Security Enhanced LinuxµÄÀúÊ·
Ò»¸öСÀúÊ·½«ÓÐÖúÓÚ°ïÖúÄúÀí½â Security-Enhanced Linux£¨SELinux£©——¶øÇÒËü±¾ÉíÒ²ÊǶÎÓÐȤµÄÀúÊ·¡£
ÃÀ¹ú¹ú¼Ò°²È«¾Ö
£¨National
Security
Agency£¬NSA£©³¤Ê±¼äÒÔÀ´¾Í¹Ø×¢´ó²¿·Ö²Ù×÷ϵͳÖÐÊÜÏ޵ݲȫÄÜÁ¦¡£±Ï¾¹£¬ËûÃǵŤ×÷Ö®Ò»¾ÍÊÇҪȷ±£ÃÀ¹ú¹ú·À²¿Ê¹ÓõļÆËã»úÔÚÃæÁÙûÍêûÁ˵Ĺ¥»÷ʱ
±£³Ö°²È«¡£NSA ·¢Ïִ󲿷ֲÙ×÷ϵͳµÄ°²È«»úÖÆ£¬°üÀ¨ Windows ºÍ´ó²¿·Ö UNIX ºÍ Linux ϵͳ£¬Ö»ÊµÏÖÁ˓ѡÔñÐÔ·ÃÎÊ¿ØÖÆ
£¨discretionary access control£©”£¨DAC
£©»úÖÆ¡£DAC »úÖÆÖ»ÊǸù¾ÝÔËÐгÌÐòµÄÓû§µÄÉí·ÝºÍÎļþµÈ¶ÔÏóµÄËùÓÐÕßÀ´¾ö¶¨³ÌÐò¿ÉÒÔ×öʲô¡£NSA ÈÏΪÕâÊÇÒ»¸öÑÏÖØµÄÎÊÌ⣬ÒòΪ DAC ±¾Éí¶Ô´àÈõµÄ»ò¶ñÒâµÄ³ÌÐòÀ´ËµÊÇÒ»¸ö²»ºÏ¸ñµÄ·À»¤Õß¡£È¡¶ø´úÖ®µÄ£¬NSA ³¤ÆÚÒÔÀ´Ò»Ö±Ï£Íû²Ù×÷ϵͳͬÑùÄÜÖ§³Ö“Ç¿ÖÆ·ÃÎÊ¿ØÖÆ
£¨mandatory access control£©”£¨MAC
£©»úÖÆ¡£
MAC
»úÖÆÊ¹µÃϵͳ¹ÜÀíÔ±¿ÉÒÔ¶¨ÒåÕû¸öϵͳµÄ°²È«²ßÂÔ£¬Õâ¸ö²ßÂÔ¿ÉÒÔ»ùÓÚÆäËûÒòËØ£¬ÏñÊÇÓû§µÄ½ÇÉ«¡¢³ÌÐòµÄ¿ÉÐÅÐÔ¼°Ô¤ÆÚʹÓᢳÌÐò½«ÒªÊ¹ÓõÄÊý¾ÝµÄÀàÐ͵ȵȣ¬À´
ÏÞÖÆ³ÌÐò¿ÉÒÔ×öÄÄЩÊÂÇé¡£Ò»¸öСÀý×Ó£¬ÓÐÁË MAC
ºóÓû§²»ÄÜÇáÒ׵ؽ«“±£Ãܵģ¨Secret£©”Êý¾Ýת»¯Îª“²»±£Ãܵģ¨Unclassified£©”µÄÊý¾Ý¡£²»¹ý£¬MAC
ʵ¼ÊÉÏ¿ÉÒÔ×öµÄ±ÈÄÇÒª¶àµÃ¶à¡£
NSA ÒѾÓë²Ù×÷ϵͳÌṩÉ̺Ï×÷Á˶àÄ꣬µ«ÊǺܶàÕ¼ÓÐ×î´óÊг¡µÄÌṩÉ̶ÔÓÚ½« MAC ¼¯³É½øÀ´Ã»ÓÐÐËȤ¡£¼´Ê¹ÊÇÄÇЩ¼¯³ÉÁË MAC µÄÌṩÉÌҲͨ³£Êǽ«Æä×öΪ“µ¥¶ÀµÄ²úÆ·”£¬¶ø²»Êdz£¹æ²úÆ·¡£Ò»²¿·ÖÔÒòÖ»ÊÇÒòΪ¾ÉʽµÄ MAC ²»¹»Áé»î¡£
ÓÚÊÇ
NSA µÄÑо¿Á¦Á¿¾¡Á¦È¥Ê¹ MAC ¸üÁé»î²¢ÇÒ²¢ÈÝÒ×±»°üº¬ÔÚ²Ù×÷ϵͳÖС£ËûÃÇʹÓà Mach
²Ù×÷ϵͳ¿ª·¢ÁËËûÃǵÄ˼ÏëµÄÔÐÍ£¬ºóÀ´·¢ÆðµÄ¹¤×÷À©Õ¹ÁË“Fluke”Ñо¿²Ù×÷ϵͳ¡£²»¹ý£¬ÄÑÒÔÈÃÈËÃÇÐÅ·þÕâЩ˼Ïë¿ÉÒÔÊÊÓÃÓÚ “ÕæÊµµÄ”²Ù×÷ϵͳ
£¬ÒòΪËùÓÐÕâЩ¹¤×÷¶¼»ùÓÚ΢ÐÍµÄ“Íæ¾ß¼¶µÄ”Ñо¿ÏîÄ¿¡£¼«ÉÙ¿ÉÒÔÔÚÔÐÍÖ®Íâ½øÐг¢ÊÔÒԲ鿴ÕâЩ˼ÏëÔÚÕæÊµµÄÓ¦ÓóÌÐòÖй¤×÷µÃÈçºÎ¡£NSA
²»ÄÜ˵·þ¾ßÓÐËùÓÐȨµÄÌṩÉÌÀ´Ìí¼ÓÕâЩ˼Ï룬¶øÇÒ NSA ҲûÓÐȨÀûÈ¥ÐÞ¸Ä˽ÓеIJÙ×÷ϵͳ¡£Õâ²»ÊǸöÐÂÎÊÌ⣻¶àÄêǰ DARPA
ÊÔÍ¼Ç¿ÖÆËüµÄ²Ù×÷ϵͳÑо¿ÈËԱʹÓÃ˽ÓеIJÙ×÷ϵͳ Windows£¬µ«Óöµ½Á˺ܶàÎÊÌâ¡£
ÓÚÊÇ£¬NSA żȻ·¢ÏÖÁËÒ»¸ö»ØÏëÆðÀ´ËƺõÏÔ¶øÒ×¼ûµÄÏë·¨£ºÊ¹ÓÃÒ»¸ö²»ÊÇ Íæ¾ßµÄ¿ª·ÅÔ´´úÂë²Ù×÷ϵÍ
Ïà¹ØÎĵµ£º
Linux version
[1] 2.6.10
2.6 version number, 10 release number
[2] 2.6.10 and 2.6.11
They can differ significantly even in core components and in fundamental algorithms
[3] 2.6.11.12
when a new kernel release appears, it is potentially unstable and buggy. To address this problem, the kern ......
¹Ø¼üÒµÎñÉ÷ÓÃlinux!
ÔÚÕâÀïÎÒÖ¸µÄ“¹Ø¼üÒµÎñ”ÊÇÖ¸ÔÚÆóÒµÖÐÌṩÖîÈçÊÕ·Ñ¡¢ÏúÊÛµÈÒµÎñ£¬ÐèÒªÌṩҪÇó¿Á¿ÌµÄ“°²È«ÐÔ”¡¢“¿É¿¿ÐÔ£¨7X24£©µÈÒªÇóµÄÒµÎñ¡£²»ÊÇå´»ú¼¸¸öСʱ¶¼ÎÞËùνµÄÒµÎñ¡£´ÓÎÒµÄÒÔÍùµÄÓ¦Óð¸ÀýÀ´¿´£¬Ê¹ÓÃlinuxÊǸö·Ç³£Ôã¸âµÄÑ¡Ôñ¡£°²È«ÐÔ£¬ÓÉÓÚ²»Äܵõ½¼°Ê±ÐÞ²¹ºÜÈÝÒ×±»ÀûÓá£Îȶ¨ ......
ÐÞ¸Ä/etc/fstab, /etc/rc.d/rc.sysinitµÈϵͳÆô¶¯ÎļþʱÎó²Ù×÷¾Í»áÔì³ÉlinuxÎÞ·¨½øÈ룬ÓÐrescueÅÌ¿ÉÒÔÈÝÒ×ÐÞ¸´£¬Õâ¸ö·½·¨ÊʺÏÓÚûÓÐrescueÅÌʱÐÞ¸´ÏµÍ³¡£
grub²Ëµ¥ÖÐÑ¡Ôñlinux,°´e,e,½øÈë±à¼Ä£Ê½£¬kernel (hd0,0)/vmlinuz root=/dev/hda2.....ÕâÒ»ÐÐ×îºó¼ÓÉÏinit=/bin/bash,Ð޸ĺúó°´enter,bÒýµ¼Ð޸ĺóµÄÒýµ¼ÐÅÏ¢ÀàËÆÈçÏ ......
¡¡¡¡»·¾³£ºCentOS 5.3 x86_64Ï£¬/dev/sdb1ΪÊý¾Ý·ÖÇø/data0£¬EXT3Îļþϵͳ¡£
¡¡¡¡Ç°Òò£ºÎóɾÁË/data0/tcsql/cankao/phpcws-1.5.0/httpcws.cppÎļþ¡£ÓÉÓÚÍüÁ˱¸·Ýhttpcws.cppÎļþ£¬ÖØÐ¿ª·¢¹¤×÷Á¿½Ï´ó£¬Òò´ËÖ»Óлָ´¸ÃÎļþÒ»Ìõ·¿É×ß¡£
¡¡¡¡debugfsÃüÁîÕë¶ÔEXT2·ÖÇø»¹ÐУ¬µ«¶ÔEXT3·ÖÇø¾Í°ï²»ÉÏæÁË¡£Å¼È»·¢ÏÖµÄÒ»¿î¿ªÔ´Èí ......