{"id":31,"date":"2026-02-17T17:29:51","date_gmt":"2026-02-17T09:29:51","guid":{"rendered":"https:\/\/word.ronrin.cn\/?p=31"},"modified":"2026-02-17T17:29:51","modified_gmt":"2026-02-17T09:29:51","slug":"%e6%9c%8d%e5%8a%a1%e5%99%a8%e5%ae%89%e5%85%a8%e9%a1%b9%e7%9b%ae","status":"publish","type":"post","link":"https:\/\/word.ronrin.cn\/index.php\/2026\/02\/17\/%e6%9c%8d%e5%8a%a1%e5%99%a8%e5%ae%89%e5%85%a8%e9%a1%b9%e7%9b%ae\/","title":{"rendered":"\u670d\u52a1\u5668\u5b89\u5168\u9879\u76ee"},"content":{"rendered":"\n<p>\u751f\u4ea7\u73af\u5883\uff08\u5bf9\u5916\u7f51\u7ad9\uff09<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u7b2c\u4e00\u9636\u6bb5\uff1a<\/h1>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2460 \u5173\u95ed MySQL \u516c\u7f51\u8bbf\u95ee\uff08\u6700\u9ad8\u4f18\u5148\u7ea7\uff09<\/h2>\n\n\n\n<p>\u68c0\u67e5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ss -lntp | grep 3306\n<\/code><\/pre>\n\n\n\n<p>\u5982\u679c\u663e\u793a\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>0.0.0.0:3306\n<\/code><\/pre>\n\n\n\n<p>\u8bf4\u660e\u5bf9\u516c\u7f51\u5f00\u653e \u274c<\/p>\n\n\n\n<p>\u4fee\u6539 MySQL \u914d\u7f6e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/etc\/my.cnf\n\u6216\n\/etc\/mysql\/mysql.conf.d\/mysqld.cnf\n<\/code><\/pre>\n\n\n\n<p>\u6539\u6210\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>bind-address = 127.0.0.1\n<\/code><\/pre>\n\n\n\n<p>\u7136\u540e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>systemctl restart mysqld\n<\/code><\/pre>\n\n\n\n<p>\u2714 \u6570\u636e\u5e93\u53ea\u5141\u8bb8\u672c\u673a\u8bbf\u95ee<br>\u2714 \u66b4\u529b\u7834\u89e3\u76f4\u63a5\u5931\u6548<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2461 \u4fee\u6539\u5b9d\u5854\u9ed8\u8ba4\u7aef\u53e3 8888<\/h2>\n\n\n\n<p>\u5b9d\u5854\u9ed8\u8ba4\u7aef\u53e3\u88ab\u5168\u7403\u626b\u63cf\u3002<\/p>\n\n\n\n<p>\u6539\u7aef\u53e3\uff1a<\/p>\n\n\n\n<p>\u5b9d\u5854 \u2192 \u8bbe\u7f6e \u2192 \u9762\u677f\u7aef\u53e3<\/p>\n\n\n\n<p>\u6539\u6210\u4f8b\u5982\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>24739\n<\/code><\/pre>\n\n\n\n<p>\u7136\u540e\uff1a<\/p>\n\n\n\n<p>\u2714 \u9632\u706b\u5899\u53ea\u5141\u8bb8\u4f60\u81ea\u5df1\u7684IP\u8bbf\u95ee<br>\u2714 \u6216\u4f7f\u7528 Cloudflare Tunnel<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2462 SSH \u5b89\u5168\u914d\u7f6e\uff08\u5fc5\u987b\uff09<\/h2>\n\n\n\n<p>\u7f16\u8f91\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>vi \/etc\/ssh\/sshd_config\n<\/code><\/pre>\n\n\n\n<p>\u4fee\u6539\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>PermitRootLogin no\nPasswordAuthentication no\nClientAliveInterval 600\nClientAliveCountMax 0\n<\/code><\/pre>\n\n\n\n<p>\u7136\u540e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>systemctl restart sshd\n<\/code><\/pre>\n\n\n\n<p>\u8bf4\u660e\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7981\u6b62root\u76f4\u767b<\/li>\n\n\n\n<li>\u7981\u6b62\u5bc6\u7801\u767b\u5f55\uff08\u53ea\u5141\u8bb8\u5bc6\u94a5\uff09<\/li>\n\n\n\n<li>10\u5206\u949f\u65e0\u64cd\u4f5c\u81ea\u52a8\u65ad\u5f00<\/li>\n<\/ul>\n\n\n\n<p>\u26a0 \u505a\u4e4b\u524d\u786e\u8ba4\u4f60\u5df2\u7ecf\u80fd\u7528\u5bc6\u94a5\u767b\u5f55\uff01<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2463 \u5220\u9664 rsh<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>yum remove rsh -y\n# \u6216\napt remove rsh-client -y\n<\/code><\/pre>\n\n\n\n<p>rsh = \u660e\u6587\u534f\u8bae<br>\u6ca1\u5fc5\u8981\u5b58\u5728\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2464 \u4fee\u590d sudo NOPASSWD<\/h2>\n\n\n\n<p>\u68c0\u67e5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cat \/etc\/sudoers.d\/90-cloud-init-users\n<\/code><\/pre>\n\n\n\n<p>\u5982\u679c\u6709\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>NOPASSWD\n<\/code><\/pre>\n\n\n\n<p>\u6539\u4e3a\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ALL=(ALL) ALL\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\ud83d\udfe0 \u7b2c\u4e8c\u9636\u6bb5\uff1a\u6807\u51c6\u751f\u4ea7\u52a0\u56fa<\/h1>\n\n\n\n<p>\u8fd9\u4e9b\u662f Linux \u5b89\u5168\u57fa\u7ebf\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2460 \u542f\u7528 SYN Cookie\uff08\u9632 SYN Flood\uff09<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>echo \"net.ipv4.tcp_syncookies=1\" &gt;&gt; \/etc\/sysctl.conf\nsysctl -p\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2461 \u7981\u6b62 ICMP \u91cd\u5b9a\u5411<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>echo \"net.ipv4.conf.all.accept_redirects=0\" &gt;&gt; \/etc\/sysctl.conf\necho \"net.ipv4.conf.default.accept_redirects=0\" &gt;&gt; \/etc\/sysctl.conf\nsysctl -p\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2462 \u7981\u6b62 Source Route<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>echo \"net.ipv4.conf.all.accept_source_route=0\" &gt;&gt; \/etc\/sysctl.conf\necho \"net.ipv4.conf.default.accept_source_route=0\" &gt;&gt; \/etc\/sysctl.conf\nsysctl -p\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2463 \/tmp \u52a0 nosuid<\/h2>\n\n\n\n<p>\u7f16\u8f91\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/etc\/fstab\n<\/code><\/pre>\n\n\n\n<p>\u6539\u4e3a\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>tmpfs \/tmp tmpfs defaults,noexec,nosuid,nodev 0 0\n<\/code><\/pre>\n\n\n\n<p>\u7136\u540e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>mount -o remount \/tmp\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u2464 \u5f00\u542f fail2ban\uff08\u5f3a\u70c8\u5efa\u8bae\uff09<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>yum install fail2ban -y\nsystemctl enable fail2ban\nsystemctl start fail2ban\n<\/code><\/pre>\n\n\n\n<p>\u9632\u7206\u7834\u795e\u5668\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\ud83d\udfe2 \u7b2c\u4e09\u9636\u6bb5\uff1a\u4f01\u4e1a\u7ea7\u8fdb\u9636\uff08\u5efa\u8bae\u4f46\u4e0d\u6025\uff09<\/h1>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">auditd<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>yum install audit -y\nsystemctl enable auditd\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">AIDE \u6587\u4ef6\u5b8c\u6574\u6027\u68c0\u6d4b<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>yum install aide -y\naide --init\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6539 GRUB \u6743\u9650<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>chmod 600 \/boot\/grub\/grub.cfg\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\ud83c\udfaf \u5b9d\u5854\u751f\u4ea7\u73af\u5883\u6700\u4f73\u67b6\u6784\uff08\u5efa\u8bae\u4f60\u8003\u8651\uff09<\/h1>\n\n\n\n<p>\u4f60\u73b0\u5728\u505a\u7f51\u7ad9\uff0c\u6211\u5efa\u8bae\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u516c\u7f51\n \u2193\nCloudflare\n \u2193\nNginx\n \u2193\nPHP\n \u2193\nMySQL (127.0.0.1)\n<\/code><\/pre>\n\n\n\n<p>\u52a0\u4e0a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>WAF\uff08Cloudflare\uff09<\/li>\n\n\n\n<li>\u53ea\u5f00\u653e 80\/443<\/li>\n\n\n\n<li>\u5173\u95ed 3306<\/li>\n\n\n\n<li>SSH \u53ea\u5141\u8bb8\u4f60IP<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\ud83d\udcca \u771f\u5b9e\u98ce\u9669\u6392\u5e8f\uff08\u6309\u88ab\u9ed1\u6982\u7387\uff09<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u98ce\u9669\u9879<\/th><th>\u5b9e\u9645\u5371\u9669<\/th><\/tr><\/thead><tbody><tr><td>3306\u516c\u7f51\u5f00\u653e<\/td><td>\ud83d\udd34\ud83d\udd34\ud83d\udd34<\/td><\/tr><tr><td>SSH\u5bc6\u7801\u767b\u5f55<\/td><td>\ud83d\udd34\ud83d\udd34<\/td><\/tr><tr><td>\u9762\u677f\u9ed8\u8ba4\u7aef\u53e3<\/td><td>\ud83d\udd34\ud83d\udd34<\/td><\/tr><tr><td>\u672a\u542f\u7528fail2ban<\/td><td>\ud83d\udd34<\/td><\/tr><tr><td>sysctl\u672a\u52a0\u56fa<\/td><td>\ud83d\udfe1<\/td><\/tr><tr><td>audit\u7f3a\u5931<\/td><td>\ud83d\udfe2<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\u26a0 \u6700\u91cd\u8981\u4e00\u53e5\u8bdd<\/h1>\n\n\n\n<p>\u751f\u4ea7\u73af\u5883\u670d\u52a1\u5668\uff1a<\/p>\n\n\n\n<p>\u2714 \u4e0d\u8981\u8ffd\u6c42\u201c\u626b\u63cf\u5168\u7eff\u201d<br>\u2714 \u91cd\u70b9\u662f\u51cf\u5c11\u53ef\u653b\u51fb\u9762<br>\u2714 \u7aef\u53e3\u8d8a\u5c11\u8d8a\u5b89\u5168<br>\u2714 \u670d\u52a1\u8d8a\u5c11\u8d8a\u5b89\u5168<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u751f\u4ea7\u73af\u5883\uff08\u5bf9\u5916\u7f51\u7ad9\uff09 \u7b2c\u4e00\u9636\u6bb5\uff1a \u2460 \u5173 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[3],"tags":[],"class_list":["post-31","post","type-post","status-publish","format-standard","hentry","category-linux-"],"_links":{"self":[{"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/posts\/31","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/comments?post=31"}],"version-history":[{"count":1,"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/posts\/31\/revisions"}],"predecessor-version":[{"id":32,"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/posts\/31\/revisions\/32"}],"wp:attachment":[{"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/media?parent=31"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/categories?post=31"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/word.ronrin.cn\/index.php\/wp-json\/wp\/v2\/tags?post=31"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}