Amathiphu okuphepha kuzinhlelo ze-GNU / Linux

Yebo, bengikulungiselela lokhu okuthunyelwe ibhulogi yami isikhathi esithile bangiphakamisela yona ku- DesdeLinux, futhi ngenxa yokushoda kwesikhathi, ubengakwazi noma ethanda. Uma ngivila ngandlela thile 😀. Kepha manje batelekile, njengoba sisho eCuba ...

Lokhu kuhlanganiswa kwemithetho eyisisekelo yokuphepha yabaphathi bohlelo, kulokhu, kulabo abangithandayo baphatha amanethiwekhi / amasistimu asuselwa ku-GNU / Linux ... Kungaba nokuningi futhi empeleni kukhona okuningi, lokhu kuyisampula nje ukuzulazula kwami ​​emhlabeni weLinux ...

0- Gcina amasistimu ethu evuselelwa ngezibuyekezo zakamuva zokuphepha.

0.1- Uhlu Olubalulekile Lwe-imeyiliUmeluleki Wezokuphepha weSlackware, Umeluleki wezokuphepha we-Debian, kimi]

1- Zero ukufinyelela ngokomzimba kumaseva ngabasebenzi abangagunyaziwe.

1.1- Sebenzisa iphasiwedi ku- I-BIOS amaseva ethu

1.2- Ayikho ibhuthi ngeCD / DVD

1.3- Iphasiwedi ku-GRUB / Lilo

2- Inqubomgomo yephasiwedi enhle, izinhlamvu zamagama nezinye.

2.1- Ukuguga kwamaphasiwedi [Ukuguga kwephasiwedi] ngomyalo we “chage”, kanye nenombolo yezinsuku phakathi kokushintshwa kwephasiwedi nosuku lokugcina lokushintsha.

2.2- Gwema ukusebenzisa amaphasiwedi wangaphambilini:

ku /etc/pam.d/common-password

password sufficient pam_unix.so use_auth ok md5 shadow remember 10

Ngakho-ke ushintsha iphasiwedi futhi ikukhumbuza amaphasiwedi wokugcina ayi-10 umsebenzisi abenawo.

3- Inqubomgomo yokuphatha / yokuhlukanisa kahle yenethiwekhi yethu [ama-routers, switch, vlans] kanye ne-firewall, kanye nemithetho yokuhlunga INPUT, OUTPUT, FORWARD [NAT, SNAT, DNAT]

4- Nika amandla ukusetshenziswa kwamagobolondo [/ etc / shells]. Abasebenzisi akudingeki bangene ohlelweni bathola / bin / false noma / bin / nologin.

5- Vimba abasebenzisi lapho ukungena ngemvume kwehluleka [i-faillog], kanye nokulawula i-akhawunti yomsebenzisi wesistimu.

ipasswd -l pepe -> vimba iposi lomsebenzisi ipasswd -v pepe -> vulela iposi lomsebenzisi

6- Nika amandla ukusetshenziswa kwe- "Sudo", UNGALOKOTHI ungene ngemvume njengezimpande nge-ssh, "NEVER". Eqinisweni kufanele uhlele ukumiswa kwe-ssh ukufeza le nhloso. Sebenzisa izinkinobho zomphakathi / eziyimfihlo kumaseva wakho ngeSudo.

7- Sebenzisa ezinhlelweni zethu “Isimiso selungelo elincane".

8- Bheka izinsizakalo zethu ngezikhathi ezithile [netstat -lptun], zeseva ngayinye yethu. Faka amathuluzi wokuqapha angasisiza kulo msebenzi [Nagios, Cacti, Munin, Monit, Ntop, Zabbix].

9- Faka ama-IDS, Snort / AcidBase, Snotby, Barnyard, OSSEC.

10- UNmap ungumngani wakho, yisebenzise ukuhlola ama-subnet / subnet akho.

11- Imikhuba emihle yokuphepha ku-OpenSSH, i-Apache2, i-Nginx, i-MySQL, i-PostgreSQL, i-Postfix, i-squid, i-Samba, i-LDAP [leyo esetshenziswa kakhulu] kanye nenye insizakalo oyidingayo kunethiwekhi yakho.

12- Bethela konke ukuxhumana ngenkathi kungenzeka ezinhlelweni zethu, i-SSL, i-gnuTLS, i-StarTTLS, ukugaya, njll. Futhi uma uphatha imininingwane ebucayi, bhala ngemfihlo i-hard drive yakho !!!

13- Vuselela amaseva ethu eposi ngemithetho yakamuva yezokuphepha, yokuvinjelwa kanye neye-antispam.

14- Ukungena ngemvume komsebenzi ezinhlelweni zethu nge-logwatch kanye nokuhlolwa kokuhlola.

15- Ulwazi nokusetshenziswa kwamathuluzi anjenge top, sar, vmstat, free, phakathi kwabanye.

sar -> umbiko womsebenzi wohlelo vmstat -> izinqubo, inkumbulo, isistimu, i / o, umsebenzi we-cpu, njll iostat -> cpu i / o isimo mpstat -> isimo se-multiprocessor nokusetshenziswa pmap -> ukusetshenziswa kwememori ngezinqubo zamahhala -> iptraf memory -> Ithrafikhi ngesikhathi sangempela se-ethstatus yethu yenethiwekhi -> i-ethernet yezibalo ezisekelwa kukhonsoli eqapha i-etherape -> inethiwekhi yokuqhafaza yenethiwekhi ss -> isimo sesokhethi [i-tcp socket info, udp, amasokhethi aluhlaza, amasokhethi eDCCP] tcpdump -> Ukuhlaziywa okuningiliziwe kwe-traffic vnstat -> Ukuqapha ithrafikhi yenethiwekhi ye-interface ekhethiwe mtr -> ithuluzi lokuxilonga nokuhlaziywa kokugcwala kakhulu kumanethiwekhi ethtool -> izibalo mayelana namakhadi enethiwekhi

Okwamanje kuphelele. Ngiyazi ukuthi kukhona iziphakamiso zokuphepha eziyinkulungwane neyodwa kulolu hlobo lwendawo, kepha lezi yizo ezingithinte kakhulu, noma ukuthi kwesinye isikhathi kuye kwadingeka ngisebenzise / ngivivinye umzimba endaweni engiyiphethe .

Ukwanga futhi ngethemba lokuthi kuzokusebenzela 😀


Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Ubhekele imininingwane: Miguel Ángel Gatón
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.

  1.   I-Koratsuki kusho

    Ngiyakumema emibhalweni ukuthi usitshele ngeminye imithetho esetshenzisiwe ngaphandle kwaleyo esivele ishiwo, ukukhulisa ulwazi lwabafundi bethu 😀

    1.    I-Yukiteru kusho

      Ngingeza kahle:

      1.- Sebenzisa imithetho ye-sysctl ukuvimbela ukufinyelela kwe-dmesg, / proc, i-SysRQ, unikeze i-PID1 kungqangi, unike amandla ukuvikelwa kwama-symlink aqinile futhi athambile, ukuvikelwa kwezitaki ze-TCP / IP kuzo zombili i-IPv4 ne-IPv6, yenza kusebenze i-VDSO ephelele ukuze kusetshenziswe izinkomba ngokuphelele nokwabiwa kwesikhala sememori nokuthuthukisa amandla ngokuqhamuka kokuchichima kwesibambi.

      2.- Dala izindonga zomlilo zohlobo lwe-SPI (Stateful Package Inspect) ukuvikela ukuxhumana okungadalwanga noma obekuvunyelwe ngaphambilini ekubeni nokufinyelela ohlelweni.

      3.- Uma ungenazo izinsizakalo ezivumela ukuxhumana ngamalungelo aphakeme ukusuka endaweni ekude, mane ubuyise ukufinyelela kuzo usebenzisa i-access.conf, noma, uma wehluleka lokho, vumela ukufinyelela kumsebenzisi othile noma iqembu elithile kuphela.

      4.- Sebenzisa imikhawulo enzima ukuvimbela ukufinyelela kumaqembu athile noma abasebenzisi ekulimazeni uhlelo lwakho. Iwusizo kakhulu ezindaweni lapho kukhona umsebenzisi wangempela osebenzayo ngaso sonke isikhathi.

      5.- I-TCPWrappers ingumngani wakho, uma usohlelweni oluyisekelayo, ukuyisebenzisa ngeke kulimaze, ngakho-ke ungaphika ukufinyelela kunoma yimuphi umphathi ngaphandle kokuthi kwakulungiselelwe ngaphambilini ohlelweni.

      6.- Dala okhiye be-SSH RSA okungenani ama-bits angama-2048 noma okungcono ngamabhithi angama-4096 ngezinkinobho ze-alphanumeric zezinhlamvu ezingaphezu kwe-16.

      7.- Ubhaleka kangakanani emhlabeni? Ukuhlola izimvume zokufundwa kokubhalwa kwezinkomba zakho akukubi nakancane futhi kuyindlela engcono yokugwema ukufinyelela okungagunyaziwe ezindaweni zabasebenzisi abaningi, ingasaphathwa eyokuthi kwenza kube nzima kakhulu ukufinyelela okuthile okungagunyaziwe ukuthola ukufinyelela olwazini olwenza akekho omunye umuntu obonayo.

      8. - Beka noma yikuphi ukwahlukanisa kwangaphandle okungakufaneli, ngezinketho noexec, nosuid, nodev.

      9.- Sebenzisa amathuluzi afana ne-rkhunter ne-chkrootkit ukuhlola ngezikhathi ezithile ukuthi isistimu ayinayo i-rootkit noma i-malware efakiwe. Isinyathelo esihlakaniphile uma ungomunye walabo abafaka izinto kusuka kumakhosombe angavikelekile, avela kuma-PPAs, noma bamane baphile ngokuhlanganisa ikhodi kusuka kumasayithi angathembekile.

      1.    I-Koratsuki kusho

        Uhmmm, okumnandi… Amazwana amahle, engeza abafana… 😀

    2.    UWilliam Moreno Reyes kusho

      Faka isicelo sokulawulwa kokufinyelela okugunyaziwe nge-SElinux?

  2.   U-ArmandoF kusho

    i-athikili enhle kakhulu

    1.    I-Koratsuki kusho

      Ngiyabonga mngani 😀

  3.   joako kusho

    Sawubona futhi uma ngingumsebenzisi ojwayelekile, kufanele ngisebenzise i-su noma i-Sudo?
    Ngisebenzisa su ngoba angithandi iSudo, ngoba noma ngubani onephasiwedi yami yomsebenzisi angashintsha noma yini ayifunayo ohlelweni, esikhundleni salokho nge su no.

    1.    I-Koratsuki kusho

      Ku-PC yakho akukhathazi ukusebenzisa i-su, ungayisebenzisa ngaphandle kwezinkinga, kumaseva, kunconywa kakhulu ukukhubaza ukusetshenziswa kwe-su nokusebenzisa i-Sudo, abaningi bathi kungenxa yeqiniso lokucwaninga ukuthi ngubani owenze lokho umyalo noSudo benza lowo msebenzi ... Mina ikakhulukazi, kwi-pc yami ngisebenzisa eyakhe, njengawe ...

      1.    joako kusho

        Impela, angazi ngempela ukuthi isebenza kanjani kumaseva. Noma, kubonakala kimi ukuthi uSudo wayenethuba lokuthi unganikeza amalungelo kumsebenzisi wenye ikhompyutha, uma ngingaphosisi.

    2.    U-Andrew kusho

      I-athikili ethokozisayo, ngibhala ngemfihlo amanye amafayela nge-gnu-gpg, njengaleyo yelungelo eliphansi, uma kwenzeka ufuna ukwenza, ngokwesibonelo, i-kanambambili yemvelaphi engaziwa elahlekile olwandle olukhulu lolwazi kwidiski, ngilisusa kanjani ukufinyelela emisebenzini ethile?

      1.    I-Koratsuki kusho

        Ngikukweleta leyo ngxenye, yize ngicabanga ukuthi kufanele usebenzise kuphela njenge-Sudo / impande, izinhlelo ezinokwethenjelwa, okungukuthi, zivela ku-repo yakho ...

      2.    I-Yukiteru kusho

        Ngikhumbula ngifunda ukuthi kunendlela yokunika amandla amandla empande kubhukwana elithile ku-GNU / Linux naku-UNIX, uma ngikuthola ngizokubeka 😀

      3.    clown kusho

        namakheji e-chown ukusebenzisa ama-binaries angaziwa?

    3.    I-Yukiteru kusho

      Sebenzisa iSudo ngaso sonke isikhathi kungcono kakhulu.

    4.    izinga kusho

      Noma ungasebenzisa iSudo, kepha ubeke umkhawulo esikhathini lapho kukhunjulwa khona iphasiwedi.

  4.   UKevin Rodriguez kusho

    Amathuluzi afanayo engiwasebenzisa ukuqapha i-pc, "iotop" esikhundleni se- "iostat", "htop" omuhle kakhulu "umphathi womsebenzi", "iftop" bandwidth monitoring.

  5.   i-monitolinux kusho

    abaningi bazokholwa ukuthi lokhu kuyihaba, kepha sengikubonile ukuhlaselwa ukufaka i-server kwi-botnet.

    https://twitter.com/monitolinux/status/594235592260636672/photo/1

    ps: Abancengi baseChina kanye nemizamo yabo yokugenca isiphakeli sami.

  6.   clown kusho

    okuthile okulula futhi ukusebenzisa amakheji e-chown ezinsizakalweni, ngakho-ke uma ngasizathu simbe behlaselwa bebengeke balulaze uhlelo.

  7.   Isifo sikashukela kusho

    Ukusebenzisa umyalo we-ps nakho kuhle kakhulu ekuqapheni futhi kungaba yingxenye yezenzo zokubheka amaphutha okuphepha. ukusebenzisa i-ps -ef kuklelisa zonke izinqubo, kuyefana nokwaphezulu kepha kukhombisa umehluko othile. ukufaka i-iptraf ngelinye ithuluzi elingasebenza.

  8.   UClaudio J. Concepción Certad kusho

    Umnikelo omuhle.

    Ngingeza: i-SELinux noma i-Apparmor, ngokuya nge-distro, ihlala inikwe amandla.

    Ngokwami ​​ukubona ngabona ukuthi kuwumkhuba omubi ukukhubaza lezo zinto. Cishe ngaso sonke isikhathi siyakwenza lapho sizofaka noma silungiselela insiza, ngezaba zokuthi isebenza ngaphandle kwezinkinga, lapho empeleni okufanele sikwenze ukufunda ukubaphatha ukuvumela leyo nsizakalo.

    A ukubingelela.

  9.   IGnuLinux ?? kusho

    1.Ungayibhala kanjani lonke uhlelo lwefayela? kuyakufaneleka??
    Ngabe kufanele isuswe ukubethela njalo lapho uhlelo luzobuyekezwa?
    3. Ingabe ukubhala ngemfihlo lonke uhlelo lwefayela lomshini kuyefana nokubethela noma yiliphi elinye ifayela?

    1.    I-Yukiteru kusho

      Wazi kanjani ukuthi uyakwazi lokhu okhuluma ngakho?

  10.   I-NauTiluS kusho

    Futhi, ungafaka izinhlelo zezinyoni ngisho nabasebenzisi abaningi. Yize ukwenza lokhu kungumsebenzi owengeziwe, kepha uma kukhona okwenzekile, futhi ube nekhophi langaphambilini laleyo folda, kumane kushaya futhi kuyaculwa.

  11.   ithoni kusho

    Inqubomgomo yezokuphepha ehamba phambili futhi elula kunazo zonke akumele iphazamise.
    Kuzame, akunaphutha.

  12.   izingelosi kusho

    Ngisebenzisa i-csf futhi lapho ngivula iklayenti elifake kabi iphasiwedi yalo kokunye ukufinyelela, libambezela inqubo kepha liyakwenza. Kuyinto evamile?

    Ngifuna umyalo wokuvula ku-ssh ... noma yisiphi isiphakamiso