ʹÓÃYassp¹¤¾ß°ü°²×°°²È«µÄSolarisϵͳ £¨ËÄ£©
À´Ô´£º
×÷Õߣº
ʱ¼ä£º2005-03-27
µã»÷£º
11¡¢°²×°ÍêÕûÐÔ¼ì²â¹¤¾ß£ºÈçTripwire
Ó¦¸Ã¾³£¶ÔϵͳÖÐÎļþµÄÍêÕûÐÔ½øÐмì²é£¬ÒÔÈ·±£ËûÃÇûÓб»¶ñÒâµÄ¸Ä±ä¡£SolarisÌṩÁË
"pkgchk -n"ÃüÁ°²×°µÄÎļþ´óС¡¢È¨ÏÞ¼°Ð£ÑéÓëpackageÊý¾Ý¿â½øÐбȽϡ£µ«ÊǼìÑéÊÇ¿ÉÒÔ»á
ÆÛƵģ¬Êý¾Ý¿âÒ²¿ÉÄܻᱻ¸ü¸Ä¡£Òò´Ë£¬ÕæÕýÐèÒªµÄÊDzÉÓð²È«µÄhashingËã·¨µÄÎļþÍêÕûÐÔ¼ì²é
¹¤¾ß¡£
Yassp½«ÔÚ/secure/tripwireÖа²×°tripwire¡£Ëü²ÉÓöàÖÖhashingËã·¨¡£
ϵͳ°²×°µ½Õâ¸ö½×¶Î£¬ÎÒÃǽ¨Òé¶ÔÐÂÅäÖõÄϵͳ¼°Îļþ´´½¨¿ìÕÕ(snapshot)£¬³õʼ»¯tripwireµÄ
Êý¾Ý¿â£¬¶¨ÆÚ½øÐмì²é±ä¶¯Çé¿ö¡£Èç¹ûÓпÉÄܵϰ£¬½«Ö÷Êý¾Ý¿âµ¥¶À±£´æ¡£
ÎļþÍêÕûÐÔ¼ì²éµÄ¿ÉÑ¡¹¦ÄÜ
* Tripwire£ºÓÐÃâ·ÑºÍÉÌÒµÁ½ÖÖ°æ±¾
* ½¨ÒéÔÚÖÐÐÄ·þÎñÆ÷ÉÏʹÓÃÉÌÒµ°æ±¾£¬¸ü¼ÓÎȶ¨£¬ÔÚÆäËüÖ÷»úÉÏʹÓÃÃâ·ÑµÄ°æ±¾¡£
* PGP¿ÉÓã¬PGP can also be used,by signing files to be protected(creating lots of
signature files),then writing a script to check the validity of signatures.This will
not catch permission,link,inode or modify date changes though.
* MD5 signatures(µ¥ÏòhashËã·¨)¿ÉÄÜͬÑùʹÓ㬵«ÊÇMD5Ç©ÃûÁÐ±í²»Òª±£´æÔÚ±»¼àÊÓµÄÖ÷»úÉÏ£¬
³ý·ÇÒѾ¼ÓÃÜ»òÕßPGP signed¡£
ʹÓÃÃâ·ÑTripwirerÀý×Ó£º
* Yassp°²×°/secure/tripwire/tripwire¼°È±ÉÙµÄÅäÖÃtw.config£¬Ò²¿ÉÒÔ»ñµÃÔ´´úÂëºó×ÔÐбàÒë
¡£
* Èç¹ûÐèÒª£¬±à¼/secure/tripwire/tw.config£¬·ûºÏ×Ô¼ºÒªÇó¡£
* ½ÓÏÂÀ´£¬×öϵͳµÄ³õʼ״̬¡£
cd /secure/tripwire; ./tripwire -i 2 -initialise -c tw.config½¨Á¢Ò»¸öеÄÎļþÊý¾Ý¿â
¡£¿ÉÄÜ»áÓÐһЩÎļþÎÞ·¨ÕÒµ½µÄ±¨´íÐÅÏ¢£¬ºöÂÔËüÃÇ¡£°ÑвúÉúµÄÊý¾Ý¿â(ÔÚ
/secure/tripwire/database)¸´ÖƵ½ÈíÅÌÉÏ¡£ÔÚ½«À´Èç¹û»³ÒÉϵͳÔâÊܹ¥»÷»òÕ߸Ķ¯Ê±£¬¿ÉÒÔʹ
ÓôËÎļþ¡£
* ¿ÉÒÔÔÚcronÖÐÉèÖÃÿÌì½øÐмì²é£¬Ò²¿ÉÒÔÊÖ¹¤½øÐÐ
./tripwire -i 2 -c tw.config
* ¸æËßtripwire£¬Îļþ¼°Ä¿Â¼µÄ¸Ä±äÕý³£
tripwire -update [/file1 /file2 /patch3.....]
* improvements:
* tripwireÊý¾Ý¿âÈç¹û±£´æÔÚͬһÖ÷»úÉÏ£¬Ó¦Ñ¹Ëõ²¢¼ÓÃÜ£¬»òÕßÓÃÇ¿¼ÓÃܹ¤¾ß(ÈçPGP)¶ÔÆä½øÐÐ
sign¡£
* ´Óһ̨ÐÅÈÎÖ÷»úÉϼì²éÆäËüϵͳ£¬¸´ÖÆtripwire¼°ÆäÊý¾Ý¿â£¬Í¨¹ýSSHÔ¶³ÌÔËÐÐËü£¬¼ì²éÍêºó£¬
ɾ³ýÊý¾Ý¿âÎļþ¡£
* ÕâÑùʹµÃ¹¥»÷ÕßÄÑÓÚ¾õ²ìϵͳ²ÉÓÃÁËtripwire½øÐÐ¼à¿Ø¡£
* ÔĶÁ½Å±¾trip_host.sh£¬¹ýÂ˵ô¡°ÎÞÎļþ¼°Ä¿Â¼¡±±¨´í¡£Ëü±ØÐë´Ó¡®master'Ö÷»úÉÏÔËÐУ¬¶ÔÄ¿
±ê»úÓÐSSHÐÅÈιØÏµ¡£
µÚÒ»´ÎÔËÐÐ
/secure/tripwire/trip_host.sh -init HOST
ÒÔºóÿ´ÎÔËÐÐ
/sevure/tripwire/trip_host.sh -check HOST
½«databaseÎļþÍ×ÉÆ±£´æ¡£
12¡¢°²×°¡¢²âÊÔ¡¢¼Ó¹ÌÓ¦ÓóÌÐò
ÌØ¶¨µÄÓ¦Óã¬ÈçFTP¡¢DNS¡¢EmailµÈ½«ÔÚÆäËüÎÄÕÂÖÐÂÛÊö¡£
13¡¢¿ªÊ¼Ê¹ÓÃ
×¼±¸Ê¹ÓÃ
1£®Èç¹û²»ÔÙÐèҪʹÓÃCD-ROM£¬ÔÚ/etc/yassp.confÖйرÕvolume manager¡£Èç¹ûÔÚ½ñºóÐèÒª°²×°
CD£¬ÊÖ¹¤Æô¶¯vold½øÐÐÐÂÉ豸µÄ¼ì²â£º
drvconfig;disks;vold &; df -k
2£®Èç¹ûÔÚ°²×°µ÷ÊԵĹý³Ìµ±ÖУ¬±ØÐ뽫/opt¼°/usr·ÖÇø°²×°³ÉΪread-write£¬ÄÇô´Ëʱ£¬½«ËüÃÇ
mount³ÉΪread-only¡£
3£®ÖØÐÂ×ötripwireµÄ³õʼ»¯¡£
4£®½«ÏµÍ³±¸·Ýµ½Á½ÅÌ´Å´øÉÏ£¬one offsite¡£
5£®Ê¹ÓÃɨÃèÆ÷ɨÃèϵͳ£¬È·±£Ö»ÓÐÐèÒªµÄ·þÎñ¿ªÆô¡£
6£® ÇëÆäËûÈË×ö²âÊÔ£¬±ÜÃâÒÅ©¡£
7£® Ïêϸ¼ì²é-ʲôÔÚ¹¤×÷£¿Ê²Ã´±»½ûÖ¹£¿¼ì²é¿ØÖÆÌ¨/logµÄÄÚÈÝ£¬ÏµÍ³ÊÇ·ñÈçÏ£ÍûÄÇÑù¹¤×÷£¿¾
³£¼ì²éÈÕÖ¾¼Ç¼¡£
ÈÕ³£Î¬»¤
* ʹÓÃSunµÄPatchdiag½øÐв¹¶¡µÄ¼ì²é£¬ÐèÒª¾Í½øÐÐÉý¼¶¡£¶ÔÓÚÄں˵IJ¹¶¡£¬ÒªÔÚ±ðµÄ»úÆ÷ÉÏÏÈ
½øÐвâÊÔ¡£
* ¼ì²éËùÓеĴíÎóÈÕÖ¾¼°Òì³£ÐÐΪ£ºsyslog(/var/adm/messages»ò
/var/log/*log),/var/cron/log,last,/var/adm/sulog,/var/adm/loginlog,application/server
ÈÕÖ¾¼Ç¼¡£
* ±àд½Å±¾£¬±¨¸æ¹Ø¼ü½ø³ÌÊÇ·ñÕý³££¬¹Ø¼üµÄϵͳÊÇ·ñ¿ÉÒÔpingͨ¡£
* ÔËÐÐtripwire¡£
* ¶¨ÆÚ²é¿´×îеĩ¶´¼°·çÏÕ±¨¸æ¡£
===================================================================================
´ËÎĵÄÔÎÄÔÚÕâÀï
http://www.boran.com/security/sp/Solaris_hardening3.html
ÎÒˮƽÓÐÏÞ£¬·ÒëÖÐÒ»¶¨Óкܶà´íÎ󣬶øÇÒÒ²Óв»ÉÙ²»Ã÷°×µÄµØ·½£¬Ï£Íû´ó¼ÒÒ»ÆðÌÖÂÛ£¬Ö¸³ö
ÆäÖÐÀí½â´íÎóµÄµØ·½£¬¹²Í¬Ìá¸ß¡£
¶«·½
2001.3.16
×îÐÂÆÀÂÛ¹²ÓÐ 0 Î»ÍøÓÑ·¢±íÁËÆÀÂÛ
²é¿´ËùÓÐÆÀÂÛ
·¢±íÆÀÂÛ
- ÔÞÖúÉÌÁ¬½Ó
ÈÈµã¹Ø×¢
- SolarisʹÓü¼ÇÉ
- SolarisÊý¾Ý±¸·ÝÃüÁî
- Sun RPC ±à³Ì¼ò½é
- Sun Solaris Óû§ÊÖ²á --
- Solarisϵͳ¹ÜÀíÅàѵ£¨µÚ
- Sun Solaris Óû§ÊÖ²á --
- Solarisϵͳ¹ÜÀíÅàѵ£¨µÚ
- SolarisÍøÂç¹ÜÀíÅàѵ£¨µÚ
- Solaris7 ½»Á÷ --- swap¹Ü
- SolarisÈçºÎ¸Ä±äϵͳÔËÐÐ
- SolarisÐÔÄÜ¼à¿ØµÄSwap¿Õ
- SolarisÈçºÎÔö¼ÓÓû§?(gro
- ÔÚSolarisϵͳÖа²×°GCC±à
- fsckÃüÁî
- Solaris7 ½»Á÷ --- ½ø³Ì¹Ü
- SUNÈí¼þ°ü¹ÜÀíµÄÃüÁpkg
- solarisÖеĽø³Ì¹¤¾ß
- Solarisϵͳ¹ÜÀíÅàѵ£¨µÚ
- Solaris 8 ÈçºÎ´òÓ¡ÖÐÎÄ(
- SolarisÍøÂç¹ÜÀíÅàѵ£¨µÚ