ÔÚÈÕ³£ÔËάºÍ¿ª·¢¹¤×÷ÖУ¬ÓÐʱÐèÒªÇл»µ½ÆäËûÓû§ÕË»§½øÐвÙ×÷£¬Õâ²»½öÊÇΪÁËÖ´ÐÐÌØ¶¨ÈÎÎñ£¬¸üÊdzöÓÚϵͳ¹ÜÀíºÍ°²È«ÐԵĿ¼ÂÇ
±¾ÎĽ«ÉîÈë̽ÌÖÔÚLinuxϵͳÖÐÈçºÎµÇ¼ÆäËûÓû§ÕË»§µÄ·½·¨¡¢Ó¦Óó¡¾°¡¢Ç±ÔÚ·çÏÕÒÔ¼°ÏàÓ¦µÄ°²È«²ßÂÔ£¬Ö¼ÔÚ°ïÖú¶ÁÕßÕÆÎÕÕâÒ»¹Ø¼ü¼¼ÄÜ£¬ÌáÉý¹¤×÷ЧÂÊÓëϵͳ°²È«ÐÔ
Ò»¡¢ÎªºÎÐèÒªµÇ¼ÆäËûÓû§ÕË»§ 1.ȨÏÞ¹ÜÀí£ºLinux²ÉÓûùÓÚ½ÇÉ«µÄ·ÃÎÊ¿ØÖÆ£¨RBAC£©Ä£ÐÍ£¬²»Í¬Óû§ÓµÓв»Í¬µÄȨÏÞ¼¯
ÓÐʱ£¬¹ÜÀíÔ±ÐèÒªÁÙʱÒÔÆÕͨÓû§Éí·ÝÔËÐгÌÐò»ò¼ì²éÎļþ£¬ÒÔ±ÜÃâÖ±½ÓʹÓÃrootȨÏÞ¿ÉÄÜ´øÀ´µÄ·çÏÕ
2.¹ÊÕÏÅŲ飺µ±Ä³¸öÓ¦ÓóÌÐò»ò·þÎñÔÚÌØ¶¨Óû§Ï³öÏÖÎÊÌâʱ£¬Çл»µ½¸ÃÓû§ÕË»§¿ÉÒÔ°ïÖú¿ìËÙ¶¨Î»ÎÊÌâÔÒò£¬ÒòΪ²»Í¬Óû§µÄ»·¾³±äÁ¿¡¢ÅäÖÃÎļþµÈ¿ÉÄÜÓÐËù²»Í¬
3.ά»¤Óë²âÊÔ£º¿ª·¢ÈËÔ±ÔÚ²âÊÔй¦ÄÜ»òÐÞ¸´bugʱ£¬¿ÉÄÜÐèҪģÄⲻͬÓû§µÄÐÐΪ£¬È·±£Èí¼þµÄ¼æÈÝÐÔºÍÎȶ¨ÐÔ
4.ºÏ¹æÐÔÒªÇó£ºÔÚijЩÐÐÒµ£¬Èç½ðÈÚ¡¢Ò½ÁƵȣ¬¶ÔÊý¾ÝµÄ·ÃÎʺͲÙ×÷ÓÐÑϸñµÄºÏ¹æÐÔÒªÇó
ͨ¹ýµÇÂ¼ÌØ¶¨Óû§ÕË»§£¬¿ÉÒÔÈ·±£ËùÓвÙ×÷¶¼·ûºÏÉó¼ÆºÍºÏ¹æ±ê×¼
¶þ¡¢µÇ¼ÆäËûÓû§ÕË»§µÄ·½·¨ 1.ʹÓÃsuÃüÁî `su`£¨substitute user£©ÊÇ×î»ù±¾µÄÇл»Óû§ÃüÁî
ͨ¹ý`su ÀýÈ磺
bash
su john
Èç¹ûÒªÒÔrootÓû§Éí·ÝÇл»£¬¿ÉÒÔÖ±½ÓʹÓÃ`su-`»ò`su`£¨ÈôrootÃÜÂëΪ¿Õ»òµ±Ç°Óû§ÓÐsudoȨÏÞÇÒÅäÖÃÁËÃâÃÜ£©£¬µ«³öÓÚ°²È«¿¼ÂÇ£¬½¨Ò龡¿ÉÄܱÜÃâÖ±½ÓʹÓÃrootÕË»§
2.ʹÓÃsudoÃüÁî
`sudo`£¨superuser do£©ÔÊÐíÊÚȨÓû§ÒÔÆäËûÓû§µÄÉí·ÝÖ´ÐÐÃüÁĬÈÏÅäÖÃÏ£¬ÆÕͨÓû§¿ÉÒÔʹÓÃ`sudo`À´Ö´ÐÐÐèÒªÌØÈ¨µÄÃüÁ¶øÎÞÐèÖªµÀrootÃÜÂë ÈôÒªÒÔÌØ¶¨Óû§Éí·ÝÖ´ÐÐÃüÁ¿ÉÒÔʹÓÃ`-u`Ñ¡Ï
bash
sudo -u john whoami
Õ⽫ÏÔʾµ±Ç°ÒÔ`john`Óû§µÄÉí·ÝÖ´ÐÐÃüÁî ×¢Ò⣬`sudo`ÃüÁîͨ³£»á¼Ç¼ÔÚϵͳÈÕÖ¾ÖУ¬±ãÓÚÉó¼Æ
3.µÇ¼»á»°Çл»
³ýÁËÖ±½ÓÃüÁîÐÐÇл»Í⣬»¹¿ÉÒÔͨ¹ýͼÐνçÃæ£¨Èç¹û°²×°ÁË×ÀÃæ»·¾³£©µÄ×¢Ïú/Çл»Óû§¹¦ÄÜ£¬ÒÔͼÐη½Ê½µÇ¼ÆäËûÓû§ÕË»§ Õâͨ³£Éæ¼°µ½×¢Ïúµ±Ç°Óû§£¬È»ºóÑ¡ÔñÒªµÇ¼µÄÓû§
4.SSHÔ¶³ÌµÇ¼
ÔÚÔ¶³Ì·þÎñÆ÷¹ÜÀí³¡¾°ÖУ¬¿ÉÒÔͨ¹ýSSH£¨Secure Shell£©ÐÒéÒÔÌØ¶¨Óû§Éí·ÝÔ¶³ÌµÇ¼µ½·þÎñÆ÷ ÀýÈ磺
bash
ssh john@remote_host
Õ⽫ÔÚÔ¶³ÌÖ÷»ú`remote_host`ÉÏÒÔ`john`Óû§µÄÉí·ÝÆô¶¯Ò»¸öSSH»á»°
Èý¡¢Ó¦Ó󡾰ʵÀý
³¡¾°Ò»£ºÈí¼þ²¿ÊðÓë²âÊÔ
¼ÙÉèÄãÊÇÒ»Ãû¿ª·¢ÈËÔ±£¬ÐèÒªÔÚÉú²ú»·¾³Öв¿Êðа汾µÄÓ¦ÓÃÈí¼þ£¬²¢²âÊÔÆäÔÚÆÕͨÓû§ÏµÄÔËÐÐÇé¿ö ´Ëʱ£¬Äã¿ÉÒÔʹÓÃ`su`»ò`sudo -u`Çл»µ½·ÇÌØÈ¨Óû§£¬Ö´Ðа²×°½Å±¾»òÔËÐвâÊÔ°¸Àý
³¡¾°¶þ£ºÈÕÖ¾Éó²éÓëϵͳ¼à¿Ø
ϵͳ¹ÜÀíÔ±ÔÚÉó²éÈÕÖ¾Îļþʱ£¬¿ÉÄÜÐèÒª´Ó¶à¸öÓû§ÊӽDz鿴»î¶¯¼Ç¼£¬ÒÔ±ã¸üÈ«ÃæµØÁ˽âϵͳ״̬ ͨ¹ýÇл»µ½²»Í¬Óû§£¬¿ÉÒÔ·ÃÎʲ¢·ÖÎö¸÷×ÔµÄÓû§ÈÕÖ¾£¬Èç`/home/
³¡¾°Èý£º¹ÊÕÏÅŲéÓë»Ö¸´
µ±Ä³¸ö·þÎñ»òÓ¦ÓñÀÀ£Ê±£¬Çл»µ½Ïà¹ØÓû§ÕË»§£¬¼ì²éÆä»·¾³±äÁ¿¡¢ÅäÖÃÎļþºÍ´íÎóÈÕÖ¾£¬ÊÇ¿ìËÙ¶¨Î»ÎÊÌâÔÒòµÄÓÐЧÊÖ¶Î ÀýÈ磬Web·þÎñÆ÷¿ÉÄÜÒòÅäÖôíÎóµ¼ÖÂÎÞ·¨Æô¶¯£¬Çл»µ½Web·þÎñÓû§£¨Èç`www-data`£©£¬¼ì²éÅäÖÃÎļþºÍȨÏÞÉèÖã¬ÍùÍùÄÜѸËÙÕÒµ½½â¾ö·½°¸
ËÄ¡¢Ç±ÔÚ·çÏÕÓ밲ȫ²ßÂÔ
·çÏÕÒ»£ºÈ¨ÏÞÀÄÓÃ
²»µ±µÄȨÏÞ¹ÜÀí¿ÉÄܵ¼ÖÂȨÏÞÀÄÓã¬ÓÈÆäÊǵ±¶à¸öÓû§¹²Ïíͬһϵͳʱ Ó¦Ñϸñ¿ØÖÆÄÄЩÓû§ÓÐȨʹÓÃ`su`»ò`sudo`£¬²¢ÏÞÖÆËûÃÇ¿ÉÒÔÖ´ÐеÄÃüÁΧ
·çÏÕ¶þ£ºÃÜÂëй¶
Ƶ·±Çл»Óû§ÐèÒªÊäÈëÃÜÂ룬Ôö¼ÓÁËÃÜÂëй¶µÄ·çÏÕ ½¨Òé²ÉÓð²È«µÄÃÜÂë¹ÜÀí²ßÂÔ£¬È綨ÆÚ¸ü»»ÃÜÂ롢ʹÓÃÃÜÂë¹ÜÀí¹¤¾ßµÈ
·çÏÕÈý£ºÉó¼ÆÈ±Ê§
δ¼Ç¼»òδÍ×ÉÆ±£´æµÄÓû§Çл»¼Ç¼£¬¿ÉÄÜʹµÃϵͳÐÐΪÄÑÒÔ×·ËÝ Ó¦ÆôÓò¢¶¨ÆÚ¼ì²éϵͳÈÕÖ¾£¬Èç`/var/log/auth.log`£¨Debian/Ubuntu£©»ò`/var/log/secure`£¨Red Hat/CentOS£©£¬È·±£ËùÓÐÓû§Çл»»î¶¯¶¼±»¼Ç¼
°²È«²ßÂÔ
-×îСȨÏÞÔÔò£ºÎªÃ¿¸öÓû§·ÖÅä×îµÍ±ØÒªÈ¨ÏÞ£¬±ÜÃâ¹ý¶ÈÊÚȨ
-¶¨ÆÚÉ󼯣ºÍ¨¹ýÈÕÖ¾·ÖÎöºÍ¶¨ÆÚÉ󼯣¬¼à¿ØÓû§»î¶¯£¬¼°Ê±·¢ÏÖ²¢´¦ÀíÒì³£ÐÐΪ
-¶àÒòËØÈÏÖ¤£º¶ÔÓÚÃô¸Ð²Ù×÷£¬ÒýÈë¶àÒòËØÈÏÖ¤£¨MFA£©£¬Èç½áºÏÃÜÂëºÍÉúÎïʶ±ð¼¼Êõ£¬Ìá¸ß°²È«ÐÔ
-¶¨ÆÚÅàѵ£º¶ÔÓû§½øÐа²È«ÒâʶÅàѵ£¬Ìá¸ßËûÃǶÔDZÔÚÍþвµÄÈÏʶºÍ·À·¶ÄÜÁ¦
Îå¡¢½áÓï
ÔÚLinuxϵͳÖУ¬µÇ¼ÆäËûÓû§ÕË»§ÊÇÒ»Ïî»ù´¡¶øÇ¿´óµÄ¹¦ÄÜ£¬Ëü´Ù½øÁËȨÏÞµÄÓÐЧ¹ÜÀí¡¢¹ÊÕϵĿìËÙÅŲéÒÔ¼°ºÏ¹æÐÔ²Ù×÷µÄÖ´ÐÐ È»¶ø£¬ÕâÒ»¹¦ÄÜÒ²°éËæ×ÅDZÔڵķçÏÕ£¬ÐèÒª¹ÜÀíÔ±ºÍÓû§¹²Í¬Å¬Á¦£¬Í¨¹ýʵʩÑϸñµÄ°²È«²ßÂԺ͹ÜÀí´ëÊ©£¬È·±£Æä±»ÕýȷʹÓà ͨ¹ýÕÆÎÕ±¾ÎÄËùÊöµÄ·½·¨¡¢Ó¦Óó¡¾°¡¢·çÏÕÓ밲ȫ²ßÂÔ£¬¶ÁÕß½«Äܹ»ÔÚ±£ÕÏϵͳ°²È«µÄͬʱ£¬¸ü¼Ó¸ßЧµØÀûÓÃLinuxµÄ¶àÓû§ÌØÐÔ£¬Îª¹¤×÷ºÍѧϰ´´Ôì¸ü¶à¼ÛÖµ