ÌýÆðÀ´¿ÉÄÜºÜÆÕͨ£¬Îª×Ô¼ºÑ¡Ôñ¸ßÖÊÁ¿ÃÜÂ룬²¢ÇÒ¡°¹ÄÀø¡±£¨Ò²¾ÍÊÇÃüÁÓû§Ò²ÕâÑù×ö£¬ÒÔÐγÉÁ¼ºÃµÄ°²È«ÐԵĻùʯ¡£¼ÇסҪ±ÜÃâ³£¼ûµÄ´ÊºÍÃû×Ö£¬ÌرðÊÇÓë×Ô¼ºÓйصÄÈκÎÊÂÎÈçÅóÓѵÄÃû×Ö¡¢¹¤×÷µØµã»ò³èÎïµÄÃû×Ö¡£»¹Òª±ÜÃâ¿É²Â²âµÄÊý×Ö£¬ÈçÉúÈÕ»òÖÜÄê¼ÍÄîÈÕ¡£Ïà·´Òª³¢ÊÔʹÓÃ×Öĸ¡¢Êý×ֺͱêµãµÄËæ»ú×éºÏ¡£

  3. àÖવδð ÓÚ 2006-10-02 21:41:07·¢±í:

    ³£¹æÖ¸ÄÏ£º±£³ÖÈí¼þΪ×îÐÂ

    ÒòΪËùÓÐÈí¼þ¶¼¿ÉÄÜÓа²È«ÐÔ©¶´£¬ËùÒÔÖØÒªµÄÊÇ£ºÖ»Òª»ñµÃ°üµÄ°²È«ÐÔÐÞÕý°ü¾ÍÁ¢¿Ì°²×°¡£ÕâÊǰ²È«×¨¼Ò×î³£Ìá³öµÄÒ»Ìõ½¨Ò飬ҲÊǹÜÀíÔ±ÐÂÊÖÃÇ×î³£ºöÂÔµÄÒ»Ìõ½¨Òé¡£²»Òª³Ô¹ý¿àÍ·²ÅÎüÈ¡½Ìѵ -- »úÆ÷ÒòΪÄúºöÊÓÁËʹ²¹¶¡³ÌÐò±£³Ö×îжø±»ÈËͨ¹ý´æÔÚÊýÄêÖ®¾ÃµÄºóÃÅÇÖÈë¡£

    ¶ÔÓÚ¿ª·ÅÔ´ÂëºÍ·â±ÕÔ´ÂëÄĸö¸ü°²È«µÄÕùÂ۷dz£¼¤ÁÒ¡£Æù½ñ×îºÃµÄ½áÂÛÊÇ£º¹ÜÀíÕýȷʱ£¬Á½Õß¶¼×ã¹»°²È«£¬ÕâÀïµÄ¹ÜÀí°üÀ¨±£³Ö°²È«ÐÔ²¹¶¡³ÌÐòΪ×îУ¡

    Óм¸¸öÍøÕ¾¿ÉÒÔ°ïÖú±£³ÖÈí¼þΪ×îУ¬²¢ÓÐÖúÓÚÌá·ÀÒÑÖªµÄÍþв¡£°üÀ¨Ìرð×¢ÒⰲȫÐ﵀ CERT ºÍ SecurityFocus µÄ BugTraq ÁÐ±í£¬ÒÔ¼°Í¨³£µÄÈí¼þ¸üÐÂÕ¾µã£¨Ïófreshmeat.net£©ºÍ·Ö·¢°æµÄÖ÷Ò³¡£ÎÒÃÇ»¹½«Ôڲο¼×ÊÁÏÖÐÖØ¸´ÕâЩ URL£¬²»¹ý°²È«ÐÔÕæµÄ·Ç³£ÖØÒª -- Èç¹û»¹²»ÊìϤÕâЩվµãµÄ»°£¬½¨ÒéÄúÏÖÔھͻ¨¼¸·ÖÖÓ·ÃÎÊÍ·Á½¸öÕ¾µã¡£

  4. àÖવδð ÓÚ 2006-10-02 21:40:41·¢±í:

    ÈëÇÖ¼ì²â -- portsentry

    PortSentry °üÀ´×Ô Psionic Technologies£¬Ëüʵ¼ÊÉÏÓеã½éÓÚÈëÇÖÔ¤·ÀÓë¼ì²âÖ®¼ä¡£¸Ã°ü¼à¿ØÍøÂçÁ¬½Ó£¬²¢ÇÒÈç¹ûËü¿´µ½ÈκÎËüÈÏΪ¡°¿ÉÒÉ¡±µÄÓëϵͳÁ¬½ÓµÄ³¢ÊÔ£¬Ëü»á°ÑÕâһʼþ±àÈëÈÕ־Ȼºó×èÖ¹ËüÔٴη¢Éú¡£¸Ã°üÒ²¿ÉÒÔÔÚ±¾½Ì³ÌĩβµÄ²Î¿¼×ÊÁÏÖÐÕÒµ½¡£

    µ±°²×°Á˸ðü²¢ÔËÐÐËüʱ£¬½«Äܹ»ÔÚ syslog Öп´µ½ËùÓг¢ÊÔµÄÁ¬½Ó£¬²¢¿´µ½ PortSentry ÈçºÎ¶ÔËüÃÇ×ö³ö·´Ó¦£º

    [code]# tail /var/log/messages
    Oct 15 00:21:24 mycroft portsentry[603]: attackalert:
    SYN/Normal scan from host: 302.174.40.34/302.174.40.34 to TCP port: 111
    Oct 15 00:21:24 mycroft portsentry[603]: attackalert:
    Host 302.174.40.34 has been blocked via wrappers with string:
    "ALL: 302.174.40.34"
    Oct 15 00:21:24 mycroft portsentry[603]: attackalert:
    Host 302.174.40.34 has been blocked via dropped route using command:
    "/sbin/route add -host 302.174.40.34 reject"
    Oct 15 00:21:24 mycroft portsentry[603]: attackalert:
    SYN/Normal scan from host: 302.174.40.34/302.174.40.34 to TCP port: 111
    Oct 15 00:21:24 mycroft portsentry[603]: attackalert:
    Host: 302.174.40.34/302.174.40.34 is already blocked Ignoring
    Oct 15 00:33:59 mycroft portsentry[603]: attackalert:
    SYN/Normal scan from host: 302.106.103.19/302.106.103.19 to TCP port: 111
    Oct 15 00:33:59 mycroft portsentry[603]: attackalert:
    Host 302.106.103.19 has been blocked via wrappers with string:
    "ALL: 302.106.103.19"
    Oct 15 00:33:59 mycroft portsentry[603]: attackalert:
    Host 302.106.103.19 has been blocked via dropped route using command:
    "/sbin/route add -host 302.106.103.19 reject"[/code]

  5. àÖવδð ÓÚ 2006-10-02 21:40:12·¢±í:

    ÈëÇÖ¼ì²â -- tripwire

    ÓÐÐí¶à¿ÉÓõİü¿ÉÒÔ¶ÔÕû¸öÎļþϵͳ½øÐС°¿ìÕÕ¡±£¬È»ºó½«ËüÓë½ÏÔçµÄ¿ìÕձȽÏÒÔÁ˽âʲô·¢ÉúÁ˸ü¸Ä¡£ÈôÄÜÃ÷È·µØ¶¨ÒåÄÄЩÎļþ×÷ΪϵͳÕý³£²Ù×÷µÄÒ»²¿·ÖÓ¦¸Ã·¢Éú¸ü¸Ä£¬ÔòÕâЩ°üÄܺܿìÌáÐѺڿ͵ĴæÔÚ¼°Æä»î¶¯¡£

    Tripwire ÊÇ×îÁ÷ÐеÄÈëÇÖ¼ì²â°üÖ®Ò»£¨Çë²ÎÔı¾½Ì³ÌĩβµÄ²Î¿¼×ÊÁÏÒÔ»ñÈ¡Á´½Ó£©¡£°²×° tripwire ºó£¬±ØÐë¶¨ÖÆËüµÄÅäÖÃÎļþÒÔʹËüÖªµÀÄÄЩÎļþÓ¦¸Ã¸ü¸Ä¶øÄÄЩ²»Ó¦¸ü¸Ä¡£»¹ÐèÒª¸æËßËüÈçºÎÏòÄú·¢ËÍÓйط¢Éúʲô¸ü¸ÄµÄ±¨¸æ£¬ÒÔ¼°ËüÓ¦¸ô¶à¾ÃÔËÐÐÒ»´Î£¨Í¨³£Ã¿ÌìÒ»´Î£©¡£

  6. àÖવδð ÓÚ 2006-10-02 21:39:51·¢±í:

    ÈëÇÖ¼ì²â -- ϵͳÈÕÖ¾£¨syslog£©

    ÈëÇÖ¼ì²âͨ³£±»ÄÇЩÏàÐÅ×Ô¼º°²ÖõÄÈëÇÖÔ¤·ÀÉ豸µÄϵͳ¹ÜÀíÔ±ËùºöÂÔ¡£²»ÐÒµÄÊÇ£¬ÕâÒâζ×ÅÒ»µ©ºÚ¿ÍÕÒµ½¿ÉÒÔÈëÇÖµÄϸ΢©¶´£¬ÔÚ×¢Òâµ½ËûÃǵĴæÔÚÒÔǰ£¬ÏµÍ³¿ÉÄܺܳ¤Ò»¶Îʱ¼ä¶¼´¦ÓÚËûÃǵĿØÖÆÖ®Ï¡£

    ÈëÇÖ¼ì²â×î»ù±¾µÄÐÎʽÊÇ×¢ÒâϵͳÈÕÖ¾¡£ÕâЩÎļþͨ³£³öÏÖÔÚ /var/log Ŀ¼ÖУ¬²»¹ýʵ¼ÊµÄÎļþÃû»áÒò·Ö·¢°æºÍÅäÖöøÓÐËù²»Í¬¡£

    [code]# less /var/log/messages
    Feb 17 21:21:38 [kernel] Vendor: SONY Model: CD-RW CRX140E Rev: 1.0n
    Feb 17 21:21:39 [kernel] eth0: generic NE2100 found at 0xe800, Version 0x031243,
    DMA 3 (autodetected), IRQ 11 (autodetected).
    Feb 17 21:21:39 [kernel] ne.c:v1.10 9/23/94 Donald Becker (becker@scyld.com)
    Feb 17 21:22:11 [kernel] NVRM: AGPGART: VIA MVP3 chipset
    Feb 17 21:22:11 [kernel] NVRM: AGPGART: allocated 16 pages
    Feb 17 22:20:05 [PAM_pwdb] authentication failure; (uid=1000)
    -> root for su service
    Feb 17 22:20:06 [su] pam_authenticate: Authentication failure
    Feb 17 22:20:06 [su] - pts/3 chouser-root[/code]

    ÒªÀí½âËùÓÐÕâЩÏûÏ¢¿ÉÄÜÐèÒª½øÐÐһЩʵ¼ù£¬µ«´ó¶àÊýÖØÒªÏûÏ¢¶¼Ï൱Çå³þ¡£ÀýÈ磬ÔÚÈÕÖ¾µÄĩ⣬ÎÒÃÇ¿ÉÒÔ¿´µ½Óû§¡°chouser¡±ÊÔͼʹÓà su ³ÉΪ root Óû§£¬µ«Ê§°ÜÁË¡£

  7. àÖવδð ÓÚ 2006-10-02 21:39:24·¢±í:

    iptables ºÍ Linux ÐÅÏ¢°ü¹ýÂËÆ÷

    ÓÐЧµØÊ¹Óà Linux ÐÅÏ¢°ü¹ýÂËÆ÷ÐèÒª¶Ô TCP/IP ÁªÍø¼°ÆäÈçºÎÔÚ Linux ÄÚºËÖÐʵÏÖÓÐÔúʵµÄÀí½â¡£netfilter Ö÷Ò³£¨Çë²ÎÔı¾½Ì³Ì×îºóÒ»ÕµIJο¼×ÊÁÏ£¬ÒÔ»ñµÃÁ´½Ó£©ÊÇѧϰ¸ü¶à֪ʶµÄºÃÈ¥´¦¡£

    ÔÚÄÜ×ÔÈçµØ¹¹½¨×Ô¼ºµÄ¹æÔò¼¯ÒÔǰ£¬ÓÐÐí¶à½Å±¾¿ÉÒÔÈÃÄúÈëÃÅ£¬Ö»ÒªÄúÐÅÈÎËüÃǵÄ×÷Õß¼´¿É¡£×îÍêÕûµÄ½Å±¾Ö®Ò»ÊÇ gShield£¨Çë²ÎÔIJο¼×ÊÁÏ£©¡£Äú¿ÉÒÔµ÷ÕûÆä×¢ÊÍÁ¼ºÃÇÒÏ൱¼òµ¥µÄÅäÖÃÎļþÒÔÉèÖÃÐÅÏ¢°ü¹ýÂËÆ÷¹æÔò×î³£¹æµÄ¸ñʽ¡£

  8. àÖવδð ÓÚ 2006-10-02 21:39:03·¢±í:

    iptables£¨ipchains£©¼ò½é

    iptables ºÍ ipchains ÃüÁîÓÃÓÚÔÚÔËÐÐµÄ Linux ÄÚºËÖе÷ÕûºÍ¼ì²éÍøÂçÐÅÏ¢°ü¹ýÂËÆ÷¹æÔò¡£ipchains ÃüÁîÓÃÓÚ 2.2.x °æ±¾Äںˣ¬¾¡¹ÜËüÈÔ¿ÉÓÃÓÚ 2.4.x Äںˣ¬µ«Òѱ» iptables È¡´ú¡£

    ¿ÉÉèÖÃÐÅÏ¢°ü¹ýÂËÆ÷¹æÔò½øÐзÀ»ðǽºÍ·ÓÉÆ÷µÄ»î¶¯¡£¿ÉÒÔ¶Ô iptables ÃüÁî¼ÓÉÏ -L Ñ¡ÏîÀ´¼ì²éµ±Ç°µÄ¹æÔò£º

    [code]# iptables -L
    Chain INPUT (policy ACCEPT)
    target prot opt source destination

    Chain FORWARD (policy ACCEPT)
    target prot opt source destination

    Chain OUTPUT (policy ACCEPT)
    target prot opt source destination[/code]

    ÕâÊÇÒ»¸ö·Ç³£¿ª·ÅµÄϵͳʾÀý£¬Ã»ÓÐÆôÓ÷ÓÉ»ò·À»ðǽ¡£

  9. àÖવδð ÓÚ 2006-10-02 21:38:33·¢±í:

    ¾Ü¾øµÇ¼ÒÔ½øÐÐά»¤

    ³ýÁËÒÔÉÏ·½·¨Í⣬»¹ÓÐͨ¹ý´´½¨ /etc/nologin ÎļþÀ´¾Ü¾øµÇ¼µÄÆÕͨ·½·¨¡£Í¨³£ÕâÒ»·½·¨ÓÃÓÚ¶ÌÆÚά»¤²Ù×÷¡£ÈÔÈ»¿ÉÒÔÔÊÐíÒÔ root Óû§Éí·ÝµÇ¼£¬µ«½«¾Ü¾øÒÔÆäËûÓû§Éí·ÝµÇ¼¡£ÀýÈ磺

    [code]# cat > /etc/nologin
    ==============================================

    System is currently undergoing maintenance
    until 2:00. Please come back later.

    ==============================================
    # telnet localhost
    login: agriffis
    Password:
    ==============================================

    System is currently undergoing maintenance
    until 2:00. Please come back later.

    ==============================================

    Login incorrect[/code]

    Íê³Éά»¤ºó£¬Ò»¶¨ÒªÉ¾³ýÕâ¸öÎļþ£¬·ñÔòÔÚÄúÏëÆðÒÔǰ£¬Ã»ÈËÄܵǼ£¡ÎÒ¿ÉûÕâô×ö¹ý£¬¶Ô£¬ÎÒûÓÐ...

  10. àÖવδð ÓÚ 2006-10-02 21:38:04·¢±í:

    ²âÊÔ¸ü¸Ä

    ÔÚÐÞ¸Ä inetd »ò xinetd ÅäÖÃÒÔ½ûÓûòÏÞÖÆ·þÎñ£¬»òÓ÷þÎñÆ÷³õʼ»¯½Å±¾¹Ø±Õ¸Ã·þÎñÆ÷ºó£¬Ó¦¸Ã¶ÔËù×öµÄ¸ü¸Ä¼ÓÒÔ²âÊÔ¡£¿ÉÒÔʹÓà telnet ¿Í»§»úͨ¹ýÖ¸¶¨·þÎñÃû³Æ»òºÅÂëÀ´²âÊÔ tcp ¶Ë¿Ú¡£ÀýÈ磬ҪÑéÖ¤ rlogin Òѱ»½ûÓãº

    [code]# grep ^login /etc/services
    login 513/tcp
    # telnet localhost 513
    Trying 127.0.0.1...
    telnet: Unable to connect to remote host: Connection refused[/code]

    ³ýÁ˱ê×¼ telnet ¿Í»§»úÒÔÍ⣬»¹Ó¦¿¼ÂÇʹÓÃʵÓóÌÐòÒÔ²âÊÔϵͳ¡°¿ª·Å³Ì¶È¡±µÄ¿ÉÄÜÐÔ¡£ÎÒÃÇÍÆ¼öʹÓà netcat ºÍ nmap¡£

    ncat ÊÇ¡°ÍøÂçÈðÊ¿¾üµ¶¡±£ºËüÊÇʹÓà TCP »ò UDP ЭÒé¡¢¿çÔ½ÍøÂçÁ¬½Ó¶ÁдÊý¾ÝµÄ¼òµ¥ UNIX ʵÓóÌÐò¡£nmap ÊÇÓÃÓÚÍøÂç̽²â»ò°²È«ÐÔÉ󼯵ÄʵÓóÌÐò¡£¾ßÌå¶øÑÔ£¬nmap ɨÃè¶Ë¿ÚÒÔÈ·¶¨Äĸö¶Ë¿Ú´ò¿ªÁË¡£

    ¿ÉÒÔÔÚ±¾½Ì³Ì×îºóÒ»Õ£¨²Î¿¼×ÊÁÏ£©ÖÐÕÒµ½Ö¸ÏòÕâЩʵÓóÌÐòµÄÁ´½Ó¡£

  11. àÖવδð ÓÚ 2006-10-02 21:37:34·¢±í:

    ¹Ø±ÕδʹÓõÄÍøÂç·þÎñ£¨¶ÀÁ¢·þÎñÆ÷£©

    ÓÐЩ·þÎñÆ÷²¢²»ÓÉ inetd »ò xinetd Æô¶¯£¬µ«È´×÷Ϊ¡°¶ÀÁ¢¡±·þÎñÆ÷ʼÖÕÔËÐÐ×Å¡£ÕâÑùµÄ·þÎñÆ÷ͨ³£ÊÇ atd¡¢lpd¡¢sshd¡¢nfsd ºÍÆäËü·þÎñÆ÷¡£ÊÂʵÉÏ£¬inetd ºÍ xinetd ±¾Éí¶¼ÊǶÀÁ¢·þÎñÆ÷£¬Èç¹ûÔÚËüÃǸ÷×ÔµÄÅäÖÃÎļþÖÐ×¢Ê͵ôËùÓеķþÎñ£¬¾ÍÑ¡ÔñÁ˽«ËüÃÇÍêÈ«¹Ø±Õ¡£

    ¶ÀÁ¢·þÎñÆ÷ͨ³£ÔÚϵͳÒýµ¼»ò¸ü¸ÄÔËÐм¶±ðʱÓÉ init ϵͳÆô¶¯¡£Èç¹û²»¼ÇµÃÔËÐм¶±ðÊÇÈçºÎ¹¤×÷µÄ£¬¿ÉÒÔ¿´¿´ LPI 101 ϵÁÐµÚ 4 ²¿·Ö¡£

    Ҫʹ init ϵͳ²»ÔÙÆô¶¯·þÎñÆ÷£¬ÔÚÿ¸öÔËÐм¶±ðĿ¼ÖÐÕÒµ½Ö¸Ïò¸Ã·þÎñÆ÷Æô¶¯½Å±¾µÄ·ûºÅÁ´½Ó£¬È»ºóɾ³ýËü¡£ÔËÐм¶±ðĿ¼µÄÃû³ÆÍ¨³£Îª /etc/rc3.d »ò /etc/rc.d/rc3.d£¨Õë¶ÔÔËÐм¶±ð 3£©¡£»¹ÐèÒª¼ì²éÆäËüÔËÐм¶±ð¡£

    ³ýÈ¥·þÎñµÄÔËÐм¶±ð·ûºÅÁ´½Óºó£¬ÈÔÐèÒª¹Ø±Õµ±Ç°ÔËÐеķþÎñÆ÷¡£×îºÃÓ÷þÎñµÄ³õʼ»¯½Å±¾Íê³ÉÕâÒ»²Ù×÷£¬Í¨³£¿ÉÒÔÔÚ /etc/init.d »ò /etc/rc.d/init.d ÖÐÕÒµ½ÕâÒ»½Å±¾¡£ÀýÈ磬Ҫ¹Ø±Õ sshd£º

    [code]# /etc/init.d/sshd stop
    * Stopping sshd... [ ok ][/code]

  12. àÖવδð ÓÚ 2006-10-02 21:37:04·¢±í:

    ¹Ø±ÕδʹÓõÄÍøÂç·þÎñ£¨³¬¼¶·þÎñÆ÷£©

    ¹Ø±ÕδʹÓõÄÍøÂç·þÎñÒ»Ö±ÊÇÌá¸ßÈëÇÖÔ¤·ÀÄÜÁ¦µÄºÃ·½·¨¡£ÀýÈ磬Èç¹ûÕýÔÚÔËÐÐÒòÌØÍø³¬¼¶·þÎñÆ÷£¨Èç±¾½Ì³ÌÇ°ÃæÃèÊöµÄ inetd »ò xinetd£©£¬ÄÇô in.rshd¡¢in.rlogind ºÍ in.telnetd ͨ³£¶¼ÔÚȱʡÇé¿öÏÂÆôÓá£ÕâÐ©ÍøÂç·þÎñ¼¸ºõ¶¼Òѱ»¸ü°²È«µÄÌæ´úÏÈç ssh£©ËùÈ¡´ú¡£

    ÒªÔÚ inetd ÖнûÓ÷þÎñ£¬Ö»ÐèÔÚ /etc/inetd.conf ÖÐÔÚÊʵ±µÄÐÐÇ°Ãæ¼ÓÉÏ¡°#¡±½«Æä×¢Ê͵ô£»È»ºóÖØÐÂÆô¶¯ inetd ¼´¿É¡££¨ÕâÔÚ±¾½Ì³ÌÇ°ÃæÒÑÓÐÃèÊö£¬ÈôÐèÒª¸´Ï°£¬¿É·µ»Ø¼¸Ò³¿ìËÙä¯ÀÀ¡££©

    ÒªÔÚ xinetd ÖнûÓ÷þÎñ£¬¿ÉÒÔÖ´ÐÐÓë /etc/xinetd.d ÖÐÊʵ±µÄ´úÂëÆ¬¶ÎÏàËÆµÄ¹¤×÷¡£ÀýÈ磬Ҫ½ûÓà telnet£¬¿ÉÒÔ½« /etc/xinetd.d/telnet ÎļþµÄÕû¸öÄÚÈÝ×¢Ê͵ô£¬»ò¼òµ¥µØÉ¾³ý¸ÃÎļþ¡£ÖØÐÂÆô¶¯ xinetd ÒÔÍê³É´Ë¹ý³Ì¡£

    Èç¹ûÕýÔÚ½áºÏ inetd ʹÓà tcpd£¬»òÈç¹ûÕýÔÚʹÓà xinetd£¬»¹¿ÉÒÔÑ¡ÔñÏÞÖÆÓë¿ÉÐŵÄÖ÷»ú½øÐеĽøÈëÁ¬½Ó¡£¶ÔÓÚ tcpd£¬¿É²ÎÔı¾½Ì³ÌµÄǰ¼¸Õ¡£¶ÔÓÚ xinetd£¬¿ÉÔÚ xinetd.conf(5) ÊÖ²áÒ³ÖÐËÑË÷¡°only_from¡±¡£

  13. àÖવδð ÓÚ 2006-10-02 21:36:39·¢±í:

    ÈëÇÖÔ¤·À

    Íⲿ°²È«ÐÔ¿É·ÖΪÁ½ÀࣺÈëÇÖÔ¤·ÀºÍÈëÇÖ¼ì²â¡£²ÉÈ¡ÈëÇÖÔ¤·ÀÊÖ¶ÎÊÇΪÁË·ÀֹδÊÚȨÓû§·ÃÎÊϵͳ¡£Èç¹ûÕâЩÊÖ¶Îʧ°Ü£¬ÄÇôÈëÇÖ¼ì²âÔÚÈ·¶¨ºÎʱ·¢ÉúδÊÚȨ·ÃÎÊÒÔ¼°Ôì³ÉʲôË𻵷½Ãæ»òÐíÓÐÓá£

    ÍêÈ«µÄ Linux °²×°ÊǾ޴óÇÒ¸´ÔÓµÄϵͳ¡£¸ú×ÙÒѰ²×°µÄÿһÏîÊǺÜÀ§Äѵ쬶øÅäÖÃÿ¸ö°üµÄ°²È«ÐÔÌØÕ÷¾Í¸üÀ§ÄÑÁË¡£°²×°µÄ°üÔ½ÉÙ£¬ÔòÎÊÌâ¾Í±äµÃÔ½¼òµ¥¡£ÈëÇÖÔ¤·ÀµÄµÚÒ»²½ÊdzýÈ¥²»ÐèÒªµÄ°ü¡£

  14. àÖવδð ÓÚ 2006-10-02 21:36:09·¢±í:

    Óà ulimit ÉèÖà CPU ʱ¼äÏÞÖÆ

    ×÷Ϊ ulimit µÄÒ»¸öʾÀý£¬ÎÒÃdz¢ÊÔ½«Ò»¸ö½ø³ÌµÄ CPU ʱ¼äÉèÖÃΪ 1 ÃëÖÓ£¬È»ºóÓÃÒ»¸öæѭ»·Ê¹Ëü³¬Ê±¡£Ò»¶¨ÒªÈ·±£Æô¶¯Ð嵀 bash ½ø³Ì£¨ÏóÎÒÃÇÔÚÏÂÃæ×öµÄÄÇÑù£©£¬ÒÔÔÚÆäÖнøÐг¢ÊÔ£»·ñÔò½«±»×¢Ïú£¡

    [code]# time bash
    # ulimit -t 1
    # while true; do true; done
    Killed

    real 0m28.941s
    user 0m1.990s
    sys 0m0.017s[/code]

    ÔÚÉÏÃæµÄʾÀýÖУ¬¡°user¡±Ê±¼ä¼ÓÉÏ¡°sys¡±Ê±¼äµÈÓڸýø³ÌËùÓõÄÈ«²¿ CPU ʱ¼ä¡£µ± bash ½ø³Ìµ½´ï 2 Ãë±ê¼Çʱ£¬Linux ¶Ï¶¨Ëü³¬¹ý 1 ÃëµÄÏÞÖÆ£¬Òò´Ë¸Ã½ø³Ì±»É±µô¡£¿á°É£¿

    ×¢£ºÒ»ÃëÖÓÖ»ÊÇʾÀý¶øÒÑ¡£²»Òª¶ÔÄúµÄÓû§ÕâÑù×ö£¡¼´Ê¹¼¸Ð¡Ê±Ò²ÊDz»¶ÔµÄ£¬ÒòΪ X ÕæµØºÜÏûºÄʱ¼ä£¨ÎÒµ±Ç°µÄ»á»°ÒÑÓõôÁË 69+ СʱµÄ CPU ʱ¼ä£©¡£ÔÚʵ¼ÊµÄʵÏÖÖУ¬Äú¿ÉÄÜÒª¶ÔijЩÏî¶ø²»ÊÇ CPU ʱ¼äÖ´ÐÐ ulimit¡£

  15. àÖવδð ÓÚ 2006-10-02 21:35:40·¢±í:

    Óà ulimit ÉèÖÃÓû§ÏÞÖÆ

    bash ÖÐµÄ ulimit ÃüÁîÌṩÁËÏÞÖÆÌØ¶¨Óû§µÄ×ÊԴʹÓÃÇé¿öµÄ·½·¨¡£Ò»µ©ÏÞÖÆ½µµÍ£¬ÔòÔÚ½ø³ÌµÄÉúÃüÆÚÄÚÎÞ·¨Ìá¸ß¸ÃÏÞÖÆ¡£´ËÍ⣬¸ÃÏÞÖÆ»á±»ËùÓÐ×Ó½ø³Ì¼Ì³Ð¡£½á¹ûÊÇ£º¿ÉÒÔÔÚ /etc/profile Öе÷Óà ulimit£¬¶øÏÞÖÆ½«ÒÔ²»Äܳ·ÏûµÄ·½Ê½Ó¦ÓÃÓÚËùÓÐÓû§£¨¼ÙÉèÓû§ÕýÔÚÔËÐÐ bash »òÁíÒ»¸ö shell£¬¸Ã shell ÔڵǼʱÔËÐÐ /etc/profile£©¡£

    Òª¼ìË÷µ±Ç°ÏÞÖÆ£¬¿ÉʹÓà ulimit -a£º

    [code]# ulimit -a
    core file size (blocks, -c) 0
    data seg size (kbytes, -d) unlimited
    file size (blocks, -f) unlimited
    max locked memory (kbytes, -l) unlimited
    max memory size (kbytes, -m) unlimited
    open files (-n) 1024
    pipe size (512 bytes, -p) 8
    stack size (kbytes, -s) unlimited
    cpu time (seconds, -t) unlimited
    max user processes (-u) 3071
    virtual memory (kbytes, -v) unlimited[/code]

    ÒÔÒ»ÖÖÄÜʵ¼ÊÌá¸ßϵͳ°²È«ÐÔ¶ø²»»á¶ÔºÏ·¨Óû§Ôì³ÉÂé·³µÄ·½Ê½ÉèÖÃÕâЩÏÞÖÆÊÇÏ൱¸´Ôӵģ¬ËùÒÔµ÷ÕûÕâЩÉèÖÃʱҪСÐÄ¡£

  16. àÖવδð ÓÚ 2006-10-02 21:35:10·¢±í:

    ²éÕÒ SUID/SGID ³ÌÐò

    ѰÇó root ·ÃÎÊȨµÄ¶ñÒâÓû§×ÜÊÇ»áÔÚϵͳÉÏѰÕÒÉèÖÃÁË SUID »ò SGID λµÄ³ÌÐò¡£¾ÍÏóÎÒÃÇÔÚ LPI 101 ϵÁÐµÚ 3 ²¿·ÖÖÐÌÖÂÛµÄÄÇÑù£¬ÕâЩλʹ³ÌÐòʼÖÕ×÷ΪӵÓиÃÎļþµÄÓû§»ò×éÔËÐС£ÓÐʱÕâÊdzÌÐòÕýÈ·ÔËÐÐËù±ØÐèµÄ¡£ÎÊÌâÊÇÈκγÌÐò¶¼¿ÉÄܰüº¬ÔÊÐíÓû§ÔÚ²»ÕýÈ·µØÊ¹ÓóÌÐòʱ»ñµÃÌØÈ¨µÄ´íÎó¡£

    Ó¦¸Ã×Ðϸ¿¼ÂÇÿ¸ö³ÌÐòÒÔÈ·¶¨ÊÇ·ñÐèÒª½«Æä SUID »ò SGID λ´ò¿ª¡£ÏµÍ³ÉÏÓÐЩ SUID/SGID ³ÌÐò¿ÉÄÜÊǸù±¾²»ÐèÒªµÄ¡£

    ÒªËÑË÷¾ßÓÐÕâÑùÐÔÖʵijÌÐò£¬¿ÉʹÓà find ÃüÁî¡£ÀýÈ磬¿ÉÒÔÔÚ /usr Ŀ¼ÖÐÆô¶¯¶Ô SUID/SGID ³ÌÐòµÄËÑË÷£º

    [code]# cd /usr
    # find . -type f -perm +6000 -xdev -exec ls {} \;
    -rwsr-sr-x 1 root root 593972 11-09 12:47 ./bin/gpg
    -r-xr-sr-x 1 root man 38460 01-27 22:13 ./bin/man
    -rwsr-xr-x 1 root root 15576 09-29 22:51 ./bin/rcp
    -rwsr-xr-x 1 root root 8256 09-29 22:51 ./bin/rsh
    -rwsr-xr-x 1 root root 29520 01-17 19:42 ./bin/chfn
    -rwsr-xr-x 1 root root 27500 01-17 19:42 ./bin/chsh
    -rwsr-xr-x 1 lp root 8812 01-15 23:21 ./bin/lppasswd
    -rwsr-x--- 1 root cron 10476 01-15 22:16 ./bin/crontab[/code]

    ÔÚÕâ¸öÇåµ¥ÖУ¬ÎÒÒѾ­·¢ÏÖÁËÐèÒª¸ü×Ðϸ¼ì²éµÄºîÑ¡¶ÔÏó£ºlppasswd ÊÇ CUPS ´òÓ¡Èí¼þ·Ö·¢°æµÄÒ»²¿·Ö¡£ÒòΪûÓÐÔÚϵͳÉÏÌṩ´òÓ¡·þÎñ£¬ËùÒÔÎһῼÂdzýÈ¥ CUPS£¬ÄÇÒ²»á³ýÈ¥ lppasswd ³ÌÐò¡£lppasswd ÖпÉÄÜûÓÐΣ¼°°²È«ÐԵĴíÎ󣬵«ÎªÊ²Ã´ÒªÔÚ²»Ê¹ÓõijÌÐòÉÏðÏÕÄØ£¿Í¬ÑùµØ£¬Ó¦¸Ã¹Ø±ÕËùÓв»Ê¹ÓõķþÎñ¡£Äú×ÜÊÇ¿ÉÒÔÔÚÐèҪʱÔÙÆôÓÃËüÃÇ¡£

  17. àÖવδð ÓÚ 2006-10-02 21:34:36·¢±í:

    Óû§ÎļþµÄÎļþȨÏÞ

    ×îºó£¬Óû§ÎļþÔÚȱʡÇé¿öÏÂͨ³£±»´´½¨ÎªËùÓÐÈ˿ɶÁ¡£ÄÇ¿ÉÄܲ»ÊÇÓû§ËùÆÚÍûµÄ£¬¶øÇÒËüµ±È»²»ÊÇ×îºÃµÄ²ßÂÔ¡£Ó¦¸ÃʹÓÃÓëÏÂÃæÀàËÆµÄÃüÁîÔÚ /etc/profile ÖÐÉèÖÃȱʡµÄ umask£º

    [code]if [ "$UID" = 0 ]; then
    # root user; set world-readable by default so that
    # installed files can be read by normal users.
    umask 022
    else
    # make user files secure unless they explicitly open them
    # for reading by other users
    umask 077
    fi[/code]

    Ó¦¸Ã²éѯ umask(2) ºÍ bash(1) ÊÖ²áÒ³ÒÔ»ñÈ¡ÓйØÉèÖà umask µÄ¸ü¶àÐÅÏ¢¡£Çë×¢Ò⣺umask(2) ÊÖ²áÒ³Éæ¼° C º¯Êý£¬µ«ËüËù°üº¬µÄÐÅÏ¢Ò²ÊÊÓÃÓÚ bash ÃüÁî¡£

  18. àÖવδð ÓÚ 2006-10-02 21:34:07·¢±í:

    root Óû§ÆäËüÎļþµÄÎļþȨÏÞ

    Æä´Î£¬root Óû§µÄµãÎļþ¶ÔÓÚÆÕͨÓû§Ó¦ÊDz»¿É¶ÁµÄ¡£¼ì²é root Óû§Ö÷Ŀ¼ÖеÄÎļþ£¨ls -la£©ÒÔÈ·±£ËüÃÇÊܵ½Êʵ±µÄ±£»¤¡£ÉõÖÁ¿ÉÒÔʹÕû¸öĿ¼½ö¶Ô root Óû§¿É¶Á£º

    [code]# cd
    # pwd
    /root
    # chmod 700 .[/code]

  19. àÖવδð ÓÚ 2006-10-02 21:33:19·¢±í:

    ÈÕÖ¾ÎļþµÄÎļþȨÏÞ

    ÄÚ²¿°²È«ÐÔ¿ÉÒÔÊǺܴóµÄÈÎÎñ£¬ÕâÒª¿´Äú¶ÔÓû§µÄÐÅÈγ̶ȡ£ÕâÀï½éÉܵÄÖ¸µ¼Ô­ÔòÊÇÉè¼ÆÓÃÀ´·ÀֹżȻÓû§·ÃÎÊÃô¸ÐÐÅÏ¢ºÍ·ÀÖ¹²»¹«Æ½µØÊ¹ÓÃϵͳ×ÊÔ´¡£

    ÖÁÓÚÎļþȨÏÞ£¬Äú¿ÉÄÜÏ£ÍûÐÞ¸ÄÒÔÏÂÈýÖÖÇé¿öµÄȨÏÞ£º

    Ê×ÏÈ£¬/var/log ÖеÄÈÕÖ¾Îļþ²»ÐèÒªÊÇËùÓÐÈ˶¼¿ÉÒÔ¶ÁÈ¡µÄ¡£Ã»ÓÐÀíÓÉÈÃ·Ç root Óû§¿úÊÓÈÕÖ¾¡£ÎªÁË´´½¨¾ßÓÐÊʵ±È¨ÏÞµÄÈÕÖ¾¡£