| 一部連上Internet上面的您的個人主機,最重要的是什麼呢?大概就是如何讓您自己可以連線進入自己的主機,並且進行所謂的『遠端操控』了吧!也就是說,您可以在任何具有連上Internet的電腦中,以遠端連線軟體連上Internet,並藉由您主機上面的遠端連線伺服器軟體提供的功能,直接登入您的主機來進行操控的工作!此時,您將發現Linux有趣又好玩的地方囉!在早期的Unix Like機器當中,幾乎都提供Telnet這個遠端連線伺服器軟體,不過,Telnet本身是以『明碼』來傳送您操作的資料,安全上面是值得來思考要不要開放吶!這個時候就有需要瞭解一下傳送過程中以加密動作來傳送資料封包的SSH這個遠端連線伺服器軟體啦!另外,除了純文字介面登入主機來進行操控之外,在現在的Linux distributions當中,還可以利用X相關的服務來幫助我們以圖形介面登入喔!很棒吧!^_^ |
[root@linux ~]# rpm -qa | grep telnet telnet-0.17-31.EL4.3 telnet-server-0.17-31.EL4.3 # 上面是 CentOS 4.x 預設的套件版本。如果是其他的 distribution, # 檔名可能會不太一樣∼可利用 yum 或 apt 等方式來安裝喔! |
[root@linux ~]# vi /etc/xinetd.d/telnet
service telnet
{
flags = REUSE
socket_type = stream
wait = no
user = root
server = /usr/sbin/in.telnetd
log_on_failure += USERID
# disable = yes
disable = no
# 基本上,改上面這兩行就夠了!將 disable 設定成 no 表示要啟動!
}
|
僅適合 Red Hat 系列 / Mandriva 系列的主機啟動方式 [root@linux ~]# service xinetd restart Stopping xinetd: [ OK ] Starting xinetd: [ OK ] 適合各版本的主機啟動方式 [root@linux ~]# /etc/init.d/xinetd restart Stopping xinetd: [ OK ] Starting xinetd: [ OK ] # 某些版本並沒有 restart 的選項,這個時候就需要:stop 再 start 囉! |
[root@linux ~]# netstat -tlup Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 *:telnet *:* LISTEN 23817/xinetd |
Step 1: 修改設定檔
[root@linux ~]# vi /etc/xinetd.d/telnet
service telnet
{
flags = REUSE
socket_type = stream
wait = no
user = root
server = /usr/sbin/in.telnetd
log_on_failure += USERID
disable = yes <== 就是這裡啦!將他改成 yes 就是關閉!
}
Step 2: 重新啟動 xinetd 這個 super daemon
[root@linux ~]# /etc/init.d/xinetd restart
|
[root@linux ~]# telnet localhost Trying 127.0.0.1... Connected to localhost.localdomain (127.0.0.1). Escape character is '^]'. CentOS release 4.4 (Final) Kernel 2.6.9-42.0.2.EL on an i686 login: dmtsai <== 就是這裡啦!請輸入『一般』帳號,不能用 root 喔! Password: <== 這裡輸入該帳號的密碼!請注意,輸入時,螢幕不會有任何資訊! Last login: Fri Jul 1 09:31:21 from 127.0.0.1 <== 上次登入的資訊為何? [dmtsai@linux ~]$ <== 這裡就是已經登入的地方!亦即遠端主機了! [dmtsai@linux ~]$ exit <== 這樣就能夠離開 telnet 與遠端主機咯! |
[root@linux ~]# vi /etc/xinetd.d/telnet
# This file had been modified by VBird 2002/11/04
# First is about inside the network
service telnet
{
disable = no
bind = 192.168.1.2
only_from = 192.168.1.0/24
# 上面這兩行說明僅提供內部網域!
instance = UNLIMITED
nice = 0
flags = REUSE
socket_type = stream
wait = no
user = root
server = /usr/sbin/telnetd
server_args = -a none
log_on_failure += USERID
}
# Second is about the outside domain's settings
service telnet
{
disable = no
bind = 140.116.142.196
only_from = 140.116.0.0/16
no_access = 140.116.32.{10,26}
# 上面這三行設定外部較為嚴格的限制
instance = 10 <==最多允許同時 10 個連線
umask = 022
nice = 10
flags = REUSE
socket_type = stream
wait = no
user = root
server = /usr/sbin/telnetd
server_args = -a none
log_on_failure += USERID
}
|
[root@linux ~]# mv /etc/securetty /etc/securetty.bak |
[root@linux ~]# vi /etc/pam.d/login #%PAM-1.0 #auth required pam_securetty.so <== 就是這樣一行,將他註解即可! auth required pam_stack.so service=system-auth auth required pam_nologin.so account required pam_stack.so service=system-auth password required pam_stack.so service=system-auth # pam_selinux.so close should be the first session rule session required pam_selinux.so close session required pam_stack.so service=system-auth session required pam_loginuid.so session optional pam_console.so # pam_selinux.so open should be the last session rule session required pam_selinux.so multiple open |
iptables -A INPUT -p tcp -i $INIF -s 192.168.0.0/24 --dport 23 -j ACCEPT iptables -A INPUT -p tcp -i $EXTIF -s 61.xxx.xxx.xxx --dport 23 -j ACCEPT iptables -A INPUT -p tcp -i $EXTIF --dport 23 -j DROP |
[root@linux ~]# vi /etc/hosts.allow in.telnetd: 192.168.0.1, 192.168.0.2, 192.168.0.3, 192.168.0.4 in.telnetd: 192.168.0.5 [root@linux ~]# vi /etc/hosts.deny in.telnetd : ALL : spawn (/bin/echo Security notice from `/bin/hostname`; \ /bin/echo; /usr/sbin/safe_finger @%h ) | \ /bin/mail -s "%d -%h security" root@localhost & \ : twist ( /bin/echo -e " WARNING connectin not allowed. " ) |

[root@linux ~]# /etc/init.d/sshd restart [root@linux ~]# netstat -tlp Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 *:ssh *:* LISTEN 24266/sshd |
1. 直接登入到對方主機的方法: [root@linux ~]# ssh account@hostname # 連接到我們自己本機上面的 ssh 服務!更多訊息,請 man ssh 喔! [root@linux ~]# ssh dmtsai@localhost The authenticity of host 'localhost (127.0.0.1)' can't be established. RSA key fingerprint is f8:ae:67:0e:f0:e0:3e:bb:d9:88:1e:c9:2e:62:22:72. Are you sure you want to continue connecting (yes/no)? yes # 上面很重要喔!務必填入完整的 "yes" 而不是 Y 或 y 而已。 Warning: Permanently added 'localhost' (RSA) to the list of known hosts. dmtsai@localhost's password: <== 在這裡填入密碼,同樣的,螢幕不會有訊息的! Last login: Fri Jul 1 14:23:27 2005 from localhost.localdomain [dmtsai@linux ~]$ <== 瞧!已經登入囉∼ [dmtsai@linux ~]$ exit <== 輸入 exit 就能夠離開對方主機囉! 2. 不登入對方主機,直接在對方主機執行指令的方法: [root@linux ~]# ssh dmtsai@localhost date dmtsai@localhost's password: Tue Nov 22 11:57:27 CST 2005 [root@linux ~]# # 看!身份還是 root 喔!只是以 dmtsai 的身份在遠端主機上執行了一個指令而已! |
[root@linux ~]# ssh dmtsai@localhost @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! Someone could be eavesdropping on you right now (man-in-the-middle attack)! It is also possible that the RSA host key has just been changed. The fingerprint for the RSA key sent by the remote host is f8:ae:67:0e:f0:a0:3e:aa:d9:77:19:c9:2e:62:22:72. Please contact your system administrator. Add correct host key in /root/.ssh/known_hosts to get rid of this message. Offending key in /root/.ssh/known_hosts:1 RSA host key for localhost has changed and you have requested strict checking. Host key verification failed. |
[root@linux ~]# vi ~/.ssh/known_hosts localhost ssh-rsa AAAAB3NzaC1yc2Euowireffodjoiwjefmoeiwhoqhwupoi t[egmlomowimvoiweo6VpTHTw2/tENp4U7Wn8J6nxYWP36YziFgxtWu4MPSKaRmr E4eUpR1G/zV3TkChRZY5hGUybAreupTVdxCZvJlYvNiejfijoejwiojfijeoiwx5 eRkzvSj7a19vELZ5f8XhzH62E= |
[root@linux ~]# sftp dmtsai@localhost Connecting to localhost... dmtsai@localhost's password: <== 這裡請輸入密碼啊! sftp> <== 這裡就是在等待您輸入 ftp 相關指令的地方了! |
| 針對遠方主機(Server)之行為 | |
| 變換目錄到/etc/test或其他目錄 | cd /etc/test cd PATH |
| 列出目前所在目錄下的檔名 | ls dir |
| 建立目錄 | mkdir directory |
| 刪除目錄 | rmdir directory |
| 顯示目前所在的目錄 | pwd |
| 更改檔案或目錄群組 | chgrp groupname PATH |
| 更改檔案或目錄擁有者 | chown username PATH |
| 更改檔案或目錄的權限 | chmod 644 PATH 其中,644與權限有關!回去看基礎篇! |
| 建立連結檔 | ln oldname newname |
| 刪除檔案或目錄 | rm PATH |
| 更改檔案或目錄名稱 | rename oldname newname |
| 離開遠端主機 | exit(or)bye(or)quit |
| 針對本機(Client)之行為(都加上l,L的小寫) | |
| 變換目錄到本機的PATH當中 | lcd PATH |
| 列出目前本機所在目錄下的檔名 | lls |
| 在本機建立目錄 | lmkdir |
| 顯示目前所在的本機目錄 | lpwd |
| 針對資料上傳/下載的行為 | |
| 將檔案由本機上傳到遠端主機 | put[本機目錄或檔案][遠端] put[本機目錄或檔案] 如果是這種格式,則檔案會放置到目前遠端主機的目錄下! |
| 將檔案由遠端主機下載回來 | get[遠端主機目錄或檔案][本機] get[遠端主機目錄或檔案] 若是這種格式,則檔案會放置在目前本機所在的目錄當中!可以使用萬用字元,例如: get* get*.rpm 亦是可以的格式! |
1. 將資料由本機上傳到遠端主機上去
[root@linux ~]# scp /etc/crontab dmtsai@localhost:/home/dmtsai/
dmtsai@localhost's password: <== 這裡請輸入密碼啊!
crontab 100% 620 0.6KB/s 00:00
# 這個例子在說明,我將本機目錄的 /etc/crontab 這個檔案傳送給 dmtsai
# 這個使用者,而這個使用者是在 "localhost" 那部主機上面喔!
# 仔細看一下,會有一個傳輸資料的訊息跑出來喔!
2. 將資料由遠端主機下載到本機上!
[root@linux ~]# scp dmtsai@localhost:~/.bashrc .
# 這個例子則是在說明,我要將 localhost 那部機器上的 dmtsai 這個人,
# 他家目錄下的 .bashrc 複製到我的機器上!
|







psftp: no hostname specified; use "open host.name" to connect psftp> |
psftp: no hostname specified; use "open host.name" to connect psftp> open test.linux.org login as: dmtsai Using username "dmtsai". dmtsai@linux.dmtsai.tw's password: Remote working directory is /home/dmtsai psftp> <== 這裡就在等待您輸入 FTP 的指令了! |
[root@linux ~]# vi /etc/ssh/sshd_config # 1. 關於 SSH Server 的整體設定,包含使用的 port 啦,以及使用的密碼演算方式 # 先留意一下,在預設的檔案內,只要是被註解的設定值(#),即為『預設值!』 Port 22 # SSH 預設使用 22 這個port,也可以使用多個port,即重複使用 port 這個設定項目! # 例如想要開放 sshd 在 22 與 443 ,則多加一行內容為: # Port 443 # 這樣就好了!不過,不建議修改 port number 啦! Protocol 1,2 # 選擇的 SSH 協定版本,可以是 1 也可以是 2 , # 如果要同時支援兩者,就必須要使用 2,1 這個分隔了(Protocol 1,2)! # 目前我們會建議您,直接使用 Protocol 2 即可! #ListenAddress 0.0.0.0 # 監聽的主機介面卡!舉個例子來說,如果您有兩個 IP, # 分別是 192.168.0.100 及 192.168.2.20 ,那麼只想要 # 開放 192.168.0.100 時,就可以寫如同下面的樣式: ListenAddress 192.168.0.100 # 只監聽來自 192.168.0.100 這個 IP 的SSH連線。 # 如果不使用設定的話,則預設所有介面均接受 SSH #PidFile /var/run/sshd.pid # 可以放置 SSHD 這個 PID 的檔案!左列為預設值 #LoginGraceTime 2m # 當使用者連上 SSH server 之後,會出現輸入密碼的畫面,在該畫面中, # 在多久時間內沒有成功連上 SSH server ,就斷線!若無單位則預設時間為秒! #Compression yes # 是否可以使用壓縮指令?當然可以囉 # 2. 說明主機的 Private Key 放置的檔案,預設使用下面的檔案即可! #HostKey /etc/ssh/ssh_host_key # SSH version 1 使用的私鑰 #HostKey /etc/ssh/ssh_host_rsa_key # SSH version 2 使用的 RSA 私鑰 #HostKey /etc/ssh/ssh_host_dsa_key # SSH version 2 使用的 DSA 私鑰 # 還記得我們在主機的 SSH 連線流程裡面談到的,這裡就是 Host Key ∼ # 2.1 關於 version 1 的一些設定! #KeyRegenerationInterval 1h # 由前面連線的說明可以知道, version 1 會使用 server 的 Public Key , # 那麼如果這個 Public Key 被偷的話,豈不完蛋?所以需要每隔一段時間 # 來重新建立一次!這裡的時間為秒!不過我們通常都僅使用 version 2 , # 所以這個設定可以被忽略喔! #ServerKeyBits 768 # 沒錯!這個就是 Server key 的長度!用預設值即可。 # 3. 關於登錄檔的訊息資料放置與 daemon 的名稱! SyslogFacility AUTHPRIV # 當有人使用 SSH 登入系統的時候,SSH會記錄資訊,這個資訊要記錄在什麼 daemon name # 底下?預設是以 AUTH 來設定的,即是 /var/log/secure 裡面!什麼?忘記了! # 回到 Linux 基礎 去翻一下。其他可用的 daemon name 為:DAEMON,USER,AUTH, # LOCAL0,LOCAL1,LOCAL2,LOCAL3,LOCAL4,LOCAL5, #LogLevel INFO # 登錄記錄的等級!嘿嘿!任何訊息!同樣的,忘記了就回去參考! # 4. 安全設定項目!極重要! # 4.1 登入設定部分 PermitRootLogin no # 是否允許 root 登入!預設是允許的,但是建議設定成 no! #UserLogin no # 在 SSH 底下本來就不接受 login 這個程式的登入! #StrictModes yes # 當使用者的 host key 改變之後,Server 就不接受連線,可以抵擋部分的木馬程式! #RSAAuthentication yes # 是否使用純的 RSA 認證!?僅針對 version 1 ! #PubkeyAuthentication yes # 是否允許 Public Key ?當然允許啦!僅針對 version 2 #AuthorizedKeysFile .ssh/authorized_keys # 上面這個在設定若要使用不需要密碼登入的帳號時,那麼那個帳號的存放檔案所在檔名! # 這個設定值很重要喔!檔名給他記一下! # 4.2 認證部分 #RhostsAuthentication no # 本機系統不使用 .rhosts,因為僅使用 .rhosts太不安全了,所以這裡一定要設定為 no #IgnoreRhosts yes # 是否取消使用 ~/.ssh/.rhosts 來做為認證!當然是! #RhostsRSAAuthentication no # # 這個選項是專門給 version 1 用的,使用 rhosts 檔案在 /etc/hosts.equiv # 配合 RSA 演算方式來進行認證!不要使用啊! #HostbasedAuthentication no # 這個項目與上面的項目類似,不過是給 version 2 使用的! #IgnoreUserKnownHosts no # 是否忽略家目錄內的 ~/.ssh/known_hosts 這個檔案所記錄的主機內容? # 當然不要忽略,所以這裡就是 no 啦! PasswordAuthentication yes # 密碼驗證當然是需要的!所以這裡寫 yes 囉! #PermitEmptyPasswords no # 若上面那一項如果設定為 yes 的話,這一項就最好設定為 no , # 這個項目在是否允許以空的密碼登入!當然不許! ChallengeResponseAuthentication no # 允許任何的密碼認證!所以,任何 login.conf 規定的認證方式,均可適用! # 但目前我們比較喜歡使用 PAM 模組幫忙管理認證,因此這個選項可以設定為 no 喔! UsePAM yes # 利用 PAM 管理使用者認證有很多好處,可以記錄與管理。 # 所以這裡我們建議您使用 UsePAM 且 ChallengeResponseAuthentication 設定為 no # 4.3 與 Kerberos 有關的參數設定!因為我們沒有 Kerberos 主機,所以底下不用設定! #KerberosAuthentication no #KerberosOrLocalPasswd yes #KerberosTicketCleanup yes #KerberosTgtPassing no # 4.4 底下是有關在 X-Window 底下使用的相關設定! X11Forwarding yes #X11DisplayOffset 10 #X11UseLocalhost yes # 4.5 登入後的項目: PrintMotd no # 登入後是否顯示出一些資訊呢?例如上次登入的時間、地點等等,預設是 yes # 亦即是列印出 /etc/motd 這個檔案的內容。但是,如果為了安全,可以考慮改為 no ! PrintLastLog yes # 顯示上次登入的資訊!可以啊!預設也是 yes ! KeepAlive yes # 一般而言,如果設定這項目的話,那麼 SSH Server 會傳送KeepAlive 的訊息給 # Client端,以確保兩者的連線正常!在這個情況下,任何一端死掉後,SSH可以立刻知道! # 而不會有僵屍程序的發生! UsePrivilegeSeparation yes # 使用者的權限設定項目!就設定為 yes 吧! MaxStartups 10 # 同時允許幾個尚未登入的連線畫面?當我們連上 SSH ,但是尚未輸入密碼時, # 這個時候就是我們所謂的連線畫面啦!在這個連線畫面中,為了保護主機, # 所以需要設定最大值,預設最多十個連線畫面,而已經建立連線的不計算在這十個當中 # 4.6 關於使用者抵擋的設定項目: DenyUsers * # 設定受抵擋的使用者名稱,如果是全部的使用者,那就是全部擋吧! # 若是部分使用者,可以將該帳號填入!例如下列! DenyUsers test DenyGroups test # 與 DenyUsers 相同!僅抵擋幾個群組而已! # 5. 關於 SFTP 服務的設定項目! Subsystem sftp /usr/lib/ssh/sftp-server |
[test2@test2 ~]$ ssh-keygen -t rsa <==這個步驟在產生 Key pair Generating public/private rsa key pair. Enter file in which to save the key (/home/test2/.ssh/id_rsa): <==這裡按下Enter Enter passphrase (empty for no passphrase): <==這裡按 Enter Enter same passphrase again: <==再按一次 Enter Your identification has been saved in /home/test2/.ssh/id_rsa. <==這是私鑰 Your public key has been saved in /home/test2/.ssh/id_rsa.pub. <==這是公鑰 The key fingerprint is: c4:ae:d9:02:d1:ba:06:5d:07:e6:92:e6:6a:c8:14:ba test2@test2.linux.org # 注意: -t 指的是『使用何種密碼演算方式?』由於我們使用 RSA , # 所以直接輸入 -t rsa 即可建立兩支 Keys ! # 此外,建立的兩把 Keys 都放置在家目錄下的 .ssh 這個目錄中! # 察看一下這兩把 Keys 吧! [test2@test2 ~]$ ll ~/.ssh total 12 -rw------- 1 test2 test2 887 Nov 12 22:36 id_rsa -rw-r--r-- 1 test2 test2 233 Nov 12 22:36 id_rsa.pub -rw-r--r-- 1 test2 test2 222 Oct 31 11:20 known_hosts |
1. 先在 Client 端以 sftp 將公鑰丟到 test 上面去! [test2@test2 ~]$ cd ~/.ssh [test2@test2 .ssh]$ scp id_rsa.pub test@192.168.0.2:~/ test@192.168.0.2's password: id_rsa.pub 100% 233 0.2KB/s 00:00 2. 到 Server 上面,將公鑰轉存到 authorized_keys 檔案中! [test@linux ~]$ cd ~/.ssh [test@linux .ssh]$ cat ../id_rsa.pub >> authorized_keys |
[test2@test2 ~]$ ssh test@linux.dmtsai.tw |
[root@linux ~]# vi /etc/ssh/sshd_config PermitRootLogin no <== 將他改成 no 吧! [root@linux ~]# /etc/init.d/sshd restart |
[root@linux ~]# vi /etc/hosts.allow sshd: 192.168.0.1, 192.168.0.2, 192.168.0.3, 192.168.0.4, 192.168.0.5: allow [root@linux ~]# vi /etc/hosts.deny sshd : ALL : spawn (/bin/echo Security notice from host `/bin/hostname`; \ /bin/echo; /usr/sbin/safe_finger @%h ) | \ /bin/mail -s "%d -%h security" root@localhost & \ : twist ( /bin/echo -e " WARNING connectin not allowed.". ) |

DisplayManager.requestPort: 0 |
!DisplayManager.requestPort: 0 |
1. 先讓 kdm 支援 xdmcp 模式 [root@linux ~]# cd /etc/X11/xdm [root@linux xdm]# vi kdmrc [Xdmcp] Enable=1 # 大約是在 70 行左右。不要懷疑!真的只要這樣就好了! 2. 讓 client 可以透過 X 來登入系統!與權限有關的設定 [root@linux xdm]# vi Xaccess * # 為了安全性上面的需要,想要登入 X 的話,得要通過這個檔案的驗證才行。 # 找到上面這一行,如果沒有這一行的話(整行只有一個 * ), # 就自行加入。這表示『不論來自哪裡,我都接受 X 登入』的意思! 3. 啟動 kdm 喔! [root@linux xdm]# /etc/init.d/xfs start # 就如同我們上面提到的, kdm 執行後,可能的話,會在本機端啟動一個 X server 的, # 而我們這一版的 Xorg 要順利的啟動,得要先啟用 X font Server 才行, # 否則的話,您就得要到 /etc/X11/Xorg.conf 裡面去設定好每個字型的路徑才行。 [root@linux xdm]# kdm [root@linux xdm]# netstat -tlunp Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:6000 0.0.0.0:* LISTEN 5920/X tcp 0 0 :::6000 :::* LISTEN 5920/X udp 0 0 :::177 :::* 5918/kdm # 要看到有 177 的 udp port 出現才行∼ 因為那是 xdmcp 協定的監聽埠口。 # 不過,如果要看看是否有成功啟動 X 的話,就得要查閱 6000 這個 port 囉∼ # 如果沒有看到 port 6000 的話,請查閱 /var/log/Xorg.0.log 喔! # 如果想要設定開機就自動執行的話,可以利用 chkconfig 加入 xfs , # 也可以將 kdm 這個指令寫到 /etc/rc.d/rc.local 這個檔案中∼ |
0. 請務必要在 X Window 當中,進入 X Window 的方式有: [root@client ~]# startx # 或 [root@client ~]# init 5 1. 在 X Window 的畫面當中,啟用一個 shell ,然後輸入: [root@client ~]# xhost + 192.168.1.100 192.168.1.100 being added to access control list # 假設我剛剛那部 Linux 主機的 IP 為 192.168.1.100 [root@client ~]# init 3 <== 關閉 X Server 2. 在文字介面下輸入: [root@client ~]# X -query 192.168.1.100 # 進入 X Window 囉! |









[root@linux xdm]# killall -9 kdm [root@linux xdm]# /etc/init.d/xfs stop |

1. 先讓 kdm 支援 xdmcp 模式 [root@linux ~]# cd /etc/X11/xdm [root@linux xdm]# vi kdmrc [Xdmcp] Enable=1 2. 讓 client 可以透過 X 來登入系統!與權限有關的設定 [root@linux xdm]# vi Xaccess * 3. 啟動 kdm 喔! [root@linux xdm]# /etc/init.d/xfs start [root@linux xdm]# kdm [root@linux xdm]# netstat -tlunp Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:6000 0.0.0.0:* LISTEN 5920/X tcp 0 0 :::6000 :::* LISTEN 5920/X udp 0 0 :::177 :::* 5918/kdm # 要看到有 177 的 udp port 與 port 6000 才行; # 如果沒有看到的話,就得要查詢底下幾個檔案的內容,看看錯誤訊息了! # a. 必須查閱 netstat -tlunp # b. 必須查閱 /var/log/Xorg.log.0 # c. 必須查閱 /var/log/messages # d. 必須查閱 /var/log/kdm.log 4. 用某身份建立 passfile 給 VNC 連線時使用 # 因為 VNC 開的每個 port 都是給某特定使用者登入的,因此, # 每個 VNC server 都會啟用自己的 port 呢∼據說最大可開放到 10 個∼ # 鳥哥這裡假設利用 dmtsai 這個使用者來執行 VNC ,那麼他就必須要有底下幾個動作: 4.1 建立連線用密碼 [root@linux xdm]# su dmtsai [dmtsai@linux xdm]$ vncpasswd Password: <== 這裡請輸入密碼 Verify: <== 再輸入一次∼ # 特別注意,為了安全起見,密碼的長度是有限制的! # 至少要大於六個字元,且不能與帳號相同∼ # 密碼建立後,會在 /home/dmtsai/.vnc/passwd 這個檔案中記錄了你的密碼∼ # 同時,在這個目錄下,還有設定檔 xstartup 可以利用喔! ^_^ 4.2 修改設定檔 xstartup [dmtsai@linux xdm]$ vi /home/dmtsai/.vnc/xstartup # 將這個檔案內的所有資料通通給他註解掉∼不需要保留∼ 4.3 離開此一身份使用者的畫面 [dmtsai@linux xdm]$ exit 5. 修改 /etc/sysconfig/vncserver 檔案內容 # 這個檔案是 FC4 預設的啟動 VNC 的讀取檔,所以我們可以修改他∼ [root@linux xdm]# vi /etc/sysconfig/vncservers # 將原本的資料改成這樣: VNCSERVERS="2:dmtsai" VNCSERVERARGS[2]="-geometry 800x600 -query localhost" # 意思是說,我們要啟動一個 VNC 在 port 5900+2 即 5902 的意思, 6. 啟動 VNC server [root@linux xdm]# /etc/init.d/vncserver start # 此時在 /home/dmtsai/.vnc/ 裡面應該會有幾個檔案您應該要注意的, # 最重要的就是 dmtasi.linux.dmtsai.tw:2.log 這個檔案,檔名的由來是: # username.hostname.domainname:[port number].log ,因為我們是啟用 5902 , # 所以就有 :2.log 的附檔名啦∼務必看到裡面沒有錯誤才行喔∼ # 如果發現找不到/usr/X11R6/lib/X11/xserver/SecurityPolicy 的錯誤,先略過不要緊∼ 7. 查閱設定結果 [root@linux xdm]# netstat -tulnp Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:5802 0.0.0.0:* LISTEN 15287/Xvnc tcp 0 0 0.0.0.0:5902 0.0.0.0:* LISTEN 15287/Xvnc tcp 0 0 0.0.0.0:6000 0.0.0.0:* LISTEN 15019/X tcp 0 0 0.0.0.0:6002 0.0.0.0:* LISTEN 15287/Xvnc tcp 0 0 :::6000 :::* LISTEN 15019/X tcp 0 0 :::6002 :::* LISTEN 15287/Xvnc udp 0 0 0.0.0.0:32924 0.0.0.0:* 15287/Xvnc udp 0 0 :::177 :::* 15017/kdm |
[root@linux ~]# vncserver :3 You will require a password to access your desktops. Password: <== 就輸入密碼吧! Verify: <== 再輸入密碼吧! New 'dmtsai.linux.dmtsai.tw:3 (dmtsai)' desktop is dmtsai.linux.dmtsai.tw:3 Starting applications specified in /root/.vnc/xstartup Log file is /root/.vnc/dmtsai.linux.dmtsai.tw:3.log |
[root@linux ~]# vncserver -kill :3 |




[root@linux ~]# vi /etc/X11/xorg.conf (或 XF86Config)
Section "Module"
....
Load "vnc"
EndSection
# 在 Module 這個 section 當中加入 vnc 這個模組即可
Section "Screen"
Identifier "Screen0"
Device "Videocard0"
Monitor "Monitor0"
Option "passwordFile" "/etc/vnc/passwd"
DefaultDepth 16
......
EndSection
# 假設您的 vnc 密碼檔案放置在 /etc/vnc/passwd 裡頭,
# 這個時候就得要將密碼檔內容寫到 Screen 這個 section 當中了
|

[root@linux ~]# vi /etc/xinetd.d/rsh
service shell
{
disable = no
socket_type = stream
wait = no
user = root
log_on_success += USERID
log_on_failure += USERID
server = /usr/sbin/in.rshd
}
# 沒錯!只要將 disable 改成 no 即可!
[root@linux ~]# /etc/init.d/xinetd restart
[root@linux ~]# netstat -tlnp | grep 514
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:514 0.0.0.0:* LISTEN 23369/xinetd
# 有看到 514 的 port 出現就對了!
|
[root@linux ~]# vi /etc/hosts 127.0.0.1 localhost localhost.localdomain 192.168.1.2 rsh.server rshserver 192.168.1.100 rsh.client rshclient # 上面僅有兩部主機,假設 RSH server 的 IP 是 192.168.1.2 啦! |
[root@linux ~]# vi /etc/hosts.equiv rsh.client dmtsai # 這個檔案的格式是 [hostname] [username] # 將你要開放的使用者與某主機給他對應好寫上去即可! |
[root@linux ~]# vi ~dmtsai/.rhosts rsh.client |
[root@linux ~]# vi /etc/skel/.rhosts rsh.client |
[root@linux ~]# vi /etc/pam.d/rsh #%PAM-1.0 # For root login to succeed here with pam_securetty, "rsh" must be # listed in /etc/securetty. auth required pam_nologin.so #auth required pam_securetty.so auth required pam_env.so auth required pam_rhosts_auth.so account required pam_stack.so service=system-auth session required pam_stack.so service=system-auth |
[root@linux ~]# vi /etc/securetty .....(省略)..... rsh |
[dmtsai@rshclient ~]$ rsh [-l 遠端帳號] [遠端主機名] [遠端主機指令]
參數:
-l :一般來說, server 與 client 『要有相同的使用者帳號名稱』比較好的!
如果沒有的話,那麼您必須要指定 server 的使用者帳號名才行!
遠端主機名 :您要登入的那部 rsh.server 主機名稱,記得與 /etc/hosts 相應!
遠端主機指令:您要在遠端機器上面下達什麼指令?
範例一:在 rsh.server 上面下達 ls -l / 這個指令:
[dmtsai@rshclient ~]$ rsh rsh.server 'ls -l /'
.....輸出省略.....
# 注意喔,我是使用 dmtsai 這個一般身份使用者,而且 rshserver rshclient
# 兩部主機上面都有一個名為 dmtsai 的使用者帳號才行喔!至於那個 ls -l /
# 則是在 rsh.server 主機上面的指令!留意留意!
|
範例:先查閱遠端主機有什麼資料,然後將他複製過來: [dmtsai@rshclient ~]# rsh rsh.server 'ls -l ~' drwx------ 3 dmtsai dmtsai 4096 Dec 27 2005 Desktop -rw-r--r-- 1 dmtsai dmtsai 3385 May 29 17:52 bashrc drwx------ 3 dmtsai dmtsai 4096 Mar 6 2006 mail -rw-r--r-- 1 dmtsai dmtsai 883888 May 29 17:51 netcdf.tar.gz drwxr-xr-x 2 dmtsai dmtsai 4096 Jul 26 16:05 test -rw-rw-r-- 1 dmtsai dmtsai 34816 Mar 19 2006 testing.ppt [dmtsai@rshclient ~]# rcp -r dmtsai@rsh.server:~/mail . # 加上 -r 是為了要複製目錄喔!否則的話,可以直接複製即可! |
[root@linux ~]# rsync [-avrlptgoD] [-e ssh] [user@host:/dir] [/local/path] 參數: -v :觀察模式,可以列出更多的資訊; -q :與 -v 相反,安靜模式,輸出的資訊比較少; -r :遞迴複製!可以針對『目錄』來處理!很重要! -u :僅更新 (update),不會覆蓋目標的新檔案; -l :複製連結檔的屬性,而非連結的目標原始檔案內容; -p :複製時,連同屬性 (permission) 也保存不變! -g :保存原始檔案的擁有群組; -o :保存原始檔案的擁有人; -D :保存原始檔案的裝置屬性 (device) -t :保存原始檔案的時間參數; -I :忽略更新時間 (mtime) 的屬性,檔案比對上會比較快速; -z :加上壓縮的參數! -e :使用的通道協定,例如使用 ssh 通道,則 -e ssh -a :相當於 -rlptgoD ,所以這個 -a 是最常用的參數了! 更多說明請參考 man rsync 的解說! 範例一:將 /etc 的資料備份到 /tmp 底下: [root@linux ~]# rsync -av /etc /tmp ....前面輸出省略.... sent 23007335 bytes received 32280 bytes 5119914.44 bytes/sec total size is 22870014 speedup is 0.99 # 第一次運作時會花比較久的時間,因為首次建立嘛!如果再次備份呢? [root@linux ~]# rsync -av /etc /tmp building file list ... done sent 77105 bytes received 20 bytes 154250.00 bytes/sec total size is 22870014 speedup is 296.53 # 瞧!立刻就跑完了!傳輸的資料也很少!因為再次比對,僅有差異的檔案會被複製。 範例二:利用 dmtsai 的身份,將 rsh.server 使用者家目錄複製到 /tmp [root@linux ~]# rsync -av -e ssh dmtsai@rsh.server:~ /tmp The authenticity of host 'rsh.server (192.168.1.2)' can't be established. RSA key fingerprint is 29:b8:a9:32:ea:d8:ff:97:6c:42:3b:aa:11:ab:55:dd. Are you sure you want to continue connecting (yes/no)? yes Warning: Permanently added 'rsh.server' (RSA) to the list of known hosts. dmtsai@rsh.server's password: receiving file list ... done ....檔案輸出省略.... sent 8436 bytes received 43224862 bytes 2789245.03 bytes/sec total size is 43189031 speedup is 1.00 [root@linux ~]# ll -d /tmp/dmtsai drwxr-xr-x 22 dmtsai dmtsai 4096 Sep 18 23:25 /tmp/dmtsai # 瞧!這樣就做好備份啦!很簡單吧! |