ÿһ¸öÎļþ¡¢Ä¿Â¼ÄËÖÁ½ø³Ì£¬¶¼×ñÑ×ÅÒ»Ì×ÑϸñµÄȨÏÞ¿ØÖÆ»úÖÆ£¬ÒÔÈ·±£ÏµÍ³µÄÎȶ¨ÔËÐкÍÊý¾ÝµÄ°²È«
ÔÚÖÚ¶àÓû§ºÍ×éÕ˺ÅÖУ¬¡°nobody¡±Óû§ÊÇÒ»¸ö¿´ËÆÆ½·²È´ÖÁ¹ØÖØÒªµÄ´æÔÚ
±¾ÎĽ«ÉîÈë̽ÌÖ¡°nobody¡±Óû§µÄº¬Òå¡¢×÷Óá¢ÅäÖ÷½·¨ÒÔ¼°ÆäÔÚLinux°²È«ÌåϵÖеIJ»¿ÉÌæ´úÐÔ£¬Ö¼ÔÚ°ïÖú¶ÁÕßÉîÈëÀí½â²¢ÓÐЧÀûÓÃÕâÒ»ÌØÊâÕË»§
Ò»¡¢LinuxȨÏÞ»ù´¡»Ø¹Ë ÔÚLinuxϵͳÖУ¬ÎļþºÍĿ¼µÄȨÏÞ·ÖΪÈýÀࣺËùÓÐÕߣ¨Owner£©¡¢ËùÊô×飨Group£©ºÍÆäËûÈË£¨Others£©
ÿÀàȨÏÞÓÖϸ·ÖΪ¶Á£¨r£©¡¢Ð´£¨w£©ºÍÖ´ÐУ¨x£©ÈýÖÖ
ÕâÖÖȨÏÞÄ£ÐÍͨ¹ýÊý×Ö£¨Èç755£©»ò·ûºÅ£¨Èçrwxr-xr-x£©ÐÎʽ±íʾ£¬ÎªÏµÍ³¹ÜÀíÔ±ÌṩÁ˾«Ï¸µÄ¿ØÖÆÊÖ¶Î
- ËùÓÐÕߣºÎļþµÄ´´½¨Õß»òÖ¸¶¨ÓµÓÐÕߣ¬ÓµÓжԸÃÎļþµÄ×î¸ßȨÏÞ
- ËùÊô×飺ÎļþµÄËùÊôÓû§×飬×éÄÚ³ÉÔ±¹²ÏíÒ»¶¨µÄȨÏÞ
- ÆäËûÈË£º¼È²»ÊÇÎļþËùÓÐÕßÒ²²»ÊôÓÚÎļþËùÊô×éµÄËùÓÐÓû§
¶þ¡¢¡°nobody¡±Óû§µÄ¶¨ÒåÓëÆðÔ´ ¡°nobody¡±Óû§£¬ÔÚLinuxϵͳÖÐÊÇÒ»¸öÔ¤¶¨ÒåµÄ¡¢¾ßÓм«µÍȨÏÞµÄÌØÊâÓû§
Ëüͨ³£±»¸³ÓèUID£¨Óû§±êʶ·û£©ºÍGID£¨×é±êʶ·û£©¾ùΪ65534£¨»ò¸ù¾Ý²»Í¬Linux·¢Ðаæ¿ÉÄÜÓÐËù²»Í¬£©£¬Òâζ×ÅËüÊÇϵͳÖÐ×î²»¾ßÌØÈ¨µÄ·ÇrootÓû§Ö®Ò»
¡°nobody¡±Óû§µÄÆðÔ´¿ÉÒÔ×·Ëݵ½UnixϵͳµÄÔçÆÚÉè¼Æ£¬ÄÇʱËüÖ÷ÒªÓÃÓÚÔËÐÐÄÇЩ²»ÐèÒª¸ßȨÏ޵ĺǫ́·þÎñ»òÊØ»¤½ø³Ì
Ëæ×ÅLinuxµÄ·¢Õ¹£¬¡°nobody¡±Óû§µÄ½ÇÉ«Öð½¥±»Ã÷ȷΪϵͳÖеÄÒ»¸ö¡°ÄäÃû¡±»ò¡°·ÇÌØÈ¨¡±Óû§£¬ÓÃÓÚ¸ôÀëÄÇЩ²»Ó¦ÓµÓÐϵͳ×ÊÔ´·ÃÎÊȨÏ޵ķþÎñ½ø³Ì
Èý¡¢¡°nobody¡±Óû§µÄ×÷ÓÃÓëÖØÒªÐÔ 1.°²È«¸ôÀ룺ͨ¹ý½«·þÎñÔËÐÐÔÚ¡°nobody¡±Óû§Ï£¬¿ÉÒÔÏÔÖø½µµÍ·þÎñ±»¶ñÒâÀûÓõķçÏÕ
¼´Ê¹·þÎñ±»¹¥ÆÆ£¬¹¥»÷ÕßÒ²Ö»ÄÜ»ñµÃ¡°nobody¡±Óû§µÄȨÏÞ£¬ÎÞ·¨¶Ôϵͳ½øÐиüÉî²ã´ÎµÄÆÆ»µ
2.×ÊÔ´ÏÞÖÆ£ºÔÚLinuxÖУ¬¿ÉÒÔͨ¹ýÅäÖÃÏÞÖÆ¡°nobody¡±Óû§µÄ×ÊԴʹÓã¬ÈçCPUʱ¼ä¡¢ÄÚ´æÊ¹ÓÃÁ¿¡¢Îļþ¾ä±úÊýµÈ£¬´Ó¶ø·ÀֹijЩ·þÎñ¹ý¶ÈÏûºÄϵͳ×ÊÔ´
3.ºÏ¹æÐÔÒªÇó£ºÔÚ×ñѰ²È«×î¼Ñʵ¼ùºÍºÏ¹æÐÔ±ê×¼£¨ÈçISO27001¡¢HIPAAµÈ£©µÄϵͳÖУ¬Ê¹ÓõÍȨÏÞÕË»§ÔËÐзþÎñÊÇ»ù±¾ÒªÇóÖ®Ò»
¡°nobody¡±Óû§ÕýºÃ·ûºÏÕâÒ»ÐèÇó£¬ÎªÏµÍ³°²È«ºÏ¹æÌṩÁ˱ãÀû
4.¼ò»¯È¨ÏÞ¹ÜÀí£ºÍ¨¹ýͳһʹÓá°nobody¡±Óû§ÔËÐжà¸ö·þÎñ£¬¿ÉÒÔ¼ò»¯È¨ÏÞ¹ÜÀí²ßÂÔ£¬¼õÉÙÒòȨÏÞÅäÖò»µ±µ¼Öµİ²È«·çÏÕ
ËÄ¡¢ÅäÖá°nobody¡±Óû§ÔËÐзþÎñ ÒªÈ÷þÎñÒÔ¡°nobody¡±Óû§Éí·ÝÔËÐУ¬Í¨³£Éæ¼°ÒÔϼ¸¸ö²½Ö裺 1.´´½¨»òÈ·ÈÏ¡°nobody¡±Óû§£º´ó¶àÊýLinux·¢ÐаæÄ¬Èϰüº¬¡°nobody¡±Óû§£¬µ«¿ÉÒÔͨ¹ý`cat /etc/passwd | grep nobody`ÃüÁî¼ì²éÆä´æÔÚ
Èç¹û²»´æÔÚ£¬¿ÉÒÔʹÓÃ`useradd -r -s /sbin/nologinnobody`ÃüÁî´´½¨£¬ÆäÖÐ`-r`Ñ¡Ïî±íʾ´´½¨ÏµÍ³ÕË»§£¬`-s /sbin/nologin`ÏÞÖÆ¸ÃÓû§²»ÄܵǼϵͳ
2.Ð޸ķþÎñÅäÖÃÎļþ£º¸ù¾Ý·þÎñµÄ²»Í¬£¬ÐÞ¸ÄÆäÅäÖÃÎļþ£¬Ö¸¶¨ÒÔ¡°nobody¡±Óû§ÔËÐÐ
ÀýÈ磬¶ÔÓÚApache HTTP·þÎñÆ÷£¬¿ÉÒÔÔÚÆäÅäÖÃÎļþÖÐÕÒµ½`User`ºÍ`Group`Ö¸ÁÉèÖÃΪ`nobody`
3.²âÊÔÓëÑéÖ¤£ºÖØÐÂÆô¶¯·þÎñºó£¬Ê¹ÓÃ`ps -ef |grep ¡¾·þÎñÃû¡¿`²é¿´·þÎñ½ø³ÌÊÇ·ñȷʵÒÔ¡°nobody¡±Óû§ÔËÐÐ
ͬʱ£¬¼ì²é·þÎñµÄÈÕÖ¾Îļþ£¬È·±£Ã»ÓÐÒòȨÏÞ²»×ãµ¼ÖµĴíÎó
4.°²È«ÓëÐÔÄÜ¼à¿Ø£ºÊµÊ©³ÖÐøµÄ°²È«ÓëÐÔÄÜ¼à¿Ø£¬È·±£¡°nobody¡±Óû§ÔËÐеķþÎñ²»»á³ÉΪϵͳƿ¾±»ò°²È«Â©¶´
Îå¡¢×î¼Ñʵ¼ùÓë×¢ÒâÊÂÏî - ±ÜÃâÀÄÓãºËäÈ»¡°nobody¡±Óû§ÌṩÁ˰²È«¸ôÀ룬µ«²»Ó¦ÀÄÓÃ
¶ÔÓÚÐèÒªÌØ¶¨È¨Ï޵ķþÎñ£¬Ó¦´´½¨¾ßÓÐ×îС±ØÒªÈ¨ÏÞµÄרÓÃÓû§ÕË»§
- ÈÕÖ¾É󼯣ºÆôÓò¢¶¨ÆÚ¼ì²éÓë¡°nobody¡±Óû§Ïà¹ØµÄϵͳÈÕÖ¾£¬ÒԱ㼰ʱ·¢ÏÖÒì³£ÐÐΪ
- ÎļþȨÏÞ£ºÈ·±£¡°nobody¡±Óû§Ö»ÄÜ·ÃÎÊÆä±ØÐèµÄÎļþºÍĿ¼£¬±ÜÃâ²»±ØÒªµÄȨÏÞй¶
- °æ±¾¼æÈÝÐÔ£º²»Í¬Linux·¢ÐаæºÍ°æ±¾¼ä£¬¶Ô¡°nobody¡±Óû§µÄ´¦Àí¿ÉÄÜÓÐËù²»Í¬
ÔÚÇ¨ÒÆ»òÉý¼¶ÏµÍ³Ê±£¬×¢Òâ¼ì²éÏà¹ØÅäÖõļæÈÝÐÔ
Áù¡¢½áÂÛ ¡°nobody¡±Óû§£¬Õâ¸ö¿´ËƲ»ÆðÑÛµÄLinuxϵͳ³ÉÔ±£¬Êµ¼ÊÉÏÔÚά»¤ÏµÍ³°²È«¡¢×ÊÔ´¹ÜÀíºÍºÏ¹æÐÔ·½Ãæ°çÑÝ×ÅÖÁ¹ØÖØÒªµÄ½ÇÉ«
ͨ¹ýºÏÀíÅäÖúÍʹÓá°nobody¡±Óû§£¬ÏµÍ³¹ÜÀíÔ±¿ÉÒÔÓÐЧ½µµÍ°²È«·çÏÕ£¬ÌáÉýϵͳÕûÌåµÄ½¡×³ÐÔºÍÎȶ¨ÐÔ
Ëæ×ÅÍøÂç¹¥»÷ÊֶεIJ»¶ÏÑݽø£¬ÉîÈëÀí½â²¢³ä·ÖÀûÓá°nobody¡±Óû§µÈ°²È«»úÖÆ£¬½«ÊDZ£ÕÏLinuxϵͳ°²È«µÄÖØÒªÒ»»·
ÈÃÎÒÃÇ´Óϸ½Ú×öÆð£¬¹²Í¬¹¹½¨Ò»¸ö¸ü¼Ó°²È«¡¢¿É¿¿µÄLinux»·¾³