4. vsFTPd°²È«ÉèÖÃ
vsFTPdÊÇÒ»¿î·Ç³£ÖøÃûµÄftp daemon³ÌÐò£¬Ä¿Ç°°üÀ¨Redhat.comÔÚÄںܶà´ó¹«Ë¾¶¼ÔÚʹÓã¬ËüÊÇÒ»¿î·Ç³£°²È«µÄ³ÌÐò£¬ÒòΪËüµÄÃû×־ͽУºVery Secure FTP Daemon (·Ç³£°²È«µÄFTP·þÎñÆ÷)¡£
vsftpdÉèÖÃÑ¡Ïî±È½Ï¶à£¬Éæ¼°·½·½ÃæÃ棬ÎÒÃÇÏÂÃæÖ÷ÒªÊÇÕë¶Ô°²È«·½Ãæ½øÐÐÉèÖá£
ĿǰÎÒÃǵÄÐèÇó¾ÍÊÇʹÓÃϵͳÕÊ»§Í¬Ê±Ò²×÷ΪÊÇÎÒÃǵÄFTPÕÊ»§À´½øÐÐÎÒÃÇÎļþµÄ¹ÜÀí£¬Ä¿Ç°¼ÙÉèÎÒÖ»ÐèÒªÒ»¸öÕÊ»§À´¸üÐÂÎÒµÄÍøÕ¾£¬²¢ÇÒÎÒ²»Ï£Íû¸ÃÕÊ»§Äܹ»µÇ½ÎÒÃǵÄϵͳ£¬±ÈÈçÎÒÃǵÄÍøÕ¾µÄĿ¼ÊÇÔÚ/usr/wwwÏÂÃæ£¬ÄÇôÎÒÃÇн¨Ò»¸öÓû§ftp£¬ËüµÄÖ÷Ŀ¼ÊÇ/usr/www£¬²¢ÇÒËüµÄshellÊÇ /usr/sbin/nologin£¬¾ÍÊÇûÓÐshell£¬·ÀÖ¹¸ÃÓû§Í¨¹ýsshµÈµÇ½µ½ÏµÍ³¡£
ÏÂÃæÔÚ½øÐÐϵͳÏ꾡µÄÉèÖã¬Ö÷Òª¾ÍÊÇÕë¶ÔvsftpdµÄÅäÖÃÎļþvsftpd.confÎļþµÄÅäÖá£
(1) ½ûÖ¹ÄäÃûÓû§·ÃÎÊ, ÎÒÃDz»ÐèҪʲôÄäÃûÓû§£¬Ö±½Ó½ûÖ¹µô£º
anonymous_enable=NO
(2) ÔÊÐí±¾µØÓû§µÇ½£¬ÒòΪÎÒÃÇÐèҪʹÓÃftpÓû§À´¶ÔÎÒÃÇÍøÕ¾½øÐйÜÀí:
local_enable=YES
(3) Ö»ÔÊÐíϵͳÖеÄftpÓû§»òÕßijЩָ¶¨µÄÓû§·ÃÎÊftp£¬ÒòΪϵͳÖÐÕÊ»§Öڶ࣬²»¿ÉÄÜÈÃ˶¼·ÃÎÊ¡£
´ò¿ªÓû§ÎļþÁÐ±í¹¦ÄÜ£º
userlist_enable=YES
Ö»ÔÊÐíÓû§ÎļþÁбíÖеÄÓû§·ÃÎÊftp:
userlist_deny=NO
Óû§ÃûÎļþÁбí·¾¶£º
userlist_file=/etc/vsftpd.user_list
È»ºóÔÚ/etcϽ¨Á¢Îļþ vsftpd.user_list Îļþ£¬Ò»ÐÐÒ»¸ö£¬°ÑÓû§ftp¼Ó½øÈ¥£¬Í¬Ê±Ò²¿ÉÒÔ¼ÓÉÏÄãÔÊÐí·ÃÎʵÄϵͳÕÊ»§Ãû¡£
(4) ½ûֹijЩÓû§µÇ½ftp:
pam_service_name=vsftpd
Ö¸³öVSFTPD½øÐÐPAMÈÏ֤ʱËùʹÓõÄPAMÅäÖÃÎļþÃû£¬Ä¬ÈÏÖµÊÇvsftpd£¬Ä¬ÈÏPAMÅäÖÃÎļþÊÇ/etc/pam.d/vsftpd¡£
/etc/vsftpd.ftpusers
VSFTPD½ûÖ¹ÁÐÔÚ´ËÎļþÖеÄÓû§µÇ¼FTP·þÎñÆ÷£¬Óû§ÃûÊÇÒ»ÐÐÒ»¸ö¡£Õâ¸ö»úÖÆÊÇÔÚ/etc/pam.d/vsftpdÖÐĬÈÏÉèÖõġ£
Õâ¸ö¹¦ÄܺÍ(3)ÀïµÄ¹¦ÄÜÓеãÀàËÆ£¬ËûÃÇÁ©ÄܽáºÏʹÓã¬ÄÇÑù¾Í×îºÃÁË¡£
(5) °Ñ±¾µØÓû§Ëø¶¨ÔÚ×Ô¼ºµÄÖ÷Ŀ¼£¬·Àֹתµ½ÆäËûĿ¼£¬±ÈÈç°Ñ/etc/passwd¸øÏÂÔØÁË:
chroot_local_users=NO
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd.chroot_list
È»ºóÔÚ/etcϽ¨Á¢vsftpd.chroot_listÎļþ£¬ÀïÃæ°ÑÎÒÃÇÒªÏÞÖÆµÄ±¾µØÕÊ»§¼Ó½øÈ¥£¬Ò»ÐÐÒ»¸ö£¬ÎÒÃǼÓÉÏftp£¬·ÀÖ¹ËüµÇ½µ½ÏµÍ³¡£
(6) Òþ²ØÎļþÕæÊµµÄËùÓÐÓû§ºÍ×éÐÅÏ¢£¬·ÀÖ¹ºÚ¿ÍÄÃÏÂftpºó²é¿´¸ü¶àϵͳÓû§ÐÅÏ¢£º
hide_ids=YES
(7) È¡Ïûls -RÃüÁ½ÚÊ¡×ÊÔ´£¬ÒòΪʹÓøÃÃüÁÔÚÎļþÁбíºÜ¶àµÄʱºò½«ÀË·Ñ´óÁ¿ÏµÍ³×ÊÔ´£º
ls_recurse_enable=NO
( ÉÏ´«ÎļþµÄĬÈÏȨÏÞ£¬ÉèÖÃΪ022£º
local_umask=022
Èç¹ûÒª¸²¸Çɾ³ýµÈ£¬»¹Òª´ò¿ª£º
write_enable=YES
(9) ftpµÄbannerÐÅÏ¢£¬ÎªÁË·ÀÖ¹ºÚ¿Í»ñÈ¡¸ü¶à·þÎñÆ÷µÄÐÅÏ¢£¬ÉèÖøÃÏ
ftpd_banner=banner string
°ÑºóÃæµÄbanner stringÉèΪÄãÐèÒªµÄbannerÌáʾÐÅÏ¢£¬ÎªÁ˰²È«£¬½¨Òé²»Òª±©Â¶¹ØÓÚvsFTPdµÄÈκÎÐÅÏ¢¡£
ÁíÍ⣬Èç¹ûÄãµÄÐÅÏ¢±È½Ï¶àµÄ»°£¬¿ÉÒÔÉèÖÃΪÌáʾÐÅÏ¢ÊǶÁȡһ¸öÎļþÖеÄÐÅÏ¢£º
banner_file=/directory/vsftpd_banner_file
(10) ´ò¿ªÈÕÖ¾¹¦ÄÜ£º
xferlog_enable=YES
ͬʱÉèÖÃÈÕÖ¾µÄĿ¼£º
xferlog_file=/var/log/vsftpd.log
ÆôÓÃÏêϸµÄÈÕÖ¾¼Ç¼¸ñʽ£º
xferlog_enable=YES
(11) Èç¹û´ò¿ªÐéÓû§¹¦Äܵȣ¬ÄÇô½¨Ò鹨±Õ±¾µØÓû§µÇ½£º
local_enable=NO
vsFTPd»¹ÓкܶలȫÉèÖ㬱Ͼ¹È˼ҵÄÃû×Ö¾ÍÊÇ£ºVery Secure FTP Daemon£¬·´ÕýËüµÄÒç³ö©¶´Ê²Ã´µÄÊǺÜÉٵģ¬Èç¹ûÒª¸ü°²È«£¬½¨Òé°´ÕÕ×Ô¼ºµÄÐèÒªÉèÖÃvsftpd£¬ÉèÖõĺã¬Ëü¾ø¶ÔÊÇ×ȫµÄ¡£
5. SSH°²È«ÉèÖÃ
SSHÊÇÒ»¸ö»ùÓÚSSLµÄ°²È«Á¬½ÓÔ¶³Ì¹ÜÀíµÄ·þÎñ³ÌÐò,Ö÷Òª³öÏÖ¾ÍÊÇΪÁ˽â¾ötelnet¡¢rlogin¡¢rshµÈ³ÌÐòÔÚ³ÌÐò½»»¥¹ý³ÌÖдæÔÚÃ÷ÎÄ´«ÊäÒ×±»¼àÌýµÄÎÊÌâ¶ø²úÉúµÄ£¬Ä¿Ç°»ù±¾ÉÏÊÇÍÆ¼öʹÓÃsshÀ´´úÌætelnet¡¢rlogin¡¢rshµÈÔ¶³Ì¹ÜÀí·þÎñ¡£
sshÄܹ»Ö±½ÓÔÚwindowsƽ̨ÏÂͨ¹ýSecure SSH ClientµÈ¿Í»§¶Ë¹¤¾ß½øÐÐÁ¬½Ó¹ÜÀí£¬Ä¿Ç°×îÁ÷ÐеķþÎñÆ÷¶Ë¾ÍÊÇOpenSSH³ÌÐò£¬Ä¿Ç°×îа汾ÊÇOpenSSH4.0°æ£¬Ïêϸ¿ÉÒԲο¼
www.openssh.comÍøÕ¾¡£
OpenSSHÔÚFreeBSDÏÂÒѾ¼¯³É°²×°ÁË£¬FreeBSD5.3ϵÄOpenSSH°æ±¾ÊÇ3.8.1£¬½¨ÒéportsÉý¼¶µ½4.0¡£
Ö÷ÒªµÄ°²È«ÅäÖÃÎļþÊÇ/etc/ssh/sshd_configÎļþ£¬ÎÒÃDZ༸ÃÎļþ¡£
(1) ʹÓÃprotocol 2´úÌæprotocol 1£¬SSH2¸ü¼Ó°²È«£¬¿ÉÒÔ·ÀÖ¹¹¥»÷Õßͨ¹ýÐÞ¸ÄЯ´øµÄ°æ±¾bannerÀ´½Ù³Ö£¨hijacking£©Æô¶¯»á»°½ø³Ì²¢½µµÍµ½protocol 1¡£×¢Ê͵ôprotocol 2,1 ¸ÄÓÃÏÂÃæÓï¾ä´úÌæ£º
protocol 2
(2) ºÏÀíÉèÖÃ×î´óÁ¬½ÓÊýÁ¿£¬ ·ÀÖ¹DOS¹¥»÷
¡¡¡¡MaxStartups 5:50:10
(3)¹Ø±ÕX11forwording £¬·ÀÖ¹»á»°½Ù³Ö
¡¡¡¡X11Forwarding no
(4)½¨Ò鲻ʹÓþ²Ì¬ÃÜÂ룬¶øÊ¹ÓÃDSA »òRSA KEY£¬ÐÞ¸ÄÈçÏÂÄÚÈÝ¿ÉÒԹرÕʹÓÃÃÜÂëÈÏÖ¤£º
¡¡¡¡PasswordAuthentication no
(5)¿ÉÒÔÏÞ֯ij¸ö×é»ò¹âÊǵ¥¸öÓû§·ÃÎÊshell
¡¡¡¡AllowGroups wheel
»òÕß
¡¡¡¡AllowUsers heiyeluren
(6) ÏÞÖÆrootÓû§µÇ½£¬Ö÷ÒªÊÇΪÁË·ÀÖ¹±©Á¦ÆÆ½â
PermitRootLogin no
(7) ²»ÔÊÐí¿ÚÁîΪ¿ÕµÄÓû§µÇ½
PermitEmptyPasswords no
(ʹÓÃTCP wrappersÀ´ÏÞÖÆÒ»Ð©·ÃÎÊ£¬ÐÞ¸Ä/etc/hosts.allowÎļþ£¬×¢Ê͵ô"ALL : ALL : allow"£¬Ôö¼ÓÈçÏÂÄÚÈÝ£º
¡¡¡¡sshd:localhost:allow
¡¡¡¡sshd:friendlcomputer:allow
¡¡¡¡sshd:all : deny
¡¡¡¡#Ïà¹ØÃüÁ
¡¡¡¡#chsh -s /sbin/nologin user
ËÄ¡¢·À»ðǽµÄ°²×°ºÍÉèÖÃ
FreeBSD×Ô´øÓÐÒ»¸ö»ùÓÚ°ü¹ýÂ˵ķÀ»ðǽ--ipfw£¬ËäÈ»¹¦ÄÜûÓÐרҵ·À»ðǽÄÇôǿ´ó£¬µ«ÊÇÓ¦¸¶Ò»¸öWebÕ¾µãµÄ°²È«»¹ÊÇ×ã¹»µÄ£¬ËùÒÔÎÒÃǾö¶¨Ñ¡Óø÷À»ðǽÀ´±£»¤ÎÒÃǵÄWeb·þÎñÆ÷¡£
1. °²×°ipfw
IPFW µÄÖ÷Òª²¿·ÖÊÇÔÚÄÚºËÖÐÔËÐеģ¬ Òò´Ë»áÐèÒªÔÚFreeBSDÄÚºËÅäÖÃÎļþÖÐÌí¼Ó²¿·ÖÑ¡Ïî¡££¨×¢Ò⣬Èç¹ûÄãûÓа²×°FreeBSDºËÐÄÔ´´úÂ룬ÊÇÎÞ·¨½øÈëÒÔÏÂĿ¼µÄ£¬ËùÒÔÔËÐÐ֮ǰһ¶¨ÒªÏȰ²×°ÄÚºËÔ´´úÂ룩ÎÒÃÇÏȽøÈëÄÚºËÅäÖÃÎļþ£º
# cd /sys/i386/conf
# cp GENERIC ./kernel_fw
´ò¿ªÄÚºËÅäÖÃÎļþ£º
# ee ./kernel_fw
Ìí¼ÓËĸöÑ¡Ï²»ÐèÒªºóÃæµÄ×¢ÊÍÐÅÏ¢£º
options IPFIREWALL # ½«°ü¹ýÂ˲¿·ÖµÄ´úÂë±àÒë½øÄںˡ£
options IPFIREWALL_VERBOSE
# ÆôÓÃͨ¹ýsyslogd¼Ç¼µÄÈÕÖ¾¡£Èç¹ûûÓÐÖ¸¶¨Õâ¸öÑ¡Ï¼´Ê¹ÄúÔÚ¹ýÂ˹æÔòÖÐÖ¸¶¨¼Ç¼°ü£¬ Ò²²»»áÕæµÄ¼Ç¼ËüÃÇ
options IPFIREWALL_VERBOSE_LIMIT=10
# ÏÞÖÆÍ¨¹ý syslogd( ¼Ç¼µÄÿÏî°ü¹æÔòµÄ¼Ç¼ÌõÊý¡£ÔÚ¶ñÁӵĻ·¾³ÖÐÈç¹ûÄúÏë¼Ç¼·À»ðǽµÄ»î¶¯£¬ ¶øÓÖ²»ÏëÓÉÓÚ syslog ºéˮһ°ãµÄ¼Ç¼¶øµ¼Ö¾ܾø·þÎñ¹¥»÷£¬ ÄÇôÕâ¸öÑ¡Ï»áºÜÓÐÓá£
options IPFIREWALL_DEFAULT_TO_ACCEPT
# Õ⽫°ÑĬÈϵĹæÔò¶¯×÷´Ó ``deny'' ¸ÄΪ ``allow''¡£Õâ¿ÉÒÔ·ÀÖ¹ÔÚûÓÐÅäÖ÷À»ðǽ֮ǰʹÓÃÆôÓùý IPFIREWALL Ö§³ÖµÄÄÚºËÖØÆôʱ°Ñ×Ô¼ºËøÔÚÍâÃæ¡£ ÁíÍ⣬ Èç¹ûÄú¾³£Ê¹Óà ipfw( À´½â¾öһЩÎÊÌâʱËüÒ²·Ç³£ÓÐÓᣠ¾¡¹ÜÈç´Ë£¬ÔÚʹÓÃʱӦ¸ÃСÐÄ£¬ÒòΪÕ⽫ʹ·À»ðǽ³¨¿ª£¬ ²¢¸Ä±äËüµÄÐÐΪ¡£
±àÒëÄںˣº
# /usr/sbin/config kernel_fw
# cd ../compile/kernel_fw (×¢ÒâÄãµÄ°æ±¾£¬Èç¹ûÊǵÍÓÚ5.0µÄ°æ±¾ÓÃ../../compile/kernel_fw)
# make depend
# make
# make install
ÖØÆôϵͳ¡£×¢Ò⣬ÎÒÃÇûÓÐÑ¡Ôñoptions IPFIREWALL_DEFAULT_TO_ACCEPT¸ÃÑ¡Ï¾ÍÊÇ˵ĬÈÏϵͳÆô¶¯ºóÊÇ´ò¿ª·À»ðǽµÄ£¬²¢ÇÒ·À»ðǽĬÈÏÊDz»ÔÊÐíÈκÎÁ¬½ÓµÄ(deny from any to any)£¬ËùÒÔÒ»¶¨ÒªÔÚ±¾µØ²Ù×÷£¬·ñÔòÄ㽫±»¡°ËøÔÚÃÅÍ⡱£¬Èç¹ûÄãÑ¡ÔñÁ˸ÃÑ¡ÏîÔò¿ÉÒÔʹÓÃsshµÈÁ¬½Ó²»ÊÜÓ°Ï죬²»¹ýÕâÏà¶Ô²»°²È«¡£
2. ÅäÖÃipfw
Èç¹ûÅäÖÃÆÕͨÇé¿öÏµĹæÔò£¬Ê¹ÓÃÃüÁîÅäÖõÄģʽ£º
ipfwµÄÅäÖÃÃüÁipfw [-N] ÃüÁî [±àºÅ] ¶¯×÷ [log(ÈÕÖ¾)] ÐÒé µØÖ· [ÆäËüÑ¡Ïî]
ÀýÈ磺
# ipfw add allow tcp from any to 10.10.10.1 80 #ÔÊÐíÍâ½ç·ÃÎÊÎÒµÄweb·þÎñ
# ipfw add allow tcp from any to 10.10.10.1 21 #ÔÊÐíÍâÃæ·ÃÎÊÎÒµÄftp·þÎñ
# ipfw add allow tcp from any to 10.10.10.1 22 #ÔÊÐíÍâ½ç·ÃÎÊÎÒµÄssh·þÎñ
Èç¹ûʹÓùæÔò°üµÄÐÎʽ£¬ÄÇô²é¿´ÏÂÃæÄÚÈÝ¡£
ϵͳÆô¶¯ºó£¬ÎÒÃÇ»¹ÒªÅäÖÃrc.confÎļþÀ´ÔËÐÐÎÒÃǵķÀ»ðǽ£º
# ee /etc/rc.conf
¼ÓÈëÈçÏÂÄÚÈÝ£º
gateway_enable="YES" # Æô¶¯Íø¹Ø
firewall_enable="YES" # ¼¤»îfirewall·À»ðǽ
firewall_script="/etc/rc.firewall" # firewall·À»ðǽµÄĬÈϽű¾
firewall_type="/etc/ipfw.conf" # firewall×Ô¶¨Òå½Å±¾
firewall_quiet="NO" # ÆðÓýű¾Ê±£¬ÊÇ·ñÏÔʾ¹æÔòÐÅÏ¢¡£ÏÖÔÚΪ¡°NO¡±¼ÙÈçÄãµÄ·À»ðǽ½Å±¾ÒѾ¶¨ÐÍ£¬ÄÇô¾Í¿ÉÒÔ°ÑÕâÀïÉèÖóɡ°YES¡±ÁË¡£
firewall_logging_enable="YES" # ÆôÓÃfirewallµÄlog¼Ç¼¡£
ÉèÖÃÍê³ÉºóÎÒÃÇÔÙ±à¼/etc/syslog.confÎļþ£º
# ee /etc/syslog.conf
¼ÓÈëÒÔÏÂÐУº
!ipfw
*.* /var/log/ipfw.log
ÏÖÔÚµ½ÁË×îÖØÒªµÄ±à¼¹æÔò°üÁË£º
# ee /etc/ipfw.conf
ÎÒÃÇÌí¼ÓһϹæÔò£º(×¢Òâ 10.10.10.1ÊÇÎÒÃÇ·þÎñÆ÷µÄIP)
######### TCP ##########
add 00001 deny log ip from any to any ipopt rr
add 00002 deny log ip from any to any ipopt ts
add 00003 deny log ip from any to any ipopt ssrr
add 00004 deny log ip from any to any ipopt lsrr
add 00005 deny tcp from any to any in tcpflags syn,fin
# Õâ5ÐÐÊǹýÂ˸÷ÖÖɨÃè°ü
add 10001 allow tcp from any to 10.10.10.1 80 in # ÏòÕû¸öInternet¿ª·Åhttp·þÎñ¡£
add 10002 allow tcp from any to 10.10.10.1 21 in # ÏòÕû¸öInternet¿ª·Åftp·þÎñ¡£
add 10000 allow tcp from 1.2.3.4 to 10.10.10.1 22 in
# ÏòInternetµÄxx.xx.xx.xxÕâ¸öIP¿ª·ÅSSH·þÎñ¡£Ò²¾ÍÊÇÖ»ÐÅÈÎÕâ¸öIPµÄSSHµÇ½¡£
# Èç¹ûÄãµÇ½·þÎñÆ÷µÄIP²»¹Ì¶¨£¬ÄÇô¾ÍÒªÉèΪ£ºadd 10000 allow tcp from any to 10.10.10.1 22 in
add 19997 check-state
add 19998 allow tcp from any to any out keep-state setup
add 19999 allow tcp from any to any out #ÕâÈý¸ö×éºÏÆðÀ´ÊÇÔÊÐíÄÚ²¿ÍøÂç·ÃÎʳöÈ¥£¬Èç¹ûÏë·þÎñÆ÷×Ô¼º²»ºÍInternet½øÐÐtcpÁ¬½Ó³öÈ¥£¬¿ÉÒÔ°Ñ19997ºÍ19998È¥µô¡££¨²»Ó°ÏìInternet¶Ô·þÎñÆ÷µÄ·ÃÎÊ£©
########## UDP ##########
add 20001 allow udp from any 53 to 10.10.10.1 # ÔÊÐíÆäËûDNS·þÎñÆ÷µÄÐÅÏ¢½øÈë¸Ã·þÎñÆ÷£¬ÒòΪ×Ô¼ºÒª½øÐÐDNS½âÎöÂï~
add 29999 allow udp from any to any out # ÔÊÐí×Ô¼ºµÄUDP°üÍùÍâ·¢ËÍ¡£
########## ICMP #########
add 30000 allow icmp from any to any icmptypes 3
add 30001 allow icmp from any to any icmptypes 4
add 30002 allow icmp from any to any icmptypes 8 out
add 30003 allow icmp from any to any icmptypes 0 in
add 30004 allow icmp from any to any icmptypes 11 in
#ÔÊÐí×Ô¼ºping±ðÈ˵ķþÎñÆ÷¡£Ò²ÔÊÐíÄÚ²¿ÍøÂçÓÃrouterÃüÁî½øÐзÓɸú×Ù¡£
Îå¡¢Unix/LinuxÉϵĺóÃż¼ÊõºÍ·À·¶
¶ÔºÚ¿ÍÀ´½²£¬ÈëÇÖÒ»¸öϵͳֻÊÇÍòÀﳤÕ÷µÄ¿ªÊ¼£¬×îÖ÷ÒªµÄÊdz¤ÆÚÕ¼ÓÐÒ»¸öÈ⼦£¨¿þÀÜ»ú£©£¬ËùÒÔ£¬ºóÃż¼ÊõÍùÍù·Ç³£ÖØÒª¡£¶ÔÓÚÎÒÃÇÀ´½²£¬×ÜÊÇ´¦ÓÚ±»¶¯µÄµØÎ»£¬°ÙÃÜÒ»Ê裬×ÜÓÐûÓÐ×öµ½Î»µÄµØ·½£¬Ë¶¼²»Äܱ£Ö¤×Ô¼ºµÄϵͳÊǾø¶Ô°²È«µÄ£¬ËùÒÔ²»ÄܱÜÃâÎÒÃÇ¿ÉÄܻᱻÈëÇÖ¡£ºÚ¿ÍÈëÇÖºó¿Ï¶¨»áÁôºóÃÅ£¬µ±È»£¬³ýÁËÄÇЩ¸ßÊÖ£¬¾³½ç·Ç³£¸ß£¬ÈëÇÖÖ»ÊÇΪÁ˲âÊÔ»òÕß¼¼ÊõÌôÕ½£¬¶ÔÓÚÒ»°ãºÚ¿ÍÀ´½²£¬ÈëÇÖÖ®ºóÁô¸öºóÃÅÊǺÜÖØÒªµÄ£¬ÎÒÃÇÒª·À·¶£¬µ±È»¾ÍÒªÁ˽ⳣÓõĺóÃż¼Êõ£¬ÏÂÃæ¾Í¼òµ¥µÄ½²½«ÔÚ Unix/LinuxϵͳÖбȽϳ£¼ûµÄºóÃż¼Êõ¡£
1. ÕʺźóÃÅ
×îÆÕͨºÍÔʼµÄºóÃż¼Êõ£¬Ò»°ã¾ÍÊÇÔÚϵͳÖÐÌí¼ÓÒ»¸ö¹ÜÀíÔ±ÕÊ»§¡£
# echo "heiyeluren:*:0:0::/root:/bin/sh" >;>; /etc/passwd
# echo "heiyeluren::0:0::0:0::/root:/bin/sh" >;>; /etc/shadow
¸øÏµÍ³Ôö¼ÓÒ»¸ö uidºÍgid¶¼Îª0£¨root)µÄÕʺţ¬ÎÞ¿ÚÁî¡£
FreeBSDµÄÃÜÂëÊÇ´æ´¢ÔÚ /etc/master.passwdÀïÃæµÄ£¬ÄÇôºóÃæµÄÃüÁî¾ÍÓ¦¸Ã¸Ä³É:
# echo "heiyeluren:::::::::" >;>; /etc/master.passwd
Ò²¿ÉÒÔʹÓóÌÐòÀ´ÊµÏÖ:
/* Add super user */
#include "stdio.h"
#define PASSWD_PATH "/etc/passwd"
#define SHADOW_PATH "/etc/master.passwd"
main()
{
FILE *fd;
fd = fopen(PASSWD_PATH, "a+";
fprintf(fd, "heiyeluren:*:0:0::/root:/bin/sh\n";
fclose(fd);
fd = fopen(SHADOW_PATH, "a+";
fprintf(fd, "heiyeluren::0:0::0:0::/root:/bin/sh\n";
fclose(fd);
}
# gcc -o adduser adduser.c
# ./adduser
ÕâÖÖ·½·¨±È½Ïɵ£¬Ò»°ã±È½ÏÈÝÒ×·¢ÏÖ£¬ÌرðÊÇϵͳÕÊ»§²»¶àµÄʱºò¡£Ò²ÓеÄÓû§ÃûÆðµÄ±È½ÏÃÔ»óÈË£¬±ÈÈçÆð¸ör00tµÄÓû§Ãû£¬uidºÍgid¶¼ÊÇ0£¬ÕâÑùÈç¹û²»×¢Ò⣬¿ÉÄܾͻᱻÃÉ»ì¹ý¹ØÁË¡£
* ·À·¶·½·¨£º
ÕâÖÖ·½·¨ËäÈ»±È½ÏÈÝÒ×·¢ÏÖ£¬µ«ÊÇÎÒÃÇ»¹ÊÇÒª·À·¶£¬Òª¶à×¢Òâ¹Û²ìϵͳµÄÕÊ»§Çé¿ö£¬±¾À´ÎÒÃÇϵͳÕÊ»§¾Í²»¶à£¬¼ì²éÆðÀ´±È½Ï·½±ã£¬ÁíÍâҲҪעÒâÄÇЩ±È½ÏÉÙʹÓõÄÕÊ»§ÊDz»ÊDZ»¸ü¸Ä¹ý£¬±ÈÈçĬÈϵÄÕÊ»§ÓÐbind£¬ËüµÄshellÊÇ /usr/sbin/nologin£¬¾ÍÊDz»ÄܵǽµÄ£¬µ«ÊǺڿÍÈëÇÖºó°ÑËü¸ÄÁË£¬±ÈÈç¸ÄΪ/bin/csh£¬ÄÇô¶Ô·½¾ÍÄܵǽÁË£¬µ«ÊÇÄãÈ·²»ÖªµÀ¡£ËùÒÔ×îºÃ°ì·¨ÊǰÑ/etc/passwdÁíÍⱸ·ÝÒ»·Ý£¬²»¶¨ÆÚµÄ¼ì²é£¬Í¬Ê±°Ñ/etc/passwdºÍ/etc/master.passwdÉèΪֻÓÐroot²ÅÄܲ鿴¡£
2. shellºóÃÅ
Õâ¸ö±È½Ï³£Óã¬Ò²±È½ÏÁ÷ÐС£Ò»°ã¾ÍÊǰÑrootÖ´ÐеÄshell³ÌÐòͨ¹ýsetuidµÄÐÎʽ°Ñshell³ÌÐò¿½±´µ½ÆäËûÄܹ»Ö´Ðеĵط½£¬È»ºóÖ»ÒªÓÃСȨÏÞÓû§Ö´ÐиÃshell¾ÍÄܹ»Ö±½Ó»ñÈ¡rootȨÏÞ¡£
±ÈÈ磺
# cp /bin/sh /tmp/.backdoor
# chown root:root /tmp/.backdoor
# chmod +s /tmp/.backdoor
ÕâÑùÖ»ÊǰÑsh¸´ÖÆÁË£¬Èç¹ûÄãϲ»¶ÆäËûshell£¬±ÈÈçksh¡¢cshÒ²¿ÉÒÔ£¬¾ßÌåÄã¿´¸÷¸ö²»Í¬µÄ²Ù×÷ϵͳ¶ø¶¨¡£Äã¾Í¿ÉÒÔ°ÑÄǸö¼ÓÁËs±ê¼ÇµÄshell³ÌÐò·Åµ½ÈκÎĿ¼£¬×îºÃÊÇÉîÒ»µã£¬²»ÈÝÒ×±»ÈË·¢Ïֵĵط½£¬±ÈÈç/usr/local/share/manÖ®ÀàµÄĿ¼£¬È»ºóÄãʹÓÃСȨÏÞÓû§µÇ½ºóÖ´Ðиà shell¾Í¿ÉÒÔÁË£¬±ÈÈçÎÒÃÇÉÏÃæ¸´ÖƵÄshell£¬ÎÒÃÇÖ»ÒªÓÃСȨÏÞÓû§µÇ½ºóÖ´ÐУº
$ /tmp/.backdoor
#
¾Í¿ÉÒÔÁË£¬µ±È»£¬ÈçºÎ»ñµÃСȨÏÞÓû§£¬Äã¿ÉÒÔʹÓñ©Á¦ÆÆ½âһЩÕÊ»§£¬»òÕß×Ô¼º´´½¨Ò»¸öСȨÏÞµÄÕÊ»§¡£
* ·À·¶·½·¨£º
Ê×Ïȸø¸÷¸öÖ÷ҪĿ¼¼ÓÉÏÎÒÃÇÉÏÃæËµµÄÎļþÖ¸ÎÆÐ£Ñ飬֪µÀij¸öĿ¼ÏÂÓÐʲôÎļþ£¬Èç¹û¶à³öÁË¿ÉÒÉÎļþ¿ÉÒÔ×Ðϸ¼ì²é¡£»¹ÓÐʹÓÃfindÃüÁîÀ´²éÕÒÓÐûÓÐΣÏÕµÄroot suid³ÌÐò£º
find / -type f (-perm -4000 -o -perm -2000 ) -print
3. Crontab·þÎñºóÃÅ
crontabÃüÁî¾ÍÏ൱ÓÚwindowsϵÄatÃüÁ¶¨ÆÚÖ´ÐÐijЩÈÎÎñ¡£¶ÔºÚ¿ÍÀ´½²£¬±ÈÈ綨ÆÚ½¨Á¢Ò»¸öÕÊ»§£¬È»ºó¹ý¶à¾Ã¾Íɾ³ý£¬ÕâÑù¹ÜÀíÔ±ÓÀÔ¶¿´²»µ½ÏµÍ³ÖÐÓкóÃÅ£¬ÕâÑùÊǷdz£±£Ïյġ£¡£
* ·À·¶·½·¨£º
cronµÄ·þÎñĬÈÏÊÇ´æ´¢ÔÚ /var/spool/crontab/rootĿ¼Ï£¬¶¨ÆÚ¼ì²écron·þÎñ£¬¿´ÊÇ·ñÓÐÒì³£µÄÈÎÎñÔÚÖ´ÐУ¬»òÕßÈç¹ûÄ㲻ʹÓÃcronµÄ»°£¬Ö±½Ó¹Ø±ÕµôËü¡£
4. rhostsºóÃÅ
RhostsÎļþ³£³£±»ºÚ¿ÍÀûÓÃÀ´ÖÆ×÷ºóÃÅ£¬Èç¹ûϵͳ¿ªÁËrlogin¡¢rexecµÈrµÄ·þÎñ£¬ÒòΪÏórloginÕâÑùµÄ·þÎñÊÇ»ùÓÚrhostsÎļþÀïµÄÖ÷»úÃûʹÓüòµ¥µÄÈÏÖ¤·½·¨£¬ËùÒÔºÚ¿ÍÖ»Òª½«.rhostsÎļþÉèÖóÉ"++"£¬ÄÇô¾ÍÔÊÐíÈκÎÈË´ÓÈκεط½Ê¹ÓøÃÓû§Ãû£¬ÎÞÐë¿ÚÁîµÇ½513¶Ë¿ÚµÄ rlogin·þÎñ¾ÍÐС£¶øÇÒrÖ®ÀàµÄ·þÎñûÓÐÈÕÖ¾ÄÜÁ¦£¬²»ÈÝÒ×±»·¢ÏÖ¡£
ʵÏÖ·½·¨£º
# echo "++" >; /usr/heiyeluren/.rhosts
# rlogin -l heiyeluren localhost
ÕâÑù¾Í²»ÐèÒªÈκÎÃÜÂ룬ֱ½ÓÊäÈëÓû§Ãûheiyeluren¾ÍµÇ½µ½ÁËϵͳ¡£
* ·À·¶°ì·¨£º
²»ÒªÊ¹ÓÃrloginµÈ·þÎñ£¬Í¬Ê±Ò²²»ÍƼöʹÓÃtelnetµÈ·þÎñ£¬ÒòΪtelnetdµÈÊØ»¤½ø³ÌÒç³ö©¶´Ò»¶Ñ£¬¶øÇÒÔÚÊý¾Ý´«Êä¹ý³ÌÖÐÊÇûÓмÓÃܵģ¬ºÜÈÝÒ×±»Ðá̽£¬½¨ÒéʹÓÃsshµÈ¾¹ý°²È«¼ÓÃܵķþÎñÀ´Ìæ´ú¡£
5. LoginºóÃÅ
login³ÌÐòͨ³£ÓÃÀ´¶ÔtelnetÀ´µÄÓû§½øÐпÚÁîÑéÖ¤. ÈëÇÖÕß»ñÈ¡loginµÄÔ´úÂë²¢ÐÞ¸ÄʹËüÔڱȽÏÊäÈë¿ÚÁîÓë´æ´¢¿ÚÁîʱÏȼì²éºóÃÅ¿ÚÁî. Èç¹ûÓû§ÇÃÈëºóÃÅ¿ÚÁî,Ëü½«ºöÊÓ¹ÜÀíÔ±ÉèÖõĿÚÁîÈÃÄ㳤ÇýÖ±Èë¡£
* ·À·¶·½·¨£º
Ò»°ãÕë¶ÔÕâÀàºóÃÅ£¬Ò»°ã¶¼ÊÇʹÓÃ"string"ÃüÁîËÑË÷login³ÌÐòÖÐÊÇ·ñÓÐÖÐÊÇ·ñÓÐÃÜÂëµÈ×Ö·û´®À´½øÐмì²é¡£Èç¹ûÃÜÂë¾¹ý¼ÓÃÜ£¬ÄÇô¾Í¶ÔloginÎļþ½øÐÐÖ¸ÎÆ¼Ç¼ºÍMD5ÖµµÄ¼Ç¼£¬¾õµÃÒ쳣ʱ½øÐмì²â¡£
6. BindºóÃÅ
¾ÍÊÇͨ¹ý³£ÓõÄÍøÂçÁ¬½ÓÐÒé TCP/UDP/ICMP À´½¨Á¢Á¬½ÓµÄºóÃÅ£¬Õâ¸öÔÚWindowsÏ¿ÉÊǺäºäÁÒÁÒ¡£
±È½ÏÆÕ±éµÄÓÐTCPÐÒéµÄºóÃŶ¼ÊÇдһ¶Î³ÌÐò¿ªÒ»¸öÖ¸¶¨µÄ¶Ë¿Ú½øÐмàÌý£¬È»ºó´Ó¿Í»§¶Ë½øÐÐÁ¬½ÓºóµÇ½ϵͳ¡£Ò²ÓкڿÍΪÁËÒþ±ÎʹÓÃUDPÐÒéÀ´Á¬½Ó¡£ icmpºóÃÅÒ²³£¼û£¬Ò»°ãÊÇ¡£ÓÐʱºò¿ÉÄÜbindºóßú·þÎñºóÃŽáºÏ£¬ºÚ¿Íͨ¹ý×Ô¼ºÐ´µÄbindºóÃÅÀ´Ìæ»»inetdÖеķþÎñ¡£
* ·À·¶·½·¨£º
¾³£Ê¹ÓÃnetstatÃüÁî¼ì²éÓÐûÓзǷ¨µÄ¶Ë¿Ú´ò¿ª£¬×îºÃÖ±½ÓÓ÷À»ðǽÆÁ±Î³ýÁËÕý³£·ÃÎʵĶ˿ÚÖ®ÍâµÄ¶Ë¿Ú¡£¶ÔÓÚpingºóÃŵϰ£¬Ö±½ÓÔÚ·À»ðǽÉϽûÖ¹ping·þÎñÆ÷
7. ·þÎñºóÃÅ
Ò»°ãÊÇÌæ»»»òÕßÌí¼Ó·þÎñÀ´ÊµÏÖºóÃÅ¡£±ÈÈçÔÚ /etc/inetd.conf ÖÐÌí¼Ó»òÕßÌæ»»Ä³¸ö·þÎñÀ´ÔËÐÐ×Ô¼ºµÄºóÃųÌÐò£¬»òÕßÔÚijЩ·þÎñÖмÓÈë×Ô¼ºµÄºóÃÅ´úÂë¡£Èç¹ûÊÇÌæ»»·þÎñµÄ»°£¬¸Ã·þÎñ±ØÐë²»±»Ê¹Ó㬶øÇÒ²»ÈÝÒ×·¢ÏÖ¡£Èç¹ûÊÇ×Ô¼ºÌí¼ÓµÄ·þÎñ£¬ÄÇô±ØÐëÔÚ/etc/servicesÖÐÉèÖöÔÓ¦µÄ·þÎñºÍ¶Ë¿Ú²ÅÄÜʹÓá£
* ·À·¶·½·¨£º
¾³£¼ì²é·þÎñ£¬×îºÃ±¸·Ý /etc/inetd.conf ¡¢/etc/servicesµÈÎļþ£¬Í¬Ê±ÔÚFreeBSDÏÂҲҪʱ³£¼ì²é /usr/loca/etc/rc.d ÏÂÃæµÄ½Å±¾ÊÇ·ñÊǺϷ¨µÄ²¢ÇÒÊÇ·ñÄÇЩ½Å±¾ÀïÃæÓÐûÓÐÆô¶¯·Ç·¨³ÌÐò¡£Èç¹ûÊÇÔÚ·þÎñ³ÌÐòÖÐÌí¼Ó×Ô¼ºµÄ´úÂ룬ÄÇô¾ÍÒª¶ÔÎļþµÄÖ¸ÎÆ½øÐÐУÑ飬±ÈÈçmd5Öµ¿´ÊÇ·ñÆ¥Åä¡£
8. rootkitºóÃÅ
rootkitºóÃÅÒ»°ãÊÇÌæ»»¹ÜÀíԱʹÓõŤ¾ß£¬±ÈÈçls¡¢ps¡¢netstat¡¢whoµÈ³£ÓÃÎļþ£¬°ÑÄÇЩ³ÌÐòÌæ»»³É±»ºÚ¿Í¼ÓÁËÌØÊâ´úÂëµÄ³ÌÐò£¬ÄÇÑù¾ÍÄÜ´ïµ½¿ØÖƵÄЧ¹û¡£¶øÇÒÏÖÔÚÒѾÓкܶàÏÖ³ÉÄÜÏÂÔØÊ¹ÓõÄrootkit¡£
* ·À·¶·½·¨£º
°´ÕÕÎÒÃÇÇ°ÃæµÄ·½·¨£¬¸øÃ¿¸öÎļþ½¨Á¢ÏµÍ³Ö¸ÎƵµ°¸ºÍmd5УÑéÖµ£¬Èç¹û¾õµÃ²»¶Ô¾¢µÄʱºò²é¿´ÎļþÖ¸ÎÆÊÇ·ñÆ¥Å䣬ÓÐûÓбðÐ޸Ĺý£¬¾ÍÖªµÀÊÇ·ñ×ÅÁËrootkitµÄµÀ¡£
9. Äں˺óÃÅ
ͨ¹ý¼ÓÔØÄÚºËÄ£¿éµÄ·½Ê½À´¼ÓÔØºóÃÅ£¬±È½Ï¸´ÔÓ¡£Ò»°ãÄں˺óÃŶ¼ÊÇÕë¶Ô²Ù×÷ϵͳ¶øÑԵ쬲»Í¬µÄ²Ù×÷ϵͳÄÚºËÄ£¿éÉèÖñàд·½·¨¶¼²»Ò»Ñù£¬Ò»°ã²»Í¨Óá£Äں˺óÃÅÒ»°ãÎÞ·¨Í¨¹ýmd5УÑéµÈÀ´Åжϣ¬ËùÓлù±¾±È½ÏÄÑ·¢ÏÖ£¬Ä¿Ç°Õë¶ÔÄں˺óÃűȽ϶àµÄÊÇLinuxºÍSolarisÏ¡£
* ·À·¶·½·¨£º
FreeBSDÏÂͨ¹ýÎÒÃÇÉÏÃæ½²µÄÉèÖÃÄں˰²È«µÈ¼¶À´¿ØÖƼÓÔØÄÚºËÄ£¿é¡£
10. ÆäËûºóÃÅ
»¹ÓаüÀ¨.forwardµÈÆäËû¸÷ÀàºóÃÅ£¬ÁíÍâºÜ¶àºóÃÅ¿ÉÄÜÊǽáºÏ¶àÖÖ¼¼Êõ£¬±ÈÈç°ÑrootkitºÍÄں˺óÃŽáºÏÔÚÒ»Æð£¬Êµ¼Ê¹ý³ÌÖУ¬ºÚ¿ËÊÇ»á¸üÄѶԸ¶µÄ¡£µ±È»»¹ÓÐÐí¶àÎÒÃÇûÓз¢ÏÖ¸ßÊÖ¶ÀÃÅÃØ¾÷£¬ÕâÐèÒªÁé»î¼ì²é£¬²»¹ýÖ»ÒªÇÚÀÍÒ»µã£¬°²È«»áÌáÉýºÜ¶à¡£
Áù¡¢½áÊøÓï
°²È«ÊÇÒ»¸öÕûÌ壬¼´Ê¹ÄÇô·þÎñÄãÉèÖõķdz£°²È«£¬µ«ÊDz»Äܱ£Ö¤ÓÀÔ¶°²È«£¬°²È«ÊǶ¯Ì¬µÄ£¬±ØÐë²»¶ÏµÄ³äʵ×Ô¼ºµÄ֪ʶ£¬·¢ÏÖЩ¶´¡¢Ð¼¼Êõ¡£Èç¹ûÄãÐèÒª¸ü°²È«µÄϵͳ£¬Ò»¶¨Òª×Ô¼ºÓÐʱ³£Äܹ»ÊÖ¹¤×÷ÈëÇÖ¼ì²â»òÕßʹÓò¿·Ö¹¤¾ß°ïÖúÄã½øÐÐÈëÇÖ¼ì²â¡£Í¬Ê±ÍƼöÄã°²×°Ò»Ð©ÍøÂçÈëÇÖ¼ì²âϵͳ£¨NIDS£©£¬±ÈÈçSnort¡£
ÎÒÏëÕâ¸öÌâÄ¿ÕæµÄÓеã´óÁË£¬¿ªÊ¼Ð´µÄʱºòûÓÐÄÇÖָоõ£¬Ô½×öµ½ºóÀ´Ô½¾õµÃÏëҪ˵µÄºÜ¶à£¬×îºóÖ»ÄÜ·º·º¶øÌ¸ÁËһϣ¬ËäÈ»Èç´Ë£¬Ò²Ï£ÍûÄܹ»¸øÔÚʹÓÃFreeBSDµÄÍø¹ÜºÍÍøÂ簲ȫ°®ºÃÕßÒ»µãµãµÄ°ïÖú£¬ÄǾÍ×ã¹»ÁË¡£
¸ÐлËùÓÐÖÂÁ¦ÓÚ¿ªÔ´ÊÀ½ç°²È«Ñо¿ºÍ¹ÜÀí²¢ÇÒÔ¸Òâ¹²Ïí×Ô¼ºÑ§Ï°ÐĵõÄÅóÓÑ!
×îºóллÄãÄܹ»ÄÍÐÄÔĶÁ±¾ÎÄ¡£
£¨ÉùÃ÷£º±¾ÈËÒ²ÊdzõѧÕߣ¬ÎÄÕ²»µ±Ö®´¦£¬¾´ÇëÖ¸³ö£¬Í¬Ê±±¾ÎIJο¼Á˺ܶà¸ßÊÖµÄÎÄÕ£¬ÓÐЩ²»ÄÜÒ»Ò»×¢Ã÷£¬¾´ÇëÁ½⡣£©
¸½Â¼£¨±¾ÎIJο¼×ÊÁÏ£©
* ¡¶ºÚ¿Í·ÀÏß¡·2004Äê6Ô ¡¶Ï¸ÐĹ¹Ô찲ȫµÄPHPϵͳ¡·£¨×÷Õߣºµ¥³¤ºç£©
* ¡¶ºÚ¿Í·ÀÏß¡·2004Äê5Ô ¡¶Ò»²½Ò»²½¼ÓÇ¿MysqlµÄ°²È«¡·£¨×÷Õߣºµ¥³¤ºç£©
* ¡¶ºÚ¿Í·ÀÏß¡·2004Äê5Ô ¡¶Îļþϵͳ°²È«ÇÉÉèÖá·£¨×÷ÕߣºÐ¡»ª½¡£©
* ¡¶ºÚ¿Í·ÀÏß¡·2004Äê1Ô ¡¶Öª¼ºÖª±Ë£¬·½ÄܰÙÕ½²»´ù£Apache°²È«Éè¶¨ÃæÃæ¹Û¡·£¨×÷ÕߣºÀÏÅ££©
* ¡¶ºÚ¿Í·ÀÏß¡·2003Äê11Ô¡¶´òÔìÃâ·ÑµÄ·Ö²¼Ê½ÈëÇÖ¼ì²âϵͳ¡·£¨×÷ÕߣºÍõÑ©±ù£©
* ¡¶°²È«½¹µã¡·Îĵµ¾«»ª ¡¶ÀûÓÃFreeBSD×齨°²È«µÄÍø¹Ø¡·£¨×÷Õߣºiceblood£©
* ¡¶°²È«½¹µã¡·Îĵµ¾«»ª ¡¶MySQLÊý¾Ý¿â°²È«ÅäÖá·£¨×÷Õߣºsan£©
* ¡¶°²È«½¹µã¡·Îĵµ¾«»ª ¡¶PHP°²È«ÅäÖá·£¨×÷Õߣºsan£©
* ¡¶°²È«½¹µã¡·Îĵµ¾«»ª ¡¶Ò»Ð©FreeBSDÏà¹ØµÄ°²È«ÎÊÌâ¡·£¨×÷Õߣºxundi£©
* ¡¶°²È«½¹µã¡·Îĵµ¾«»ª ¡¶FreeBSDϵͳÓÅ»¯²¿·ÖÄں˲ÎÊýµ÷ÕûÖÐÎÄ×¢ÊÍ¡·£¨×÷Õߣºiceblood£©
* ¡¶FreeBSDϵͳ°²×°¼°°²È«µ÷Õû¡·£¨×÷Õߣºxundi£©
* ¡¶Ïê̸ vsftpd µÄÉèÖà ¡·£¨×÷ÕߣºÎ´Öª£©
* ¡¶LinuxϵͳÖÐOpenSSHµÄ°²×°ºÍÅäÖá·£¨LinuxAid.com.cnÍøÕ¾¼¼ÊõÎĵµ£©
* ¡¶ÈçºÎ´´½¨ºóÃÅ¡·£¨×÷ÕߣºÎ´Öª£©