LinuxЧÀÍÆ÷Çå¾²ÐÔµÄÇÏÃÅ£ºÐÑÄ¿ÕâЩ±Ø±¸ÏÂÁî
LinuxЧÀÍÆ÷Çå¾²ÐÔµÄÇÏÃÅ£ºÐÑÄ¿ÕâЩ±Ø±¸ÏÂÁî
ÕªÒª£º±£»¤LinuxЧÀÍÆ÷µÄÇå¾²ÐèÒªÒ»¸ö×ۺϵÄÒªÁ죬ÆäÖÐÊìÁ·Ê¹ÓÃһЩ±Ø±¸ÏÂÁîÊǺÜÊÇÖ÷ÒªµÄ¡£±¾ÎĽ«ÏÈÈݼ¸¸ö³£ÓõÄLinuxÏÂÁ²¢Ìṩ´úÂëʾÀý£¬×ÊÖúÖÎÀíÔ±ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£
·À»ðǽ (Firewall)
·À»ðǽÊDZ£»¤Ð§ÀÍÆ÷Çå¾²µÄµÚÒ»µÀ·ÀµØ¡£ÔÚLinuxÖУ¬Ê¹ÓÃiptablesÏÂÁîÀ´ÉèÖ÷À»ðǽ¹æÔò¡£ÏÂÃæÊÇһЩ³£ÓõÄiptablesÏÂÁîºÍÆäʾÀý£º
1.1 ÆôÓ÷À»ðǽ
sudo systemctl start iptables
µÇ¼ºó¸´ÖÆ
1.2 Ìí¼Ó¹æÔò
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPT sudo iptables -A INPUT -j DROP
µÇ¼ºó¸´ÖÆ
1.3 Éó²é·À»ðǽ¹æÔò
sudo iptables -L -n
µÇ¼ºó¸´ÖÆ
SSHµÇ¼ÖÎÀí
SSHÊÇÖÎÀíÔ±ÓëЧÀÍÆ÷Ö®¼ä¾ÙÐÐÔ¶³ÌµÇ¼µÄ³£Óù¤¾ß£¬Í¬Ê±Ò²ÊÇЧÀÍÆ÷Çå¾²ÐÔµÄÒ»¸öÒªº¦µã¡£ÒÔÏÂÊǼ¸¸ö±£»¤SSHÇå¾²µÄÒªÁ죺
2.1 ½ûÓÃrootÓû§Ô¶³ÌµÇ¼
sudo nano /etc/ssh/sshd_config PermitRootLogin no
µÇ¼ºó¸´ÖÆ
2.2 ʹÓÃÃÜÔ¿¶Ô¾ÙÐÐÉí·ÝÑéÖ¤
ssh-keygen -t rsa
µÇ¼ºó¸´ÖÆ
2.3 ¸ü¸ÄSSH¶Ë¿Ú
sudo nano /etc/ssh/sshd_config Port 2222
µÇ¼ºó¸´ÖÆ
ϸÁ£¶ÈµÄÎļþȨÏÞ¿ØÖÆ
׼ȷÉèÖÃÎļþȨÏÞ¿ÉÒÔ±ÜÃâδ¾ÊÚȨµÄ»á¼ûºÍÐ޸ġ£ÒÔÏÂÊǼ¸¸ö³£ÓõÄÏÂÁ
3.1 ¸ü¸ÄÎļþȨÏÞ
chmod 600 file.txt # Ö»ÓÐËùÓÐÕßÓµÓжÁдȨÏÞ chmod 644 file.txt # ËùÓÐÕßÓµÓжÁдȨÏÞ£¬ÆäËûÓû§Ö»¶ÁȨÏÞ chmod +x script.sh # Ìí¼Ó¿ÉÖ´ÐÐȨÏÞ
µÇ¼ºó¸´ÖÆ
3.2 ¸ü¸ÄÎļþËùÓÐÕß
sudo chown username:groupname file.txt
µÇ¼ºó¸´ÖÆ
Èí¼þ°ü¹ÜÀí
ʵʱ¸üÐÂÈí¼þ°üÊǼá³ÖЧÀÍÆ÷Çå¾²µÄÒªº¦¡£ÒÔÏÂÊÇʹÓÃaptÏÂÁîÀ´ÖÎÀíÈí¼þ°üµÄʾÀý£º
4.1 ¸üÐÂÈí¼þ°üÁбí
sudo apt update
µÇ¼ºó¸´ÖÆ
4.2 Éý¼¶ËùÓÐÒÑ×°ÖõÄÈí¼þ°ü
sudo apt upgrade
µÇ¼ºó¸´ÖÆ
4.3 ËÑË÷Ìض¨Èí¼þ°ü
apt search package_name
µÇ¼ºó¸´ÖÆ
ÈÕÖ¾ÖÎÀí
ÈÕÖ¾Îļþ¼Í¼ÁËϵͳµÄÖÖÖÖÔ˶¯£¬°üÀ¨Çå¾²Ïà¹ØµÄÐÅÏ¢¡£ÒÔÏÂÊÇһЩ³£ÓõÄÏÂÁ
5.1 Éó²éϵͳÈÕÖ¾
tail -f /var/log/syslog
µÇ¼ºó¸´ÖÆ
5.2 Éó²éµÇ¼ÈÕÖ¾
tail -f /var/log/auth.log
µÇ¼ºó¸´ÖÆ
5.3 Éó²é¹ýʧÈÕÖ¾
tail -f /var/log/nginx/error.log
µÇ¼ºó¸´ÖÆ
×ÛÉÏËùÊö£¬ÊìÁ·Ê¹ÓÃÕâЩ±Ø±¸ÏÂÁîÊDZ£»¤LinuxЧÀÍÆ÷Çå¾²µÄÒªº¦¡£ÖÎÀíÔ±Ó¦¸Ã°´ÆÚ¸üÐÂÈí¼þ°ü¡¢ÉèÖ÷À»ðǽ¹æÔò¡¢ÏÞÖÆSSH»á¼û£¬²¢×¼È·ÉèÖÃÎļþȨÏÞ¡£Í¬Ê±£¬°´ÆÚÉóºËϵͳºÍµÇ¼ÈÕÖ¾£¬ÒÔ¼°ÆäËûÇå¾²Ïà¹ØµÄ¼Í¼ҲÊǺÜÊÇÖ÷ÒªµÄ¡£Í¨¹ýÕÆÎÕÕâЩ֪ʶ£¬ÖÎÀíÔ±½«ÄܸüºÃµØ±£»¤Ð§ÀÍÆ÷µÄÇå¾²£¬²¢Ìá¸ßϵͳµÄÎȹÌÐÔºÍÐÔÄÜ¡£
ÒÔÉϾÍÊÇLinuxЧÀÍÆ÷Çå¾²ÐÔµÄÇÏÃÅ£ºÐÑÄ¿ÕâЩ±Ø±¸ÏÂÁîµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡