Linux°²È«ÉèÖÃÊÖ²á
1¡¢Bios¡¡Security
Ò»¶¨Òª¸øBiosÉèÖÃÃÜÂ룬ÒÔ·Àͨ¹ýÔÚBiosÖиıäÆô¶¯Ë³Ðò£¬¶ø¿ÉÒÔ´ÓÈíÅÌÆô¶¯¡£ÕâÑù¿ÉÒÔ×èÖ¹±ðÈËÊÔͼÓÃÌØÊâµÄÆô¶¯ÅÌÆô¶¯ÄãµÄϵͳ£¬»¹¿ÉÒÔ×èÖ¹±ðÈ˽øÈëBios¸Ä¶¯ÆäÖеÄÉèÖ㨱ÈÈçÔÊÐíͨ¹ýÈíÅÌÆô¶¯µÈ£©¡£
2¡¢LILO¡¡Security
ÔÚ"/etc/lilo.conf"ÎļþÖмÓÈëÏÂÃæÈý¸ö²ÎÊý£ºtime-out,restricted,password¡£ÕâÈý¸ö²ÎÊý¿ÉÒÔʹÄãµÄϵͳÔÚÆô¶¯liloʱ¾ÍÒªÇóÃÜÂëÑéÖ¤¡£
µÚÒ»²½£º
±à¼lilo.confÎļþ£¨vi¡¡/etc/lilo.comf£©,¼ÙÈç»ò¸Ä±äÕâÈý¸ö²ÎÊý£º
boot=/dev/hda¡¡
map=/boot/map¡¡
install=/boot/boot.b¡¡
time-out=00¡¡¡¡¡¡#°ÑÕâÐиÃΪ00
prompt¡¡
Default=linux¡¡
restricted¡¡¡¡¡¡#¼ÓÈëÕâÐÐ
password=¡¡¡¡¡¡#¼ÓÈëÕâÐв¢ÉèÖÃ×Ô¼ºµÄÃÜÂë
image=/boot/vmlinuz-2.2.14-12¡¡
label=linux¡¡
initrd=/boot/initrd-2.2.14-12.img¡¡
root=/dev/hda6¡¡
read-only¡¡
µÚ¶þ²½£º
ÒòΪ"/etc/lilo.conf"ÎļþÖаüº¬Ã÷ÎÄÃÜÂ룬ËùÒÔÒª°ÑËüÉèÖÃΪrootȨÏÞ¶ÁÈ¡¡£
[root@kapil¡¡/]#¡¡chmod¡¡600¡¡/etc/lilo.conf¡¡
µÚÈý²½£º
¸üÐÂϵͳ£¬ÒÔ±ã¶Ô"/etc/lilo.conf"Îļþ×öµÄÐÞ¸ÄÆð×÷Óá£
[Root@kapil¡¡/]#¡¡/sbin/lilo¡¡-v
µÚËIJ½£º
ʹÓÃ"chattr"ÃüÁîʹ"/etc/lilo.conf"Îļþ±äΪ²»¿É¸Ä±ä¡£
[root@kapil¡¡/]#¡¡chattr¡¡+i¡¡/etc/lilo.conf¡¡
ÕâÑù¿ÉÒÔ·ÀÖ¹¶Ô"/etc/lilo.conf"Èκθı䣨ÒÔÍâ»òÆäËûÔÒò£©
3¡¢É¾³ýËùÓеÄÌØÊâÕË»§
ÄãÓ¦¸Ãɾ³ýËùÓв»ÓõÄȱʡÓû§ºÍ×éÕË»§£¨±ÈÈçlp,¡¡sync,¡¡shutdown,¡¡halt,¡¡news,¡¡uucp,¡¡operator,¡¡games,¡¡gopherµÈ£©¡£
ɾ³ýÓû§£º
[root@kapil¡¡/]#¡¡userdel¡¡LP¡¡
ɾ³ý×飺
[root@kapil¡¡/]#¡¡groupdel¡¡LP¡¡
4¡¢Ñ¡ÔñÕýÈ·µÄÃÜÂë
ÔÚÑ¡ÔñÕýÈ·ÃÜÂë֮ǰ»¹Ó¦×÷ÒÔÏÂÐ޸ģº
ÐÞ¸ÄÃÜÂ볤¶È£ºÔÚÄã°²×°linuxʱĬÈϵÄÃÜÂ볤¶ÈÊÇ5¸ö×Ö½Ú¡£µ«Õâ²¢²»¹»£¬Òª°ÑËüÉèΪ8¡£ÐÞ¸Ä×î¶ÌÃÜÂ볤¶ÈÐèÒª±à¼login.defsÎļþ£¨vi¡¡/etc/login.defs£©£¬°ÑÏÂÃæÕâÐÐ
PASS_MIN_LEN¡¡¡¡¡¡¡¡5¡¡
¸ÄΪ
PASS_MIN_LEN¡¡¡¡¡¡¡¡8
login.defsÎļþÊÇlogin³ÌÐòµÄÅäÖÃÎļþ¡£
5¡¢´ò¿ªÃÜÂëµÄshadowÖ§³Ö¹¦ÄÜ£º
ÄãÓ¦¸Ã´ò¿ªÃÜÂëµÄshadow¹¦ÄÜ£¬À´¶Ôpassword¼ÓÃÜ¡£Ê¹ÓÃ"/usr/sbin/authconfig"¹¤¾ß´ò¿ªshadow¹¦ÄÜ¡£Èç¹ûÄãÏë°ÑÒÑÓеÄÃÜÂëºÍ×éת±äΪshadow¸ñʽ£¬¿ÉÒÔ·Ö±ðʹÓÃ"pwcov,grpconv"ÃüÁî¡£
6¡¢rootÕË»§
ÔÚunixϵͳÖÐrootÕË»§ÊǾßÓÐ×î¸ßÌØÈ¨µÄ¡£Èç¹ûϵͳ¹ÜÀíÔ±ÔÚÀ뿪ϵͳ֮ǰÍü¼Ç×¢ÏúrootÕË»§£¬ÏµÍ³»á×Ô¶¯×¢Ïú¡£Í¨¹ýÐÞ¸ÄÕË»§ÖÐ"TMOUT"²ÎÊý£¬¿ÉÒÔÊ
Ïà¹ØÎĵµ£º
×ÜÀÀ
ÓÃiptables -ADC À´Ö¸¶¨Á´µÄ¹æ
Ôò
£¬-AÌí¼Ó -Dɾ³ý -C ÐÞ¸Ä
iptables - [RI] chain rule num rule-specification[option]
ÓÃiptables - RI ͨ¹ý¹æÔòµÄ˳ÐòÖ¸¶¨
iptables -D chain rule num[option]
ɾ³ýÖ¸¶¨¹æÔò
iptables -[LFZ] [chain][option]
ÓÃiptables -LFZ Á´Ãû [Ñ¡Ïî]
iptables -[NX] chain
ÓÃ -NX ......
Ãæ¶Ô²»¶ÏÉý¼¶µÄlinuxÄںˡ¢GNU¿ª·¢¹¤¾ß¡¢linux»·¾³Ïµĸ÷ÖÖͼÐο⣬ºÜ¶àlinuxÓ¦ÓóÌÐò
¿ª·¢ÈËÔ±ºÍlinuxÉ豸Çý¶¯¿ª·¢ÈËÔ±¼´ÐË·Ü£¬ÓÖ·³Ôê¡£Ð˷ܵÄÊÇеÄÈí¼þÈí¼þ¡¢¹¤¾ß¸øÎÒÌṩÁ˸üÇ¿´óµÄ¹¦ÄÜ£¬·³ÔêµÄÊÇÊÊÓ¦ÐÂÈí¼þµÄÌØÐÔ¡¢´î½¨Ð»·¾³ÊÇÒ»Ïî
·Ç³£·±ËöµÄÊÂÇé¡£±¾ÎÄÏë´ÓÒÔÏÂ3¸ö·½ÃæÌ½ÌÖÒ»ÏÂ“Ãæ¶Ô²»¶ÏÉý¼¶µÄÄںˣ¬ÈçºÎÑ ......
±¾ÎÄÏêϸÃèÊöÁËÔÚLinux²Ù×÷ϵͳÉϰ²×°ºÍÅäÖÓ×ÔÊÊӦͨÐÅ»·¾³(ACE)”µÄ¹ý³ÌºÍ×¢ÒâÊÂÏî¡£zCkLinuxÁªÃË
ÎÄÖеÄÃèÊö»ùÓÚRedHat Linux 9²Ù×÷ϵͳºÍACE 5.4°æzCkLinuxÁªÃË
×¼±¸¹¤×÷£ºzCkLinuxÁªÃË
1.È·±£ÄãµÄLinux²Ù×÷ϵͳµÄ¿ª·¢»·¾³(gcc¡¢make……)ÊÇÍêÕûÇÒ¿ÉÓõġ£zCkLinuxÁªÃË
2.ÔÚ°²×°ACEµÄ¹ý³ÌÖÐ ......
=======================================================================
һЩ¹ØÓÚLinuxµÄ×ÊÔ´Õ¾µã£¬Ï£Íû¶Ô´ó¼ÒÓаïÖú
http://www.linux.org/ ;
Linux¹Ù·½ÐÂÎźÍÐÅÏ¢ÍøÕ¾¡£
http://freesoft.cei.gov.cn/ ;
ÖйúÈí¼þÐÐҵлá¹ú¼Ê×ÔÓÉÈí¼þÓ¦ÓÃÑо¿·¢Õ¹·Ö»áµÄ×ÔÓÉÈí¼þ¿â£¬ÉÏÃæÌṩÓи÷ÖÖLinuxÈí¼þ¿É¹©ÏÂÔØ£¬²¢ÓÐLinux ......
whereis ÃüÁîÏê½â
¹¦ÄÜ˵Ã÷£º²éÕÒÎļþ¡£
Óï¡¡¡¡·¨£ºwhereis [-bfmsu][-B ...][-M ...][-S ...][Îļþ...]
²¹³ä˵Ã÷£ºwhereisÖ¸Áî»áÔÚÌØ¶¨Ä¿Â¼ÖвéÕÒ·ûºÏÌõ¼þµÄÎļþ¡£ÕâЩÎļþµÄÁÒÐÔÓ¦ÊôÓÚÔʼ´úÂ룬¶þ½øÖÆÎļþ£¬»òÊǰïÖúÎļþ¡£
²Î¡¡¡¡Êý£º
¡¡-b ¡¡Ö»²éÕÒ¶þ½øÖÆÎļþ¡£
¡¡-B ¡¡Ö»ÔÚÉèÖõÄĿ¼Ï²éÕÒ¶þ½øÖÆÎļþ¡£
¡¡-f ......