Linux SSH°æ±¾¼ì²éÒªÁìÏê½â
¡¾ÎÊÌâ¡¿Linux SSH°æ±¾¼ì²éÒªÁìÏê½â
SSH£¨Secure Shell£©ÊÇÒ»ÖÖÓÃÓÚÔ¶³ÌµÇ¼ºÍÖ´ÐÐÏÂÁîµÄÍøÂçÐÒ飬³£ÓÃÓÚLinuxϵͳÉÏ¡£Ëæ×ÅÊÖÒÕµÄÒ»Ö±Éú³¤£¬SSHÐÒéÒ²Ò»Ö±¸üÐÂÉý¼¶£¬¶ø¼ì²éSSH°æ±¾ÊÇ°ü¹ÜϵͳÇå¾²µÄÖ÷ÒªÒ»»·¡£±¾ÎĽ«ÏêϸÏÈÈÝLinuxϼì²éSSH°æ±¾µÄÒªÁ죬²¢¸½ÉÏÏêϸµÄ´úÂëʾÀý¡£
Ò»¡¢Éó²éÒÑ×°ÖõÄSSH°æ±¾ºÅ
ʹÓÃÏÂÁîÉó²éSSHЧÀͶ˰汾ºÅ£º
ssh -V
µÇ¼ºó¸´ÖÆ µÇ¼ºó¸´ÖÆ
ÔËÐÐÒÔÉÏÏÂÁ¼´¿ÉÔÚÖÕ¶ËÊä³öÖп´µ½SSHЧÀͶ˵İ汾ºÅÐÅÏ¢£¬Èç¡°OpenSSH_7.9p1¡±¡£
ʹÓÃÏÂÁîÉó²éSSH¿Í»§¶Ë°æ±¾ºÅ£º
ssh -V
µÇ¼ºó¸´ÖÆ µÇ¼ºó¸´ÖÆ
ͬÑù£¬ÔÚÖÕ¶ËÔËÐÐÒÔÉÏÏÂÁî¿ÉÒÔÉó²éSSH¿Í»§¶ËµÄ°æ±¾ºÅ¡£
¶þ¡¢¼ì²éSSHÉèÖÃÎļþ
·¿ªSSHÉèÖÃÎļþ£º
sudo nano /etc/ssh/sshd_config
µÇ¼ºó¸´ÖÆ
ÔÚÉèÖÃÎļþÖУ¬¿ÉÒÔÕÒµ½¹ØÓÚSSH°æ±¾µÄÐÅÏ¢¡£³£¼ûÉèÖÃÏîÈçÏ£º
# SSHÐÒé°æ±¾ÉèÖà # Protocol 2, 1
µÇ¼ºó¸´ÖÆ
ĬÈÏÇéÐÎÏ£¬ProtocolÉèÖÃΪ¡°2¡±£¬ÌåÏÖ½öÖ§³ÖSSHÐÒé°æ±¾2¡£ÈôÐèÒªÉèÖÃÖ§³ÖSSH°æ±¾1ºÍ2£¬¿ÉÒÔ½«¡°Protocol 2, 1¡±×÷·Ï×¢ÊÍ£¬²¢ÖØÆôSSHЧÀÍÉúЧ¡£
Èý¡¢Ê¹ÓÃnmap¼ì²âSSH°æ±¾
×°ÖÃnmap¹¤¾ß£º
sudo apt install nmap
µÇ¼ºó¸´ÖÆ
ʹÓÃnmap¼ì²âSSH¶Ë¿ÚÐÅÏ¢£¬°üÀ¨SSH°æ±¾£º
nmap -sV -p 22 ЧÀÍÆ÷IPµØµã
µÇ¼ºó¸´ÖÆ
ÔËÐÐÒÔÉÏÏÂÁnmap»áɨÃèЧÀÍÆ÷µÄSSH¶Ë¿Ú£¬²¢ÁгöÏà¹Ø°æ±¾ÐÅÏ¢£¬°üÀ¨SSH°æ±¾ºÅ¡£
ËÄ¡¢SSHÎó²îɨÃ蹤¾ß
³ýÁËÊÖ¶¯¼ì²éSSH°æ±¾£¬»¹¿ÉʹÓÃһЩרÓù¤¾ß¾ÙÐÐɨÃè¼ì²â£¬ÒÔ·¢Ã÷¿ÉÄܱ£´æµÄÎó²î¡£
ʹÓÃSSHÈõ¿ÚÁîɨÃ蹤¾ßssh_scan£º
git clone https://github.com/mozilla/ssh_scan.git cd ssh_scan bundle install bundle exec ruby bin/ssh_scan --timeout 30 --user admin ЧÀÍÆ÷IPµØµã
µÇ¼ºó¸´ÖÆ
ÉÏÊö´úÂëʾÀýÊÇʹÓÃssh_scan¹¤¾ß¶ÔЧÀÍÆ÷µÄSSH¶Ë¿Ú¾ÙÐÐɨÃ裬¼ì²â¿ÉÄܱ£´æµÄÈõ¿ÚÁîΣº¦¡£
ʹÓÃSSHÎó²îɨÃ蹤¾ßssh-audit£º
git clone https://github.com/arthepsy/ssh-audit.git cd ssh-audit python3 ssh-audit.py ЧÀÍÆ÷IPµØµã
µÇ¼ºó¸´ÖÆ
ͨ¹ýssh-audit¹¤¾ß¿ÉÒÔ¶ÔSSHÉèÖþÙÐÐÖÜÈ«¼ì²â£¬°üÀ¨°æ±¾Îó²î¡¢¼ÓÃÜË㷨ǿ¶ÈµÈ·½Ãæ¡£
½áÓï
ͨ¹ýÒÔÉÏÒªÁìºÍ¹¤¾ß£¬¿ÉÒÔÀû±ãµØ¼ì²éSSH°æ±¾£¬ÊµÊ±·¢Ã÷DZÔÚµÄÇ徲Σº¦²¢½ÓÄÉÏìÓ¦²½·¥ÔöǿϵͳÇå¾²ÐÔ¡£ÔÚʹÓÃSSHÐÒéʱ£¬¼á³Öʵʱ¸üкÍÖÎÀí£¬ÊÇÈ·±£ÏµÍ³Çå¾²²»¿É»òȱµÄÒ»»·¡£Ï£Íû±¾ÎĶԶÁÕßÓÐËù×ÊÖú£¬Ò²Ï£Íû¸÷ÈËÔÚϵͳÖÎÀíÖжà¼Ó×¢ÖØÇå¾²ÎÊÌâ¡£
ÒÔÉϾÍÊÇLinux SSH°æ±¾¼ì²éÒªÁìÏê½âµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡