ºìÁªLinuxÃÅ»§
Linux°ïÖú

Linux¸³ÓèÆÕͨÓû§µÄÌØÊâȨÏÞ

·¢²¼Ê±¼ä:2007-04-08 21:05:02À´Ô´:ºìÁª×÷Õß:earwig
ÔÚLinuxϵͳÖУ¬¹ÜÀíÔ±ÍùÍù²»Ö¹Ò»ÈË£¬Èôÿλ¹ÜÀíÔ±¶¼ÓÃrootÉí·Ý½øÐйÜÀí¹¤×÷£¬¸ù±¾ÎÞ·¨ÅªÇå³þË­¸Ã×öʲô¡£ËùÒÔ×îºÃµÄ·½Ê½ÊÇ£º¹ÜÀíÔ±´´½¨Ò»Ð©ÆÕͨÓû§£¬·ÖÅäÒ»²¿·Öϵͳ¹ÜÀí¹¤×÷¸øËûÃÇ¡£

ÎÒÃDz»¿ÉÒÔʹÓÃsuÈÃËûÃÇÖ±½Ó±ä³Éroot£¬ÒòΪÕâЩÓû§¶¼±ØÐëÖªµÀrootµÄÃÜÂ룬ÕâÖÖ·½·¨ºÜ²»°²È«£¬¶øÇÒÒ²²»·ûºÏÎÒÃǵķֹ¤ÐèÇó¡£Ò»°ãµÄ×ö·¨ÊÇÀûÓÃȨÏÞµÄÉèÖã¬ÒÀ¹¤×÷ÐÔÖÊ·ÖÀ࣬ÈÃÌØÊâÉí·ÝµÄÓû§³ÉΪͬһ¸ö¹¤×÷×飬²¢ÉèÖù¤×÷×éȨÏÞ¡£ÀýÈ磺ҪwwwadmÕâλÓû§¸ºÔð¹ÜÀíÍøÕ¾Êý¾Ý£¬Ò»°ãApache Web ServerµÄ½ø³ÌhttpdµÄËùÓÐÕßÊÇwww£¬Äú¿ÉÒÔÉèÖÃÓû§wwwadmÓëwwwΪͬһ¹¤×÷×飬²¢ÉèÖÃApacheĬÈÏ´æ·ÅÍøÒ³Ä¿Â¼ /usr/local/httpd/htdocsµÄ¹¤×÷×éȨÏÞΪ¿É¶Á¡¢¿Éд¡¢¿ÉÖ´ÐУ¬ÕâÑùÊôÓڴ˹¤×÷×éµÄÿλÓû§¾Í¿ÉÒÔ½øÐÐÍøÒ³µÄ¹ÜÀíÁË¡£

µ«Õâ²¢²»ÊÇ×îºÃµÄ½â¾ö°ì·¨£¬ÀýÈç¹ÜÀíÔ±ÏëÊÚÓèÒ»¸öÆÕͨÓû§¹Ø»úµÄȨÏÞ£¬ÕâʱʹÓÃÉÏÊöµÄ°ì·¨¾Í²»ÊǺÜÀíÏë¡£ÕâʱÄúÒ²Ðí»áÏ룬ÎÒÖ»ÈÃÕâ¸öÓû§¿ÉÒÔÒÔ rootÉí·ÝÖ´ÐÐshutdownÃüÁî¾ÍÐÐÁË¡£Íêȫû´í£¬¿ÉϧÔÚͨ³£µÄLinuxϵͳÖÐÎÞ·¨ÊµÏÖÕâÒ»¹¦ÄÜ£¬²»¹ýÒѾ­ÓÐÁ˹¤¾ß¿ÉÒÔʵÏÖÕâÑùµÄ¹¦ÄÜ---- sudo¡£

sudoͨ¹ýά»¤Ò»¸öÌØÈ¨µ½Óû§ÃûÓ³ÉäµÄÊý¾Ý¿â½«ÌØÈ¨·ÖÅ䏸²»Í¬µÄÓû§£¬ÕâÐ©ÌØÈ¨¿ÉÓÉÊý¾Ý¿âÖÐËùÁеÄһЩ²»Í¬µÄÃüÁîÀ´Ê¶±ð¡£ÎªÁË»ñµÃÄ³Ò»ÌØÈ¨ÏÓÐ×ʸñµÄÓû§Ö»Ðè¼òµ¥µØÔÚÃüÁîÐÐÊäÈësudoÓëÃüÁîÃûÖ®ºó£¬°´ÕÕÌáʾÔÙ´ÎÊäÈë¿ÚÁÓû§×Ô¼ºµÄ¿ÚÁ²»ÊÇrootÓû§¿ÚÁ¡£ÀýÈ磬sudoÔÊÐíÆÕͨÓû§¸ñʽ»¯´ÅÅÌ£¬µ«ÊÇȴûÓи³ÓèÆäËûµÄrootÓû§ÌØÈ¨¡£

1¡¢sudo¹¤¾ßÓÉÎļþ/etc/sudoers½øÐÐÅäÖ㬸ÃÎļþ°üº¬ËùÓпÉÒÔ·ÃÎÊsudo¹¤¾ßµÄÓû§ÁÐ±í²¢¶¨ÒåÁËËûÃǵÄÌØÈ¨¡£Ò»¸öµäÐ͵Ä/etc/sudoersÌõÄ¿ÈçÏ£º

´úÂë:

liming ALL=(ALL) ALL

Õâ¸öÌõĿʹµÃÓû§liming×÷Ϊ³¬¼¶Óû§·ÃÎÊËùÓÐÓ¦ÓóÌÐò£¬ÈçÓû§limingÐèÒª×÷Ϊ³¬¼¶Óû§ÔËÐÐÃüÁËûÖ»Ðè¼òµ¥µØÔÚÃüÁîǰ¼ÓÉÏǰ׺sudo¡£Òò´Ë£¬ÒªÒÔrootÓû§µÄÉí·ÝÖ´ÐÐÃüÁîformat£¬liming¿ÉÒÔÊäÈëÈçÏÂÃüÁ

´úÂë:

# sudo /usr/sbin/useradd sam

×¢Ò⣺ÃüÁîҪд¾ø¶Ô·¾¶£¬/usr/sbinĬÈϲ»ÔÚÆÕͨÓû§µÄËÑË÷·¾¶ÖУ¬»òÕß¼ÓÈë´Ë·¾¶£ºPATH=$PATH:/usr/sbin;export PATH¡£ÁíÍ⣬²»Í¬ÏµÍ³ÃüÁîµÄ·¾¶²»¾¡Ïàͬ£¬¿ÉÒÔʹÓÃÃüÁî¡°whereis ÃüÁîÃû¡±À´²éÕÒÆä·¾¶¡£

Õâʱ»áÏÔʾÏÂÃæµÄÊä³ö½á¹û£º

´úÂë:

We trust you have received the usual lecture from the local System

Administrator. It usually boils down to these two things:

#1) Respect the privacy of others.

#2) Think before you type.

Password:

Èç¹ûlimingÕýÈ·µØÊäÈëÁË¿ÚÁÃüÁîuseradd½«»áÒÔrootÓû§Éí·ÝÖ´ÐС£

×¢Ò⣺ÅäÖÃÎļþ/etc/sudoers±ØÐëʹÓÃÃüÁî VisudoÀ´±à¼­¡£

Ö»Òª°ÑÏàÓ¦µÄÓû§Ãû¡¢Ö÷»úÃûºÍÐí¿ÉµÄÃüÁîÁбíÒÔ±ê×¼µÄ¸ñʽ¼ÓÈëµ½Îļþ/etc/sudoers£¬²¢±£´æ¾Í¿ÉÒÔÉúЧ£¬ÔÙ¿´Ò»¸öÀý×Ó¡£

2¡¢Àý×Ó£º¹ÜÀíÔ±ÐèÒªÔÊÐígemÓû§ÔÚÖ÷»úsunÉÏÖ´ÐÐrebootºÍshutdownÃüÁÔÚ/etc/sudoersÖмÓÈ룺

´úÂë:

gem sun=/usr/sbin/reboot£¬/usr/sbin/shutdown

×¢Ò⣺ÃüÁîÒ»¶¨ÒªÊ¹Óþø¶Ô·¾¶£¬ÒÔ±ÜÃâÆäËûĿ¼µÄͬÃûÃüÁî±»Ö´ÐУ¬´Ó¶øÔì³É°²È«Òþ»¼¡£

È»ºó±£´æÍ˳ö£¬gemÓû§ÏëÖ´ÐÐrebootÃüÁîʱ£¬Ö»ÒªÔÚÌáʾ·ûÏÂÔËÐÐÏÂÁÐÃüÁ

´úÂë:

$ sudo /usr/sbin/reboot

ÊäÈëÕýÈ·µÄÃÜÂ룬¾Í¿ÉÒÔÖØÆô·þÎñÆ÷ÁË¡£

Èç¹ûÄúÏë¶ÔÒ»×éÓû§½øÐж¨Ò壬¿ÉÒÔÔÚ×éÃûǰ¼ÓÉÏ%£¬¶ÔÆä½øÐÐÉèÖã¬È磺

´úÂë:

%cuug ALL=(ALL) ALL

3¡¢ÁíÍ⣬»¹¿ÉÒÔÀûÓñðÃûÀ´¼ò»¯ÅäÖÃÎļþ¡£±ðÃûÀàËÆ×éµÄ¸ÅÄÓÐÓû§±ðÃû¡¢Ö÷»ú±ðÃûºÍÃüÁî±ðÃû¡£¶à¸öÓû§¿ÉÒÔÊ×ÏÈÓÃÒ»¸ö±ðÃûÀ´¶¨Ò壬ȻºóÔڹ涨ËûÃÇ¿ÉÒÔÖ´ÐÐʲôÃüÁîµÄʱºòʹÓñðÃû¾Í¿ÉÒÔÁË£¬Õâ¸öÅäÖöÔËùÓÐÓû§¶¼ÉúЧ¡£Ö÷»ú±ðÃûºÍÃüÁî±ðÃûÒ²ÊÇÈç´Ë¡£×¢ÒâʹÓÃǰÏÈÒªÔÚ/etc/sudoersÖж¨Ò壺 User_Alias, Host_Alias, Cmnd_AliasÏÔÚÆäºóÃæ¼ÓÈëÏàÓ¦µÄÃû³Æ£¬Ò²ÒÔ¶ººÅ·Ö¸ô¿ª¾Í¿ÉÒÔÁË£¬¾ÙÀýÈçÏ£º

´úÂë:

Host_Alias SERVER=no1

User_Alias ADMINS=liming£¬gem

Cmnd_Alias SHUTDOWN=/usr/sbin/halt£¬/usr/sbin/shutdown£¬/usr/sbin/reboot

ADMINS SERVER=SHUTDOWN

¡¢ÔÙ¿´Õâ¸öÀý×Ó£º

´úÂë:

ADMINS ALL=(ALL) NOPASSWD: ALL

±íʾÔÊÐíADMINS²»ÓÿÚÁîÖ´ÐÐÒ»ÇвÙ×÷£¬ÆäÖС°NOPASSWD:¡±ÏÒåÁËÓû§Ö´ÐвÙ×÷ʱ²»ÐèÒªÊäÈë¿ÚÁî¡£

5¡¢sudoÃüÁ¿ÉÒÔ¼ÓÉÏһЩ²ÎÊý£¬Íê³ÉһЩ¸¨ÖúµÄ¹¦ÄÜ£¬Èç

´úÂë:

$ sudo -l

»áÏÔʾ³öÀàËÆÕâÑùµÄÐÅÏ¢£º

´úÂë:

User liming may run the following commands on this host:

(root) /usr/sbin/reboot

˵Ã÷rootÔÊÐíÓû§limingÖ´ÐÐ/usr/sbin/rebootÃüÁî¡£Õâ¸ö²ÎÊý¿ÉÒÔʹÓû§²é¿´×Ô¼ºÄ¿Ç°¿ÉÒÔÔÚsudoÖÐÖ´ÐÐÄÄЩÃüÁî¡£

6¡¢ÔÚÃüÁîÌáʾ·ûϼüÈësudoÃüÁî»áÁгöËùÓвÎÊý£¬ÆäËûһЩ²ÎÊýÈçÏ£º

´úÂë:

-V ÏÔʾ°æ±¾±àºÅ¡£

-h ÏÔʾsudoÃüÁîµÄʹÓòÎÊý¡£

-v ÒòΪsudoÔÚµÚÒ»´ÎÖ´ÐÐʱ»òÊÇÔÚN·ÖÖÓÄÚûÓÐÖ´ÐУ¨NÔ¤ÉèΪ5£©»áѯÎÊÃÜÂë¡£Õâ¸ö²ÎÊýÊÇÖØÐÂ×öÒ»´ÎÈ·ÈÏ£¬Èç¹û³¬¹ýN·ÖÖÓ£¬Ò²»áÎÊÃÜÂë¡£

-k ½«»áÇ¿ÆÈʹÓÃÕßÔÚÏÂÒ»´ÎÖ´ÐÐsudoʱѯÎÊÃÜÂ루²»ÂÛÓÐûÓг¬¹ýN·ÖÖÓ£©¡£

-b ½«ÒªÖ´ÐеÄÃüÁî·ÅÔÚ±³¾°Ö´ÐС£

-p prompt ¿ÉÒÔ¸ü¸ÄÎÊÃÜÂëµÄÌáʾÓÆäÖÐ%u»áÌæ»»ÎªÊ¹ÓÃÕßµÄÕ˺ÅÃû³Æ£¬%h»áÏÔʾÖ÷»úÃû³Æ¡£

-u username/#uid ²»¼Ó´Ë²ÎÊý£¬´ú±íÒªÒÔrootµÄÉí·ÝÖ´ÐÐÃüÁ¶ø¼ÓÁ˴˲ÎÊý£¬¿ÉÒÔÒÔusernameµÄÉí·ÝÖ´ÐÐÃüÁ#uidΪ¸ÃusernameµÄUID£©¡£

-s Ö´Ðл·¾³±äÁ¿ÖÐµÄ SHELL ËùÖ¸¶¨µÄ Shell £¬»òÊÇ /etc/passwd ÀïËùÖ¸¶¨µÄ Shell¡£

-H ½«»·¾³±äÁ¿ÖеÄHOME£¨ËÞÖ÷Ŀ¼£©Ö¸¶¨ÎªÒª±ä¸üÉí·ÝµÄʹÓÃÕßµÄËÞÖ÷Ŀ¼¡££¨Èç²»¼Ó-u²ÎÊý¾ÍÊÇϵͳ¹ÜÀíÕßroot¡££©

ÒªÒÔϵͳ¹ÜÀíÕßÉí·Ý£¨»òÒÔ-u¸ü¸ÄΪÆäËûÈË£©Ö´ÐеÄÃüÁî¡£
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ