Linux is an open system. Many ready-made programs and tools can be found on the Internet. This is not only convenient for users, but also for hackers, because they can easily find programs and tools to sneak into the Linux system or steal Linux. Important information on the system. However, as long as we carefully set the various system functions of Linux, and add the necessary security measures, hackers can not take advantage of it.
Generally speaking, the security settings for Linux systems include canceling unnecessary services, restricting remote access, hiding important information, patching security vulnerabilities, using security tools, and regular security checks.
This article is a practical operation that can be referred to. It does not involve principles such as IP spoofing, and security issues are not preventable by a few lines of commands.
This is just a basic security reinforcement method on Linux systems, and new content will be added later.
Note: All files must be backed up before modification such as
cp /etc/passwd{,.dist}
1. Linux disables unused users
Note: It is not recommended to delete it directly. When you need a user, adding it yourself will be troublesome. It can also be locked by usermod -L or passwd -l user .
cp /etc/passwd{,.bak} backup before modification
vi /etc/passwd edit the user, add # in front of the comment out this line
Annotated user name:
# cat /etc/passwd|grep ^#
# adm:x:3:4:adm:/var/adm:/sbin/nologin
# lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
# shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
# halt:x:7:0:halt:/sbin:/sbin/halt
# uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
# operator:x:11:0:operator:/root:/sbin/nologin
# games:x:12:100:games:/usr/games:/sbin/nologin
# gopher:x:13:30:gopher:/var/gopher:/sbin/nologin
# ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
# nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
# postfix:x:89:89::/var/spool/postfix:/sbin/nologin
**Linux commented group: **
# cat /etc/group|grep ^#
# adm:x:4:adm,daemon
# lp:x:7:daemon
# uucp:x:14:
# games:x:20:
# gopher:x:30:
# video:x:39:
# dip:x:40:
# ftp:x:50:
# audio:x:63:
# floppy:x:19:
# postfix:x:89:
2. Linux shuts down unused services
# chkconfig --list |grep '3:on'
Mail service, using company mail server:
service postfix stop
chkconfig postfix --level 2345 off
General unix printing service, useless to the server:
service cups stop
chkconfig cups --level 2345 off
Adjust cpu speed to save power, commonly used on Laptop:
service cpuspeed stop
chkconfig cpuspeed --level 2345 off
Bluetooth wireless communication is useless for the server:
service bluetooth stop
chkconfig bluetooth --level 2345 off
After the system is installed, the initial settings are useless after starting the system for the first time:
service firstboot stop
chkconfig firstboot --level 2345 off
Linux closes the nfs service and client:
service netfs stop
chkconfig netfs --level 2345 off
service nfslock stop
chkconfig nfslock --level 2345 off
If you want to restore a certain service, you can do the following:
service acpid start && chkconfig acpid on
You can also use the setup tool to set
3. Linux disable IPV6
IPv6 is to solve the problem of IPv4 address exhaustion, but our servers generally do not use it. On the contrary, disabling IPv6 will not only speed up the network, but also help reduce management overhead and improve security levels. The following steps completely disable ipv6 on CentOS.
Linux prohibits the loading of IPv6 modules:
To prevent the system from loading ipv6 related modules, this needs to modify the modprobe related setting files. For management convenience, we create a new setting file /etc/modprobe.d/ipv6off.conf, the content is as follows
alias net-pf-10 off
options ipv6 disable=1
Linux disables IPv6-based networks so that they will not be triggered to start:
# vi /etc/sysconfig/network
NETWORKING_IPV6=no
Linux disables the IPv6 setting of the network card so that it only runs in IPv4 mode:
# vi /etc/sysconfig/network-scripts/ifcfg-eth0
IPV6INIT=no
IPV6_AUTOCONF=no
Linux close ip6tables:
# chkconfig ip6tables off
Restart the system and verify that it takes effect:
# lsmod | grep ipv6
# ifconfig | grep -i inet6
If there is no output, then the IPv6 module has been disabled, otherwise it is enabled.
4. Linux iptables rules
Enable linux firewall to prohibit illegal program access. Use iptable rules to filter inbound, outbound and forwarded packets. We can grant and deny access to specific udp/tcp ports for source and destination addresses.
For the firewall setting rules, please refer to the blog post iptables setting examples.
5. Linux SSH security
If possible, the first thing is to modify the default port 22 of ssh. Changing to a larger port such as 20002 will greatly increase the safety factor and reduce the possibility of ssh cracking the login.
Create recognizable application users such as crm and system management users sysmgr
# useradd crm -d /apps/crm
# passwd crm
# useradd sysmgr
# passwd sysmgr
5.1 Linux only allows user su in the wheel user group to switch
# usermod -G wheel sysmgr
# vi /etc/pam.d/su
# Uncomment the following line to require a user to be in the "wheel" group.
auth required pam_wheel.so use_uid
If other users switch to root, they will prompt su: incorrect password even if they enter the correct password
5.2 Linux login timeout
If the user is online for 5 minutes without any operation, the connection will be overtime and disconnected. Add in /etc/profile:
export TMOUT=300
readonly TMOUT
5.3 Linux prohibits root direct remote login
# vi /etc/ssh/sshd_config
PermitRootLogin no
5.4 Linux limits the number of failed logins and locks out
Add after /etc/pam.d/login
auth required pam_tally2.so deny=6 unlock_time=180 even_deny_root root_unlock_time=180
Login failed 5 times and locked for 180 seconds. Set whether to include root as required.
5.5 Linux login IP restrictions
(Because it is bound to a fixed IP or IP segment, it has not been set yet)
A stricter restriction is to define the user and source ip that allows ssh in sshd_config:
## allowed ssh users sysmgr
AllowUsers [email protected].*
Or use tcpwrapper:
vi /etc/hosts.deny
sshd:all
vi /etc/hosts.allow
sshd:172.29.73.23
sshd:172.29.73.
6. Linux configuration can only log in with the key file
Using key files instead of ordinary simple password authentication will also greatly improve security:
[ dir@username ~]$ ssh-keygen -t rsa -b 2048
Generating public/private rsa key pair.
Enter file in which to save the key(/root/.ssh/id_rsa)://Default path, press enter
Enter passphrase(empty for no passphrase)://Enter your key phrase to use when logging in
Enter same passphrase again:
Your identification has been saved in/root/.ssh/id_rsa.
Your public key has been saved in/root/.ssh/id_rsa.pub.
The key fingerprint is:
3 e:fd:fc:e5:d3:22:86:8e:2c:4b:a7:3d:92:18:9f:64 [email protected]
The key's randomart image is:+--[ RSA 2048]----+||
…
| o++o..oo..o|+-----------------+
Rename the public key to authorized_key:
$ mv ~/.ssh/id_rsa.pub ~/.ssh/authorized_keys
$ chmod 600~/.ssh/authorized_keys
Download the private key file id_rsa to the local (for easier identification, you can rename it to hostname_username_id_rsa) and save it in a safe place. In the future, the username user must use this private key to log in to this host, with a passphrase (the username user’s own password is no longer used)
Also modify the /etc/ssh/sshd_config file
Open comment
RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
We require the username user (can switch to other users, especially root) to log in with the ssh key file, while other ordinary users can log in directly with the password. Therefore, it is necessary to add at the end of the sshd_config file:
Match User itsection
PasswordAuthentication no
Restart the sshd service
# service sshd restart
Another reminder, this pair of public and private keys must be stored separately on another machine. Loss of the public key on the server or the loss of the private key (or key phrase) on the connection end may result in no longer being able to log in to the server to obtain root privileges!
7. Linux reduces history command records
The more historical commands that have been executed, the more convenient maintenance will be brought to a certain extent, but it will also be accompanied by security issues
vi /etc/profile
Find HISTSIZE=1000 and change it to HISTSIZE=50.
Or clean up history, history -c every time you exit
8. Linux enhanced special file permissions
Add unchangeable attributes to the following files to prevent unauthorized users from gaining permissions
chattr +i /etc/passwd
chattr +i /etc/shadow
chattr +i /etc/group
chattr +i /etc/gshadow
chattr +i /etc/services #Lock the system service port list file to prevent unauthorized deletion or addition of services
chattr +i /etc/pam.d/su
chattr +i /etc/ssh/sshd_config
Show file attributes
lsattr /etc/passwd /etc/shadow /etc/services /etc/ssh/sshd_config
Note: After performing the above chattr permission modification, users cannot be added or deleted.
If you want to add or delete users, you need to cancel the above settings first, and then perform the above operations after the user is added and deleted, such as canceling the read-only permission chattr -i /etc/passwd. (Remember to reset read-only)
9. Linux prevents general network attacks
Network attacks cannot be avoided with a few lines of settings. The following are just some simple ways to minimize the possibility and increase the difficulty of the attack, but they cannot be completely prevented.
9.1 Linux prohibits ping
Preventing ping If no one can ping your system, the security is naturally increased and ping floods can be effectively prevented. To this end, you can add the following line to the /etc/rc.d/rc.local file:
# echo 1>/proc/sys/net/ipv4/icmp_echo_ignore_all
Or use iptable to ban ping:
iptables -A INPUT -p icmp --icmp-type 0-s 0/0-j DROP
Not allowed to ping other hosts:
iptables -A OUTPUT -p icmp --icmp-type 8-j DROP
9.2. Linux prevents IP spoofing
Edit the /etc/host.conf file and add the following lines to prevent IP spoofing attacks.
order hosts,bind #Name interpretation order
multi on #Allow the host to have multiple IP addresses
nospoof on #Prohibit IP address spoofing
9.3 Linux prevents DoS attacks
Setting resource limits for all users of the system can prevent DoS attacks, such as the maximum number of processes and memory usage.
You can add the following lines in /etc/security/limits.conf:
* soft core 0* soft nproc 2048* hard nproc 16384* soft nofile 1024* hard nofile 65536
core 0 means that it is forbidden to create core files; nproc 128 limits the maximum number of processes to 20; nofile 64 means that the maximum number of files opened by a user at the same time is limited to 64; * means all users who log in to the system, excluding root
Then you must edit the /etc/pam.d/login file to check whether the following line exists.
session required pam_limits.so
The value of the limits.conf parameter needs to be adjusted according to the specific situation.
10. Linux fixes known security vulnerabilities
Destructive vulnerabilities, such as udev, heartbleed, shellshock, ghost, etc., are occasionally exposed on Linux. If the server is exposed to the external network, it must be fixed in time.
11. Linux regularly performs log security checks
Move the log to a dedicated log server, which can prevent intruders from easily changing the local log. The following are common linux default log files and their uses:
/var/log/message-Record system log or current activity log.
/var/log/auth.log-Identity authentication log.
/var/log/cron-Crond log(cron task)./var/log/maillog-mail server log.
/var/log/secure-authentication log.
/var/log/wtmp historical login, logout, startup, shutdown logs and lastb command can view users who failed to log in
/var/run/utmp currently logged in user information log, the source of the information for the w and who commands
/var/log/yum.log Yum log.
Refer to the in-depth analysis CentOS to check the intrusion through logs.
11.1 Linux install logwatch
Logwatch is a log analysis tool developed using Perl. It can analyze Linux log files and automatically send mail to relevant processing personnel, and can customize requirements.
The mail function of Logwatch uses the mail server that comes with the host system to send mail, so the system needs to install a mail server, such as sendmail, postfix, Qmail, etc.
For installation and configuration methods, see the blog post linux log monitoring logwatch.
12. Linux web server security
When configuring server programs like apache or tomcat, if there are security problems, you can consult the documentation for security reinforcement. There will be time to add new articles in the future.
Recommended Posts