ÔÚLinuxϵͳÖУ¬¹ÜÀíÔ±ÍùÍù²»Ö¹Ò»ÈË£¬Èôÿλ¹ÜÀíÔ±¶¼ÓÃrootÉí·Ý½øÐйÜÀí¹¤×÷£¬¸ù±¾ÎÞ·¨ÅªÇå³þ˸Ã×öʲô¡£ËùÒÔ×îºÃµÄ·½Ê½ÊÇ£º¹ÜÀíÔ±´´½¨Ò»Ð©ÆÕͨÓû§£¬·ÖÅäÒ»²¿·Öϵͳ¹ÜÀí¹¤×÷¸øËûÃÇ¡£
ÎÒÃDz»¿ÉÒÔʹÓÃsuÈÃËûÃÇÖ±½Ó±ä³Éroot£¬ÒòΪÕâЩÓû§¶¼±ØÐëÖªµÀrootµÄÃÜÂ룬ÕâÖÖ·½·¨ºÜ²»°²È«£¬¶øÇÒÒ²²»·ûºÏÎÒÃǵķֹ¤ÐèÇó¡£Ò»°ãµÄ×ö·¨ÊÇÀûÓÃȨÏÞµÄÉèÖã¬ÒÀ¹¤×÷ÐÔÖÊ·ÖÀ࣬ÈÃÌØÊâÉí·ÝµÄÓû§³ÉΪͬһ¸ö¹¤×÷×飬²¢ÉèÖù¤×÷×éȨÏÞ¡£ÀýÈ磺ҪwwwadmÕâλÓû§¸ºÔð¹ÜÀíÍøÕ¾Êý¾Ý£¬Ò»°ãApache Web ServerµÄ½ø³ÌhttpdµÄËùÓÐÕßÊÇwww£¬Äú¿ÉÒÔÉèÖÃÓû§wwwadmÓëwwwΪͬһ¹¤×÷×飬²¢ÉèÖÃApacheĬÈÏ´æ·ÅÍøÒ³Ä¿Â¼ /usr/local/httpd/htdocsµÄ¹¤×÷×éȨÏÞΪ¿É¶Á¡¢¿Éд¡¢¿ÉÖ´ÐУ¬ÕâÑùÊôÓڴ˹¤×÷×éµÄÿλÓû§¾Í¿ÉÒÔ½øÐÐÍøÒ³µÄ¹ÜÀíÁË¡£
µ«Õâ²¢²»ÊÇ×îºÃµÄ½â¾ö°ì·¨£¬ÀýÈç¹ÜÀíÔ±ÏëÊÚÓèÒ»¸öÆÕͨÓû§¹Ø»úµÄȨÏÞ£¬ÕâʱʹÓÃÉÏÊöµÄ°ì·¨¾Í²»ÊǺÜÀíÏë¡£ÕâʱÄúÒ²Ðí»áÏ룬ÎÒÖ»ÈÃÕâ¸öÓû§¿ÉÒÔÒÔ rootÉí·ÝÖ´ÐÐshutdownÃüÁî¾ÍÐÐÁË¡£Íêȫû´í£¬¿ÉϧÔÚͨ³£µÄLinuxϵͳÖÐÎÞ·¨ÊµÏÖÕâÒ»¹¦ÄÜ£¬²»¹ýÒѾÓÐÁ˹¤¾ß¿ÉÒÔʵÏÖÕâÑùµÄ¹¦ÄÜ---- sudo¡£
sudoͨ¹ýά»¤Ò»¸öÌØÈ¨µ½Óû§ÃûÓ³ÉäµÄÊý¾Ý¿â½«ÌØÈ¨·ÖÅ䏸²»Í¬µÄÓû§£¬ÕâÐ©ÌØÈ¨¿ÉÓÉÊý¾Ý¿âÖÐËùÁеÄһЩ²»Í¬µÄÃüÁîÀ´Ê¶±ð¡£ÎªÁË»ñµÃÄ³Ò»ÌØÈ¨ÏÓÐ×ʸñµÄÓû§Ö»Ðè¼òµ¥µØÔÚÃüÁîÐÐÊäÈësudoÓëÃüÁîÃûÖ®ºó£¬°´ÕÕÌáʾÔÙ´ÎÊäÈë¿ÚÁÓû§×Ô¼ºµÄ¿ÚÁ²»ÊÇrootÓû§¿ÚÁ¡£ÀýÈ磬sudoÔÊÐíÆÕͨÓû§¸ñʽ»¯´ÅÅÌ£¬µ«ÊÇȴûÓи³ÓèÆäËûµÄrootÓû§ÌØÈ¨¡£
1¡¢sudo¹¤¾ßÓÉÎļþ/etc/sudoers½øÐÐÅäÖ㬸ÃÎļþ°üº¬ËùÓпÉÒÔ·ÃÎÊsudo¹¤¾ßµÄÓû§ÁÐ±í²¢¶¨ÒåÁËËûÃǵÄÌØÈ¨¡£Ò»¸öµäÐ͵Ä/etc/sudoersÌõÄ¿ÈçÏ£º
´úÂë:
liming ALL=(ALL) ALL
Õâ¸öÌõĿʹµÃÓû§liming×÷Ϊ³¬¼¶Óû§·ÃÎÊËùÓÐÓ¦ÓóÌÐò£¬ÈçÓû§limingÐèÒª×÷Ϊ³¬¼¶Óû§ÔËÐÐÃüÁËûÖ»Ðè¼òµ¥µØÔÚÃüÁîǰ¼ÓÉÏǰ׺sudo¡£Òò´Ë£¬ÒªÒÔrootÓû§µÄÉí·ÝÖ´ÐÐÃüÁîformat£¬liming¿ÉÒÔÊäÈëÈçÏÂÃüÁ
´úÂë:
# sudo /usr/sbin/useradd sam
×¢Ò⣺ÃüÁîҪд¾ø¶Ô·¾¶£¬/usr/sbinĬÈϲ»ÔÚÆÕͨÓû§µÄËÑË÷·¾¶ÖУ¬»òÕß¼ÓÈë´Ë·¾¶£ºPATH=$PATH:/usr/sbin;export PATH¡£ÁíÍ⣬²»Í¬ÏµÍ³ÃüÁîµÄ·¾¶²»¾¡Ïàͬ£¬¿ÉÒÔʹÓÃÃüÁî¡°whereis ÃüÁîÃû¡±À´²éÕÒÆä·¾¶¡£
Õâʱ»áÏÔʾÏÂÃæµÄÊä³ö½á¹û£º
´úÂë:
We trust you have received the usual lecture from the local System
Administrator. It usually boils down to these two things:
#1) Respect the privacy of others.
#2) Think before you type.
Password:
Èç¹ûlimingÕýÈ·µØÊäÈëÁË¿ÚÁÃüÁîuseradd½«»áÒÔrootÓû§Éí·ÝÖ´ÐС£
×¢Ò⣺ÅäÖÃÎļþ/etc/sudoers±ØÐëʹÓÃÃüÁî VisudoÀ´±à¼¡£
Ö»Òª°ÑÏàÓ¦µÄÓû§Ãû¡¢Ö÷»úÃûºÍÐí¿ÉµÄÃüÁîÁбíÒÔ±ê×¼µÄ¸ñʽ¼ÓÈëµ½Îļþ/etc/sudoers£¬²¢±£´æ¾Í¿ÉÒÔÉúЧ£¬ÔÙ¿´Ò»¸öÀý×Ó¡£
2¡¢Àý×Ó£º¹ÜÀíÔ±ÐèÒªÔÊÐígemÓû§ÔÚÖ÷»úsunÉÏÖ´ÐÐrebootºÍshutdownÃüÁÔÚ/etc/sudoersÖмÓÈ룺
´úÂë:
gem sun=/usr/sbin/reboot£¬/usr/sbin/shutdown
×¢Ò⣺ÃüÁîÒ»¶¨ÒªÊ¹Óþø¶Ô·¾¶£¬ÒÔ±ÜÃâÆäËûĿ¼µÄͬÃûÃüÁî±»Ö´ÐУ¬´Ó¶øÔì³É°²È«Òþ»¼¡£
È»ºó±£´æÍ˳ö£¬gemÓû§ÏëÖ´ÐÐrebootÃüÁîʱ£¬Ö»ÒªÔÚÌáʾ·ûÏÂÔËÐÐÏÂÁÐÃüÁ
´úÂë:
$ sudo /usr/sbin/reboot
ÊäÈëÕýÈ·µÄÃÜÂ룬¾Í¿ÉÒÔÖØÆô·þÎñÆ÷ÁË¡£
Èç¹ûÄúÏë¶ÔÒ»×éÓû§½øÐж¨Ò壬¿ÉÒÔÔÚ×éÃûǰ¼ÓÉÏ%£¬¶ÔÆä½øÐÐÉèÖã¬È磺
´úÂë:
%cuug ALL=(ALL) ALL
3¡¢ÁíÍ⣬»¹¿ÉÒÔÀûÓñðÃûÀ´¼ò»¯ÅäÖÃÎļþ¡£±ðÃûÀàËÆ×éµÄ¸ÅÄÓÐÓû§±ðÃû¡¢Ö÷»ú±ðÃûºÍÃüÁî±ðÃû¡£¶à¸öÓû§¿ÉÒÔÊ×ÏÈÓÃÒ»¸ö±ðÃûÀ´¶¨Ò壬ȻºóÔڹ涨ËûÃÇ¿ÉÒÔÖ´ÐÐʲôÃüÁîµÄʱºòʹÓñðÃû¾Í¿ÉÒÔÁË£¬Õâ¸öÅäÖöÔËùÓÐÓû§¶¼ÉúЧ¡£Ö÷»ú±ðÃûºÍÃüÁî±ðÃûÒ²ÊÇÈç´Ë¡£×¢ÒâʹÓÃǰÏÈÒªÔÚ/etc/sudoersÖж¨Ò壺 User_Alias, Host_Alias, Cmnd_AliasÏÔÚÆäºóÃæ¼ÓÈëÏàÓ¦µÄÃû³Æ£¬Ò²ÒÔ¶ººÅ·Ö¸ô¿ª¾Í¿ÉÒÔÁË£¬¾ÙÀýÈçÏ£º
´úÂë:
Host_Alias SERVER=no1
User_Alias ADMINS=liming£¬gem
Cmnd_Alias SHUTDOWN=/usr/sbin/halt£¬/usr/sbin/shutdown£¬/usr/sbin/reboot
ADMINS SERVER=SHUTDOWN
¡¢ÔÙ¿´Õâ¸öÀý×Ó£º
´úÂë:
ADMINS ALL=(ALL) NOPASSWD: ALL
±íʾÔÊÐíADMINS²»ÓÿÚÁîÖ´ÐÐÒ»ÇвÙ×÷£¬ÆäÖС°NOPASSWD:¡±ÏÒåÁËÓû§Ö´ÐвÙ×÷ʱ²»ÐèÒªÊäÈë¿ÚÁî¡£
5¡¢sudoÃüÁ¿ÉÒÔ¼ÓÉÏһЩ²ÎÊý£¬Íê³ÉһЩ¸¨ÖúµÄ¹¦ÄÜ£¬Èç
´úÂë:
$ sudo -l
»áÏÔʾ³öÀàËÆÕâÑùµÄÐÅÏ¢£º
´úÂë:
User liming may run the following commands on this host:
(root) /usr/sbin/reboot
˵Ã÷rootÔÊÐíÓû§limingÖ´ÐÐ/usr/sbin/rebootÃüÁî¡£Õâ¸ö²ÎÊý¿ÉÒÔʹÓû§²é¿´×Ô¼ºÄ¿Ç°¿ÉÒÔÔÚsudoÖÐÖ´ÐÐÄÄЩÃüÁî¡£
6¡¢ÔÚÃüÁîÌáʾ·ûϼüÈësudoÃüÁî»áÁгöËùÓвÎÊý£¬ÆäËûһЩ²ÎÊýÈçÏ£º
´úÂë:
-V ÏÔʾ°æ±¾±àºÅ¡£
-h ÏÔʾsudoÃüÁîµÄʹÓòÎÊý¡£
-v ÒòΪsudoÔÚµÚÒ»´ÎÖ´ÐÐʱ»òÊÇÔÚN·ÖÖÓÄÚûÓÐÖ´ÐУ¨NÔ¤ÉèΪ5£©»áѯÎÊÃÜÂë¡£Õâ¸ö²ÎÊýÊÇÖØÐÂ×öÒ»´ÎÈ·ÈÏ£¬Èç¹û³¬¹ýN·ÖÖÓ£¬Ò²»áÎÊÃÜÂë¡£
-k ½«»áÇ¿ÆÈʹÓÃÕßÔÚÏÂÒ»´ÎÖ´ÐÐsudoʱѯÎÊÃÜÂ루²»ÂÛÓÐûÓг¬¹ýN·ÖÖÓ£©¡£
-b ½«ÒªÖ´ÐеÄÃüÁî·ÅÔÚ±³¾°Ö´ÐС£
-p prompt ¿ÉÒÔ¸ü¸ÄÎÊÃÜÂëµÄÌáʾÓÆäÖÐ%u»áÌæ»»ÎªÊ¹ÓÃÕßµÄÕ˺ÅÃû³Æ£¬%h»áÏÔʾÖ÷»úÃû³Æ¡£
-u username/#uid ²»¼Ó´Ë²ÎÊý£¬´ú±íÒªÒÔrootµÄÉí·ÝÖ´ÐÐÃüÁ¶ø¼ÓÁ˴˲ÎÊý£¬¿ÉÒÔÒÔusernameµÄÉí·ÝÖ´ÐÐÃüÁ#uidΪ¸ÃusernameµÄUID£©¡£
-s Ö´Ðл·¾³±äÁ¿ÖÐµÄ SHELL ËùÖ¸¶¨µÄ Shell £¬»òÊÇ /etc/passwd ÀïËùÖ¸¶¨µÄ Shell¡£
-H ½«»·¾³±äÁ¿ÖеÄHOME£¨ËÞÖ÷Ŀ¼£©Ö¸¶¨ÎªÒª±ä¸üÉí·ÝµÄʹÓÃÕßµÄËÞÖ÷Ŀ¼¡££¨Èç²»¼Ó-u²ÎÊý¾ÍÊÇϵͳ¹ÜÀíÕßroot¡££©
ÒªÒÔϵͳ¹ÜÀíÕßÉí·Ý£¨»òÒÔ-u¸ü¸ÄΪÆäËûÈË£©Ö´ÐеÄÃüÁî¡£

