温馨提示×

centos exploit怎么加固

小樊
36
2026-10-03 06:37:33
栏目: 智能运维

在 CentOS 上“加固 exploit(漏洞利用)风险”通常是指系统安全加固,防止被 exploit 攻击,而不是使用 exploit。下面从系统、服务、权限、网络、监控几个层面给你一套实用加固方案。


一、系统层面加固

1. 及时打补丁(最重要)

yum update -y

或仅更新安全补丁:

yum update --security -y

查看未修复漏洞:

yum updateinfo list security

2. 启用自动更新(可选)

yum install yum-cron -y
systemctl enable yum-cron
systemctl start yum-cron

二、账号与权限加固

3. 禁用 root 直接登录

编辑:

vi /etc/ssh/sshd_config

修改:

PermitRootLogin no

4. 使用普通用户 + sudo

useradd admin
passwd admin
usermod -aG wheel admin

5. 密码策略加固

vi /etc/login.defs

示例:

PASS_MAX_DAYS 90
PASS_MIN_DAYS 1
PASS_MIN_LEN 12

6. 锁定不必要账号

passwd -l lp
passwd -l sync

三、SSH 安全加固

7. 修改 SSH 端口

Port 22222

8. 禁用密码登录(推荐)

PasswordAuthentication no
PubkeyAuthentication yes

9. 限制登录 IP(可选)

AllowUsers admin@192.168.1.*

重启:

systemctl restart sshd

四、服务与端口加固

10. 关闭不必要的服务

systemctl list-unit-files --type=service | grep enabled

关闭示例:

systemctl disable telnet.socket

11. 防火墙(firewalld)

systemctl enable firewalld
systemctl start firewalld

只开放必要端口:

firewall-cmd --permanent --add-port=22222/tcp
firewall-cmd --reload

五、内核与 exploit 防护

12. 开启 SELinux

getenforce

若为 disabled,改为:

SELINUX=enforcing

重启生效。

13. 内核安全参数

编辑:

vi /etc/sysctl.conf

示例:

net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
kernel.exec-shield = 1

生效:

sysctl -p

六、审计与入侵检测

14. 开启 auditd

systemctl enable auditd
systemctl start auditd

15. 安装入侵检测(可选)

yum install aide -y
aide --init

16. 日志监控

journalctl -p err -xb
/var/log/secure
/var/log/messages

七、常见 exploit 防护重点

风险 加固方式
提权漏洞 最小权限 + SELinux
SSH 爆破 密钥登录 + 防火墙
服务漏洞 少装服务 + 及时更新
内核漏洞 及时内核更新

八、如果你指的是“CentOS 被 exploit 了怎么办”

  1. 断网
  2. 备份日志
  3. 查异常进程
ps auxf
netstat -antup
  1. 重装或彻底清理
  2. 复盘漏洞来源

如果你愿意,可以告诉我:

  • CentOS 版本(6 / 7 / 8 / Stream)
  • 是防止被攻击还是已经被入侵
  • 是否有公网 IP / 跑什么服务

我可以给你一套更精准的加固清单。

0 踩