在 Debian(以及大多数 Linux 发行版)上防御 exploit(漏洞利用),核心思路是:减少攻击面 + 及时修补 + 最小权限 + 运行时防护。下面按“实用优先级”给你一套防御方案。
sudo apt update
sudo apt upgrade
sudo apt dist-upgrade
安装无人值守更新:
sudo apt install unattended-upgrades
sudo dpkg-reconfigure unattended-upgrades
减少非官方源,避免第三方软件引入漏洞。
sudo systemctl list-unit-files --type=service
sudo systemctl disable <service>
sudo systemctl stop <service>
sudo apt install ufw
sudo ufw enable
sudo ufw default deny incoming
sudo ufw allow ssh
sudo passwd -l root
PasswordAuthentication no
Debian 默认已启用:
确保未手动关闭。
Debian 推荐 AppArmor:
sudo apt install apparmor apparmor-profiles
sudo systemctl enable apparmor
示例(/etc/sysctl.conf):
net.ipv4.ip_forward=0
net.ipv4.conf.all.accept_redirects=0
kernel.dmesg_restrict=1
find / -perm -4000 2>/dev/null
sudo apt install fail2ban
sudo apt install auditd
sudo apt install lynis
sudo lynis audit system
ps aux
netstat -antp
crontab -l
ls -la /tmp
Debian 防御 exploit = 更新 + 最小权限 + 防火墙 + 审计 + 不瞎装软件
如果你有具体场景(如:Web 服务器 / 内网机器 / 云主机 / 某一类 exploit),我可以给你更针对性的方案。