Linux/CentOS server security configuration general guide

Linux is an open system. Many ready-made programs and tools can be found on the Internet. This is not only convenient for users, but also for hackers, because they can easily find programs and tools to sneak into the Linux system or steal Linux. Important information on the system. However, as long as we carefully set the various system functions of Linux, and add the necessary security measures, hackers can not take advantage of it.

Generally speaking, the security settings for Linux systems include canceling unnecessary services, restricting remote access, hiding important information, patching security vulnerabilities, using security tools, and regular security checks.

This article is a practical operation that can be referred to. It does not involve principles such as IP spoofing, and security issues are not preventable by a few lines of commands.

This is just a basic security reinforcement method on Linux systems, and new content will be added later.

Note: All files must be backed up before modification such as

cp /etc/passwd{,.dist}

1. Linux disables unused users

Note: It is not recommended to delete it directly. When you need a user, adding it yourself will be troublesome. It can also be locked by usermod -L or passwd -l user .

cp /etc/passwd{,.bak} backup before modification

vi /etc/passwd edit the user, add # in front of the comment out this line

Annotated user name:

# cat /etc/passwd|grep ^#
# adm:x:3:4:adm:/var/adm:/sbin/nologin
# lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
# shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
# halt:x:7:0:halt:/sbin:/sbin/halt
# uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
# operator:x:11:0:operator:/root:/sbin/nologin
# games:x:12:100:games:/usr/games:/sbin/nologin
# gopher:x:13:30:gopher:/var/gopher:/sbin/nologin
# ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
# nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
# postfix:x:89:89::/var/spool/postfix:/sbin/nologin

**Linux commented group: **

# cat /etc/group|grep ^#
# adm:x:4:adm,daemon
# lp:x:7:daemon
# uucp:x:14:
# games:x:20:
# gopher:x:30:
# video:x:39:
# dip:x:40:
# ftp:x:50:
# audio:x:63:
# floppy:x:19:
# postfix:x:89:

2. Linux shuts down unused services

# chkconfig --list |grep '3:on'

Mail service, using company mail server:

service postfix stop
chkconfig postfix --level 2345 off

General unix printing service, useless to the server:

service cups stop
chkconfig cups --level 2345 off

Adjust cpu speed to save power, commonly used on Laptop:

service cpuspeed stop
chkconfig cpuspeed --level 2345 off

Bluetooth wireless communication is useless for the server:

service bluetooth stop
chkconfig bluetooth --level 2345 off

After the system is installed, the initial settings are useless after starting the system for the first time:

service firstboot stop
chkconfig firstboot --level 2345 off

Linux closes the nfs service and client:

service netfs stop
chkconfig netfs --level 2345 off
service nfslock stop
chkconfig nfslock --level 2345 off

If you want to restore a certain service, you can do the following:

service acpid start && chkconfig acpid on

You can also use the setup tool to set

3. Linux disable IPV6

IPv6 is to solve the problem of IPv4 address exhaustion, but our servers generally do not use it. On the contrary, disabling IPv6 will not only speed up the network, but also help reduce management overhead and improve security levels. The following steps completely disable ipv6 on CentOS.

Linux prohibits the loading of IPv6 modules:

To prevent the system from loading ipv6 related modules, this needs to modify the modprobe related setting files. For management convenience, we create a new setting file /etc/modprobe.d/ipv6off.conf, the content is as follows

alias net-pf-10 off
options ipv6 disable=1

Linux disables IPv6-based networks so that they will not be triggered to start:

# vi /etc/sysconfig/network
NETWORKING_IPV6=no

Linux disables the IPv6 setting of the network card so that it only runs in IPv4 mode:

# vi /etc/sysconfig/network-scripts/ifcfg-eth0
IPV6INIT=no
IPV6_AUTOCONF=no

Linux close ip6tables:

# chkconfig ip6tables off

Restart the system and verify that it takes effect:

# lsmod | grep ipv6
# ifconfig | grep -i inet6

If there is no output, then the IPv6 module has been disabled, otherwise it is enabled.

4. Linux iptables rules

Enable linux firewall to prohibit illegal program access. Use iptable rules to filter inbound, outbound and forwarded packets. We can grant and deny access to specific udp/tcp ports for source and destination addresses.

For the firewall setting rules, please refer to the blog post iptables setting examples.

5. Linux SSH security

If possible, the first thing is to modify the default port 22 of ssh. Changing to a larger port such as 20002 will greatly increase the safety factor and reduce the possibility of ssh cracking the login.

Create recognizable application users such as crm and system management users sysmgr

# useradd crm -d /apps/crm
# passwd crm

# useradd sysmgr
# passwd sysmgr

5.1 Linux only allows user su in the wheel user group to switch

# usermod -G wheel sysmgr

# vi /etc/pam.d/su
# Uncomment the following line to require a user to be in the "wheel" group.
auth      required    pam_wheel.so use_uid

If other users switch to root, they will prompt su: incorrect password even if they enter the correct password

5.2 Linux login timeout

If the user is online for 5 minutes without any operation, the connection will be overtime and disconnected. Add in /etc/profile:

export TMOUT=300
readonly TMOUT

5.3 Linux prohibits root direct remote login

# vi /etc/ssh/sshd_config
PermitRootLogin no

5.4 Linux limits the number of failed logins and locks out

Add after /etc/pam.d/login

auth required pam_tally2.so deny=6 unlock_time=180 even_deny_root root_unlock_time=180

Login failed 5 times and locked for 180 seconds. Set whether to include root as required.

5.5 Linux login IP restrictions

(Because it is bound to a fixed IP or IP segment, it has not been set yet)

A stricter restriction is to define the user and source ip that allows ssh in sshd_config:

## allowed ssh users sysmgr
AllowUsers [email protected].*
Or use tcpwrapper:

vi /etc/hosts.deny
sshd:all
vi /etc/hosts.allow
sshd:172.29.73.23
sshd:172.29.73.

6. Linux configuration can only log in with the key file

Using key files instead of ordinary simple password authentication will also greatly improve security:

[ dir@username ~]$ ssh-keygen -t rsa -b 2048
Generating public/private rsa key pair.
Enter file in which to save the key(/root/.ssh/id_rsa)://Default path, press enter
Enter passphrase(empty for no passphrase)://Enter your key phrase to use when logging in
Enter same passphrase again: 
Your identification has been saved in/root/.ssh/id_rsa.
Your public key has been saved in/root/.ssh/id_rsa.pub.
The key fingerprint is:
3 e:fd:fc:e5:d3:22:86:8e:2c:4b:a7:3d:92:18:9f:64 [email protected]
The key's randomart image is:+--[ RSA 2048]----+||
…
| o++o..oo..o|+-----------------+

Rename the public key to authorized_key:

$ mv ~/.ssh/id_rsa.pub ~/.ssh/authorized_keys
$ chmod 600~/.ssh/authorized_keys

Download the private key file id_rsa to the local (for easier identification, you can rename it to hostname_username_id_rsa) and save it in a safe place. In the future, the username user must use this private key to log in to this host, with a passphrase (the username user’s own password is no longer used)

Also modify the /etc/ssh/sshd_config file

Open comment

RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile   .ssh/authorized_keys

We require the username user (can switch to other users, especially root) to log in with the ssh key file, while other ordinary users can log in directly with the password. Therefore, it is necessary to add at the end of the sshd_config file:

Match User itsection
 PasswordAuthentication no

Restart the sshd service

# service sshd restart

Another reminder, this pair of public and private keys must be stored separately on another machine. Loss of the public key on the server or the loss of the private key (or key phrase) on the connection end may result in no longer being able to log in to the server to obtain root privileges!

7. Linux reduces history command records

The more historical commands that have been executed, the more convenient maintenance will be brought to a certain extent, but it will also be accompanied by security issues

vi /etc/profile

Find HISTSIZE=1000 and change it to HISTSIZE=50.

Or clean up history, history -c every time you exit

8. Linux enhanced special file permissions

Add unchangeable attributes to the following files to prevent unauthorized users from gaining permissions

chattr +i /etc/passwd
chattr +i /etc/shadow
chattr +i /etc/group
chattr +i /etc/gshadow
chattr +i /etc/services #Lock the system service port list file to prevent unauthorized deletion or addition of services
chattr +i /etc/pam.d/su
chattr +i /etc/ssh/sshd_config

Show file attributes

lsattr /etc/passwd /etc/shadow /etc/services /etc/ssh/sshd_config

Note: After performing the above chattr permission modification, users cannot be added or deleted.

If you want to add or delete users, you need to cancel the above settings first, and then perform the above operations after the user is added and deleted, such as canceling the read-only permission chattr -i /etc/passwd. (Remember to reset read-only)

9. Linux prevents general network attacks

Network attacks cannot be avoided with a few lines of settings. The following are just some simple ways to minimize the possibility and increase the difficulty of the attack, but they cannot be completely prevented.

9.1 Linux prohibits ping

Preventing ping If no one can ping your system, the security is naturally increased and ping floods can be effectively prevented. To this end, you can add the following line to the /etc/rc.d/rc.local file:

# echo 1>/proc/sys/net/ipv4/icmp_echo_ignore_all

Or use iptable to ban ping:

iptables -A INPUT -p icmp --icmp-type 0-s 0/0-j DROP

Not allowed to ping other hosts:

iptables -A OUTPUT -p icmp --icmp-type 8-j DROP

9.2. Linux prevents IP spoofing

Edit the /etc/host.conf file and add the following lines to prevent IP spoofing attacks.

order hosts,bind  #Name interpretation order
multi on      #Allow the host to have multiple IP addresses
nospoof on     #Prohibit IP address spoofing

9.3 Linux prevents DoS attacks

Setting resource limits for all users of the system can prevent DoS attacks, such as the maximum number of processes and memory usage.
You can add the following lines in /etc/security/limits.conf:

* soft  core  0*  soft  nproc  2048*  hard  nproc  16384*  soft  nofile 1024*  hard  nofile 65536

core 0 means that it is forbidden to create core files; nproc 128 limits the maximum number of processes to 20; nofile 64 means that the maximum number of files opened by a user at the same time is limited to 64; * means all users who log in to the system, excluding root

Then you must edit the /etc/pam.d/login file to check whether the following line exists.

session required pam_limits.so

The value of the limits.conf parameter needs to be adjusted according to the specific situation.

10. Linux fixes known security vulnerabilities

Destructive vulnerabilities, such as udev, heartbleed, shellshock, ghost, etc., are occasionally exposed on Linux. If the server is exposed to the external network, it must be fixed in time.

11. Linux regularly performs log security checks

Move the log to a dedicated log server, which can prevent intruders from easily changing the local log. The following are common linux default log files and their uses:

/var/log/message-Record system log or current activity log.
/var/log/auth.log-Identity authentication log.
/var/log/cron-Crond log(cron task)./var/log/maillog-mail server log.
/var/log/secure-authentication log.
/var/log/wtmp historical login, logout, startup, shutdown logs and lastb command can view users who failed to log in
/var/run/utmp currently logged in user information log, the source of the information for the w and who commands
/var/log/yum.log Yum log.

Refer to the in-depth analysis CentOS to check the intrusion through logs.

11.1 Linux install logwatch

Logwatch is a log analysis tool developed using Perl. It can analyze Linux log files and automatically send mail to relevant processing personnel, and can customize requirements.

The mail function of Logwatch uses the mail server that comes with the host system to send mail, so the system needs to install a mail server, such as sendmail, postfix, Qmail, etc.

For installation and configuration methods, see the blog post linux log monitoring logwatch.

12. Linux web server security

When configuring server programs like apache or tomcat, if there are security problems, you can consult the documentation for security reinforcement. There will be time to add new articles in the future.

Recommended Posts

Linux/CentOS server security configuration general guide