{"id":49709,"date":"2025-07-30T19:11:28","date_gmt":"2025-07-30T11:11:28","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/49709.html"},"modified":"2025-07-30T19:11:28","modified_gmt":"2025-07-30T11:11:28","slug":"%e6%9c%8d%e5%8a%a1%e5%99%a8%e5%88%b0%e6%89%8b%ef%bc%8c%e5%a6%82%e4%bd%95%e5%ae%89%e5%85%a8%e5%8a%a0%e5%9b%ba%ef%bc%9f%e8%80%81%e8%bf%90%e7%bb%b4%e7%9a%84%e5%85%a8%e6%96%b9%e4%bd%8d%e5%ae%9e%e6%88%98","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/49709.html","title":{"rendered":"\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357"},"content":{"rendered":"<p>\u5728\u4e92\u8054\u7f51\u5b89\u5168\u4e8b\u6545\u9891\u53d1\u7684\u4eca\u5929&#xff0c;\u670d\u52a1\u5668\u5b89\u5168\u5df2\u7ecf\u6210\u4e3a\u6bcf\u4f4d\u8fd0\u7ef4\u5de5\u7a0b\u5e08\u5fc5\u987b\u9762\u5bf9\u7684\u5934\u7b49\u5927\u4e8b\u3002\u524d\u51e0\u5929\u521a\u63a5\u624b\u4e00\u6279\u65b0\u670d\u52a1\u5668&#xff0c;\u60f3\u5230\u5f88\u591a\u670b\u53cb\u7ecf\u5e38\u95ee\u6211&#xff1a;&#034;\u65b0\u670d\u52a1\u5668\u5e94\u8be5\u5982\u4f55\u8fdb\u884c\u5b89\u5168\u52a0\u56fa&#xff1f;&#034;\u4eca\u5929\u5c31\u501f\u8fd9\u4e2a\u673a\u4f1a&#xff0c;\u548c\u5927\u5bb6\u5206\u4eab\u4e00\u4e0b\u6211\u5341\u591a\u5e74\u8fd0\u7ef4\u751f\u6daf\u4e2d\u603b\u7ed3\u7684\u670d\u52a1\u5668\u5b89\u5168\u52a0\u56fa\u5b9e\u6218\u7ecf\u9a8c\u3002\u65e0\u8bba\u4f60\u662f\u521a\u5165\u884c\u7684\u65b0\u624b&#xff0c;\u8fd8\u662f\u6709\u7ecf\u9a8c\u7684\u8fd0\u7ef4\u4eba\u5458&#xff0c;\u8fd9\u7bc7\u6587\u7ae0\u90fd\u80fd\u5e2e\u4f60\u6784\u5efa\u4e00\u4e2a\u66f4\u52a0\u5b89\u5168\u7684\u670d\u52a1\u5668\u73af\u5883\u3002<\/p>\n<h3>\u4e00\u3001\u7cfb\u7edf\u57fa\u7840\u5b89\u5168<\/h3>\n<h4>1. \u7cfb\u7edf\u66f4\u65b0\u4e0e\u8865\u4e01\u7ba1\u7406<\/h4>\n<p>\u7cfb\u7edf\u6f0f\u6d1e\u662f\u9ed1\u5ba2\u5165\u4fb5\u7684\u9996\u9009\u76ee\u6807\u3002\u8bb0\u5f97\u53bb\u5e74\u67d0\u91d1\u878d\u5ba2\u6237\u56e0\u4e3a\u6ca1\u53ca\u65f6\u6253\u8865\u4e01&#xff0c;\u7ed3\u679c\u88ab\u52d2\u7d22\u8f6f\u4ef6\u653b\u51fb&#xff0c;\u635f\u5931\u60e8\u91cd\u3002\u6240\u4ee5&#xff0c;\u62ff\u5230\u65b0\u670d\u52a1\u5668\u7684\u7b2c\u4e00\u4ef6\u4e8b\u5c31\u662f\u66f4\u65b0\u7cfb\u7edf&#xff1a;<\/p>\n<p>CentOS\/RHEL\u7cfb\u7edf:<\/p>\n<p><span class=\"token comment\"># \u67e5\u770b\u53ef\u66f4\u65b0\u7684\u5305<\/span><br \/>\nyum check-update<\/p>\n<p><span class=\"token comment\"># \u66f4\u65b0\u6240\u6709\u5305<\/span><br \/>\nyum update -y<\/p>\n<p><span class=\"token comment\"># \u53ea\u66f4\u65b0\u5b89\u5168\u8865\u4e01<\/span><br \/>\nyum update &#8211;security<\/p>\n<p>Ubuntu\/Debian\u7cfb\u7edf:<\/p>\n<p><span class=\"token comment\"># \u66f4\u65b0\u8f6f\u4ef6\u5305\u5217\u8868<\/span><br \/>\n<span class=\"token function\">apt<\/span> update<\/p>\n<p><span class=\"token comment\"># \u5347\u7ea7\u6240\u6709\u5df2\u5b89\u88c5\u7684\u5305<\/span><br \/>\n<span class=\"token function\">apt<\/span> upgrade -y<\/p>\n<p><span class=\"token comment\"># \u667a\u80fd\u5347\u7ea7&#xff08;\u5904\u7406\u4f9d\u8d56\u5173\u7cfb&#xff09;<\/span><br \/>\n<span class=\"token function\">apt<\/span> dist-upgrade -y<\/p>\n<p>\u522b\u5fd8\u4e86\u8bbe\u7f6e\u81ea\u52a8\u66f4\u65b0&#xff0c;\u4f46\u8981\u6ce8\u610f\u751f\u4ea7\u73af\u5883\u4e2d\u5148\u5728\u6d4b\u8bd5\u73af\u5883\u9a8c\u8bc1\u8865\u4e01\u7684\u7a33\u5b9a\u6027\u3002<\/p>\n<h4>2. \u6700\u5c0f\u5316\u5b89\u88c5\u539f\u5219<\/h4>\n<p>\u4e0a\u4e2a\u6708\u5e2e\u4e00\u4e2a\u5ba2\u6237\u6392\u67e5\u5b89\u5168\u95ee\u9898\u65f6&#xff0c;\u53d1\u73b0\u4ed6\u4eec\u670d\u52a1\u5668\u4e0a\u88c5\u4e86\u4e00\u5806\u7528\u4e0d\u5230\u7684\u670d\u52a1&#xff0c;\u6bcf\u4e00\u4e2a\u90fd\u662f\u6f5c\u5728\u7684\u5b89\u5168\u98ce\u9669\u3002\u8bb0\u4f4f&#xff1a;\u4e0d\u9700\u8981\u7684\u670d\u52a1\u5c31\u662f\u98ce\u9669\u3002<\/p>\n<p><span class=\"token comment\"># \u5217\u51fa\u6240\u6709\u5df2\u5b89\u88c5\u7684\u5305<\/span><br \/>\n<span class=\"token function\">rpm<\/span> -qa    <span class=\"token comment\"># RHEL\/CentOS<\/span><br \/>\ndpkg -l    <span class=\"token comment\"># Debian\/Ubuntu<\/span><\/p>\n<p><span class=\"token comment\"># \u5220\u9664\u4e0d\u5fc5\u8981\u7684\u670d\u52a1<\/span><br \/>\nyum remove <span class=\"token operator\">&lt;<\/span>package_name<span class=\"token operator\">&gt;<\/span>    <span class=\"token comment\"># RHEL\/CentOS<\/span><br \/>\n<span class=\"token function\">apt<\/span> purge <span class=\"token operator\">&lt;<\/span>package_name<span class=\"token operator\">&gt;<\/span>     <span class=\"token comment\"># Debian\/Ubuntu<\/span><\/p>\n<p>\u5e38\u89c1\u53ef\u79fb\u9664\u7684\u670d\u52a1&#xff1a;<\/p>\n<ul>\n<li>telnet\u3001rsh\u3001rlogin&#xff08;\u4f7f\u7528SSH\u66ff\u4ee3&#xff09;<\/li>\n<li>\u4e0d\u5fc5\u8981\u7684\u6253\u5370\u670d\u52a1\u5982CUPS<\/li>\n<li>\u4e0d\u4f7f\u7528\u7684\u4ee3\u7406\u670d\u52a1\u3001\u90ae\u4ef6\u670d\u52a1\u7b49<\/li>\n<\/ul>\n<h4>3. \u7981\u7528\u4e0d\u5fc5\u8981\u7684\u542f\u52a8\u670d\u52a1<\/h4>\n<p><span class=\"token comment\"># \u5217\u51fa\u6240\u6709\u542f\u52a8\u7684\u670d\u52a1<\/span><br \/>\nsystemctl list-unit-files &#8211;state<span class=\"token operator\">&#061;<\/span>enabled<\/p>\n<p><span class=\"token comment\"># \u7981\u7528\u4e0d\u9700\u8981\u7684\u670d\u52a1<\/span><br \/>\nsystemctl disable <span class=\"token operator\">&lt;<\/span>service_name<span class=\"token operator\">&gt;<\/span><br \/>\nsystemctl mask <span class=\"token operator\">&lt;<\/span>service_name<span class=\"token operator\">&gt;<\/span>  <span class=\"token comment\"># \u5f7b\u5e95\u7981\u7528<\/span><\/p>\n<h3>\u4e8c\u3001\u7528\u6237\u8d26\u6237\u5b89\u5168<\/h3>\n<h4>1. \u52a0\u56faroot\u8d26\u6237<\/h4>\n<p>root\u8d26\u6237\u662f\u9ed1\u5ba2\u7684\u9996\u8981\u653b\u51fb\u76ee\u6807\u3002\u524d\u6bb5\u65f6\u95f4\u4e00\u4e2a\u670b\u53cb\u7684\u670d\u52a1\u5668\u88ab\u5165\u4fb5&#xff0c;\u5c31\u662f\u56e0\u4e3aroot\u5bc6\u7801\u592a\u7b80\u5355\u88ab\u66b4\u529b\u7834\u89e3\u3002<\/p>\n<p><span class=\"token comment\"># \u8bbe\u7f6e\u5f3a\u5bc6\u7801<\/span><br \/>\n<span class=\"token function\">passwd<\/span> root<\/p>\n<p><span class=\"token comment\"># \u7981\u6b62root\u8fdc\u7a0b\u767b\u5f55&#xff08;\u7f16\u8f91\/etc\/ssh\/sshd_config&#xff09;<\/span><br \/>\nPermitRootLogin no<\/p>\n<p><span class=\"token comment\"># \u91cd\u542fSSH\u670d\u52a1<\/span><br \/>\nsystemctl restart sshd<\/p>\n<h4>2. \u521b\u5efa\u7ba1\u7406\u5458\u8d26\u6237<\/h4>\n<p><span class=\"token comment\"># \u521b\u5efa\u7ba1\u7406\u5458\u7528\u6237<\/span><br \/>\n<span class=\"token function\">useradd<\/span> -m admin<br \/>\n<span class=\"token function\">passwd<\/span> admin<\/p>\n<p><span class=\"token comment\"># \u8d4b\u4e88sudo\u6743\u9650<\/span><br \/>\n<span class=\"token function\">usermod<\/span> -aG wheel admin    <span class=\"token comment\"># CentOS\/RHEL<\/span><br \/>\n<span class=\"token function\">usermod<\/span> -aG <span class=\"token function\">sudo<\/span> admin     <span class=\"token comment\"># Ubuntu\/Debian<\/span><\/p>\n<h4>3. \u5bc6\u7801\u7b56\u7565\u52a0\u56fa<\/h4>\n<p>\u5728\/etc\/login.defs\u548c\/etc\/security\/pwquality.conf\u4e2d\u8bbe\u7f6e\u5bc6\u7801\u590d\u6742\u5ea6\u8981\u6c42&#xff1a;<\/p>\n<p>PASS_MAX_DAYS   90    # \u5bc6\u7801\u6700\u957f\u6709\u6548\u671f<br \/>\nPASS_MIN_DAYS   7     # \u4e24\u6b21\u4fee\u6539\u5bc6\u7801\u7684\u6700\u5c0f\u95f4\u9694<br \/>\nPASS_MIN_LEN    12    # \u6700\u5c0f\u5bc6\u7801\u957f\u5ea6<br \/>\nPASS_WARN_AGE   7     # \u8fc7\u671f\u524d\u8b66\u544a\u5929\u6570<\/p>\n<p># \u5bc6\u7801\u590d\u6742\u5ea6<br \/>\nminlen &#061; 12<br \/>\nminclass &#061; 3<br \/>\nmaxrepeat &#061; 3<\/p>\n<p>\u522b\u5fd8\u4e86\u914d\u7f6ePAM\u6a21\u5757\u5f3a\u5236\u6267\u884c\u8fd9\u4e9b\u7b56\u7565&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u7f16\u8f91\/etc\/pam.d\/system-auth&#xff08;CentOS&#xff09;\u6216\/etc\/pam.d\/common-password&#xff08;Ubuntu&#xff09;<\/span><br \/>\npassword requisite pam_pwquality.so <span class=\"token assign-left variable\">retry<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">3<\/span><\/p>\n<h3>\u4e09\u3001SSH\u5b89\u5168\u52a0\u56fa<\/h3>\n<p>SSH\u662f\u8fd0\u7ef4\u4eba\u5458\u7684\u5fc5\u5907\u5de5\u5177&#xff0c;\u4f46\u4e5f\u662f\u9ed1\u5ba2\u91cd\u70b9\u653b\u51fb\u7684\u670d\u52a1\u4e4b\u4e00\u3002<\/p>\n<h4>1. \u4fee\u6539\u9ed8\u8ba4\u7aef\u53e3<\/h4>\n<p><span class=\"token comment\"># \u7f16\u8f91\/etc\/ssh\/sshd_config<\/span><br \/>\nPort <span class=\"token number\">2222<\/span>  <span class=\"token comment\"># \u4f7f\u7528\u975e\u6807\u51c6\u7aef\u53e3<\/span><\/p>\n<p><span class=\"token comment\"># \u5982\u679c\u4f7f\u7528SELinux&#xff0c;\u9700\u8981\u8bbe\u7f6e<\/span><br \/>\nsemanage port -a -t ssh_port_t -p tcp <span class=\"token number\">2222<\/span><\/p>\n<h4>2. \u5bc6\u94a5\u8ba4\u8bc1\u66ff\u4ee3\u5bc6\u7801<\/h4>\n<p><span class=\"token comment\"># \u5ba2\u6237\u7aef\u751f\u6210\u5bc6\u94a5\u5bf9<\/span><br \/>\nssh-keygen -t ed25519 -C <span class=\"token string\">&#034;admin&#064;example.com&#034;<\/span><\/p>\n<p><span class=\"token comment\"># \u4e0a\u4f20\u516c\u94a5\u5230\u670d\u52a1\u5668<\/span><br \/>\nssh-copy-id -i ~\/.ssh\/id_ed25519.pub admin&#064;server_ip<\/p>\n<p><span class=\"token comment\"># \u7981\u7528\u5bc6\u7801\u8ba4\u8bc1&#xff08;\u7f16\u8f91\/etc\/ssh\/sshd_config&#xff09;<\/span><br \/>\nPasswordAuthentication no<br \/>\nChallengeResponseAuthentication no<\/p>\n<h4>3. \u5176\u4ed6SSH\u52a0\u56fa\u63aa\u65bd<\/h4>\n<p>\u7f16\u8f91\/etc\/ssh\/sshd_config&#xff1a;<\/p>\n<p>Protocol 2                      # \u53ea\u4f7f\u7528SSH v2\u534f\u8bae<br \/>\nMaxAuthTries 3                  # \u6700\u5927\u8ba4\u8bc1\u5c1d\u8bd5\u6b21\u6570<br \/>\nMaxSessions 5                   # \u6700\u5927\u4f1a\u8bdd\u6570<br \/>\nLoginGraceTime 60              # \u767b\u5f55\u8d85\u65f6\u65f6\u95f4<br \/>\nClientAliveInterval 300        # \u5ba2\u6237\u7aef\u6d3b\u8dc3\u68c0\u6d4b\u95f4\u9694<br \/>\nClientAliveCountMax 2          # \u5ba2\u6237\u7aef\u6d3b\u8dc3\u68c0\u6d4b\u6b21\u6570<br \/>\nAllowUsers admin               # \u53ea\u5141\u8bb8\u7279\u5b9a\u7528\u6237\u767b\u5f55<\/p>\n<p>\u91cd\u542fSSH\u670d\u52a1\u751f\u6548&#xff1a;<\/p>\n<p>systemctl restart sshd<\/p>\n<h3>\u56db\u3001\u9632\u706b\u5899\u914d\u7f6e<\/h3>\n<h4>1. \u914d\u7f6eiptables\/firewalld<\/h4>\n<p><span class=\"token comment\"># \u4f7f\u7528firewalld&#xff08;CentOS 7&#043;\/RHEL 7&#043;&#xff09;<\/span><br \/>\nsystemctl <span class=\"token builtin class-name\">enable<\/span> firewalld<br \/>\nsystemctl start firewalld<\/p>\n<p><span class=\"token comment\"># \u53ea\u5f00\u653e\u5fc5\u8981\u7aef\u53e3<\/span><br \/>\nfirewall-cmd &#8211;permanent &#8211;add-port<span class=\"token operator\">&#061;<\/span><span class=\"token number\">2222<\/span>\/tcp  <span class=\"token comment\"># SSH<\/span><br \/>\nfirewall-cmd &#8211;permanent &#8211;add-port<span class=\"token operator\">&#061;<\/span><span class=\"token number\">80<\/span>\/tcp    <span class=\"token comment\"># HTTP<\/span><br \/>\nfirewall-cmd &#8211;permanent &#8211;add-port<span class=\"token operator\">&#061;<\/span><span class=\"token number\">443<\/span>\/tcp   <span class=\"token comment\"># HTTPS<\/span><br \/>\nfirewall-cmd &#8211;reload<\/p>\n<p>\u6216\u8005\u4f7f\u7528\u4f20\u7edfiptables&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u57fa\u672ciptables\u89c4\u5219<\/span><br \/>\niptables -F<br \/>\niptables -P INPUT DROP<br \/>\niptables -P FORWARD DROP<br \/>\niptables -P OUTPUT ACCEPT<br \/>\niptables -A INPUT -i lo -j ACCEPT<br \/>\niptables -A INPUT -m state &#8211;state ESTABLISHED,RELATED -j ACCEPT<br \/>\niptables -A INPUT -p tcp &#8211;dport <span class=\"token number\">2222<\/span> -j ACCEPT<br \/>\niptables -A INPUT -p tcp &#8211;dport <span class=\"token number\">80<\/span> -j ACCEPT<br \/>\niptables -A INPUT -p tcp &#8211;dport <span class=\"token number\">443<\/span> -j ACCEPT<\/p>\n<p><span class=\"token comment\"># \u4fdd\u5b58\u89c4\u5219<\/span><br \/>\n<span class=\"token function\">service<\/span> iptables save<\/p>\n<h4>2. \u9632DDoS\u914d\u7f6e<\/h4>\n<p><span class=\"token comment\"># \u9650\u5236SYN\u6d2a\u6c34<\/span><br \/>\niptables -A INPUT -p tcp &#8211;syn -m limit &#8211;limit <span class=\"token number\">1<\/span>\/s &#8211;limit-burst <span class=\"token number\">3<\/span> -j ACCEPT<br \/>\niptables -A INPUT -p tcp &#8211;syn -j DROP<\/p>\n<p><span class=\"token comment\"># \u9650\u5236ICMP\u8bf7\u6c42<\/span><br \/>\niptables -A INPUT -p icmp &#8211;icmp-type echo-request -m limit &#8211;limit <span class=\"token number\">1<\/span>\/s &#8211;limit-burst <span class=\"token number\">4<\/span> -j ACCEPT<br \/>\niptables -A INPUT -p icmp &#8211;icmp-type echo-request -j DROP<\/p>\n<h3>\u4e94\u3001\u6587\u4ef6\u7cfb\u7edf\u5b89\u5168<\/h3>\n<h4>1. \u5206\u533a\u4e0e\u6302\u8f7d\u9009\u9879<\/h4>\n<p>\u5408\u7406\u7684\u5206\u533a\u7b56\u7565\u53ef\u4ee5\u6709\u6548\u9632\u6b62\u67d0\u4e9b\u653b\u51fb\u3002\u53bb\u5e74\u4e00\u4e2a\u5ba2\u6237\u56e0\u4e3a\/tmp\u76ee\u5f55\u548c\u6839\u76ee\u5f55\u5728\u540c\u4e00\u5206\u533a&#xff0c;\u88ab\u9ed1\u5ba2\u5229\u7528\u586b\u6ee1\u78c1\u76d8\u5bfc\u81f4\u7cfb\u7edf\u5d29\u6e83\u3002\u5728\/etc\/fstab\u4e2d\u6dfb\u52a0\u5b89\u5168\u6302\u8f7d\u9009\u9879&#xff1a;<\/p>\n<p>\/dev\/sda1  \/boot  ext4  defaults,nosuid,nodev,noexec  1 2<br \/>\n\/dev\/sda2  \/tmp   ext4  defaults,nosuid,nodev,noexec  1 2<br \/>\n\/dev\/sda3  \/var   ext4  defaults,nosuid  1 2<br \/>\n\/home      \/home  ext4  defaults,nosuid,nodev  1 2<\/p>\n<p>\u8fd9\u4e9b\u9009\u9879\u7684\u4f5c\u7528&#xff1a;<\/p>\n<ul>\n<li>nosuid: \u7981\u6b62SUID\/SGID\u4f4d\u751f\u6548<\/li>\n<li>nodev: \u7981\u6b62\u89e3\u91ca\u8bbe\u5907\u6587\u4ef6<\/li>\n<li>noexec: \u7981\u6b62\u6267\u884c\u4e8c\u8fdb\u5236\u6587\u4ef6<\/li>\n<\/ul>\n<h4>2. \u6587\u4ef6\u6743\u9650\u5ba1\u8ba1\u4e0e\u4fee\u590d<\/h4>\n<p><span class=\"token comment\"># \u8bbe\u7f6e\u5173\u952e\u6587\u4ef6\u7684\u6b63\u786e\u6743\u9650<\/span><br \/>\n<span class=\"token function\">chmod<\/span> <span class=\"token number\">644<\/span> \/etc\/passwd<br \/>\n<span class=\"token function\">chmod<\/span> 000 \/etc\/shadow<br \/>\n<span class=\"token function\">chmod<\/span> <span class=\"token number\">644<\/span> \/etc\/group<br \/>\n<span class=\"token function\">chmod<\/span> <span class=\"token number\">600<\/span> \/etc\/gshadow<\/p>\n<p><span class=\"token comment\"># \u67e5\u627e\u5e76\u4fee\u590d\u5371\u9669\u7684SUID\/SGID\u6587\u4ef6<\/span><br \/>\n<span class=\"token function\">find<\/span> \/ -type f <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">(<\/span> -perm -4000 -o -perm -2000 <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">)<\/span> -exec <span class=\"token function\">ls<\/span> -l <span class=\"token punctuation\">{<\/span><span class=\"token punctuation\">}<\/span> <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p><span class=\"token comment\"># \u67e5\u627e\u4e16\u754c\u53ef\u5199\u6587\u4ef6<\/span><br \/>\n<span class=\"token function\">find<\/span> \/ -type f -perm -o&#043;w -not -path <span class=\"token string\">&#034;\/proc\/*&#034;<\/span> -not -path <span class=\"token string\">&#034;\/sys\/*&#034;<\/span> -exec <span class=\"token function\">ls<\/span> -l <span class=\"token punctuation\">{<\/span><span class=\"token punctuation\">}<\/span> <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<h4>3. \u6587\u4ef6\u5b8c\u6574\u6027\u68c0\u67e5<\/h4>\n<p>\u5b89\u88c5AIDE&#xff08;Advanced Intrusion Detection Environment&#xff09;\u8fdb\u884c\u6587\u4ef6\u5b8c\u6574\u6027\u76d1\u63a7&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u5b89\u88c5AIDE<\/span><br \/>\nyum <span class=\"token function\">install<\/span> aide    <span class=\"token comment\"># CentOS\/RHEL<\/span><br \/>\n<span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> aide    <span class=\"token comment\"># Ubuntu\/Debian<\/span><\/p>\n<p><span class=\"token comment\"># \u521d\u59cb\u5316\u6570\u636e\u5e93<\/span><br \/>\naide &#8211;init<br \/>\n<span class=\"token function\">mv<\/span> \/var\/lib\/aide\/aide.db.new.gz \/var\/lib\/aide\/aide.db.gz<\/p>\n<p><span class=\"token comment\"># \u8bbe\u7f6e\u5b9a\u671f\u68c0\u67e5<\/span><br \/>\n<span class=\"token builtin class-name\">echo<\/span> <span class=\"token string\">&#034;0 4 * * * root \/usr\/sbin\/aide &#8211;check | mail -s &#039;AIDE\u68c0\u67e5\u62a5\u544a&#039; admin&#064;example.com&#034;<\/span> <span class=\"token operator\">&gt;<\/span> \/etc\/cron.d\/aide<\/p>\n<h3>\u516d\u3001\u7cfb\u7edf\u5ba1\u8ba1\u4e0e\u65e5\u5fd7<\/h3>\n<h4>1. \u914d\u7f6e\u96c6\u4e2d\u65e5\u5fd7<\/h4>\n<p>\u6700\u8fd1\u4e00\u4e2a\u5ba2\u6237\u56e0\u4e3a\u6ca1\u6709\u4fdd\u5b58\u8db3\u591f\u7684\u65e5\u5fd7&#xff0c;\u9ed1\u5ba2\u5165\u4fb5\u540e\u65e0\u6cd5\u8ffd\u6eaf\u653b\u51fb\u8def\u5f84\u3002\u914d\u7f6ersyslog\u5c06\u65e5\u5fd7\u53d1\u9001\u5230\u96c6\u4e2d\u670d\u52a1\u5668&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u7f16\u8f91\/etc\/rsyslog.conf<\/span><br \/>\n*.* &#064;logserver.example.com:514  <span class=\"token comment\"># UDP<\/span><br \/>\n*.* &#064;&#064;logserver.example.com:514 <span class=\"token comment\"># TCP&#043;TLS<\/span><\/p>\n<p><span class=\"token comment\"># \u91cd\u542f\u670d\u52a1<\/span><br \/>\nsystemctl restart rsyslog<\/p>\n<h4>2. \u914d\u7f6eAuditd\u5ba1\u8ba1\u7cfb\u7edf<\/h4>\n<p><span class=\"token comment\"># \u5b89\u88c5auditd<\/span><br \/>\nyum <span class=\"token function\">install<\/span> audit    <span class=\"token comment\"># CentOS\/RHEL<\/span><br \/>\n<span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> auditd   <span class=\"token comment\"># Ubuntu\/Debian<\/span><\/p>\n<p><span class=\"token comment\"># \u542f\u7528\u5e76\u914d\u7f6e<\/span><br \/>\nsystemctl <span class=\"token builtin class-name\">enable<\/span> auditd<br \/>\nsystemctl start auditd<\/p>\n<p><span class=\"token comment\"># \u7f16\u8f91\/etc\/audit\/auditd.conf<\/span><br \/>\nmax_log_file <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">50<\/span><br \/>\nmax_log_file_action <span class=\"token operator\">&#061;<\/span> rotate<br \/>\nnum_logs <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">10<\/span><br \/>\nspace_left_action <span class=\"token operator\">&#061;<\/span> email<br \/>\naction_mail_acct <span class=\"token operator\">&#061;<\/span> root<br \/>\nadmin_space_left_action <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">halt<\/span><\/p>\n<p>\u6dfb\u52a0\u5173\u952e\u5ba1\u8ba1\u89c4\u5219&#xff08;\/etc\/audit\/rules.d\/audit.rules&#xff09;&#xff1a;<\/p>\n<p># \u76d1\u63a7\/etc\u76ee\u5f55\u53d8\u66f4<br \/>\n-w \/etc\/ -p wa -k etc_changes<\/p>\n<p># \u76d1\u63a7\u7528\u6237\/\u7ec4\u53d8\u66f4<br \/>\n-w \/etc\/passwd -p wa -k user_modification<br \/>\n-w \/etc\/shadow -p wa -k user_modification<br \/>\n-w \/etc\/group -p wa -k user_modification<br \/>\n-w \/etc\/gshadow -p wa -k user_modification<\/p>\n<p># \u76d1\u63a7sudo\u4f7f\u7528<br \/>\n-w \/usr\/bin\/sudo -p x -k sudo_usage<\/p>\n<p># \u76d1\u63a7\u5931\u8d25\u7684\u8bbf\u95ee\u5c1d\u8bd5<br \/>\n-a always,exit -F arch&#061;b64 -S open -F exit&#061;-EACCES -k file_access<br \/>\n-a always,exit -F arch&#061;b64 -S open -F exit&#061;-EPERM -k file_access<\/p>\n<h4>3. \u65e5\u5fd7\u8f6e\u8f6c\u4e0e\u4fdd\u7559<\/h4>\n<p>\u914d\u7f6elogrotate\u786e\u4fdd\u65e5\u5fd7\u4e0d\u4f1a\u5360\u6ee1\u78c1\u76d8&#xff1a;<\/p>\n<p># \u7f16\u8f91\/etc\/logrotate.conf<br \/>\nrotate 90         # \u4fdd\u755990\u5929<br \/>\ndaily             # \u6bcf\u5929\u8f6e\u8f6c<br \/>\ncompress          # \u538b\u7f29\u65e7\u65e5\u5fd7<br \/>\ndateext           # \u4f7f\u7528\u65e5\u671f\u6269\u5c55\u540d<\/p>\n<h3>\u4e03\u3001\u5165\u4fb5\u68c0\u6d4b\u4e0e\u9632\u5fa1<\/h3>\n<h4>1. \u5b89\u88c5\u914d\u7f6eFail2ban<\/h4>\n<p>Fail2ban\u53ef\u4ee5\u81ea\u52a8\u5c01\u7981\u5c1d\u8bd5\u66b4\u529b\u7834\u89e3\u7684IP&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u5b89\u88c5Fail2ban<\/span><br \/>\nyum <span class=\"token function\">install<\/span> epel-release <span class=\"token operator\">&amp;&amp;<\/span> yum <span class=\"token function\">install<\/span> fail2ban    <span class=\"token comment\"># CentOS\/RHEL<\/span><br \/>\n<span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> fail2ban                                <span class=\"token comment\"># Ubuntu\/Debian<\/span><\/p>\n<p><span class=\"token comment\"># \u914d\u7f6eSSH\u9632\u62a4<\/span><br \/>\n<span class=\"token function\">cat<\/span> <span class=\"token operator\">&gt;<\/span> \/etc\/fail2ban\/jail.local <span class=\"token operator\">&lt;&lt;<\/span> <span class=\"token string\">EOF<br \/>\n[sshd]<br \/>\nenabled &#061; true<br \/>\nport &#061; 2222<br \/>\nfilter &#061; sshd<br \/>\nlogpath &#061; \/var\/log\/auth.log<br \/>\nmaxretry &#061; 3<br \/>\nbantime &#061; 3600<br \/>\nfindtime &#061; 600<br \/>\nEOF<\/span><\/p>\n<p><span class=\"token comment\"># \u542f\u52a8\u670d\u52a1<\/span><br \/>\nsystemctl <span class=\"token builtin class-name\">enable<\/span> fail2ban<br \/>\nsystemctl start fail2ban<\/p>\n<h4>2. \u5b89\u88c5\u914d\u7f6erootkit\u68c0\u6d4b\u5de5\u5177<\/h4>\n<p><span class=\"token comment\"># \u5b89\u88c5rkhunter<\/span><br \/>\nyum <span class=\"token function\">install<\/span> rkhunter    <span class=\"token comment\"># CentOS\/RHEL<\/span><br \/>\n<span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> rkhunter    <span class=\"token comment\"># Ubuntu\/Debian<\/span><\/p>\n<p><span class=\"token comment\"># \u66f4\u65b0\u6570\u636e\u5e93<\/span><br \/>\nrkhunter &#8211;update<br \/>\nrkhunter &#8211;propupd<\/p>\n<p><span class=\"token comment\"># \u8bbe\u7f6e\u5b9a\u671f\u626b\u63cf<\/span><br \/>\n<span class=\"token builtin class-name\">echo<\/span> <span class=\"token string\">&#034;0 3 * * * root \/usr\/bin\/rkhunter &#8211;check &#8211;skip-keypress &#8211;report-warnings-only&#034;<\/span> <span class=\"token operator\">&gt;<\/span> \/etc\/cron.d\/rkhunter<\/p>\n<h4>3. \u914d\u7f6e\u6587\u4ef6\u76d1\u63a7<\/h4>\n<p>\u4f7f\u7528osquery\u8fdb\u884c\u9ad8\u7ea7\u76d1\u63a7&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u5b89\u88c5osquery<\/span><br \/>\n<span class=\"token comment\"># \u4ece\u5b98\u7f51\u4e0b\u8f7d\u5e76\u5b89\u88c5\u5bf9\u5e94\u7cfb\u7edf\u7684\u5305<\/span><\/p>\n<p><span class=\"token comment\"># \u914d\u7f6e\u6587\u4ef6\u76d1\u63a7<\/span><br \/>\n<span class=\"token function\">cat<\/span> <span class=\"token operator\">&gt;<\/span> \/etc\/osquery\/osquery.conf <span class=\"token operator\">&lt;&lt;<\/span> <span class=\"token string\">EOF<br \/>\n{<br \/>\n  &#034;schedule&#034;: {<br \/>\n    &#034;file_events&#034;: {<br \/>\n      &#034;query&#034;: &#034;SELECT * FROM file_events;&#034;,<br \/>\n      &#034;interval&#034;: 60<br \/>\n    },<br \/>\n    &#034;process_events&#034;: {<br \/>\n      &#034;query&#034;: &#034;SELECT * FROM process_events;&#034;,<br \/>\n      &#034;interval&#034;: 60<br \/>\n    }<br \/>\n  },<br \/>\n  &#034;file_paths&#034;: {<br \/>\n    &#034;etc&#034;: [&#034;\/etc\/%%&#034;],<br \/>\n    &#034;bin&#034;: [&#034;\/bin\/%%&#034;, &#034;\/sbin\/%%&#034;, &#034;\/usr\/bin\/%%&#034;, &#034;\/usr\/sbin\/%%&#034;]<br \/>\n  }<br \/>\n}<br \/>\nEOF<\/span><\/p>\n<p><span class=\"token comment\"># \u542f\u52a8\u670d\u52a1<\/span><br \/>\nsystemctl <span class=\"token builtin class-name\">enable<\/span> osqueryd<br \/>\nsystemctl start osqueryd<\/p>\n<h3>\u516b\u3001\u7f51\u7edc\u5b89\u5168\u52a0\u56fa<\/h3>\n<h4>1. \u5185\u6838\u53c2\u6570\u4f18\u5316<\/h4>\n<p>\u7f16\u8f91\/etc\/sysctl.conf&#xff1a;<\/p>\n<p># \u9632\u6b62IP\u6b3a\u9a97<br \/>\nnet.ipv4.conf.all.rp_filter &#061; 1<br \/>\nnet.ipv4.conf.default.rp_filter &#061; 1<\/p>\n<p># \u7981\u6b62IP\u6e90\u8def\u7531<br \/>\nnet.ipv4.conf.all.accept_source_route &#061; 0<br \/>\nnet.ipv4.conf.default.accept_source_route &#061; 0<\/p>\n<p># \u9632\u6b62SYN\u6d2a\u6c34\u653b\u51fb<br \/>\nnet.ipv4.tcp_syncookies &#061; 1<br \/>\nnet.ipv4.tcp_max_syn_backlog &#061; 2048<br \/>\nnet.ipv4.tcp_synack_retries &#061; 2<br \/>\nnet.ipv4.tcp_syn_retries &#061; 5<\/p>\n<p># \u7981\u7528ICMP\u91cd\u5b9a\u5411<br \/>\nnet.ipv4.conf.all.accept_redirects &#061; 0<br \/>\nnet.ipv4.conf.default.accept_redirects &#061; 0<br \/>\nnet.ipv4.conf.all.secure_redirects &#061; 0<br \/>\nnet.ipv4.conf.default.secure_redirects &#061; 0<br \/>\nnet.ipv4.conf.all.send_redirects &#061; 0<br \/>\nnet.ipv4.conf.default.send_redirects &#061; 0<\/p>\n<p># \u542f\u7528\u53cd\u5411\u8def\u5f84\u8fc7\u6ee4<br \/>\nnet.ipv4.conf.all.rp_filter &#061; 1<br \/>\nnet.ipv4.conf.default.rp_filter &#061; 1<\/p>\n<p># \u8bb0\u5f55\u53ef\u7591\u5305<br \/>\nnet.ipv4.conf.all.log_martians &#061; 1<br \/>\nnet.ipv4.conf.default.log_martians &#061; 1<\/p>\n<p>\u5e94\u7528\u914d\u7f6e&#xff1a;<\/p>\n<p>sysctl -p<\/p>\n<h4>2. \u7f51\u7edc\u670d\u52a1\u52a0\u56fa<\/h4>\n<p>\u5bf9\u4e8eWeb\u670d\u52a1\u5668&#xff0c;\u914d\u7f6eTLS\/SSL&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u751f\u6210\u5f3a\u5bc6\u94a5\u548cCSR<\/span><br \/>\nopenssl req -new -newkey rsa:4096 -nodes -keyout server.key -out server.csr<\/p>\n<p><span class=\"token comment\"># \u5728Nginx\u4e2d\u914d\u7f6e\u5b89\u5168\u53c2\u6570<\/span><br \/>\nserver <span class=\"token punctuation\">{<\/span><br \/>\n    listen <span class=\"token number\">443<\/span> ssl http2<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_certificate \/etc\/ssl\/certs\/server.crt<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_certificate_key \/etc\/ssl\/private\/server.key<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_protocols TLSv1.2 TLSv1.3<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_prefer_server_ciphers on<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_ciphers <span class=\"token string\">&#039;ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305&#039;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    ssl_session_timeout 1d<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_session_cache shared:SSL:50m<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_session_tickets off<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_stapling on<span class=\"token punctuation\">;<\/span><br \/>\n    ssl_stapling_verify on<span class=\"token punctuation\">;<\/span><br \/>\n    add_header Strict-Transport-Security <span class=\"token string\">&#034;max-age&#061;63072000&#034;<\/span> always<span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<h4>3. \u914d\u7f6e\u7f51\u7edc\u8bbf\u95ee\u63a7\u5236<\/h4>\n<p>\u4f7f\u7528TCP Wrappers\u9650\u5236\u670d\u52a1\u8bbf\u95ee&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u7f16\u8f91\/etc\/hosts.allow<\/span><br \/>\nsshd: <span class=\"token number\">192.168<\/span>.1.0\/24 <span class=\"token number\">10.0<\/span>.0.0\/8<\/p>\n<p><span class=\"token comment\"># \u7f16\u8f91\/etc\/hosts.deny<\/span><br \/>\nALL: ALL<\/p>\n<h3>\u4e5d\u3001\u5b9a\u671f\u5b89\u5168\u68c0\u67e5<\/h3>\n<h4>1. \u521b\u5efa\u5b89\u5168\u57fa\u7ebf\u68c0\u67e5\u811a\u672c<\/h4>\n<p><span class=\"token shebang important\">#!\/bin\/bash<\/span><br \/>\n<span class=\"token comment\"># security_check.sh &#8211; \u5b9a\u671f\u5b89\u5168\u68c0\u67e5\u811a\u672c<\/span><\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> <span class=\"token string\">&#034;&#061;&#061;&#061; \u7cfb\u7edf\u4fe1\u606f &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">hostname<\/span><br \/>\n<span class=\"token function\">date<\/span><br \/>\n<span class=\"token function\">uname<\/span> -a<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u7528\u6237\u767b\u5f55\u68c0\u67e5 &#061;&#061;&#061;&#034;<\/span><br \/>\nlast <span class=\"token operator\">|<\/span> <span class=\"token function\">head<\/span> -20<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u5f53\u524d\u767b\u5f55\u7528\u6237 &#061;&#061;&#061;&#034;<\/span><br \/>\nw<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u5931\u8d25\u7684\u767b\u5f55\u5c1d\u8bd5 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">grep<\/span> <span class=\"token string\">&#034;Failed password&#034;<\/span> \/var\/log\/auth.log <span class=\"token operator\">|<\/span> <span class=\"token function\">tail<\/span> -20<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u7279\u6743\u7528\u6237\u5217\u8868 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">grep<\/span> -v -E <span class=\"token string\">&#034;^#|^$&#034;<\/span> \/etc\/sudoers<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; SUID\/SGID\u6587\u4ef6\u68c0\u67e5 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">find<\/span> \/ -type f <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">(<\/span> -perm -4000 -o -perm -2000 <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">)<\/span> -exec <span class=\"token function\">ls<\/span> -l <span class=\"token punctuation\">{<\/span><span class=\"token punctuation\">}<\/span> <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token operator\"><span class=\"token file-descriptor important\">2<\/span>&gt;<\/span>\/dev\/null<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u5f00\u653e\u7aef\u53e3\u68c0\u67e5 &#061;&#061;&#061;&#034;<\/span><br \/>\nss -tuln<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u7cfb\u7edf\u670d\u52a1\u68c0\u67e5 &#061;&#061;&#061;&#034;<\/span><br \/>\nsystemctl list-units &#8211;type<span class=\"token operator\">&#061;<\/span>service &#8211;state<span class=\"token operator\">&#061;<\/span>running<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u9632\u706b\u5899\u89c4\u5219\u68c0\u67e5 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token keyword\">if<\/span> <span class=\"token builtin class-name\">command<\/span> -v firewall-cmd <span class=\"token operator\">&amp;&gt;<\/span> \/dev\/null<span class=\"token punctuation\">;<\/span> <span class=\"token keyword\">then<\/span><br \/>\n    firewall-cmd &#8211;list-all<br \/>\n<span class=\"token keyword\">elif<\/span> <span class=\"token builtin class-name\">command<\/span> -v iptables <span class=\"token operator\">&amp;&gt;<\/span> \/dev\/null<span class=\"token punctuation\">;<\/span> <span class=\"token keyword\">then<\/span><br \/>\n    iptables -L -n<br \/>\n<span class=\"token keyword\">fi<\/span><\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u7cfb\u7edf\u66f4\u65b0\u72b6\u6001 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token keyword\">if<\/span> <span class=\"token builtin class-name\">command<\/span> -v yum <span class=\"token operator\">&amp;&gt;<\/span> \/dev\/null<span class=\"token punctuation\">;<\/span> <span class=\"token keyword\">then<\/span><br \/>\n    yum check-update &#8211;security <span class=\"token operator\">|<\/span> <span class=\"token function\">head<\/span> -20<br \/>\n<span class=\"token keyword\">elif<\/span> <span class=\"token builtin class-name\">command<\/span> -v <span class=\"token function\">apt<\/span> <span class=\"token operator\">&amp;&gt;<\/span> \/dev\/null<span class=\"token punctuation\">;<\/span> <span class=\"token keyword\">then<\/span><br \/>\n    <span class=\"token function\">apt<\/span> list &#8211;upgradable <span class=\"token operator\">|<\/span> <span class=\"token function\">head<\/span> -20<br \/>\n<span class=\"token keyword\">fi<\/span><\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u78c1\u76d8\u7a7a\u95f4\u4f7f\u7528\u60c5\u51b5 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">df<\/span> -h<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u5927\u6587\u4ef6\u68c0\u67e5 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">find<\/span> \/ -type f -size &#043;100M -exec <span class=\"token function\">ls<\/span> -lh <span class=\"token punctuation\">{<\/span><span class=\"token punctuation\">}<\/span> <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token operator\"><span class=\"token file-descriptor important\">2<\/span>&gt;<\/span>\/dev\/null <span class=\"token operator\">|<\/span> <span class=\"token function\">head<\/span> -20<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u68c0\u67e5\u53ef\u7591\u7684cron\u4efb\u52a1 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token keyword\">for<\/span> <span class=\"token for-or-select variable\">user<\/span> <span class=\"token keyword\">in<\/span> <span class=\"token variable\"><span class=\"token variable\">$(<\/span><span class=\"token function\">cut<\/span> -f1 -d: \/etc\/passwd<span class=\"token variable\">)<\/span><\/span><span class=\"token punctuation\">;<\/span> <span class=\"token keyword\">do<\/span><br \/>\n    <span class=\"token function\">crontab<\/span> -u <span class=\"token variable\">$user<\/span> -l <span class=\"token operator\"><span class=\"token file-descriptor important\">2<\/span>&gt;<\/span>\/dev\/null <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> -v <span class=\"token string\">&#034;^#&#034;<\/span><br \/>\n<span class=\"token keyword\">done<\/span><\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u5f02\u5e38\u8fdb\u7a0b\u68c0\u67e5 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">ps<\/span> aux &#8211;sort<span class=\"token operator\">&#061;<\/span>-%cpu <span class=\"token operator\">|<\/span> <span class=\"token function\">head<\/span> -20<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u68c0\u67e5\u6700\u8fd1\u4fee\u6539\u7684\u7cfb\u7edf\u6587\u4ef6 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">find<\/span> \/etc -type f -mtime -7 -exec <span class=\"token function\">ls<\/span> -la <span class=\"token punctuation\">{<\/span><span class=\"token punctuation\">}<\/span> <span class=\"token punctuation\">\\\\<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token operator\"><span class=\"token file-descriptor important\">2<\/span>&gt;<\/span>\/dev\/null<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u68c0\u67e5\u7f51\u7edc\u8fde\u63a5 &#061;&#061;&#061;&#034;<\/span><br \/>\n<span class=\"token function\">netstat<\/span> -antup <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> ESTABLISHED <span class=\"token operator\">|<\/span> <span class=\"token function\">head<\/span> -20<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u68c0\u67e5\u767b\u5f55\u5931\u8d25\u8bb0\u5f55 &#061;&#061;&#061;&#034;<\/span><br \/>\nlastb <span class=\"token operator\">|<\/span> <span class=\"token function\">head<\/span> -20<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> -e <span class=\"token string\">&#034;<span class=\"token entity\" title=\"\\\\n\">\\\\n<\/span>&#061;&#061;&#061; \u5b89\u5168\u68c0\u67e5\u5b8c\u6210 &#061;&#061;&#061;&#034;<\/span><\/p>\n<p>\u5c06\u6b64\u811a\u672c\u8bbe\u7f6e\u4e3a\u6bcf\u5468\u8fd0\u884c&#xff1a;<\/p>\n<p><span class=\"token function\">chmod<\/span> &#043;x \/usr\/local\/bin\/security_check.sh<br \/>\n<span class=\"token builtin class-name\">echo<\/span> <span class=\"token string\">&#034;0 8 * * 1 root \/usr\/local\/bin\/security_check.sh | mail -s &#039;Weekly Security Check Report&#039; admin&#064;example.com&#034;<\/span> <span class=\"token operator\">&gt;<\/span> \/etc\/cron.d\/security_check<\/p>\n<h4>2. \u4f7f\u7528Lynis\u8fdb\u884c\u5b89\u5168\u5ba1\u8ba1<\/h4>\n<p>Lynis\u662f\u4e00\u4e2a\u5f3a\u5927\u7684\u5b89\u5168\u5ba1\u8ba1\u5de5\u5177&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u5b89\u88c5Lynis<\/span><br \/>\n<span class=\"token function\">wget<\/span> https:\/\/downloads.cisofy.com\/lynis\/lynis-3.0.8.tar.gz<br \/>\n<span class=\"token function\">tar<\/span> xzf lynis-3.0.8.tar.gz<br \/>\n<span class=\"token builtin class-name\">cd<\/span> lynis<\/p>\n<p><span class=\"token comment\"># \u8fd0\u884c\u5ba1\u8ba1<\/span><br \/>\n.\/lynis audit system<\/p>\n<p><span class=\"token comment\"># \u67e5\u770b\u62a5\u544a<\/span><br \/>\n<span class=\"token function\">cat<\/span> \/var\/log\/lynis.log<br \/>\n<span class=\"token function\">cat<\/span> \/var\/log\/lynis-report.dat<\/p>\n<p>\u8bbe\u7f6e\u5b9a\u671f\u5ba1\u8ba1&#xff1a;<\/p>\n<p><span class=\"token builtin class-name\">echo<\/span> <span class=\"token string\">&#034;0 2 * * 7 root cd \/path\/to\/lynis &amp;&amp; .\/lynis audit system &#8211;cronjob&#034;<\/span> <span class=\"token operator\">&gt;<\/span> \/etc\/cron.d\/lynis<\/p>\n<h4>3. \u6f0f\u6d1e\u626b\u63cf<\/h4>\n<p>\u4f7f\u7528OpenVAS\u6216Nessus\u5b9a\u671f\u626b\u63cf\u670d\u52a1\u5668\u6f0f\u6d1e&#xff0c;\u6216\u8005\u4f7f\u7528\u66f4\u8f7b\u91cf\u7ea7\u7684\u5de5\u5177\u5982Vuls&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u5b89\u88c5Vuls&#xff08;\u7b80\u5316\u7248\u5b89\u88c5\u6b65\u9aa4&#xff09;<\/span><br \/>\n<span class=\"token comment\"># \u8be6\u7ec6\u5b89\u88c5\u6b65\u9aa4\u8bf7\u53c2\u8003\u5b98\u65b9\u6587\u6863<\/span><\/p>\n<p><span class=\"token comment\"># \u914d\u7f6e\u626b\u63cf\u76ee\u6807<\/span><br \/>\n<span class=\"token function\">cat<\/span> <span class=\"token operator\">&gt;<\/span> config.toml <span class=\"token operator\">&lt;&lt;<\/span> <span class=\"token string\">EOF<br \/>\n[servers]<br \/>\n[servers.localhost]<br \/>\nhost &#061; &#034;localhost&#034;<br \/>\nport &#061; &#034;local&#034;<br \/>\nEOF<\/span><\/p>\n<p><span class=\"token comment\"># \u8fd0\u884c\u626b\u63cf<\/span><br \/>\nvuls scan<br \/>\nvuls report -format-json<\/p>\n<h3>\u5341\u3001\u5e94\u6025\u54cd\u5e94\u51c6\u5907<\/h3>\n<h4>1. \u521b\u5efa\u5e94\u6025\u54cd\u5e94\u8ba1\u5212<\/h4>\n<p>\u4e3a\u670d\u52a1\u5668\u521b\u5efa\u5e94\u6025\u54cd\u5e94\u8ba1\u5212\u6587\u6863&#xff0c;\u5305\u62ec&#xff1a;<\/p>\n<ul>\n<li>\u7d27\u6025\u8054\u7cfb\u4eba\u5217\u8868<\/li>\n<li>\u4e8b\u4ef6\u5206\u7c7b\u548c\u54cd\u5e94\u7a0b\u5e8f<\/li>\n<li>\u8bc1\u636e\u6536\u96c6\u6307\u5357<\/li>\n<li>\u6062\u590d\u7a0b\u5e8f<\/li>\n<li>\u4e8b\u540e\u5206\u6790\u6a21\u677f<\/li>\n<\/ul>\n<h4>2. \u914d\u7f6e\u7cfb\u7edf\u5feb\u7167\u548c\u5907\u4efd<\/h4>\n<p><span class=\"token comment\"># \u5b89\u88c5\u5e76\u914d\u7f6e\u5907\u4efd\u5de5\u5177&#xff08;\u4f8b\u5982rsnapshot&#xff09;<\/span><br \/>\nyum <span class=\"token function\">install<\/span> rsnapshot    <span class=\"token comment\"># CentOS\/RHEL<\/span><br \/>\n<span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> rsnapshot    <span class=\"token comment\"># Ubuntu\/Debian<\/span><\/p>\n<p><span class=\"token comment\"># \u914d\u7f6e\u5907\u4efd&#xff08;\u7f16\u8f91\/etc\/rsnapshot.conf&#xff09;<\/span><br \/>\nsnapshot_root   \/backup\/<br \/>\nretain  daily   <span class=\"token number\">7<\/span><br \/>\nretain  weekly  <span class=\"token number\">4<\/span><br \/>\nretain  monthly <span class=\"token number\">6<\/span><\/p>\n<p>backup  \/etc\/           localhost\/<br \/>\nbackup  \/home\/          localhost\/<br \/>\nbackup  \/var\/www\/       localhost\/<br \/>\nbackup  \/var\/log\/       localhost\/<br \/>\nbackup  \/usr\/local\/     localhost\/<\/p>\n<p><span class=\"token comment\"># \u8bbe\u7f6e\u5b9a\u671f\u5907\u4efd<\/span><br \/>\n<span class=\"token builtin class-name\">echo<\/span> <span class=\"token string\">&#034;0 1 * * * root \/usr\/bin\/rsnapshot daily&#034;<\/span> <span class=\"token operator\">&gt;<\/span> \/etc\/cron.d\/rsnapshot<br \/>\n<span class=\"token builtin class-name\">echo<\/span> <span class=\"token string\">&#034;0 2 * * 7 root \/usr\/bin\/rsnapshot weekly&#034;<\/span> <span class=\"token operator\">&gt;&gt;<\/span> \/etc\/cron.d\/rsnapshot<br \/>\n<span class=\"token builtin class-name\">echo<\/span> <span class=\"token string\">&#034;0 3 1 * * root \/usr\/bin\/rsnapshot monthly&#034;<\/span> <span class=\"token operator\">&gt;&gt;<\/span> \/etc\/cron.d\/rsnapshot<\/p>\n<h4>3. \u521b\u5efa\u7d27\u6025\u6062\u590d\u5de5\u5177\u5305<\/h4>\n<p>\u51c6\u5907\u4e00\u4e2a\u7d27\u6025\u6062\u590dUSB\u9a71\u52a8\u5668&#xff0c;\u5305\u542b&#xff1a;<\/p>\n<ul>\n<li>\u7cfb\u7edf\u5b89\u88c5\u4ecb\u8d28<\/li>\n<li>\u5173\u952e\u914d\u7f6e\u6587\u4ef6\u5907\u4efd<\/li>\n<li>\u6062\u590d\u6307\u5357\u6587\u6863<\/li>\n<li>\u53d6\u8bc1\u5de5\u5177&#xff08;\u5982CAINE\u3001Kali Linux&#xff09;<\/li>\n<li>\u5bc6\u7801\u91cd\u7f6e\u5de5\u5177<\/li>\n<\/ul>\n<h3>\u603b\u7ed3<\/h3>\n<p>\u7ecf\u8fc7\u591a\u5e74\u7684\u8fd0\u7ef4\u7ecf\u9a8c&#xff0c;\u6211\u53d1\u73b0\u670d\u52a1\u5668\u5b89\u5168\u4e0d\u662f\u4e00\u6b21\u6027\u5de5\u4f5c&#xff0c;\u800c\u662f\u6301\u7eed\u7684\u8fc7\u7a0b\u3002\u8fd9\u91cc\u662f\u4e00\u4e9b\u6700\u4f73\u5b9e\u8df5&#xff1a;<\/p>\n<li>\n<p>\u5b9a\u671f\u66f4\u65b0\u548c\u5ba1\u8ba1&#xff1a;\u6bcf\u5468\u81f3\u5c11\u68c0\u67e5\u4e00\u6b21\u7cfb\u7edf\u66f4\u65b0&#xff0c;\u6bcf\u6708\u8fdb\u884c\u4e00\u6b21\u5168\u9762\u5b89\u5168\u5ba1\u8ba1\u3002<\/p>\n<\/li>\n<li>\n<p>\u6700\u5c0f\u6743\u9650\u539f\u5219&#xff1a;\u53ea\u6388\u4e88\u7528\u6237\u5b8c\u6210\u5de5\u4f5c\u6240\u9700\u7684\u6700\u5c0f\u6743\u9650\u3002<\/p>\n<\/li>\n<li>\n<p>\u6df1\u5ea6\u9632\u5fa1\u7b56\u7565&#xff1a;\u4e0d\u8981\u4f9d\u8d56\u5355\u4e00\u5b89\u5168\u63aa\u65bd&#xff0c;\u800c\u662f\u6784\u5efa\u591a\u5c42\u6b21\u9632\u5fa1\u4f53\u7cfb\u3002<\/p>\n<\/li>\n<li>\n<p>\u76d1\u63a7\u548c\u8b66\u62a5&#xff1a;\u8bbe\u7f6e\u5168\u9762\u7684\u76d1\u63a7\u7cfb\u7edf&#xff0c;\u786e\u4fdd\u5f02\u5e38\u884c\u4e3a\u80fd\u591f\u53ca\u65f6\u89e6\u53d1\u8b66\u62a5\u3002<\/p>\n<\/li>\n<li>\n<p>\u6587\u6863\u548c\u57f9\u8bad&#xff1a;\u8bb0\u5f55\u6240\u6709\u5b89\u5168\u914d\u7f6e&#xff0c;\u5e76\u786e\u4fdd\u56e2\u961f\u6210\u5458\u4e86\u89e3\u5b89\u5168\u7b56\u7565\u3002<\/p>\n<\/li>\n<li>\n<p>\u5b9a\u671f\u6d4b\u8bd5&#xff1a;\u8fdb\u884c\u5b9a\u671f\u6e17\u900f\u6d4b\u8bd5\u548c\u707e\u96be\u6062\u590d\u6f14\u7ec3\u3002<\/p>\n<\/li>\n<li>\n<p>\u4fdd\u6301\u7b80\u5355&#xff1a;\u590d\u6742\u7684\u7cfb\u7edf\u66f4\u96be\u4ee5\u7ef4\u62a4\u548c\u5ba1\u8ba1&#xff0c;\u5c3d\u91cf\u4fdd\u6301\u7b80\u5355\u660e\u4e86\u3002<\/p>\n<\/li>\n<p>\u8bb0\u4f4f&#xff0c;\u670d\u52a1\u5668\u5b89\u5168\u662f\u4e00\u573a\u6301\u4e45\u6218\u3002\u9ed1\u5ba2\u53ea\u9700\u627e\u5230\u4e00\u4e2a\u6f0f\u6d1e&#xff0c;\u800c\u6211\u4eec\u5fc5\u987b\u9632\u5fa1\u6240\u6709\u53ef\u80fd\u7684\u653b\u51fb\u3002\u901a\u8fc7\u5b9e\u65bd\u672c\u6587\u63d0\u5230\u7684\u5b89\u5168\u52a0\u56fa\u63aa\u65bd&#xff0c;\u4f60\u7684\u670d\u52a1\u5668\u5c06\u80fd\u591f\u62b5\u5fa1\u5927\u591a\u6570\u5e38\u89c1\u7684\u653b\u51fb&#xff0c;\u4f46\u5b89\u5168\u5de5\u4f5c\u6c38\u8fdc\u4e0d\u4f1a\u7ed3\u675f\u3002<\/p>\n<p>\u5e0c\u671b\u8fd9\u4efd\u5168\u65b9\u4f4d\u7684\u670d\u52a1\u5668\u5b89\u5168\u52a0\u56fa\u6307\u5357\u5bf9\u4f60\u6709\u6240\u5e2e\u52a9\u3002\u5982\u679c\u4f60\u6709\u4efb\u4f55\u95ee\u9898\u6216\u9700\u8981\u8fdb\u4e00\u6b65\u7684\u5efa\u8bae&#xff0c;\u6b22\u8fce\u5728\u8bc4\u8bba\u533a\u7559\u8a00\u4ea4\u6d41&#xff01;<\/p>\n<hr \/>\n<p>\u5982\u679c\u8fd9\u7bc7\u6587\u7ae0\u5bf9\u4f60\u6709\u5e2e\u52a9&#xff0c;\u522b\u5fd8\u4e86\u70b9\u8d5e\u8f6c\u53d1\u652f\u6301\u4e00\u4e0b&#xff01;\u60f3\u4e86\u89e3\u66f4\u591a\u8fd0\u7ef4\u5b9e\u6218\u7ecf\u9a8c\u548c\u6280\u672f\u5e72\u8d27&#xff0c;\u8bb0\u5f97\u5173\u6ce8\u5fae\u4fe1\u516c\u4f17\u53f7&#064;\u8fd0\u7ef4\u8eac\u884c\u5f55&#xff0c;\u6211\u4f1a\u6301\u7eed\u5206\u4eab\u66f4\u591a\u63a5\u5730\u6c14\u7684\u8fd0\u7ef4\u77e5\u8bc6\u548c\u8e29\u5751\u7ecf\u9a8c\u3002\u8ba9\u6211\u4eec\u4e00\u8d77\u5728\u8fd0\u7ef4\u8fd9\u6761\u8def\u4e0a\u4e92\u76f8\u5b66\u4e60&#xff0c;\u5171\u540c\u8fdb\u6b65&#xff01; \u5fae\u4fe1\u516c\u4f17\u53f7&#xff1a;\u8fd0\u7ef4\u8eac\u884c\u5f55 \u4e2a\u4eba\u535a\u5ba2&#xff1a;\u8eac\u884c\u7b14\u8bb0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb718\u6b21\uff0c\u70b9\u8d5e14\u6b21\uff0c\u6536\u85cf27\u6b21\u3002\u670d\u52a1\u5668\u5b89\u5168\u52a0\u56fa\u5b9e\u6218\u6307\u5357 \u672c\u6587\u9488\u5bf9\u4e92\u8054\u7f51\u5b89\u5168\u5a01\u80c1\uff0c\u63d0\u4f9b\u5168\u9762\u7684\u670d\u52a1\u5668\u5b89\u5168\u52a0\u56fa\u65b9\u6848\u3002\u4ece\u7cfb\u7edf\u57fa\u7840\u5b89\u5168\u5165\u624b\uff0c\u5f3a\u8c03\u53ca\u65f6\u66f4\u65b0\u8865\u4e01\u3001\u6700\u5c0f\u5316\u5b89\u88c5\u539f\u5219\u548c\u7981\u7528\u4e0d\u5fc5\u8981\u670d\u52a1\u3002\u7528\u6237\u8d26\u6237\u5b89\u5168\u65b9\u9762\uff0c\u5efa\u8bae\u7981\u7528root\u8fdc\u7a0b\u767b\u5f55\u3001\u521b\u5efa\u7ba1\u7406\u5458\u8d26\u6237\u5e76\u8bbe\u7f6e\u4e25\u683c\u7684\u5bc6\u7801\u7b56\u7565\u3002SSH\u5b89\u5168\u52a0\u56fa\u5305\u62ec\u4fee\u6539\u9ed8\u8ba4\u7aef\u53e3\u3001\u4f7f\u7528\u5bc6\u94a5\u8ba4\u8bc1\u548c\u914d\u7f6e\u8bbf\u95ee\u9650\u5236\u3002\u9632\u706b\u5899\u914d\u7f6e\u4ecb\u7ecd\u4e86iptables\/firewalld\u7684\u57fa\u672c\u89c4\u5219\u548c\u9632DDoS\u63aa\u65bd\u3002\u6587\u4ef6\u7cfb\u7edf\u5b89\u5168\u63d0\u51fa\u4e86\u5206\u533a\u7b56\u7565\u3001\u6743\u9650\u5ba1\u8ba1\u548cAIDE\u6587\u4ef6\u5b8c\u6574\u6027\u68c0\u67e5\u3002\u6700\u540e\u5f3a\u8c03\u4e86\u7cfb\u7edf\u5ba1\u8ba1\u548c\u65e5\u5fd7\u96c6\u4e2d\u7ba1\u7406\u7684\u91cd\u8981\u6027\uff0c\u5e2e\u52a9\u8fd0\u7ef4\u4eba\u5458\u6784\u5efa\u66f4\u5b89\u5168\u7684\u670d\u52a1\u5668\u73af\u5883\u3002<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[61,43,44],"topic":[],"class_list":["post-49709","post","type-post","status-publish","format-standard","hentry","category-server","tag-61","tag-43","tag-44"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/49709.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb718\u6b21\uff0c\u70b9\u8d5e14\u6b21\uff0c\u6536\u85cf27\u6b21\u3002\u670d\u52a1\u5668\u5b89\u5168\u52a0\u56fa\u5b9e\u6218\u6307\u5357 \u672c\u6587\u9488\u5bf9\u4e92\u8054\u7f51\u5b89\u5168\u5a01\u80c1\uff0c\u63d0\u4f9b\u5168\u9762\u7684\u670d\u52a1\u5668\u5b89\u5168\u52a0\u56fa\u65b9\u6848\u3002\u4ece\u7cfb\u7edf\u57fa\u7840\u5b89\u5168\u5165\u624b\uff0c\u5f3a\u8c03\u53ca\u65f6\u66f4\u65b0\u8865\u4e01\u3001\u6700\u5c0f\u5316\u5b89\u88c5\u539f\u5219\u548c\u7981\u7528\u4e0d\u5fc5\u8981\u670d\u52a1\u3002\u7528\u6237\u8d26\u6237\u5b89\u5168\u65b9\u9762\uff0c\u5efa\u8bae\u7981\u7528root\u8fdc\u7a0b\u767b\u5f55\u3001\u521b\u5efa\u7ba1\u7406\u5458\u8d26\u6237\u5e76\u8bbe\u7f6e\u4e25\u683c\u7684\u5bc6\u7801\u7b56\u7565\u3002SSH\u5b89\u5168\u52a0\u56fa\u5305\u62ec\u4fee\u6539\u9ed8\u8ba4\u7aef\u53e3\u3001\u4f7f\u7528\u5bc6\u94a5\u8ba4\u8bc1\u548c\u914d\u7f6e\u8bbf\u95ee\u9650\u5236\u3002\u9632\u706b\u5899\u914d\u7f6e\u4ecb\u7ecd\u4e86iptables\/firewalld\u7684\u57fa\u672c\u89c4\u5219\u548c\u9632DDoS\u63aa\u65bd\u3002\u6587\u4ef6\u7cfb\u7edf\u5b89\u5168\u63d0\u51fa\u4e86\u5206\u533a\u7b56\u7565\u3001\u6743\u9650\u5ba1\u8ba1\u548cAIDE\u6587\u4ef6\u5b8c\u6574\u6027\u68c0\u67e5\u3002\u6700\u540e\u5f3a\u8c03\u4e86\u7cfb\u7edf\u5ba1\u8ba1\u548c\u65e5\u5fd7\u96c6\u4e2d\u7ba1\u7406\u7684\u91cd\u8981\u6027\uff0c\u5e2e\u52a9\u8fd0\u7ef4\u4eba\u5458\u6784\u5efa\u66f4\u5b89\u5168\u7684\u670d\u52a1\u5668\u73af\u5883\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/49709.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-30T11:11:28+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/49709.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/49709.html\",\"name\":\"\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2025-07-30T11:11:28+00:00\",\"dateModified\":\"2025-07-30T11:11:28+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/49709.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/49709.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/49709.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/49709.html","og_locale":"zh_CN","og_type":"article","og_title":"\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb718\u6b21\uff0c\u70b9\u8d5e14\u6b21\uff0c\u6536\u85cf27\u6b21\u3002\u670d\u52a1\u5668\u5b89\u5168\u52a0\u56fa\u5b9e\u6218\u6307\u5357 \u672c\u6587\u9488\u5bf9\u4e92\u8054\u7f51\u5b89\u5168\u5a01\u80c1\uff0c\u63d0\u4f9b\u5168\u9762\u7684\u670d\u52a1\u5668\u5b89\u5168\u52a0\u56fa\u65b9\u6848\u3002\u4ece\u7cfb\u7edf\u57fa\u7840\u5b89\u5168\u5165\u624b\uff0c\u5f3a\u8c03\u53ca\u65f6\u66f4\u65b0\u8865\u4e01\u3001\u6700\u5c0f\u5316\u5b89\u88c5\u539f\u5219\u548c\u7981\u7528\u4e0d\u5fc5\u8981\u670d\u52a1\u3002\u7528\u6237\u8d26\u6237\u5b89\u5168\u65b9\u9762\uff0c\u5efa\u8bae\u7981\u7528root\u8fdc\u7a0b\u767b\u5f55\u3001\u521b\u5efa\u7ba1\u7406\u5458\u8d26\u6237\u5e76\u8bbe\u7f6e\u4e25\u683c\u7684\u5bc6\u7801\u7b56\u7565\u3002SSH\u5b89\u5168\u52a0\u56fa\u5305\u62ec\u4fee\u6539\u9ed8\u8ba4\u7aef\u53e3\u3001\u4f7f\u7528\u5bc6\u94a5\u8ba4\u8bc1\u548c\u914d\u7f6e\u8bbf\u95ee\u9650\u5236\u3002\u9632\u706b\u5899\u914d\u7f6e\u4ecb\u7ecd\u4e86iptables\/firewalld\u7684\u57fa\u672c\u89c4\u5219\u548c\u9632DDoS\u63aa\u65bd\u3002\u6587\u4ef6\u7cfb\u7edf\u5b89\u5168\u63d0\u51fa\u4e86\u5206\u533a\u7b56\u7565\u3001\u6743\u9650\u5ba1\u8ba1\u548cAIDE\u6587\u4ef6\u5b8c\u6574\u6027\u68c0\u67e5\u3002\u6700\u540e\u5f3a\u8c03\u4e86\u7cfb\u7edf\u5ba1\u8ba1\u548c\u65e5\u5fd7\u96c6\u4e2d\u7ba1\u7406\u7684\u91cd\u8981\u6027\uff0c\u5e2e\u52a9\u8fd0\u7ef4\u4eba\u5458\u6784\u5efa\u66f4\u5b89\u5168\u7684\u670d\u52a1\u5668\u73af\u5883\u3002","og_url":"https:\/\/www.wsisp.com\/helps\/49709.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2025-07-30T11:11:28+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"8 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/49709.html","url":"https:\/\/www.wsisp.com\/helps\/49709.html","name":"\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2025-07-30T11:11:28+00:00","dateModified":"2025-07-30T11:11:28+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/49709.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/49709.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/49709.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"\u670d\u52a1\u5668\u5230\u624b\uff0c\u5982\u4f55\u5b89\u5168\u52a0\u56fa\uff1f\u8001\u8fd0\u7ef4\u7684\u5168\u65b9\u4f4d\u5b9e\u6218\u6307\u5357"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/49709","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=49709"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/49709\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=49709"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=49709"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=49709"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=49709"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}