¶ÔÓÚ Linux Óû§¶øÑÔ£¬¶Ë¿Ú¹ÜÀí²»½öÊÇÈÕ³£ÔËάµÄÒ»²¿·Ö£¬¸üÊÇÈ·±£ÏµÍ³°²È«µÄ¹Ø¼ü»·½Ú
±¾ÎĽ«ÉîÈë̽ÌÖ Linux Óû§ÈçºÎÓÐЧ¹ÜÀí¶Ë¿Ú£¬´Ó¶øÌáÉýϵͳµÄ°²È«ÐԺͿɿ¿ÐÔ
Ò»¡¢¶Ë¿Ú»ù´¡£ºÀí½â¶Ë¿ÚµÄ×÷ÓÃÓë·ÖÀà ¶Ë¿Ú£¬×÷ÎªÍøÂçͨÐÅÖеÄÂß¼¸ÅÄÊÇÊý¾Ý½ø³öµÄͨµÀ
ÔÚ Linux ϵͳÖУ¬Ã¿¸öÔËÐеijÌÐò»ò·þÎñ¶¼»á°ó¶¨µ½Ò»¸ö»ò¶à¸ö¶Ë¿ÚÉÏ£¬ÕâЩ¶Ë¿Ú¸ºÔð¼àÌýÀ´×ÔÍøÂçµÄÇëÇ󣬲¢½«Êý¾Ý´«µÝ¸øÏàÓ¦µÄ³ÌÐò´¦Àí
¶Ë¿ÚºÅͨ³£·ÖΪÈýÀࣺ 1.ÖªÃû¶Ë¿Ú£¨Well-Known Ports£©£º·¶Î§´Ó 0 µ½ 1023£¬ÕâЩ¶Ë¿Ú±»ÏµÍ³»òÓ¦ÓóÌÐò¹ã·ºÈϿɣ¬ÓÃÓÚÌØ¶¨µÄÍøÂç·þÎñ£¬Èç HTTP£¨80£©¡¢HTTPS£¨443£©¡¢SSH£¨22£©µÈ
2.×¢²á¶Ë¿Ú£¨Registered Ports£©£º·¶Î§´Ó 1024 µ½ 49151£¬ÕâЩ¶Ë¿Úͨ³£ÓÉÓû§×Ô¶¨ÒåµÄÓ¦ÓóÌÐòʹÓ㬲»ÐèÒªÏñÖªÃû¶Ë¿ÚÄÇÑùÑϸñ¹ÜÀí£¬µ«ÈÔÐèºÏÀí¹æ»®ºÍ¼à¿Ø
3.¶¯Ì¬/˽Óж˿ڣ¨Dynamic/Private Ports£©£º·¶Î§´Ó 49152 µ½ 65535£¬ÕâЩ¶Ë¿Úͨ³£ÓÃÓÚÁÙʱÐÔµÄͨÐÅÐèÇó£¬Èç¿Í»§¶Ë³ÌÐòÔÚ·¢ÆðÁ¬½Óʱ¶¯Ì¬·ÖÅäµÄ¶Ë¿Ú
¶þ¡¢Linux Óû§¶Ë¿Ú¹ÜÀíµÄ±ØÒªÐÔ 1.°²È«·À»¤£º²»µ±µÄ¶Ë¿Ú¿ª·Å¿ÉÄÜ»á³ÉΪºÚ¿Í¹¥»÷µÄÈë¿Ú
ͨ¹ý¾«È·¿ØÖÆÄÄЩ¶Ë¿Ú¶ÔÍ⿪·Å£¬¿ÉÒÔÓÐЧ¼õÉÙDZÔڵݲȫ·çÏÕ
2.×ÊÔ´ÓÅ»¯£ººÏÀí·ÖÅä¶Ë¿Ú×ÊÔ´£¬¿ÉÒÔ±ÜÃâ¶Ë¿Ú³åÍ»£¬È·±£ÍøÂçͨÐŵÄ˳³©½øÐÐ
3.ºÏ¹æÐÔÒªÇó£ºÐí¶àÐÐÒµºÍ×éÖ¯¶Ô¶Ë¿Ú¹ÜÀíÓÐÃ÷È·µÄºÏ¹æÐÔÒªÇó£¬È·±£ÏµÍ³·ûºÏÕâЩ±ê×¼£¬ÊÇά»¤ÒµÎñÁ¬ÐøÐÔµÄÖØÒªÒ»»·
4.ÐÔÄÜ¼à¿Ø£ºÍ¨¹ý¼à¿Ø¶Ë¿ÚµÄʹÓÃÇé¿ö£¬¿ÉÒÔ¼°Ê±·¢ÏÖ²¢½â¾öÍøÂçÐÔÄÜÆ¿¾±£¬ÓÅ»¯ÏµÍ³ÕûÌåÐÔÄÜ
Èý¡¢Linux ¶Ë¿Ú¹ÜÀíʵ¼ù 1. ²é¿´µ±Ç°¿ª·ÅµÄ¶Ë¿Ú Linux ÌṩÁ˶àÖÖ¹¤¾ßÀ´²é¿´µ±Ç°ÏµÍ³¿ª·ÅµÄ¶Ë¿Ú£¬×î³£ÓõİüÀ¨`netstat`¡¢`ss`ºÍ `lsof`
- netstat£ºnetstat -tuln ÃüÁî¿ÉÒÔÁгöËùÓмàÌýÖÐµÄ TCP ºÍ UDP ¶Ë¿Ú
bash netstat -tuln - ss£ºss ÊÇ netstat µÄÏÖ´úÌæ´úÆ·£¬ÌṩÁ˸ü·á¸»µÄ¹¦Äܺ͸ü¿ìµÄÖ´ÐÐËÙ¶È
`ss -tuln` ͬÑù¿ÉÒÔÁгö¼àÌý¶Ë¿Ú
bash ss -tuln - lsof£ºlsof -i -P -n ÃüÁî²»½öÁгö¶Ë¿Ú£¬»¹ÄÜÏÔʾÓëÖ®¹ØÁªµÄ½ø³ÌÐÅÏ¢
bash lsof -i -P -n 2. ¿ª·ÅÓë¹Ø±Õ¶Ë¿Ú - ʹÓà iptables£ºiptables ÊÇ Linux ÏÂÇ¿´óµÄ·À»ðǽ¹¤¾ß£¬¿ÉÒÔÓÃÀ´¿ª·Å»ò¹Ø±ÕÌØ¶¨¶Ë¿Ú
ÀýÈ磬¿ª·Å 8080 ¶Ë¿Ú£º bash iptables -A INPUT -p tcp --dport 8080 -j ACCEPT ¹Ø±Õ 8080 ¶Ë¿Ú£¨Êµ¼ÊÉÏÊÇɾ³ýÔÊÐí¹æÔò£©£º bash iptables -D INPUT -p tcp --dport 8080 -j ACCEPT ×¢Ò⣬ÐÞ¸Ä`iptables`¹æÔòºó£¬Í¨³£ÐèÒª±£´æÅäÖÃÒÔʹÆäÔÚÏµÍ³ÖØÆôºóÒÀÈ»ÓÐЧ
- ʹÓà firewalld£º`firewalld` ÊÇÁíÒ»ÖÖÁ÷ÐеķÀ»ðǽ¹ÜÀí¹¤¾ß£¬Ö§³Ö¶¯Ì¬¹ÜÀí·À»ðǽ¹æÔò
¿ª·Å 8080 ¶Ë¿Ú£º bash firewall-cmd --zone=public --add-port=8080/tcp --permanent firewall-cmd --reload ¹Ø±Õ 8080 ¶Ë¿Ú£º bash firewall-cmd --zone=public --remove-port=8080/tcp --permanent firewall-cmd --reload 3. ÅäÖÃÎļþ¹ÜÀí Ðí¶à·þÎñͨ¹ýÆäÅäÖÃÎļþÖ¸¶¨¼àÌýµÄ¶Ë¿Ú
ÀýÈ磬ÐÞ¸Ä Apache HTTP ·þÎñÆ÷µÄ¼àÌý¶Ë¿Ú£¬ÐèÒª±à¼`/etc/httpd/conf/httpd.conf` »ò`/etc/apache2/ports.conf` Îļþ£¬ÕÒµ½ `Listen` Ö¸Áî²¢ÐÞ¸ÄÆäÖµ
Listen 8080 Ð޸ĺó£¬ÐèÖØÆô·þÎñʹÅäÖÃÉúЧ£º systemctl restart httpd ¶ÔÓÚ CentOS/RHEL systemctl restart apache2 ¶ÔÓÚ Debian/Ubuntu 4. ¶Ë¿Úת·¢ÓëÖØ¶¨Ïò ÔÚijЩ³¡¾°Ï£¬ÐèÒª½«Ò»¸ö¶Ë¿ÚµÄÁ÷Á¿×ª·¢µ½ÁíÒ»¸ö¶Ë¿Ú»òÁíһ̨»úÆ÷ÉÏ
Õâ¿ÉÒÔͨ¹ý`iptables` »ò`socat` µÈ¹¤¾ßʵÏÖ
ÀýÈ磬ʹÓà `iptables` ½«±¾µØ 80 ¶Ë¿ÚµÄÁ÷Á¿×ª·¢µ½ 8080 ¶Ë¿Ú£º iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080 5. ÈÕÖ¾Óë¼à¿Ø ¼à¿Ø¶Ë¿Ú»î¶¯¶ÔÓÚ¼°Ê±·¢ÏÖÒì³£ÐÐΪÖÁ¹ØÖØÒª
Linux ϵͳÈÕÖ¾£¨Èç `/var/log/messages`¡¢`/var/log/syslog`£©ºÍÌØ¶¨·þÎñµÄÈÕÖ¾Îļþ£¨Èç ApacheµÄ `/var/log/httpd/access_log`ºÍ `error_log`£©ÊÇ·ÖÎö¶Ë¿ÚʹÓÃÇé¿öµÄÖØÒª×ÊÔ´
´ËÍ⣬»¹¿ÉÒÔÀûÓÃ`tcpdump`¡¢`nmap` µÈ¹¤¾ß½øÐиüÉîÈëµÄ¶Ë¿ÚɨÃèºÍÍøÂçÁ÷Á¿·ÖÎö£¬ÒÔʶ±ðDZÔڵݲȫÍþв
ËÄ¡¢×î¼Ñʵ¼ùÓ밲ȫ½¨Òé 1.×îС»¯¿ª·Å¶Ë¿Ú£º½ö¿ª·Å±ØÒªµÄ¶Ë¿Ú£¬¹Ø±ÕËùÓÐδʹÓõĶ˿Ú
2.ʹÓ÷À»ðǽ£ºÅäÖ÷À»ðǽ¹æÔò£¬ÏÞÖÆÍⲿ·ÃÎÊ£¬Ö»ÔÊÐíÐÅÈ뵀 IP µØÖ·»ò×ÓÍø·ÃÎÊÌØ¶¨¶Ë¿Ú
3.¶¨ÆÚÉ󼯣º¶¨ÆÚÉó²é¿ª·ÅµÄ¶Ë¿ÚºÍ·þÎñ£¬È·±£ËüÃÇÈÔÈ»ÐèÒª¿ª·Å£¬²¢ÒƳý²»ÔÙʹÓõĶ˿Ú
4.¸üÐÂÓëά»¤£º¼°Ê±¸üÐÂϵͳºÍÈí¼þ£¬ÒÔÐÞ¸´ÒÑÖªµÄ°²È«Â©¶´
5.ÈÕÖ¾¼Ç¼Óë·ÖÎö£ºÆôÓò¢¶¨ÆÚ¼ì²éϵͳÈÕÖ¾£¬Ê¹ÓÃÈÕÖ¾·ÖÎö¹¤¾ß£¨Èç ELK Stack£©½øÐÐÒì³£¼ì²â
6.°²È«ÅäÖãºÎª·þÎñÅäÖÃÇ¿ÃÜÂë¡¢SSL/TLS ¼ÓÃܵȰ²È«´ëÊ©£¬±£»¤Êý¾Ý´«Ê䰲ȫ
7.±¸·ÝÓë»Ö¸´£º¶¨ÆÚ±¸·ÝϵͳÅäÖúÍÖØÒªÊý¾Ý£¬ÒÔ±ãÔÚÔâÓö¹¥»÷»òϵͳ¹ÊÕÏʱ¿ìËÙ»Ö¸´
½áÓï Linux Óû§¶Ô¶Ë¿ÚµÄÓÐЧ¹ÜÀí£¬ÊÇÈ·±£ÏµÍ³°²È«¡¢Îȶ¨ÔËÐеĹؼü
ͨ¹ýÉîÈëÀí½â¶Ë¿ÚµÄ×÷ÓÃÓë·ÖÀà£¬ÕÆÎղ鿴¡¢¿ª·Å¡¢¹Ø±Õ¶Ë¿ÚµÄ¼¼ÄÜ£¬ÒÔ¼°ÊµÊ©ÓÐЧµÄ¼à¿ØºÍÉ󼯲ßÂÔ£¬Linux Óû§¿ÉÒÔÏÔÖøÌáÉýϵͳµÄ°²È«ÐԺͿɿ¿ÐÔ
ÔÚÊý×Ö»¯Ê±´ú£¬Õâ²»½öÊǶԼ¼ÊõÄÜÁ¦µÄ¿¼Ñ飬¸üÊǶ԰²È«ÒâʶµÄ¿¼Ñé
ÈÃÎÒÃÇЯÊÖ¹²½ø£¬Îª¹¹½¨¸ü¼Ó°²È«µÄÍøÂç»·¾³¹±Ï×Á¦Á¿