1.ÎļþÒþ²ØÊôÐÔ
chattr
chattr [+-=] [ASacdi] ÎļþÃû»òĿ¼
+£ºÔö¼Óijһ¸öÌØÊâ²ÎÊý£¬ÆäËûÔ±¾´æÔÚ²ÎÊý²»¶¯
-£ºÉ¾³ýijһ¸öÌØÊâ²ÎÊý£¬ÆäËûÔ±¾´æÔÚ²ÎÊý²»¶¯
=£ºÉèÖù̶¨²ÎÊý
A:¶ÁдÎļþ»òĿ¼ʱ£¬ËûµÄ·þÎñʱ¼äatime²»±ä£¬¿ÉÒÔ±ÜÃâI/O½ÏÂýµÄ»úÆ÷¹ý¶È¶Áд´ÅÅÌ¡£
S£ºµ±ÐÞ¸ÄÎļþ»òĿ¼ÊÇ×Ô¶¯Í¬²½Ð´Èë´ÅÅÌÖÐ
a£º±»ÉèÖõÄÎļþÖ»ÄÜдÈ룬¶ÔÎļþ²»ÄÜɾ³ýÒ²²»ÄÜÐÞ
¸ÄÊý¾Ý£¬Ö»ÓÐrootÄÜÉèÖÃ
c:×Ô¶¯Ñ¹Ëõ£¬¶Áȡʱ×Ô¶¯½âѹËõ
d£ºµ±dump±¸·Ýʱ£¬ÉèÖÃΪdµÄÎļþ»òĿ¼²»»á±»dump
i:ÈÃÒ»¸öÎļþ²»ÄÜɾ³ý¡¢¸ÄÃû¡¢É趨Á¬½Ó¡¢Ð´È룬ֻÓÐrootÄÜÓÃ
×¢Òâ×î³£ÓõÄÊÇa¡¢i¡£rootÓû§¾³£Ê¹Óñ£»¤ÏµÍ³
È磺½ûÖ¹ÔÚϵͳÖÐн¨¡¢É¾³ýÓû§£¬Í¬±»ÉèÖõÄÎļþ²»Äܱ»É¾³ý
chattr +i /etc/passwd /etc/shadow
Èç¹ûÏëÈ¡Ïû£º
chattr -i /etc/passwd /etc/shadow
Èç¹ûÒª±£»¤ÈÕÖ¾Îļþ·ÀÖ¹Çå¿ÕÈÕÖ¾
chattr +a /var/log/messages
lsattr:²é¿´Òþ²ØÈ¨ÏÞ
chattr +ai /tmp/test
lsattr /tmp
µ±È»chattr¿ÉÒÔʹÓÃ-RµÝ¹éÉèÖÃ
lsattrʹÓÃ-RÁ¬Í¬×ÓĿ¼µÄÊý¾ÝÒ²Áгö
2.ÎļþµÄ·ÃÎÊ¿ØÖÆÁÐ±í£¨acl£©£¬Õâ¸öÓеãÀàËÆÓÚNTFSϵͳµÄacl,Õâ¶ÔÓÚ¸øÌض¨ÓÃÉèÖÃÌØ¶¨µÄȨÏ޷dz£ÓÐÓÃ
¶¨ÒåÎļþµÄaclʹÓÃsetfacl
²é¿´ÎļþµÄaclʹÓÃgetfacl
È磺Ïë¸øÌØ¶¨Óû§u01ÉèÖöÁдִÐеÄȨÏÞ
setfacl -m user:u01:rwx /etc/yum.repos.d/
²é¿´Ê¹ÓÃ
getfacl /etc/yum.repos.d/
ɾ³ýȨÏÞ(×¢Òâ²»ÓÃÖ¸Ã÷ȨÏÞÁбí)
setfacl -x user:u01 /etc/yum.repos.d/
3.Set UID
SUIDµÄÏÞÖÆÓ빦ÄÜ£º
1£©SUIDȨÏÞ½ö½ö¶Ô¶þ½øÖÆ£¨binary program£©ÓÐЧ
2£©Ö´ÐÐÕß¶ÔÓڸóÌÐòÓÐxȨÏÞ
3£©¸ÃȨÏÞ½ö½öÔÚÖ´ÐиóÌÐòÊÇÓÐЧ£¨run-time£©
4£©Ö´ÐÐÕß½«±»¸³ÓèownerµÄȨÏÞ
¾Ù¸öÀý×Ó£¬Õâ¾ÍÏñ»ÊµÛµÄÉз½±¦½£¡¢Ö´½£ÕßÓлʵ۵ÄȨÀû£¬µ«ÊÇÕâ½ö½öÊÇÉз½±¦½£ÔÚËûÊÖÀïµÄʱ¼äÀï¡£
linuxÖеÄpasswd¾ÍÊÇ×îºÃµÄÀý×Ó£¬Ëü±»ÉèÖÃÁËSUID¡¢ÆÕͨÓû§Ò²¿ÉÒÔ¸ÄÃÜÂë¡£
×¢ÒâÔÚÉèÖÃʱÈç¹û¸ÃÎļþÓÐx
ʹÓÃls -l²é¿´ÔÚownerµÄȨÏÞΪÉÏΪСдµÄs
Èç¹ûûÓУ¬ÔòΪS¡£
ÉèÖõķ½·¨£º
chmod u+s Îļþ
4.SGID
Óësuid²»Í¬£¬SGID¿ÉÒÔ¶ÔĿ¼»òÎļþÉèÖãº
Èç¹ûÊǶÔÎļþÉèÖÃSGIDËûµÄ¹¦ÄܺÍÏÞÖÆÈçÏ£¬
1£©SGIDȨÏÞ¶Ô¶þ½øÖÆ£¨binary program£©ÓÐЧ
2£©Ö´ÐÐÕß¶ÔÓڸóÌÐòÓÐxȨÏÞ
3£©¸ÃȨÏÞ½ö½öÔÚÖ´ÐиóÌÐòÊÇÓÐЧ£¨run-time£©
4£©Ö´ÐÐÕß½«±»¸³ÓègroupµÄȨÏÞ
/usr/bin/locate¾ÍÊǸöÀý×Ó
Èç¹ûÊǶÔĿ¼ÉèÖÃSGIDËûµÄ¹¤ÄܺÍÏÞÖÆÈçÏ¡¢
1£©Óû§Èô¶Ô´ËĿ¼¾ßÓÐrÓëxµÄȨÏÞÊÇ£¬¸ÃÓû§Äܹ»½øÈëĿ¼
2£©Óû§ÔÚ´ËĿ¼ÏµÄÓÐЧ×飨effective group£©½«»á±ä³É¸ÄĿ¼µÄgroup
3£©ÓÃ;£ºÈôÓû§ÔÚ´ËĿ¼Ï¾ßÓÐwȨÏÞ£¬ÔòʹÓÃÕßËùн¨µÄÎļþÆägroup½«±ä³É¸ÃĿ¼µÄgroup
4£©SGID¶ÔÓÚÍŶÓÏîÄ¿¿ª·¢À´ËµÊǷdz£ÓÐÓõÄÉèÖõķ½·¨£º
chmod g+s
5.Sticky Bit
SBITĿǰֻ¶ÔĿ¼ÓÐЧ£¬¶ÔÎļþÎÞЧ¡£ËûµÄ×÷Óãº
µ±¶à¸öÓû§¶ÔÓÚ´ËĿ¼¾ßÓÐw¡¢xȨÏÞ£¬Óû§Ð½¨µÄÎļþ»òĿ¼ֻÓÐrootÓÐȨÀûɾ³ý£¬¼´,ÆäËûÓû§Ö»ÄܶÔ×Ô¼ºµÄÎļþ½øÐÐdel¡¢rename¡¢moveµÈ¶¯×÷£¬¶øÎÞ·¨É¾³ýÆäËûÈ˵ÄÎļþ¡£
ϵͳÖеÄ/tmp¾ÍÊÇÕâÑùÒ»¸öĿ¼
ÉèÖõķ½·¨£º
chmod o+t
À´Ô´£ºLinuxÉçÇø