日本免费全黄少妇一区二区三区-高清无码一区二区三区四区-欧美中文字幕日韩在线观看-国产福利诱惑在线网站-国产中文字幕一区在线-亚洲欧美精品日韩一区-久久国产精品国产精品国产-国产精久久久久久一区二区三区-欧美亚洲国产精品久久久久

Solaris 初步設置( 二 )


# ssh-keygen -t rsa -f /usr/local/etc/ssh_host_rsa_key -N ""
# vi /etc/init.d/sshd
===========================sshd============================
#!/sbin/sh
#
# Copyright (c) 2001 by Sun Microsystems, Inc
# All rights reserved.
#
#ident "@(#)sshd 1.1 01/09/24 SMI"

case "$1" in
start)
/usr/local/sbin/sshd

stop)
pkill sshd

*)
echo "Usage: $0 { start | stop }"
exit 1

esac
exit 0
===========================sshd============================
# chmod 750 /etc/init.d/sshd
# chown root:sys /etc/init.d/sshd
# ln –s /etc/init.d/sshd /etc/rc2.d/S98sshd
# vi /etc/hosts.deny
sshd:ALL
# vi /etc/hosts.allow
sshd:192.168.0.15
# rm /.ssh/*

8.安裝SAMBA-3

# cp /etc/rc3.d/S90samba bak.S90samba
# pkgrm SUNWsmbac SUNWsmbar SUNWsmbau
# gzip -d samba-3.0.2a-sol9-intel-local.gz
# gzip -d popt-1.7-sol9-intel-local.gz
# pkgadd -d popt-1.7-sol9-intel-local
# pkgadd -d samba-3.0.2a-sol9-intel-local
# cd /usr/local/samba/doc/samba/examples/
# cp smb.conf.default /usr/local/samba/lib/smb.conf
# 設置smb.conf文件過程略
# mv /etc/rc3.d/bak.S90samba S90samba
# chown root:sys /etc/rc3.d/S90samba
# vim /etc/rc3.d/S90samba
=======================S90samba========================
#!/sbin/sh
#
# Copyright (c) 2001 by Sun Microsystems, Inc
# All rights reserved.
#
#ident "@(#)samba 1.1 01/09/24 SMI"

case "$1" in
start)
[ -f /usr/local/samba/lib/smb.conf ] || exit 0

/usr/local/samba/sbin/smbd -D
/usr/local/samba/sbin/nmbd -D

stop)
pkill smbd
pkill nmbd

*)
echo "Usage: $0 { start | stop }"
exit 1

esac
exit 0
=======================S90samba========================

9.初步的系統(tǒng)安全設置

為安全起見在/etc/inetd.conf中注釋掉除下列服務的所有服務

ftp
echo
echo
discard
discard
rstatd/2-4
fs
100083/1

在只需要不多圖形操作的服務器或是要保證相當?shù)陌踩阋苍S應該關掉字體服務fs,也可以關掉系統(tǒng)性能監(jiān)視器rstatd和tooltalk服務器ttdbserverd(100083/1),查找剩下需要關閉的端口的進程用這個命令:
# /usr/local/bin/lsof -i | grep port

為安全起見在防止堆棧溢出

# cp /etc/system /etc/system.BACKUP
# vi /etc/system
在文件的最后,加上以下兩行:
set noexec_user_stack=1
set noexec_user_stack_log=1

禁用自動啟動DESKTOP

# /usr/dt/bin/dtconfig –d

為安全起見停掉幾個系統(tǒng)服務:

卸載SENDMAIL:
# pkgrm SUNWsndmr SUNWsndmu
卸載TELNET:
# pkgrm SUNWtnetc SUNWtnetd SUNWtnetr
# cd /etc/rc2.d
# mv S71ldap.clIEnt _S71ldap.client
# mv S72inetsvc _S72inetsvc
# mv S74autofs _S74autofs
# mv S74xntpd _S74xntpd
# mv S80lp _S80lp
# mv S71rpc _S71rpc
# mv S73nfs.client _S73nfs.client

# cd /etc/rc3.d
# mv S34dhcp _S34dhcp
# mv S15nfs.server _S15nfs.server
# mv S76snmpdx _S76snmpdx

卸載PCMCIA支持:
# pkgrm SUNWpcelx SUNWpcmci SUNWpcmcu SUNWpcmem SUNWpcser SUNWPSdpr

安裝PORT掃描工具NMAP

# gzip -d nmap-3.50-sol9-intel-local.gz
# gzip -d pcre-4.5-sol9-intel-local.gz
# pkgadd -d nmap-3.50-sol9-intel-local
# pkgadd -d pcre-4.5-sol9-intel-local
掃描本機端口:
# nmap -P0 -sT localhost

安裝網(wǎng)絡漏洞掃描工具NESSUS:

# gzip -d nessus-2.0.9-sol9-intel-local.gz
# pkgadd -d nessus-2.0.9-sol9-intel-local
建立SSL證書:
# nessus-mkcert
添加NESSUS用戶:
# nessus-adduser
以ROOT啟動NESSUS服務器:
# nessus –D
啟動NESSUS的GUI客戶端:
# nessus

推薦閱讀