ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ
ืขื•ื“ื›ืŸ ืžื“ืจื™ืš ืžืฉืœื• ืœื”ืฆืคื ืช ื“ื™ืกืง ืžืœื ื‘-RuNet V0.2.

ืืกื˜ืจื˜ื’ื™ื™ืช ื‘ื•ืงืจื™ื:

[ื] ื”ืฆืคื ืช ื—ืกื™ืžืช ืžืขืจื›ืช Windows 7 ืฉืœ ื”ืžืขืจื›ืช ื”ืžื•ืชืงื ืช;
[ื‘] ื”ืฆืคื ืช ื—ืกื™ืžืช ืžืขืจื›ืช GNU/Linux (ื“ื‘ื™ืืŸ) ืžืขืจื›ืช ืžื•ืชืงื ืช (ื›ื•ืœืœ /ืืชื—ื•ืœ);
[C] ืชืฆื•ืจืช GRUB2, ื”ื’ื ืช ืžืืชื—ื•ืœ ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช/ืื™ืžื•ืช/ื’ื™ื‘ื•ืฉ;
[ื“] ื”ืคืฉื˜ื” - ื”ืฉืžื“ืช ื ืชื•ื ื™ื ืœื ืžื•ืฆืคื ื™ื;
[E] ื’ื™ื‘ื•ื™ ืื•ื ื™ื‘ืจืกืœื™ ืฉืœ ืžืขืจื›ืช ื”ืคืขืœื” ืžื•ืฆืคื ืช;
[F] ืชืงื™ืคืช ื™ืขื“ <ืขืœ ืคืจื™ื˜ [C6]> - ื˜ื•ืขืŸ ืืชื—ื•ืœ GRUB2;
[G]ืชื™ืขื•ื“ ืžื•ืขื™ืœ.

โ•ญโ”€โ”€โ”€ืชื•ื›ื ื™ืช ืฉืœ #ื—ื“ืจ 40# :
โ”œโ”€โ”€โ•ผ ืžื•ืชืงืŸ Windows 7 - ื”ืฆืคื ืช ืžืขืจื›ืช ืžืœืื”, ืœื ืžื•ืกืชืจืช;
โ”œโ”€โ”€โ•ผ ืžื•ืชืงืŸ GNU/Linux (ื”ืคืฆื•ืช ื“ื‘ื™ืืŸ ื•ื ื’ื–ืจื•ืช) - ื”ืฆืคื ืช ืžืขืจื›ืช ืžืœืื”, ืœื ืžื•ืกืชืจืช(/, ื›ื•ืœืœ /boot; swap);
โ”œโ”€โ”€โ•ผ ืžืขืžื™ืกื™ ืืชื—ื•ืœ ืขืฆืžืื™ื™ื: ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ VeraCrypt ืžื•ืชืงืŸ ื‘-MBR, ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ GRUB2 ืžื•ืชืงืŸ ื‘ืžื—ื™ืฆื” ื”ืžื•ืจื—ื‘ืช;
โ”œโ”€โ”€โ•ผืื™ืŸ ืฆื•ืจืš ื‘ื”ืชืงื ื”/ื”ืชืงื ื” ืžื—ื“ืฉ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื”;
โ””โ”€โ”€โ•ผ ืชื•ื›ื ื” ืงืจื™ืคื˜ื•ื’ืจืคื™ืช ื‘ืฉื™ืžื•ืฉ: VeraCrypt; Cryptsetup; GnuPG; ืกื•ืกื•ืŸ ื™ื; Hashdeep; GRUB2 ื”ื•ื ื‘ื—ื™ื ื/ื—ื™ื ื.

ื”ืกื›ื™ืžื” ืœืขื™ืœ ืคื•ืชืจืช ื—ืœืงื™ืช ืืช ื”ื‘ืขื™ื” ืฉืœ "ืืชื—ื•ืœ ืžืจื—ื•ืง ืœื›ื•ื ืŸ ื”ื‘ื–ืง", ืžืืคืฉืจืช ืœืš ืœื™ื”ื ื•ืช ืžืžืขืจื›ืช ื”ืคืขืœื” ืžื•ืฆืคื ืช Windows/Linux ื•ืœื”ื—ืœื™ืฃ ื ืชื•ื ื™ื ื‘ืืžืฆืขื•ืช "ืขืจื•ืฅ ืžื•ืฆืคืŸ" ืžืžืขืจื›ืช ื”ืคืขืœื” ืื—ืช ืœืื—ืจืช.

ืกื“ืจ ื”ืืชื—ื•ืœ ืฉืœ ื”ืžื—ืฉื‘ (ืื—ืช ื”ืืคืฉืจื•ื™ื•ืช):

  • ื”ืคืขืœืช ื”ืžื›ื•ื ื”;
  • ื˜ื•ืขืŸ ืืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ VeraCrypt (ื”ื–ื ืช ื”ืกื™ืกืžื” ื”ื ื›ื•ื ื” ืชืžืฉื™ืš ืœืืชื—ืœ ืืช Windows 7);
  • ืœื—ื™ืฆื” ืขืœ ืžืงืฉ "Esc" ืชื˜ืขืŸ ืืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ GRUB2;
  • ืžื˜ืขื™ืŸ ืืชื—ื•ืœ GRUB2 (ื‘ื—ืจ ื”ืคืฆื”/GNU/Linux/CLI), ื™ื“ืจื•ืฉ ืื™ืžื•ืช ืฉืœ ืžืฉืชืžืฉ ื”ืขืœ GRUB2 <login/password>;
  • ืœืื—ืจ ืื™ืžื•ืช ื•ื‘ื—ื™ืจื” ืžื•ืฆืœื—ื™ื ืฉืœ ื”ื”ืคืฆื”, ืชืฆื˜ืจืš ืœื”ื–ื™ืŸ ื‘ื™ื˜ื•ื™ ืกื™ืกืžื” ื›ื“ื™ ืœื‘ื˜ืœ ืืช ื”ื ืขื™ืœื” ืฉืœ "/boot/initrd.img";
  • ืœืื—ืจ ื”ื–ื ืช ืกื™ืกืžืื•ืช ืœืœื ืฉื’ื™ืื•ืช, GRUB2 "ื™ื“ืจื•ืฉ" ื”ื–ื ืช ืกื™ืกืžื” (ืฉืœื™ืฉื™, ืกื™ืกืžืช BIOS ืื• ืกื™ืกืžืช ื—ืฉื‘ื•ืŸ ืžืฉืชืžืฉ GNU/Linux - ืœื ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ) ื›ื“ื™ ืœืคืชื•ื— ื•ืœืืชื—ืœ ืืช ืžืขืจื›ืช ื”ื”ืคืขืœื” GNU/Linux, ืื• ื”ื—ืœืคื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืžืคืชื— ืกื•ื“ื™ (ืฉืชื™ ืกื™ืกืžืื•ืช + ืžืคืชื—, ืื• ืกื™ืกืžื” + ืžืคืชื—);
  • ื—ื“ื™ืจื” ื—ื™ืฆื•ื ื™ืช ืœืชืฆื•ืจืช GRUB2 ืชืงืคื™ื ืืช ืชื”ืœื™ืš ื”ืืชื—ื•ืœ ืฉืœ GNU/Linux.

ื‘ืขื™ื™ืชื™? ืื•ืงื™ื™, ื‘ื•ื ื ืœืš ืœื”ืคื•ืš ืืช ื”ืชื”ืœื™ื›ื™ื ืœืื•ื˜ื•ืžื˜ื™ื™ื.

ื‘ืขืช ื—ืœื•ืงืช ื›ื•ื ืŸ ืงืฉื™ื— ืœืžื—ื™ืฆื•ืช (ื˜ื‘ืœืช MBR) ืœืžื—ืฉื‘ ืื™ืฉื™ ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ืœื ื™ื•ืชืจ ืž-4 ืžื—ื™ืฆื•ืช ืขื™ืงืจื™ื•ืช, ืื• 3 ืžื—ื™ืฆื•ืช ืจืืฉื™ื•ืช ื•ืื—ืช ืžื•ืจื—ื‘ืช, ื›ืžื• ื’ื ืื–ื•ืจ ืœื ืžื•ืงืฆื”. ืงื˜ืข ืžื•ืจื—ื‘, ื‘ื ื™ื’ื•ื“ ืœืจืืฉื™, ื™ื›ื•ืœ ืœื”ื›ื™ืœ ืชืช-ืกืขื™ืคื™ื (ื›ื•ื ื ื™ื ืœื•ื’ื™ื™ื=ืžื—ื™ืฆื” ืžื•ืจื—ื‘ืช). ื‘ืžื™ืœื™ื ืื—ืจื•ืช, "ื”ืžื—ื™ืฆื” ื”ืžื•ืจื—ื‘ืช" ื‘-HDD ืžื—ืœื™ืคื” ืืช LVM ืขื‘ื•ืจ ื”ืžืฉื™ืžื” ืฉืœืคื ื™ื ื•: ื”ืฆืคื ืช ืžืขืจื›ืช ืžืœืื”. ืื ื”ื“ื™ืกืง ืฉืœืš ืžื—ื•ืœืง ืœ-4 ืžื—ื™ืฆื•ืช ืขื™ืงืจื™ื•ืช, ืขืœื™ืš ืœื”ืฉืชืžืฉ ื‘-lvm, ืื• ื‘-transform (ืขื ืขื™ืฆื•ื‘) ื—ืœืง ืžื”ืจืืฉื™ ืœืžืชืงื“ื, ืื• ื”ืฉืชืžืฉ ื‘ื—ื•ื›ืžื” ื‘ื›ืœ ืืจื‘ืขืช ื”ื—ืœืงื™ื ื•ื”ืฉืื™ืจ ื”ื›ืœ ื›ืคื™ ืฉื”ื•ื, ื›ื“ื™ ืœืงื‘ืœ ืืช ื”ืชื•ืฆืื” ื”ืจืฆื•ื™ื”. ื’ื ืื ื™ืฉ ืœืš ืžื—ื™ืฆื” ืื—ืช ื‘ื“ื™ืกืง ืฉืœืš, Gparted ื™ืขื–ื•ืจ ืœืš ืœื—ืœืง ืืช ื”ื“ื™ืกืง ื”ืงืฉื™ื— ืฉืœืš ืœืžื—ื™ืฆื•ืช (ืœืงื˜ืขื™ื ื ื•ืกืคื™ื) ืœืœื ืื•ื‘ื“ืŸ ื ืชื•ื ื™ื, ืื‘ืœ ืขื“ื™ื™ืŸ ืขื ืงื ืก ืงื˜ืŸ ืขืœ ืคืขื•ืœื•ืช ื›ืืœื”.

ืขืจื›ืช ืคืจื™ืกืช ื”ื›ื•ื ืŸ ื”ืงืฉื™ื—, ืฉื‘ื™ื—ืก ืืœื™ื” ื™ืชืคืจืกื ื”ืžืืžืจ ื›ื•ืœื•, ืžื•ืฆื’ืช ื‘ื˜ื‘ืœื” ืฉืœื”ืœืŸ.

ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ
ื˜ื‘ืœื” (ืžืก' 1) ืฉืœ ืžื—ื™ืฆื•ืช 1TB.

ื’ื ืœืš ืฆืจื™ืš ืžืฉื”ื• ื“ื•ืžื”.
sda1 - ืžื—ื™ืฆื” ืจืืฉื™ืช ืžืก' 1 NTFS (ืžื•ืฆืคืŸ);
sda2 - ืกืžืŸ ืžืงื˜ืข ืžื•ืจื—ื‘;
sda6 - ื“ื™ืกืง ืœื•ื’ื™ (ืžื•ืชืงืŸ ื‘ื• ืืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ GRUB2);
sda8 - swap (ืงื•ื‘ืฅ ื”ื—ืœืคื” ืžื•ืฆืคืŸ/ืœื ืชืžื™ื“);
sda9 - ื‘ื“ื™ืงืช ื“ื™ืกืง ืœื•ื’ื™;
sda5 - ื“ื™ืกืง ืœื•ื’ื™ ืœืกืงืจื ื™ื;
sda7 - GNU/Linux OS (ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ื•ืขื‘ืจื” ืœื“ื™ืกืง ืœื•ื’ื™ ืžื•ืฆืคืŸ);
sda3 - ืžื—ื™ืฆื” ืจืืฉื™ืช ืžืก' 2 ืขื ืžืขืจื›ืช ื”ื”ืคืขืœื” Windows 7 (ืžื•ืฆืคืŸ);
sda4 - ืกืขื™ืฃ ืจืืฉื™ ืžืก' 3 (ื”ื•ื ื”ื›ื™ืœ GNU/Linux ืœื ืžื•ืฆืคืŸ, ืžืฉืžืฉ ืœื’ื™ื‘ื•ื™/ืœื ืชืžื™ื“).

[ื] Windows 7 System Block Encryption

A1. VeraCryptื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

ื”ื•ืจื“ ืž ืืชืจ ืจืฉืžื™, ืื• ืžื”ืžืจืื” ืžืงื•ืจ ื’ืจืกืช ื”ืชืงื ื” ืฉืœ ืชื•ื›ื ืช ื”ื”ืฆืคื ื” VeraCrypt (ื‘ื–ืžืŸ ืคืจืกื•ื ื”ืžืืžืจ v1.24-Update3, ื”ื’ืจืกื” ื”ื ื™ื™ื“ืช ืฉืœ VeraCrypt ืื™ื ื” ืžืชืื™ืžื” ืœื”ืฆืคื ืช ืžืขืจื›ืช). ื‘ื“ื•ืง ืืช ืกื›ื•ื ื”ื‘ื“ื™ืงื” ืฉืœ ื”ืชื•ื›ื ื” ืฉื”ื•ืจื“ืช

$ Certutil -hashfile "C:VeraCrypt Setup 1.24.exe" SHA256

ื•ื”ืฉื•ื• ืืช ื”ืชื•ืฆืื” ืœ-CS ืฉืคื•ืจืกืžื” ื‘ืืชืจ ื”ืžืคืชื—ื™ื ืฉืœ VeraCrypt.

ืื ืžื•ืชืงื ืช ืชื•ื›ื ืช HashTab, ื–ื” ืืคื™ืœื• ื™ื•ืชืจ ืงืœ: RMB (VeraCrypt Setup 1.24.exe)-ืžืืคื™ื™ื ื™ื - ืกื›ื•ื ื’ื™ื‘ื•ื‘ ืฉืœ ืงื‘ืฆื™ื.

ื›ื“ื™ ืœืืžืช ืืช ื—ืชื™ืžืช ื”ืชื•ื›ื ื™ืช, ื™ืฉ ืœื”ืชืงื™ืŸ ืืช ื”ืชื•ื›ื ื” ื•ืืช ืžืคืชื— ื”-pgp ื”ืฆื™ื‘ื•ืจื™ ืฉืœ ื”ืžืคืชื— ื‘ืžืขืจื›ืช gnuPG; gpg4win.

A2. ื”ืชืงื ื”/ื”ืคืขืœื” ืฉืœ ืชื•ื›ื ืช VeraCrypt ืขื ื–ื›ื•ื™ื•ืช ืžื ื”ืœื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

A3. ื‘ื—ื™ืจืช ืคืจืžื˜ืจื™ ื”ืฆืคื ืช ืžืขืจื›ืช ืขื‘ื•ืจ ื”ืžื—ื™ืฆื” ื”ืคืขื™ืœื”VeraCrypt โ€“ ืžืขืจื›ืช โ€“ ื”ืฆืคื ืช ืžื—ื™ืฆืช ืžืขืจื›ืช/ื“ื™ืกืง โ€“ ืจื’ื™ืœ โ€“ ื”ืฆืคื ืช ืžื—ื™ืฆืช ืžืขืจื›ืช Windows โ€“ Multiboot โ€“ (ืื–ื”ืจื”: "ืœื ืžื•ืžืœืฅ ืœืžืฉืชืžืฉื™ื ืœื ืžื ื•ืกื™ื ืœื”ืฉืชืžืฉ ื‘ืฉื™ื˜ื” ื–ื•" ื•ื–ื” ื ื›ื•ืŸ, ืื ื• ืžืกื›ื™ืžื™ื "ื›ืŸ") - ื“ื™ืกืง ืืชื—ื•ืœ ("ื›ืŸ", ื’ื ืื ืœื ื›ืš, ืขื“ื™ื™ืŸ "ื›ืŸ") - ืžืกืคืจ ื“ื™ืกืงื™ ืžืขืจื›ืช "2 ืื• ื™ื•ืชืจ" - ืžืกืคืจ ืžืขืจื›ื•ืช ื‘ื“ื™ืกืง ืื—ื“ "ื›ืŸ" - ื˜ื•ืขืŸ ืืชื—ื•ืœ ืฉืื™ื ื• Windows "ืœื" (ืœืžืขืฉื”, "ื›ืŸ", ืื‘ืœ ืžืขืžื™ืกื™ ื”ืืชื—ื•ืœ VeraCrypt/GRUB2 ืœื ื™ื—ืœืงื• ืืช ื”-MBR ื‘ื™ื ื ืœื‘ื™ืŸ ืขืฆืžื; ืœื™ืชืจ ื“ื™ื•ืง, ืจืง ื”ื—ืœืง ื”ืงื˜ืŸ ื‘ื™ื•ืชืจ ืฉืœ ืงื•ื“ ืžื˜ืขื™ืŸ ื”ืืชื—ื•ืœ ืžืื•ื—ืกืŸ ื‘ืžืกืœื•ืœ MBR/ืืชื—ื•ืœ, ื”ื—ืœืง ื”ืขื™ืงืจื™ ืฉืœื• ื”ื•ื ืžืžื•ืงื ื‘ืชื•ืš ืžืขืจื›ืช ื”ืงื‘ืฆื™ื) โ€“ Multiboot โ€“ ื”ื’ื“ืจื•ืช ื”ืฆืคื ื”...

ืื ืืชื” ืกื•ื˜ื” ืžื”ืฉืœื‘ื™ื ืœืขื™ืœ (ื—ืกื™ืžืช ืชื•ื›ื ื™ื•ืช ื”ืฆืคื ืช ืžืขืจื›ืช), ืื– VeraCrypt ืชื•ืฆื™ื ืื–ื”ืจื” ื•ืœื ืชืืคืฉืจ ืœืš ืœื”ืฆืคื™ืŸ ืืช ื”ืžื—ื™ืฆื”.

ื‘ืฉืœื‘ ื”ื‘ื ืœืงืจืืช ื”ื’ื ืช ืžื™ื“ืข ืžืžื•ืงื“ืช, ืขืจื›ื• "ื‘ื“ื™ืงื”" ื•ื‘ื—ืจื• ืืœื’ื•ืจื™ืชื ื”ืฆืคื ื”. ืื ื™ืฉ ืœืš ืžืขื‘ื“ ืžื™ื•ืฉืŸ, ืกื‘ื™ืจ ืœื”ื ื™ื— ืฉืืœื’ื•ืจื™ืชื ื”ื”ืฆืคื ื” ื”ืžื”ื™ืจ ื‘ื™ื•ืชืจ ื™ื”ื™ื” Twofish. ืื ื”ืžืขื‘ื“ ื—ื–ืง, ืชื‘ื—ื™ื ื• ื‘ื”ื‘ื“ืœ: ื”ืฆืคื ืช AES, ืขืœ ืคื™ ืชื•ืฆืื•ืช ื”ื‘ื“ื™ืงื”, ืชื”ื™ื” ืžื”ื™ืจื” ืคื™ ื›ืžื” ืžืžืชื—ืจื•ืช ื”ืงืจื™ืคื˜ื•. AES ื”ื•ื ืืœื’ื•ืจื™ืชื ื”ืฆืคื ื” ืคื•ืคื•ืœืจื™; ื”ื—ื•ืžืจื” ืฉืœ ืžืขื‘ื“ื™ื ืžื•ื“ืจื ื™ื™ื ืžื•ืชืืžืช ื‘ืžื™ื•ื—ื“ ื”ืŸ ืœ"ืกื•ื“ื™" ื•ื”ืŸ ืœ"ืคืจื™ืฆื”".

VeraCrypt ืชื•ืžืš ื‘ื™ื›ื•ืœืช ืœื”ืฆืคื™ืŸ ื“ื™ืกืงื™ื ื‘ืžืคืœ AES(ืฉื ื™ ื“ื’ื™ื)/ื•ืฉื™ืœื•ื‘ื™ื ืื—ืจื™ื. ืขืœ ืžืขื‘ื“ ืœื™ื‘ื” ื™ืฉืŸ ืฉืœ ืื™ื ื˜ืœ ืžืœืคื ื™ ืขืฉืจ ืฉื ื™ื (ืœืœื ืชืžื™ื›ืช ื—ื•ืžืจื” ืขื‘ื•ืจ AES, ื”ืฆืคื ืช ืžืคืœ A/T) ื”ื™ืจื™ื“ื” ื‘ื‘ื™ืฆื•ืขื™ื ื”ื™ื ืœืžืขืฉื” ื‘ืœืชื™ ืžื•ืจื’ืฉืช. (ืขื‘ื•ืจ ืžืขื‘ื“ื™ AMD ืžืื•ืชื• ืขื™ื“ืŸ/ืคืจืžื˜ืจื™ื, ื”ื‘ื™ืฆื•ืขื™ื ืžื•ืคื—ืชื™ื ืžืขื˜). ืžืขืจื›ืช ื”ื”ืคืขืœื” ืคื•ืขืœืช ื‘ืื•ืคืŸ ื“ื™ื ืžื™ ื•ืฆืจื™ื›ืช ื”ืžืฉืื‘ื™ื ืœื”ืฆืคื ื” ืฉืงื•ืคื” ืื™ื ื” ื ืจืื™ืช. ืœืขื•ืžืช ื–ืืช, ืœืžืฉืœ, ื™ืฉื ื” ื™ืจื™ื“ื” ื ื™ื›ืจืช ื‘ื‘ื™ืฆื•ืขื™ื ืขืงื‘ ืกื‘ื™ื‘ืช ืฉื•ืœื—ืŸ ื”ืขื‘ื•ื“ื” ื”ื‘ืœืชื™ ื™ืฆื™ื‘ื” ืœื‘ื“ื™ืงื” ื”ืžื•ืชืงื ืช Mate v1.20.1 (ืื• v1.20.2 ืื ื™ ืœื ื–ื•ื›ืจ ื‘ื“ื™ื•ืง) ื‘-GNU/Linux, ืื• ืขืงื‘ ืคืขื•ืœืช ืฉื’ืจืช ื”ื˜ืœืžื˜ืจื™ื” ื‘-Windows7โ†‘. ื‘ื“ืจืš ื›ืœืœ, ืžืฉืชืžืฉื™ื ืžื ื•ืกื™ื ืขื•ืจื›ื™ื ื‘ื“ื™ืงื•ืช ื‘ื™ืฆื•ืขื™ ื—ื•ืžืจื” ืœืคื ื™ ื”ื”ืฆืคื ื”. ืœื“ื•ื’ืžื”, ื‘-Aida64/Sysbench/systemd-analyze ืžืฉื•ื•ื™ื ืืช ื”ืืฉืžื” ืœืชื•ืฆืื•ืช ืฉืœ ืื•ืชืŸ ื‘ื“ื™ืงื•ืช ืœืื—ืจ ื”ืฆืคื ืช ื”ืžืขืจื›ืช, ื•ื‘ื›ืš ืžืคืจื™ื›ื™ื ื‘ืขืฆืžื ืืช ื”ืžื™ืชื•ืก ืฉ"ื”ืฆืคื ืช ื”ืžืขืจื›ืช ืžื–ื™ืงื”". ื”ืื˜ื” ืฉืœ โ€‹โ€‹ื”ืžื›ื•ื ื” ื•ืื™ ื”ื ื•ื—ื•ืช ื ื™ื›ืจื•ืช ื‘ืขืช ื’ื™ื‘ื•ื™/ืฉื—ื–ื•ืจ ื ืชื•ื ื™ื ืžื•ืฆืคื ื™ื, ืžื›ื™ื•ื•ืŸ ืฉืคืขื•ืœืช "ื’ื™ื‘ื•ื™ ื ืชื•ื ื™ ื”ืžืขืจื›ืช" ืขืฆืžื” ืื™ื ื” ื ืžื“ื“ืช ื‘-ms, ื•ื ื•ืกืคื™ื ืื•ืชื <ืคืขื ื•ื—/ื”ืฆืคื ื” ืชื•ืš ื›ื“ื™ ืชื ื•ืขื”>. ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ, ื›ืœ ืžืฉืชืžืฉ ืฉืžื•ืชืจ ืœื• ืœื”ืชืขืกืง ื‘ื”ืฆืคื ื” ืžืื–ืŸ ืืช ืืœื’ื•ืจื™ืชื ื”ื”ืฆืคื ื” ืžื•ืœ ืฉื‘ื™ืขื•ืช ื”ืจืฆื•ืŸ ืฉืœ ื”ืžืฉื™ืžื•ืช ื”ืขื•ืžื“ื•ืช ืขืœ ื”ืคืจืง, ืจืžืช ื”ืคืจื ื•ื™ื” ืฉืœื”ื ื•ืงืœื•ืช ื”ืฉื™ืžื•ืฉ.

ืขื“ื™ืฃ ืœื”ืฉืื™ืจ ืืช ืคืจืžื˜ืจ PIM ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื›ืš ืฉื‘ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ืœื ืชืฆื˜ืจืš ืœื”ื–ื™ืŸ ืืช ืขืจื›ื™ ื”ืื™ื˜ืจืฆื™ื” ื”ืžื“ื•ื™ืงื™ื ื‘ื›ืœ ืคืขื. VeraCrypt ืžืฉืชืžืฉ ื‘ืžืกืคืจ ืขืฆื•ื ืฉืœ ืื™ื˜ืจืฆื™ื•ืช ื›ื“ื™ ืœื™ืฆื•ืจ "hash ืื™ื˜ื™" ื‘ืืžืช. ื”ืชืงืคื” ืขืœ "ื—ื™ืœื–ื•ืŸ ืงืจื™ืคื˜ื•" ื›ื–ื” ื‘ืฉื™ื˜ืช Brute force/bow tables ื”ื’ื™ื•ื ื™ืช ืจืง ืขื ืžืฉืคื˜ ืกื™ืกืžื” ืงืฆืจ "ืคืฉื•ื˜" ื•ืจืฉื™ืžืช ื”ืชื•ื•ื™ื ื”ืื™ืฉื™ืช ืฉืœ ื”ืงื•ืจื‘ืŸ. ื”ืžื—ื™ืจ ืฉื™ืฉ ืœืฉืœื ืขื‘ื•ืจ ื—ื•ื–ืง ื”ืกื™ืกืžื” ื”ื•ื ืขื™ื›ื•ื‘ ื‘ื”ื–ื ืช ื”ืกื™ืกืžื” ื”ื ื›ื•ื ื” ื‘ืขืช ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื”. (ื”ืจื›ื‘ืช ื ืคื—ื™ VeraCrypt ื‘-GNU/Linux ืžื”ื™ืจื” ืžืฉืžืขื•ืชื™ืช).
ืชื•ื›ื ื” ื—ื™ื ืžื™ืช ืœื™ื™ืฉื•ื ื”ืชืงืคื•ืช ื›ื•ื— ื’ืก (ื—ืœืฅ ื‘ื™ื˜ื•ื™ ืกื™ืกืžื” ืžื›ื•ืชืจืช ื”ื“ื™ืกืง VeraCrypt/LUKS) ื”ืืฉืงื˜. ื’'ื•ืŸ ื”ืžืจื˜ืฉ ืœื ื™ื•ื“ืข ืื™ืš "ืœืฉื‘ื•ืจ ืืช Veracrypt", ื•ื›ืฉื”ื•ื ืขื•ื‘ื“ ืขื LUKS ืœื ืžื‘ื™ืŸ ื‘ืงืจื™ืคื˜ื•ื’ืจืคื™ื” ืฉืœ Twofish.

ื‘ืฉืœ ื”ื—ื•ื–ืง ื”ื”ืฆืคื ื” ืฉืœ ืืœื’ื•ืจื™ืชืžื™ ื”ื”ืฆืคื ื”, ืกื™ื™ืคืจืคืื ืงื™ื ื‘ืœืชื™ ื ื™ืชื ื™ื ืœืขืฆื™ืจื” ืžืคืชื—ื™ื ืชื•ื›ื ื” ืขื ื•ืงื˜ื•ืจ ื”ืชืงืคื” ืฉื•ื ื”. ืœื“ื•ื’ืžื”, ื—ื™ืœื•ืฅ ืžื˜ื ื ืชื•ื ื™ื/ืžืคืชื—ื•ืช ืž-RAM (ืืชื—ื•ืœ ืงืจ/ื”ืชืงืคืช ื’ื™ืฉื” ื™ืฉื™ืจื” ืœื–ื™ื›ืจื•ืŸ), ื™ืฉ ืชื•ื›ื ื” ืžื™ื•ื—ื“ืช ื—ื™ื ืžื™ืช ื•ืœื ื—ื™ื ืžื™ืช ืœืžื˜ืจื•ืช ืืœื•.

ืขื ื”ืฉืœืžืช ื”ื”ื’ื“ืจื”/ื™ืฆื™ืจืช "ืžื˜ื ื ืชื•ื ื™ื ื™ื™ื—ื•ื“ื™ื™ื" ืฉืœ ื”ืžื—ื™ืฆื” ื”ืคืขื™ืœื” ื”ืžื•ืฆืคื ืช, VeraCrypt ืชืฆื™ืข ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช ื”ืžื—ืฉื‘ ื”ืื™ืฉื™ ื•ืœื‘ื“ื•ืง ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืฉืœื•. ืœืื—ืจ ืืชื—ื•ืœ/ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ Windows, VeraCrypt ื™ื™ื˜ืขืŸ ื‘ืžืฆื‘ ื”ืžืชื ื”, ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœืืฉืจ ืืช ืชื”ืœื™ืš ื”ื”ืฆืคื ื” - Y.

ื‘ืฉืœื‘ ื”ืื—ืจื•ืŸ ืฉืœ ื”ืฆืคื ืช ื”ืžืขืจื›ืช, VeraCrypt ืชืฆื™ืข ืœื™ืฆื•ืจ ืขื•ืชืง ื’ื™ื‘ื•ื™ ืฉืœ ื”ื›ื•ืชืจืช ืฉืœ ื”ืžื—ื™ืฆื” ื”ืžื•ืฆืคื ืช ื”ืคืขื™ืœื” ื‘ืฆื•ืจื” ืฉืœ "veracrypt rescue disk.iso" - ื™ืฉ ืœืขืฉื•ืช ื–ืืช - ื‘ืชื•ื›ื ื” ื–ื• ืคืขื•ืœื” ื›ื–ื• ื”ื™ื ื“ืจื™ืฉื” (ื‘-LUKS, ื›ื“ืจื™ืฉื” - ื–ื” ืœืžืจื‘ื” ื”ืฆืขืจ ืžื•ืฉืžื˜, ืืš ืžื•ื“ื’ืฉ ื‘ืชื™ืขื•ื“). ื“ื™ืกืง ื”ืฆืœื” ื™ื”ื™ื” ืฉื™ืžื•ืฉื™ ืœื›ื•ืœื, ื•ืœื—ืœืงื ื™ื•ืชืจ ืžืคืขื ืื—ืช. ื”ึถืคืกึตื“ (ืฉื›ืชื•ื‘ ื›ื•ืชืจืช/MBR) ืขื•ืชืง ื’ื™ื‘ื•ื™ ืฉืœ ื”ื›ื•ืชืจืช ื™ืžื ืข ืœืฆืžื™ืชื•ืช ื’ื™ืฉื” ืœืžื—ื™ืฆื” ื”ืžืคื•ืขื ื—ืช ืขื ืžืขืจื›ืช ื”ื”ืคืขืœื” Windows.

A4. ื™ืฆื™ืจืช USB/ื“ื™ืกืง ื”ืฆืœื” ืฉืœ VeraCryptื›ื‘ืจื™ืจืช ืžื—ื“ืœ, VeraCrypt ืžืฆื™ืขื” ืœืฆืจื•ื‘ "~2-3MB ืฉืœ ืžื˜ื ื ืชื•ื ื™ื" ืœืชืงืœื™ื˜ื•ืจ, ืืš ืœื ืœื›ืœ ื”ืื ืฉื™ื ื™ืฉ ื“ื™ืกืงื™ื ืื• ื›ื•ื ื ื™ DWD-ROM, ื•ื™ืฆื™ืจืช ื›ื•ื ืŸ ื”ื‘ื–ืง ื”ื ื™ืชืŸ ืœืืชื—ื•ืœ "VeraCrypt Rescue disk" ืชื”ื™ื” ื”ืคืชืขื” ื˜ื›ื ื™ืช ืขื‘ื•ืจ ื—ืœืงื: Rufus /GUIDd-ROSA ImageWriter ื•ืชื•ื›ื ื•ืช ื“ื•ืžื•ืช ืื—ืจื•ืช ืœื ื™ื•ื›ืœื• ืœื”ืชืžื•ื“ื“ ืขื ื”ืžืฉื™ืžื”, ืžื›ื™ื•ื•ืŸ ืฉื‘ื ื•ืกืฃ ืœื”ืขืชืงืช ืžื˜ื ื ืชื•ื ื™ื ืื•ืคืกื˜ ืœื›ื•ื ืŸ ื”ื‘ื–ืง ื”ื ื™ืชืŸ ืœืืชื—ื•ืœ, ืขืœื™ืš ืœื”ืขืชื™ืง/ืœื”ื“ื‘ื™ืง ืืช ื”ืชืžื•ื ื” ืžื—ื•ืฅ ืœืžืขืจื›ืช ื”ืงื‘ืฆื™ื ืฉืœ ื›ื•ื ืŸ ื”-USB, ื‘ืงื™ืฆื•ืจ, ื”ืขืชืง ื ื›ื•ืŸ ืืช ื”-MBR/ื›ื‘ื™ืฉ ืœืžื—ื–ื™ืง ืžืคืชื—ื•ืช. ืืชื” ื™ื›ื•ืœ ืœื™ืฆื•ืจ ื›ื•ื ืŸ ื”ื‘ื–ืง ื”ื ื™ืชืŸ ืœืืชื—ื•ืœ ืžืžืขืจื›ืช ื”ื”ืคืขืœื” GNU/Linux ื‘ืืžืฆืขื•ืช ื›ืœื™ ื”ืฉื™ืจื•ืช "dd", ืชื•ืš ื”ืกืชื›ืœื•ืช ืขืœ ื”ืฉืœื˜ ื”ื–ื”.

ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

ื™ืฆื™ืจืช ื“ื™ืกืง ื”ืฆืœื” ื‘ืกื‘ื™ื‘ืช Windows ืฉื•ื ื”. ื”ืžืคืชื— ืฉืœ VeraCrypt ืœื ื›ืœืœ ืืช ื”ืคืชืจื•ืŸ ืœื‘ืขื™ื” ื–ื• ื‘ืจืฉืžื™ ืชื™ืขื•ื“ ืขืœ ื™ื“ื™ "ื“ื™ืกืง ื”ืฆืœื”", ืื‘ืœ ื”ืฆื™ืข ืคืชืจื•ืŸ ื‘ื“ืจืš ืื—ืจืช: ื”ื•ื ืคืจืกื ืชื•ื›ื ื” ื ื•ืกืคืช ืœื™ืฆื™ืจืช "ื“ื™ืกืง ื”ืฆืœื” usb" ืœื’ื™ืฉื” ื—ื•ืคืฉื™ืช ื‘ืคื•ืจื•ื VeraCrypt ืฉืœื•. ื”ืืจื›ื™ื•ืŸ ืฉืœ ืชื•ื›ื ื” ื–ื• ืขื‘ื•ืจ Windows "ื™ื•ืฆืจ ื“ื™ืกืง ื”ืฆืœื” usb veracrypt". ืœืื—ืจ ืฉืžื™ืจืช ื”-rescue disk.iso, ื™ืชื—ื™ืœ ืชื”ืœื™ืš ืฉืœ ื”ืฆืคื ืช ืžืขืจื›ืช ื—ืกื™ืžืช ื”ืžื—ื™ืฆื” ื”ืคืขื™ืœื”. ื‘ืžื”ืœืš ื”ื”ืฆืคื ื”, ืคืขื•ืœืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ืื™ื ื” ื ืขืฆืจืช; ืื™ืŸ ืฆื•ืจืš ื‘ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ ื”ืžื—ืฉื‘. ืขื ื”ืฉืœืžืช ืคืขื•ืœืช ื”ื”ืฆืคื ื”, ื”ืžื—ื™ืฆื” ื”ืคืขื™ืœื” ื”ื•ืคื›ืช ืœืžื•ืฆืคื ืช ืžืœืื” ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”. ืื ืžื˜ืขื™ืŸ ื”ืืชื—ื•ืœ ืฉืœ VeraCrypt ืœื ืžื•ืคื™ืข ื‘ืขืช ื”ืคืขืœืช ื”ืžื—ืฉื‘, ื•ืคืขื•ืœืช ืฉื—ื–ื•ืจ ื”ื›ื•ืชืจืช ืœื ืขื•ื–ืจืช, ื‘ื“ื•ืง ืืช ื“ื’ืœ "ืืชื—ื•ืœ", ื™ืฉ ืœื”ื’ื“ื™ืจ ืื•ืชื• ืœืžื—ื™ืฆื” ืฉื‘ื” Windows ื ืžืฆื (ืœืœื ืงืฉืจ ืœื”ืฆืคื ื” ื•ืžืขืจื›ืช ื”ืคืขืœื” ืื—ืจืช, ืจืื” ื˜ื‘ืœื” ืžืก' 1).
ื–ื” ืžืฉืœื™ื ืืช ื”ืชื™ืื•ืจ ืฉืœ ื”ืฆืคื ืช ืžืขืจื›ืช ื—ืกื™ืžื” ืขื ืžืขืจื›ืช ื”ื”ืคืขืœื” Windows.

[ื‘]ืžื–ืœ. ื”ืฆืคื ืช GNU/Linux (~ื“ื‘ื™ืืŸ) ืžืขืจื›ืช ื”ืคืขืœื” ืžื•ืชืงื ืช. ืืœื’ื•ืจื™ืชื ื•ืฉืœื‘ื™ื

ืขืœ ืžื ืช ืœื”ืฆืคื™ืŸ ื”ืคืฆื” ืฉืœ Debian/ื ื’ื–ืจืช, ืขืœื™ืš ืœืžืคื•ืช ืืช ื”ืžื—ื™ืฆื” ื”ืžื•ื›ื ื” ืœื”ืชืงืŸ ื‘ืœื•ืง ื•ื™ืจื˜ื•ืืœื™, ืœื”ืขื‘ื™ืจ ืื•ืชื” ืœื“ื™ืกืง GNU/Linux ืžืžื•ืคื” ื•ืœื”ืชืงื™ืŸ/ืœื”ื’ื“ื™ืจ GRUB2. ืื ืื™ืŸ ืœืš ืฉืจืช ืžืชื›ืช ื—ืฉื•ืฃ, ื•ืืชื” ืžืขืจื™ืš ืืช ื”ื–ืžืŸ ืฉืœืš, ืื– ืืชื” ืฆืจื™ืš ืœื”ืฉืชืžืฉ ื‘-GUI, ื•ืจื•ื‘ ืคืงื•ื“ื•ืช ื”ื˜ืจืžื™ื ืœ ื”ืžืชื•ืืจื•ืช ืœื”ืœืŸ ื ื•ืขื“ื• ืœื”ื™ื•ืช ืžื•ืคืขืœื•ืช ื‘"ืžืฆื‘ ืฆ'ืืง-ื ื•ืจื™ืก".

B1. ืืชื—ื•ืœ ื”ืžื—ืฉื‘ ืž-USB ื—ื™ GNU/Linux

"ืขืจื•ืš ืžื‘ื—ืŸ ืงืจื™ืคื˜ื• ืœื‘ื™ืฆื•ืขื™ ื”ื—ื•ืžืจื”"

lscpu && ัryptsetup benchmark

ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

ืื ืืชื” ื”ื‘ืขืœื™ื ื”ืžืื•ืฉืจ ืฉืœ ืžื›ื•ื ื™ืช ื—ื–ืงื” ืขื ืชืžื™ื›ื” ื‘ื—ื•ืžืจื” ืฉืœ AES, ืื– ื”ืžืกืคืจื™ื ื™ื™ืจืื• ื›ืžื• ื”ืฆื“ ื”ื™ืžื ื™ ืฉืœ ื”ื˜ืจืžื™ื ืœ; ืื ืืชื” ื‘ืขืœื™ื ืžืื•ืฉืจ, ืื‘ืœ ืขื ื—ื•ืžืจื” ืขืชื™ืงื”, ื”ืžืกืคืจื™ื ื™ื™ืจืื• ื›ืžื• ื”ืฆื“ ื”ืฉืžืืœื™.

B2. ื—ืœื•ืงืช ื“ื™ืกืง. ื”ืจื›ื‘ื”/ืคื™ืจืžื•ื˜ fs ื“ื™ืกืง ืœื•ื’ื™ HDD ืœ-Ext4 (Gparted)

B2.1. ื™ืฆื™ืจืช ื›ื•ืชืจืช ืžื—ื™ืฆืช sda7 ืžื•ืฆืคื ืชืืชืืจ ืืช ืฉืžื•ืช ื”ืžื—ื™ืฆื•ืช, ื›ืืŸ ื•ื‘ื”ืžืฉืš, ื‘ื”ืชืื ืœื˜ื‘ืœืช ื”ืžื—ื™ืฆื•ืช ืฉืœื™ ืฉืคื•ืจืกืžื” ืœืžืขืœื”. ื‘ื”ืชืื ืœืคืจื™ืกืช ื”ื“ื™ืกืง ืฉืœืš, ืขืœื™ืš ืœื”ื—ืœื™ืฃ ืืช ืฉืžื•ืช ื”ืžื—ื™ืฆื•ืช ืฉืœืš.

ืžื™ืคื•ื™ ื”ืฆืคื ืช ื›ื•ื ืŸ ืœื•ื’ื™ (/dev/sda7 > /dev/mapper/sda7_crypt).
#ื™ืฆื™ืจื” ืงืœื” ืฉืœ "ืžื—ื™ืฆืช LUKS-AES-XTS"

cryptsetup -v -y luksFormat /dev/sda7

ืืคืฉืจื•ื™ื•ืช:

* luksFormat - ืืชื—ื•ืœ ืฉืœ ื›ื•ืชืจืช LUKS;
* -y -phrase (ืœื ืžืคืชื—/ืงื•ื‘ืฅ);
* -v -ื•ื•ืจื‘ืœื™ื–ืฆื™ื” (ื”ืฆื’ืช ืžื™ื“ืข ื‘ื˜ืจืžื™ื ืœ);
* /dev/sda7 - ื”ื“ื™ืกืง ื”ืœื•ื’ื™ ืฉืœืš ืžื”ืžื—ื™ืฆื” ื”ืžื•ืจื—ื‘ืช (ื”ื™ื›ืŸ ืžืชื•ื›ื ืŸ ืœื”ืขื‘ื™ืจ/ืœื”ืฆืคื™ืŸ ืืช GNU/Linux).

ืืœื’ื•ืจื™ืชื ื”ืฆืคื ื” ื‘ืจื™ืจืช ืžื—ื“ืœ <LUKS1: aes-xts-plain64, ืžืคืชื—: 256 ืกื™ื‘ื™ื•ืช, ื’ื™ื‘ื•ื‘ ื›ื•ืชืจืช LUKS: sha256, RNG: /dev/urandom> (ืชืœื•ื™ ื‘ื’ืจืกืช cryptsetup).

#ะŸั€ะพะฒะตั€ะบะฐ default-ะฐะปะณะพั€ะธั‚ะผะฐ ัˆะธั„ั€ะพะฒะฐะฝะธั
cryptsetup  --help #ัะฐะผะฐั ะฟะพัะปะตะดะฝัั ัั‚ั€ะพะบะฐ ะฒ ะฒั‹ะฒะพะดะต ั‚ะตั€ะผะธะฝะฐะปะฐ.

ืื ืื™ืŸ ืชืžื™ื›ืช ื—ื•ืžืจื” ืขื‘ื•ืจ AES ื‘ืžืขื‘ื“, ื”ื‘ื—ื™ืจื” ื”ื˜ื•ื‘ื” ื‘ื™ื•ืชืจ ืชื”ื™ื” ืœื™ืฆื•ืจ ืžื—ื™ืฆืช "LUKS-Twofish-XTS-ืžื—ื™ืฆื”" ืžื•ืจื—ื‘ืช.

B2.2. ื™ืฆื™ืจื” ืžืชืงื“ืžืช ืฉืœ "LUKS-Twofish-XTS-partition"

cryptsetup luksFormat /dev/sda7 -v -y -c twofish-xts-plain64 -s 512 -h sha512 -i 1500 --use-urandom

ืืคืฉืจื•ื™ื•ืช:
* luksFormat - ืืชื—ื•ืœ ืฉืœ ื›ื•ืชืจืช LUKS;
* /dev/sda7 ื”ื•ื ื”ื“ื™ืกืง ื”ืœื•ื’ื™ ื”ืžื•ืฆืคืŸ ื”ืขืชื™ื“ื™ ืฉืœืš;
* -v ืžื™ืœื•ืœื™ืช;
* -y ื‘ื™ื˜ื•ื™ ืกื™ืกืžื”;
* -c ื‘ื—ืจ ืืœื’ื•ืจื™ืชื ื”ืฆืคื ืช ื ืชื•ื ื™ื;
* ื’ื•ื“ืœ ืžืคืชื— ื”ื”ืฆืคื ื” -s;
* -h ืืœื’ื•ืจื™ืชื ื’ื™ื‘ื•ื‘/ืคื•ื ืงืฆื™ื™ืช ืงืจื™ืคื˜ื•, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-RNG (--ืฉื™ืžื•ืฉ-ืื•ืจื ื“ื•ื) ืœื™ืฆื•ืจ ืžืคืชื— ื”ืฆืคื ื”/ืคืขื ื•ื— ื™ื™ื—ื•ื“ื™ ืขื‘ื•ืจ ื›ื•ืชืจืช ื”ื“ื™ืกืง ื”ืœื•ื’ื™, ืžืคืชื— ื›ื•ืชืจืช ืžืฉื ื™ (XTS); ืžืคืชื— ืžืืกื˜ืจ ื™ื™ื—ื•ื“ื™ ื”ืžืื•ื—ืกืŸ ื‘ื›ื•ืชืจืช ื”ื“ื™ืกืง ื”ืžื•ืฆืคื ืช, ืžืคืชื— XTS ืžืฉื ื™, ื›ืœ ื”ืžื˜ื ื ืชื•ื ื™ื ื”ืืœื” ื•ืฉื’ืจืช ื”ืฆืคื ื” ืฉื‘ืืžืฆืขื•ืช ืžืคืชื— ื”ืžืืกื˜ืจ ื•ืžืคืชื— ื”-XTS ื”ืžืฉื ื™, ืžืฆืคื™ืŸ/ืžืคืขื ื— ื›ืœ ื ืชื•ื ื™ื ืขืœ ื”ืžื—ื™ืฆื” (ื—ื•ืฅ ืžื›ื•ืชืจืช ื”ืกืขื™ืฃ) ืžืื•ื—ืกืŸ ื‘-~3MB ื‘ืžื—ื™ืฆืช ื”ื“ื™ืกืง ื”ืงืฉื™ื— ืฉื ื‘ื—ืจื”.
* -i ืื™ื˜ืจืฆื™ื•ืช ื‘ืืœืคื™ื•ืช ืฉื ื™ื•ืช, ื‘ืžืงื•ื "ื›ืžื•ืช" (ืขื™ื›ื•ื‘ ื”ื–ืžืŸ ื‘ืขืช โ€‹โ€‹ืขื™ื‘ื•ื“ ื‘ื™ื˜ื•ื™ ื”ืกื™ืกืžื” ืžืฉืคื™ืข ืขืœ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ืขืœ ื”ื—ื•ื–ืง ื”ื”ืฆืคื ื” ืฉืœ ื”ืžืคืชื—ื•ืช). ื›ื“ื™ ืœืฉืžื•ืจ ืขืœ ืื™ื–ื•ืŸ ืฉืœ ื—ื•ื–ืง ืงืจื™ืคื˜ื•ื’ืจืคื™, ืขื ืกื™ืกืžื” ืคืฉื•ื˜ื” ื›ืžื• "ืจื•ืกื™ืช" ืืชื” ืฆืจื™ืš ืœื”ื’ื“ื™ืœ ืืช ื”ืขืจืš -(i); ืขื ืกื™ืกืžื” ืžื•ืจื›ื‘ืช ื›ืžื• "?8dฦฑob/รธfh" ื ื™ืชืŸ ืœื”ืงื˜ื™ืŸ ืืช ื”ืขืจืš.
* -ืฉื™ืžื•ืฉ ืžื—ื•ืœืœ ืžืกืคืจื™ื ืืงืจืื™ื™ื ืื•ืจื ื“ื•ืžืœื™ื™ื, ื™ื•ืฆืจ ืžืคืชื—ื•ืช ื•ืžืœื—.

ืœืื—ืจ ืžื™ืคื•ื™ ื”ืงื˜ืข sda7 > sda7_crypt (ื”ืคืขื•ืœื” ืžื”ื™ืจื”, ืžื›ื™ื•ื•ืŸ ืฉื ื•ืฆืจืช ื›ื•ืชืจืช ืžื•ืฆืคื ืช ืขื ~3 MB ืฉืœ ืžื˜ื ื ืชื•ื ื™ื ื•ื–ื” ื”ื›ืœ), ืขืœื™ืš ืœืขืฆื‘ ื•ืœื˜ืขื•ืŸ ืืช ืžืขืจื›ืช ื”ืงื‘ืฆื™ื sda7_crypt.

B2.3. ื”ืฉื•ื•ืื”

cryptsetup open /dev/sda7 sda7_crypt
#ะฒั‹ะฟะพะปะฝะตะฝะธะต ะดะฐะฝะฝะพะน ะบะพะผะฐะฝะดั‹ ะทะฐะฟั€ะฐัˆะธะฒะฐะตั‚ ะฒะฒะพะด ัะตะบั€ะตั‚ะฝะพะน ะฟะฐั€ะพะปัŒะฝะพะน ั„ั€ะฐะทั‹.

ืืคืฉืจื•ื™ื•ืช:
* ืคืชื•ื— - ื”ืชืื ืืช ื”ืงื˜ืข "ืขื ืฉื";
* /dev/sda7 -ื“ื™ืกืง ืœื•ื’ื™;
* sda7_crypt - ืžื™ืคื•ื™ ืฉืžื•ืช ื”ืžืฉืžืฉ ืœื˜ืขื™ื ืช ื”ืžื—ื™ืฆื” ื”ืžื•ืฆืคื ืช ืื• ืœืืชื—ืœ ืื•ืชื” ื›ืืฉืจ ืžืขืจื›ืช ื”ื”ืคืขืœื” ืžืืชื—ืœืช.

B2.4. ืขื™ืฆื•ื‘ ืžืขืจื›ืช ื”ืงื‘ืฆื™ื sda7_crypt ืœ-ext4. ื”ืจื›ื‘ืช ื“ื™ืกืง ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื”(ื”ืขืจื”: ืœื ืชื•ื›ืœ ืœืขื‘ื•ื“ ืขื ืžื—ื™ืฆื” ืžื•ืฆืคื ืช ื‘-Gparted)

#ั„ะพั€ะผะฐั‚ะธั€ะพะฒะฐะฝะธะต ะฑะปะพั‡ะฝะพะณะพ ัˆะธั„ั€ะพะฒะฐะฝะฝะพะณะพ ัƒัั‚ั€ะพะนัั‚ะฒะฐ
mkfs.ext4 -v -L DebSHIFR /dev/mapper/sda7_crypt 

ืืคืฉืจื•ื™ื•ืช:
* -v -ืžื™ืœื•ืœื™ื•ืช;
* -L - ืชื•ื•ื™ืช ื›ื•ื ืŸ (ื”ืžื•ืฆื’ืช ื‘ืกื™ื™ืจ ื‘ื™ืŸ ื›ื•ื ื ื™ื ืื—ืจื™ื).

ืœืื—ืจ ืžื›ืŸ, ืขืœื™ืš ืœืขืœื•ืช ืœืžืขืจื›ืช ืืช ื”ืชืงืŸ ื”ื—ืกื™ืžื” ื”ืžื•ืฆืคืŸ ื”ื•ื•ื™ืจื˜ื•ืืœื™ืช /dev/sda7_crypt

mount /dev/mapper/sda7_crypt /mnt

ืขื‘ื•ื“ื” ืขื ืงื‘ืฆื™ื ื‘ืชื™ืงื™ื™ื” /mnt ืชืฆืคื™ืŸ/ืคืขื ื— ืื•ื˜ื•ืžื˜ื™ืช ื ืชื•ื ื™ื ื‘-sda7.

ื™ื•ืชืจ ื ื•ื— ืœืžืคื•ืช ื•ืœื”ืขืœื•ืช ืืช ื”ืžื—ื™ืฆื” ื‘ืืงืกืคืœื•ืจืจ (nautilus/caja GUI), ื”ืžื—ื™ืฆื” ื›ื‘ืจ ืชื”ื™ื” ื‘ืจืฉื™ืžืช ื‘ื—ื™ืจืช ื”ื“ื™ืกืงื™ื, ื›ืœ ืฉื ื•ืชืจ ื”ื•ื ืœื”ื–ื™ืŸ ืืช ืžืฉืคื˜ ื”ืกื™ืกืžื” ืœืคืชื™ื—ื”/ืคืขื ื•ื— ืฉืœ ื”ื“ื™ืกืง. ื”ืฉื ื”ืžื•ืชืื ื™ื™ื‘ื—ืจ ืื•ื˜ื•ืžื˜ื™ืช ื•ืœื "sda7_crypt", ืืœื ืžืฉื”ื• ื›ืžื• /dev/mapper/Luks-xx-xx...

B2.5. ื’ื™ื‘ื•ื™ ื›ื•ืชืจื•ืช ื“ื™ืกืง (ืžื˜ื ื ืชื•ื ื™ื ืฉืœ ~3MB)ืื—ื“ ื”ื›ื™ ื”ืจื‘ื” ื—ืฉื•ื‘ ืคืขื•ืœื•ืช ืฉื™ืฉ ืœื‘ืฆืข ืœืœื ื“ื™ื—ื•ื™ - ืขื•ืชืง ื’ื™ื‘ื•ื™ ืฉืœ ื”ื›ื•ืชืจืช "sda7_crypt". ืื ืืชื” ืžื—ืœื™ืฃ/ืคื•ื’ืข ื‘ื›ื•ืชืจืช (ืœื“ื•ื’ืžื”, ื”ืชืงื ืช GRUB2 ืขืœ ืžื—ื™ืฆืช sda7 ื•ื›ื•'), ื”ื ืชื•ื ื™ื ื”ืžื•ืฆืคื ื™ื ื™ืื‘ื“ื• ืœื—ืœื•ื˜ื™ืŸ ืœืœื ื›ืœ ืืคืฉืจื•ืช ืœืฉื—ื–ืจ ืื•ืชื, ืžื›ื™ื•ื•ืŸ ืฉืื™ ืืคืฉืจ ื™ื”ื™ื” ืœื™ืฆื•ืจ ืžื—ื“ืฉ ืืช ืื•ืชื ืžืคืชื—ื•ืช; ื”ืžืคืชื—ื•ืช ื ื•ืฆืจื™ื ื‘ืื•ืคืŸ ื™ื™ื—ื•ื“ื™.

#ะ‘ัะบะฐะฟ ะทะฐะณะพะปะพะฒะบะฐ ั€ะฐะทะดะตะปะฐ
cryptsetup luksHeaderBackup --header-backup-file ~/ะ‘ัะบะฐะฟ_DebSHIFR /dev/sda7 

#ะ’ะพััั‚ะฐะฝะพะฒะปะตะฝะธะต ะทะฐะณะพะปะพะฒะบะฐ ั€ะฐะทะดะตะปะฐ
cryptsetup luksHeaderRestore --header-backup-file <file> <device>

ืืคืฉืจื•ื™ื•ืช:
* luksHeaderBackup โ€”header-backup-file -ืคืงื•ื“ื” ื’ื™ื‘ื•ื™;
* luksHeaderRestore โ€”ืคืงื•ื“ื” header-backup-file -restore;
* ~/Backup_DebSHIFR - ืงื•ื‘ืฅ ื’ื™ื‘ื•ื™;
* /dev/sda7 - ืžื—ื™ืฆื” ืฉื™ืฉ ืœืฉืžื•ืจ ืืช ืขื•ืชืง ื”ื’ื™ื‘ื•ื™ ืฉืœ ื›ื•ืชืจืช ื”ื“ื™ืกืง ื”ืžื•ืฆืคื ืช ืฉืœื”.
ื‘ืฉืœื‘ ื–ื” ื”ื•ืฉืœืžื” <ื™ืฆื™ืจื” ื•ืขืจื™ื›ื” ืฉืœ ื”ืžื—ื™ืฆื” ื”ืžื•ืฆืคื ืช>.

B3. ื”ืขื‘ืจืช GNU/Linux OS (sda4) ืœืžื—ื™ืฆื” ืžื•ืฆืคื ืช (sda7)

ืฆื•ืจ ืชื™ืงื™ื™ื” /mnt2 (ืฉื™ื ืœื‘ - ืื ื—ื ื• ืขื“ื™ื™ืŸ ืขื•ื‘ื“ื™ื ืขื usb ื—ื™, sda7_crypt ืžื•ืชืงืŸ ื‘-/mnt), ื•ื”ืขืœื” ืืช ื”-GNU/Linux ืฉืœื ื• ื‘-/mnt2, ืฉืฆืจื™ืš ืœื”ื™ื•ืช ืžื•ืฆืคืŸ.

mkdir /mnt2
mount /dev/sda4 /mnt2

ืื ื• ืžื‘ืฆืขื™ื ื”ืขื‘ืจื” ื ื›ื•ื ื” ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื‘ืืžืฆืขื•ืช ืชื•ื›ื ืช Rsync

rsync -avlxhHX --progress /mnt2/ /mnt

ืืคืฉืจื•ื™ื•ืช Rsync ืžืชื•ืืจื•ืช ื‘ืคืกืงื” E1.

ื™ืชืจ ืขืœ ื›ืŸ, ื—ื™ื™ื‘ ืื™ื—ื•ื™ ืžื—ื™ืฆืช ื“ื™ืกืง ืœื•ื’ื™ืช

e4defrag -c /mnt/ #ะฟะพัะปะต ะฟั€ะพะฒะตั€ะบะธ, e4defrag ะฒั‹ะดะฐัั‚, ั‡ั‚ะพ ัั‚ะตะฟะตะฝัŒ ะดะตั„ั€ะฐะณะผะตะฝั‚ะฐั†ะธะธ ั€ะฐะทะดะตะปะฐ~"0", ัั‚ะพ ะทะฐะฑะปัƒะถะดะตะฝะธะต, ะบะพั‚ะพั€ะพะต ะผะพะถะตั‚ ะฒะฐะผ ัั‚ะพะธั‚ัŒ ััƒั‰ะตัั‚ะฒะตะฝะฝะพะน ะฟะพั‚ะตั€ะธ ะฟั€ะพะธะทะฒะพะดะธั‚ะตะปัŒะฝะพัั‚ะธ!
e4defrag /mnt/ #ะฟั€ะพะฒะพะดะธะผ ะดะตั„ั€ะฐะณะผะตะฝั‚ะฐั†ะธัŽ ัˆะธั„ั€ะพะฒะฐะฝะฝะพะน GNU/Linux

ื”ืคื•ืš ืืช ื–ื” ืœื›ืœืœ: ืขืฉื” e4defrag ืขืœ GNU/LInux ืžื•ืฆืคืŸ ืžืขืช ืœืขืช ืื ื™ืฉ ืœืš ื“ื™ืกืง ืงืฉื™ื—.
ื”ื”ืขื‘ืจื” ื•ื”ืกื ื›ืจื•ืŸ [GNU/Linux > GNU/Linux-ืžื•ืฆืคืŸ] ื”ื•ืฉืœืžื• ื‘ืฉืœื‘ ื–ื”.

ื‘ 4. ื”ื’ื“ืจืช GNU/Linux ืขืœ ืžื—ื™ืฆืช sda7 ืžื•ืฆืคื ืช

ืœืื—ืจ ื”ืขื‘ืจืช ื‘ื”ืฆืœื—ื” ืืช ืžืขืจื›ืช ื”ื”ืคืขืœื” /dev/sda4 > /dev/sda7, ืขืœื™ืš ืœื”ื™ื›ื ืก ืœ-GNU/Linux ื‘ืžื—ื™ืฆื” ื”ืžื•ืฆืคื ืช ื•ืœื‘ืฆืข ืชืฆื•ืจื” ื ื•ืกืคืช (ื‘ืœื™ ืœืืชื—ืœ ืืช ื”ืžื—ืฉื‘) ื‘ื™ื—ืก ืœืžืขืจื›ืช ืžื•ืฆืคื ืช. ื›ืœื•ืžืจ, ืœื”ื™ื•ืช ื‘-usb ื—ื™, ืื‘ืœ ืœื‘ืฆืข ืคืงื•ื“ื•ืช "ื‘ื™ื—ืก ืœืฉื•ืจืฉ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืžื•ืฆืคื ืช". "chroot" ื™ื“ืžื” ืžืฆื‘ ื“ื•ืžื”. ื›ื“ื™ ืœืงื‘ืœ ื‘ืžื”ื™ืจื•ืช ืžื™ื“ืข ืขืœ ืื™ื–ื• ืžืขืจื›ืช ื”ืคืขืœื” ืืชื” ืขื•ื‘ื“ ื›ืขืช (ืžื•ืฆืคืŸ ืื• ืœื, ืžื›ื™ื•ื•ืŸ ืฉื”ื ืชื•ื ื™ื ื‘-sda4 ื•-sda7 ืžืกื•ื ื›ืจื ื™ื), ื‘ื˜ืœ ืกื ื›ืจื•ืŸ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื”. ืฆื•ืจ ื‘ืกืคืจื™ื•ืช ืฉื•ืจืฉ (sda4/sda7_crypt) ืงื•ื‘ืฆื™ ืกืžืŸ ืจื™ืงื™ื, ืœื“ื•ื’ืžื”, /mnt/encryptedOS ื•-/mnt2/decryptedOS. ื‘ื“ื•ืง ื‘ืžื”ื™ืจื•ืช ื‘ืื™ื–ื• ืžืขืจื›ืช ื”ืคืขืœื” ืืชื” ื ืžืฆื (ื›ื•ืœืœ ืœืขืชื™ื“):

ls /<Tab-Tab>

B4.1. "ืกื™ืžื•ืœืฆื™ื” ืฉืœ ื›ื ื™ืกื” ืœืžืขืจื›ืช ื”ืคืขืœื” ืžื•ืฆืคื ืช"

mount --bind /dev /mnt/dev
mount --bind /proc /mnt/proc
mount --bind /sys /mnt/sys
chroot /mnt

B4.2. ื•ื™ื“ื•ื ืฉื”ืขื‘ื•ื“ื” ืžืชื‘ืฆืขืช ืžื•ืœ ืžืขืจื›ืช ืžื•ืฆืคื ืช

ls /mnt<Tab-Tab> 
#ะธ ะฒะธะดะธะผ ั„ะฐะนะป "/ัˆะธั„ั€ะพะฒะฐะฝะฝะฐัะžะก"

history
#ะฒ ะฒั‹ะฒะพะดะต ั‚ะตั€ะผะธะฝะฐะปะฐ ะดะพะปะถะฝะฐ ะฟะพัะฒะธั‚ัŒัั ะธัั‚ะพั€ะธั ะบะพะผะฐะฝะด su ั€ะฐะฑะพั‡ะตะน ะžะก.

B4.3. ื™ืฆื™ืจืช/ื”ื’ื“ืจืช ื”ื—ืœืคื” ืžื•ืฆืคื ืช, ืขืจื™ื›ืช crypttab/fstabืžื›ื™ื•ื•ืŸ ืฉืงื•ื‘ืฅ ื”ื”ื—ืœืคื” ืžืขื•ืฆื‘ ื‘ื›ืœ ืคืขื ืฉืžืขืจื›ืช ื”ื”ืคืขืœื” ืžืชื—ื™ืœื”, ืื™ืŸ ื”ื’ื™ื•ืŸ ืœื™ืฆื•ืจ ื•ืœืžืคื•ืช ืืช ื”ื”ื—ืœืคื” ืœื“ื™ืกืง ืœื•ื’ื™ ื›ืขืช, ื•ืœื”ืงืœื™ื“ ืคืงื•ื“ื•ืช ื›ืžื• ื‘ืคืกืงื” B2.2. ืขื‘ื•ืจ Swap, ืžืคืชื—ื•ืช ื”ื”ืฆืคื ื” ื”ื–ืžื ื™ื™ื ืฉืœื• ื™ื•ืคืงื• ืื•ื˜ื•ืžื˜ื™ืช ื‘ื›ืœ ื”ืชื—ืœื”. ืžื—ื–ื•ืจ ื—ื™ื™ื ืฉืœ ืžืคืชื—ื•ืช ื”ื—ืœืคื”: ื‘ื™ื˜ื•ืœ/ืคื™ืจื•ืง ืžื—ื™ืฆืช ื”ื—ืœืคื” (+ื ื™ืงื•ื™ ื–ื™ื›ืจื•ืŸ RAM); ืื• ื”ืคืขืœ ืžื—ื“ืฉ ืืช ืžืขืจื›ืช ื”ื”ืคืขืœื”. ื”ื’ื“ืจืช swap, ืคืชื™ื—ืช ื”ืงื•ื‘ืฅ ื”ืื—ืจืื™ ืขืœ ื”ืชืฆื•ืจื” ืฉืœ ืžื›ืฉื™ืจื™ื ืžื•ืฆืคื ื™ื ื‘ืœื•ืง (ืื ืœื•ื’ื™ ืœืงื•ื‘ืฅ fstab, ืื‘ืœ ืื—ืจืื™ ืขืœ ื”ืงืจื™ืคื˜ื•).

nano /etc/crypttab 

ืื ื—ื ื• ืขื•ืจื›ื™ื

#"ืฉื ื™ืขื“" "ืžื›ืฉื™ืจ ืžืงื•ืจ" "ืงื•ื‘ืฅ ืžืคืชื—" "ืืคืฉืจื•ื™ื•ืช"
swap /dev/sda8 /dev/urandom swap,cipher=twofish-xts-plain64,size=512,hash=sha512

ืืคืฉืจื•ื™ื•ืช
* swap - ืฉื ืžืžื•ืคื” ื‘ืขืช ื”ืฆืคื ืช /dev/mapper/swap.
* /dev/sda8 - ื”ืฉืชืžืฉ ื‘ืžื—ื™ืฆื” ื”ืœื•ื’ื™ืช ืฉืœืš ืœื”ื—ืœืคื”.
* /dev/urandom - ืžื—ื•ืœืœ ืžืคืชื—ื•ืช ื”ืฆืคื ื” ืืงืจืื™ื™ื ืœื”ื—ืœืคื” (ืขื ื›ืœ ืืชื—ื•ืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ื—ื“ืฉื”, ื ื•ืฆืจื™ื ืžืคืชื—ื•ืช ื—ื“ืฉื™ื). ื”ืžื—ื•ืœืœ /dev/urandom ื”ื•ื ืคื—ื•ืช ืืงืจืื™ ืž-/dev/random, ืื—ืจื™ ื”ื›ืœ /dev/random ืžืฉืžืฉ ื›ืืฉืจ ืขื•ื‘ื“ื™ื ื‘ื ืกื™ื‘ื•ืช ืคืจื ื•ืื™ื“ื™ื•ืช ืžืกื•ื›ื ื•ืช. ื‘ืขืช ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื”, /dev/random ืžืื˜ ืืช ื”ื˜ืขื™ื ื” ืœืžืฉืš ืžืกืคืจ ื“ืงื•ืช ยฑ (ืจืื” systemd-analyze).
* swap,cipher=twofish-xts-plain64,size=512,hash=sha512: -ื”ืžื—ื™ืฆื” ื™ื•ื“ืขืช ืฉื”ื™ื swap ื•ื”ื™ื ืžืขื•ืฆื‘ืช "ื‘ื”ืชืื"; ืืœื’ื•ืจื™ืชื ื”ืฆืคื ื”.

#ะžั‚ะบั€ั‹ะฒะฐะตะผ ะธ ะฟั€ะฐะฒะธะผ fstab
nano /etc/fstab

ืื ื—ื ื• ืขื•ืจื›ื™ื

ื”ื—ืœืคื” # ื”ื•ืคืขืœื” / dev / sda8 ื‘ืžื”ืœืš ื”ื”ืชืงื ื”
/dev/mapper/swap none swap sw 0 0

/dev/mapper/swap ื”ื•ื ื”ืฉื ืฉื”ื•ื’ื“ืจ ื‘-crypttab.

ื”ื—ืœืคื” ืžื•ืฆืคื ืช ื—ืœื•ืคื™ืช
ืื ืžืกื™ื‘ื” ื›ืœืฉื”ื™ ืื™ื ืš ืจื•ืฆื” ืœื•ื•ืชืจ ืขืœ ืžื—ื™ืฆื” ืฉืœืžื” ืขื‘ื•ืจ ืงื•ื‘ืฅ swap, ืื– ืืชื” ื™ื›ื•ืœ ืœืงื—ืช ืžืกืœื•ืœ ื—ืœื•ืคื™ ื•ื˜ื•ื‘ ื™ื•ืชืจ: ื™ืฆื™ืจืช ืงื•ื‘ืฅ swap ื‘ืงื•ื‘ืฅ ืขืœ ืžื—ื™ืฆื” ืžื•ืฆืคื ืช ืขื ืžืขืจื›ืช ื”ื”ืคืขืœื”.

fallocate -l 3G /swap #ัะพะทะดะฐะฝะธะต ั„ะฐะนะปะฐ ั€ะฐะทะผะตั€ะพะผ 3ะ“ะฑ (ะฟะพั‡ั‚ะธ ะผะณะฝะพะฒะตะฝะฝะฐั ะพะฟะตั€ะฐั†ะธั)
chmod 600 /swap #ะฝะฐัั‚ั€ะพะนะบะฐ ะฟั€ะฐะฒ
mkswap /swap #ะธะท ั„ะฐะนะปะฐ ัะพะทะดะฐั‘ะผ ั„ะฐะนะป ะฟะพะดะบะฐั‡ะบะธ
swapon /swap #ะฒะบะปัŽั‡ะฐะตะผ ะฝะฐัˆ swap
free -m #ะฟั€ะพะฒะตั€ัะตะผ, ั‡ั‚ะพ ั„ะฐะนะป ะฟะพะดะบะฐั‡ะบะธ ะฐะบั‚ะธะฒะธั€ะพะฒะฐะฝ ะธ ั€ะฐะฑะพั‚ะฐะตั‚
printf "/swap none swap sw 0 0" >> /etc/fstab #ะฟั€ะธ ะฝะตะพะฑั…ะพะดะธะผะพัั‚ะธ ะฟะพัะปะต ะฟะตั€ะตะทะฐะณั€ัƒะทะบะธ swap ะฑัƒะดะตั‚ ะฟะพัั‚ะพัะฝะฝั‹ะน

ื”ื’ื“ืจืช ื”ื—ืœืคืช ื”ืžื—ื™ืฆื” ื”ื•ืฉืœืžื”.

B4.4. ื”ื’ื“ืจืช GNU/Linux ืžื•ืฆืคืŸ (ืขืจื™ื›ืช ืงื‘ืฆื™ crypttab/fstab)ื”ืงื•ื‘ืฅ /etc/crypttab, ื›ืคื™ ืฉื ื›ืชื‘ ืœืขื™ืœ, ืžืชืืจ ื”ืชืงื ื™ ื‘ืœื•ืง ืžื•ืฆืคื ื™ื ื”ืžื•ื’ื“ืจื™ื ื‘ืžื”ืœืš ืืชื—ื•ืœ ื”ืžืขืจื›ืช.

#ะฟั€ะฐะฒะธะผ /etc/crypttab 
nano /etc/crypttab 

ืื ื”ืชืืžืช ืœืงื˜ืข sda7>sda7_crypt ื›ืžื• ื‘ืคืกืงื” B2.1

# "ืฉื ื™ืขื“" "ืžื›ืฉื™ืจ ืžืงื•ืจ" "ืงื•ื‘ืฅ ืžืคืชื—" "ืืคืฉืจื•ื™ื•ืช"
sda7_crypt UUID=81048598-5bb9-4a53-af92-f3f9e709e2f2 none luks

ืื ื”ืชืืžืช ืœืงื˜ืข sda7>sda7_crypt ื›ืžื• ื‘ืคืกืงื” B2.2

# "ืฉื ื™ืขื“" "ืžื›ืฉื™ืจ ืžืงื•ืจ" "ืงื•ื‘ืฅ ืžืคืชื—" "ืืคืฉืจื•ื™ื•ืช"
sda7_crypt UUID=81048598-5bb9-4a53-af92-f3f9e709e2f2 none cipher=twofish-xts-plain64,size=512,hash=sha512

ืื ื”ืชืืžืช ืœืงื˜ืข sda7>sda7_crypt ื›ืžื• ื‘ืกืขื™ืฃ B2.1 ืื• B2.2, ืืš ืื™ื ืš ืจื•ืฆื” ืœื”ื–ื™ืŸ ืžื—ื“ืฉ ืืช ื”ืกื™ืกืžื” ื›ื“ื™ ืœืคืชื•ื— ื•ืœืืชื—ืœ ืืช ืžืขืจื›ืช ื”ื”ืคืขืœื”, ืื– ื‘ืžืงื•ื ื”ืกื™ืกืžื” ืชื•ื›ืœ ืœื”ื—ืœื™ืฃ ืžืคืชื— ืกื•ื“ื™/ืงื•ื‘ืฅ ืืงืจืื™

# "ืฉื ื™ืขื“" "ืžื›ืฉื™ืจ ืžืงื•ืจ" "ืงื•ื‘ืฅ ืžืคืชื—" "ืืคืฉืจื•ื™ื•ืช"
sda7_crypt UUID=81048598-5bb9-4a53-af92-f3f9e709e2f2 /etc/skey luks

ืชื™ืื•ืจ
* ืื™ืŸ - ืžื“ื•ื•ื— ื›ื™ ื‘ืขืช ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ื ื“ืจืฉืช ื”ื–ื ืช ื‘ื™ื˜ื•ื™ ืกื™ืกืžื” ืกื•ื“ื™ ื›ื“ื™ ืœื‘ื˜ืœ ืืช ื ืขื™ืœืช ื”ืฉื•ืจืฉ.
* UUID - ืžื–ื”ื” ืžื—ื™ืฆื”. ื›ื“ื™ ืœื‘ืจืจ ืืช ืชืขื•ื“ืช ื”ื–ื”ื•ืช ืฉืœืš, ื”ืงืœื“ ื‘ื˜ืจืžื™ื ืœ (ืชื–ื›ื•ืจืช ืฉืžื–ืžืŸ ื–ื” ื•ืื™ืœืš, ืืชื” ืขื•ื‘ื“ ื‘ื˜ืจืžื™ื ืœ ื‘ืกื‘ื™ื‘ืช chroot, ื•ืœื ื‘ืžืกื•ืฃ usb ื—ื™ ืื—ืจ).

fdisk -l #ะฟั€ะพะฒะตั€ะบะฐ ะฒัะตั… ั€ะฐะทะดะตะปะพะฒ
blkid #ะดะพะปะถะฝะพ ะฑั‹ั‚ัŒ ั‡ั‚ะพ-ั‚ะพ ะฟะพะดะพะฑะฝะพะต 

/dev/sda7: UUID=ยซ81048598-5bb9-4a53-af92-f3f9e709e2f2ยป TYPE=ยซcrypto_LUKSยป PARTUUID=ยซ0332d73c-07ยป
/dev/mapper/sda7_crypt: LABEL=ยซDebSHIFRยป UUID=ยซ382111a2-f993-403c-aa2e-292b5eac4780ยป TYPE=ยซext4ยป

ื”ืฉื•ืจื” ื”ื–ื• ื’ืœื•ื™ื” ื›ืืฉืจ ืžื‘ืงืฉื™ื blkid ืžืžืกื•ืฃ ื”-USB ื”ื—ื™ ืขื sda7_crypt ืžื•ืชืงืŸ).
ืืชื” ืœื•ืงื— ืืช ื”-UUID ืžื”-sdaX ืฉืœืš (ืœื sdaX_crypt!, UUID sdaX_crypt - ื™ื™ืฉืืจ ืื•ื˜ื•ืžื˜ื™ืช ื‘ืขืช ื™ืฆื™ืจืช ื”ืชืฆื•ืจื” grub.cfg).
* cipher=twofish-xts-plain64,size=512,hash=sha512 -luks ื”ืฆืคื ื” ื‘ืžืฆื‘ ืžืชืงื“ื.
* /etc/skey - ืงื•ื‘ืฅ ืžืคืชื— ืกื•ื“ื™, ื”ืžื•ื›ื ืก ืื•ื˜ื•ืžื˜ื™ืช ื›ื“ื™ ืœื‘ื˜ืœ ืืช ื ืขื™ืœืช ื”ืืชื—ื•ืœ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” (ื‘ืžืงื•ื ืœื”ื–ื™ืŸ ืืช ื”ืกื™ืกืžื” ื”ืฉืœื™ืฉื™ืช). ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ื›ืœ ืงื•ื‘ืฅ ืฉืœ ืขื“ 8MB, ืื‘ืœ ื”ื ืชื•ื ื™ื ื™ื™ืงืจืื• <1MB.

#ะกะพะทะดะฐะฝะธะต "ะณะตะฝะตั€ะฐั†ะธั" ัะปัƒั‡ะฐะนะฝะพะณะพ ั„ะฐะนะปะฐ <ัะตะบั€ะตั‚ะฝะพะณะพ ะบะปัŽั‡ะฐ> ั€ะฐะทะผะตั€ะพะผ 691ะฑ.
head -c 691 /dev/urandom > /etc/skey

#ะ”ะพะฑะฐะฒะปะตะฝะธะต ัะตะบั€ะตั‚ะฝะพะณะพ ะบะปัŽั‡ะฐ (691ะฑ) ะฒ 7-ะน ัะปะพั‚ ะทะฐะณะพะปะพะฒะบะฐ luks
cryptsetup luksAddKey --key-slot 7 /dev/sda7 /etc/skey

#ะŸั€ะพะฒะตั€ะบะฐ ัะปะพั‚ะพะฒ "ะฟะฐั€ะพะปะธ/ะบะปัŽั‡ะธ luks-ั€ะฐะทะดะตะปะฐ"
cryptsetup luksDump /dev/sda7 

ื–ื” ื™ื™ืจืื” ื‘ืขืจืš ื›ืš:

(ืขืฉื” ื–ืืช ื‘ืขืฆืžืš ื•ืชืจืื” ื‘ืขืฆืžืš).

cryptsetup luksKillSlot /dev/sda7 7 #ัƒะดะฐะปะตะฝะธะต ะบะปัŽั‡ะฐ/ะฟะฐั€ะพะปั ะธะท 7 ัะปะพั‚ะฐ

/etc/fstab ืžื›ื™ืœ ืžื™ื“ืข ืชื™ืื•ืจื™ ืขืœ ืžืขืจื›ื•ืช ืงื‘ืฆื™ื ืฉื•ื ื•ืช.

#ะŸั€ะฐะฒะธะผ /etc/fstab
nano /etc/fstab

# "ืžืขืจื›ืช ืงื‘ืฆื™ื" "ื ืงื•ื“ืช ื”ืจื›ื‘ื”" "ื”ืงืœื“" "ืืคืฉืจื•ื™ื•ืช" "dump" "ืžืขื‘ืจ"
# / ื”ื™ื” ื‘- / dev / sda7 ื‘ืžื”ืœืš ื”ื”ืชืงื ื”
/dev/mapper/sda7_crypt / ext4 errors=remount-ro 0 1

ืื•ึนืคึผึฐืฆึดื™ึธื”
* /dev/mapper/sda7_crypt - ืฉื ื”ืžื™ืคื•ื™ sda7>sda7_crypt, ืฉืฆื•ื™ืŸ ื‘ืงื•ื‘ืฅ /etc/crypttab.
ื”ื’ื“ืจืช crypttab/fstab ื”ื•ืฉืœืžื”.

B4.5. ืขืจื™ื›ืช ืงื‘ืฆื™ ืชืฆื•ืจื”. ืจื’ืข ืžืคืชื—B4.5.1. ืขืจื™ื›ืช ื”ืชืฆื•ืจื” /etc/initramfs-tools/conf.d/resume

#ะ•ัะปะธ ัƒ ะฒะฐั ั€ะฐะฝะตะต ะฑั‹ะป ะฐะบั‚ะธะฒะธั€ะพะฒะฐะฝ swap ั€ะฐะทะดะตะป, ะพั‚ะบะปัŽั‡ะธั‚ะต ะตะณะพ. 
nano /etc/initramfs-tools/conf.d/resume

ื•ืœื”ื’ื™ื‘ (ืื ืงื™ื™ื) ืฉื•ืจื” "#" "ืงื•ืจื•ืช ื—ื™ื™ื". ื”ืงื•ื‘ืฅ ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืจื™ืง ืœื—ืœื•ื˜ื™ืŸ.

B4.5.2. ืขืจื™ื›ืช ื”ืชืฆื•ืจื” /etc/initramfs-tools/conf.d/cryptsetup

nano /etc/initramfs-tools/conf.d/cryptsetup

ืฆืจื™ืš ืœื”ืชืื™ื

# /etc/initramfs-tools/conf.d/cryptsetup
CRYPTSETUP=ื›ืŸ
ื™ื™ืฆื CRYPTSETUP

B4.5.3. ืขืจื™ื›ืช ื”ืชืฆื•ืจื” /etc/default/grub (ืชืฆื•ืจื” ื–ื• ืื—ืจืื™ืช ืœื™ื›ื•ืœืช ืœื™ืฆื•ืจ grub.cfg ื‘ืขืช ืขื‘ื•ื“ื” ืขื /boot ืžื•ืฆืคืŸ)

nano /etc/default/grub

ื”ื•ืกืฃ ืืช ื”ืฉื•ืจื” "GRUB_ENABLE_CRYPTODISK=y"
ื”ืขืจืš 'y', grub-mkconfig ื•-grub-install ื™ื‘ื“ืงื• ื›ื•ื ื ื™ื ืžื•ืฆืคื ื™ื ื•ื™ืคื™ืงื• ืคืงื•ื“ื•ืช ื ื•ืกืคื•ืช ื”ื“ืจื•ืฉื•ืช ื›ื“ื™ ืœื’ืฉืช ืืœื™ื”ื ื‘ื–ืžืŸ ื”ืืชื—ื•ืœ (ืื™ื ืกืžื•ื“ืก ).
ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื“ืžื™ื•ืŸ

GRUB_DEFAULT = 0
GRUB_TIMEOUT = 1
GRUB_DISTRIBUTOR=`lsb_release -i -s 2> /dev/null || echo Debian`
GRUB_CMDLINE_LINUX_DEFAULT="acpi_backlight=ืกืคืง"
GRUB_CMDLINE_LINUX="ื ืชื– ืฉืงื˜ ืœืœื ื”ืชืงื ื” ืื•ื˜ื•ืžื˜ื™ืช"
GRUB_ENABLE_CRYPTODISK=y

B4.5.4. ืขืจื™ื›ืช ื”ืชืฆื•ืจื” /etc/cryptsetup-initramfs/conf-hook

nano /etc/cryptsetup-initramfs/conf-hook

ืœื‘ื“ื•ืง ืฉื”ืงื• ื”ื’ื™ื‘ ืขืœ <#>.
ื‘ืขืชื™ื“ (ื•ื’ื ืขื›ืฉื™ื•, ืœืคืจืžื˜ืจ ื”ื–ื” ืœื ืชื”ื™ื” ืฉื•ื ืžืฉืžืขื•ืช, ืื‘ืœ ืœืคืขืžื™ื ื”ื•ื ืžืคืจื™ืข ืœืขื“ื›ื•ืŸ ื”ืชืžื•ื ื” initrd.img).

B4.5.5. ืขืจื™ื›ืช ื”ืชืฆื•ืจื” /etc/cryptsetup-initramfs/conf-hook

nano /etc/cryptsetup-initramfs/conf-hook

ื”ื•ืกืฃ

KEYFILE_PATTERN="/etc/skey"
UMASK=0077

ื–ื” ืชืืจื•ื– ืืช ื”ืžืคืชื— ื”ืกื•ื“ื™ "Skey" ืœืชื•ืš initrd.img, ื”ืžืคืชื— ื ื—ื•ืฅ ื›ื“ื™ ืœื‘ื˜ืœ ืืช ื ืขื™ืœืช ื”ืฉื•ืจืฉ ื›ืืฉืจ ืžืขืจื›ืช ื”ื”ืคืขืœื” ืžืืชื—ืœืช (ืื ืื™ื ืš ืจื•ืฆื” ืœื”ื–ื™ืŸ ืืช ื”ืกื™ืกืžื” ืฉื•ื‘, ืžืงืฉ "ืžืคืชื—" ืžื•ื—ืœืฃ ืœืจื›ื‘).

B4.6. ืขื“ื›ืŸ /boot/initrd.img [ื’ืจืกื”]ื›ื“ื™ ืœืืจื•ื– ืืช ื”ืžืคืชื— ื”ืกื•ื“ื™ ืœืชื•ืš initrd.img ื•ืœื”ื—ื™ืœ ืชื™ืงื•ื ื™ cryptsetup, ืขื“ื›ืŸ ืืช ื”ืชืžื•ื ื”

update-initramfs -u -k all

ื‘ืขืช ืขื“ื›ื•ืŸ initrd.img (ื›ืžื• ืฉืื•ืžืจื™ื "ื–ื” ืืคืฉืจื™, ืื‘ืœ ื–ื” ืœื ื‘ื˜ื•ื—") ื™ื•ืคื™ืขื• ืื–ื”ืจื•ืช ื”ืงืฉื•ืจื•ืช ืœ-cryptsetup, ืื•, ืœืžืฉืœ, ื”ื•ื“ืขื” ืขืœ ืื•ื‘ื“ืŸ ืžื•ื“ื•ืœื™ Nvidia - ื–ื” ื ื•ืจืžืœื™. ืœืื—ืจ ืขื“ื›ื•ืŸ ื”ืงื•ื‘ืฅ, ื‘ื“ืงื• ืฉื”ื•ื ืื›ืŸ ืขื•ื“ื›ืŸ, ืจืื• ืืช ื”ืฉืขื” (ื‘ื™ื—ืก ืœืกื‘ื™ื‘ืช chroot./boot/initrd.img). ืื–ื”ืจื”! ืœืคื ื™ [update-initramfs -u -k all] ื”ืงืคื“ ืœื‘ื“ื•ืง ืฉ-cryptsetup ืคืชื•ื— /dev/sda7 sda7_crypt - ื–ื” ื”ืฉื ืฉืžื•ืคื™ืข ื‘-/etc/crypttab, ืื—ืจืช ืœืื—ืจ ืืชื—ื•ืœ ืžื—ื“ืฉ ืชื”ื™ื” ืฉื’ื™ืืช busybox)
ื‘ืฉืœื‘ ื–ื”, ื”ื’ื“ืจืช ืงื‘ืฆื™ ื”ืชืฆื•ืจื” ื”ื•ืฉืœืžื”.

[ื’] ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืฉืœ GRUB2/Protection

C1. ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืคืจืžื˜ ืืช ื”ืžื—ื™ืฆื” ื”ื™ื™ืขื•ื“ื™ืช ืขื‘ื•ืจ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ (ืžื—ื™ืฆื” ืฆืจื™ื›ื” ืœืคื—ื•ืช 20MB)

mkfs.ext4 -v -L GRUB2 /dev/sda6

C2. ื”ืจ /dev/sda6 ืœ-/mntืื– ืื ื—ื ื• ืขื•ื‘ื“ื™ื ื‘-chroot, ืื– ืœื ืชื”ื™ื” ืกืคืจื™ื™ืช /mnt2 ื‘ืฉื•ืจืฉ, ื•ื”ืชื™ืงื™ื” /mnt ืชื”ื™ื” ืจื™ืงื”.
ื”ืจื›ื‘ ืืช ืžื—ื™ืฆืช GRUB2

mount /dev/sda6 /mnt

ืื ืžื•ืชืงื ืช ืืฆืœืš ื’ืจืกื” ื™ืฉื ื” ื™ื•ืชืจ ืฉืœ GRUB2, ื‘ืกืคืจื™ื™ืช /mnt/boot/grub/i-386-pc (ืคืœื˜ืคื•ืจืžื” ืื—ืจืช ืืคืฉืจื™ืช, ืœืžืฉืœ, ืœื "i386-pc") ืœืœื ืžื•ื“ื•ืœื™ ืงืจื™ืคื˜ื• (ื‘ืงื™ืฆื•ืจ, ื”ืชื™ืงื™ื” ืฆืจื™ื›ื” ืœื”ื›ื™ืœ ืžื•ื“ื•ืœื™ื, ื›ื•ืœืœ .mod: cryptodisk; luks; gcry_twofish; gcry_sha512; signature_test.mod), ื‘ืžืงืจื” ื–ื”, ื™ืฉ ืœื ืขืจ ืืช GRUB2.

apt-get update
apt-get install grub2 

ื—ึธืฉืื•ึผื‘! ื‘ืขืช ืขื“ื›ื•ืŸ ื—ื‘ื™ืœืช GRUB2 ืžื”ืžืื’ืจ, ื›ืืฉืจ ื ืฉืืœ "ืขืœ ื‘ื—ื™ืจื”" ื”ื™ื›ืŸ ืœื”ืชืงื™ืŸ ืืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ, ืขืœื™ืš ืœืกืจื‘ ืœื”ืชืงื ื” (ืกื™ื‘ื” - ื ืกื” ืœื”ืชืงื™ืŸ GRUB2 - ื‘-"MBR" ืื• ื‘-USB ื—ื™). ืื—ืจืช ืชื’ืจื•ื ื ื–ืง ืœื›ื•ืชืจืช/ืžื˜ืขืŸ VeraCrypt. ืœืื—ืจ ืขื“ื›ื•ืŸ ื—ื‘ื™ืœื•ืช GRUB2 ื•ื‘ื™ื˜ื•ืœ ื”ื”ืชืงื ื”, ื™ืฉ ืœื”ืชืงื™ืŸ ืืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ื‘ืื•ืคืŸ ื™ื“ื ื™ ื‘ื“ื™ืกืง ื”ืœื•ื’ื™, ื•ืœื ื‘-MBR. ืื ืœืžืื’ืจ ืฉืœืš ื™ืฉ ื’ืจืกื” ืžื™ื•ืฉื ืช ืฉืœ GRUB2, ื ืกื” ืขื“ื›ื•ืŸ ื–ื” ืžื”ืืชืจ ื”ืจืฉืžื™ - ืœื ื‘ื“ืงืชื™ ืืช ื–ื” (ืขื‘ื“ ืขื ืžื˜ืขื ื™ ื”ืืชื—ื•ืœ ื”ืขื“ื›ื ื™ื™ื ื‘ื™ื•ืชืจ ืฉืœ GRUB 2.02 ~BetaX).

C3. ื”ืชืงื ืช GRUB2 ืœืžื—ื™ืฆื” ืžื•ืจื—ื‘ืช [sda6]ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ืœืš ืžื—ื™ืฆื” ืžื•ืชืงื ืช [ืคืจื™ื˜ C.2]

grub-install --force --root-directory=/mnt /dev/sda6

ืืคืฉืจื•ื™ื•ืช
* โ€”force - ื”ืชืงื ื” ืฉืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ, ืขืงื™ืคืช ื›ืœ ื”ืื–ื”ืจื•ืช ืฉืงื™ื™ืžื•ืช ื›ืžืขื˜ ืชืžื™ื“ ื•ื—ื•ืกืžื•ืช ื”ืชืงื ื” (ื“ื’ืœ ื ื“ืจืฉ).
* --root-directory - ื”ืชืงื ืช ืกืคืจื™ื” ืœืฉื•ืจืฉ sda6.
* /dev/sda6 - ืžื—ื™ืฆืช ื”-sdaะฅ ืฉืœืš (ืืœ ืชืคืกืคืก ืืช ื”<space> ื‘ื™ืŸ /mnt /dev/sda6).

C4. ื™ืฆื™ืจืช ืงื•ื‘ืฅ ืชืฆื•ืจื” [grub.cfg]ืชืฉื›ื— ืžื”ืคืงื•ื“ื” "update-grub2" ื•ื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” ืœื™ืฆื™ืจืช ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ื”ืžืœื

grub-mkconfig -o /mnt/boot/grub/grub.cfg

ืœืื—ืจ ื”ืฉืœืžืช ื”ื™ืฆื™ืจื”/ืขื“ื›ื•ืŸ ืฉืœ ืงื•ื‘ืฅ grub.cfg, ืžืกื•ืฃ ื”ืคืœื˜ ืฆืจื™ืš ืœื”ื›ื™ืœ ืฉื•ืจื•ืช ืขื ืžืขืจื›ืช ื”ื”ืคืขืœื” ืฉื ืžืฆืืช ื‘ื“ื™ืกืง ("grub-mkconfig" ื›ื ืจืื” ื™ืžืฆื ื•ื™ืืกื•ืฃ ืืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ืž-USB ื—ื™, ืื ื™ืฉ ืœืš ื›ื•ื ืŸ ื”ื‘ื–ืง ืจื‘ ืืชื—ื•ืœ ืขื Windows 10 ื•ื—ื‘ื•ืจื” ืฉืœ ื”ืคืฆื•ืช ื—ื™ื•ืช - ื–ื” ื ื•ืจืžืœื™). ืื ื”ื˜ืจืžื™ื ืœ "ืจื™ืง" ื•ื”ืงื•ื‘ืฅ "grub.cfg" ืœื ื ื•ืฆืจ, ืื– ื–ื” ืื•ืชื• ืžืงืจื” ื›ืฉื™ืฉ ื‘ืื’ื™ื GRUB ื‘ืžืขืจื›ืช (ื•ื›ื›ืœ ื”ื ืจืื” ื”ืžืขืžื™ืก ืžืขื ืฃ ื”ื‘ื“ื™ืงื” ืฉืœ ื”ืžืื’ืจ), ื”ืชืงืŸ ืžื—ื“ืฉ GRUB2 ืžืžืงื•ืจื•ืช ืžื”ื™ืžื ื™ื.
ื”ื”ืชืงื ื” ืฉืœ "ืชืฆื•ืจื” ืคืฉื•ื˜ื”" ื•ื”ื’ื“ืจืช GRUB2 ื”ื•ืฉืœืžื•.

C5. ืžื‘ื—ืŸ ื”ื•ื›ื—ื” ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” GNU/Linux ืžื•ืฆืคื ืชืื ื• ืžืฉืœื™ืžื™ื ืืช ืžืฉื™ืžืช ื”ื”ืฆืคื ื” ื‘ืฆื•ืจื” ื ื›ื•ื ื”. ืขื•ื–ื‘ ื‘ื–ื”ื™ืจื•ืช ืืช GNU/Linux ื”ืžื•ืฆืคืŸ (ืฆื ืžืกื‘ื™ื‘ืช chroot).

umount -a #ั€ะฐะทะผะพะฝั‚ะธั€ะพะฒะฐะฝะธะต ะฒัะตั… ัะผะพะฝั‚ะธั€ะพะฒะฐะฝะฝั‹ั… ั€ะฐะทะดะตะปะพะฒ ัˆะธั„ั€ะพะฒะฐะฝะฝะพะน GNU/Linux
Ctrl+d #ะฒั‹ั…ะพะด ะธะท ัั€ะตะดั‹ chroot
umount /mnt/dev
umount /mnt/proc
umount /mnt/sys
umount -a #ั€ะฐะทะผะพะฝั‚ะธั€ะพะฒะฐะฝะธะต ะฒัะตั… ัะผะพะฝั‚ะธั€ะพะฒะฐะฝะฝั‹ั… ั€ะฐะทะดะตะปะพะฒ ะฝะฐ live usb
reboot

ืœืื—ืจ ืืชื—ื•ืœ ื”ืžื—ืฉื‘, ืžื˜ืขื™ืŸ ื”ืืชื—ื•ืœ ืฉืœ VeraCrypt ืืžื•ืจ ืœื”ื™ื˜ืขืŸ.
ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

*ื”ื–ื ืช ื”ืกื™ืกืžื” ืœืžื—ื™ืฆื” ื”ืคืขื™ืœื” ืชืชื—ื™ืœ ืœื˜ืขื•ืŸ ืืช Windows.
*ืœื—ื™ืฆื” ืขืœ ืžืงืฉ "Esc" ืชืขื‘ื™ืจ ืืช ื”ืฉืœื™ื˜ื” ืœ-GRUB2, ืื ืชื‘ื—ืจ ื‘-GNU/Linux ืžื•ืฆืคืŸ - ืชื™ื“ืจืฉ ืกื™ืกืžื” (sda7_crypt) ื›ื“ื™ ืœืคืชื•ื— ืืช /boot/initrd.img (ืื grub2 ื›ื•ืชื‘ ืืช uuid "ืœื ื ืžืฆื" - ื–ื” ื‘ืขื™ื” ืขื ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ grub2, ื™ืฉ ืœื”ืชืงื™ืŸ ืื•ืชื• ืžื—ื“ืฉ, ืœืžืฉืœ, ืžืกื ื™ืฃ ื‘ื“ื™ืงื”/ื™ืฆื™ื‘ ื•ื›ื•').
ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

*ื‘ื”ืชืื ืœืื•ืคืŸ ืฉื‘ื• ื”ื’ื“ืจืช ืืช ื”ืžืขืจื›ืช (ืจืื” ืกืขื™ืฃ B4.4/4.5), ืœืื—ืจ ื”ื–ื ืช ื”ืกื™ืกืžื” ื”ื ื›ื•ื ื” ื›ื“ื™ ืœืคืชื•ื— ืืช ืชืžื•ื ืช /boot/initrd.img, ืชื–ื“ืงืง ืœืกื™ืกืžื” ื›ื“ื™ ืœื˜ืขื•ืŸ ืืช ืœื™ื‘ืช ืžืขืจื›ืช ื”ื”ืคืขืœื”/ืฉื•ืจืฉ, ืื• ืืช ื”ืกื•ื“ ื”ืžืคืชื— ื™ื•ื—ืœืฃ ืื•ื˜ื•ืžื˜ื™ืช ื‘- "Skey", ืชื•ืš ื‘ื™ื˜ื•ืœ ื”ืฆื•ืจืš ืœื”ื–ื™ืŸ ืžื—ื“ืฉ ืืช ื‘ื™ื˜ื•ื™ ื”ืกื™ืกืžื”.
ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ
(ืžืกืš "ื”ื—ืœืคื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืžืคืชื— ืกื•ื“ื™").

*ืื– ื™ื‘ื•ื ื”ืชื”ืœื™ืš ื”ืžื•ื›ืจ ืฉืœ ื˜ืขื™ื ืช GNU/Linux ืขื ืื™ืžื•ืช ื—ืฉื‘ื•ืŸ ืžืฉืชืžืฉ.
ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

*ืœืื—ืจ ื”ืจืฉืืช ืžืฉืชืžืฉ ื•ื›ื ื™ืกื” ืœืžืขืจื›ืช ื”ื”ืคืขืœื”, ืขืœื™ืš ืœืขื“ื›ืŸ ืฉื•ื‘ ืืช /boot/initrd.img (ืจืื” B4.6).

update-initramfs -u -k all

ื•ื‘ืžืงืจื” ืฉืœ ืงื•ื•ื™ื ื ื•ืกืคื™ื ื‘ืชืคืจื™ื˜ GRUB2 (ืžืืกื•ืฃ OS-m ืขื usb ื—ื™) ืชื™ืคื˜ืจ ืžื”ื

mount /dev/sda6 /mnt
grub-mkconfig -o /mnt/boot/grub/grub.cfg

ืกื™ื›ื•ื ืžื”ื™ืจ ืฉืœ ื”ืฆืคื ืช ืžืขืจื›ืช GNU/Linux:

  • GNU/Linuxinux ืžื•ืฆืคืŸ ื‘ืžืœื•ืื”, ื›ื•ืœืœ /boot/kernel ื•-initrd;
  • ื”ืžืคืชื— ื”ืกื•ื“ื™ ืืจื•ื– ื‘-initrd.img;
  • ืชื›ื ื™ืช ื”ื”ืจืฉืื” ื”ื ื•ื›ื—ื™ืช (ื”ื–ื ืช ื”ืกื™ืกืžื” ื›ื“ื™ ืœืคืชื•ื— ืืช ื”-initrd; ืกื™ืกืžื”/ืžืคืชื— ืœืืชื—ื•ืœ ืžืขืจื›ืช ื”ื”ืคืขืœื”; ืกื™ืกืžื” ืœื”ืจืฉืืช ื—ืฉื‘ื•ืŸ Linux).

ื”ืฆืคื ืช ืžืขืจื›ืช "ืชืฆื•ืจืช GRUB2 ืคืฉื•ื˜ื”" ืฉืœ ืžื—ื™ืฆืช ื”ื‘ืœื•ืง ื”ื•ืฉืœืžื”.

C6. ืชืฆื•ืจืช GRUB2 ืžืชืงื“ืžืช. ื”ื’ื ืช ืžืืชื—ื•ืœ ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช + ื”ื’ื ืช ืื™ืžื•ืชGNU/Linux ืžื•ืฆืคืŸ ืœื—ืœื•ื˜ื™ืŸ, ืืš ืœื ื ื™ืชืŸ ืœื”ืฆืคื™ืŸ ืืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ - ืžืฆื‘ ื–ื” ืžื•ื›ืชื‘ ืขืœ ื™ื“ื™ ื”-BIOS. ืžืกื™ื‘ื” ื–ื•, ืืชื—ื•ืœ ืžื•ืฆืคืŸ ืžืฉื•ืจืฉืจ ืฉืœ GRUB2 ืื™ื ื• ืืคืฉืจื™, ืืš ืืชื—ื•ืœ ืžืฉื•ืจืฉืจ ืคืฉื•ื˜ ืืคืฉืจื™/ื–ืžื™ืŸ, ืืš ืžื ืงื•ื“ืช ืžื‘ื˜ ืื‘ื˜ื—ื” ืื™ืŸ ืฆื•ืจืš [ืจืื” ืค' ื•].
ืขื‘ื•ืจ GRUB2 ื”"ืคื’ื™ืข", ื”ืžืคืชื—ื™ื ื”ื˜ืžื™ืขื• ืืœื’ื•ืจื™ืชื ื”ื’ื ื” ืฉืœ ืžืืชื—ื•ืœ "ื—ืชื™ืžื”/ืื™ืžื•ืช".

  • ื›ืืฉืจ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืžื•ื’ืŸ ืขืœ ื™ื“ื™ "ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืžืฉืœื•", ืฉื™ื ื•ื™ ื—ื™ืฆื•ื ื™ ืฉืœ ืงื‘ืฆื™ื, ืื• ื ื™ืกื™ื•ืŸ ืœื˜ืขื•ืŸ ืžื•ื“ื•ืœื™ื ื ื•ืกืคื™ื ื‘ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ื”ื–ื”, ื™ื•ื‘ื™ืœื• ืœื—ืกื™ืžืช ืชื”ืœื™ืš ื”ืืชื—ื•ืœ.
  • ื‘ืขืช ื”ื’ื ื” ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ื‘ืืžืฆืขื•ืช ืื™ืžื•ืช, ืขืœ ืžื ืช ืœื‘ื—ื•ืจ ื˜ืขื™ื ืช ื”ืคืฆื”, ืื• ืœื”ื–ื™ืŸ ืคืงื•ื“ื•ืช ื ื•ืกืคื•ืช ื‘-CLI, ืชืฆื˜ืจืš ืœื”ื–ื™ืŸ ืืช ืคืจื˜ื™ ื”ื›ื ื™ืกื” ื•ื”ืกื™ืกืžื” ืฉืœ superuser-GRUB2.

C6.1. ื”ื’ื ื” ืขืœ ืื™ืžื•ืช ืžืืชื—ื•ืœื‘ื“ื•ืง ืฉืืชื” ืขื•ื‘ื“ ื‘ืžืกื•ืฃ ืขืœ ืžืขืจื›ืช ื”ืคืขืœื” ืžื•ืฆืคื ืช

ls /<Tab-Tab> #ะพะฑะฝะฐั€ัƒะถะธั‚ัŒ ั„ะฐะนะป-ะผะฐั€ะบะตั€

ืฆื•ืจ ืกื™ืกืžืช ืžืฉืชืžืฉ-ืขืœ ืœื”ืจืฉืื” ื‘-GRUB2

grub-mkpasswd-pbkdf2 #ะฒะฒะตะดะธั‚ะต/ะฟะพะฒั‚ะพั€ะธั‚ะต ะฟะฐั€ะพะปัŒ ััƒะฟะตั€ะฟะพะปัŒะทะพะฒะฐั‚ะตะปั. 

ืงื‘ืœ ืืช ื”-hash ืฉืœ ื”ืกื™ืกืžื”. ืžืฉื”ื• ื›ื–ื”

grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8

ื”ืจื›ื‘ ืืช ืžื—ื™ืฆืช GRUB

mount /dev/sda6 /mnt 

ืœืขืจื•ืš ืืช ื”ืชืฆื•ืจื”

nano -$ /mnt/boot/grub/grub.cfg 

ื‘ื“ื•ืง ื‘ื—ื™ืคื•ืฉ ื”ืงื‘ืฆื™ื ืฉืื™ืŸ ื“ื’ืœื™ื ื‘ืฉื•ื ืžืงื•ื ื‘-"grub.cfg" ("-unrestricted" "-user",
ืœื”ื•ืกื™ืฃ ืžืžืฉ ื‘ืกื•ืฃ (ืœืคื ื™ ื”ืฉื•ืจื” ### END /etc/grub.d/41_custom ###)
"set superusers="root"
password_pbkdf2 hash root."

ื–ื” ืฆืจื™ืš ืœื”ื™ื•ืช ืžืฉื”ื• ื›ื–ื”

# ืงื•ื‘ืฅ ื–ื” ืžืกืคืง ื“ืจืš ืงืœื” ืœื”ื•ืกื™ืฃ ืขืจื›ื™ ืชืคืจื™ื˜ ืžื•ืชืืžื™ื ืื™ืฉื™ืช. ืคืฉื•ื˜ ื”ืงืœื“ ืืช
# ืขืจื›ื™ ืชืคืจื™ื˜ ืฉื‘ืจืฆื•ื ืš ืœื”ื•ืกื™ืฃ ืœืื—ืจ ื”ืขืจื” ื–ื•. ื”ื™ื–ื”ืจ ืœื ืœืฉื ื•ืช
# ื”ืฉื•ืจื” 'ื–ื ื‘ exec' ืœืžืขืœื”.
### END /etc/grub.d/40_custom ###

### BEGIN /etc/grub.d/41_custom ###
if [ -f ${config_directory}/custom.cfg ]; ืœืื—ืจ ืžื›ืŸ
ืžืงื•ืจ ${config_directory}/custom.cfg
elif [ -z "${config_directory}" -a -f $prefix/custom.cfg ]; ืœืื—ืจ ืžื›ืŸ
ืžืงื•ืจ $prefix/custom.cfg;
fi
set superusers="root"
password_pbkdf2 root grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8
### END /etc/grub.d/41_custom ###
#

ืื ืืชื” ืžืฉืชืžืฉ ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื‘ืคืงื•ื“ื” "grub-mkconfig -o /mnt/boot/grub/grub.cfg" ื•ืื™ื ืš ืจื•ืฆื” ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘-grub.cfg ื‘ื›ืœ ืคืขื, ื”ื–ืŸ ืืช ื”ืฉื•ืจื•ืช ืœืขื™ืœ (ืกื™ืกืžืช ื›ื ื™ืกื”) ื‘ืกืงืจื™ืคื˜ ื”ืžืฉืชืžืฉ GRUB ื‘ืชื—ืชื™ืช

nano /etc/grub.d/41_custom 

ื—ืชื•ืœ <<EOF
set superusers="root"
password_pbkdf2 root grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8
EOF

ื‘ืขืช ื™ืฆื™ืจืช ื”ืชืฆื•ืจื” "grub-mkconfig -o /mnt/boot/grub/grub.cfg", ื”ืฉื•ืจื•ืช ื”ืื—ืจืื™ื•ืช ืœืื™ืžื•ืช ื™ืชื•ื•ืกืคื• ืื•ื˜ื•ืžื˜ื™ืช ืœ-grub.cfg.
ืฉืœื‘ ื–ื” ืžืฉืœื™ื ืืช ื”ื’ื“ืจืช ื”ืื™ืžื•ืช GRUB2.

C6.2. ื”ื’ื ืช ืžืืชื—ื•ืœ ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืชื”ื”ื ื—ื” ื”ื™ื ืฉื›ื‘ืจ ื™ืฉ ืœืš ืืช ืžืคืชื— ื”ื”ืฆืคื ื” ื”ืื™ืฉื™ ืฉืœืš ื‘-pgp (ืื• ืœื™ืฆื•ืจ ืžืคืชื— ื›ื–ื”). ืขืœ ื”ืžืขืจื›ืช ืœื”ื™ื•ืช ืžื•ืชืงื ืช ืชื•ื›ื ืช ื”ืฆืคื ื”: gnuPG; ืงืœืื•ืคื˜ืจื”/GPA; ืกื•ืกื•ืŸ ื™ื. ืชื•ื›ื ืช ืงืจื™ืคื˜ื• ืชืขืฉื” ืืช ื”ื—ื™ื™ื ืฉืœืš ื”ืจื‘ื” ื™ื•ืชืจ ืงืœื™ื ื‘ื›ืœ ื”ืขื ื™ื™ื ื™ื ื”ืืœื”. ืกื•ืก ื™ื - ื’ืจืกื” ื™ืฆื™ื‘ื” ืฉืœ ื”ื—ื‘ื™ืœื” 3.14.0 (ื’ืจืกืื•ืช ื’ื‘ื•ื”ื•ืช ื™ื•ืชืจ, ืœืžืฉืœ, V3.20, ืคื’ื•ืžื•ืช ื•ื™ืฉ ืœื”ืŸ ื‘ืื’ื™ื ืžืฉืžืขื•ืชื™ื™ื).

ื™ืฉ ืœื™ืฆื•ืจ/ืœื”ืคืขื™ืœ/ืœื”ื•ืกื™ืฃ ืืช ืžืคืชื— ื”-PGP ืจืง ื‘ืกื‘ื™ื‘ืช su!

ืฆื•ืจ ืžืคืชื— ื”ืฆืคื ื” ืื™ืฉื™

gpg - -gen-key

ื™ื™ืฆื ืืช ื”ืžืคืชื— ืฉืœืš

gpg --export -o ~/perskey

ื”ืชืงืŸ ืืช ื”ื“ื™ืกืง ื”ืœื•ื’ื™ ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” ืื ื”ื•ื ืขื“ื™ื™ืŸ ืœื ืžื•ืชืงืŸ

mount /dev/sda6 /mnt #sda6 โ€“ ั€ะฐะทะดะตะป GRUB2

ื ืงื” ืืช ืžื—ื™ืฆืช GRUB2

rm -rf /mnt/

ื”ืชืงืŸ GRUB2 ื‘-sda6, ืฉื™ื ืืช ื”ืžืคืชื— ื”ืคืจื˜ื™ ืฉืœืš ื‘ืชืžื•ื ืช GRUB ื”ืจืืฉื™ืช "core.img"

grub-install --force --modules="gcry_sha256 gcry_sha512 signature_test gcry_dsa gcry_rsa" -k ~/perskey --root-directory=/mnt /dev/sda6

ืืคืฉืจื•ื™ื•ืช
* --force - ื”ืชืงืŸ ืืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ, ืขื•ืงืฃ ืืช ื›ืœ ื”ืื–ื”ืจื•ืช ืฉืชืžื™ื“ ืงื™ื™ืžื•ืช (ื“ื’ืœ ื ื“ืจืฉ).
* โ€”modules="gcry_sha256 gcry_sha512 signature_test gcry_dsa gcry_rsa" - ืžื•ืจื” ืœ-GRUB2 ืœื˜ืขื•ืŸ ืžืจืืฉ ืืช ื”ืžื•ื“ื•ืœื™ื ื”ื“ืจื•ืฉื™ื ื›ืืฉืจ ื”ืžื—ืฉื‘ ืžื•ืคืขืœ.
* -k ~/perskey -ื ืชื™ื‘ ืืœ "ืžืคืชื— PGP" (ืœืื—ืจ ืืจื™ื–ืช ื”ืžืคืชื— ื‘ืชืžื•ื ื”, ื ื™ืชืŸ ืœืžื—ื•ืง ืื•ืชื•).
* --root-directory -ื”ื’ื“ืจ ืืช ืกืคืจื™ื™ืช ื”ืืชื—ื•ืœ ืœืฉื•ืจืฉ ืฉืœ sda6
/dev/sda6 - ืžื—ื™ืฆืช ื”-sdaX ืฉืœืš.

ื™ืฆื™ืจื”/ืขื“ื›ื•ืŸ ืฉืœ grub.cfg

grub-mkconfig  -o /mnt/boot/grub/grub.cfg

ื”ื•ืกืฃ ืืช ื”ืฉื•ืจื” "trust /boot/grub/perskey" ืœืกื•ืฃ ื”ืงื•ื‘ืฅ "grub.cfg" (ื›ืคื” ืฉื™ืžื•ืฉ ื‘ืžืคืชื— pgp.) ืžื›ื™ื•ื•ืŸ ืฉื”ืชืงื ื• GRUB2 ืขื ืงื‘ื•ืฆื” ืฉืœ ืžื•ื“ื•ืœื™ื, ื›ื•ืœืœ ืžื•ื“ื•ืœ ื”ื—ืชื™ืžื” "signature_test.mod", ื–ื” ืžื‘ื˜ืœ ืืช ื”ืฆื•ืจืš ืœื”ื•ืกื™ืฃ ืคืงื•ื“ื•ืช ื›ืžื• "set check_signatures=enforce" ืœ-config.

ื–ื” ืฆืจื™ืš ืœื”ื™ืจืื•ืช ืžืฉื”ื• ื›ื–ื” (ืฉื•ืจื•ืช ืกื™ื•ื ื‘ืงื•ื‘ืฅ grub.cfg)

### BEGIN /etc/grub.d/41_custom ###
if [ -f ${config_directory}/custom.cfg ]; ืœืื—ืจ ืžื›ืŸ
ืžืงื•ืจ ${config_directory}/custom.cfg
elif [ -z "${config_directory}" -a -f $prefix/custom.cfg ]; ืœืื—ืจ ืžื›ืŸ
ืžืงื•ืจ $prefix/custom.cfg;
fi
trust /boot/grub/perskey
set superusers="root"
password_pbkdf2 root grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8
### END /etc/grub.d/41_custom ###
#

ืื™ืŸ ืฆื•ืจืš ืœื”ืฆื‘ื™ืข ืขืœ ื”ื ืชื™ื‘ ืืœ "/boot/grub/perskey" ืœืžื—ื™ืฆืช ื“ื™ืกืง ืกืคืฆื™ืคื™ืช, ืœืžืฉืœ hd0,6; ืขื‘ื•ืจ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืขืฆืžื•, "root" ื”ื•ื ื ืชื™ื‘ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื”ืžื—ื™ืฆื” ืขืœื™ื” ืžื•ืชืงืŸ GRUB2 (ืจืื” ืกื˜ ืจื™ืงื‘ื•ืŸ=..).

ื—ืชื™ืžื” ืขืœ GRUB2 (ื›ืœ ื”ืงื‘ืฆื™ื ื‘ื›ืœ ืกืคืจื™ื•ืช /GRUB) ืขื ื”ืžืคืชื— ืฉืœืš "perskey".
ืคืชืจื•ืŸ ืคืฉื•ื˜ ื›ื™ืฆื“ ืœื—ืชื•ื (ืขื‘ื•ืจ nautilus/caja explorer): ื”ืชืงืŸ ืืช ื”ืชื•ืกืฃ "ืกื•ืก ื™ื" ืขื‘ื•ืจ Explorer ืžื”ืžืื’ืจ. ื™ืฉ ืœื”ื•ืกื™ืฃ ืืช ื”ืžืคืชื— ืฉืœืš ืœืกื‘ื™ื‘ืช su.
ืคืชื— ืืช Explorer ืขื sudo "/mnt/boot" - RMB - ืกื™ืžืŸ. ืขืœ ื”ืžืกืš ื–ื” ื ืจืื” ื›ืš

ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

ื”ืžืคืชื— ืขืฆืžื• ื”ื•ื "/mnt/boot/grub/perskey" (ื”ืขืชืง ืœืกืคืจื™ื™ืช grub) ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื—ืชื•ื ื’ื ื‘ื—ืชื™ืžื” ืžืฉืœืš. ื‘ื“ื•ืง ืฉื—ืชื™ืžื•ืช ื”ืงื•ื‘ืฅ [*.sig] ืžื•ืคื™ืขื•ืช ื‘ืกืคืจื™ื™ื”/ืกืคืจื™ื•ืช ื”ืžืฉื ื”.
ื‘ืืžืฆืขื•ืช ื”ืฉื™ื˜ื” ื”ืžืชื•ืืจืช ืœืขื™ืœ, ืกื™ืžืŸ "/boot" (ื”ืœื™ื‘ื” ืฉืœื ื•, initrd). ืื ื”ื–ืžืŸ ืฉืœืš ืฉื•ื•ื” ืžืฉื”ื•, ืฉื™ื˜ื” ื–ื• ืžื‘ื˜ืœืช ืืช ื”ืฆื•ืจืš ืœื›ืชื•ื‘ ืกืงืจื™ืคื˜ bash ื›ื“ื™ ืœื—ืชื•ื ืขืœ "ื”ืจื‘ื” ืงื‘ืฆื™ื".

ื›ื“ื™ ืœื”ืกื™ืจ ืืช ื›ืœ ื”ื—ืชื™ืžื•ืช ืฉืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ (ืื ืžืฉื”ื• ื”ืฉืชื‘ืฉ)

rm -f $(find /mnt/boot/grub -type f -name '*.sig')

ื›ื“ื™ ืœื ืœื—ืชื•ื ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืœืื—ืจ ืขื“ื›ื•ืŸ ื”ืžืขืจื›ืช, ืื ื• ืžืงืคื™ืื™ื ืืช ื›ืœ ื—ื‘ื™ืœื•ืช ื”ืขื“ื›ื•ื ื™ื ื”ืงืฉื•ืจื•ืช ืœ-GRUB2.

apt-mark hold grub-common grub-pc grub-pc-bin grub2 grub2-common

ื‘ืฉืœื‘ ื–ื” <ื”ื’ืŸ ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช> ื”ื•ืฉืœืžื” ื”ืชืฆื•ืจื” ื”ืžืชืงื“ืžืช ืฉืœ GRUB2.

C6.3. ื‘ื“ื™ืงืช ื”ื•ื›ื—ื” ืฉืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ GRUB2, ืžื•ื’ืŸ ืขืœ ื™ื“ื™ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื•ืื™ืžื•ืชGRUB2. ื‘ืขืช ื‘ื—ื™ืจืช ื”ืคืฆืช GNU/Linux ื›ืœืฉื”ื™ ืื• ื›ื ื™ืกื” ืœ-CLI (ืฉื•ืจืช ืคืงื•ื“ื”) ื™ื™ื“ืจืฉ ื”ืจืฉืืช ืžืฉืชืžืฉ-ืขืœ. ืœืื—ืจ ื”ื–ื ืช ืฉื ื”ืžืฉืชืžืฉ/ื”ืกื™ืกืžื” ื”ื ื›ื•ื ื™ื, ืชื–ื“ืงืง ืœืกื™ืกืžื” Initrd

ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ
ืฆื™ืœื•ื ืžืกืš ืฉืœ ืื™ืžื•ืช ืžื•ืฆืœื— ืฉืœ ืžืฉืชืžืฉ ื”ืขืœ GRUB2.

ืื ืชืชืขืกืง ื‘ืื—ื“ ืžืงื‘ืฆื™ GRUB2/ืชื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘-grub.cfg, ืื• ืชืžื—ืง ืืช ื”ืงื•ื‘ืฅ/ื—ืชื™ืžื”, ืื• ื˜ื•ืขืŸ module.mod ื–ื“ื•ื ื™, ืชื•ืคื™ืข ืื–ื”ืจื” ืžืชืื™ืžื”. GRUB2 ื™ืฉื”ื” โ€‹โ€‹ืืช ื”ื˜ืขื™ื ื”.

ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ
ืฆื™ืœื•ื ืžืกืš, ื ื™ืกื™ื•ืŸ ืœื”ืคืจื™ืข ืœ-GRUB2 "ืžื‘ื—ื•ืฅ".

ื‘ืžื”ืœืš ืืชื—ื•ืœ "ืจื’ื™ืœ" "ืœืœื ื—ื“ื™ืจื”", ืžืฆื‘ ืงื•ื“ ื”ื™ืฆื™ืื” ืฉืœ ื”ืžืขืจื›ืช ื”ื•ื "0". ืœื›ืŸ, ืœื ื™ื“ื•ืข ืื ื”ื”ื’ื ื” ืขื•ื‘ื“ืช ืื• ืœื (ื›ืœื•ืžืจ, "ืขื ืื• ื‘ืœื™ ื”ื’ื ืช ื—ืชื™ืžื•ืช ืฉืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ" ื‘ืžื”ืœืš ื˜ืขื™ื ื” ืจื’ื™ืœื”, ื”ืžืฆื‘ ื”ื•ื ืื•ืชื• "0" - ื–ื” ืจืข).

ืื™ืš ื‘ื•ื“ืงื™ื ื”ื’ื ื” ืขืœ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช?

ื“ืจืš ืœื ื ื•ื—ื” ืœื‘ื“ื•ืง: ื–ื™ื•ืฃ/ื”ืกืจ ืžื•ื“ื•ืœ ื‘ืฉื™ืžื•ืฉ GRUB2, ืœืžืฉืœ, ื”ืกืจ ืืช ื”ื—ืชื™ืžื” luks.mod.sig ื•ืงื‘ืœ ืฉื’ื™ืื”.

ื”ื“ืจืš ื”ื ื›ื•ื ื”: ืขื‘ื•ืจ ืืœ CLI ืฉืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ื•ื”ืงืœื“ ืืช ื”ืคืงื•ื“ื”

trust_list

ื‘ืชื’ื•ื‘ื”, ืืชื” ืืžื•ืจ ืœืงื‘ืœ ื˜ื‘ื™ืขืช ืืฆื‘ืข "perskey"; ืื ื”ืžืฆื‘ ื”ื•ื "0", ืื– ื”ื’ื ืช ื—ืชื™ืžื” ืœื ืขื•ื‘ื“ืช, ื‘ื“ื•ืง ืฉื•ื‘ ืืช ืกืขื™ืฃ C6.2.
ื‘ืฉืœื‘ ื–ื”, ื”ื•ืฉืœืžื” ื”ืชืฆื•ืจื” ื”ืžืชืงื“ืžืช "ื”ื’ื ื” ืขืœ GRUB2 ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื•ืื™ืžื•ืช".

C7 ืฉื™ื˜ื” ื—ืœื•ืคื™ืช ืœื”ื’ื ื” ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ GRUB2 ื‘ืืžืฆืขื•ืช hashingืฉื™ื˜ืช "ื”ื’ื ืช/ืื™ืžื•ืช ืžืืชื—ื•ืœ ืฉืœ CPU" ื”ืžืชื•ืืจืช ืœืขื™ืœ ื”ื™ื ืงืœืืกื™ืช. ื‘ืฉืœ ื—ื•ืกืจ ื”ืฉืœืžื•ืช ืฉืœ GRUB2, ื‘ืชื ืื™ื ืคืจื ื•ืื™ื“ื™ื ื”ื•ื ืจื’ื™ืฉ ืœื”ืชืงืคื” ืืžื™ืชื™ืช, ืื•ืชื” ืืชืŸ ืœื”ืœืŸ ื‘ืคืกืงื” [F]. ื‘ื ื•ืกืฃ, ืœืื—ืจ ืขื“ื›ื•ืŸ ืžืขืจื›ืช ื”ื”ืคืขืœื”/ืงืจื ืœ, ื™ืฉ ืœื—ืชื•ื ืžื—ื“ืฉ ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ.

ื”ื’ื ื” ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ GRUB2 ื‘ืืžืฆืขื•ืช hashing

ื™ืชืจื•ื ื•ืช ืขืœ ืคื ื™ ืงืœืืกื™ืงื•ืช:

  • ืจืžืช ืืžื™ื ื•ืช ื’ื‘ื•ื”ื” ื™ื•ืชืจ (ื’ื™ื‘ื•ืฉ/ืื™ืžื•ืช ืžืชื‘ืฆืข ืจืง ืžืžืฉืื‘ ืžืงื•ืžื™ ืžื•ืฆืคืŸ. ื›ืœ ื”ืžื—ื™ืฆื” ืฉื”ื•ืงืฆืชื” ืชื—ืช GRUB2 ื ืฉืœื˜ืช ืขื‘ื•ืจ ื›ืœ ืฉื™ื ื•ื™, ื•ื›ืœ ื”ืฉืืจ ืžื•ืฆืคืŸ; ื‘ืกื›ื™ืžื” ื”ืงืœืืกื™ืช ืขื ื”ื’ื ื”/ืื™ืžื•ืช ืžื˜ืขื™ืŸ ืžืขื‘ื“, ืจืง ืงื‘ืฆื™ื ื ืฉืœื˜ื™ื, ืืš ืœื ื‘ื—ื™ื ื ื—ืœืœ, ืฉื‘ื• ื ื™ืชืŸ ืœื”ื•ืกื™ืฃ "ืžืฉื”ื•" ืžืฉื”ื• ืžืจื•ืฉืข).
  • ืจื™ืฉื•ื ืžื•ืฆืคืŸ (ื™ื•ืžืŸ ืžื•ืฆืคืŸ ืื™ืฉื™ ื”ื ื™ืชืŸ ืœืงืจื™ืื” ืขืœ ื™ื“ื™ ืื“ื ื ื•ืกืฃ ืœืกื›ื™ืžื”).
  • ืžื”ื™ืจื•ืช (ื”ื’ื ื”/ืื™ืžื•ืช ืฉืœ ืžื—ื™ืฆื” ืฉืœืžื” ืฉื”ื•ืงืฆืชื” ืขื‘ื•ืจ GRUB2 ืžืชืจื—ืฉืช ื›ืžืขื˜ ื‘ืื•ืคืŸ ืžื™ื™ื“ื™).
  • ืื•ื˜ื•ืžืฆื™ื” ืฉืœ ื›ืœ ืชื”ืœื™ื›ื™ ื”ื”ืฆืคื ื”.

ื—ืกืจื•ื ื•ืช ืขืœ ื”ืงืœืืกื™ืงื”.

  • ื–ื™ื•ืฃ ื—ืชื™ืžื” (ืชื™ืื•ืจื˜ื™ืช, ืืคืฉืจ ืœืžืฆื•ื ื”ืชื ื’ืฉื•ืช ืฉืœ ืคื•ื ืงืฆื™ื™ืช ื’ื™ื‘ื•ื‘ ื ืชื•ื ื”).
  • ืจืžืช ืงื•ืฉื™ ืžื•ื’ื‘ืจืช (ื‘ื”ืฉื•ื•ืื” ืœืงืœืืกื™, ื ื“ืจืฉื•ืช ืงืฆืช ื™ื•ืชืจ ืžื™ื•ืžื ื•ื™ื•ืช ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” GNU/Linux).

ืื™ืš ืขื•ื‘ื“ ืจืขื™ื•ืŸ ื”ื’ื™ื‘ื•ื‘ ืฉืœ GRUB2/ืžื—ื™ืฆื”

ืžื—ื™ืฆืช GRUB2 "ื—ืชื•ืžื”"; ื›ืืฉืจ ืžืขืจื›ืช ื”ื”ืคืขืœื” ืžืืชื—ืœืช, ืžื—ื™ืฆืช ืžื˜ืขื™ืŸ ื”ืืชื—ื•ืœ ื ื‘ื“ืงืช ืœื ื ื™ืชื ืช ืœืฉื™ื ื•ื™, ื•ืœืื—ืจ ืžื›ืŸ ื›ื ื™ืกื” ืœืกื‘ื™ื‘ื” ืžืื•ื‘ื˜ื—ืช (ืžื•ืฆืคื ืช). ืื ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืื• ื”ืžื—ื™ืฆื” ืฉืœื• ื ืคื’ืขื™ื, ื‘ื ื•ืกืฃ ืœื™ื•ืžืŸ ื”ื—ื“ื™ืจื”, ื™ื•ืคืขืœ ื”ืคืจืง ื”ื‘ื:

ื“ึธื‘ึธืจ.ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

ื‘ื“ื™ืงื” ื“ื•ืžื” ืžืชืจื—ืฉืช ืืจื‘ืข ืคืขืžื™ื ื‘ื™ื•ื, ืฉืื™ื ื” ื˜ื•ืขื ืช ืžืฉืื‘ื™ ืžืขืจื›ืช.
ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” "-$ check_GRUB", ื‘ื“ื™ืงื” ืžื™ื™ื“ื™ืช ืžืชืจื—ืฉืช ื‘ื›ืœ ืขืช ืœืœื ืจื™ืฉื•ื, ืืœื ืขื ืคืœื˜ ืžื™ื“ืข ืœ-CLI.
ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” "-$ sudo signature_GRUB", ื˜ื•ืขืŸ/ืžื—ื™ืฆืช ื”ืืชื—ื•ืœ ืฉืœ GRUB2 ื ื—ืชื ืžื—ื“ืฉ ื‘ืื•ืคืŸ ืžื™ื™ื“ื™ ื•ื”ืจื™ืฉื•ื ืฉืœื• ืžืขื•ื“ื›ืŸ (ื”ื›ืจื—ื™ ืœืื—ืจ ืขื“ื›ื•ืŸ ืžืขืจื›ืช ื”ื”ืคืขืœื”/ืืชื—ื•ืœ), ื•ื”ื—ื™ื™ื ืžืžืฉื™ื›ื™ื.

ื”ื˜ืžืขืช ืฉื™ื˜ืช ื’ื™ื‘ื•ื‘ ืขื‘ื•ืจ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ื•ื”ืงื˜ืข ืฉืœื•

0) ื‘ื•ืื• ื ื—ืชื•ื ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ/ืžื—ื™ืฆื” GRUB ืขืœ ื™ื“ื™ ื”ืจื›ื‘ื” ืชื—ื™ืœื” ื‘-/media/username

-$ hashdeep -c md5 -r /media/username/GRUB > /podpis.txt

1) ืื ื• ื™ื•ืฆืจื™ื ืกืงืจื™ืคื˜ ืœืœื ื”ืจื—ื‘ื” ื‘ืฉื•ืจืฉ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืžื•ืฆืคื ืช ~/podpis, ืžื—ื™ืœื™ื ืขืœื™ื• ืืช ื–ื›ื•ื™ื•ืช ื”ืื‘ื˜ื—ื” ื”ื“ืจื•ืฉื•ืช 744 ื•ื”ื’ื ื” ื—ืกื™ื ืช ืชืงืœื•ืช.

ืžื™ืœื•ื™ ืชื•ื›ื ื•

#!/bin/bash

#ะŸั€ะพะฒะตั€ะบะฐ ะฒัะตะณะพ ั€ะฐะทะดะตะปะฐ ะฒั‹ะดะตะปะตะฝะฝะพะณะพ ะฟะพะด ะทะฐะณั€ัƒะทั‡ะธะบ GRUB2 ะฝะฐ ะฝะตะธะทะผะตะฝะฝะพัั‚ัŒ.
#ะ’ะตะดะตั‚ัั ะปะพะณ "ะพ ะฒั‚ะพั€ะถะตะฝะธะธ/ัƒัะฟะตัˆะฝะพะน ะฟั€ะพะฒะตั€ะบะต ะบะฐั‚ะฐะปะพะณะฐ", ะบะพั€ะพั‡ะต ะณะพะฒะพั€ั ะฒะตะดะตั‚ัั ะฟะพะปะฝั‹ะน ะปะพะณ ั ั‚ั€ะพะนะฝะพะน ะฒะตั€ะฑะฐะปะธะทะฐั†ะธะตะน. ะ’ะฝะธะผะฐะฝะธะต! ะพะฑั€ะฐั‚ะธั‚ัŒ ะฒะทะพั€ ะฝะฐ ะฟัƒั‚ะธ: ั…ั€ะฐะฝะธั‚ัŒ ะฆะŸ GRUB2 ั‚ะพะปัŒะบะพ ะฝะฐ ะทะฐัˆะธั„ั€ะพะฒะฐะฝะฝะพะผ ั€ะฐะทะดะตะปะต OS GNU/Linux. 
echo -e "******************************************************************n" >> '/var/log/podpis.txt' && date >> '/var/log/podpis.txt' && hashdeep -vvv -a -k '/podpis.txt' -r '/media/username/GRUB' >> '/var/log/podpis.txt'

a=`tail '/var/log/podpis.txt' | grep failed` #ะฝะต ะธัะฟะพะปัŒะทะพะฒะฐั‚ัŒ "cat"!! 
b="hashdeep: Audit failed"

#ะฃัะปะพะฒะธะต: ะฒ ัะปัƒั‡ะฐะต ะปัŽะฑั‹ั… ะบะฐะบะธั…-ะปะธะฑะพ ะธะทะผะตะฝะตะฝะธะน ะฒ ั€ะฐะทะดะตะปะต ะฒั‹ะดะตะปะตะฝะฝะพะผ ะฟะพะด GRUB2 ะบ ะฟะพะปะฝะพะผัƒ ะปะพะณัƒ ะฟะธัˆะตั‚ัั ะฒั‚ะพั€ะพะน ะพั‚ะดะตะปัŒะฝั‹ะน ะบั€ะฐั‚ะบะธะน ะปะพะณ "ั‚ะพะปัŒะบะพ ะพ ะฒั‚ะพั€ะถะตะฝะธะธ" ะธ ะฒั‹ะฒะพะดะธั‚ัั ะฝะฐ ะผะพะฝะธั‚ะพั€ ะผะธะณะฐะฝะธะต gif-ะบะธ "warning".
if [[ "$a" = "$b" ]] 
then
echo -e "****n" >> '/var/log/vtorjenie.txt' && echo "vtorjenie" >> '/var/log/vtorjenie.txt' && date >> '/var/log/vtorjenie.txt' & sudo -u username DISPLAY=:0 eom '/warning.gif' 
fi

ืื ื—ื ื• ืžืจื™ืฆื™ื ืืช ื”ืชืกืจื™ื˜ ืž su, ื”ื’ื™ื‘ื•ื‘ ืฉืœ ืžื—ื™ืฆืช GRUB ื•ืžื˜ืขืŸ ื”ืืชื—ื•ืœ ืฉืœื” ื™ื™ื‘ื“ืง, ืฉืžื•ืจ ืืช ื”ื™ื•ืžืŸ.

ื‘ื•ืื• ื ื™ืฆื•ืจ ืื• ื ืขืชื™ืง, ืœืžืฉืœ, "ืงื•ื‘ืฅ ื–ื“ื•ื ื™" [virus.mod] ืœืžื—ื™ืฆืช GRUB2 ื•ื ืคืขื™ืœ ืกืจื™ืงื”/ื‘ื“ื™ืงื” ื–ืžื ื™ืช:

-$ hashdeep -vvv -a -k '/podpis.txt' -r '/media/username/GRUB

ื”-CLI ื—ื™ื™ื‘ ืœืจืื•ืช ืคืœื™ืฉื” ืœืžืฆื•ื“ื” ืฉืœื ื•#Trimmed ื›ื ื™ืกื” ืœ-CLI

ะกั€ ัะฝะฒ  2 11::41 MSK 2020
/media/username/GRUB/boot/grub/virus.mod: Moved from /media/username/GRUB/1nononoshifr
/media/username/GRUB/boot/grub/i386-pc/mda_text.mod: Ok
/media/username/GRUB/boot/grub/grub.cfg: Ok
hashdeep: Audit failed
   Input files examined: 0
  Known files expecting: 0
          Files matched: 325
Files partially matched: 0
            Files moved: 1
        New files found: 0
  Known files not found: 0

#ื›ืคื™ ืฉืืชื” ื™ื›ื•ืœ ืœืจืื•ืช, ืžื•ืคื™ืข "ืงื‘ืฆื™ื ื”ื•ืขื‘ืจื•: 1 ื•ื‘ื™ืงื•ืจืช ื ื›ืฉืœื”", ืžื” ืฉืื•ืžืจ ืฉื”ื‘ื“ื™ืงื” ื ื›ืฉืœื”.
ืขืงื‘ ืื•ืคื™ ื”ืžื—ื™ืฆื” ื”ื ื‘ื“ืงืช, ื‘ืžืงื•ื "ื ืžืฆืื• ืงื‘ืฆื™ื ื—ื“ืฉื™ื" > "ืงื‘ืฆื™ื ื”ื•ืขื‘ืจื•"

2) ืฉื™ื ืืช ื”-gif ื›ืืŸ > ~/warning.gif, ื”ื’ื“ืจ ืืช ื”ื”ืจืฉืื•ืช ืœ-744.

3) ื”ื’ื“ืจืช fstab ืœื˜ืขื™ื ื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืžื—ื™ืฆืช GRUB ื‘ืขืช ื”ืืชื—ื•ืœ

-$ sudo nano /etc/fstab

LABEL=GRUB /media/username/GRUB ext4 ื‘ืจื™ืจืช ื”ืžื—ื“ืœ 0 0

4) ืกื™ื‘ื•ื‘ ื”ื™ื•ืžืŸ

-$ sudo nano /etc/logrotate.d/podpis 

/var/log/podpis.txt {
ื™ื•ืžื™
ืกื•ื‘ื‘ 50
ื’ื•ื“ืœ 5M
ื˜ืงืกื˜ ื ืชื•ื ื™ื
ืœื“ื—ื•ืก
ื“ื—ื™ืกืช ื“ื—ื™ืกื”
olddir /var/log/old
}

/var/log/vtorjenie.txt {
ืื—ืช ืœื—ื•ื“ืฉ
ืกื•ื‘ื‘ 5
ื’ื•ื“ืœ 5M
ื˜ืงืกื˜ ื ืชื•ื ื™ื
olddir /var/log/old
}

5) ื”ื•ืกืฃ ืขื‘ื•ื“ื” ืœ-cron

-$ sudo crontab -e

ืืชื—ื•ืœ ืžื—ื“ืฉ '/ืžึดื ื•ึผื™'
0 */6 * * * '/podpis

6) ื™ืฆื™ืจืช ื›ื™ื ื•ื™ื™ื ืงื‘ื•ืขื™ื

-$ sudo su
-$ echo "alias ะฟะพะดะฟะธััŒ_GRUB='hashdeep -c md5 -r /media/username/GRUB > /podpis.txt'" >> /root/.bashrc && bash
-$ echo "alias ะฟั€ะพะฒะตั€ะบะฐ_GRUB='hashdeep -vvv -a -k '/podpis.txt' -r /media/username/GRUB'" >> .bashrc && bash

ืœืื—ืจ ืขื“ื›ื•ืŸ ืžืขืจื›ืช ื”ื”ืคืขืœื” -$ apt-get upgrade ืœื—ืชื•ื ืžื—ื“ืฉ ืขืœ ืžื—ื™ืฆืช GRUB ืฉืœื ื•
-$ ะฟะพะดะฟะธััŒ_GRUB
ื‘ืฉืœื‘ ื–ื”, ื”ื’ื ืช ื”ื’ื™ื‘ื•ื‘ ืฉืœ ืžื—ื™ืฆืช GRUB ื”ื•ืฉืœืžื”.

[ื“] ื ื™ื’ื•ื‘ - ื”ืฉืžื“ืช ื ืชื•ื ื™ื ืœื ืžื•ืฆืคื ื™ื

ืžื—ืง ืืช ื”ืงื‘ืฆื™ื ื”ืื™ืฉื™ื™ื ืฉืœืš ื‘ืฆื•ืจื” ื›ืœ ื›ืš ืžืœืื” ืฉ"ืืคื™ืœื• ืืœื•ื”ื™ื ืœื ื™ื›ื•ืœ ืœืงืจื•ื ืื•ืชื", ืขืœ ืคื™ ื“ื•ื‘ืจ ื“ืจื•ื ืงืจื•ืœื™ื™ื ื”, ื˜ืจื™ื™ ื’ืื•ื“ื™.

ื›ืจื’ื™ืœ, ื™ืฉื ื "ืžื™ืชื•ืกื™ื ื• ืื’ื“ื•ืช", ืขืœ ืฉื—ื–ื•ืจ ื ืชื•ื ื™ื ืœืื—ืจ ืžื—ื™ืงืชื ืžื”ื›ื•ื ืŸ ื”ืงืฉื™ื—. ืื ืืชื” ืžืืžื™ืŸ ื‘ื›ื™ืฉื•ืฃ ืกื™ื™ื‘ืจ, ืื• ืฉืืชื” ื—ื‘ืจ ื‘ืงื”ื™ืœืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœ Dr ื•ืžืขื•ืœื ืœื ื ื™ืกื™ืช ืฉื—ื–ื•ืจ ื ืชื•ื ื™ื ืœืื—ืจ ืžื—ื™ืงืชื/ื”ื—ืœืคืชื (ืœื“ื•ื’ืžื”, ื”ืชืื•ืฉืฉื•ืช ื‘ืืžืฆืขื•ืช R-studio), ืื– ืœื ืกื‘ื™ืจ ืฉื”ืฉื™ื˜ื” ื”ืžื•ืฆืขืช ืชืชืื™ื ืœืš, ื”ืฉืชืžืฉ ื‘ืžื” ืฉื”ื›ื™ ืงืจื•ื‘ ืืœื™ืš.

ืœืื—ืจ ื”ืขื‘ืจืช GNU/Linux ื‘ื”ืฆืœื—ื” ืœืžื—ื™ืฆื” ืžื•ืฆืคื ืช, ื™ืฉ ืœืžื—ื•ืง ืืช ื”ืขื•ืชืง ื”ื™ืฉืŸ ืœืœื ืืคืฉืจื•ืช ืœืฉื—ื–ื•ืจ ื ืชื•ื ื™ื. ืฉื™ื˜ืช ื ื™ืงื•ื™ ืื•ื ื™ื‘ืจืกืœื™ืช: ืชื•ื›ื ื” ืœืชื•ื›ื ืช GUI ื—ื™ื ืžื™ืช ืฉืœ Windows/Linux BleachBit.
ืžื”ืจ ืœืขืฆื‘ ืืช ื”ืงื˜ืข, ืฉื”ื ืชื•ื ื™ื ืขืœื™ื”ื ืฆืจื™ื›ื™ื ืœื”ื™ื”ืจืก (ื“ืจืš Gparted) ื”ืคืขืœ ืืช BleachBit, ื‘ื—ืจ "ื ืงื” ืžืงื•ื ืคื ื•ื™" - ื‘ื—ืจ ืืช ื”ืžื—ื™ืฆื” (sdaX ืฉืœืš ืขื ืขื•ืชืง ืงื•ื“ื ืฉืœ GNU/Linux), ืชื”ืœื™ืš ื”ื”ืคืฉื˜ื” ื™ืชื—ื™ืœ. BleachBit - ืžื ื’ื‘ ืืช ื”ื“ื™ืกืง ื‘ืžืขื‘ืจ ืื—ื“ - ื–ื” ืžื” "ืื ื—ื ื• ืฆืจื™ื›ื™ื", ืื‘ืœ! ื–ื” ืขื•ื‘ื“ ืจืง ื‘ืชื™ืื•ืจื™ื” ืื ืคื™ืจืžื˜ืช ืืช ื”ื“ื™ืกืง ื•ื ื™ืงื™ืช ืื•ืชื• ื‘ืชื•ื›ื ืช BB v2.0.

ืชืฉื•ืžืช ืœื‘! BB ืžื ื’ื‘ ืืช ื”ื“ื™ืกืง ื•ืžืฉืื™ืจ ืžื˜ื ื ืชื•ื ื™ื; ืฉืžื•ืช ื”ืงื‘ืฆื™ื ื ืฉืžืจื™ื ื›ืืฉืจ ื”ื ืชื•ื ื™ื ื ืžื—ืงื™ื (CCleaner - ืœื ืžืฉืื™ืจ ืžื˜ื ื ืชื•ื ื™ื).

ื•ื”ืžื™ืชื•ืก ืœื’ื‘ื™ ื”ืืคืฉืจื•ืช ืœืฉื—ื–ื•ืจ ื ืชื•ื ื™ื ืื™ื ื• ืœื’ืžืจื™ ืžื™ืชื•ืก.Bleachbit V2.0-2 ื—ื‘ื™ืœืช Debian OS ืœื ื™ืฆื™ื‘ื” ืœืฉืขื‘ืจ (ื•ื›ืœ ืชื•ื›ื ื” ื“ื•ืžื” ืื—ืจืช: sfill; wipe-Nautilus - ื”ื‘ื—ื™ื ื• ื’ื ื‘ืขืกืง ื”ืžืœื•ื›ืœืš ื”ื–ื”) ืœืžืขืฉื” ื”ื™ื” ื‘ืื’ ืงืจื™ื˜ื™: ื”ืคื•ื ืงืฆื™ื” "ืคื™ื ื•ื™ ืฉื˜ื— ืคื ื•ื™". ื–ื” ืขื•ื‘ื“ ื‘ืฆื•ืจื” ืœื ื ื›ื•ื ื” ื‘ื›ื•ื ื ื™ HDD/Flash (ntfs/ext4). ืชื•ื›ื ื•ืช ืžืกื•ื’ ื–ื”, ื‘ืขืช ืคื™ื ื•ื™ ืžืงื•ื ืคื ื•ื™, ืื™ื ืŸ ืžื—ืœื™ืคื•ืช ืืช ื›ืœ ื”ื“ื™ืกืง, ื›ืคื™ ืฉืžืฉืชืžืฉื™ื ืจื‘ื™ื ื—ื•ืฉื‘ื™ื. ื•ื›ืžื” (ืจื‘) ื ืชื•ื ื™ื ืฉื ืžื—ืงื• ืžืขืจื›ืช ื”ืคืขืœื”/ืชื•ื›ื ื” ืžื—ืฉื™ื‘ื” ืืช ื”ื ืชื•ื ื™ื ื”ืืœื” ื›ื ืชื•ื ื™ื ืฉืœื ื ืžื—ืงื•/ืžืฉืชืžืฉื™ื ื•ื‘ืขืช ื ื™ืงื•ื™ "OSP" ื”ื™ื ืžื“ืœื’ืช ืขืœ ืงื‘ืฆื™ื ืืœื”. ื”ื‘ืขื™ื” ื”ื™ื ืฉืื—ืจื™ ื›ืœ ื›ืš ื”ืจื‘ื” ื–ืžืŸ, ืžื ืงื™ื ืืช ื”ื“ื™ืกืง ื ื™ืชืŸ ืœืฉื—ื–ืจ "ืงื‘ืฆื™ื ืฉื ืžื—ืงื•". ื’ื ืœืื—ืจ 3 ืžืขื‘ืจื™ื ืฉืœ ื ื™ื’ื•ื‘ ื”ื“ื™ืกืง.
ื‘-GNU/Linux ื‘-Bleachbit 2.0-2 ื”ืคื•ื ืงืฆื™ื•ืช ืฉืœ ืžื—ื™ืงืช ืงื‘ืฆื™ื ื•ืกืคืจื™ื•ืช ืœืฆืžื™ืชื•ืช ืคื•ืขืœื•ืช ื‘ืฆื•ืจื” ืžื”ื™ืžื ื”, ืืš ืื™ื ืŸ ืžืคื ื” ืžืงื•ื ืคื ื•ื™. ืœืฉื ื”ืฉื•ื•ืื”: ื‘-Windows ื‘-CCleaner ื”ืคื•ื ืงืฆื™ื” "OSP for ntfs" ืขื•ื‘ื“ืช ื›ืžื• ืฉืฆืจื™ืš, ื•ืืœื•ื”ื™ื ื‘ืืžืช ืœื ื™ื•ื›ืœ ืœืงืจื•ื ื ืชื•ื ื™ื ืฉื ืžื—ืงื•.

ื•ื›ืš, ืœื”ืกื™ืจ ื‘ื™ืกื•ื“ื™ื•ืช "ืคึผึทืฉืืจึธื ึดื™" ื ืชื•ื ื™ื ื™ืฉื ื™ื ืœื ืžื•ืฆืคื ื™ื, Bleachbit ืฆืจื™ืš ื’ื™ืฉื” ื™ืฉื™ืจื” ืœื ืชื•ื ื™ื ื”ืืœื”, ืœืื—ืจ ืžื›ืŸ, ื”ืฉืชืžืฉ ื‘ืคื•ื ืงืฆื™ื” "ืžื—ืง ืงื‘ืฆื™ื/ืกืคืจื™ื•ืช ืœืฆืžื™ืชื•ืช".
ื›ื“ื™ ืœื”ืกื™ืจ "ืงื‘ืฆื™ื ืฉื ืžื—ืงื• ื‘ืืžืฆืขื•ืช ื›ืœื™ ืžืขืจื›ืช ื”ืคืขืœื” ืกื˜ื ื“ืจื˜ื™ื™ื" ื‘-Windows, ื”ืฉืชืžืฉ ื‘-CCleaner/BB ืขื ื”ืคื•ื ืงืฆื™ื” "OSP". ื‘-GNU/Linux ืขืœ ื”ื‘ืขื™ื” ื”ื–ื• (ืžื—ืง ืงื‘ืฆื™ื ืฉื ืžื—ืงื•) ืืชื” ืฆืจื™ืš ืœื”ืชืืžืŸ ืœื‘ื“ (ืžื—ื™ืงืช ื ืชื•ื ื™ื + ื ื™ืกื™ื•ืŸ ืขืฆืžืื™ ืœืฉื—ื–ืจ ืื•ืชื ื•ืื™ืŸ ืœื”ืกืชืžืš ืขืœ ื’ืจืกืช ื”ืชื•ื›ื ื” (ืื ืœื ืกื™ืžื ื™ื”, ืื– ื‘ืื’)), ืจืง ื‘ืžืงืจื” ื–ื” ืชื•ื›ืœ ืœื”ื‘ื™ืŸ ืืช ื”ืžื ื’ื ื•ืŸ ืฉืœ ื‘ืขื™ื” ื–ื• ื•ืœื”ื™ืคื˜ืจ ืœื—ืœื•ื˜ื™ืŸ ืžื”ื ืชื•ื ื™ื ืฉื ืžื—ืงื•.

ืœื ื‘ื“ืงืชื™ ืืช Bleachbit v3.0, ื™ื™ืชื›ืŸ ืฉื”ื‘ืขื™ื” ื›ื‘ืจ ืชื•ืงื ื”.
Bleachbit v2.0 ืขื•ื‘ื“ ื‘ื™ื•ืฉืจ.

ื‘ืฉืœื‘ ื–ื”, ื ื™ื’ื•ื‘ ื”ื“ื™ืกืง ื”ื•ืฉืœื.

[ื”] ื’ื™ื‘ื•ื™ ืื•ื ื™ื‘ืจืกืœื™ ืฉืœ ืžืขืจื›ืช ื”ืคืขืœื” ืžื•ืฆืคื ืช

ืœื›ืœ ืžืฉืชืžืฉ ื™ืฉ ืฉื™ื˜ื” ืžืฉืœื• ืœื’ื™ื‘ื•ื™ ื ืชื•ื ื™ื, ืืš ื ืชื•ื ื™ ืžืขืจื›ืช ื”ืคืขืœื” ืžื•ืฆืคื ื™ื ื“ื•ืจืฉื™ื ื’ื™ืฉื” ืžืขื˜ ืฉื•ื ื” ืœืžืฉื™ืžื”. ืชื•ื›ื ื•ืช ืžืื•ื—ื“ื•ืช, ื›ื’ื•ืŸ Clonezilla ื•ืชื•ื›ื ื•ืช ื“ื•ืžื•ืช, ืื™ื ืŸ ื™ื›ื•ืœื•ืช ืœืขื‘ื•ื“ ื™ืฉื™ืจื•ืช ืขื ื ืชื•ื ื™ื ืžื•ืฆืคื ื™ื.

ื”ืฆื”ืจื” ืขืœ ื”ื‘ืขื™ื” ืฉืœ ื’ื™ื‘ื•ื™ ื”ืชืงื ื™ ื—ืกื™ืžื” ืžื•ืฆืคื ื™ื:

  1. ืื•ื ื™ื‘ืจืกืœื™ื•ืช - ืื•ืชื• ืืœื’ื•ืจื™ืชื/ืชื•ื›ื ื” ื’ื™ื‘ื•ื™ ืขื‘ื•ืจ Windows/Linux;
  2. ื”ื™ื›ื•ืœืช ืœืขื‘ื•ื“ ื‘ืงื•ื ืกื•ืœื” ืขื ื›ืœ GNU/Linux usb ื—ื™ ืœืœื ืฆื•ืจืš ื‘ื”ื•ืจื“ื•ืช ืชื•ื›ื ื” ื ื•ืกืคื•ืช (ืื‘ืœ ืขื“ื™ื™ืŸ ืžืžืœื™ืฅ ืขืœ GUI);
  3. ืื‘ื˜ื—ืช ืขื•ืชืงื™ ื’ื™ื‘ื•ื™ - "ืชืžื•ื ื•ืช" ืžืื•ื—ืกื ื•ืช ื—ื™ื™ื‘ื•ืช ืœื”ื™ื•ืช ืžื•ืฆืคื ื•ืช/ืžื•ื’ื ื•ืช ื‘ืืžืฆืขื•ืช ืกื™ืกืžื”;
  4. ื’ื•ื“ืœ ื”ื ืชื•ื ื™ื ื”ืžื•ืฆืคื ื™ื ื—ื™ื™ื‘ ืœื”ืชืื™ื ืœื’ื•ื“ืœ ื”ื ืชื•ื ื™ื ื”ืžื•ืขืชืงื™ื ื‘ืคื•ืขืœ;
  5. ื—ื™ืœื•ืฅ ื ื•ื— ืฉืœ ืงื‘ืฆื™ื ื ื—ื•ืฆื™ื ืžืขื•ืชืง ื’ื™ื‘ื•ื™ (ืื™ืŸ ืฆื•ืจืš ืœืคืขื ื— ืชื—ื™ืœื” ืืช ื›ืœ ื”ืงื˜ืข).

ืœื“ื•ื’ืžื”, ื’ื™ื‘ื•ื™/ืฉื—ื–ื•ืจ ื‘ืืžืฆืขื•ืช ื›ืœื™ ื”ืฉื™ืจื•ืช "dd".

dd if=/dev/sda7 of=/ะฟัƒั‚ัŒ/sda7.img bs=7M conv=sync,noerror
dd if=/ะฟัƒั‚ัŒ/sda7.img of=/dev/sda7 bs=7M conv=sync,noerror

ื–ื” ืžืชืื™ื ื›ืžืขื˜ ืœื›ืœ ื ืงื•ื“ื•ืช ื”ืžืฉื™ืžื”, ืื‘ืœ ืœืคื™ ื ืงื•ื“ื” 4 ื”ื•ื ืœื ืขื•ืžื“ ื‘ื‘ื™ืงื•ืจืช, ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ืžืขืชื™ืง ืืช ื›ืœ ืžื—ื™ืฆืช ื”ื“ื™ืกืง, ื›ื•ืœืœ ืžืงื•ื ืคื ื•ื™ - ืœื ืžืขื ื™ื™ืŸ.

ืœื“ื•ื’ืžื”, ื’ื™ื‘ื•ื™ GNU/Linux ื“ืจืš ื”ืืจื›ื™ื•ืŸ [tar" | gpg] ื ื•ื—, ืื‘ืœ ืœื’ื™ื‘ื•ื™ ืฉืœ Windows ืืชื” ืฆืจื™ืš ืœื—ืคืฉ ืคืชืจื•ืŸ ืื—ืจ - ื–ื” ืœื ืžืขื ื™ื™ืŸ.

E1. ื’ื™ื‘ื•ื™ ืื•ื ื™ื‘ืจืกืœื™ ืฉืœ Windows/Linux. ืงื™ืฉื•ืจ rsync (Grsync)+ื ืคื— VeraCryptืืœื’ื•ืจื™ืชื ืœื™ืฆื™ืจืช ืขื•ืชืง ื’ื™ื‘ื•ื™:

  1. ื™ืฆื™ืจืช ืžื™ื›ืœ ืžื•ืฆืคืŸ (ื ืคื—/ืงื•ื‘ืฅ) VeraCrypt ืขื‘ื•ืจ ืžืขืจื›ืช ื”ื”ืคืขืœื”;
  2. ื”ืขื‘ืจ/ืกื ื›ืจืŸ ืืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ื‘ืืžืฆืขื•ืช ืชื•ื›ื ืช Rsync ืœืชื•ืš ืžื™ื›ืœ ื”ื”ืฆืคื ื” ืฉืœ VeraCrypt;
  3. ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ื”ืขืœื” ืืช ืืžืฆืขื™ ื”ืื—ืกื•ืŸ ืฉืœ VeraCrypt ืืœ www.

ืœื™ืฆื™ืจืช ืžื™ื›ืœ VeraCrypt ืžื•ืฆืคืŸ ื™ืฉ ืžืืคื™ื™ื ื™ื ืžืฉืœื”:
ื™ืฆื™ืจืช ื ืคื— ื“ื™ื ืžื™ (ื™ืฆื™ืจืช DT ื–ืžื™ื ื” ืจืง ื‘-Windows, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื’ื ื‘-GNU/Linux);
ื™ืฆื™ืจืช ื ืคื— ืจื’ื™ืœ, ืืš ื™ืฉื ื” ื“ืจื™ืฉื” ืœ"ื“ืžื•ืช ืคืจื ื•ืื™ื“ื™ืช" (ืœืคื™ ื”ื™ื–ื) - ืขื™ืฆื•ื‘ ืžื™ื›ืœ.

ื ืคื— ื“ื™ื ืžื™ ื ื•ืฆืจ ื›ืžืขื˜ ื‘ืื•ืคืŸ ืžื™ื™ื“ื™ ื‘-Windows, ืืš ื‘ืขืช ื”ืขืชืงืช ื ืชื•ื ื™ื ืž-GNU/Linux > VeraCrypt DT, ื”ื‘ื™ืฆื•ืขื™ื ื”ื›ื•ืœืœื™ื ืฉืœ ืคืขื•ืœืช ื”ื’ื™ื‘ื•ื™ ื™ื•ืจื“ื™ื ื‘ืื•ืคืŸ ืžืฉืžืขื•ืชื™.

ื ื•ืฆืจ ื ืคื— Twofish ืจื’ื™ืœ ืฉืœ 70 GB (ื‘ื•ื ื ื’ื™ื“, ื‘ื›ื•ื— ื”ืžื—ืฉื‘ ื”ืžืžื•ืฆืข) ืœ- HDD ~ ื‘ืขื•ื“ ื—ืฆื™ ืฉืขื” (ื”ื—ืœืคืช ื ืชื•ื ื™ ื”ืžื›ื•ืœื” ืœืฉืขื‘ืจ ื‘ืžืขื‘ืจ ืื—ื“ ื ื•ื‘ืขืช ืžื“ืจื™ืฉื•ืช ืื‘ื˜ื—ื”). ื”ืคื•ื ืงืฆื™ื” ืฉืœ ืขื™ืฆื•ื‘ ืžื”ื™ืจ ืฉืœ ืืžืฆืขื™ ืื—ืกื•ืŸ ื‘ืขืช โ€‹โ€‹ื™ืฆื™ืจืชื• ื”ื•ืกืจื” ืž-VeraCrypt Windows/Linux, ื›ืš ืฉื™ืฆื™ืจืช ืงื•ื ื˜ื™ื™ื ืจ ืืคืฉืจื™ืช ืจืง ื‘ืืžืฆืขื•ืช "ืฉื›ืชื•ื‘ ืžื—ื“ืฉ ื‘ืžืขื‘ืจ ืื—ื“" ืื• ื™ืฆื™ืจืช ืืžืฆืขื™ ืื—ืกื•ืŸ ื“ื™ื ืžื™ ื‘ืขืœ ื‘ื™ืฆื•ืขื™ื ื ืžื•ื›ื™ื.

ืฆื•ืจ ืืžืฆืขื™ ืื—ืกื•ืŸ ืจื’ื™ืœื™ื ืฉืœ VeraCrypt (ืœื ื“ื™ื ืžื™/ntfs), ืœื ืืžื•ืจื•ืช ืœื”ื™ื•ืช ื‘ืขื™ื•ืช.

ื”ื’ื“ืจ/ืฆื•ืจ/ืคืชื— ืžื™ื›ืœ ื‘-VeraCrypt GUI> GNU/Linux live usb (ืขื•ืฆืžืช ื”ืงื•ืœ ื™ื•ืจื›ื‘ ืื•ื˜ื•ืžื˜ื™ืช ืœ-/media/veracrypt2, ืขื•ืฆืžืช ื”ืงื•ืœ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” ืฉืœ Windows ื™ื•ืจื›ื‘ ืœ-/media/veracrypt1). ื™ืฆื™ืจืช ื’ื™ื‘ื•ื™ ืžื•ืฆืคืŸ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” Windows ื‘ืืžืฆืขื•ืช GUI rsync (grsync)ืขืœ ื™ื“ื™ ืกื™ืžื•ืŸ ื”ืชื™ื‘ื•ืช.

ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืžืขืจื›ื•ืช ืžื•ืชืงื ื•ืช ืฉืœ Windows Linux. ืจื™ื‘ื•ื™ ืืชื—ื•ืœ ืžื•ืฆืคืŸ

ื”ืžืชืŸ ืขื“ ืœื”ืฉืœืžืช ื”ืชื”ืœื™ืš. ืœืื—ืจ ื”ืฉืœืžืช ื”ื’ื™ื‘ื•ื™, ื™ื”ื™ื” ืœื ื• ืงื•ื‘ืฅ ืžื•ืฆืคืŸ ืื—ื“.

ื‘ืื•ืคืŸ ื“ื•ืžื”, ืฆื•ืจ ืขื•ืชืง ื’ื™ื‘ื•ื™ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” GNU/Linux ืขืœ ื™ื“ื™ ื‘ื™ื˜ื•ืœ ื”ืกื™ืžื•ืŸ ื‘ืชื™ื‘ืช ื”ืกื™ืžื•ืŸ "ืชืื™ืžื•ืช Windows" ื‘ืžืžืฉืง ื”ืžืฉืชืžืฉ ืฉืœ rsync.

ืชืฉื•ืžืช ืœื‘! ืฆื•ืจ ืžื™ื›ืœ Veracrypt ืขื‘ื•ืจ "ื’ื™ื‘ื•ื™ GNU/Linux" ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ext4. ืื ืชื‘ืฆืข ื’ื™ื‘ื•ื™ ืœืงื•ื ื˜ื™ื™ื ืจ ntfs, ืื– ื›ืฉืชืฉื—ื–ืจ ืขื•ืชืง ื›ื–ื”, ืชืื‘ื“ ืืช ื›ืœ ื”ื–ื›ื•ื™ื•ืช/ืงื‘ื•ืฆื•ืช ืœื›ืœ ื”ื ืชื•ื ื™ื ืฉืœืš.

ื ื™ืชืŸ ืœื‘ืฆืข ืืช ื›ืœ ื”ืคืขื•ืœื•ืช ื‘ื˜ืจืžื™ื ืœ. ืืคืฉืจื•ื™ื•ืช ื‘ืกื™ืกื™ื•ืช ืขื‘ื•ืจ rsync:
* -g -ืฉืžื•ืจ ืงื‘ื•ืฆื•ืช;
* -P โ€” ื”ืชืงื“ืžื•ืช โ€” ืžืฆื‘ ื”ื–ืžืŸ ืฉื”ื•ืฉืงืข ื‘ืขื‘ื•ื“ื” ืขืœ ื”ืงื•ื‘ืฅ;
* -H - ื”ืขืชืง ืงื™ืฉื•ืจื™ื ืงืฉื™ื—ื™ื ื›ืคื™ ืฉื”ื;
* -ืžืฆื‘ ืืจื›ื™ื•ืŸ (ืžืกืคืจ ื“ื’ืœื™ื ืฉืœ rlptgoD);
* -v -ืžื™ืœื•ืœื™ื•ืช.

ืื ื‘ืจืฆื•ื ืš ืœื”ืขืœื•ืช "ื ืคื— Windows VeraCrypt" ื“ืจืš ื”ืžืกื•ืฃ ื‘ืชื•ื›ื ืช cryptsetup, ืืชื” ื™ื›ื•ืœ ืœื™ืฆื•ืจ ื›ื™ื ื•ื™ (su)

echo "alias veramount='cryptsetup open --veracrypt --tcrypt-system --type tcrypt /dev/sdaX Windows_crypt && mount /dev/mapper/ Windows_crypt /media/veracrypt1'" >> .bashrc && bash

ื›ืขืช ื”ืคืงื•ื“ื” "veramount pictures" ืชื‘ืงืฉ ืžืžืš ืœื”ื–ื™ืŸ ื‘ื™ื˜ื•ื™ ืกื™ืกืžื”, ื•ื ืคื— ืžืขืจื›ืช Windows ื”ืžื•ืฆืคืŸ ื™ื•ืชืงืŸ ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื”.

ืžืคื”/ื”ืจ ื ืคื— ืžืขืจื›ืช VeraCrypt ื‘ืคืงื•ื“ืช cryptsetup

cryptsetup open --veracrypt --tcrypt-system --type tcrypt /dev/sdaX Windows_crypt
mount /dev/mapper/Windows_crypt /mnt

ืžืคื”/ื”ืจ ืžื—ื™ืฆืช VeraCrypt/ืžื™ื›ืœ ื‘ืคืงื•ื“ื” cryptsetup

cryptsetup open --veracrypt --type tcrypt /dev/sdaY test_crypt
mount /dev/mapper/test_crypt /mnt

ื‘ืžืงื•ื ื›ื™ื ื•ื™, ื ื•ืกื™ืฃ (ืกืงืจื™ืคื˜ ืœื”ืคืขืœื”) ืืžืฆืขื™ ืื—ืกื•ืŸ ื‘ืžืขืจื›ืช ืขื ืžืขืจื›ืช ื”ื”ืคืขืœื” Windows ื•ื“ื™ืกืง ntfs ืžื•ืฆืคืŸ ืœื•ื’ื™ ืœืืชื—ื•ืœ GNU/Linux

ืฆื•ืจ ืกืงืจื™ืคื˜ ื•ืฉืžื•ืจ ืื•ืชื• ื‘-~/VeraOpen.sh

printf 'Ym9i' | base64 -d | cryptsetup open --veracrypt --tcrypt-system --type tcrypt /dev/sda3 Windows_crypt && mount /dev/mapper/Windows_crypt /media/Winda7 #ะดะตะบะพะดะธั€ัƒะตะผ ะฟะฐั€ะพะปัŒ ะธะท base64 (bob) ะธ ะพั‚ะฟั€ะฐะฒะปัะตะผ ะตะณะพ ะฝะฐ ะทะฐะฟั€ะพั ะฒะฒะพะดะฐ ะฟะฐั€ะพะปั ะฟั€ะธ ะผะพะฝั‚ะธั€ะพะฒะฐะฝะธะธ ัะธัั‚ะตะผะฝะพะณะพ ะดะธัะบะฐ ะžะก Windows.
printf 'Ym9i' | base64 -d | cryptsetup open --veracrypt --type tcrypt /dev/sda1 ntfscrypt && mount /dev/mapper/ntfscrypt /media/ะšะพะฝั‚ะตะนะฝะตั€ะั‚ั„ั #ะฐะฝะฐะปะพะณะธั‡ะฝะพ, ะฝะพ ะผะพะฝั‚ะธั€ัƒะตะผ ะปะพะณะธั‡ะตัะบะธะน ะดะธัะบ ntfs.

ืื ื• ืžืคื™ืฆื™ื ืืช ื”ื–ื›ื•ื™ื•ืช "ื”ื ื›ื•ื ื•ืช":

sudo chmod 100 /VeraOpen.sh

ืฆื•ืจ ืฉื ื™ ืงื‘ืฆื™ื ื–ื”ื™ื (ืื•ืชื• ืฉื!) ื‘-/etc/rc.local ื•-~/etc/init.d/rc.local
ืžื™ืœื•ื™ ื”ืงื‘ืฆื™ื

#!/bin/sh -e
#
# rc.local
#
# This script is executed at the end of each multiuser runlevel.
# Make sure that the script will ยซexit 0ยป on success or any other
# value on error.
#
# In order to enable or disable this script just change the execution
# bits.
#
# By default this script does nothing.

sh -c "sleep 1 && '/VeraOpen.sh'" #ะฟะพัะปะต ะทะฐะณั€ัƒะทะบะธ ะžะก, ะถะดั‘ะผ ~ 1ั ะธ ั‚ะพะปัŒะบะพ ะฟะพั‚ะพะผ ะผะพะฝั‚ะธั€ัƒะตะผ ะดะธัะบะธ.
exit 0

ืื ื• ืžืคื™ืฆื™ื ืืช ื”ื–ื›ื•ื™ื•ืช "ื”ื ื›ื•ื ื•ืช":

sudo chmod 100 /etc/rc.local && sudo chmod 100 /etc/init.d/rc.local 

ื–ื”ื•, ื›ืขืช ื‘ืขืช ื˜ืขื™ื ืช GNU/Linux ืื™ื ื ื• ืฆืจื™ื›ื™ื ืœื”ื–ื™ืŸ ืกื™ืกืžืื•ืช ื›ื“ื™ ืœื”ืขืœื•ืช ื“ื™ืกืงื™ ntfs ืžื•ืฆืคื ื™ื, ื”ื“ื™ืกืงื™ื ืžื•ืชืงื ื™ื ืื•ื˜ื•ืžื˜ื™ืช.

ื”ืขืจื” ื‘ืงืฆืจื” ืขืœ ืžื” ืฉืžืชื•ืืจ ืœืขื™ืœ ื‘ืคืกืงื” E1 ืฉืœื‘ ืื—ืจ ืฉืœื‘ (ืื‘ืœ ืขื›ืฉื™ื• ืขื‘ื•ืจ OS GNU/Linux)
1) ืฆื•ืจ ืืžืฆืขื™ ืื—ืกื•ืŸ ื‘-fs ext4 > 4gb (ืขื‘ื•ืจ ืงื•ื‘ืฅ) ืœื™ื ื•ืงืก ื‘-Veracrypt [Cryptbox].
2) ื”ืคืขืœ ืžื—ื“ืฉ ืœ-USB ื—ื™.
3) ~$ cryptsetup ืคืชื•ื— /dev/sda7 Lunux #ืžื™ืคื•ื™ ืžื—ื™ืฆื” ืžื•ืฆืคื ืช.
4) ~$ mount /dev/mapper/Linux /mnt #ื”ืขืœื” ืืช ื”ืžื—ื™ืฆื” ื”ืžื•ืฆืคื ืช ืœ-/mnt.
5) ~$ mkdir mnt2 #ื™ืฆื™ืจืช ืกืคืจื™ื™ื” ืœื’ื™ื‘ื•ื™ ืขืชื™ื“ื™.
6) ~$ cryptsetup open โ€”veracrypt โ€”type tcrypt ~/CryptoBox CryptoBox && mount /dev/mapper/CryptoBox /mnt2 #ืžืคื• ืืžืฆืขื™ ืื—ืกื•ืŸ ืฉืœ Veracrypt ื‘ืฉื "CryptoBox" ื•ื”ืขืœื• ืืช ื”-CryptoBox ืœ-/mnt2.
7) ~$ rsync -avlxhHX โ€”progress /mnt /mnt2/ #ืคืขื•ืœืช ื’ื™ื‘ื•ื™ ืฉืœ ืžื—ื™ืฆื” ืžื•ืฆืคื ืช ืœื ืคื— Veracrypt ืžื•ืฆืคืŸ.

(ื .ื‘/ ืชืฉื•ืžืช ืœื‘! ืื ืืชื” ืžืขื‘ื™ืจ GNU/Linux ืžื•ืฆืคืŸ ืžืืจื›ื™ื˜ืงื˜ื•ืจื”/ืžื›ื•ื ื” ืื—ืช ืœืื—ืจืช, ืœืžืฉืœ, Intel > AMD (ื›ืœื•ืžืจ, ืคืจื™ืกืช ื’ื™ื‘ื•ื™ ืžืžื—ื™ืฆื” ืžื•ืฆืคื ืช ืื—ืช ืœืžื—ื™ืฆืช Intel > AMD ืžื•ืฆืคื ืช ืื—ืจืช), ืืœ ืชืฉื›ื— ืœืื—ืจ ื”ืขื‘ืจืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืžื•ืฆืคื ืช, ืขืจื•ืš ืืช ืžืคืชื— ื”ืชื—ืœื™ืฃ ื”ืกื•ื“ื™ ื‘ืžืงื•ื ืืช ื”ืกื™ืกืžื”, ืื•ืœื™. ื”ืžืคืชื— ื”ืงื•ื“ื ~/etc/skey - ืœื ื™ืชืื™ื ื™ื•ืชืจ ืœืžื—ื™ืฆื” ืžื•ืฆืคื ืช ืื—ืจืช, ื•ืœื ื›ื“ืื™ ืœื™ืฆื•ืจ ืžืคืชื— ื—ื“ืฉ "cryptsetup luksAddKey" ืžืชื—ืช ืœ-chroot - ืชื™ืชื›ืŸ ืชืงืœื”, ืจืง ื‘-~/etc/crypttab ืฆื™ื™ืŸ ื‘ืžืงื•ื "/etc/skey" ื‘ืื•ืคืŸ ื–ืžื ื™ "none" ", ืœืื—ืจ ื‘ื•ื˜ ืžื—ื“ืฉ ื•ื›ื ื™ืกื” ืœืžืขืจื›ืช ื”ื”ืคืขืœื”, ืฆื•ืจ ืžื—ื“ืฉ ืืช ืžืคืชื— ื”ืชื• ื”ื›ืœืœื™ ื”ืกื•ื“ื™ ืฉืœืš ืฉื•ื‘).

ื‘ืชื•ืจ ื•ืชื™ืงื™ IT, ื–ื›ืจื• ืœื‘ืฆืข ื’ื™ื‘ื•ื™ื™ื ื‘ื ืคืจื“ ืฉืœ ื”ื›ื•ืชืจื•ืช ืฉืœ ืžื—ื™ืฆื•ืช ืžืขืจื›ืช ื”ื”ืคืขืœื” Windows/Linux ื”ืžื•ืฆืคื ื•ืช, ืื—ืจืช ื”ื”ืฆืคื ื” ืชืคื ื” ื ื’ื“ื›ื.
ื‘ืฉืœื‘ ื–ื”, ื”ื’ื™ื‘ื•ื™ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืžื•ืฆืคื ืช ื”ื•ืฉืœื.

[F] ื”ืชืงืคื” ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ GRUB2

ืคืจื˜ื™ืืื ื”ื’ื ืช ืขืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืฉืœืš ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื•/ืื• ืื™ืžื•ืช (ืจืื” ื ืงื•ื“ื” C6.), ืื– ื–ื” ืœื ื™ื’ืŸ ืžืคื ื™ ื’ื™ืฉื” ืคื™ื–ื™ืช. ื ืชื•ื ื™ื ืžื•ืฆืคื ื™ื ืขื“ื™ื™ืŸ ืœื ื™ื”ื™ื• ื ื’ื™ืฉื™ื, ืื‘ืœ ื”ื”ื’ื ื” ืชืขืงื•ืฃ (ืืคืก ืืช ื”ื’ื ืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช) GRUB2 ืžืืคืฉืจ ืœื ื‘ืœ ืกื™ื™ื‘ืจ ืœื”ื—ื“ื™ืจ ืืช ื”ืงื•ื“ ืฉืœื• ืœืžื˜ืขืŸ ื”ืืชื—ื•ืœ ืžื‘ืœื™ ืœืขื•ืจืจ ื—ืฉื“ (ืืœื ืื ื”ืžืฉืชืžืฉ ืขื•ืงื‘ ื‘ืื•ืคืŸ ื™ื“ื ื™ ืื—ืจ ืžืฆื‘ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ, ืื• ืžื’ื™ืข ืขื ืงื•ื“ ืกืงืจื™ืคื˜ ืฉืจื™ืจื•ืชื™ ื—ื–ืง ืžืฉืœื• ืขื‘ื•ืจ grub.cfg).

ืืœื’ื•ืจื™ืชื ืชืงื™ืคื”. ืคึผื•ึนืœึตืฉื

* ืืชื—ื•ืœ ืžื—ืฉื‘ ืž-USB ื—ื™. ื›ืœ ืฉื™ื ื•ื™ (ืžืคืจ) ืงื‘ืฆื™ื ื™ื•ื“ื™ืขื• ืœื‘ืขืœื™ื ื”ืืžื™ืชื™ ืฉืœ ื”ืžื—ืฉื‘ ืขืœ ื”ื—ื“ื™ืจื” ืœื˜ื•ืขืŸ ื”ืืชื—ื•ืœ. ืื‘ืœ ื”ืชืงื ื” ืžื—ื“ืฉ ืคืฉื•ื˜ื” ืฉืœ โ€‹โ€‹GRUB2 ืชื•ืš ืฉืžื™ืจื” ืขืœ grub.cfg (ื•ื”ื™ื›ื•ืœืช ืฉืœืื—ืจ ืžื›ืŸ ืœืขืจื•ืš ืื•ืชื•) ื™ืืคืฉืจ ืœืชื•ืงืฃ ืœืขืจื•ืš ื›ืœ ืงื•ื‘ืฅ (ื‘ืžืฆื‘ ื–ื”, ื‘ืขืช ื˜ืขื™ื ืช GRUB2, ื”ืžืฉืชืžืฉ ื”ืืžื™ืชื™ ืœื ื™ืงื‘ืœ ื”ื•ื“ืขื”. ื”ืกื˜ื˜ื•ืก ื–ื”ื” <0>)
* ืžืขืœื” ืžื—ื™ืฆื” ืœื ืžื•ืฆืคื ืช, ืžืื—ืกืŸ ืืช "/mnt/boot/grub/grub.cfg".
* ืžืชืงื™ืŸ ืžื—ื“ืฉ ืืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ (ื”ืกืจืช "perskey" ืžืชืžื•ื ืช core.img)

grub-install --force --root-directory=/mnt /dev/sda6

* ืžื—ื–ื™ืจ ืืช "grub.cfg" > "/mnt/boot/grub/grub.cfg", ืขื•ืจืš ืื•ืชื• ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืœื“ื•ื’ืžื”, ื”ื•ืกืคืช ื”ืžื•ื“ื•ืœ ืฉืœืš "keylogger.mod" ืœืชื™ืงื™ื™ื” ืขื ืžื•ื“ื•ืœื™ ื”ื˜ืขื™ื ื”, ื‘-"grub.cfg" > ืฉื•ืจื” "Insmod keylogger". ืื•, ืœืžืฉืœ, ืื ื”ืื•ื™ื‘ ืขืจืžื•ืžื™, ืื– ืœืื—ืจ ื”ืชืงื ื” ืžื—ื“ืฉ ืฉืœ GRUB2 (ื›ืœ ื”ื—ืชื™ืžื•ืช ื ืฉืืจื•ืช ื‘ืžืงื•ืžืŸ) ื”ื•ื ื‘ื•ื ื” ืืช ืชืžื•ื ืช GRUB2 ื”ืจืืฉื™ืช ื‘ืืžืฆืขื•ืช "grub-mkimage ืขื ืืคืฉืจื•ืช (-c)." ื”ืืคืฉืจื•ืช "-c" ืชืืคืฉืจ ืœืš ืœื˜ืขื•ืŸ ืืช ื”ืชืฆื•ืจื” ืฉืœืš ืœืคื ื™ ื˜ืขื™ื ืช ื”-"grub.cfg" ื”ืจืืฉื™. ื”ืชืฆื•ืจื” ื™ื›ื•ืœื” ืœื”ื™ื•ืช ืžื•ืจื›ื‘ืช ืžืฉื•ืจื” ืื—ืช ื‘ืœื‘ื“: ื ื™ืชื•ื‘ ืžื—ื“ืฉ ืœื›ืœ "modern.cfg", ืžืขื•ืจื‘ื‘, ืœืžืฉืœ, ืขื ~400 ืงื‘ืฆื™ื (ืžื•ื“ื•ืœื™ื+ื—ืชื™ืžื•ืช) ื‘ืชื™ืงื™ื™ื” "/boot/grub/i386-pc". ื‘ืžืงืจื” ื–ื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ื›ื ื™ืก ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื•ืœื˜ืขื•ืŸ ืžื•ื“ื•ืœื™ื ืžื‘ืœื™ ืœื”ืฉืคื™ืข ืขืœ "/boot/grub/grub.cfg", ื’ื ืื ื”ืžืฉืชืžืฉ ื”ื—ื™ืœ "hashsum" ืขืœ ื”ืงื•ื‘ืฅ ื•ื”ืฆื™ื’ ืื•ืชื• ื‘ืื•ืคืŸ ื–ืžื ื™ ืขืœ ื”ืžืกืš.
ืชื•ืงืฃ ืœื ื™ืฆื˜ืจืš ืœืคืจื•ืฅ ืืช ื”ื›ื ื™ืกื”/ืกื™ืกืžื” ืฉืœ ืžืฉืชืžืฉ ื”ืขืœ GRUB2; ื”ื•ื ืจืง ื™ืฆื˜ืจืš ืœื”ืขืชื™ืง ืืช ื”ืฉื•ืจื•ืช (ืื—ืจืื™ ืขืœ ื”ืื™ืžื•ืช) "/boot/grub/grub.cfg" ืœ-"modern.cfg" ืฉืœืš

set superusers="root"
password_pbkdf2 root grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8

ื•ื‘ืขืœ ื”ืžื—ืฉื‘ ืขื“ื™ื™ืŸ ื™ืื•ืฉืจ ื›ืžืฉืชืžืฉ ื”ืขืœ GRUB2.

ื˜ืขื™ื ืช ืฉืจืฉืจืช (ืžื˜ืขืŸ ื”ืืชื—ื•ืœ ื˜ื•ืขืŸ ื˜ื•ืขืŸ ืืชื—ื•ืœ ืื—ืจ), ื›ืคื™ ืฉื›ืชื‘ืชื™ ืœืžืขืœื”, ืœื ื”ื’ื™ื•ื ื™ (ื–ื” ื ื•ืขื“ ืœืžื˜ืจื” ืื—ืจืช). ืœื ื ื™ืชืŸ ืœื˜ืขื•ืŸ ื˜ื•ืขืŸ ืืชื—ื•ืœ ืžื•ืฆืคืŸ ืขืงื‘ BIOS (ืืชื—ื•ืœ ื”ืฉืจืฉืจืช ืžื•ืคืขืœ ืžื—ื“ืฉ GRUB2 > GRUB2 ืžื•ืฆืคืŸ, ืฉื’ื™ืื”!). ืขื ื–ืืช, ืื ืืชื” ืขื“ื™ื™ืŸ ืžืฉืชืžืฉ ื‘ืจืขื™ื•ืŸ ืฉืœ ื˜ืขื™ื ืช ืฉืจืฉืจืช, ืืชื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ื‘ื˜ื•ื— ืฉื–ื• ื”ืžื•ืฆืคื ืช ืฉื ื˜ืขื ืช. (ืœื ืžื•ื“ืจื ื™ื–ืฆื™ื”) "grub.cfg" ืžื”ืžื—ื™ืฆื” ื”ืžื•ืฆืคื ืช. ื•ื–ื• ื’ื ืชื—ื•ืฉืช ื‘ื™ื˜ื—ื•ืŸ ืžื–ื•ื™ืคืช, ื›ื™ ื›ืœ ืžื” ืฉืžืฆื•ื™ืŸ ื‘-"grub.cfg" ื”ืžื•ืฆืคืŸ (ื˜ืขื™ื ืช ืžื•ื“ื•ืœ) ืžืชื•ื•ืกืคืช ืœืžื•ื“ื•ืœื™ื ืฉื ื˜ืขื ื™ื ืž-GRUB2 ืœื ืžื•ืฆืคืŸ.

ืื ื‘ืจืฆื•ื ืš ืœื‘ื“ื•ืง ื–ืืช, ื”ืงืฆื•/ื”ืฆืคื™ืŸ ืžื—ื™ืฆื” ื ื•ืกืคืช sdaY, ื”ืขืชืง ืืช GRUB2 ืืœื™ื” (ืคืขื•ืœืช ื”ืชืงื ืช grub ืขืœ ืžื—ื™ืฆื” ืžื•ืฆืคื ืช ืื™ื ื” ืืคืฉืจื™ืช) ื•ื‘-"grub.cfg" (ืชืฆื•ืจื” ืœื ืžื•ืฆืคื ืช) ืœืฉื ื•ืช ืงื•ื•ื™ื ื›ืืœื”

menuentry 'GRUBx2' --class parrot --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-simple-382111a2-f993-403c-aa2e-292b5eac4780' {
load_video
insmod gzio
if [x$grub_platform = xxen]; ื•ืื– insmod xzio; insmod lzopio; fi
part_msdos insmod
insmod cryptodisk
insmod lux
insmod gcry_twofish
insmod gcry_twofish
insmod gcry_sha512
insmod ext2
cryptomount -u 15c47d1c4bd34e5289df77bcf60ee838
set root=โ€™cryptouuid/15c47d1c4bd34e5289df77bcf60ee838โ€ฒ
ืจื’ื™ืœ /boot/grub/grub.cfg
}

ืงื•ื•ื™ื
* insmod - ื˜ืขื™ื ืช ื”ืžื•ื“ื•ืœื™ื ื”ื“ืจื•ืฉื™ื ืœืขื‘ื•ื“ื” ืขื ื“ื™ืกืง ืžื•ืฆืคืŸ;
* GRUBx2 - ืฉื ื”ืฉื•ืจื” ื”ืžื•ืฆื’ืช ื‘ืชืคืจื™ื˜ ื”ืืชื—ื•ืœ ืฉืœ GRUB2;
* cryptomount -u 15c47d1c4bd34e5289df77bcf60ee838 -ืจืื”. fdisk -l (sda9);
* ื”ื’ื“ืจ ืฉื•ืจืฉ - ื”ืชืงืŸ ืฉื•ืจืฉ;
* ืจื’ื™ืœ /boot/grub/grub.cfg - ืงื•ื‘ืฅ ืชืฆื•ืจื” ื‘ืจ ื”ืคืขืœื” ืขืœ ืžื—ื™ืฆื” ืžื•ืฆืคื ืช.

ื”ื‘ื™ื˜ื—ื•ืŸ ื‘ื›ืš ืฉื–ื”ื• "grub.cfg" ื”ืžื•ืฆืคืŸ ืฉื ื˜ืขืŸ ื”ื•ื ืชื’ื•ื‘ื” ื—ื™ื•ื‘ื™ืช ืœื”ื–ื ืช ื”ืกื™ืกืžื”/ื‘ื™ื˜ื•ืœ ื”ื ืขื™ืœื” ืฉืœ "sdaY" ื‘ืขืช ื‘ื—ื™ืจืช ื”ืฉื•ืจื” "GRUBx2" ื‘ืชืคืจื™ื˜ GRUB.

ื›ืฉืขื•ื‘ื“ื™ื ื‘-CLI, ื›ื“ื™ ืœื ืœื”ืชื‘ืœื‘ืœ (ื•ื‘ื“ื•ืง ืื ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” "ื”ื’ื“ืจ ืฉื•ืจืฉ" ืขื‘ื“), ืฆื•ืจ ืงื‘ืฆื™ ืืกื™ืžื•ืŸ ืจื™ืงื™ื, ืœืžืฉืœ, ื‘ืงื˜ืข ื”ืžื•ืฆืคืŸ "/shifr_grub", ื‘ืงื˜ืข ื”ืœื ืžื•ืฆืคืŸ "/noshifr_grub". ื‘ื•ื“ืง ื‘-CLI

cat /Tab-Tab

ื›ืคื™ ืฉืฆื•ื™ืŸ ืœืขื™ืœ, ื–ื” ืœื ื™ืขื–ื•ืจ ื ื’ื“ ื”ื•ืจื“ืช ืžื•ื“ื•ืœื™ื ื–ื“ื•ื ื™ื™ื ืื ืžื•ื“ื•ืœื™ื ื›ืืœื” ืžื’ื™ืขื™ื ืœืžื—ืฉื‘ ื”ืื™ืฉื™ ืฉืœืš. ืœื“ื•ื’ืžื”, ืžืงืœื“ืช ืฉื™ื•ื›ืœ ืœืฉืžื•ืจ ื”ืงืฉื•ืช ืœืงื•ื‘ืฅ ื•ืœืขืจื‘ื‘ ืื•ืชื• ืขื ืงื‘ืฆื™ื ืื—ืจื™ื ื‘-"~/i386" ืขื“ ืฉื™ื•ืจื“ ืขืœ ื™ื“ื™ ืชื•ืงืฃ ืขื ื’ื™ืฉื” ืคื™ื–ื™ืช ืœืžื—ืฉื‘ ื”ืื™ืฉื™.

ื”ื“ืจืš ื”ืงืœื” ื‘ื™ื•ืชืจ ืœื•ื•ื“ื ืฉื”ื”ื’ื ื” ืขืœ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืคื•ืขืœืช ื‘ืื•ืคืŸ ืคืขื™ืœ (ืœื ืžืื•ืคืก), ื•ืืฃ ืื—ื“ ืœื ืคืœืฉ ืœืžื˜ืขืŸ ื”ืืชื—ื•ืœ, ื”ื–ืŸ ืืช ื”ืคืงื•ื“ื” ื‘-CLI

list_trusted

ื‘ืชื’ื•ื‘ื” ืื ื• ืžืงื‘ืœื™ื ืขื•ืชืง ืฉืœ ื”"perskey" ืฉืœื ื•, ืื• ืฉืื™ื ื ื• ืžืงื‘ืœื™ื ื“ื‘ืจ ืื ืื ื• ืžื•ืชืงืคื™ื (ืขืœื™ืš ืœืกืžืŸ ื’ื "set check_signatures=enforce").
ื—ื™ืกืจื•ืŸ ืžืฉืžืขื•ืชื™ ืฉืœ ืฉืœื‘ ื–ื” ื”ื•ื ื”ื–ื ืช ืคืงื•ื“ื•ืช ื‘ืื•ืคืŸ ื™ื“ื ื™. ืื ืชื•ืกื™ืฃ ืืช ื”ืคืงื•ื“ื” ื”ื–ื• ืœ-"grub.cfg" ื•ืชื’ืŸ ืขืœ ื”ืชืฆื•ืจื” ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช, ืื– ื”ืคืœื˜ ื”ืจืืฉื•ื ื™ ืฉืœ ืชืžื•ื ืช ื”ืžืฆื‘ ืขืœ ื”ืžืกืš ืงืฆืจ ืžื“ื™ ื‘ืชื–ืžื•ืŸ, ื•ื™ื™ืชื›ืŸ ืฉืœื ื™ื”ื™ื” ืœืš ื–ืžืŸ ืœืจืื•ืช ืืช ื”ืคืœื˜ ืœืื—ืจ ื˜ืขื™ื ืช GRUB2 .
ืื™ืŸ ืœืžื™ ื‘ืžื™ื•ื—ื“ ืœื˜ืขื•ืŸ ื˜ืขื ื•ืช: ื”ื™ื–ื ื‘ืฉืœื• ืชื™ืขื•ื“ ืกืขื™ืฃ 18.2 ืžืฆื”ื™ืจ ื‘ืื•ืคืŸ ืจืฉืžื™

"ืฉื™ื ืœื‘ ืฉืืคื™ืœื• ืขื ื”ื’ื ืช ืกื™ืกืžื” ืฉืœ GRUB, GRUB ืขืฆืžื• ืœื ื™ื›ื•ืœ ืœืžื ื•ืข ืžืžื™ืฉื”ื• ืขื ื’ื™ืฉื” ืคื™ื–ื™ืช ืœืžื›ื•ื ื” ืœืฉื ื•ืช ืืช ืชืฆื•ืจืช ื”ืงื•ืฉื—ื” ืฉืœ ื”ืžื—ืฉื‘ (ืœืžืฉืœ, Coreboot ืื• BIOS) ื›ื“ื™ ืœื’ืจื•ื ืœืžื›ื•ื ื” ืœืืชื—ืœ ืžื”ืชืงืŸ ืื—ืจ (ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ืชื•ืงืฃ). GRUB ื”ื•ื ื‘ืžืงืจื” ื”ื˜ื•ื‘ ืจืง ื—ื•ืœื™ื” ืื—ืช ื‘ืฉืจืฉืจืช ืืชื—ื•ืœ ืžืื•ื‘ื˜ื—ืช."

GRUB2 ืขืžื•ืก ืžื“ื™ ื‘ืคื•ื ืงืฆื™ื•ืช ืฉื™ื›ื•ืœื•ืช ืœืชืช ืชื—ื•ืฉืช ืื‘ื˜ื—ื” ืžื–ื•ื™ืคืช, ื•ื”ืคื™ืชื•ื— ืฉืœื• ื›ื‘ืจ ืขืœื” ืขืœ MS-DOS ืžื‘ื—ื™ื ืช ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช, ืื‘ืœ ื”ื•ื ืจืง ื˜ื•ืขืŸ ืืชื—ื•ืœ. ื–ื” ืžืฆื—ื™ืง ืฉ-GRUB2 - "ืžื—ืจ" ื™ื›ื•ืœ ืœื”ืคื•ืš ืœืžืขืจื›ืช ื”ื”ืคืขืœื”, ื•ืœืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืฉืœ GNU/Linux ื”ื ื™ืชื ื•ืช ืœืืชื—ื•ืœ ืขื‘ื•ืจื”.

ืกืจื˜ื•ืŸ ืงืฆืจ ืขืœ ืื™ืš ืื™ืคืกืชื™ ืืช ื”ื’ื ืช ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ GRUB2 ื•ื”ืฆื”ืจืชื™ ืขืœ ื”ื—ื“ื™ืจื” ืฉืœื™ ืœืžืฉืชืžืฉ ืืžื™ืชื™ (ื”ืคื—ื“ืชื™ ืื•ืชืš, ืื‘ืœ ื‘ืžืงื•ื ืžื” ืฉืžื•ืฆื’ ื‘ืกืจื˜ื•ืŸ, ืืชื” ื™ื›ื•ืœ ืœื›ืชื•ื‘ ืงื•ื“ ืฉืจื™ืจื•ืชื™ ืœื ืžื–ื™ืง/.mod).

ืžืกืงื ื•ืช:

1) ืงืœ ื™ื•ืชืจ ืœื™ื™ืฉื ื”ืฆืคื ืช ืžืขืจื›ืช ื—ืกื™ืžื” ืขื‘ื•ืจ Windows, ื•ื”ื’ื ื” ื‘ืืžืฆืขื•ืช ืกื™ืกืžื” ืื—ืช ื ื•ื—ื” ื™ื•ืชืจ ืžื”ื’ื ื” ื‘ืืžืฆืขื•ืช ืžืกืคืจ ืกื™ืกืžืื•ืช ืขื ื”ืฆืคื ืช ืžืขืจื›ืช ื—ืกื™ืžืช GNU/Linux, ืœืžืขืŸ ื”ื”ื’ื™ื ื•ืช: ื”ืื—ืจื•ื ื” ื”ื™ื ืื•ื˜ื•ืžื˜ื™ืช.

2) ื›ืชื‘ืชื™ ืืช ื”ืžืืžืจ ื›ืจืœื•ื•ื ื˜ื™ ื•ืžืคื•ืจื˜ ืคืฉื•ื˜ ืžื“ืจื™ืš ืœื”ืฆืคื ืช ื“ื™ืกืง ืžืœื VeraCrypt/LUKS ืขืœ ื‘ื™ืช ืื—ื“ ืฉืœ ื”ืžื›ื•ื ื”, ืฉื”ื™ื ืœืœื ืกืคืง ื”ื˜ื•ื‘ื” ื‘ื™ื•ืชืจ ื‘-RuNet (IMHO). ื”ืžื“ืจื™ืš ื”ื•ื ื‘ืื•ืจืš ืฉืœ ื™ื•ืชืจ ืž-50 ืืœืฃ ืชื•ื•ื™ื, ื›ืš ืฉื”ื•ื ืœื ื›ื™ืกื” ื›ืžื” ืคืจืงื™ื ืžืขื ื™ื™ื ื™ื: ืงืจื™ืคื˜ื•ื’ืจืคื™ื ืฉื ืขืœืžื™ื/ื ืฉืืจื™ื ื‘ืฆืœ; ืขืœ ื”ืขื•ื‘ื“ื” ืฉื‘ืกืคืจื™ื ืฉื•ื ื™ื ืฉืœ GNU/Linux ื›ื•ืชื‘ื™ื ืžืขื˜/ืœื ื›ื•ืชื‘ื™ื ืขืœ ืงืจื™ืคื˜ื•ื’ืจืคื™ื”; ืขืœ ืกืขื™ืฃ 51 ืฉืœ ื”ื—ื•ืงื” ืฉืœ ื”ืคื“ืจืฆื™ื” ื”ืจื•ืกื™ืช; O ืจื™ืฉื•ื™/ืœึถืึฑืกื•ึนืจ ื”ืฆืคื ื” ื‘ืคื“ืจืฆื™ื” ื”ืจื•ืกื™ืช, ืขืœ ื”ืกื™ื‘ื” ืฉืืชื” ืฆืจื™ืš ืœื”ืฆืคื™ืŸ "ืฉื•ืจืฉ/ืืชื—ื•ืœ". ื”ืžื“ืจื™ืš ื”ืชื‘ืจืจ ื›ืžืจื—ื™ื‘ ืœืžื“ื™, ืืš ืžืคื•ืจื˜. (ืžืชืืจ ืืคื™ืœื• ืฉืœื‘ื™ื ืคืฉื•ื˜ื™ื), ื‘ืชื•ืจื•, ื–ื” ื™ื—ืกื•ืš ืœืš ื”ืจื‘ื” ื–ืžืŸ ื›ืฉืชื’ื™ืข ืœ"ื”ืฆืคื ื” ื”ืืžื™ืชื™ืช".

3) ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ื‘ื•ืฆืขื” ื‘-Windows 7 64; GNU/Linux Parrot 4x; GNU/Debian 9.0/9.5.

4) ื™ื™ืฉื ื”ืชืงืคื” ืžื•ืฆืœื—ืช ืขืœ ืฉืœื• ื˜ื•ืขืŸ ืืชื—ื•ืœ GRUB2.

5) ื”ื“ืจื›ื” ื ื•ืฆืจื” ื›ื“ื™ ืœืขื–ื•ืจ ืœื›ืœ ื”ืื ืฉื™ื ื”ืคืจื ื•ืื™ื“ื™ื ื‘ื—ื‘ืจ ื”ืขืžื™ื, ืฉื‘ื• ืขื‘ื•ื“ื” ืขื ื”ืฆืคื ื” ืžื•ืชืจืช ื‘ืจืžืช ื”ื—ืงื™ืงื”. ื•ื‘ืขื™ืงืจ ืœืžื™ ืฉืจื•ืฆื” ืœื”ืคืขื™ืœ ื”ืฆืคื ืช ื“ื™ืกืง ืžืœื ืžื‘ืœื™ ืœื”ืจื•ืก ืืช ื”ืžืขืจื›ื•ืช ื”ืžื•ื’ื“ืจื•ืช ืฉืœื”ื.

6) ืขื™ื‘ื“ ื•ืขื™ื“ื›ืŸ ืืช ื”ืžื“ืจื™ืš ืฉืœื™, ืฉืจืœื•ื•ื ื˜ื™ ื‘-2020.

[ื–] ืชื™ืขื•ื“ ืฉื™ืžื•ืฉื™

  1. ืžื“ืจื™ืš ืœืžืฉืชืžืฉ ืฉืœ TrueCrypt (ืคื‘ืจื•ืืจ 2012 RU)
  2. ืชื™ืขื•ื“ VeraCrypt
  3. /usr/share/doc/cryptsetup(-run) [ืžืฉืื‘ ืžืงื•ืžื™] (ืชื™ืขื•ื“ ืžืคื•ืจื˜ ืจืฉืžื™ ืขืœ ื”ื’ื“ืจืช ื”ืฆืคื ืช GNU/Linux ื‘ืืžืฆืขื•ืช cryptsetup)
  4. ื”ื’ื“ืจืช ืงืจื™ืคื˜ื” ืจืฉืžื™ืช ืฉืœ ืฉืืœื•ืช ื ืคื•ืฆื•ืช (ืชื™ืขื•ื“ ืงืฆืจ ืขืœ ื”ื’ื“ืจืช ื”ืฆืคื ืช GNU/Linux ื‘ืืžืฆืขื•ืช cryptsetup)
  5. ื”ืฆืคื ืช ืžื›ืฉื™ืจ LUKS (ืชื™ืขื•ื“ archlinux)
  6. ืชื™ืื•ืจ ืžืคื•ืจื˜ ืฉืœ ืชื—ื‘ื™ืจ cryptsetup (ื“ืฃ ืื™ืฉ ืงืฉืช)
  7. ืชื™ืื•ืจ ืžืคื•ืจื˜ ืฉืœ crypttab (ื“ืฃ ืื™ืฉ ืงืฉืช)
  8. ืชื™ืขื•ื“ ืจืฉืžื™ ืฉืœ GRUB2.

ืชื’ื™ื•ืช: ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื”, ื”ืฆืคื ืช ืžื—ื™ืฆื•ืช, ื”ืฆืคื ืช ื“ื™ืกืง ืžืœืื” ืฉืœ ืœื™ื ื•ืงืก, ื”ืฆืคื ืช ืžืขืจื›ืช ืžืœืื” LUKS1.

ืจืง ืžืฉืชืžืฉื™ื ืจืฉื•ืžื™ื ื™ื›ื•ืœื™ื ืœื”ืฉืชืชืฃ ื‘ืกืงืจ. ืœื”ืชื—ื‘ืจื‘ื‘ืงืฉื”.

ืืชื” ืžืฆืคื™ืŸ?

  • 17,1%ืื ื™ ืžืฆืคื™ืŸ ื›ืœ ืžื” ืฉืื ื™ ื™ื›ื•ืœ. ืื ื™ ืคืจื ื•ืื™ื“.14

  • 34,2%ืื ื™ ืžืฆืคื™ืŸ ืจืง ื ืชื•ื ื™ื ื—ืฉื•ื‘ื™ื.28

  • 14,6%ืœืคืขืžื™ื ืื ื™ ืžืฆืคื™ืŸ, ืœืคืขืžื™ื ืื ื™ ืฉื•ื›ื—.12

  • 34,2%ืœื, ืื ื™ ืœื ืžืฆืคื™ืŸ, ื–ื” ืœื ื ื•ื— ื•ื™ืงืจ.28

82 ืžืฉืชืžืฉื™ื ื”ืฆื‘ื™ืขื•. 22 ืžืฉืชืžืฉื™ื ื ืžื ืขื•.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”