服务器安全运维
网络安全运维
数据安全运维
1、账号安全
删除特殊的用户和组:adm,lp,sync,shutdown,halt,news,uucp,operator,games,gopher
adm,lp,news,uucp,games,dip,pppusers,popusers,slipusers
userdel x
groupdel x
usermod -s /sbin/nologin nagios
2、关闭不需要的服务
anacron,auditd,autofs,
data:image/s3,"s3://crabby-images/1b1ab/1b1ab010477063ee78ef879a56b281fa674cac93" alt=""
chkconfig --level 345 bluetooth off
需要开启的服务:
acpid,apmd,kudzu,crond,atd,keytables,iptables,xinetd,xfs,network,sshd,syslog
3、密码安全策略(堡垒机替代)
秘钥认证
密码认证
vi /etc/ssh/sshd_config
data:image/s3,"s3://crabby-images/9b8fc/9b8fc6bb1cfe08d8d39bb1de0784c897ab44c3e3" alt=""
4、su sudo
data:image/s3,"s3://crabby-images/c842e/c842effc99ded5e9d97d721f71a459febe3580b3" alt=""
xx ALL = NOPASSWD: /etc/init.d/nagios restart
超级用户
user02 ALL=(ALL) NOPASSWD: ALL
5、删减登陆信息
6、禁用 alt+control+delete
7、SSH配置修改
更改默认端口
使用协议2 Protocol 2
ListenAddress 0.0.0.0 + allow deny
PermitRootLogin no
MaxAuthTries 3
AllowUsers x y
AllowGroups x y
DenyUsers
DenyGroups x
8、记录详细指令历史:bashrc
data:image/s3,"s3://crabby-images/801eb/801ebd0570bcf263419d5fb7030f28d651ca159d" alt=""
把历史记录保存到特定文件供审计用,\
/etc/profile
data:image/s3,"s3://crabby-images/f607a/f607a89c4efcc883ec2b42b754216913c752935b" alt=""
data:image/s3,"s3://crabby-images/c9e44/c9e44320e229a2673d89466c5adf47d5a3fe9ae7" alt=""
data:image/s3,"s3://crabby-images/73776/73776ddd5d7c67249a241e0348ce469e34f71be0" alt=""
9、tcp_wrappers
/etc/hosts.allow /etc/hosts.deny
sshd,portmap,sendmail,xinetd,vsftpd,tcpd
sshd:xxx
sshd:ip
data:image/s3,"s3://crabby-images/82efc/82efc3cfa49877d759d14b7d53c0714d16df74b6" alt=""
sshd:ALL
data:image/s3,"s3://crabby-images/9bf53/9bf539d27b527c813891e2a7d400cb7724798515" alt=""
10 文件系统安全
chattr +i xxx
data:image/s3,"s3://crabby-images/46711/46711ab0516c96a808edf7a1024fbe1ed11ac1c1" alt=""
data:image/s3,"s3://crabby-images/79451/79451d91bb8791aaaba28bb52cbb4f488883a884" alt=""
11 文件权限检查和修改
data:image/s3,"s3://crabby-images/43b63/43b636275a4baa9436284e46622751495ade7482" alt=""
data:image/s3,"s3://crabby-images/2d696/2d6961f24a6c0e6398db68f1a791b7389fe19770" alt=""
12 定期升级软件
yum check-update
13 每天定时执行rootkit检查
使用RKHunter
data:image/s3,"s3://crabby-images/4fce5/4fce58aed97e91f2467b65f42a0c34160d72a4dc" alt=""
14 服务器遭受攻击后处理方法
切断网络
查找攻击源
分析入侵原因
备份数据
修复漏洞
恢复连接
15、网络安全
NTOP检测网络
iperf检查网络性能
nmap端口扫描
网友评论