在 CentOS(以及 RHEL 系列)系统中,“exploit(漏洞利用)”的防范是一个系统性工程,核心原则是:减少攻击面 + 及时修补 + 最小权限 + 多层防御。下面按实战优先级给你一套可落地的方案。
# CentOS 7
yum update -y
# CentOS 8(已 EOL,建议迁移到 Rocky/Alma/RHEL)
dnf update -y
yum install yum-cron -y
systemctl enable --now yum-cron
✅ 90% 的 exploit 都来自未修复的已知漏洞
systemctl list-unit-files --type=service | grep enabled
systemctl disable --now telnet.socket
# /etc/ssh/sshd_config
PermitRootLogin no
systemctl restart sshd
useradd ops
passwd ops
usermod -aG wheel ops
PasswordAuthentication no
PubkeyAuthentication yes
firewall-cmd --permanent --add-service=http
firewall-cmd --reload
# /etc/hosts.allow
sshd: 10.0.0.0/24
# /etc/hosts.deny
sshd: ALL
getenforce
setenforce 1
# /etc/selinux/config
SELINUX=enforcing
✅ SELinux 可大幅降低 exploit 提权成功率
示例(/etc/sysctl.conf):
net.ipv4.ip_forward=0
net.ipv4.conf.all.accept_redirects=0
kernel.exec-shield=1
yum install epel-release -y
yum install fail2ban -y
lynis audit system
rpm -Va 检查系统文件变更--privileged如果你愿意,可以告诉我:
我可以给你定制化的加固方案。