男人吃奶摸下挵进去好爽,日日躁夜夜躁狠狠躁,freesexvide0s性欧美高清,高清freexxxx性国产,无码人妻一区二区三区一,乱人伦中文字幕成人网站在线,亚洲欧美综合一区二区三区 ,神马影院在线视频观看
知識學堂
  • ·聯系電話:+86.023-75585550
  • ·聯系傳真:+86.023-75585550
  • ·24小時手機:13896886023
  • ·QQ 咨 詢:361652718 513960520
當前位置 > 首頁 > 知識學堂 > 常見技術問題
linux基本安全配置設置腳本
更新時間:2011-10-22 | 發布人:本站 | 點擊率:981
方便設置一些基本的linux安全設置
 
#vi autosafe.sh
 
#!/bin/bash
#########################################################################
#
# File:         autosafe.sh
# Description: 
# Language:     GNU Bourne-Again SHell
# Version: 1.1
# Date: 2010-6-23
# Corp.: c1gstudio.com
# Author: c1g
# WWW: http://blog.c1gstudio.com
### END INIT INFO
###############################################################################
 
V_DELUSER="adm lp sync shutdown halt mail news uucp operator games gopher ftp"
V_DELGROUP="adm lp mail news uucp games gopher mailnull floppy dip pppusers popusers slipusers daemon"
V_PASSMINLEN=8
V_HISTSIZE=30
V_TMOUT=300
V_GROUPNAME=suadmin
V_SERVICE="acpid anacron apmd atd auditd autofs avahi-daemon avahi-dnsconfd bluetooth cpuspeed cups dhcpd firstboot gpm haldaemon hidd ip6tables ipsec isdn kudzu lpd mcstrans messagebus microcode_ctl netfs nfs nfslock nscd pcscd portmap readahead_early restorecond rpcgssd rpcidmapd rstatd sendmail setroubleshoot snmpd sysstat xfs xinetd yppasswdd ypserv yum-updatesd"
V_TTY="3|4|5|6"
V_SUID=(
'/usr/bin/chage'
'/usr/bin/gpasswd'
'/usr/bin/wall'
'/usr/bin/chfn'
'/usr/bin/chsh'
'/usr/bin/newgrp'
'/usr/bin/write'
'/usr/sbin/usernetctl'
'/bin/traceroute'
'/bin/mount'
'/bin/umount'
'/sbin/netreport'
)
version=1.0
 
 
# we need root to run
if test "`id -u`" -ne 0
then
echo "You need to start as root!"
exit
fi
 
case $1 in
"deluser")
echo "delete user ..."
for i in $V_DELUSER ;do
echo "deleting $i";
userdel $i ;
done
;;
 
"delgroup")
echo "delete group ..."
for i in $V_DELGROUP ;do
echo "deleting $i";
groupdel $i;
done
;;
 
"password")
echo "change password limit ..."
echo "/etc/login.defs"
echo "PASS_MIN_LEN $V_PASSMINLEN"
sed -i "/^PASS_MIN_LEN/s/5/$V_PASSMINLEN/" /etc/login.defs
;;
 
"history")
echo "change history limit ..."
echo "/etc/profile"
echo "HISTSIZE $V_HISTSIZE"
sed -i "/^HISTSIZE/s/1000/$V_HISTSIZE/" /etc/profile
;;
 
"logintimeout")
echo "change login timeout ..."
echo "/etc/profile"
echo "TMOUT=$V_TMOUT"
sed -i "/^HISTSIZE/a\TMOUT=$V_TMOUT" /etc/profile
;;
 
"bashhistory")
echo "denied bashhistory ..."
echo "/etc/skel/.bash_logout"
echo 'rm -f $HOME/.bash_history'
if egrep "bash_history" /etc/skel/.bash_logout > /dev/null
then
echo 'warning:existed'
else
echo 'rm -f $HOME/.bash_history' >> /etc/skel/.bash_logout
fi
 
;;
"addgroup")
echo "groupadd $V_GROUPNAME ..."
groupadd $V_GROUPNAME
;;
 
"sugroup")
echo "permit $V_GROUPNAME use su ..."
echo "/etc/pam.d/su"
echo "auth sufficient /lib/security/pam_rootok.so debug"
echo "auth required /lib/security/pam_wheel.so group=$V_GROUPNAME"
if egrep "auth sufficient /lib/security/pam_rootok.so debug" /etc/pam.d/su > /dev/null
then
echo 'warning:existed'
else
echo 'auth sufficient /lib/security/pam_rootok.so debug' >> /etc/pam.d/su
echo "auth required /lib/security/pam_wheel.so group=${V_GROUPNAME}" >> /etc/pam.d/su
fi
;;
 
"denyrootssh")
echo "denied root login ..."
echo "/etc/ssh/sshd_config"
echo "PermitRootLogin no"
sed -i '/^#PermitRootLogin/s/#PermitRootLogin yes/PermitRootLogin no/' /etc/ssh/sshd_config
;;
 
"stopservice")
echo "stop services ..."
for i in $V_SERVICE ;do
service $i stop;
done
;;
 
"closeservice")
echo "close services autostart ..."
for i in $V_SERVICE ;do
chkconfig $i off;
done
;;
 
"tty")
echo "close tty ..."
echo "/etc/inittab"
echo "#3:2345:respawn:/sbin/mingetty tty3"
echo "#4:2345:respawn:/sbin/mingetty tty4"
echo "#5:2345:respawn:/sbin/mingetty tty5"
echo "#6:2345:respawn:/sbin/mingetty tty6"
sed -i '/^[$V_TTY]:2345/s/^/#/' /etc/inittab
;;
 
"ctrlaltdel")
echo "close ctrl+alt+del  ..."
echo "/etc/inittab"
echo "#ca::ctrlaltdel:/sbin/shutdown -t3 -r now"
sed -i '/^ca::/s/^/#/' /etc/inittab
;;
 
"lockfile")
echo "lock user&services ..."
echo "chattr +i /etc/passwd /etc/shadow /etc/group /etc/gshadow /etc/services"
chattr +i /etc/passwd /etc/shadow /etc/group /etc/gshadow /etc/services
;;
 
"unlockfile")
echo "unlock user&services ..."
echo "chattr -i /etc/passwd /etc/shadow /etc/group /etc/gshadow /etc/services"
chattr -i /etc/passwd /etc/shadow /etc/group /etc/gshadow /etc/services
;;
 
"chmodinit")
echo "init script only for root ..."
echo "chmod -R 700 /etc/init.d/*"
echo "chmod 600 /etc/grub.conf"
echo "chattr +i /etc/grub.conf"
chmod -R 700 /etc/init.d/*
chmod 600 /etc/grub.conf
chattr +i /etc/grub.conf
;;
 
"chmodcommand")
echo "remove SUID ..."
echo "/usr/bin/chage /usr/bin/gpasswd ..."
for i in ${V_SUID[@]};
do
chmod a-s $i
done
;;
 
        "version")
                echo "Version: Autosafe for Linux $version"
                ;;
 
*)
echo "Usage: $0 <action>"
echo ""
echo " deluser      delete user"
echo " delgroup     delete group"
echo " password     change password limit"
echo " history      change history limit"
echo " logintimeout      change login timeout"
echo " bashhistory      denied bashhistory"
echo " addgroup      groupadd $V_GROUPNAME"
echo " sugroup      permit $V_GROUPNAME use su"
echo " denyrootssh      denied root login"
echo " stopservice     stop services "
echo " closeservice      close services"
echo " tty      close tty"
echo " ctrlaltdel     close ctrl+alt+del "
echo " lockfile      lock user&services"
echo " unlockfile      unlock user&services"
echo " chmodinit      init script only for root"
echo " chmodcommand      remove SUID"
echo " version      "
echo ""
 
;;
esac
設置權限
 
chmod u+x ./autosafe.sh
運行腳本
 
./autosafe.sh deluser
./autosafe.sh delgroup
.....
分享到: QQ空間 新浪微博 開心網 人人網
主站蜘蛛池模板: 亚洲精品毛片一区二区三区| 熟妇高潮喷沈阳45熟妇高潮喷| 给我免费观看片在线| 亚洲天堂男人影院| 女友被粗大的猛烈进出动漫| 国产毛多水多高潮高清| gogogo高清在线播放韩国| 青青草国产成人99久久| 国产精品一区二区av| 公天天吃我奶躁我的在| 中文字幕 日韩精品 在线| 快穿名器高h喷水荡肉爽文| 一本大道av伊人久久综合| 无码aⅴ精品一区二区三区浪潮 | 亚洲av无码一区二区三区网站| 一面上边一面膜下边的免费| 一二三四视频高清在线观看3| 亚洲av无码一区二区三区网站| 玩弄人妻少妇精品视频| youjizz国产在线观看| 亚洲精品美女久久777777| 《漂亮的女邻居》三级| 少妇粗大进出白浆嘿嘿视频| 特级欧美aaaaaa片| 欧美v国产v亚洲v日韩九九| 最新亚洲人成无码网www电影| 免费看撕开奶罩揉吮奶头视频 | 精品 综合 国产| 实拍女处破www免费看| 亚洲 中文字幕 日韩 无码| 精品无人码麻豆乱码1区2区| 蜜桃mv在线播放免费观看视频| 99精品久久久久久久婷婷| 自拍偷自拍亚洲精品第1页| 蜜桃精品成人影片| 欧美精产国品一二三产品价格| 国产精品久久久久久影视不卡| 成人试看120秒体验区| 亚洲2022国产成人精品无码区| 亚洲成av人片一区二区| 日产幕无线码三区在线|