在 CentOS(以及一般 Linux 系统)上,“exploit 加固”通常指防止已知漏洞被利用、减少攻击面、提升系统安全性。下面按实用优先级给你一套加固清单,适用于 CentOS 7 / 8 / Stream。
# CentOS 7
yum update -y
# CentOS 8 / Stream
dnf update -y
yum install -y yum-cron
systemctl enable --now yum-cron
systemctl list-unit-files --type=service | grep enabled
常见可关:
systemctl disable --now telnet.socket
systemctl disable --now rsh.socket
vi /etc/ssh/sshd_config
修改:
PermitRootLogin no
PasswordAuthentication no # 建议用密钥
systemctl restart sshd
useradd admin
passwd admin
usermod -aG wheel admin
vi /etc/login.defs
示例:
PASS_MAX_DAYS 90
PASS_MIN_DAYS 1
PASS_MIN_LEN 12
systemctl enable --now firewalld
firewall-cmd --permanent --add-service=ssh
firewall-cmd --reload
yum install -y epel-release
yum install -y fail2ban
systemctl enable --now fail2ban
getenforce
setenforce 1
永久:
vi /etc/selinux/config
SELINUX=enforcing
sysctl -w kernel.unprivileged_bpf_disabled=1
sysctl -w net.core.bpf_jit_harden=2
chattr +i /etc/passwd /etc/shadow
systemctl enable --now auditd
如果你是担心某个具体漏洞(如:
请提供:
uname -a)我可以给你精确修复命令。
rpm -q --changelog kernel | head
ss -tulnp
lastlog
如果你愿意,我可以:
你现在的 CentOS 是哪个版本?有没有具体 exploit?