Security Enhanced LinuxµÄÀúÊ·
Ò»¸öСÀúÊ·½«ÓÐÖúÓÚ°ïÖúÄúÀí½â Security-Enhanced Linux£¨SELinux£©——¶øÇÒËü±¾ÉíÒ²ÊǶÎÓÐȤµÄÀúÊ·¡£
ÃÀ¹ú¹ú¼Ò°²È«¾Ö
£¨National
Security
Agency£¬NSA£©³¤Ê±¼äÒÔÀ´¾Í¹Ø×¢´ó²¿·Ö²Ù×÷ϵͳÖÐÊÜÏ޵ݲȫÄÜÁ¦¡£±Ï¾¹£¬ËûÃǵŤ×÷Ö®Ò»¾ÍÊÇҪȷ±£ÃÀ¹ú¹ú·À²¿Ê¹ÓõļÆËã»úÔÚÃæÁÙûÍêûÁ˵Ĺ¥»÷ʱ
±£³Ö°²È«¡£NSA ·¢Ïִ󲿷ֲÙ×÷ϵͳµÄ°²È«»úÖÆ£¬°üÀ¨ Windows ºÍ´ó²¿·Ö UNIX ºÍ Linux ϵͳ£¬Ö»ÊµÏÖÁ˓ѡÔñÐÔ·ÃÎÊ¿ØÖÆ
£¨discretionary access control£©”£¨DAC
£©»úÖÆ¡£DAC »úÖÆÖ»ÊǸù¾ÝÔËÐгÌÐòµÄÓû§µÄÉí·ÝºÍÎļþµÈ¶ÔÏóµÄËùÓÐÕßÀ´¾ö¶¨³ÌÐò¿ÉÒÔ×öʲô¡£NSA ÈÏΪÕâÊÇÒ»¸öÑÏÖØµÄÎÊÌ⣬ÒòΪ DAC ±¾Éí¶Ô´àÈõµÄ»ò¶ñÒâµÄ³ÌÐòÀ´ËµÊÇÒ»¸ö²»ºÏ¸ñµÄ·À»¤Õß¡£È¡¶ø´úÖ®µÄ£¬NSA ³¤ÆÚÒÔÀ´Ò»Ö±Ï£Íû²Ù×÷ϵͳͬÑùÄÜÖ§³Ö“Ç¿ÖÆ·ÃÎÊ¿ØÖÆ
£¨mandatory access control£©”£¨MAC
£©»úÖÆ¡£
MAC
»úÖÆÊ¹µÃϵͳ¹ÜÀíÔ±¿ÉÒÔ¶¨ÒåÕû¸öϵͳµÄ°²È«²ßÂÔ£¬Õâ¸ö²ßÂÔ¿ÉÒÔ»ùÓÚÆäËûÒòËØ£¬ÏñÊÇÓû§µÄ½ÇÉ«¡¢³ÌÐòµÄ¿ÉÐÅÐÔ¼°Ô¤ÆÚʹÓᢳÌÐò½«ÒªÊ¹ÓõÄÊý¾ÝµÄÀàÐ͵ȵȣ¬À´
ÏÞÖÆ³ÌÐò¿ÉÒÔ×öÄÄЩÊÂÇé¡£Ò»¸öСÀý×Ó£¬ÓÐÁË MAC
ºóÓû§²»ÄÜÇáÒ׵ؽ«“±£Ãܵģ¨Secret£©”Êý¾Ýת»¯Îª“²»±£Ãܵģ¨Unclassified£©”µÄÊý¾Ý¡£²»¹ý£¬MAC
ʵ¼ÊÉÏ¿ÉÒÔ×öµÄ±ÈÄÇÒª¶àµÃ¶à¡£
NSA ÒѾÓë²Ù×÷ϵͳÌṩÉ̺Ï×÷Á˶àÄ꣬µ«ÊǺܶàÕ¼ÓÐ×î´óÊг¡µÄÌṩÉ̶ÔÓÚ½« MAC ¼¯³É½øÀ´Ã»ÓÐÐËȤ¡£¼´Ê¹ÊÇÄÇЩ¼¯³ÉÁË MAC µÄÌṩÉÌҲͨ³£Êǽ«Æä×öΪ“µ¥¶ÀµÄ²úÆ·”£¬¶ø²»Êdz£¹æ²úÆ·¡£Ò»²¿·ÖÔÒòÖ»ÊÇÒòΪ¾ÉʽµÄ MAC ²»¹»Áé»î¡£
ÓÚÊÇ
NSA µÄÑо¿Á¦Á¿¾¡Á¦È¥Ê¹ MAC ¸üÁé»î²¢ÇÒ²¢ÈÝÒ×±»°üº¬ÔÚ²Ù×÷ϵͳÖС£ËûÃÇʹÓà Mach
²Ù×÷ϵͳ¿ª·¢ÁËËûÃǵÄ˼ÏëµÄÔÐÍ£¬ºóÀ´·¢ÆðµÄ¹¤×÷À©Õ¹ÁË“Fluke”Ñо¿²Ù×÷ϵͳ¡£²»¹ý£¬ÄÑÒÔÈÃÈËÃÇÐÅ·þÕâЩ˼Ïë¿ÉÒÔÊÊÓÃÓÚ “ÕæÊµµÄ”²Ù×÷ϵͳ
£¬ÒòΪËùÓÐÕâЩ¹¤×÷¶¼»ùÓÚ΢ÐÍµÄ“Íæ¾ß¼¶µÄ”Ñо¿ÏîÄ¿¡£¼«ÉÙ¿ÉÒÔÔÚÔÐÍÖ®Íâ½øÐг¢ÊÔÒԲ鿴ÕâЩ˼ÏëÔÚÕæÊµµÄÓ¦ÓóÌÐòÖй¤×÷µÃÈçºÎ¡£NSA
²»ÄÜ˵·þ¾ßÓÐËùÓÐȨµÄÌṩÉÌÀ´Ìí¼ÓÕâЩ˼Ï룬¶øÇÒ NSA ҲûÓÐȨÀûÈ¥ÐÞ¸Ä˽ÓеIJÙ×÷ϵͳ¡£Õâ²»ÊǸöÐÂÎÊÌ⣻¶àÄêǰ DARPA
ÊÔÍ¼Ç¿ÖÆËüµÄ²Ù×÷ϵͳÑо¿ÈËԱʹÓÃ˽ÓеIJÙ×÷ϵͳ Windows£¬µ«Óöµ½Á˺ܶàÎÊÌâ¡£
ÓÚÊÇ£¬NSA żȻ·¢ÏÖÁËÒ»¸ö»ØÏëÆðÀ´ËƺõÏÔ¶øÒ×¼ûµÄÏë·¨£ºÊ¹ÓÃÒ»¸ö²»ÊÇ Íæ¾ßµÄ¿ª·ÅÔ´´úÂë²Ù×÷ϵÍ
Ïà¹ØÎĵµ£º
°²×°MySQL
ºÃ£¬ÎÒÃÇ¿ÉÒÔ¿ªÊ¼ÕýʽµÄ°²×°ÁË¡£¼ÙÉèÄã°ÑËùÓбØÐëµÄÔ´Âë»òÕß°ü¶¼·ÅÔÚÁË/tmpÏ¡£Èç¹ûÄãÏÂÔØµÄÊÇRPM°üµÄ»°£¬ÄDZȽϼòµ¥£»Èç¹ûÄãÏÂÔØµÄÊǶþ½øÖưü£¨ÄãûÓÐrpm³ÌÐò»òÕßÄãÏë×Ô¶¨ÒåµÄ»°£©£¬ÄÇô»áÉÔ΢Âé·³Ò»µã¡£
RPM°ü°²×°
Äã±ØÐë³ÉΪrootÓû§²ÅÄÜʹÓÃrpm°²×°³ÌÐò£¬ÒÔÏÂÊǰ²×°¹ý³Ì£º
$ cd /tmp
$ su
# rpm -Uvh ......
viµÄʹÓÃÖ®»ã×Ü
¹¦ÄÜ×îÇ¿ÔÚµÄ±à¼Æ÷——vi
viÊÇËùÓÐUNIXϵͳ¶¼»áÌṩµÄÆÁÄ»±à¼Æ÷£¬ËüÌṩÁËÒ»¸öÊÓ´°É豸£¬Í¨¹ýËü¿ÉÒÔ±à¼Îļþ¡£µ±È»£¬¶ÔUNIXϵͳÂÔÓÐËùÖªµÄÈË£¬»ò¶à»òÉÙ¶¼¾õµÃvi³¬¼¶ÄÑÓ㬵«viÊÇ×î»ù±¾µÄ±à¼Æ÷£¬ËùÒÔÏ£Íû¶ÁÕßÄܺúðÑËüѧÆðÀ´£¬ÒÔºóÔÚUNIXÊÀ½çÀï±Ø½«³©ÐÐÎÞ×è¡¢ÓÎÈÐÓÐÓ࣬ÒòΪÆäËû¼¸Ö ......
http://hi.baidu.com/chance_gao/blog/item/a8bfe3cd57c7be590fb345ff.html
Redhat4forxmanager [GDM]
µÚÒ»²½£¬ÎÒÃÇÔÚLinuxϵͳÏ£¬ÐÞ¸Ä/etc/X11/xdm/XaccessÎļþ£¬ÕÒµ½ÏÂÃæµÄÓï¾ä£º
# * #any host can get a login windowÈ¥µô×îÇ°ÃæµÄ#ºÅ£¬³ÉΪ
* #any host can get a login window
µÚ¶þ²½£¬ÎÒÃÇÐÞ¸Ä/etc/X11/gdm/gdm ......
¡¡¡¡Ð´ÁËÕ⼸Äê³ÌÐò£¬Í»È»×ªµ½linuxÏ£¬Í»È»¸Ðµ½×Ô¼º»¹ÒªÑ§µÄÌ«¶à¡£
¡¡¡¡1¡£linuxµÄÃüÁºÃ¶à....
2. Ì«¶àµÄIDE£¬²»ÖªµÀ¾¿¾¹Äĸö²ÅÕæÕýºÃʹ£¬ÔÝʱÓÃeclicpes°É£¬¾Ý˵ºÜÏóVS¡£
¡¡¡¡3. VMWAREϵÄlinux,¡¡ÏÔ¿¨¾¹È»×°²»ºÃ£¬Ìý˵µ½×°VTOOLS,£¬µ«Ã»ÕÒµ½ºÃÓõġ£
¡¡¡¡4¡¡³ýÁËMSµÄ ......
¡¡¡¡»·¾³£ºCentOS 5.3 x86_64Ï£¬/dev/sdb1ΪÊý¾Ý·ÖÇø/data0£¬EXT3Îļþϵͳ¡£
¡¡¡¡Ç°Òò£ºÎóɾÁË/data0/tcsql/cankao/phpcws-1.5.0/httpcws.cppÎļþ¡£ÓÉÓÚÍüÁ˱¸·Ýhttpcws.cppÎļþ£¬ÖØÐ¿ª·¢¹¤×÷Á¿½Ï´ó£¬Òò´ËÖ»Óлָ´¸ÃÎļþÒ»Ìõ·¿É×ß¡£
¡¡¡¡debugfsÃüÁîÕë¶ÔEXT2·ÖÇø»¹ÐУ¬µ«¶ÔEXT3·ÖÇø¾Í°ï²»ÉÏæÁË¡£Å¼È»·¢ÏÖµÄÒ»¿î¿ªÔ´Èí ......