在 CentOS 上“加固 exploit(漏洞利用)风险”通常是指系统安全加固,防止被 exploit 攻击,而不是使用 exploit。下面从系统、服务、权限、网络、监控几个层面给你一套实用加固方案。
yum update -y
或仅更新安全补丁:
yum update --security -y
查看未修复漏洞:
yum updateinfo list security
yum install yum-cron -y
systemctl enable yum-cron
systemctl start yum-cron
编辑:
vi /etc/ssh/sshd_config
修改:
PermitRootLogin no
useradd admin
passwd admin
usermod -aG wheel admin
vi /etc/login.defs
示例:
PASS_MAX_DAYS 90
PASS_MIN_DAYS 1
PASS_MIN_LEN 12
passwd -l lp
passwd -l sync
Port 22222
PasswordAuthentication no
PubkeyAuthentication yes
AllowUsers admin@192.168.1.*
重启:
systemctl restart sshd
systemctl list-unit-files --type=service | grep enabled
关闭示例:
systemctl disable telnet.socket
systemctl enable firewalld
systemctl start firewalld
只开放必要端口:
firewall-cmd --permanent --add-port=22222/tcp
firewall-cmd --reload
getenforce
若为 disabled,改为:
SELINUX=enforcing
重启生效。
编辑:
vi /etc/sysctl.conf
示例:
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
kernel.exec-shield = 1
生效:
sysctl -p
systemctl enable auditd
systemctl start auditd
yum install aide -y
aide --init
journalctl -p err -xb
/var/log/secure
/var/log/messages
| 风险 | 加固方式 |
|---|---|
| 提权漏洞 | 最小权限 + SELinux |
| SSH 爆破 | 密钥登录 + 防火墙 |
| 服务漏洞 | 少装服务 + 及时更新 |
| 内核漏洞 | 及时内核更新 |
ps auxf
netstat -antup
如果你愿意,可以告诉我:
我可以给你一套更精准的加固清单。