ܦh𫎆IJ Linux Bͱ``|ݪ@yܴNOGyھ Linux NOF[]AAJMuOF[]AA٭nDz Linux
L\HҦpGҦʤu@Ƶ{BBash Shell ASFh{ѩҦnɵAڤSΤI~AJMnΪ
Web Server ]wnAiH²檺N[]_ӡA٭nhDz vim
ʪs@dz]wɡHFٻݭnhzѦAu@zHzWoǸܹǷ|[]HӻAuOL̹DXF@ӷs⪺nڡILA@ӴgL[]}BͨӻAWoǸܡAuO|`HIOHUڭ̴NӤR@UC
1.1.1 uQ Linux
[]AݭnԣOH
pGHݧAGyLinux ̱jj\OzHjja|^yO\IzAUӡApGAݡGyҥH Linux
NOF[]AoHzIoӰDiNoIFA Linux
NO@MD`íw@~tΡAu@unb Linux oӧ@~tΤW]ALNO
Linux iHF\ध@oIҥH Linux @ιbA[]oC
|ҨӻAb Linux W}oxƭȼҦ (model) ѦpjjҦAѩ Linux
íwP귽t\Aϱob Linux W}oXӪ{B@S֤SíwC~AѦp KDE, GNOME
}GϧΤAftѦp Open Office 줽dznALinux ߨn@ܦӦuq줽ǮୱqF
(Desktop)C~AGoogle s@XMtΥΪ Android ]OH Linux }oCҥHAdUnpݤF
Linux h˥\oC
LAޫA Linux jj\TOy Linux bA줺@uanءC
JMpAڭ̴Nnnӱ@U Linux @ɧaIA Linux
쩳iHFǺ\OHoiNh۫IO
WWW, Mail,
FTP, DNS, Ϊ̬O
DHCP, NAT P
Router ALinux tγiHFAӥBAun@
Linux NFWҦ\FIMAObҼ{wPįpUAAiHϥΤ@
Linux DӹFҦ\C
OAonDAy[e@zڡI`@hӻAy@٦nBڡIz[]@ӺHYϧASNL
Linux AunѦҳyΪ̬OAӥB@B@Bӵ۰A]ǧA@ӤUȴNiH[]ӥHWAȤFIҥHA
[]AHnoOAo˪@ӺAhhTѡA֫hƤpɡAߨN|QJIFI
~AQJIAγ\iHǥѤ@ǤuAN root KXϦ^ӡAiOA
o˪@Ӻ٬OQ~MIsbI
t~ApGAϥΤu (Ҧp Webmin)
o][]_ӬYӺɡAnѨMHpGA Server B@zP Linux
tΪTADuLyݻaѡHnhóoرpiʡA
ѦҤ@UUj¤WdNiHܲMDoرpsbVӶV㪺ͶթOI
ҥHA[]Ae٬O@ǰޯݭnǷ|IӥBoǧޯOy@Ƿ|AuOרΰڡIzun@ӾǴ
(T~Ӥ) NǷ|@liHϥΪޯAoӾDzߪSvuOӰFI
ҥHA@}lDzߤnıoWAuOȱoI^_^
|ҨӻAb 2003 ~ 2005 ~]hLFALܤָI Linux աIhᱵ쪺Ĥ@ӯZna Linux
ҷӮɡAXGҦObݤ_ @_@㤣LAoDzߪkAzL man աAzL google աA
zLHeDzߪ@ǷաAJDXGiHb@ѨMAPǤ]|MҤxZIAA
oˬOOܦnOH
Linux OܦnǡAھڳLhоǪgAܦhPǦb Linux ɯuOD`hWALǧA
Heb Windows WJ쪺xo]۵MӵMbӸѡI] Linux Vmڭ̮ɡAOnڭ̥hѨM@ӵo{DA
oL{ݭnܦh¦ѪiAҥHǧLAA|ıoܦhƱܪ²ӳ¡CpGϥ
Windows iHסAܦhDNiAѬԣ|oͻPԣiHo˳BzFIڭ̷|bU@`R@U[]Ay{A
]|Ѭ۹Aӭn| Linux ޯI
1.1.2 []AOH
ެO Windows ٬O Linux An[]n@٧AAy\ҡz٬OoAo]AFG
- ¦AHKipP]wΰF
- x@~tΪ²ާ@G]AnRBbzBѽs边ϥεޥF
- Tw譱G]APns譱ѵF
- ӦAwһݳn骺wˡB]wBA~k@C
ӥBAC@Ӷظ̭һݭnDzߪޥih۩OIyHnǪF诊hڡIzOڡI
ҥHAnHTzHѶSƷFoAjaiOѤѦbX檾ѪAPɡA
ٱoѤIHɥi|oͪUغ|}PkOIuOHFu@
oܡA[]AuOIƹWA[]AZ²檺IxIS[]A²FH
O[]AܡHIy[]AzOѩBͭ̾DzߪצIt]աI
ٰOoiJzuǰ|ɭԡAѤѦb᪺FO¦zB¦ƾǡBu{ƾǻPyOǵ¦ءA
oǬتFڭ̤@ܨǴɶAӥBe٫o㳣O@j諸zIC
ǤFHڭ̶izuǰ|OFD`ѡAoǰ¦ѾǤFΧoH
I`ѳOغcboǰتzפWAҥH
U@A¦بSŪnAM~ظ̭쪺ziťH
o˻ӴNAѤFaISI{ѧ@~tλPӧ@~tΪާ@A٦ӭn¦A
NOڭ̦b[]Aey¦ءzաIҥHAbiJ
Linux A@ɤeAuL¦ѡAPɡA Linux
tΪޯ]ݭnzѧoI
nFAγ\A٬O Linux tθ̭yOܭnzAѡA
GupܡAڭ̴N|²檺Ҥlӻ@UoIUCX@몺[]Ay{A
ڭ̥Ѭ[]Ay{AӬݤ@ݤOn
Linux ޯaI ^_^C
bo@AAN linux ¦OiѪRA]b
y
Linux pе -- ¦Dz߽gz̭wgԲӪйLFI
pGЫOA²OOgTҥHUȤФ@
Linux ¦Dz߭nʪRI
MPAѪAȨäۦPAӥBCتAȪz]o@ˡALACئAѳWB[]w@A
Ӭy{OjPpCHA۫HڡHFA۫HAڭ̴NӤ@@RݬݧaI
1.2.1
A\suR
Uڭ̴NӦA²[]y{ӤR@UAHAAѧ@~tΪ¦@O۷nOHA쩳ڭ̬OpsuAH
suASoԣNNHڭ̥HUoiϥܨӧ@²檺nFG

1.2-1BsuܦAһݸgLU`
ӲzѤ@UA쩳ڭ̳suAQno줰H|ҨӻAAsu Youtube QnݼvAҥHNѼvyƵAF
As Yahoo QnݷsDAҥHNѷsDrɮAFAsuLWpQnݬkANǹɵAFAsu Facebook
QnhإСANѦҧAedUӪOAqƮw̭NAOXӶǵACݨSAAsuAAIbo𫍧ơA
Ӥ@ƪsbNOϥɮoIASvoH̲PɮרtΪ]wաI
WܪOGAΤݨAnqAΤݨFAA|ѦAP_ӳsu_A
椧~ϥΨAn骺\CӸӥ\SonqL SELinux oӲӳv]wثA~ŪɮרtΡC
णŪɮרtΩOHoSɮרtΪv (rwx) աIWzCӳn\A_hNLkQŪoC
ҥHAھڤWy{ڭ̤jiHNӳsuXӳA]AGBABn]wBUAȳ]wɡBӳv
SELinux Hγ̲׳̭nɮvCUNXӲӶӽͽoC
- GAѺ¦ѻPһݪAȤqTw
JMn[]AAMonAѤ@UںC]ެOا@~tΡAYQnPںsuAoӺ¦NoAѡC
|ҨӻAyzOg`|ͨ쪺AAo{@ӳ]w 192.168.1.0/255.255.255.0 ɡAoOFܡH
pGDܡAILk]wnաIt~AAݭnAHMOQnFYAȡC
|ҨӻAǿɮץiH FTPA WWW iHǻɮܡHڥiHǻܡHUγBHӤKH
ȤΦӻAڭ̩ҳ]wAȯ_L̪ݨDAoݭnAѡA_hAN@YڡI
]oANonAѡG
- ¦ѡG]AAӺwPwBTCP/IPBsuһݰѼƵF
- UAȩҹqTwzAHΦUqTwһݹnC
- AGAѬ[AتHtXDw˳W
Qn[]AܡH...[AHoӦAnn Internet }HoӪAȭnnwȤᴣѬbH
nnw藍PȤbiҦpϺЮeqBiʪŶPiΨtθ귽i歭HpGniU귽A
A@~tӭnpw˻P]wHDܦhaIҥHAAѧAnAAȥتAW~XlC
LApG[uOFym\zӤwAINݭnҼ{ӦhF
- AGAѧ@~tΪާ@
AȳnOݭnظmb@~tΤWAҥH@~tξާ@NonAѤ~ڡI]Anpw˻PH
ptζiҦ檺u@zHp̾ڦAAȤتWɮרtΡHpɮרtΨ㦳XR (LVM )H
tΦpzUAȤҰʡHtΪ}y{HtΥXɡAӦpiֳt_쵥AoݭnAѪOI
- ]wGztΪiɸ귽
@DiH֦hئAn骺B@Aӫܦh Linux distributions Xtw]ȴNwg}ܦhAȵ Internet
ϥΤFALoǪAȥiäOAQn}OCڭ̦bAѺ¦PһݪAȪتA
UӴNOzLӳWdiHϥΥAAȪΤAHtΦbϥΤW֦ΪޱpC
~AާAtγ]wAYAunOAn}AȡA
ӪAȴNSO@ĪGC]AӭnuWsnN@wnwiI_hAtαN|D`D`wI
- An]wGDz߳]wޥP}O_۰ʰ
Ĥ@INڭ̱onDCتAȩүF\Ap@Ӥ~[]pһݭnAȪC
pһݭnAȬOѭӳnFHP@ӪAȥi_PnHCسniHFتO_ۦPH
̾کһݭn\p]wAAnH[]L{pGX{~ApӦp[PH
i_wRAnTAHKAѸӦAϥαpP~oͪ]H
_qhӥΤisuաAHoΪA]wȡHҥHo̧AiNonDG
- npwˡBpd߬]wɩҦbmF
- Anp]wH
- AnpҰʡHp]w۰ʶ}ҰʡHp[ҰʪfH
- AnҰʥѦpHp[nɡHpzLnɶi气H
- zLΤݶisuաApGѸӦpBzHsuѪ]OA٬OH
- A]wקO_إߤxHnɬO_wRH
- AҴѩΤɪƦLwƥHpw۰ʳƥβaƥH
- ӳv]wG]A SELinux Pɮv
AA]wA̫AҴѪɮvoOFy 000 zvơA
ܪ֩wAjaLkŪAҴѪư...I~As distributions ijAnҰ SELinux AONNH
pGAƩmDWؿAӦpBz SELinux DHSpɮר㦳OKʩΦ@ɩ
(ɮvP
ACL )HAo]OݭnM[I
WzA[]y{A갣F 5 I~ALBJbUA]wݭnAѰڡIӥBO@˪F軡I
]Aoǰ¦pGǷ|FA̲סAAunD 5 I̭ӳn骺¦]wAAA@UlNiH]wաI
o˻AAO_}lıo¦Dz߫ܭnڡI ^_^
1.2.2
@ӱ`A]wרҤR
Wγ\A٬OܲM쩳oǧޯp_ӡHo̴Ѥ@²檺רҨӤR@UnFA
o˧AӴNeMDݭnDz߳oǩNNC
- ҡG]AҸ̭ (ެOa٬OJ) @qAoqݭn걵b@_ABiH~suF
- ~GAҥu@ӹ~su觋Ao̰]OxWy檺 ADSL 10M ֳoسzLqܽuF
- B~AȡGAQnoqiHWAӥB𫟺٦@iHϺоAѦPǩήaH@ƳƥPɤΡF
- AzGѩAiݭni卤ݺzA]AoAon}suAHݹqiHsuoDӶi@F
- zG]߳oɮפɦAtγQA]Aݭnw IP ӷinJvOF
- bzGt~AѩPǪƦKP@ɤA]AٱonѨCӦPǭӧObA
BCӱbϺЮeqϥέF
- ݤRG̫AѩߨtΥXDҥHAontΦ۰ʩwRϺШϥζqBnɰѼƸTC
bWzҤAAnҼ{F観ǩOH̾ڥp`@}lͨ쪺ӨBJӤRܡAAiݭnUoǩNNI
1.2.2-1 AѺ¦
ڭ̷QnNq걵b@AOoSu@ӥiH~suAɴNonʶRu (hub) Ϊ̬O洫 (switch)
Ӧ걵ҦqFCOo̦PH switch QHڭ̪DuQ٬ RJ-45 uA
uMŤAoӵŭnHPŪutצStHoǵw¦AѤA
A~wAҨӶisu]pCoڭ̵U@AӤСC
ѩu@~suӤwA]q`ڭ̴NijAiHΦpU觋Ӧ걵AG

1.2-2Bw骺suܷN
zL IP ɾAڭ̪qNWFCɧAon`NA_WP Internet A Internet
NOW TCP/IP qTwAӷQnAѺNonDԣO
OSI ChwCڭ̤]DsW Internet
Pҿת IP Aڭ̤oqҨo IP णளӬ[H]NOA IP SPH
pG IP ɾMFAAoqणsu]~HoNҼ{AѼƳ]wDFI
pGAPǩήaH]ӸAAqIAı|OHwDHnDH٬OԣW䧮DH
pGA¦ IP ѼơA]Aѳ]wHλW٨t (DNS) ܡA֩wDisuժC
ҥHoAɧAN|Q|GyٷQnzڭ̮az...ɤOɶܡHҥHnǦn@ǹI
oNܽFA]A TCP/IP, Network IP, Netmask IP, Broadcast IP, Gateway, DNS IP AݭnzѳI
AѤFoǭzAA~i气 (debug) u@A_hA~@XAAiN|Q|YI
̱`~A|ҨӻApGADNiHϥ ping oӫOhIJ𫍧D (ping
IP)AONOLkϥ ping hostname hIJ𫍧DAаݡAoӭ]OOHAѺ¦Bͤ@ݴNDXGO
DNS XDFAoBʹNOQ}Y]o쵪סCJMDXDaANwӰDhBzI
¦|vTA]wO_TAouܭnoA]ApGAqAYϦA[]\FA
OHiHݪܡHҥHAn[Auo¦U@ǥ\Ҥ~檺C¦oڭ̦b¦gèSLA
ҥHڭ̷|bU@¦ɦAԥ[I
1.2.2-2
Aw˳WP[تft
pP 1.2-2 ҥܡAServer ݬObqAӥB Server
nѰw藍PbϺоAڭ̳o|Ѻ (SAMBA) oӪAȡA]LiHb Linux/Windows qΤGC
BѩݭnѱbϥΪ̡AHηQ쥼ӪϺXRpA]ڭ̷QnN /home WߥXӡABϥ LVM oӺzҦA
÷ft Quota ӱCӱbϺШϥζqC
ҥHAAoD Linux ؿU
FHS (Filesystem Hierarchy Standard)
WdA_hμѵ~ؿA|yLk}InN /home WߩJ@ӤμѡH
O] quota Ȥ䴩 filesystem Ӥ䴩@ؿڡInFApGA@sDAAӦpw˧AtΩOH
@D-swG
G
ѩ Linux w˧ڭ̤wgb ¦gĥ|йLFAo̧ڭ̤AϥιϧΤӻA
ȨϥΤrӤЧAbCӶӳBzʧ@ӤwC~AṶ̪̄^o{ADzߪ̸g`u@DA
]Ao̧ڭ̫ijzϥ Virtualbox ( http://www.virtualbox.org/) ӼX@DAHw˱zҡCýЪ`NA
oDN|ϥΦbѪUӳ`դC
Virtualbox w˻P]wЦۦѦҨxW Documentation СAo̤AبCuOݭn`NOA
Y (1)ݭn[]PWAijϥξҦ (bridge) ABdϥ Intel WqYiC
(2)Ϻаtmijϥ SATA ABeqе 60GB HWC (3)Oܤָӵ 512MB HWA̦n 1GB ӴաC
LаѦҩxAΪ̨ϥιw]tmYiCMաApGAWߪӦwˡANnFI
ݲz|o@pqrC
w]tmpUG
- ΪШ̦pU觋iG
- /@@: 3GB
- /boot: 300MB
- /usr : 5GB
- /var : 5GB
- /tmp : 2GB
- swap : 1GB
- /home: 20GBAåBϥ LVM ҦظmAB LVM ]tѾlϺЮeqC
- nDɡAпܹw]w˥[Wy Server zPy Server-GUI zءF
- TwAܱҰʡASELinux ܱj (Enforce)F
- ] IP ɾ۰ʤt IP \AҥHѼƥ DHCP YiAӦAۤvקC
ڬy{jPpU (H CentOS 5.5 һ)
- iJ BIOS Aܥо}AåBN CentOS 5.5 DVD JоF
- bҰʦw˪eAX{ boot: ɡA Enter YiF
- X{y CD Found zrˡAɫijiHܡy Skip zYiLF
- bweHƹIy Next zF
- ytƥiHܡyChinese(Traditional)(c餤)F
- L榡Ody^zYiF
- Ĥ@ϥάΪϺСA|X{@ĵi䤣ΪAɿܡyOzYiLF
- bX{ήɡA̤ܳWƬyإߦۭqμҦzAMyU@BzF
- ysWziJεeANIBeqgNiHTwFCeIoˡG

1.2-3BΪѼƤUFܷN
- iWzʧ@ANҦƳBzAF /home ~C
- O /home BzëDpIpnsW@ӤμѡA
MNҦeqoӤμѡAÿ LVM AIUoˡG

1.2-4BΥX LVM μѪ觋"
UӦ^쥻εeAUy LVM zӫإߤ@ӦW server LVM VG Aëإ /home o LV oI
eIUoˡG

1.2-5Bإ̲߳ת LVM LV P /home"
^쥻εeA̲תܦIUoˡAMЫUyU@Bz~G

1.2-6BΪ̲G"
- X{}z{Aϥιw]ȧYiAЫyU@BzF
- ]w˸mAqq DHCP YiIOdw]ȤnʡAyU@Bz~F
- w]ɰϷ|X{Ȭw/x_AOdw]ȡAyU@Bz~F
- X{ root KXs@Ao̧ڭ̥]w centos aIA]iHۦ]wF
- bX{nܫAOd쥻÷sWyServerzPyServer-GUIzⶵF
- X{̩ۨˬdAyU@BzN}lw˨tΤFF
- gL@qɶݡAX{s}AANs}aI
|
BzwˤAAӴNOݭn]wU@nDFCoӭnD|bnJɶiA
AnJAӭn]wOHNӳBzBzU@DaG
@D-s]wG
Wzw˰ʧ@åBsw˫A̾ڥ]wݨDAݭnHαҰ SELinux A
]AnipUB~]wA~iHnJtγI
G
ƹWoD²OIy{jPpUG
- Ĥ@}|s@X\hn_ơA]Ĥ@}q`ɶ[Aеy@ݡF
- X{weAЫUyU@z~F
- ]wпܡyҥΡz~AU SSH ؽбNLĿF
- ѩקLơA]|X{@ӽT{AЫUyOzaI
- bX{ SELinux ]wUAпܹw]yjzAU@F
- X{ Kdump ɡAOdnܡALoӪAȫU@F
- X{]wApGSDNЫU@F
- إߨϥΪ̦W٪aAЫإߤ@ӱbGstudentAW studentAKX 123456 bAMU@F
- Yĥd|X{ĸTA]ЫU@~F
- X{LЪASݭnw˨LnAҥHЫyzYi
- ̲|X{ݵnJeANO]wFI
|
1.2.2-3 A@~tξާ@
JMڭ̳oDonѤPbӨϥΥL̦ۤvϺСA]ٻݭnإ߱bڡAϥκϺаtB (quota) C
A||إ߱bOHA||ظm@ɥؿOHAणBzCӱb Quota tBOHpG /home eqFA
A||j /home eqOHSkNtΪϺШϥαpwoelzOHodzO@欰I
ڭ̩UNHXӹڨҤlӽm߬ݬݧA¦OaI
D-jqظmbG
]ڪӪBͱbOO vbirduser{1,2,3,4,5}ABoӪBͥӷQn@ɤ@ӥؿA]ӭn[JP@ӸsաA]oӸsլ
vbirdgroupABoӱbKX password CӦpظmoӱbH
G
AiHg@}{ӶiWzu@I
[root@www ~]# vim useradd.sh
#!/bin/bash
groupadd vbirdgroup
for username in vbirduser1 vbirduser2 vbirduser3 vbirduser4 vbirduser5
do
useradd -G vbirdgroup $username
echo "password" | passwd --stdin $username
done
[root@www ~]# sh useradd.sh
[root@www ~]# id vbirduser1
uid=501(vbirduser1) gid=502(vbirduser1) groups=502(vbirduser1),501(vbirdgroup)
context=root:system_r:unconfined_t:SystemLow-SystemHigh
|
̫Q id oӫOӬd߬ݬݡAO_sժ䴩O諸ڡI
|
D-@ɥؿvG
oӪBͪ@ɥؿظm /home/vbirdgroup oӥؿAoӥؿu൹oӤHϥΡABCӤHiӥؿiʧ@I
YLHhLkϥ (Sv)AӦpظmoӥؿvOH
G
Ҽ{@ɥؿA]ؿݭn SGID v~I_hӧOsոƷ|oӤHLkק𫍧ƪC]ݭno˰G
[root@www ~]# mkdir /home/vbirdgroup
[root@www ~]# chgrp vbirdgroup /home/vbirdgroup
[root@www ~]# chmod 2770 /home/vbirdgroup
[root@www ~]# ll -d /home/vbirdgroup
drwxrws--- 2 root vbirdgroup 4096 7 13 11:11 /home/vbirdgroup
WSr骺NOAݭn`NoISO`Nv s \I
|
|
D-Quota @G
]oӥΤ᧡ݭniϺаtBACӥΤ᪺tB 2GB (hard) H 1.8GB (soft)AӦpBzH
G
o@D@A]n]AɮרtΪ䴩Bquota ɮظmBquota ҰʡBإߨϥΪ quota TL{C
ӹL{b¦gLFAo̫ܧֳtajai@aI
# 1. Ұ filesystem Quota 䴩
[root@www ~]# vim /etc/fstab
LABEL=/ / ext3 defaults 1 1
/dev/server/server /home ext3 defaults,usrquota,grpquota 1 2
LABEL=/tmp /tmp ext3 defaults 1 2
....(Uٲ)....
# ]OnBzϥΪ̪ϺСAҥH쪺O /home oӥؿӳBzڡI
[root@www ~]# umount /home; mount -a
[root@www ~]# mount | grep home
/dev/mapper/server-server on /home type ext3 (rw,usrquota,grpquota)
# ϥ mount hˬd@U /home Ҧb filesystem SWzrI
# 2. s@ Quota ɡAñҰ Quota 䴩
[root@www ~]# quotacheck -avug
quotacheck: Scanning /dev/mapper/server-server [/home] quotacheck:
....(Uٲ)....
# |X{@ǿ~ĵiTAO`IX{Wzr˴NFI
[root@www ~]# quotaon -avug
/dev/mapper/server-server [/home]: group quotas turned on
/dev/mapper/server-server [/home]: user quotas turned on
# 3. s@ Quota ƵΤ
[root@www ~]# edquota -u vbirduser1
Disk quotas for user vbirduser1 (uid 501):
Filesystem blocks soft hard inodes soft hard
/dev/mapper/server-server 56 1800000 2000000 7 0 0
# ] Quota O KB AҥHo̭nɤWnh 0 ڡIݪFI
[root@www ~]# edquota -p vbirduser1 vbirduser2
# @XAN vbirduser{3,4,5} qqɤWhI
[root@www ~]# repquota -au
*** Report for user quotas on device /dev/mapper/server-server
Block grace time: 7days; Inode grace time: 7days
Block limits File limits
User used soft hard grace used soft hard grace
----------------------------------------------------------------------
root -- 176212 0 0 5 0 0
student -- 56 0 0 7 0 0
vbirduser1 -- 56 1800000 2000000 7 0 0
vbirduser2 -- 56 1800000 2000000 7 0 0
vbirduser3 -- 56 1800000 2000000 7 0 0
vbirduser4 -- 56 1800000 2000000 7 0 0
vbirduser5 -- 56 1800000 2000000 7 0 0
# ݨSHWzGNOo{]w Quota oIӬy{NOoˡI
|
|
D-ɮרtΪj (LVM)G
º鳌]Aڭ̪ /home ΤFApQnN /home j 25GB iiڡH
G
]N߳oӰDAҥH /home wgO LVM 觋ӺzFCɧڭ̭n@@ VG ΡApGΪܡA
NiH~iCpGΩOHڭ̴Nonq PV ۤoIӬy{iHOo˨[C
# 1. ݬ VG qΡG
[root@www ~]# vgdisplay
--- Volume group ---
VG Name server
System ID
Format lvm2
....(ٲ)....
VG Size 44.06 GB
PE Size 32.00 MB
Total PE 1410
Alloc PE / Size 625 / 19.53 GB
Free PE / Size 785 / 24.53 GB
VG UUID RnQYZM-1bXC-hLTg-wT2J-ugHh-LvrH-b0FzmI
# ӴΤFI٦ 24GB iHϥΡIڭ̥unAW[ 5GB ӤwIӬOΪI
# 2. ˬd LV ζܡG
[root@www ~]# lvdisplay
--- Logical volume ---
LV Name /dev/server/server
VG Name server
LV UUID zSW5Cd-NfRV-e5lY-95fH-HAv5-02lO-01z8v8
LV Write Access read/write
LV Status available
# open 1
LV Size 19.53 GB
....(Uٲ)....
# ݰ_ӡAOݭnW[eqoIڭ̨ϥ lvresize XjeqaI
[root@www ~]# lvresize -L 25G /dev/server/server
Extending logical volume server to 25.00 GB
Logical volume server successfully resized
[root@www ~]# lvdisplay
--- Logical volume ---
LV Name /dev/server/server
VG Name server
LV UUID zSW5Cd-NfRV-e5lY-95fH-HAv5-02lO-01z8v8
LV Write Access read/write
LV Status available
# open 1
LV Size 25.00 GB
....(Uٲ)....
# ݨӽTOXj 25GB oI}lBzɮרtΧaI
# 3. Xjɮרt
[root@www ~]# resize2fs /dev/server/server
resize2fs 1.39 (29-May-2006)
Filesystem at /dev/server/server is mounted on /home; on-line resizing required
Performing an on-line resize of /dev/server/server to 6553600 (4k) blocks.
The filesystem on /dev/server/server is now 6553600 blocks long.
[root@www ~]# df -h
Filesystem Size Used Avail Use% Mounted on
/dev/sda5 2.9G 305M 2.4G 12% /
/dev/mapper/server-server
25G 173M 23G 1% /home
....(Lٲ)....
# iHݨɮרtνT꦳j 25G IoAѤFܡH
|
|
W@A{bAob¦gɭԡAڭ̤@jդ@ǦSFaH]ǪFbo̳ΪWI
pGoDاA|AƦܳsn@oǪF卖ܡAo^h\Ū¦gAnAUhFI
|D`D`WI
1.2.2-4
A귽zPW
AiDĤ@ӹ@Dw˦nFA Linux AtΨ쩳}Fh֪AȩOHoǪAȦS~@ɶ}ťH
oǪAȦS|}Ϊ̬OणiuWsHoǪAȦpGSnΨAणH~A
oǪAȯणȶ}ӷϥΦӤO Internet }HoOݭnAѪOC
Uڭ̴NHXӤpרҨAAѤ@UA쩳ǸƬOAnxOH
D-P runlevel AȱG
bثe runlevel UAow]ҰʪAȦǩOH~AڪtήڥS isdn PŪ˸mA
ڤQnҰʳoӪAȪܡAӦpBzH
G
w] runlevel iHϥ runlevel oӫOӳBzAڭ̹w]ϥ 5 runlevel A]AiHo˰G
[root@www ~]# LANG=C chkconfig --list | grep '5:on'
|
WOXTA| isdn P bluetooth ӪAȬObҰʪAApGQnLAiHo˰G
[root@www ~]# chkconfig isdn off
[root@www ~]# chkconfig bluetooth off
[root@www ~]# /etc/init.d/isdn stop
[root@www ~]# /etc/init.d/bluetooth stop
|
|
W쪺ȥuOҰʪAȡApGڷQnAѨҰʺť TCP/UDP ʥ]A (ʥ]榡U|ͨ)AӦpBzH
iHѦҩUoӽmDI
D-d߱ҰʦbťA
ڷQnˬdثeڳoDҰʦbfťAȦǡAåBn{AӦpiH
G
ťfRAiHϥΦpU觋RG
[root@www ~]# netstat -tulnp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:2208 0.0.0.0:* LISTEN 2032/hpiod
tcp 0 0 0.0.0.0:738 0.0.0.0:* LISTEN 1828/rpc.statd
tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 1796/portmap
tcp 0 0 127.0.0.1:631 0.0.0.0:* LISTEN 2059/cupsd
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 2091/sendmail: acce
tcp 0 0 127.0.0.1:2207 0.0.0.0:* LISTEN 2037/python
tcp 0 0 :::22 :::* LISTEN 2050/sshd
udp 0 0 0.0.0.0:57814 0.0.0.0:* 2196/avahi-daemon:
udp 0 0 0.0.0.0:732 0.0.0.0:* 1828/rpc.statd
udp 0 0 0.0.0.0:735 0.0.0.0:* 1828/rpc.statd
udp 0 0 0.0.0.0:5353 0.0.0.0:* 2196/avahi-daemon:
udp 0 0 0.0.0.0:111 0.0.0.0:* 1796/portmap
udp 0 0 0.0.0.0:631 0.0.0.0:* 2059/cupsd
udp 0 0 :::52792 :::* 2196/avahi-daemon:
udp 0 0 :::5353 :::* 2196/avahi-daemon:
|
{b]ڷQn avahi-daemon oӪAȥHӪAȱҰʪfɡAӭnpPWD@ˡA
Q /etc/init.d/xxx stop AAϥ chkconfig hBz}Ұʪ欰ILA]ҰʪAȦWٻPګOiण@ˡA
ڭ̦b netstat Wݨ쪺 program جOڳnɡAiP /etc/init.d/ UAɦWPA]iݭnϥ grep h^ơA
Ϊ̳zLnΪ [tab] hoAɦW~C
[root@www ~]# /etc/init.d/avahi-daemon stop
[root@www ~]# chkconfig avahi-daemon off
|
|
ڭ̱``|}ApG~}nSsA𤣹LOӧIҥHաAnsO۷nC
b CentOS Aڭ̤wg yum ӶiuWsFAAMiHۤvQΧ]wɨӫw yum nhdߪMg
(mirror site)ALo̳ijϥιw]]wȧYiA]tη|DʪP_Mg (M``|~P)A
ݭnHuLհաI
D-Q yum itΧs
]AwgqFAثeAQnBztΧsAPɻݭnCѭ 2:15 ۰ʶitΧsAӦp@H
G
tΧsϥ yum update YiCOѩ yum update ݭnϥΪ̤ʿJ y hT{unwˡA]b crontab YBzȮɡA
Nonϥ yum -y update FI
[root@www ~]# yum -y update
# Ĥ@@|iD`[I]tίuǸƭnsI٬OoݪI
[root@www ~]# vim /etc/crontab
15 2 * * * root /usr/bin/yum -y update
|
|
crontab ɮתBzAH crontab -e OΡAegk줣Ӥ@ˡAЦۦѦҰ¦gh[jDz߳I
bqLFWzU]wAڭ̪ Linux tӬOíwǤFAAۤUӡAڭ̭n}lӳ]w귽O@FI
Ҧp ssh oӻݥinJAȱoninJ IP ӷAHΨqWhy{C
ohOоǤnۭЪAdݫ᭱`AӽͧaI
{]pvҼg{ëDQQAҥHA`OiǦaS]pnA]Nyҿתy{|}zoC
{|}ҳyDjpApDiOyDAjDhiyDKƥ~yA
Ϊ̥DޱvQ cracker oCb{oF~NA{|}DOyDQBJI̥Dn]@FC
]AֳtBĪw{|}iɡAO@ӫܭn@DC
1.2.2-5
An]wGDz߳]wޥP}O_۰ʰ
oNOӦA[]gneFIe@p`]LAbA[]Aonx۷hTA
_hӺ@|㪺ܳ·СCڭ̥H쪺jeҡAڭ̷QnѤ@ӺϺоAϺоϥΪǩOH
`FΦɺϺФ~A٦`ڥH Linux NFS 觋 (᭱`|~ͨ)C
ѩ]ϰ@~tΤjO Windows nFA]ӬOӤXzϺФɿܡC
ڨ쩳ҰʤFh֭ӰfHOpѺڸƪHѪbSHѪvӦp]wH
O_iWw֥inJYǯSwؿHwڪAȪfӦp]wHpGtΥXӦpd߿~TH
oӺڦb Linux UnϥΤAȨӹFHoOݭnDzߪOI
iDAAڪs@b Linux UO Samba oMnӹFCSamba Բӳ]wڭ̷|b`СC
o̭niDAOA []@ӺڦAAAӭn|¦ѦǡHHΧiDAAAiHIUӪ[]y{A
zפWӭngLǨBJL{Ao˹AӳBzA]wɡA~|IUڡI
- nw˻Pd
ڭ̤wgDڻݭnw˪O Samba oMnAӦpdߦSw˩OHpGSwˤSӦpw˩OH
NӳBzBzC
DG
dXAtΩUS samba oMnAYLAЦۦdPw˸ӳn
G
ww˪niHϥ rpm hݬݡA|w˪hϥ yum \CҥHiHo˶iݬݡG
[root@www ~]# rpm -qa | grep -i samba
samba-3.0.33-3.29.el5_5
system-config-samba-1.2.41-5.el5
samba-common-3.0.33-3.29.el5_5
samba-client-3.0.33-3.29.el5_5
# ݰ_ӬOwgw˦\oIpGSݨWzSrɡANno˰G
[root@www ~]# yum search samba <==d@USn
[root@www ~]# yum install samba <==줧ANw˧aI
# pX]wɩOH]ڭ`Oݭnק]wɰڡIo˰aG
[root@www ~]# rpm -qc samba samba-common
/etc/logrotate.d/samba
/etc/pam.d/samba
/etc/rc.d/init.d/smb
/etc/samba/smbusers
/etc/sysconfig/samba
/etc/samba/lmhosts
/etc/samba/smb.conf
/etc/security/pam_winbind.conf
|
|
- AD]wP]w
oiN·ФFI]AonAѨAA쩳ݭnAȬOAwӪAȻݭn]wئǡH
odz]wݭnΨ줰Oγ]wɵC@ӻAAonݳoӪAȪqTwOԣAMAѸӦp]wA
UӽsD]wɡAھڥD]wɪƥh۹OӨoTҳ]wCHڭ̳o̪ڬҡA
ڭ̻ݭn]wu@sաAMݭn]wiHϥκڪDΦWAUӴN}lBzD]wɡC
]AݭnG
- ϥ vim hs /etc/samba/smb.conf ]wɡF
- Q useradd إߩһݭnڹΤF
- Q smbpasswd إߥiκڪbF
- Q testparm դ@UҦƻykO_TF
- ˬdݬݦbڤɪؿvO_TC
odz]wdwA~~iҰʻP[ʧ@IӷQnAѧh samba ]wޥPΡA
F google j~A /usr/share/doc AH man oӦnΪå볣nh\Ū@fI
- AҰʻP[
b]wAUӷMNOҰʸӦAFC@AҰʤjhOϥ stand alone ҦA
pGO֥ΪAȡAp telnet ANiϥΨ super daemon AȱҰCڭ̳ǫ¨ϥ samba ҡA
@@pҰʥLaI
DG
pҰ samba oӪAȩOHåB]wn}NҰʥLI
G
QnAѦpҰʡAonϥ rpm h@Un骺Ұʤ觋AMAhBzҰʪ欰oI
# dߤ@UҰʪ觋G
[root@www ~]# rpm -ql samba | grep '/etc'
/etc/logrotate.d/samba
/etc/pam.d/samba
/etc/rc.d/init.d/smb <==ҥHO stand alone BɦW smb I
/etc/samba/smbusers
/etc/sysconfig/samba
# }lҰʥLIB]w}NҰʳIG
[root@www ~]# /etc/init.d/smb start
[root@www ~]# chkconfig smb on
# UӡAڭ[@USҰʬfaI
[root@www ~]# netstat -tlunp | grep '[sn]mbd'
tcp 0 0 0.0.0.0:139 0.0.0.0:* LISTEN 7893/smbd
tcp 0 0 0.0.0.0:445 0.0.0.0:* LISTEN 7893/smbd
udp 0 0 192.168.201.111:137 0.0.0.0:* 7896/nmbd
udp 0 0 0.0.0.0:137 0.0.0.0:* 7896/nmbd
udp 0 0 192.168.201.111:138 0.0.0.0:* 7896/nmbd
udp 0 0 0.0.0.0:138 0.0.0.0:* 7896/nmbd
|
̲קڭ̥iHݨҰʪf 137, 138, 139, 445 I
|
- Τݪsu
UӴNOn@ΤݡAMըϥΥѪڥ\ڡIoˤ~Aѳ]wO٬OI
ΤݳsuPAѪAȦAҦp WWW ANnϥ browser
hաAڷMNonϥκڥΤݵ{oIo]OAgneաI
OܦhɨAΤݳsuդ\ëDOA]wDAܦhOΤݨϥΤ觋I
]AΤݦۤvS}աAΤݪbvKXOյADܤjաI
`ӻGyШ|A Client ϥΪ̨㦳̳̰¦ Linux
bBsաBɮvA~O@ӹѨMDkzAo]O...
- ~JAP[n
@ӻApG Linux WAȥX{DɡAq`|bùWiDA~]AҥHAon`NùTC
ѹ껡AùTq`NwgiDAӦpBzFCpG٤BzOHAiHo˳BmݬݡG
- ݬݬnɦS~TA|ҨӻA samba F|b /var/log/messages ̭CXT~A
jTӬO\b /var/log/samba/ oӥؿUơA]ANohd\@fCq`bnɤTA
|bùW٭nJӡAANiHۦBzFF
- NTaJ Google dߡAq`iHѨMnɥX{OASkJADIFviF 95% HWaI
- ٬O\ANUjQװϥhoݧaIijžǶ (http://phorum.study-area.org)
̱`X{O SELinux ~աIɴNonϥ SELinux kӹճBzoI
o]OAg|yL쪺eC
gLWy{AANiHDաA[]n@DݭnDG(1)U
process P signal [F(2)bPsժ[PʡF(3)ɮPؿvAoM]tPbSʡF
(4)MzDzߡF(5)BASH ykP shell scripts ykA٦ӫܭn vim
oIG(6)}y{RAHΰOnɪ]wPRF(7)ٱoD
quota HγsɵCnDuܦhAӥB٬OٲBJI
1.2.2-6 ӳvP SELinux
pGǯSϥαpɡAv]wNOӫܭn]C|ҨӻAڭ̨tΤWA{b vbirduser{1,2,3,4,5} H
student bAӦ@ɥؿ /home/vbirdgroupC{bA vbirdgroup sշQn student oӥΤiHiJӦ@ɥؿd\A
OḼ쥻ơAAӦpiOHAγ\iHo˷QG
- student [J vbirdgroup sէYiGp@ӡA student 㦳 vbirdgroup rwx vA]NiHgJPקoA
]oӤצ椣qC
- N /home/vbirdgroup vאּ 2775 YiGp@ student ֦LHv (rx)Ap@ӨLҦH֦
rx vAoӤפ]椣qC
DzΪPvNuWظѨMצӤwAoUlYFIڭ̨Skw student iv]wI
ɴNonϥ ACL oP˳oӨҤlAڭ̴Nӹ@@UG
D-@ΤBsժv]w ACL
Qn student iHiJ /home/vbirdgroup idߡAigJCP vbirduser5 b /home/vbirdgroup A
㦳vC
G
uϥ ACL oIѩwˮɹw]榡ƴN[W acl ɮרtΥ\䴩A]AiHBzpUUOC
pGAOϥΫӷsW partition filesystem Aγ\onb /etc/fstab B~W[ acl ѼƤ~I
[root@www ~]# setfacl -m u:student:rx /home/vbirdgroup
[root@www ~]# setfacl -m u:vbirduser5:- /home/vbirdgroup
[root@www ~]# getfacl /home/vbirdgroup
# file: home/vbirdgroup
# owner: root
# group: vbirdgroup
user::rwx
user:student:r-x <==NOoAB~vѼƭI
user:vbirduser5:---
group::rwx
mask::rwx
other::---
[root@www ~]# ll -d /home/vbirdgroup
drwxrws---+ 2 root vbirdgroup 4096 7 13 11:11 /home/vbirdgroup
|
|
WOTv欰CU@tκzOӪF...OաItκzäDvnʮɡA
``|]YǯSݨDANNӥؿ]w 777 pI|ҨӻApGO@ӤQntdޤHA
FۤvKBjaKANN /home/vbirdgroup ]w 777 AoˡyjawߡzIɡApGAS[WzA
KKIoӸsզu@GAqqiHQjaѨAuOnRFI
FwoؤߤbjzAONF SELinux oӪNCSELinux DnbӳvA
LiHwYǵ{ǭnŪɮרӳ]p SELinux OA{ǻPɮתOκAiH۲ŦXɡAɮפ~}lQŪC
p@ӡAA]wɮv 777 AO]{ǻPɮת SELinux Ҧ椣šAҥHSYA]ӵ{٬OŪɮסI
ҥHڭ̦b 1.2-1 ~|N SELinux ϥøs daemon P file permission ڡI
ƹW SELinux ٮAOڭ̦pGȬOQnΦӤwA SELinux Bz觋qqiHzLnɨӳBmI
ҥH SELinux X{D|D`jAOѨMޥo²INOzLnɤh@YiC
ԲӪ@kڭ̦b`AaI
1.2.3 tΦwPƥBz
ѹ껡AbzAgӻAwDn@~tλPnD٨ӪYAӤHDSwDYI
|ҨӻApGAAGyڭnbO eric AӥBڪKX]nO eric IoˤnOIz
AӭnBzOHyGMݭnAШ|zIШ|֡HШ|ۤvաIOnԭ@٬OnAOoˡnQPıaI
]AbtΦw譱Anu@OzL`ͬ次ʤACCzS@Ǹw譱xZA
ôѦ@ǨqwWh譱TAo˥ӤnjwqCڭ̴NY檺KXӫijaG
yqKXzO@ӤiJIqIҦp SSH pG Internet }ܡAASSN
root nJvANiH root յnJA Linux DAoӮɭԹ̭nBJNOqXA root
KXFIpGA root KX]wy1234567zIQQJI
ҥHMݭnY檺WdϥΪ̱KX]wFIpWdY檺KXWhOHiHǥ
(1)ק /etc/login.defs ɮ̭WhAHϥΪ̻ݭnCb~@KXABKXݭn
8 ӦrOI(2)Q /etc/security/limits.conf ӳWdCӨϥΪ̪vAA
Linux iHw@II(3)Q pam ҲըB~iKXҤu@C
t~AMyLνסz``QΡAO netfilter (Linux ֤ߤب) ꤴLsbnC
]A٬OoNnAۤvDҨӳ]pMݩۤvWhAҦpW쪺 SSH AȤA
AiHȰwYӰϰάYӯSw IP }su\YiڡI
̫AƥOi@C`}YNFAJL``W䧮۰ʭ}ΨtΤíAg`OQA
ӬOw馎qlsѤƩҳytΤíw...ɡAaƴաBƥξzANܭnoI
ӧA`Qn]wбIɭPơy``hzAҥHoAƥNuLXnoI
DG
tΤWnؿ /etc, /home, /root, /var/spool/mail AA{bQnbC 2:45am iƥABƥƦs /backup A
ƥ|ʨϥ tar AӦpBzH
G
q`Oϥ shell script ӶiƥƪJAdҦpUG
[root@www ~]# mkdir /root/bin; vim /root/bin/backup.sh
#!/bin/bash
backdir="/etc /home /root /var/spool/mail"
basedir=/backup
[ ! -d "$basedir" ] && mkdir $basedir
backfile=$basedir/backup.tar.gz
tar -zcvf $backfile $backdir
[root@www ~]# vim /etc/crontab
45 2 * * * root sh /root/bin/backup.sh
|
|
LצpAH{\κ@ӬݡA[]@ӡy\ʱjzDA
٤p[]@ӡyíwBwDzn@II]ADwnDNݭnY檺nDաIN[IӬݡA
pGADOΨӴAȿAҦpYǬs쪺j Cluster BDA
YϬ[]@ӬƦAıoܤKtΡAOXzqI]DQJINFAYƳQѨAI
iOx۪I
ѤWӬ[y{ӬݡAѳWwˡBD]wBbPɮvzBwʺ@PzHέnƥu@A
ݭnC`ܲMA~]wX@Ӹíwӥi`u@ACӤWC@Ӥu@AΨ۷h
Linux ¦ާ@PAҥHAQnǬ[AuuٲF Linux ¦DzߡA
o]Oڭ̤@Aj Linux s⤣n@YJQn¬[]AgoI
pGAWͨ쪺XӰ¦OܲMܡAijAѩUӺǰ_G
ޤHݭnOOHڷQA[Xӯ@@Ӻ¾ޤHA
ۮtOƻI[AuAO@²檺ƱAݵۮѥ@B@B@WhA@wiH\IOAܦhHuo
yp[zoyp@@ӺwzIWA
@@Ӥwg[]n`B@Aun[]@ӺhFIAonHɪDAtΪpA
Hɪ`NO_sM|}ӥhɥLAHɭn`NUتAȪnɮ(logfile)HAѨtΪB@pI
oDoͰDɭԡA쩳DIOb@ӡI
pFAAD]ܡH
YϤDA]ioݭnqoXӤ~CӡApGwXFDAQJIFAF
format + ~AikbtΪpUɺ|}H
odzOޤHݭnDzߪAӥBAq`Oݭng窥ֿn~|DDҦbI
~AOߪOHHɪ`NuWwƸTIݭnƪI
~AYDOAޤH̻ݭnO
yDwPPdPzIAinoAWҦHpbAʱUA
pGANwgsFAiDohiȶܡHt~ApGSdPH@@ӺޡA
i|ƱA]צɦaAunOAʱDXFDAKKKKAA@wOĤ@ӳQQ쪺HA
ҥHAAoHHaniHɷ|Ql^De߲zdzơI
iOApGAAȪHsA
Xӳs}ɭԳnоF@i}nСAɭPLk`}A
]|A軡yIAg⪺qoAʤʴN}zɭԡA
AoneHqANܸѸѴeaI`AޤHäOun|[NiHFA
yDwPzydPz٦y@ߡzIM@y{bHwfYIyoO@wnաIz
ޤHOH n[HeݨFȪ@gɡA
ejOGOWzHywʨ@z{Aγ\OإߤA
Ϊ̬O{bȤ|JIpAҥHbAѪpUAQҿתyFbȲ´zҤJIA
MHOWQJIqOAhԵnĬAMް_갪תCѩOW߳Iooo
( o䤣άFv]AϥثepOoˡC ) AҥH@ӪijHNܴƤC
ouO@ӨƥDALoӨƥD]IXF@ӭIANOڭ̪TiuOZoFA
LAzHib{{פWNIѮtFIwOZnAuOA
ja``|ѰOLIӤH{AެOZnAӤ~C
nFApGAAѤFWp̩ҷQnFNAӵݬݧAO_AX@Ӻ¾ޤHaI
- O_㦳 Linux ¦G
oM]tܦhAҦpbzBBASHBvBProcess
P signal B²wP Linux (p mount){ѡBnɮתѪRBdaemon
{ѵAݭn@w{תAѡF
- O_ư¦G
SѷQn[AOѤ]ӡIнT{Awgx
IP, Netmask, route, DNS, daemon P port, TCP ʥ]ѡF
- O_wg߬ƤFG
ޤHnHɪ`NTAo]AM|}ɡB
WiwqA٦AonCRDnɡA
AO_wgƤFHɪ`NoǸTy@ߡzOH
- O_㦳DwPPdPG
pG٬O㦳@IIsAA[oaI^_^
At~ApGQnЧAyszɡAзQɥkALzѳoOhi
MA@AjժA[]@ Linux AO²檺AO@u@FߤwgơA
åB٭n֦зǪDwPA_h.....˯ȬOiHw@ӫG.....