Linux audit log full
7.4 Set Default umask for Users
The default umask determines the permissions of files created by users. The user creating the file has the discretion of making their files and directories readable by others via the chmod command. Users who wish to allow their files and directories to be readable by others by default may choose a different default umask by inserting the umask command into the standard shell configuration files (.profile, .cshrc, etc.) in their home directories.
Setting a very secure default value for umask ensures that users make a conscious choice about their file permissions. A default umask setting of 077 causes files and directories created by users to not be readable by any other user on the system. A umask of 027 would make files and directories readable by users in the same Unix group, while a umask of 022 would make files readable by every user on the system.
Note: The directives in this section apply to bash and shell. If other shells are supported on the system, it is recommended that their configuration files also are checked.
# 077 is too restrictive
《计算机网络安全与应用》贺思德 申浩如 科学出版社2007 http://netsecurity.ynu.edu.cn 附录A 端口号大全
From Wikipedia, the free encyclopedia
In computer networking, the protocols of the Transport Layer of the Internet Protocol Suite,
most notably the Transmission Control Protocol (TCP) and the User Datagram Protocol (UDP), but also other protocols, use a numerical identifier for the data structures of the endpoints for host-to-host communications. Such an endpoint is known as a port and the identifier is the port number. The Internet Assigned Numbers Authority (IANA) is responsible for maintaining the
official assignments of port numbers for specific uses.[1]
1 Ranges
2 Table legend
3 Well known ports: 1 - 1023
4 Registered ports: 1024–49151
5 Dynamic and/or private ports: 49152–65535
6 See also
1. Ranges Ranges
The port numbers are divided into three ranges:
The Well Known Ports are those in the range 0–1023. On Unix-like operating systems,
binding a communications socket to a port in this range requires administrative privileges
or possessing CAP_NET_BIND_SERVICE capability[2]
? The Registered Ports are those in the range 1024–49151.
The Dynamic and/or Private Ports are those in the range 49152–65535. Randomly chosen port numbers out of this range are called ephemeral ports. These ports are not permanently assigned to any publicly defined application.
IANA does not enforce adherence in use of port numbers to these assignments; it is simply a set of recommended uses. Sometimes applications use port numbers for different purposes than the official assignments suggest. This misuse may be, for example, by malicious software (e.g. Trojan horse) to intercept unsecured traffic or simply because no unique port exists for the application.
/etc/init.d/psacct status --- check the status of the psacct process.
# chkconfig psacct on
# /etc/init.d/psacct start
Starting process accounting: [ OK ]
# chkconfig psacct off
# /etc/init.d/psacct stop
关于linux命令chkconfig --list的问题答案:这是linux下的6种状态,说明HTTPD这个服务在0.下是关闭的,在5下是开启的,0代表的是关机状态,6代表的是重启状态,1代表的是单用户模式,2是没有网络功能的多用户模式,3是有网络功能的多用户模式,4还没有定义,5是桌面模式,123都是用的命令行。 问题:chkconfig --list httpd 0:关闭 1:关闭 2:关闭 3:关闭 4:关闭 5:启用 6:关闭 bluetooth 0:关闭 1:关闭 2:关闭 3:关闭 4:关闭 5:关闭 6:关闭 中 0:关闭 1:关闭 2:关闭 3:关闭 4:关闭 5:关闭 6:关闭 分别代表什么意思呢?
nfslock 0:off 1:off 2:on 3:on 4:on 5:on 6:off