温馨提示×

centos exploit该如何防范

小樊
42
2026-09-12 02:59:20
栏目: 智能运维

在 CentOS(以及 RHEL 系列)系统中,“exploit(漏洞利用)”的防范是一个系统性工程,核心原则是:减少攻击面 + 及时修补 + 最小权限 + 多层防御。下面按实战优先级给你一套可落地的方案。


一、系统与软件层面(最基础也最重要)

1. 及时打补丁(最关键)

# CentOS 7
yum update -y

# CentOS 8(已 EOL,建议迁移到 Rocky/Alma/RHEL)
dnf update -y
  • 开启自动安全更新:
yum install yum-cron -y
systemctl enable --now yum-cron
  • 关注安全公告:
    • https://access.redhat.com/security/alerts
    • https://lists.centos.org/

✅ 90% 的 exploit 都来自未修复的已知漏洞


2. 关闭不必要的服务

systemctl list-unit-files --type=service | grep enabled
  • 关闭无用服务(如 telnet、ftp、rpcbind)
systemctl disable --now telnet.socket

3. 使用最小化安装

  • 不要安装 GUI(除非必要)
  • 只装业务需要的软件包

二、账号与权限控制

4. 禁用 root 直接登录

# /etc/ssh/sshd_config
PermitRootLogin no
systemctl restart sshd

5. 使用普通用户 + sudo

useradd ops
passwd ops
usermod -aG wheel ops

6. 强密码 / 密钥登录

  • 禁用密码登录(推荐):
PasswordAuthentication no
PubkeyAuthentication yes

三、网络与防火墙

7. 使用 firewalld / iptables

firewall-cmd --permanent --add-service=http
firewall-cmd --reload
  • 只开放必要端口
  • 禁止公网访问数据库、Redis、Elasticsearch

8. 限制 SSH 访问来源

# /etc/hosts.allow
sshd: 10.0.0.0/24

# /etc/hosts.deny
sshd: ALL

四、内核与系统加固

9. 开启 SELinux(非常重要)

getenforce
setenforce 1
# /etc/selinux/config
SELINUX=enforcing

✅ SELinux 可大幅降低 exploit 提权成功率


10. 使用安全内核参数

示例(/etc/sysctl.conf):

net.ipv4.ip_forward=0
net.ipv4.conf.all.accept_redirects=0
kernel.exec-shield=1

五、漏洞与入侵检测

11. 安装安全工具

  • Fail2Ban(防爆破)
yum install epel-release -y
yum install fail2ban -y
  • ClamAV(病毒扫描)
  • Lynis(安全审计)
lynis audit system

12. 定期漏洞扫描

  • OpenVAS
  • Nessus
  • 定期 rpm -Va 检查系统文件变更

六、应用层防范(常被忽略)

  • Web 服务(Nginx/Apache)及时升级
  • 数据库禁止公网
  • 应用使用非 root 用户运行
  • 容器环境:
    • 不使用 --privileged
    • 限制 capabilities

七、CentOS 特殊提醒 ⚠️

  • CentOS 8 已停止维护
  • CentOS 7 将于 2024-06-30 EOL ✅ 建议迁移到:
  • Rocky Linux
  • AlmaLinux
  • RHEL(免费额度)

八、最简防 exploit 清单(记住这 8 条)

  1. 定期更新系统
  2. 不开 root SSH
  3. 防火墙只开必要端口
  4. SELinux 开启
  5. 不用弱密码
  6. 不跑多余服务
  7. 装 Fail2Ban
  8. 用最小化系统

如果你愿意,可以告诉我:

  • CentOS 版本
  • 用途(Web / 数据库 / 内网)
  • 是否公网暴露

我可以给你定制化的加固方案。

0 踩