谈谈 ubuntu 的 VPS 安全问题 - V2EX
V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
johnnyR

谈谈 ubuntu 的 VPS 安全问题

  •  
  •   johnnyR Aug 14, 2015 4733 views
    This topic created in 3911 days ago, the information mentioned may be changed or developed.

    防火墙要安装吗?装什么好呢?
    基本的安全配置有哪些?
    怎样防止C段?

    13 replies    2015-08-14 23:50:35 +08:00
    crazycen
        1
    crazycen  
       Aug 14, 2015 via Android
    只开80 443 和ssh端口,使用证书登陆vps。汗忘了还有ss端口。一共4个端口
    scys
        2
    scys  
       Aug 14, 2015
    ss 是必备的了?
    Pastsong
        3
    Pastsong  
       Aug 14, 2015
    fail2ban ufw或iptables
    xqdoo00o
        4
    xqdoo00o  
       Aug 14, 2015 via Android
    谷歌两步验证 fail2ban
    Starduster
        5
    Starduster  
       Aug 14, 2015
    个人感觉 VPS 其实没多大必要,又不会有什么重要的东西,VPS 控制台权限在你手上你就有最高控制权,备份做好,最不济的情况也就 rebuild,而且设防火墙经常给自己使用带来麻烦
    防火墙默认入站规则 reject 手动添加需要的服务和端口,SSH 加上密钥关闭密码登陆,再进一步可以设置允许登陆的 IP 段
    johnnyR
        6
    johnnyR  
    OP
       Aug 14, 2015
    有防C段的招数吗
    skydiver
        7
    skydiver  
       Aug 14, 2015
    C段是啥?
    Wice
        8
    Wice  
       Aug 14, 2015
    C段是啥?+1
    ipconfiger
        9
    ipconfiger  
       Aug 14, 2015
    @Starduster 刚开始也这么想的,结果被人肉鸡了,在linode上跑了超了流量多耗了30美刀,后来还是老实的吧iptables配好就啥事没有了
    47jm9ozp
        10
    47jm9ozp  
       Aug 14, 2015
    arno-iptables-firewall
    fail2ban
    google-authenticator
    msg7086
        11
    msg7086  
       Aug 14, 2015
    @ipconfiger fail2ban+证书验证,还能被人肉鸡?
    ipconfiger
        12
    ipconfiger  
       Aug 14, 2015
    @msg7086 当时是裸奔的
    msg7086
        13
    msg7086  
       Aug 14, 2015
    @ipconfiger 嗯裸奔作死,最少也要上fail2ban。
    About     Help     Advertise     Blog     API     FAQ     Solana     4896 Online   Highest 6679       Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 51ms UTC 03:51 PVG 11:51 LAX 20:51 JFK 23:51
    Do have faith in what you're doing.
    ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86