sudo apt-get install chkrootkit
sudo apt-get install rkhunter
二、更新與掃描
sudo chkrootkit
sudo rkhunter –check
sudo rkhunter --update
參考鏈結:http://www.arthurtoday.com/2012/01/ubuntu-rootkit-scanner.html
sudo apt-get install chkrootkit
sudo apt-get install rkhunter
sudo chkrootkit
sudo rkhunter –check
sudo rkhunter --update
sudo apt-get install logcheck設定要把log寄到你的信箱
sudo vim /etc/logcheck/logcheck.conf內容修改:
... SENDMAILTO="xxxxxx@gmail.com" ...測試是否可以把log寄到信箱
sudo -u logcheck logcheck
sudo apt-get install msmtp將msmtp 寄件者改成gmail,內容如下:
sudo vim /etc/msmtprc
account gmail account default: gmail host smtp.gmail.com from xxxxxx@gmail.com protocol smtp tls on auth on port 587 user xxxxxx@gmail.com password xxooxx logfile /var/log/msmtp.log tls_starttls on tls_certcheck off測試msmtp寄mail
echo "Test from msmtp" | msmtp xxxxxx@gmail.com將logcheck寄信功能改成msmtp來寄
sudo ln -s /usr/bin/msmtp /usr/local/sbin/sendmail
sudo ln -s /usr/bin/msmtp /usr/local/bin/sendmail測試是否可以寄信
echo -e "Subject: I hope I receive this\nTest from sendmail" | sendmail xxxxxx@gmail.com
sudo wget http://apache.stu.edu.tw/tomcat/tomcat-connectors/jk/tomcat-connectors-1.2.40-src.tar.gz
sudo tar xvzf tomcat-connectors-1.2.40-src.tar.gz
cd tomcat-connectors-1.2.40-src/native
sudo ./buildconf.sh
sudo ./configure --with-apxs=/usr/local/apache2/bin/apxs
sudo make
sudo make install查看 /usr/local/apache2/modules/ 是否有mod_jk.so
ls -al /usr/local/apache2/modules/
sudo vim /usr/local/apache2/conf/workers.properties內容新增如下:
worker.list=DLOG4J,DLOG4J1, status worker.DLOG4J.type=lb worker.DLOG4J.sticky_session=1 worker.DLOG4J.error_escalation_time=0 worker.DLOG4J.max_reply_timeouts=10 worker.DLOG4J1.type=lb worker.DLOG4J1.sticky_session=1 worker.DLOG4J1.error_escalation_time=0 worker.DLOG4J1.max_reply_timeouts=10 worker.s1.reference=worker.template worker.s1.port=8009 worker.s1.host=localhost worker.s1.lbfactor=5 worker.s2.reference=worker.template worker.s2.port=8010 worker.s2.host=localhost worker.s2.lbfactor=5 worker.template.type=ajp13 worker.template.socket_connect_timeout=5000 worker.template.socket_keepalive=true worker.template.ping_mode=A worker.template.ping_timeout=10000 worker.template.connection_pool_minsize=0 worker.template.connection_pool_timeout=600 worker.template.reply_timeout=300000 worker.template.recovery_options=3 worker.retries=3 worker.DLOG4J.balanced_workers= s1 worker.DLOG4J1.balanced_workers= s2 worker.status.type=statusworker.s1.port=8009 這一個port請看你tomcat/conf/server.xml的AJP port
sudo vim /usr/local/apache2/conf/httpd.conf內容新增如下:
... #LoadModule userdir_module modules/mod_userdir.so LoadModule alias_module modules/mod_alias.so #LoadModule rewrite_module modules/mod_rewrite.so #這邊新增 LoadModule jk_module modules/mod_jk.so JkWorkersFile conf/workers.properties JkLogFile /var/log/mod_jk.log JkLogLevel info JkLogStampFormat "[%a %b %d %H:%M:%S %Y]" JkOptions +ForwardKeySize +ForwardURICompat -ForwardDirectories JkRequestLogFormat "%w %V %T" JkMount /private/admin/status status JkMount /test/* DLOG4J JkMount /test1/* DLOG4J1請在tomcat webapps裡面新增test資料夾,在寫一支index.jsp,看是否用80 port可不可以進來。
sudo cd /usr/local/tomcat
sudo wget http://apache.stu.edu.tw/tomcat/tomcat-8/v8.0.18/bin/apache-tomcat-8.0.18.tar.gz
sudo tar xzvf apache-tomcat-8.0.18.tar.gz
sudo cp ./apache-tomcat-8.0.18 /usr/local/tomcat/apache-tomcat-8.0.18-1
sudo cp ./apache-tomcat-8.0.18 /usr/local/tomcat/apache-tomcat-8.0.18-2
sudo useradd -s /sbin/nologin -d /opt/tomcat/temp tomcat
cd /usr/local/tomcat
cd /usr/local/tomcat/apache-tomcat-8.0.18-1/bin
sudo ./startup.sh
sudo ./catalina.sh run
sudo ./catalina.sh start停止
sudo ./shutdown.sh
sudo ./catalina.sh stop
sudo vim /etc/init.d/tomcat8-1內容新增如下:
#!/bin/bash export CATALINA_HOME=/usr/local/tomcat/apache-tomcat-8.0.18-1 PATH=/sbin:/bin:/usr/sbin:/usr/bin start() { sh $CATALINA_HOME/bin/startup.sh } stop() { sh $CATALINA_HOME/bin/shutdown.sh } case $1 in start|stop) $1;; restart) stop; start;; *) echo "Run as $0儲存後,離開。"; exit 1;; esac
sudo chmod 755 /etc/init.d/tomcat8-1
sudo service tomcat8-1 start
sudo /etc/init.d/tomcat8-1 start
sudo service tomcat8-1 stop
sudo /etc/init.d/tomcat8-1 stop
sudo update-rc.d tomcat8-1 defaults一個Tomcat的服務就安裝完成。
sudo vim /usr/local/tomcat/apache-tomcat-8.0.18-2/conf/server.xml內容如下:
... <Server port="8005" shutdown="SHUTDOWN"> ... ... <Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" /> ... ... <Connector port="8009" protocol="AJP/1.3" redirectPort="8443" /> ... ...將 8005、8080、8009的port改沒有使用過的port,在從剛剛的第三個步驟開始設定。