È»¶ø£¬ÔÚijЩÇé¿öÏ£¬Óû§¿ÉÄÜ»áÓöµ½ÎÞ·¨ÉèÖûòµÇ¼ΪrootÓû§µÄÎÊÌâ
Õâ²»½ö»áÓ°Ïìϵͳ¹ÜÀíºÍά»¤£¬»¹¿ÉÄܶÔϵͳµÄ°²È«ÐÔºÍÎȶ¨ÐÔ¹¹³ÉÍþв
±¾ÎĽ«ÉîÈë̽ÌÖLinuxϵͳÖÐÎÞ·¨ÉèÖÃrootÓû§µÄÔÒò¡¢Ç±ÔÚÓ°ÏìÒÔ¼°ÏàÓ¦µÄ½â¾ö·½°¸£¬Ö¼ÔÚ°ïÖúϵͳ¹ÜÀíÔ±ºÍ¸ß¼¶Óû§ÓÐЧӦ¶ÔÕâÒ»ÌôÕ½
Ò»¡¢ÎÞ·¨ÉèÖÃrootÓû§µÄÔÒò·ÖÎö 1.ĬÈϽûÓÃrootµÇ¼ - ¶àÊýÏÖ´úLinux·¢Ðа棨ÈçUbuntu¡¢FedoraµÈ£©³öÓÚ°²È«¿¼ÂÇ£¬Ä¬ÈϽûÓÃÁËÖ±½Óͨ¹ýSSH»òÆäËûÔ¶³Ì·þÎñÒÔrootÉí·ÝµÇ¼
Óû§ÐèҪͨ¹ýÆÕͨÓû§ÕË»§µÇ¼ºó£¬Ê¹ÓÃ`sudo`ÃüÁîÀ´ÌáÉýȨÏÞ
2.rootÃÜÂëδÉèÖûòÒÅÍü - ÔÚijЩ°²×°¹ý³ÌÖУ¬ÏµÍ³¿ÉÄܲ»»áÌáʾÉèÖÃrootÃÜÂ룬»òÕßÓû§¿ÉÄÜÒÅÍüÁË֮ǰÉèÖõÄrootÃÜÂë
Õâ»áµ¼ÖÂÎÞ·¨Ö±½Óͨ¹ýrootÕË»§µÇ¼ϵͳ
3.sudoȨÏÞÅäÖôíÎó -`/etc/sudoers`Îļþ¶¨ÒåÁËÄÄЩÓû§ºÍÓû§×é¿ÉÒÔÖ´ÐÐÄÄЩÃüÁî×÷Ϊroot
Èç¹û¸ÃÎļþÅäÖò»µ±£¬ÆÕͨÓû§¿ÉÄÜÎÞ·¨»ñµÃ±ØÒªµÄȨÏÞÀ´Ö´ÐÐϵͳ¹ÜÀíÈÎÎñ
4.PAM£¨¿É²å°ÎÈÏ֤ģ¿é£©ÅäÖÃÎÊÌâ - PAM¸ºÔðLinuxϵͳÖеÄÈÏÖ¤»úÖÆ
Èç¹ûPAMÅäÖôíÎ󣬿ÉÄܻᵼÖ¼´Ê¹rootÃÜÂëÕýÈ·Ò²ÎÞ·¨µÇ¼
5.SELinux»òAppArmor°²È«²ßÂÔÏÞÖÆ - SELinux£¨°²È«ÔöÇ¿ÐÍLinux£©ºÍAppArmorÊÇLinuxϵݲȫģ¿é£¬ÓÃÓÚÏÞÖÆ½ø³Ì·ÃÎÊϵͳ×ÊÔ´
Èç¹ûÅäÖò»µ±£¬ËüÃÇ¿ÉÄÜ×èÖ¹rootÓû§Ö´ÐÐijЩ²Ù×÷
6.ÎļþϵͳȨÏÞÎÊÌâ - ϵͳÎļþ»òĿ¼µÄȨÏÞÉèÖò»µ±£¬¿ÉÄܵ¼ÖÂrootÓû§Ò²ÎÞ·¨·ÃÎÊ»òÐ޸ĹؼüÅäÖÃÎļþ
¶þ¡¢ÎÞ·¨ÉèÖÃrootÓû§µÄDZÔÚÓ°Ïì 1.ϵͳ¹ÜÀíÊÜÏÞ - ÎÞ·¨ÒÔrootÉí·ÝµÇ¼Òâζ×ÅÎÞ·¨Ö´ÐÐϵͳ¼¶µÄÅäÖú͹ÜÀíÈÎÎñ£¬Èç°²×°Èí¼þ¡¢ÐÞ¸ÄϵͳÎļþ¡¢¹ÜÀíÓû§ºÍȨÏÞµÈ
2.ϵͳά»¤À§ÄÑ - ϵͳά»¤ºÍ¹ÊÕÏÅųýͨ³£ÐèÒªrootȨÏÞ
ÎÞ·¨·ÃÎÊrootÕË»§»áÏÔÖøÔö¼Óϵͳά»¤µÄÄѶȺͳɱ¾
3.°²È«·çÏÕÔö¼Ó - ÈôÎÞ·¨Í¨¹ýÕý¹æÍ¾¾¶»ñÈ¡rootȨÏÞ£¬ÏµÍ³¹ÜÀíÔ±¿ÉÄ᳢ܻÊÔÈÆ¹ý°²È«´ëÊ©£¬Õâ²»½ö¿ÉÄÜÎ¥·´°²È«Õþ²ß£¬»¹¿ÉÄÜÒýÈëÐµİ²È«·çÏÕ
4.·þÎñÖÐ¶Ï - ijЩ¹Ø¼ü·þÎñ£¨ÈçÊý¾Ý¿â¡¢Web·þÎñÆ÷£©µÄÆô¶¯ºÍÅäÖÃÐèÒªrootȨÏÞ
ÎÞ·¨·ÃÎÊrootÕË»§¿ÉÄܵ¼Ö·þÎñÖжϣ¬Ó°ÏìÒµÎñÔËÐÐ
Èý¡¢½â¾öÎÞ·¨ÉèÖÃrootÓû§ÎÊÌâµÄ²ßÂÔ 1.ÆôÓÃrootÕË»§£¨Èç¹ûÊÊÓã© - ¶ÔÓÚÔÊÐírootµÇ¼µÄϵͳ£¬¿ÉÒÔͨ¹ýÐÞ¸ÄSSHÅäÖÃÎļþ£¨Èç`/etc/ssh/sshd_config`£©ÖеÄ`PermitRootLogin`²ÎÊýÀ´ÆôÓÃrootµÇ¼
ÖØÆôSSH·þÎñºóÉúЧ
2.ÖØÖÃrootÃÜÂë - Èç¹ûÒÅÍüÁËrootÃÜÂ룬¿ÉÒÔͨ¹ýÆô¶¯µ½µ¥Óû§Ä£Ê½»òʹÓÃLive CD/USBÖØÖÃÃÜÂë
ÔÚµ¥Óû§Ä£Ê½Ï£¬¿ÉÒÔÖ±½ÓÒÔrootÉí·ÝµÇ¼²¢ÐÞ¸ÄÃÜÂë
3.¼ì²éºÍÐÞ¸´sudoȨÏÞ -ʹÓÃ`visudo`ÃüÁî±à¼`/etc/sudoers`Îļþ£¬È·±£ÐèÒªsudoȨÏÞµÄÓû§»òÓû§×é±»ÕýÈ·ÅäÖÃ
`visudo`»á½øÐÐÓï·¨¼ì²é£¬¼õÉÙÅäÖôíÎóµÄ·çÏÕ
4.¼ì²éPAMÅäÖà - ¼ì²é`/etc/pam.d/`Ŀ¼ÏµÄÏà¹ØÅäÖÃÎļþ£¬È·±£Ã»ÓдíÎóµÄÅäÖõ¼ÖÂÈÏ֤ʧ°Ü
ÌØ±ðÊÇÕë¶ÔSSHµÄ`sshd`ÅäÖÃÎļþ£¬ÐèÌØ±ð×¢Òâ
5.µ÷ÕûSELinux»òAppArmor²ßÂÔ -ʹÓÃ`sestatus`²é¿´SELinux״̬£¬²¢¸ù¾ÝÐèÒªµ÷Õû²ßÂÔ
¶ÔÓÚAppArmor£¬¿ÉÒԲ鿴`/etc/apparmor.d/`ϵÄÅäÖÃÎļþ£¬²¢Êʵ±µ÷Õû
6.ÐÞ¸´ÎļþϵͳȨÏÞ -ʹÓÃ`chmod`ºÍ`chown`ÃüÁîÐÞ¸´¹Ø¼üÎļþºÍĿ¼µÄȨÏÞ
¶ÔÓÚϵͳ¼¶±ðµÄÎļþ£¬Í¨³£ÐèÒªrootȨÏÞÀ´Ö´ÐÐÕâЩ²Ù×÷
7.ʹÓûָ´Ä£Ê½»òLive»·¾³ - Èç¹ûÉÏÊö·½·¨¾ùÎÞЧ£¬¿ÉÒÔ¿¼ÂÇʹÓÃϵͳ»Ö¸´Ä£Ê½»òLive CD/USB»·¾³À´·ÃÎÊϵͳÎļþ£¬²¢½øÐбØÒªµÄÐÞ¸´»òÅäÖøü¸Ä
8.ÈÕÖ¾·ÖÎö - ¼ì²éϵͳÈÕÖ¾£¨Èç`/var/log/auth.log`¡¢`/var/log/secure`£©ÒÔ»ñÈ¡¹ØÓÚÈÏ֤ʧ°ÜµÄÏêϸÐÅÏ¢£¬ÕâÓÐÖúÓÚÕï¶ÏÎÊÌâµÄ¸ù±¾ÔÒò
ËÄ¡¢×î¼Ñʵ¼ùÓ뽨Òé 1.¶¨ÆÚ±¸·Ý - ¶¨ÆÚ±¸·ÝϵͳÅäÖÃÎļþºÍÓû§Êý¾Ý£¬ÒÔ·ÀÍòÒ»ÐèÒª»Ö¸´ÏµÍ³
2.ʹÓÃsudo¶ø·ÇÖ±½ÓµÇ¼root - ¹ÄÀøÊ¹ÓÃsudoÀ´Ö´ÐÐÐèÒªrootȨÏ޵IJÙ×÷£¬ÕâÓÐÖúÓÚÉó¼ÆºÍ×·×ÙÄÄЩÓû§Ö´ÐÐÁËÄÄЩ²Ù×÷
3.Ç¿»¯ÃÜÂë²ßÂÔ - ʵʩǿÃÜÂë²ßÂÔ£¬¶¨ÆÚ¸ü»»rootºÍÆäËûÖØÒªÕË»§µÄÃÜÂë
4.¼à¿ØÓëÉó¼Æ - ÆôÓÃϵͳ¼à¿ØºÍÉ󼯹¦ÄÜ£¬¼°Ê±·¢ÏÖ²¢ÏìӦDZÔڵݲȫÍþв
5.³ÖÐøÑ§Ï°ÓëÅàѵ - ϵͳ¹ÜÀíÔ±Ó¦³ÖÐø¹Ø×¢Linux°²È«ºÍά»¤µÄ×îж¯Ì¬£¬½ÓÊÜÏà¹ØÅàѵ£¬ÌáÉý¼¼ÄÜˮƽ
×ÜÖ®£¬LinuxϵͳÖÐÎÞ·¨ÉèÖÃrootÓû§µÄÎÊÌâ¿ÉÄÜÔ´ÓÚ¶àÖÖÔÒò£¬µ«Í¨¹ýϵͳµÄ·ÖÎöºÍ²ÉÈ¡Êʵ±µÄ½â¾ö²ßÂÔ£¬Í¨³£¿ÉÒÔ¿Ë·þÕâЩÕϰ
ÖØÒªµÄÊÇ£¬Òª²ÉȡԤ·À´ëÊ©£¬È·±£ÏµÍ³µÄ°²È«ÐÔºÍÎȶ¨ÐÔ£¬Í¬Ê±×ñÑ×î¼Ñʵ¼ù£¬Ìá¸ßϵͳµÄ¿Éά»¤ÐԺͰ²È«ÐÔ