全部指南
本页内容
新服务器上线后不久就会遭到自动化的登录尝试。请在最初的一小时内按顺序完成本清单。命令适用于 Debian 和 Ubuntu,AlmaLinux 和 Rocky Linux 有所不同之处会另行说明。在创建 sudo 用户之前,请以 root 身份运行这些命令,并将 aliceSERVER_IP
安装更新并开启自动安全更新
apt update
apt full-upgrade -y
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades
在对话框中选择“Yes”。该操作会写入 /etc/apt/apt.conf.d/20auto-upgrades,此后安全更新将每天自动安装。如需在更新要求重启时(例如安装了新内核)自动重启,请在 /etc/apt/apt.conf.d/50unattended-upgrades 中设置以下几行:
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
在 AlmaLinux 和 Rocky Linux 上,安装 /etc/dnf/automatic.confupgrade_type = securityapply_updates = yes
dnf upgrade --refresh -y
dnf install -y dnf-automatic
systemctl enable --now dnf-automatic.timer
如果内核已更新,请重启。
创建 sudo 用户
以 root 身份工作时,每一个输入错误都会变成影响整个系统的更改,而且 root 是攻击者最先尝试的账户。请创建一个拥有 sudo 权限的个人账户:
apt install -y sudo
adduser alice
usermod -aG sudo alice
在 AlmaLinux 和 Rocky Linux 上,管理员组名为 wheel
useradd -m -G wheel alice
passwd alice
使用 SSH 密钥登录
在您的电脑上创建一个受密码短语保护的密钥对,将公钥复制到新账户,然后用它登录,并检查 sudo 是否可用:
ssh-keygen -t ed25519 -C "alice laptop"
ssh-copy-id alice@SERVER_IP
ssh alice@SERVER_IP
sudo -v
在 Windows 上,请使用快速入门指南中的 PowerShell 命令代替 ssh-copy-id
禁用密码登录和 root 登录
只有在新用户的密钥登录和 sudo 都正常可用后,才可继续。创建 /etc/ssh/sshd_config.d/00-hardening.conf,写入以下内容:
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
X11Forwarding no
AllowUsers alice
00-sshd_config.dsshd_config50-cloud-init.conf01-permitrootlogin.confAllowUsers
sshd -t
sshd -T | grep -Ei 'permitrootlogin|passwordauthentication|kbdinteractive|allowusers'
systemctl restart ssh
在 AlmaLinux 和 Rocky Linux 上,该服务名为 sshdalice
更改 SSH 端口(可选)
非标准端口可以消除日志中大部分来自机器人的噪音,但它并不是安全边界:扫描仍然能找到它,每条 ssh、scp 和 rsync 命令都需要指定端口,而且有些网络会封锁不常见的端口。如果只允许密钥登录,继续使用 22 端口也没有问题。如果仍要更改,请将 Port 2222
ufw allow 2222/tcp
systemctl restart ssh
systemctl daemon-reload
systemctl restart ssh.socket
在 AlmaLinux 和 Rocky Linux 上,还必须让 SELinux 和 firewalld 放行新端口:
dnf install -y policycoreutils-python-utils
semanage port -a -t ssh_port_t -p tcp 2222
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload
systemctl restart sshd
在删除 22 端口的规则之前,请先从新的终端测试新端口:
ssh -p 2222 alice@SERVER_IP
设置防火墙
Debian 和 Ubuntu 上的 ufw
apt install -y ufw
ufw default deny incoming
ufw default allow outgoing
ufw limit 22/tcp
ufw allow 443/tcp
ufw enable
ufw status verbose
limit
使用 nftables
如需直接控制,请将您自己的规则集写入 /etc/nftables.conf
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
ct state established,related accept
ct state invalid drop
iif "lo" accept
meta l4proto { icmp, ipv6-icmp } accept
tcp dport { 22, 443 } accept
}
}
检查该文件,然后立即加载,并设置为每次启动时自动加载:
nft -c -f /etc/nftables.conf
systemctl enable --now nftables
ufw 和您自己的 nftables 文件只能二选一,不要同时使用。flush ruleset
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
使用 fail2ban 拦截暴力破解
apt install -y fail2ban python3-systemd
创建 /etc/fail2ban/jail.localignoreipport
[DEFAULT]
backend = systemd
bantime = 1h
ignoreip = 127.0.0.1/8 ::1 YOUR_IP
[sshd]
enabled = true
port = 22
systemctl enable fail2ban
systemctl restart fail2ban
fail2ban-client status sshd
systemd/var/log/auth.log
fail2ban-client set sshd unbanip IP_ADDRESS
在 AlmaLinux 和 Rocky Linux 上,fail2ban 由 EPEL 提供:
dnf install -y epel-release
dnf install -y fail2ban
在仅允许密钥登录的 SSH 上,fail2ban 主要用于减少日志噪音;对于接受密码登录的服务,它的作用更大。
保持时钟同步
timedatectl set-ntp true
timedatectl set-timezone UTC
timedatectl
确认输出中有 System clock synchronized: yes。如果 set-ntp
apt install -y systemd-timesyncd
AlmaLinux 和 Rocky Linux 默认启用 chrony。准确的时间对 TLS、一次性密码、日志关联分析和 Tor 都很重要;使用 UTC 可以让多台服务器的日志便于相互比对。
使用 Lynis 进行审计
apt install -y lynis
lynis audit system
Lynis 会检查数百项设置,并输出警告、建议和加固指数。详细信息会写入 /var/log/lynis.log/var/log/lynis-report.dat
提前做好备份
加固可以降低风险;备份则能让事件发生后得以恢复。在 VPS 上,完成本清单后请创建一个快照,并按照 VPS 快照与异地备份中的说明,使用 restic 或 Borg 设置加密的异地备份。请将备份仓库设为仅追加模式,这样即使入侵者进入服务器,也无法删除您的历史备份。
Tor 中继与 VPN 服务器注意事项
Tor 中继
- 我们的运行 Tor 中继、网桥或洋葱服务指南提供了每种角色的完整设置步骤。
- 非出口中继和网桥只在 Tor 网络内部传递加密流量;请在
中写入/etc/tor/torrc ,将这一点明确下来。ExitRelay 0 - 出口中继则不同:它们发往网站的流量看起来来自您的 IP,并会招来滥用举报。运行出口中继之前,请阅读可接受使用政策。出站 25 端口默认关闭。
- 从 Tor 项目的软件仓库安装 tor,并让 unattended-upgrades 自动更新它;Tor 中继指南给出了适用于 Debian 和 Ubuntu 的确切 origin 配置行。
- 在防火墙中只开放 ORPort,并将任何 ControlPort 或指标端口都限制在 localhost 上。
- 带宽在合理使用范围内不限流量。如果预计会有持续的大流量,请在
中使用torrc 和RelayBandwidthRate (或RelayBandwidthBurst )设置上限。AccountingMax - 请用一台单独的服务器运行中继:中继地址是公开的,许多服务都会封锁这些地址。
WireGuard VPN 服务器
从密钥到手机客户端的完整设置步骤,请参阅如何使用 WireGuard 自建 VPN。简而言之:开放 WireGuard 端口,启用 IP 转发,只允许从隧道到公网接口的转发(可用 ip -br addr
ufw allow 51820/udp
echo 'net.ipv4.ip_forward=1' > /etc/sysctl.d/99-wireguard.conf
sysctl --system
ufw route allow in on wg0 out on eth0
chmod 600 /etc/wireguard/wg0.conf
- 为隧道的地址段添加 NAT;如果需要路由 IPv6,还要启用 IPv6 转发。
- VPN 用户的流量会通过您服务器的 IP 发出。根据可接受使用政策,他们发送的垃圾邮件、扫描和攻击都视为来自您的服务器,因此请只向您信任的人提供访问权限。
- WireGuard 本身不保留连接日志。如果您向用户承诺不记录日志,还请检查 journald 和防火墙的日志记录。
如果服务器遭到入侵
典型迹象:不明进程占用 CPU、出现意料之外的出站流量、出现新的账户或 SSH 密钥,或者收到我们发出的滥用通知。
- 控制事态。首先阻止向外发起的攻击:在防火墙中阻断出站流量,或关闭服务器。根据可接受使用政策中的零容忍规则,对于从我们网络发起的攻击,我们会立即采取行动,即使服务器是被劫持的也不例外。
- 保全证据。在 VPS 上,请在做任何更改之前创建快照,并将日志复制到服务器之外。
- 展开调查:使用下面的命令检查登录记录、开放端口、进程、cron 任务、服务、root 的 SSH 密钥,以及用户 ID 为 0 的账户。
- 轮换服务器上存放过的所有密钥和凭据:密码、SSH 密钥(请在干净的机器上生成新密钥)、访问令牌、数据库密码和 TLS 私钥。
- 重建。从干净的模板重装系统,用入侵发生之前的备份恢复数据,执行本清单中的步骤,并堵上攻击者利用的漏洞,例如过时的插件、弱密码或暴露在外的服务。
- 告知我们。如果是独立服务器或 GPU 服务器,请通过工单回复我们的滥用通知,说明您发现并修复了哪些问题,或者请求帮助。
last -a
ss -tulpn
ps auxf
ls -la /etc/cron.d /var/spool/cron
systemctl list-units --type=service --state=running
cat /root/.ssh/authorized_keys
awk -F: '$3 == 0' /etc/passwd