ʲôÊÇprocÎļþϵͳ£¿
procÎļþϵͳÊÇÒ»¸öαÎļþϵͳ£¬ËüÖ»´æÔÚÄÚ´æµ±ÖУ¬¶ø²»Õ¼ÓÃÍâ´æ¿Õ¼ä¡£ËüÒÔÎļþϵͳµÄ·½Ê½Îª·ÃÎÊϵͳÄÚºËÊý¾ÝµÄ²Ù×÷Ìṩ½Ó¿Ú¡£Óû§ºÍÓ¦ÓóÌÐò¿ÉÒÔͨ¹ýprocµÃµ½ÏµÍ³µÄÐÅ
Ï¢£¬²¢¿ÉÒԸıäÄں˵ÄijЩ²ÎÊý¡£ÓÉÓÚϵͳµÄÐÅÏ¢£¬Èç½ø³Ì£¬ÊǶ¯Ì¬¸Ä±äµÄ£¬ËùÒÔÓû§»òÓ¦ÓóÌÐò¶ÁÈ¡procÎļþʱ£¬procÎļþϵͳÊǶ¯Ì¬´ÓϵͳÄں˶Á³öËùÐèÐÅÏ¢²¢Ìá½»µÄ¡£ËüµÄ
Ŀ¼½á¹¹ÈçÏ£º
Ŀ¼Ãû³Æ Ŀ¼ÄÚÈÝ
apm ¸ß¼¶µçÔ´¹ÜÀíÐÅÏ¢
cmdline ÄÚºËÃüÁîÐÐ
Cpuinfo ¹ØÓÚCpuÐÅÏ¢
Devices ¿ÉÒÔÓõ½µÄÉ豸£¨¿éÉ豸/×Ö·ûÉ豸£©
Dma ʹÓõÄDMAͨµÀ
Filesystems Ö§³ÖµÄÎļþϵͳ
Interrupts ÖжϵÄʹÓÃ
Ioports I/O¶Ë¿ÚµÄʹÓÃ
Kcore Äں˺ËÐÄÓ¡Ïó
Kmsg ÄÚºËÏûÏ¢
Ksyms Äں˷ûºÅ±í
Loadavg ¸ºÔؾùºâ
Locks ÄÚºËËø
Meminfo ÄÚ´æÐÅÏ¢
Misc ÔÓÏî
Modules ¼ÓÔØÄ£¿éÁбí
Mounts ¼ÓÔØµÄÎļþϵͳ
Partitions ϵͳʶ±ðµÄ·ÖÇø±í
Rtc ʵʱʱÖÓ
Slabinfo Slab³ØÐÅÏ¢
Stat È«ÃæÍ³¼Æ×´Ì¬±í
Swaps ¶Ô»»¿Õ¼äµÄÀûÓÃÇé¿ö
Version Äں˰汾
Uptime ϵͳÕý³£ÔËÐÐʱ¼ä
²¢²»ÊÇËùÓÐÕâЩĿ¼ÔÚÄãµÄϵͳÖж¼ÓУ¬ÕâÈ¡¾öÓÚÄãµÄÄÚºËÅäÖúÍ×°ÔØµÄÄ£¿é¡£ÁíÍ⣬ÔÚ /procÏ»¹ÓÐÈý¸öºÜÖØÒ ......
Securing your Linux server is important to protect your data, intellectual property, and time, from the hands of crackers (hackers). The system administrator is responsible for security Linux box. In this first part of a Linux server security series, I will provide 20 hardening tips for default installation of Linux system.
#1: Encrypt Data Communication
All data transmitted over a network is open to monitoring. Encrypt transmitted data whenever possible with password or using keys / certificates.
Use scp, ssh, rsync, or sftp for file transfer. You can also mount remote server file system or your own home directory using special sshfs and fuse tools.
GnuPG allows to encrypt and sign your data and communication, features a versatile key managment system as well as access modules for all kind of public key directories.
Fugu is a graphical frontend to the commandline Secure File Transfer application (SFTP). SFTP is similar to FTP, but unlike FTP, the entire session is encrypted, mean ......
¶ÔÓÚϵͳ¶øÑÔ£¬ÎÒÃÇ¿ÉÒÔÓкܶàÖְ취ȥ±¸·Ý£¨»¹Ô£©ÏµÍ³»òÎļþ£¬Ö®ËùÒÔҪȥ×ö±¸·Ý£¬¾ÍÊÇΪÁËÔÚϵͳ»òÎļþÔâµ½Ëðº¦Ê±£¬Äܼ°Ê±»Ö¸´£¬°ÑËðʧ¼õСµ½×î
С¡£µ±È»£¬¶ÔÓÚÆóÒµ·þÎñÆ÷¶øÑÔ£¬±¸·ÝµÄÖØÒªÐÔÊǾÙ×ãÇáÖØ¡£ÔÛÃǽñÌì¾ÍÏêϸÌÖÂÛÒ»ÏÂLINUXÖÐÈçºÎÓÃdumpºÍrestoreʵÏÖ±¸·ÝºÍ»¹Ô¡£
Ò»£¬dumpµÄÔÀí£¬Óŵ㼰ÏÞÖÆ
dumpºÍrestoreĬÈÏÒѾ°²×°ÔÚRHEL5ÖУ¬Èç¹ûÄãʹÓõÄLinuxÖÐûÓУ¬¿ÉÒÔ×Ô¼ºÈ¥googleÖÐËÑһϲ¢ÏÂÔØ°²×°¡£
ʹ
ÓÃdumpÃüÁîʱ£¬Ëü»á½¨Á¢Ò»·Ý×ÔÉϴα¸·Ý²Ù×÷ÒÔÀ´½øÐÐÐ޸ĹýµÄÎļþÁÐ±í£¬È»ºó°ÑÕâЩÎļþ´ò°ü³ÉÒ»¸öµ¥¶ÀµÄÎļþ¡£ÔÚ×ö±¸·Ýʱ£¬ÐèÒªÖ¸¶¨Ò»¸ö±¸·Ý¼¶±ð£¬ËüÊÇ
0-9Ö®¼äµÄÒ»¸öÕûÊý¡£¼¶±ðΪNµÄת´¢»á¶Ô´ÓÉϴνøÐеļ¶±ðСÓÚNµÄת´¢²Ù×÷ÒÔÀ´Ð޸ĹýµÄËùÓÐÎļþ½øÐб¸·Ý£¬¶ø¼¶±ð0¾ÍÊÇÍêÈ«±¸·Ý¡£Í¨¹ýÕâÖÖ·½Ê½£¬¿ÉÒÔºÜ
ÇáËɵÄʵÏÖÔöÁ¿±¸·Ý£¬²îÒ챸·Ý£¬ÉõÖÁÿÈÕ±¸·Ý¡£ÀýÈ磬µÚÒ»´Î±¸·Ýʱ¿ÉÑ¡Ôñ¼¶±ð0£¨¾ßÌå²Ù×÷¿´ºóÃæ£©£¬ÒÔºóÿÌì×öÔöÁ¿±¸·Ýʱ¾Í¿ÉÒÔÿÌìÒÀ´ÎʹÓü¶±ð1£¬¼¶±ð
2£¬¼¶±ð3µÈµÈ…
…£»µ±ÐèҪÿÌì×ö²îÒ챸·Ýʱ£¬¿ÉÏÈÑ¡Ôñ¼¶±ð0×öÍêÕû±¸·Ý£¬È»ºóÿÌ춼ʹÓÃͬһ´óÓÚ0µÄ¼¶±ð¾ÍÐÐÁË£¬±ÈÈç˵µÚ¶þÌìÓÃ5£¬µÚÈýÌìÒ²ÓÃ5£¬µÚËÄÌìÒ²Ò»Ñù¡£
ʹÓÃdumpµÄÓŵ㣺
1£¬ ......
ifconfig
1.×÷ÓÃ
ifconfigÓÃÓڲ鿴ºÍ¸ü¸ÄÍøÂç½Ó¿ÚµÄµØÖ·ºÍ²ÎÊý£¬°üÀ¨IPµØÖ·¡¢ÍøÂçÑÚÂë¡¢¹ã²¥µØÖ·£¬Ê¹ÓÃȨÏÞÊdz¬¼¶Óû§¡£
2.¸ñʽ
ifconfig -interface [options] address
3.Ö÷Òª²ÎÊý
-interface£ºÖ¸¶¨µÄÍøÂç½Ó¿ÚÃû£¬Èçeth0ºÍeth1¡£
up£º¼¤»îÖ¸¶¨µÄÍøÂç½Ó¿Ú¿¨¡£
down£º¹Ø±ÕÖ¸¶¨µÄÍøÂç½Ó¿Ú¡£
broadcast address£ºÉèÖýӿڵĹ㲥µØÖ·¡£
pointopoint£ºÆôÓõã¶Ôµã·½Ê½¡£
address£ºÉèÖÃÖ¸¶¨½Ó¿ÚÉ豸µÄIPµØÖ·¡£
netmask address£ºÉèÖýӿڵÄ×ÓÍøÑÚÂë¡£
4.Ó¦ÓÃ˵Ã÷
ifconfigÊÇÓÃÀ´ÉèÖúÍÅäÖÃÍø¿¨µÄÃüÁîÐй¤¾ß¡£ÎªÁËÊÖ¹¤ÅäÖÃÍøÂ磬ÕâÊÇÒ»¸ö±ØÐëÕÆÎÕµÄÃüÁʹÓøÃÃüÁîµÄºÃ´¦ÊÇÎÞÐëÖØÐÂÆô¶¯»úÆ÷¡£Òª¸³¸øeth0½Ó¿ÚIPµØÖ·207.164.186.2£¬²¢ÇÒÂíÉϼ¤»îËü£¬Ê¹ÓÃÏÂÃæÃüÁ
#fconfig eth0 210.34.6.89 netmask 255.255.255.128 broadcast 210.34.6.127
¸ÃÃüÁîµÄ×÷ÓÃÊÇÉèÖÃÍø¿¨eth0µÄIPµØÖ·¡¢ÍøÂçÑÚÂëºÍÍøÂçµÄ±¾µØ¹ã²¥µØÖ·¡£ÈôÔËÐв»´øÈκβÎÊýµÄifconfigÃüÁÕâ¸öÃüÁÏÔʾ»úÆ÷ËùÓ줻î½Ó¿ÚµÄÐÅÏ¢¡£´øÓГ-a”²ÎÊýµÄÃüÁîÔòÏÔʾËùÓнӿڵÄÐÅÏ¢£¬°üÀ¨Ã»Ó줻îµÄ½Ó¿Ú¡£×¢Ò⣬ÓÃifconfigÃüÁîÅäÖõÄÍøÂçÉ豸²ÎÊý£¬»úÆ÷ÖØÐÂÆô¶¯ÒԺ󽫻ᶪʧ¡£
Èç¹ûÒªÔÝͣij¸öÍøÂç½Ó¿ÚµÄ ......
¡¡Ëæ×ÅÈËÃǶԿª·ÅÔ´´úÂëÈí¼þÈÈÇéµÄÈÕÒæÔö¸ß£¬Linux×÷Ϊһ¸ö¹¦ÄÜÇ¿´ó¶øÎȶ¨µÄ¿ªÔ´²Ù×÷ϵͳ£¬Ô½À´Ô½Êܵ½³ÉǧÉÏÍòµÄ¼ÆËã»úר¼ÒºÍ°®ºÃÕßµÄÇàíù¡£ÔÚǶÈëʽÁìÓò£¬Í¨¹ý¶ÔLinux½øÐÐСÐÍ»¯²Ã¼ôºó£¬Ê¹ÆäÄܹ»¹Ì»¯ÔÚÈÝÁ¿Ö»Óм¸Ê®Õ××ֽڵĴ洢Æ÷оƬ»òµ¥Æ¬»úÖУ¬³ÉΪӦÓÃÓÚÌØ¶¨³¡ºÏµÄǶÈëʽLinuxϵͳ¡£LinuxÇ¿´óµÄÍøÂçÖ§³Ö¹¦ÄÜʵÏÖÁ˶԰üÀ¨TCP/IPÔÚÄڵĶàÖÖÐÒéµÄÖ§³Ö£¬Âú×ãÁËÃæÏò21ÊÀ¼ÍµÄǶÈëʽϵͳӦÓÃÁªÍøµÄÐèÇó¡£Òò´Ë£¬ÔÚǶÈëʽϵͳ¿ª·¢µ÷ÊÔʱ£¬ÍøÂç½Ó¿Ú¼¸ºõ³ÉΪ²»¿É»òȱµÄÄ£¿é¡£
¡¡¡¡1 ǶÈëʽLinuxÍøÂçÇý¶¯³ÌÐò½éÉÜ
¡¡¡¡LinuxÍøÂçÇý¶¯³ÌÐò×÷ΪLinuxÍøÂç×ÓϵͳµÄÒ»²¿·Ö£¬Î»ÓÚTCP/IPÍøÂçÌåϵ½á¹¹µÄÍøÂç½Ó¿Ú²ã£¬Ö÷ҪʵÏÖÉϲãÐÒéÕ»ÓëÍøÂçÉ豸µÄÊý¾Ý½»»»¡£LinuxµÄÍøÂçϵͳÖ÷ÒªÊÇ»ùÓÚBSD UnixµÄÌ×½Ó×Ö£¨socket£©»úÖÆ£¬ÍøÂçÉ豸Óë×Ö·ûÉ豸ºÍ¿éÉ豸²»Í¬£¬Ã»ÓжÔÓ¦µØÓ³Éäµ½ÎļþϵͳÖеÄÉ豸½Úµã¡£
¡¡¡¡Í¨³££¬LinuxÇý¶¯³ÌÐòÓÐÁ½ÖÖ¼ÓÔØ·½Ê½£ºÒ»ÖÖÊǾ²Ì¬µØ±àÒë½øÄںˣ¬ÄÚºËÆô¶¯Ê±×Ô¶¯¼ÓÔØ£»ÁíÒ»ÖÖÊDZàдΪÄÚºËÄ£¿é,ʹÓÃinsmodÃüÁģ¿é¶¯Ì¬¼ÓÔØµ½ÕýÔÚÔËÐеÄÄںˣ¬²»ÐèҪʱ¿ÉÓÃrmmodÃüÁģ¿éÐ¶ÔØ¡£Linux 2.6ÄÚºËÒýÈëÁËkbuild»úÖÆ£¬½«ÍⲿÄÚºËÄ£¿éµÄ±àÒëͬÄÚºËÔ´ÂëÊ÷µÄ±àÒëͳһÆðÀ´£¬´ó´ó¼ò»¯ ......
ÕâÊDZ¾È˵Ĵ¦ÄÐ×÷Æ·£¬¿´ÍêµÄÈËÒª¶Ô±¾È˸ºÔð°¡£¡
gccºÍg++¶¼ÊÇGNU(×éÖ¯)µÄÒ»¸ö±àÒëÆ÷¡£
gccÓëg++µÄ¶Ô±È
ÎóÇøÒ»:gccÖ»ÄܱàÒëc´úÂë,g++Ö»ÄܱàÒëc++´úÂë
Á½Õß¶¼¿ÉÒÔ£¬µ«ÊÇÇë×¢Ò⣺
1.ºó׺Ϊ.cµÄ£¬gcc°ÑËüµ±×÷ÊÇC³ÌÐò£¬¶øg++µ±×÷ÊÇc++³ÌÐò£»ºó׺Ϊ.cppµÄ£¬Á½Õß¶¼»áÈÏΪÊÇc++³ÌÐò£¬×¢Ò⣬ËäÈ»c++ÊÇcµÄ³¬¼¯£¬µ«ÊÇÁ½Õß¶ÔÓï·¨µÄÒªÇóÊÇÓÐÇø±ðµÄ¡£C++µÄÓï·¨¹æÔò¸ü¼ÓÑϽ÷һЩ¡£
2.±àÒë½×¶Î£¬g++»áµ÷ÓÃgcc£¬¶ÔÓÚc++´úÂ룬Á½ÕßÊǵȼ۵쬵«ÊÇÒòΪgccÃüÁî²»ÄÜ×Ô¶¯ºÍC£«£«³ÌÐòʹÓõĿâÁª½Ó£¬ËùÒÔͨ³£ÓÃg++À´Íê³ÉÁ´½Ó£¬ÎªÁËͳһÆð¼û£¬¸É´à±àÒë/Á´½ÓͳͳÓÃg++ÁË£¬Õâ¾Í¸øÈËÒ»ÖÖ´í¾õ£¬ºÃÏñcpp³ÌÐòÖ»ÄÜÓÃg++ËÆµÄ¡£
ÎóÇø¶þ:gcc²»»á¶¨Òå__cplusplusºê£¬¶øg++»á
ʵ¼ÊÉÏ£¬Õâ¸öºêÖ»ÊDZêÖ¾×űàÒëÆ÷½«»á°Ñ´úÂë°´C»¹ÊÇC++Óï·¨À´½âÊÍ£¬ÈçÉÏËùÊö£¬Èç¹ûºó׺Ϊ.c£¬²¢ÇÒ²ÉÓÃgcc±àÒëÆ÷£¬Ôò¸Ãºê¾ÍÊÇ䶨ÒåµÄ£¬·ñÔò£¬¾ÍÊÇÒѶ¨Òå¡£
ÎóÇøÈý:±àÒëÖ»ÄÜÓÃgcc£¬Á´½ÓÖ»ÄÜÓÃg++
ÑϸñÀ´Ëµ£¬Õâ¾ä»°²»Ëã´íÎ󣬵«ÊÇËü»ìÏýÁ˸ÅÄӦ¸ÃÕâÑù˵£º±àÒë¿ÉÒÔÓÃgcc/g++£¬¶øÁ´½Ó¿ÉÒÔÓÃg++»òÕßgcc -lstdc++¡£ÒòΪgccÃüÁî²»ÄÜ×Ô¶¯ºÍC£«£«³ÌÐòʹÓõĿâÁª½Ó£¬ËùÒÔͨ³£Ê¹ÓÃg++À´Íê³ÉÁª½Ó¡£µ«ÔÚ±àÒë½×¶ ......