À´Ô´£ºd1net
OpenSSHÈí¼þ±»±¬³öÒ»¸ö¼òµ¥È´¸ßΣµÄ©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚ¶Ìʱ¼äÄÚ½øÐÐÊýǧ´ÎµÄµÇ¼³¢ÊÔ¡£
OpenSSHÊÇ×îÁ÷ÐеÄLinuxϵͳ½øÐÐÔ¶³Ì¿ØÖƵÄÈí¼þ¡£Ò»°ãÀ´Ëµ£¬Èí¼þÔÊÐí3µ½6´ÎµÄÃÜÂëµÇ½³¢ÊÔ£¬È»ºó¾Í»á¹Ø±ÕÁ¬½Ó¡£µ«ÊÇÕâ¸öб¬³öµÄ©¶´»áÔÊÐí¹¥»÷ÕßÖ´ÐдóÁ¿µÄµÇ¼³¢ÊÔ¡£
Ò»Î»ÍøÃûKingCopeµÄ°²È«Ñо¿ÈËÔ±ÔÚ²©¿ÍÖÐдµÀ£¬¶ÔÓÚʹÓüüÅ̽»»¥ÈÏ֤ģʽµÄOpenSSH·þÎñÆ÷£¬°üÀ¨FreeBSD Linux£¬ºÚ¿Í¶¼¿ÉÒÔʵʩ±©Á¦ÆÆ½â¡£
©¶´Ï¸½Ú
¾ÝÖª£¬´ó²¿·Öϵͳ¶¼Ä¬ÈÏ¿ªÆôÁ˼üÅ̽»»¥ÈÏ֤ģʽ£¬ËùÒÔºÚ¿Í¿ÉÒÔ´ó¹æÄ£µØÀûÓÃÕâ¸ö©¶´¡£Ñо¿ÈËÔ±¹«²¼ÁËPOC´úÂ룬ÈçÏÂËùʾ:
ssh -lusername -oKbdInteractiveDevices=`perl -e 'print "pam," x 10000'` targethost
Õâ¶Î¼òµ¥µÄÃüÁî¿ÉÒÔÔڵǼ´°¿Ú¿ª·ÅµÄ2·ÖÖÓÄÚ½øÐÐÒ»Íò´ÎµÄÃÜÂë²Â½â¡£
"ÖØÒªµÄÊÇ£¬Èç¹û¹¥»÷Õß¶ÔʹÓüüÅ̽»»¥ÈÏ֤ģʽµÄÉ豸·¢ÆðÁË1Íò´ÎµÄ½»»¥ÇëÇó£¬ÄÇôOpenSSH»áÖ´ÐÐÕâЩÇëÇó£¬È»ºóÏÝÈëÒ»¸ö½ÓÊÕ¿ÚÁîµÄÑ»·Ö®ÖУ¬Ö±µ½³¬¹ýÉ豸µÄÏÞÖÆ¡£"
¶ø»ùÓÚÍøÂçÁ¬½ÓºÍÊܺ¦LinuxÖ÷»úµÄÇé¿ö£¬2·ÖÖÓµÄʱ¼äºÍÕ⼸ǧ´ÎµÄÃÜÂë²Â½âÒѾ×ã¹»Èù¥»÷ÕßʹÓó£ÓÃÃÜÂë×Öµä³É¹¦ÆÆ½âÃÜÂëÁË¡£
Õâ¸ö©¶´´æÔÚÓÚ×îа汾µÄOpenSSHÖУ¬¼´6.9°æ¡£
ÈçºÎ·ÀÓù
ÔÚOpenSSH·¢²¼¹Ù·½²¹¶¡Ö®Ç°£¬½¨ÒéÍøÕ¾¹ÜÀíÔ±ÃDzÉÈ¡ÒÔÏ´ëÊ©:
1.ʹÓÃÖÁÉÙ2,048λµÄÃÜÔ¿¶ÔÓÃÓڵǽ
2.ʹÓÃÇ¿ÃÜÂë±£»¤ÄãµÄ˽Կ
3.½«µÇ¼´°¿Ú¿ª·ÅµÄ¿íÏÞÆÚ(grace period)¼õÉÙΪ20ÖÁ30Ãë
4.ʹÓÃFail2Ban»òPam-ShieldÏÞÖÆµÇ½³¢ÊÔ
jiangfengwk ÓÚ 2015-07-27 10:20:28·¢±í:
ºÜºÃ