Linux ϵͳÄں˲ÎÊý sysctl.confÓÅ»¯·½°¸
Öйú×îÍêÕûµÄsysctl.confÓÅ»¯·½°¸
ÍøÉϹØÓÚsysctl.confµÄÓÅ»¯·½°¸Óи÷ÖÖ°æ±¾£¬´ó¶à¶¼ÊdzÀ´³È¥µÄ£¬ÈÃÐÂÈË¿´Á˺ÜÃÔ㡣Ϊ½â¾ö´ËÎÊÌ⣬¾¹ýÁ½ÌìµÄÕûÀí£¬²éÁËN¶à×ÊÁÏ£¬½«´ó¼Ò³£ÓõÄ×ܽáÈçÏ£¬ºÜ¶àĬÈϵIJ»ÐèÒªÐ޸ĵÄÔÝÎ´Éæ¼°£¬½ñºó½«Öð²½°ÑËùÓеÄÏîÄ¿¶¼Óиö·Òë¡¢½²½â¡¢Ð޸Ľ¨Ò飬ÈçÓÐÐ޸쬽«ÒÔ´ËÎÄΪ׼£¬ÆäËûµØ·½µÄÄÚÈÝ£¬±¾È˲»¸ºÔð¸üС£Òò´Ë×ªÔØÇë×¢Ã÷Á´½ÓµØÖ·£º
http://www.bsdlover.cn/security/2007/1216/article_8.html
Èç¹ûÄúÓв¹³ä»òÐÞ¶©Òâ¼û£¬ÇëÓÚ±¾ÎĺóÆÀÂÛ»òÓʼþÁªÏµ
cujxtm@gmail.com
£¬Íò·Ö¸Ðл£¡
###################
ËùÓÐrfcÏà¹ØµÄÑ¡Ïî¶¼ÊÇĬÈÏÆôÓõģ¬Òò´ËÍøÉϵÄÄÇЩ»¹×Ô¼ºÐ´rfcÖ§³ÖµÄ¶¼¿ÉÒÔÈÓµôÁË:)
###############################
net.inet.ip.sourceroute=0
net.inet.ip.accept_sourceroute=0
#############################
ͨ¹ýԴ·ÓÉ£¬¹¥»÷Õß¿ÉÒÔ³¢ÊÔµ½´ïÄÚ²¿IPµØÖ· --°üÀ¨RFC1918ÖеĵØÖ·£¬ËùÒÔ
²»½ÓÊÜԴ·ÓÉÐÅÏ¢°ü¿ÉÒÔ·ÀÖ¹ÄãµÄÄÚ²¿ÍøÂ类̽²â¡£
#################################
net.inet.tcp.drop_synfin=1
###################################
°²È«²ÎÊý£¬±àÒëÄں˵Äʱºò¼ÓÁËoptions TCP_DROP_SYNFIN²Å¿ÉÒÔÓ㬿ÉÒÔ×èֹijЩOS̽²â¡£
##################################
kern.maxvnodes=8446
#################http://www.bsdlover.cn#########
vnode ÊǶÔÎļþ»òĿ¼µÄÒ»ÖÖÄÚ²¿±í´ï¡£ Òò´Ë£¬ Ôö¼Ó¿ÉÒÔ±»²Ù×÷ϵͳÀûÓÃµÄ vnode ÊýÁ¿½«½µµÍ´ÅÅÌµÄ I/O¡£
Ò»°ã¶øÑÔ£¬ ÕâÊÇÓɲÙ×÷ϵͳ×ÔÐÐÍê³ÉµÄ£¬Ò²²»ÐèÒª¼ÓÒÔÐ޸ġ£µ«ÔÚijЩʱºò´ÅÅÌ I/O »á³ÉΪƿ¾±£¬
¶øÏµÍ³µÄ vnode ²»×㣬 ÔòÕâÒ»ÅäÖÃÓ¦±»Ôö¼Ó¡£´ËʱÐèÒª¿¼ÂÇÊÇ·Ç»îÔ¾ºÍ¿ÕÏÐÄÚ´æµÄÊýÁ¿¡£
Òª²é¿´µ±Ç°ÔÚÓÃµÄ vnode ÊýÁ¿£º
# sysctl vfs.numvnodes
vfs.numvnodes: 91349
Òª²é¿´×î´ó¿ÉÓÃµÄ vnode ÊýÁ¿£º
# sysctl kern.maxvnodes
kern.maxvnodes: 100000
Èç¹ûµ±Ç°µÄ vnode ÓÃÁ¿½Ó½ü×î´óÖµ£¬Ôò½« kern.maxvnodes ÖµÔö´ó 1,000 ¿ÉÄÜÊǸöºÃÖ÷Òâ¡£
ÄúÓ¦¼ÌÐø²é¿´ vfs.numvnodes µÄÊýÖµ£¬ Èç¹ûËüÔÙ´ÎÅÊÉýµ½½Ó½ü×î´óÖµµÄ³Ì¶È£¬
ÈÔÐè¼ÌÐøÌá¸ß kern.maxvnodes¡£ ÔÚ top(1) ÖÐÏÔʾµÄÄÚ´æÓÃÁ¿Ó¦ÓÐÏÔÖø±ä»¯£¬
¸ü¶àÄÚ´æ»á´¦ÓÚ»îÔ¾ (active) ״̬¡£
####################################
kern.maxproc: 964
#################http://www.bsdlover.cn#########
Maximum number of processes
####################################
kern.maxproc
Ïà¹ØÎĵµ£º
±¸·ÝMBR·ÖÇø
0. ±¸·ÝÓ²Å̵ķÖÇøÐÅÏ¢£º
#fdisk /dev/sda -l > /tem/sda.txt
¡¡
¡¡¡¡1.ʹÓÃfdisk -l È·¶¨MBRλÖÃ
¡¡
¡¡¡¡2.±¸·ÝMBR
¡¡
¡¡¡¡dd if=/dev/sda1 of=/root/mbr bs=512 count=1
¡¡
¡¡¡¡3.»Ö¸´MBR
¡¡
¡¡¡¡dd if=/root/mbr of=/dev/sda1 bs=512 count=1
¡¡
¡¡ ......
¹ØÓÚlinuxµÄÎļþȨÏÞ£¬Á˽âÒ»Ïµļ¸¸öÒªµã¾ÍÐÐÁË£¬Ê×ÏÈlinuxÓÐÓû§×éµÄ¸ÅÄÿ¸öÓû§×éÓ÷ÖÅäÓÐÒ»¸öid,ÓÃÓÚΨһµÄ±êʶ£¬¿ÉÒÔÓÃÓÚ·½±ãÖ¸¶¨´ËÓû§×éÖеÄÓû§²Ù×÷ijЩÎļþµÄȨÏÞ¡£Í¬Ñùÿ¸öÓû§Ò²ÓµÓÐÒ»¸öÓû§id£¬ÓÃÓÚΨһ±êʶÓû§£¬¶ø¶ÔÓÚÿ¸öÎļþÓà ls -l -a ¾Í¿ÉÒÔÏÔʾµ±Ç°Ä¿Â¼ÏÂÃæËùÓеÄÎļþÎļþ¼ÐµÄÏêϸÐÅÏ¢¡£ÀýÈ磺ÎÒÃÇÔ ......
Ê×ÏÈ£¬ÄÚ´æµÄ´óСÔÚlinuxÄÚºËÖеĻñÖª·½·¨
1.ͨ¹ýbootloader µÄ tag mem´«Èë¡£
Setup.c Öеĺ¯ÊýÈçÏ£º
static int __init parse_tag_mem32(const struct tag *tag)
{
if (meminfo.nr_banks >= NR_BANKS) {
printk(KERN_WARNING
"Ignoring memory bank 0x%08x size %dKB\n",
tag->u.mem.start, tag->u.mem ......
¶ÔÓںܶàÆÕͨÓû§À´ËµLinuxÊÇÉñÃØµÄ£¬ºÜ¶àÅóÓÑ´Ó½Ó´¥PC¿ªÊ¼½Ó´¥µÄ¾ÍÊÇwindow£¬Ò»ÇÐϰ¹ß¶¼Ô´ÓÚwindow£¬ÅóÓÑLinuxϵͳ¼¸ºõÊøÊÖÎ޲ߣ¨±ÊÕß»ù±¾¾ÍÕâÑù£¬ËùÒÔÔÚŬÁ¦Ñ§Ï°ing…£©£¬ÄÇôLinuxµ½µ×ÄÜ×öЩʲô£¬ÓÖÓÐʲôÓÃÍ¾ÄØ£¿ÈÃÎÒÃÇÀ´Ò»Ì½¾¿¾¹¡£ÊÀ½çÉÏ×î´óµÄ¼¼ÊõÖ§³Ö¡¢Èí¼þºÍÓ²¼þ¹«Ë¾Ã¿ÌìÊ¹Ó ......