【正文】
urity and authentication mechanism. Γ В ?“is this user authorized to use me?” Γ В ? Γ В ?PAM is used, for example, to dynamically link system binaries. ?(Dynamic linking does necessitate a recovery mechanism to address potential problems in the linker or in shared libraries. One way of implementing a recovery mechanism is to supply a /rescue directory that contains statically linked versions of important system binaries. This method is used in both NetBSD and FreeBSD.) Γ В ? 第一部分是 libpam,是實(shí)現(xiàn) PAM API的庫, ? 第二部分是 PAM配置文件, /etc/, ? 第三部分有一套動(dòng)態(tài)可裝載兩進(jìn)位對(duì)象組成,常常用來調(diào)用一些處理實(shí)際鑒別 (authentication)工作的服務(wù)模塊。 pam_chauthtok()。 Γ В Γ В ? Examples of SUID programs: ? passwd: Allows users to update the /etc/shadow file ? mount: Allows users to mount a floppy or CD ? su: Runs a shell as another user, after supplying the password ? sudo: Runs a particular mand as another user ? Various games (to track highscores) ? All SUID programs should be known to the administrator and checked/updated for security problems Γ В ?查找 SUID屬性文件 find /usr/bin type f perm 2023 print ?SGID find /usr/bin type f perm 4000 print Γ В ?任何人 (同組 )都可寫的文件,可能是入侵的遺留 find . perm 2 print find . perm 20 ?無主文件 find /dev nouser print find /dev nogroup print Γ В ?CMOS口令 ?LILO/GRUB口令 ?磁盤 /分區(qū)加密 ?虛擬磁盤 ?文件權(quán)限訪問控制 ?特權(quán)操作 ?事件審計(jì) Γ В Γ В ?看源碼的工具,首推 LXR,其次也可以使用source insight或則 sourcenavigator。// show login prompt, optionally preceded by /etc/issue contents open_tty ()。 p = crypt(pp, salt)。 ? setuid(pwdpw_uid)。 410 int keep_capabilities:1。 ? 219 if (retval) ? 220 return retval。 run_shell (shell, mand, additional_args)。 2023年 1月 25日星期三 下午 9時(shí) 47分 56秒 21:47: ? 1比不了得就不比,得不到的就不要。 21:47:5621:47:5621:47Wednesday, January 25, 2023 ? 1不知香積寺,數(shù)里入云峰。 21:47:5621:47:5621:471/25/2023 9:47:56 PM ? 1越是沒有本領(lǐng)的就越加自命不凡。 下午 9時(shí) 47分 56秒 下午 9時(shí) 47分 21:47: MOMODA POWERPOINT Lorem ipsum dolor sit amet, consectetur adipiscing elit. Fusce id urna blandit, eleifend nulla ac, fringilla purus. Nulla iaculis tempor felis ut cursus. 感 謝 您 的 下 載 觀 看 專家告訴