Linux×÷Ϊ¹ã·ºÓ¦ÓõĿªÔ´²Ù×÷ϵͳ£¬ÆäÇ¿´óµÄ¹¦ÄܺÍÁé»îµÄÅäÖÃÑ¡ÏîʹµÃËü³ÉΪ·þÎñÆ÷ºÍ×ÀÃæ»·¾³µÄÊ×Ñ¡
È»¶ø£¬LinuxϵͳµÄÇ¿´óÒ²´øÀ´ÁËÒ»¶¨µÄ¸´ÔÓÐÔ£¬ÓÈÆäÊÇÔÚ¹ÜÀíÍøÂç¶Ë¿Ú·½Ãæ
¿ª·ÅµÄÍøÂç¶Ë¿ÚÊÇDZÔڵݲȫ©¶´£¬¿ÉÄܻᱻºÚ¿ÍÀûÓýøÐй¥»÷
Òò´Ë£¬ºÏÀí¹Ø±Õ²»±ØÒªµÄ¶Ë¿Ú£¬ÊÇÌáÉýLinuxϵͳ°²È«ÐÔµÄÖØÒª´ëÊ©
±¾ÎĽ«Ïêϸ̽ÌÖÈçºÎÔÚLinuxϵͳÖйرն˿ڣ¬ÒÔÈ·±£ÏµÍ³µÄ°²È«Îȶ¨
Ò»¡¢Àí½â¶Ë¿ÚµÄ¸ÅÄîºÍ×÷Óà ¶Ë¿ÚÊǼÆËã»úÓëÍâ½çͨÐŵÄͨµÀ£¬ÊÇÍøÂçͨÐÅÖеÄÂß¼½Úµã
ÿ¸ö¶Ë¿Ú¶¼ÓÐÒ»¸öΨһµÄÊý×Ö±êʶ£¬ÓÃÓÚÇø·Ö²»Í¬µÄÍøÂç·þÎñ
ÔÚLinuxϵͳÖУ¬³£¼ûµÄ¶Ë¿ÚÓÐHTTP£¨80¶Ë¿Ú£©¡¢HTTPS£¨443¶Ë¿Ú£©¡¢SSH£¨22¶Ë¿Ú£©µÈ
ÕâЩ¶Ë¿Úͨ³£ÓÃÓÚÌØ¶¨µÄ·þÎñ£¬ÀýÈçWeb·þÎñÆ÷¼àÌý80¶Ë¿ÚÒÔÌṩHTTP·þÎñ£¬¶øSSH·þÎñÔòͨ¹ý22¶Ë¿Ú½øÐÐÔ¶³ÌµÇ¼
¶Ë¿Ú·ÖΪTCP¶Ë¿ÚºÍUDP¶Ë¿ÚÁ½Àà
TCP£¨´«Êä¿ØÖÆÐÒ飩¶Ë¿Úͨ³£ÓÃÓÚÐèÒª¿É¿¿´«ÊäµÄÊý¾ÝÁ÷£¬ÈçHTTP¡¢FTPµÈ
¶øUDP£¨Óû§Êý¾Ý±¨ÐÒ飩¶Ë¿ÚÔòÓÃÓÚ²»ÐèÒª¿É¿¿´«ÊäµÄÊý¾ÝÁ÷£¬ÈçDNS¡¢VoIPµÈ
Á˽â¶Ë¿ÚµÄ¸ÅÄîºÍÀàÐÍ£¬¶ÔÓÚÕýÈ·ÅäÖú͹ÜÀí¶Ë¿ÚÖÁ¹ØÖØÒª
¶þ¡¢Ê¶±ðϵͳÖеĿª·Å¶Ë¿Ú Ôڹرն˿Ú֮ǰ£¬Ê×ÏÈÐèÒªÁ˽âϵͳÖÐÄÄЩ¶Ë¿ÚÊÇ¿ª·ÅµÄ
LinuxϵͳÌṩÁ˶àÖÖ¹¤¾ßÀ´²é¿´¿ª·ÅµÄ¶Ë¿Ú
1.netstatÃüÁnetstatÊÇÒ»¸öÇ¿´óµÄÍøÂ繤¾ß£¬ÓÃÓÚÏÔÊ¾ÍøÂçÁ¬½Ó¡¢Â·ÓÉ±í¡¢½Ó¿Úͳ¼ÆµÈÐÅÏ¢
ͨ¹ý`netstat -tuln`ÃüÁ¿ÉÒԲ鿴ϵͳÖÐËùÓмàÌýµÄTCPºÍUDP¶Ë¿Ú
2.ssÃüÁssÊÇnetstatµÄÌæ´úÆ·£¬ÌṩÁ˸üÏêϸºÍ¸ü¿ìµÄÐÅÏ¢
ʹÓÃ`ss -tuln`ÃüÁ¿ÉÒÔÁгöËùÓмàÌýµÄ¶Ë¿Ú
3.lsofÃüÁlsof£¨List Open Files£©ÊÇÒ»¸öÁгöµ±Ç°ÏµÍ³´ò¿ªÎļþµÄ¹¤¾ß
ÓÉÓÚÍøÂçÌ×½Ó×ÖÔÚLinuxÖÐÒ²±»ÊÓΪÎļþ£¬Òò´Ë`lsof -i`ÃüÁî¿ÉÒÔÓÃÀ´²é¿´ÍøÂçÁ¬½ÓºÍ¶Ë¿ÚʹÓÃÇé¿ö
4.nmapÃüÁnmapÊÇÒ»¸öÍøÂçɨÃ蹤¾ß£¬ÓÃÓÚ·¢ÏÖÍøÂçÉϵÄÖ÷»úºÍ·þÎñ
ͨ¹ý`nmap -sT -O localhost`ÃüÁ¿ÉÒÔɨÃè±¾µØÖ÷»úµÄ¿ª·Å¶Ë¿ÚºÍ·þÎñ
ͨ¹ýÕâЩ¹¤¾ß£¬¹ÜÀíÔ±¿ÉÒÔÈ«ÃæÁ˽âϵͳÖеĶ˿ÚʹÓÃÇé¿ö£¬´Ó¶øÊ¶±ð³öÄÄЩ¶Ë¿ÚÊDz»±ØÒªµÄ»ò´æÔÚ°²È«Òþ»¼µÄ
Èý¡¢¹Ø±Õ¶Ë¿ÚµÄ·½·¨ ¹Ø±Õ²»±ØÒªµÄ¶Ë¿Ú£¬ÊÇÌáÉýϵͳ°²È«ÐԵĹؼü²½Öè
ÔÚLinuxϵͳÖУ¬¹Ø±Õ¶Ë¿ÚµÄ·½·¨Ö÷ÒªÓÐÒÔϼ¸ÖÖ£º 1.Í£Ö¹Ïà¹Ø·þÎñ£º´ó¶àÊý¿ª·Å¶Ë¿ÚÊÇÓÉϵͳ·þÎñ¼àÌýµÄ
Òò´Ë£¬Í£Ö¹ÕâЩ·þÎñÊǹرն˿ڵÄ×îÖ±½Ó·½·¨
ʹÓÃ`systemctl stop ·þÎñÃû`ÃüÁ¿ÉÒÔÍ£Ö¹Ö¸¶¨µÄ·þÎñ
ÀýÈ磬ҪֹͣSSH·þÎñ£¬¿ÉÒÔʹÓÃ`systemctl stopsshd`ÃüÁî
2.½ûÓÃÏà¹Ø·þÎñ£º½ö½öÍ£Ö¹·þÎñÊDz»¹»µÄ£¬ÒòΪ·þÎñ¿ÉÄÜ»áÔÚÏ´ÎϵͳÆô¶¯Ê±×Ô¶¯»Ö¸´
Òò´Ë£¬ÐèÒª½ûÓÃÕâЩ·þÎñ
ʹÓÃ`systemctl disable ·þÎñÃû`ÃüÁ¿ÉÒÔ½ûÖ¹·þÎñÔÚϵͳÆô¶¯Ê±×Ô¶¯ÔËÐÐ
ÀýÈ磬Ҫ½ûÓÃSSH·þÎñ£¬¿ÉÒÔʹÓÃ`systemctl disablesshd`ÃüÁî
3.ʹÓ÷À»ðǽ¹æÔò£º·À»ðǽÊÇ¿ØÖÆÍøÂçÁ÷Á¿½ø³öϵͳµÄÖØÒª¹¤¾ß
ͨ¹ýÅäÖ÷À»ðǽ¹æÔò£¬¿ÉÒÔÔÊÐí»ò¾Ü¾øÌض¨¶Ë¿ÚµÄÁ÷Á¿
Linuxϵͳ³£ÓõķÀ»ðǽ¹¤¾ßÓÐ`iptables`ºÍ`firewalld`
-ʹÓÃ`iptables`£º`iptables`ÊÇLinuxÄÚºË×Ô´øµÄ·À»ðǽ¹¤¾ß
ͨ¹ýÌí¼Ó¹æÔò£¬¿ÉÒԾܾøÌض¨¶Ë¿ÚµÄÁ÷Á¿
ÀýÈ磬Ҫ¾Ü¾ø23¶Ë¿ÚµÄÁ÷Á¿£¨Telnet·þÎñ£©£¬¿ÉÒÔʹÓÃ`iptables -A INPUT -p tcp --dport 23 -jDROP`ÃüÁî
-ʹÓÃ`firewalld`£º`firewalld`ÊÇÒ»¸ö¶¯Ì¬µÄ·À»ðǽ¹ÜÀí¹¤¾ß£¬Ö§³ÖÇøÓò£¨zones£©ºÍ·þÎñµÄ¸ÅÄî
ͨ¹ý`firewall-cmd`ÃüÁ¿ÉÒÔÌí¼Ó»òɾ³ý·À»ðǽ¹æÔò
ÀýÈ磬Ҫ¾Ü¾ø23¶Ë¿ÚµÄÁ÷Á¿£¬¿ÉÒÔʹÓÃ`firewall-cmd --zone=public --remove-port=23/tcp --permanent`ÃüÁ²¢Ó¦ÓùæÔò`firewall-cmd --reload`
4.ÐÞ¸ÄÅäÖÃÎļþ£ºÄ³Ð©·þÎñÔÊÐíͨ¹ýÐÞ¸ÄÅäÖÃÎļþÀ´¸ü¸Ä¼àÌýµÄ¶Ë¿Ú»ò½ûÓÃÌØ¶¨¹¦ÄÜ
ÀýÈ磬Apache·þÎñÆ÷µÄÅäÖÃÎļþͨ³£Î»ÓÚ`/etc/httpd/conf/httpd.conf`»ò`/etc/apache2/ports.conf`£¬Í¨¹ýÐÞ¸ÄÕâЩÎļþ£¬¿ÉÒÔ¸ü¸Ä»ò½ûÓÃHTTPºÍHTTPS¶Ë¿ÚµÄ¼àÌý
ËÄ¡¢×¢ÒâÊÂÏîºÍ×î¼Ñʵ¼ù Ôڹرն˿ڵĹý³ÌÖУ¬ÐèҪעÒâÒÔϼ¸µã£¬ÒÔÈ·±£ÏµÍ³µÄÕý³£ÔËÐкͰ²È«ÐÔ£º 1.½÷É÷²Ù×÷£ºÔڹرն˿Ú֮ǰ£¬È·±£Á˽â¸Ã¶Ë¿ÚµÄ×÷ÓúÍÒÀÀµ¹ØÏµ
¹Ø±ÕijЩ¹Ø¼ü¶Ë¿Ú¿ÉÄܻᵼÖÂϵͳ·þÎñÖжϻò¹¦ÄÜʧЧ
2.¶¨ÆÚÉ󼯣º¶¨ÆÚÉó¼ÆÏµÍ³ÖеĿª·Å¶Ë¿Ú£¬¼°Ê±·¢ÏÖ²¢¹Ø±Õ²»±ØÒªµÄ¶Ë¿Ú
ÕâÓÐÖúÓÚ·ÀֹDZÔڵݲȫ©¶´
3.±¸·ÝÅäÖÃÎļþ£ºÔÚÐÞ¸ÄÅäÖÃÎļþ֮ǰ£¬Îñ±Ø±¸·ÝÔʼÎļþ
ÕâÓÐÖúÓÚÔÚ³öÏÖÎÊÌâʱ¿ìËÙ»Ö¸´
4.ʹÓ÷À»ðǽ£º·À»ðǽÊDZ£»¤ÏµÍ³ÃâÊÜÍⲿ¹¥»÷µÄµÚÒ»µÀ·ÀÏß
ºÏÀíÅäÖ÷À»ðǽ¹æÔò£¬¿ÉÒÔ´ó´óÌá¸ßϵͳµÄ°²È«ÐÔ
5.³ÖÐø¸üкÍÉý¼¶£º±£³ÖϵͳºÍ·þÎñµÄ×îÐÂ״̬£¬¼°Ê±°²×°°²È«²¹¶¡ºÍ¸üÐÂ
ÕâÓÐÖúÓÚÐÞ¸´ÒÑÖªµÄ°²È«Â©¶´£¬Ìá¸ßϵͳµÄ¿¹¹¥»÷ÄÜÁ¦
6.ÈÕÖ¾¼à¿Ø£º¶¨ÆÚ²é¿´ÏµÍ³ÈÕÖ¾£¬Á˽âϵͳµÄÔËÐÐ״̬ºÍDZÔڵݲȫÍþв
ͨ¹ýÈÕÖ¾·ÖÎö£¬¿ÉÒÔ¼°Ê±·¢ÏÖ²¢Ó¦¶ÔÒì³£ÐÐΪ
Îå¡¢×Ü½á ¹Ø±Õ²»±ØÒªµÄ¶Ë¿ÚÊÇÌáÉýLinuxϵͳ°²È«ÐÔµÄÖØÒª´ëÊ©
ͨ¹ýʶ±ðϵͳÖеĿª·Å¶Ë¿Ú¡¢Á˽â¶Ë¿ÚµÄ×÷ÓúÍÒÀÀµ¹ØÏµ¡¢Ñ¡ÔñºÏÊʵĹرշ½·¨£¬²¢×ñÑ×î¼Ñʵ¼ù£¬¹ÜÀíÔ±¿ÉÒÔÓÐЧµØ½µµÍϵͳµÄ°²È«·çÏÕ
È»¶ø£¬ÐèҪעÒâµÄÊÇ£¬¹Ø±Õ¶Ë¿ÚÖ»ÊÇϵͳ°²È«µÄÒ»²¿·Ö
Ҫȷ±£Ïµ