重要文件加锁

Linux重要文件加锁策略(生产环境标准)

分类文件/目录路径推荐锁类型加锁命令解锁命令作用说明风险等级
👤 用户认证/etc/passwd+ichattr +i /etc/passwdchattr -i /etc/passwd防新增/删除用户高危
/etc/shadow+ichattr +i /etc/shadowchattr -i /etc/shadow防密码篡改高危
/etc/group+ichattr +i /etc/groupchattr -i /etc/group防用户组篡改高危
/etc/gshadow+ichattr +i /etc/gshadowchattr -i /etc/gshadow防组密码篡改高危
/etc/sudoers+ichattr +i /etc/sudoerschattr -i /etc/sudoers防提权后门高危
/etc/sudoers.d/+i(递归)chattr +i -R /etc/sudoers.d/chattr -i -R /etc/sudoers.d/防sudo片段篡改高危
~/.ssh/authorized_keys+ichattr +i ~/.ssh/authorized_keyschattr -i ~/.ssh/authorized_keys防密钥后门高危
~/.ssh/id_rsa+ichattr +i ~/.ssh/id_rsachattr -i ~/.ssh/id_rsa防私钥泄露高危
~/.ssh/id_rsa.pub+ichattr +i ~/.ssh/id_rsa.pubchattr -i ~/.ssh/id_rsa.pub防公钥篡改高危
🔐 SSH服务/etc/ssh/sshd_config+ichattr +i /etc/ssh/sshd_configchattr -i /etc/ssh/sshd_config防SSH后门高危
/etc/ssh/ssh_config+ichattr +i /etc/ssh/ssh_configchattr -i /etc/ssh/ssh_config防客户端劫持中危
/etc/ssh/sshd_config.d/+i(递归)chattr +i -R /etc/ssh/sshd_config.d/chattr -i -R /etc/ssh/sshd_config.d/防配置片段篡改高危
🌐 网络基础/etc/hosts+ichattr +i /etc/hostschattr -i /etc/hosts防域名劫持高危
/etc/resolv.conf+ichattr +i /etc/resolv.confchattr -i /etc/resolv.conf防DNS劫持高危
/etc/hostname+ichattr +i /etc/hostnamechattr -i /etc/hostname防主机名篡改低危
📦 Web服务/etc/nginx/nginx.conf+ichattr +i /etc/nginx/nginx.confchattr -i /etc/nginx/nginx.conf防Web配置篡改高危
/etc/nginx/conf.d/+i(递归)chattr +i -R /etc/nginx/conf.d/chattr -i -R /etc/nginx/conf.d/防站点配置篡改高危
/etc/httpd/conf/httpd.conf+ichattr +i /etc/httpd/conf/httpd.confchattr -i /etc/httpd/conf/httpd.conf防Apache篡改高危
/etc/httpd/conf.d/+i(递归)chattr +i -R /etc/httpd/conf.d/chattr -i -R /etc/httpd/conf.d/防站点配置篡改高危
/var/www/html/+i(递归)chattr +i -R /var/www/html/chattr -i -R /var/www/html/防Web篡改/挂马高危
🗄️ 数据库/etc/my.cnf+ichattr +i /etc/my.cnfchattr -i /etc/my.cnf防MySQL配置篡改高危
/etc/mysql/my.cnf+ichattr +i /etc/mysql/my.cnfchattr -i /etc/mysql/my.cnf防MySQL配置篡改高危
/etc/mysql/mariadb.conf.d/+i(递归)chattr +i -R /etc/mysql/mariadb.conf.d/chattr -i -R /etc/mysql/mariadb.conf.d/防配置篡改高危
/etc/redis/redis.conf+ichattr +i /etc/redis/redis.confchattr -i /etc/redis/redis.conf防Redis配置篡改高危
/etc/mongod.conf+ichattr +i /etc/mongod.confchattr -i /etc/mongod.conf防MongoDB篡改高危
📝 日志审计/var/log/secure+achattr +a /var/log/securechattr -a /var/log/secure防日志删除中危
/var/log/messages+achattr +a /var/log/messageschattr -a /var/log/messages防日志删除中危
/var/log/audit/audit.log+achattr +a /var/log/audit/audit.logchattr -a /var/log/audit/audit.log防审计日志销毁高危
/var/log/wtmp+achattr +a /var/log/wtmpchattr -a /var/log/wtmp防登录记录销毁中危
/var/log/btmp+achattr +a /var/log/btmpchattr -a /var/log/btmp防失败登录销毁中危
⚙️ 系统服务/etc/systemd/system/+i(递归)chattr +i -R /etc/systemd/system/chattr -i -R /etc/systemd/system/防服务后门高危
/lib/systemd/system/+i(谨慎)chattr +i -R /lib/systemd/system/chattr -i -R /lib/systemd/system/防系统服务篡改高危
/etc/init.d/+i(谨慎)chattr +i -R /etc/init.d/chattr -i -R /etc/init.d/防SysV服务篡改高危
🛡️ 安全基线/etc/security/limits.conf+ichattr +i /etc/security/limits.confchattr -i /etc/security/limits.conf防资源限制篡改中危
/etc/sysctl.conf+ichattr +i /etc/sysctl.confchattr -i /etc/sysctl.conf防内核参数篡改高危
/etc/profile+ichattr +i /etc/profilechattr -i /etc/profile防全局环境篡改中危
/etc/bashrc+ichattr +i /etc/bashrcchattr -i /etc/bashrc防bash环境篡改中危
/etc/bash.bashrc+ichattr +i /etc/bash.bashrcchattr -i /etc/bash.bashrc防bash环境篡改中危
⏰ 定时任务/var/spool/cron/+i(递归)chattr +i -R /var/spool/cron/chattr -i -R /var/spool/cron/防定时任务后门高危
/etc/crontab+ichattr +i /etc/crontabchattr -i /etc/crontab防系统定时任务篡改高危
/etc/cron.d/+i(递归)chattr +i -R /etc/cron.d/chattr -i -R /etc/cron.d/防定时任务片段篡改高危
/etc/cron.daily/+i(递归)chattr +i -R /etc/cron.daily/chattr -i -R /etc/cron.daily/防每日任务后门高危
/etc/cron.weekly/+i(递归)chattr +i -R /etc/cron.weekly/chattr -i -R /etc/cron.weekly/防每周任务后门高危
/etc/cron.monthly/+i(递归)chattr +i -R /etc/cron.monthly/chattr -i -R /etc/cron.monthly/防每月任务后门高危
🐳 容器/etc/docker/daemon.json+ichattr +i /etc/docker/daemon.jsonchattr -i /etc/docker/daemon.json防Docker配置篡改高危
/etc/containerd/config.toml+ichattr +i /etc/containerd/config.tomlchattr -i /etc/containerd/config.toml防containerd篡改高危
⏲️ 时间同步/etc/chrony.conf+ichattr +i /etc/chrony.confchattr -i /etc/chrony.conf防NTP配置篡改中危
/etc/chrony/+i(递归)chattr +i -R /etc/chrony/chattr -i -R /etc/chrony/防NTP配置篡改中危
/etc/ntp.conf+ichattr +i /etc/ntp.confchattr -i /etc/ntp.conf防NTP配置篡改中危

❌ 严禁加锁清单(高危操作)

文件/目录原因后果替代方案
/etc/递归锁根目录系统无法启动,服务全挂锁具体配置文件
/tmp/大量程序写临时文件程序崩溃,容器无法运行锁/tmp下具体脚本
/var/日志、缓存、锁文件日志写不了,服务起不来锁/var/log下的具体日志
/var/log/日志轮转失败日志无法写入,磁盘报警+a锁具体日志文件
/run/PID文件、Socket服务无法创建PID文件不锁
/dev/设备文件设备无法访问不锁
/proc/虚拟文件系统系统状态无法读取不锁
/sys/内核参数接口内核参数无法调整不锁
/home/用户家目录用户无法写文件锁用户级配置文件
/root/Root家目录Root无法写配置锁/root/.ssh/

用户认证锁死、SSH配置锁死、Web目录锁死、Cron任务锁死、日志防删

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注