下面从系统层、Apache 层、应用层三个维度,给你一套Ubuntu + Apache2 加固清单,适合生产服务器使用。
sudo apt update
sudo apt upgrade -y
保持内核和安全补丁最新。
sudo nano /etc/ssh/sshd_config
PermitRootLogin no
PasswordAuthentication no
sudo systemctl restart ssh
sudo ufw allow 22
sudo ufw allow 80
sudo ufw allow 443
sudo ufw enable
sudo apt install fail2ban -y
sudo systemctl enable fail2ban
sudo nano /etc/apache2/conf-enabled/security.conf
修改:
ServerTokens Prod
ServerSignature Off
重启:
sudo systemctl restart apache2
<Directory /var/www/>
Options -Indexes
</Directory>
查看已加载模块:
apache2ctl -M
禁用示例:
sudo a2dismod autoindex status
sudo systemctl restart apache2
默认已使用 www-data,确保网站目录权限正确:
sudo chown -R www-data:www-data /var/www/html
sudo chmod -R 755 /var/www
<Location /admin>
Require ip 192.168.1.0/24
</Location>
sudo apt install certbot python3-certbot-apache -y
sudo certbot --apache
<VirtualHost *:80>
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
</VirtualHost>
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
SSLCipherSuite HIGH:!aNULL:!MD5
Header always append X-Frame-Options "SAMEORIGIN"
Header set X-XSS-Protection "1; mode=block"
Header set X-Content-Type-Options "nosniff"
sudo apt install libapache2-mod-security2 -y
sudo cp /etc/modsecurity/modsecurity.conf-recommended /etc/modsecurity/modsecurity.conf
sudo a2enmod security2
sudo systemctl restart apache2
# 访问日志
/var/log/apache2/access.log
# 错误日志
/var/log/apache2/error.log
建议:
logrotate<Directory /var/www/html/uploads>
php_flag engine off
</Directory>
如果你愿意,我可以:
你现在的 Ubuntu 版本和 Apache 用途是什么?