×עך×××Ö·× ×××§× ×××××¢× ×¢ ×××× ×Š× ×€××-××סק ×¢× ×§×š×׀֌ש×Ö·× ××× RuNet V0.2.
ק×Öž××××× ×¡×ך×Ö·××¢×××¢:
[×] Windows 7 ס×ס××¢× ×€×ַךש׀֌×Ö·×š× ×¢× ×§×š×׀֌ש×Ö·× ×€×× ×× ××× ×¡××Ö·×××š× ×¡×ס××¢×;
[×] ×× × / ××× ×קס ס×ס××¢× ×€×ַךש׀֌×Ö·×š× ×¢× ×§×š×׀֌ש×Ö·× (××¢×××Ö·×) ××× ×¡××Ö·×××š× ×¡×ס××¢× (×ַך××Ö·× ×עךע×× × / ש×××××);
[C] GRUB2 ק×Ö·× ×€×××עך××ש×Ö·×, ××Öž×Öž×××Öž×Ö·×עך ש××¥ ××× ××××××Ö·× ×ס×××¢ / ×Öž××¢× ××ַק××ש×Ö·× / ××ַש×× ×;
[×] ס×ך××€ÖŒ×× × - ׊עש×עך×× × ×€×× ×Ö·× ×¢× ×§×š××€ÖŒ××× ××Ö·××;
[E] ×× ×××עךס×Ö·× ××ַק×Ö·×€ÖŒ ×€×× ×× ×§×š××€ÖŒ××× ×ַס;
[F] ××Ö·×€×Ö·×× ×Š×× - GRUB6 ××Öž×Öž×××Öž×Ö·×עך;
[×] × ×׊×ק ××ַק××××¢× ×××ש×Ö·×.
ââââ ס××¢××¢ ×€×× ââ# ׊××עך 40# :
âââ⌠Windows 7 ××× ×¡××Ö·×××š× - ×€×× ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·×, × ×× ×€×ַך××֞ך××;
âââ⌠GNU/Linux ××× ×¡××Ö·×××š× (××¢×××Ö·× ××× ×עך××××Ö·× ××ס×ך××××ש×Ö·× ×) - ×€×× ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·×, × ×× ×€×ַך××֞ך××(/, ×ַך××Ö·× ×עךע×× × / ש×××××; ××ס×××Ö·××);
âââ⌠׀ך××Ö· ××Öž×Öž×××Öž×Ö·×עךס: VeraCrypt ××Öž×Öž×××Öž×Ö·×עך ××× ××× ×¡××Ö·×××š× ××× ×× MBR, GRUB2 ××Öž×Öž×××Öž×Ö·×עך ××× ××× ×¡××Ö·×××š× ××× ×× ×¢×§×¡××¢× ××¢× ×Š×¢×××××× ×;
âââ⌠ק××× ×ַס ××Ö·× ××Öž× ××ך×× × / ך××× ×¡××Ö·×××Ö·×××Öž× ×€×ך××× ××;
âââ⌠קך××€ÖŒ××Öž×ך×Ö·×€×ק ×××××××××š× ××¢× ×׊×: ××עך×ַקך××€ÖŒ×; Cryptsetup; GnuPG; Seahorse; Hashdeep; GRUB2 ××× ×€×š×× / ׀ך××.
×× ××××× ×¡××¢××¢ ×××× ×¡×Ö·×××× ×× ×€ÖŒ×š×Öž×××¢× ×€×× "××××Ö·× ×©××××× ×Š× ×Ö· ××××¥ ×€×֞ך", ×Ö·××Ö·×× ××ך ×Š× ××¢× ××¡× ×× ×§×š××€ÖŒ××× ×ַס Windows / ××× ×קס ××× ×××¢×§×¡× ××Ö·×× ×××š× ×Ö· "×¢× ×§×š××€ÖŒ××× ×§×Ö·× ×Ö·×" ×€×× ×××× ×ַס ×Š× ×× ×עך×.
×€ÖŒ××¡× ×©××××× ×¡×ך (×××× ×¢×š ×€×× ×× ×֞׀֌׊×עס):
- ×××ס××¢×ך××× ××××£ ×× ××ַש××;
- ××Öž×××× × ×× VeraCrypt ××Öž×Öž×××Öž×Ö·×עך (×ַך××Ö·× ×× ×š××××ק ×€ÖŒ×ַך×Öž× ×××¢× ×€×֞ך××¢×Š× ×Š× ×©××××× Windows 7);
- ×ך×× ×××¢× ×× "עסק" ש×××¡× ×××¢× ××Öž×× ×× GRUB2 ש××××× ××Öž××עך;
- GRUB2 ש××××× ××Öž××עך (סע×עק×××š× ×€×ַךש׀֌ך××××× × / GNU / ××× ×קס / CLI), ×××¢× ××Ö·×š×€× ×Öž××¢× ××ַק××ש×Ö·× ×€×× ×× GRUB2 ס×׀֌עך×סעך ;
- × ×Öž× ×׊××× ×Öž××¢× ××ַק××ש×Ö·× ××× ×¡×¢×עק׊××¢ ×€×× ââ×× ×€×ַךש׀֌ך××××× ×, ××ך ×××¢× ××Ö·×š×€Ö¿× ×Š× ×ַך××Ö·× ×Ö· ×€ÖŒ×ַסס׀ך×ַסע ×Š× ×׀ש×××¡× "/boot/initrd.img";
- × ×Öž× ×ַך××Ö·× ××¢×ת-׀ך×× ×€ÖŒ×ַס××עך××, GRUB2 ×××¢× "×€×Öž×עך×" ×Ö· ×€ÖŒ×ַך×Öž× ×€ÖŒ×Öž××׊××¢ (×ך××, ××××Öž×ס ×€ÖŒ×ַך×Öž× ×Öž×עך GNU / Linux ××Ö·× ×׊עך ×ש××× ×€ÖŒ×ַך×Öž× - × ×× ××Ö·×ך×Ö·×××) ×Š× ×׀ש×××¡× ××× ×©××××× GNU / Linux OS, ×Öž×עך ×Öž××Ö·××Ö·××ק ס×Ö·×ס××××ש×Ö·× ×€×× ×Ö· ס×× ×©×××¡× (׊×××× ×€ÖŒ×ַס××עך×× + ש××ס×, ×Öž×עך ×€ÖŒ×ַך×Öž× + ש××ס×);
- ×€×× ×ך×××¡× ××ק ×× ×ך××ש×Ö·× ××× ×× GRUB2 ק×Ö·× ×€×××עך××ש×Ö·× ×××¢× ×€×š××š× ×× GNU/Linux ש××××× ×€ÖŒ×š×֞׊עס.
×ך×Ö·××Ö·×ס×Ö·×? ×××, ××Öž×× ××× ×× ×Öž××Ö·×××× ×× ×€ÖŒ×š×ַסעס×Ö·×.
×××¢× ×€ÖŒ×ַך××ש×Ö·× ×× × ×Ö· ש××עך ×€×֞ך (MBR ××ש) × ×€ÖŒ××¡× ×§×¢× ×¢× ××Öž×× × ×× ×עך ××× 4 ××××€ÖŒ× ×€ÖŒ×ַך××ש×Ö·× ×, ×Öž×עך 3 ××××€ÖŒ× ××× ×××× ×¢×š עקס××¢× ××¢×, ××× ××¢××× × ××× ×Ö·× ×Ö·× ×Ö·××ַק××××× ××¢×× ×. ×Ö·× ×¢×§×¡××¢× ××¢× ×Öž×€ÖŒ×××××× ×, × ×× ×¢× ××¢× ×× ××××€ÖŒ×, ×§×¢× ×¢× ×Ö·× ×××Ö·××× ×¡×Ö·×סעקש×Ö·× × (××Ö·××ש×ק×Ö·× ×ך××××× = עקס××¢× ××¢× ×Š×¢×××××× ×). ××× ×× ×עךע ××עך×עך, ×× "עקס××¢× ××¢× ×Š×¢×××××× ×" ××××£ ×× ××× ×š××€ÖŒ×××ס×× LVM ×€Ö¿×ַך ×× ×ַך××¢× ××× ××Ö·× ×: ×€×× ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·×. ×××× ×××× ××סק ××× ×Š×¢××××× ××× 4 ××××€ÖŒ× ×€ÖŒ×ַך××ש×Ö·× ×, ××ך ××Ö·×š×€Ö¿× ×Š× × ××Š× lvm ×Öž×עך ××עך××Ö·×× (××× ×€×֞ך××Ö·×××× ×) ×Öž×€ÖŒ×××××× × ×€×× ××××€ÖŒ× ×Š× ×Ö·×××Ö·× ×¡×ך××¢, ×Öž×עך ××××××× × ××Š× ×Ö·××¢ ×€×ך סעקש×Ö·× × ××× ××Öž×× ×Ö·××¥ ××× ×××, ××× ××ַק×××¢× ×× ××¢××××× ×š×¢×××××Ö·×. ××€××× ×××× ××ך ××Öž×× ×××× ×Š×¢×××××× × ××××£ ×××× ××סק, Gparted ×××¢× ××¢××€Ö¿× ××ך ׊ע××××× ×××× ××× (×€Ö¿×ַך × ×Öž× ×¡×¢×§×©×Ö·× ×) ×Öž× ××Ö·×× ×Öž× ××עך, ×Öž×עך × ×Öž× ××× ×Ö· ק×××× ×©×ך×Öž×£ ×€Ö¿×ַך ×Ö·××Ö· ×ַקש×Ö·× ×.
×× ×©××עך ×€×֞ך ×××ס×××× ×¡××¢××¢, ××× ××ַ׊××× × ×Š× ×××֞ס ×× ××× ×Š×¢ ×ַך×××§× ×××¢× ×××× ××עך××Ö·×××××, ××× ×עך××× ×× ××× ×× ××ש ××× ××.
××ש (× ××עך ×§×¡× ××קס) ×€×× ×§×¡× ××קס×× ×€ÖŒ×ַך××ש×Ö·× ×.
××ך ××Öž× ×××× ××Öž×× ×¢×€ÖŒ×¢×¡ ×¢× ××¢×.
sda1 - ××××€ÖŒ× ×Š×¢×××××× × × ×× 1 × ×׀ס (×¢× ×§×š××€ÖŒ××ך×);
sda2 - עקס××¢× ××¢× ×Öž×€ÖŒ×××××× × ××ַךקעך;
sda6 - ××Ö·××ש×ק×Ö·× ××סק (עס ××× ×× GRUB2 ××Öž×Öž×××Öž×Ö·×עך ××× ×¡××Ö·××ך×);
sda8 - ××ס×××Ö·×× (×¢× ×§×š××€ÖŒ××× ××ס×××Ö·×× ×עקע / × ×× ×©××¢× ××ק);
sda9 - ׀֌ך××××š× ××Ö·××ש×ק×Ö·× ××סק;
sda5 - ××Ö·××ש×ק×Ö·× ××סק ×€Ö¿×ַך ×ש×ק×Ö·×××¢;
sda7 - GNU/Linux OS (×ך×Ö·× ×¡×€×¢×š× ×ַס ×Š× ×Ö· ×× ×§×š××€ÖŒ××× ××Ö·××ש×ק×Ö·× ××סק);
sda3 - ××××€ÖŒ× ×Š×¢×××××× × × ×× 2 ××× Windows 7 ×ַס (×¢× ×§×š××€ÖŒ××ך×);
sda4 - ××××€ÖŒ× ×Öž×€ÖŒ×××××× × × ×× 3 (עס ×ÖŒ××× ×Ö·× ×¢× ×§×š××€ÖŒ××× GNU / ××× ×קס, ××¢××××× × ×€Ö¿×ַך ××ַק×Ö·×€ÖŒ / × ×× ×©××¢× ××ק).
[×] Windows 7 ס×ס××¢× ×××ַק ×¢× ×§×š×׀֌ש×Ö·×
A1. ××עך×ַקך××€ÖŒ×
×ך×׀ק××€××¢ ×€Ö¿××
$ Certutil -hashfile "C:VeraCrypt Setup 1.24.exe" SHA256
××× ×€×ַך××××Ö·×× ×× ×š×¢×××××Ö·× ××× ×× CS ×ַך××Ö·× ×עש××§× ××××£ ×× VeraCrypt ××¢×××¢××֞׀֌עך ×××¢××××××.
×××× HashTab ×××××××××š× ××× ××× ×¡××Ö·××ך×, עס ××× ××€××× ×ך×× ×עך: RMB (VeraCrypt Setup 1.24.exe)-׀֌ך×֞׀֌עך××עס - ××ַש ס×Ö·××Ö·×§× ×€×× ×עקעס.
×Š× ××ַש××¢×××§× ×× ×€ÖŒ×š×Öž×ך×Ö·× ×ס×××¢, ×× ×××××××××š× ××× ×× ×¢×€× ×××¢× ×€ÖŒ××€ÖŒ ש×××¡× ×€×× ×× ××¢×××¢××֞׀֌עך ×××× ×××× ××× ×¡××Ö·×××š× ××××£ ×× ×¡×ס××¢×
A2. ×× ×¡××Öž××× × / ×€×××¡× ××ק VeraCrypt ×××××××××š× ××× ×Ö·×××× ×ס×ך×Ö·××֞ך ךע××
A3. סע×עק××× × ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·× ×€ÖŒ×ַך×Ö·××¢×עךס ×€Ö¿×ַך ×× ×ַק×××× ×Š×¢×××××× ×VeraCrypt - ס×ס××¢× - ×¢× ×§×š××€ÖŒ× ×¡×ס××¢× ×Š×¢×××××× × / ××סק - × ×֞ך××Ö·× - ×¢× ×§×š××€ÖŒ× Windows ס×ס××¢× ×Š×¢×××××× × - ×××××××Öž×Öž× - (××××š×¢× ×× ×: "×× ×קס׀֌×ך××Ö·× ×¡× × ×׊עךס ××¢× ×¢× × ××©× ×š×¢×§×Ö·××¢× ××× ×Š× × ××Š× ××¢× ×××€Ö¿×" ××× ××֞ס ××× ××ת, ××ך ש××××¢× "××") - ש××××× ××סק ("××Öž", ××€××× ×××× × ××©× ×Ö·×××, × ×Öž× "××Öž") - × ××עך ×€×× ×¡×ס××¢× ××סקס "2 ×Öž×עך ×עך" - ×¢×××¢××¢ ס×ס××¢××¢× ××××£ ×××× ××סק "××Öž" - × ××-×××× ××Öž×× ×©××××× ××Öž××עך "× ×××" (××× ×€×ַק×, "××Öž," ×Öž×עך ×× VeraCrypt / GRUB2 ש××××× ××Öž×××¢×š× ×××¢× × ××©× ××××× ×× MBR ׊××××©× ×××; ×עך ××¢× ××, ××××× ×עך ק××¢× ×¡×עך ×××× ×€×× ×× ×©××××× ××Öž××עך ק×Öž× ××× ×¡××Öž×š× ××× ×× MBR / ש××××× ×©×€ÖŒ×ך, ×עך ××××€ÖŒ× ×××× ×€×× ×¢×¡ ××× ×××× ××× ×× ×עקע ס×ס××¢×) - ×××××××Öž×Öž× - ×¢× ×§×š×׀֌ש×Ö·× ×¡×¢×××× ×ס ...
×××× ××ך ×Öž×€ÖŒ× ×××× ×€×× ×× ××××× ×¡×ע׀֌ס (×€×ַךש׀֌×Ö·×š× ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·× ×¡×§×××), ××¢××Öž×× VeraCrypt ×××¢× ×ַך××ס××¢×× ×Ö· ××××š×¢× ×× × ××× ×××¢× × ××©× ××Öž×× ××ך ×Š× ×× ×§×š××€ÖŒ× ×× ×Š×¢×××××× ×.
××× ×עך ××××Ö·×עך שך×× ×Š× ××ַך××¢××¢× ××Ö·×× ×©××¥, ××ך××€××š× ×Ö· "×עס×" ××× ×¡×¢×עק×××š× ×Ö·× ×¢× ×§×š×׀֌ש×Ö·× ×Ö·××עך×××Ö·×. ×××× ××ך ××Öž×× ×Ö· ×Ö·×××××××× ×§×€ÖŒ×, ך××Ö¿ ×סת֌×× ×× ×€×ַס××Ö·×¡× ×¢× ×§×š×׀֌ש×Ö·× ×Ö·××עך×××Ö·× ××× Twofish. ×××× ×× ×§×€ÖŒ× ××× ×©××ַךק, ××ך ×××¢× ××Ö·××¢×š×§× ×× ××××ק: AES ×¢× ×§×š×׀֌ש×Ö·×, ×××× ×× ×€ÖŒ×š×Öž××¢ ךע×××××Ö·××, ×××¢× ×××× ×¢×××¢××¢ ××Öž× ×€×ַס×עך ××× ×× ×§×š××€ÖŒ××Öž ק×Öž×׀֌ע××××֞ךס. AES ××× ×Ö· ×€×Öž×קס ×¢× ×§×š×׀֌ש×Ö·× ×Ö·××עך×××Ö·×; ×× ××Ö·×× ×××Ö·×š× ×€×× ××Öž××¢×š× ×§×€ÖŒ×ס ××× ×¡×€ÖŒ×¢×Š××¢× ×Öž×€ÖŒ××××××¢× ×€Ö¿×ַך ×××××¢ "ס××" ××× "××ַק×× ×."
VeraCrypt ש×××Š× ×× ×€×××ק××× ×Š× ×¢× ×§×š××€ÖŒ× ××סקס ××× ×Ö· AES ק×ַסק×××(׊×××××€×ש)/ ××× ×× ×עךע ק×Ö·×××Ö·× ××ש×Ö·× ×. ××××£ ×Ö·× ×Ö·×× ××ַךץ ×× ××¢× ×§×€ÖŒ× ×€×× ×Š×¢× ××֞ך ׊×ך×ק (×Öž× ××Ö·×× ×××Ö·×š× ×©×××Š× ×€Ö¿×ַך AES, A/T ק×ַסק××× ×¢× ×§×š×׀֌ש×Ö·×) ×× ×€×ַךק××¢× ×¢×š× ××× ×€×֞ךש××¢××× × ××× ××¡×¢× ×©×Ö·×× ××׀֌עךסע׀֌××××Ö·×. (×€Ö¿×ַך ×Ö·×× ×§×€ÖŒ×ס ×€×× ×עך ××¢×××קעך ×ק××€×¢ / ~ ×€ÖŒ×ַך×Ö·××¢×עךס, ×€×֞ךש××¢××× × ××× ×Ö· ×××¡× ×š×××ס×). ×× ×ַס ×ַך××¢× ××× ×Ö·××ק×Ö·××× ××× ×× ×××× ×§×Ö·× ×¡×Ö·×ש×Ö·× ×€Ö¿×ַך ×ך×Ö·× ×¡×€ÖŒ×¢×š×Ö·× × ×¢× ×§×š×׀֌ש×Ö·× ××× ××××¢×ק. ××× ×§×Ö·× ×ך×ַס×, ×€Ö¿×ַך ×××ַש׀֌××, עס ××× ×Ö· ××××¢×š×§× ×€×ַךק××¢× ×¢×š× ××× ×€×֞ךש××¢××× × ×š×¢×× ×Š× ×עך ××× ×¡××Ö·×××š× ×Ö·× ×¡×××××Ö·× ×€ÖŒ×š××××š× ×עסק××Ö·×€ÖŒ ס××××××¢ Mate v1.20.1 (×Öž×עך ××1.20.2 ××× ××Öž× × ×× ××¢××¢× ×§×¢× ×€ÖŒ×× ×§×) ××× GNU/Linux, ×Öž×עך ךע×× ×Š× ×עך ×֞׀֌עך×ַ׊××¢ ×€×× ââ×× ××¢××¢××¢××š× ×š×××× ××× Windows7â. ×××€ÖŒ×ק×Ö·×××, ×קס׀֌×ך××Ö·× ×¡× × ×׊עךס ××ך××€××š× ××Ö·×× ×××Ö·×š× ×€×֞ךש××¢××× × ×עסץ ××××עך ×¢× ×§×š×׀֌ש×Ö·×. ׊×× ×××ש׀֌××, ××× Aida64/Sysbench/systemd-analyze ××× ××ַש×××××§× ×§×Ö·××€ÖŒ×¢×š× ××× ×× ×š×¢×××××Ö·×× ×€×× ×× ××¢×××¢ ×עסץ × ×Öž× ×¢× ×§×š××€ÖŒ××× × ×× ×¡×ס××¢×, ×עך××× ×š××€××× ×× ××××֞ס ×€Ö¿×ַך ××× ×Ö·× "ס×ס××¢× ×¢× ×§×š×׀֌ש×Ö·× ××× ×©×¢×××¢×." ×× ×¡××Öž×××Ö·×× ×€×× ×× ××ַש×× ××× ×× ×× ×§×Ö·× ×××× ××Ö·× ×¡ ××¢× ×¢× ××××¢×š×§× ×××¢× ××ַק×× × ×ַך×××£ / ך×ס××֞ך×× × ×× ×§×š××€ÖŒ××× ××Ö·××, ××××Ö·× ×× "ס×ס××¢× ××Ö·×× ××ַק×Ö·×€ÖŒ" ×֞׀֌עך×ַ׊××¢ ××× ××× × ××©× ××¢××ס×× ××× MS, ××× ×× ××¢×××¢ ××¢× ×¢× ×Š×××¢××¢××. ×עס×Öž×£, ××¢×עך ××Ö·× ×׊עך ×××֞ס ××× ×עך××××× ×Š× ××× ×§×¢×š ××× ×§×š××€ÖŒ××Öž×ך×Ö·×€× ××Ö·××Ö·× ×¡×Ö·× ×× ×¢× ×§×š×׀֌ש×Ö·× ×Ö·××עך×××Ö·× ×§×¢×× ×× ×Š×׀ֿך××× ×§××× ×€×× ×× ××ַסקס ××× ××Ö·× ×, ×××עך ××ך×× ×€×× ×€ÖŒ×ַך×Ö·× ×Öž××Ö· ××× ×× ×€×× × ×׊×.
עס ××× ×עסעך ×Š× ××Öž×× ×× PIM ×€ÖŒ×ַך×Ö·××¢×עך ××× ×€×¢××ק××Ö·×, ×Ö·××× ×Ö·× ×××¢× ××Öž×××× × ×× ×ַס ××ך ××Öž× × ×× ××Öž×× ×Š× ×ַך××Ö·× ×× ×€ÖŒ×× ×××¢× ××עך×Ö·×××Öž× ×××Ö·××עס ××¢×עך ××Öž×. VeraCrypt × ××Š× ×Ö· ך×××ק × ××עך ×€×× ××עך××ש×Ö·× × ×Š× ×©×Ö·×€Ö¿× ×Ö· ×××ת "×€ÖŒ×Ö·××¢××¢× ××ַש". ×Ö· ××Ö·×€×Ö·×× ××××£ ×Ö·××Ö· ×Ö· "קך××€ÖŒ××Öž ×©× ×¢×§" × ××Š× ×× ×ך×× ×§×š×Ö·×€× / ךע×× ××××× ×××©× ×××€Ö¿× ×××× ××× ×¢× ××××× ××× ×Ö· ק×ךץ "׀֌ש××" ×€ÖŒ×ַסס׀ך×ַסע ××× ×× ×§×֞ך×× ×¡ ׀֌עך××¢× ××¢× ×ש×Ö·×š×¡×¢× ×š×©×××. ×× ×€ÖŒ×š××Ö·× ×Š× ××ַ׊×Öž×× ×€Ö¿×ַך ×€ÖŒ×ַך×Öž× ×©××ַךק××Ö·× ××× ×Ö· ×€×ַך××Ö·××× ××× ×ַך××Ö·× ×× ×š××××ק ×€ÖŒ×ַך×Öž× ×××¢× ××Öž×××× × ×× ×ַס. (××Öž×× ××× × ××עך×ַקך××€ÖŒ× ×××Ö·××××× ××× GNU / ××× ×קס ××× ×€×× ×€×ַס×עך).
׀ך×× ×××××××××š× ×€Ö¿×ַך ×××€ÖŒ××Ö·××¢× ×× × ×ך×× ×§×š×Ö·×€× ×× ×€××× (עקס×ך×Ö·×§× ×€ÖŒ×ַסס׀ך×ַסע ×€×× ââ×× ××¢×עך ×€×× VeraCrypt / LUKS ××סק) ××ַשק×Ö·×. ×××× × ×× ×š×׀֌עך ××× × ××©× ××××¡× ××× ×Š× "×ךע×× ××עך×ַק××€ÖŒ×", ××× ×××¢× ×ך××¢×× ××× LUKS ×§×¢× × ××©× ×€Ö¿×ַךש×××× Twofish קך××€ÖŒ××Öž×ך×Ö·×€×.
ךע×× ×Š× ×עך קך××€ÖŒ××Öž×ך×Ö·×€×ק ש××ַךק××× ×€×× ×¢× ×§×š×׀֌ש×Ö·× ×Ö·××עך×××Ö·××, ×Ö·× ×¡××Ö·×€ÖŒ×Ö·××Ö·× ×¡×׀עך׀֌×× ×§×¡ ×Ö·× ××××ק××¢× ×××××××××š× ××× ×Ö· ×Ö·× ×עךש ××Ö·×€×Ö·×× ××עק××֞ך. ×€Ö¿×ַך ×××ַש׀֌××, ×קס×ך×ַק××× × ××¢××Ö·××Ö·××Ö· / ש××ס××¢× ×€Ö¿×× ××ַך×Ö·× (ק×Ö·×× ×©××××× / ×××š×¢×§× ××֌ך×× ×ַקסעס ××Ö·×€×Ö·××), עס ××× ×¡×€ÖŒ×¢×©×Ö·××××× ×€×š×× ××× × ××-׀ך×× ×××××××××š× ×€Ö¿×ַך ×× ×Š××עק×.
× ×Öž× ×§×Ö·××€ÖŒ××ש×Ö·× ×€×× ××ַש××¢×××§× / ×××©×¢× ×¢×š××××× × "××× ×Š×ק ××¢××Ö·××Ö·××Ö·" ×€×× ×× ×× ×§×š××€ÖŒ××× ×ַק×××× ×Š×¢×××××× ×, VeraCrypt ×××¢× ×€×֞ךש××Öž×× ×Š× ×š×ס××Ö·×š× ×× ×€ÖŒ××¡× ××× ×€ÖŒ×š××××š× ×× ×€×Ö·× ×קש×Ö·× ×Ö·×××× ×€×× ×××× ××Öž×Öž×××Öž×Ö·×עך. × ×Öž× ×š×¢××Öž×Öž××× × / ס××ַך××× × Windows, VeraCrypt ×××¢× ××Öž×× ××× ×¡××Ö·× ×××× ××Öž××¢, ×Ö·××¢ ×××֞ס ×××××× ××× ×Š× ××ַש××¢×××§× ××¢× ×¢× ×§×š×׀֌ש×Ö·× ×€ÖŒ×š×֞׊עס - ×.
××× ×× ××¢×Š× ×©×š×× ×€×× ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·×, VeraCrypt ×××¢× ×€×֞ךש××Öž×× ×Š× ×©×Ö·×€Ö¿× ×Ö· ××ַק×Ö·×€ÖŒ ק×Öž×€ÖŒ××¢ ×€×× ââ×× ××¢×עך ×€×× ×× ×ַק×××× ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ××× ×× ×€×Öž×š×¢× ×€×× "veracrypt rescue disk.iso" - ××֞ס ×××× ×××× ××¢××× - ××× ××¢× ×××××××××š× ×Ö·××Ö· ×Ö·× ×֞׀֌עך×ַ׊××¢ ××× ×Ö· ×€×Öž×עך×× × (××× LUKS, ××× ×Ö· ×€×Öž×עך×× × - ××֞ס ××× ××××עך ×××עך××¢××Öž××, ×Öž×עך ××× ××× ×עך×עש×ך××× ××× ×× ××ַק××××¢× ×××ש×Ö·×). ךעסק×× ××סק ×××¢× ×§×××¢× ××× ××Ö·× ××ק ×€Ö¿×ַך ×Ö·××¢××¢×, ××× ×€Ö¿×ַך ×¢×××¢××¢ ×עך ××× ×Ö·××Öž×. ×Öž× ××עך (××¢×עך / MBR ך×ך×××) ×Ö· ××ַק×Ö·×€ÖŒ ק×Öž×€ÖŒ××¢ ×€×× ââ×× ××¢×עך ×××¢× ×€ÖŒ×¢×š××Ö·× ×Ö·× ××× ××××§×¢× ×¢× ×ַקסעס ×Š× ×× ×עקך××€ÖŒ××× ×Š×¢×××××× × ××× ×ַס Windows.
A4. ש×Ö·×€Ö¿× ×Ö· VeraCrypt ך×Ö·××¢×××¢× ××¡× / ××סק×××š× ×€×¢××ק××Ö·×, VeraCrypt ×֞׀׀עךס ×Š× ×€×ַך××š×¢× ×¢× "~2-3MB ×€×× ××¢××Ö·××Ö·××Ö·" ×Š× ×Ö· ק×Öž××€ÖŒ×ַק×××סק, ×Öž×עך × ×× ×Ö·××¢ ××¢× ××©× ××Öž×× ××סקס ×Öž×עך ××××-ך×Ö·× ×ך×××××, ××× ×§×š×××××× × ×Ö· ××Öž×Öž××Ö·×××¢ ××××¥ ×€×֞ך "VeraCrypt ךעסק×× ××סק" ×××¢× ×××× ×Ö· ××¢×× ×ש ××עךך×Ö·×©× ×€Ö¿×ַך ×¢×××¢××¢: Rufus / GUIdd-ROSA ImageWriter ××× ×× ×עךע ×¢× ××¢× ×××××××××š× ×××¢× × ××©× ×§×¢× ×¢× ×Š× ×§×֞׀֌ע ××× ×× ×ַך××¢×, ××××Ö·× ××× ×Ö·××ש×Ö·× ×Š× ×§×Ö·×€ÖŒ××× × ×€×Öž××Öž ××¢××Ö·××Ö·××Ö· ×Š× ×Ö· ××Öž×Öž××Ö·×××¢ ××××¥ ×€×֞ך, ××ך ××Ö·×š×€Ö¿× ×Š× × ×Öž×××Ö·×× / ×€ÖŒ×Ö·×€ÖŒ ×× ×××× ×ַך××ס ×× ×עקע ס×ס××¢× ×€×× ×× ××¡× ×€×֞ך, ××× ×§×ךץ, ך××××ק × ×Öž×××Ö·×× ×× MBR / ×××¢× ×Š× ×§×××ש×Ö·××. ××ך ×§×¢× × ×©×Ö·×€Ö¿× ×Ö· ××Öž×Öž××Ö·×××¢ ××××¥ ×€×֞ך ×€Ö¿×× GNU / Linux OS × ××Š× ×× "dd" × ×׊×, ק×ק ××× ××¢× ×Š××××.
קך×××××× × ×Ö· ך×Ö·××¢×××¢× ××סק ××× ×Ö· Windows ס××××××¢ ××× ×Ö·× ×עךש. ×עך ××¢×××¢××֞׀֌עך ×€×× VeraCrypt ××× × ××©× ×ַך××Ö·× ×עךע×× × ×× ×××××× × ×Š× ××¢× ×€ÖŒ×š×Öž×××¢× ××× ×עך ××Ö·×Ö·××עך
××֞ס ק×Ö·××€ÖŒ×××¥ ×× ××ַשך××Ö·××× × ×€×× ×€×ַךש׀֌×Ö·×š× ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·× ××× Windows OS.
[×]××קס. GNU / ××× ×קס ×¢× ×§×š×׀֌ש×Ö·× (~××¢×××Ö·×) ××× ×¡××Ö·×××š× ×ַס. ×Ö·××עך×××Ö·× ××× ×¡×ע׀֌ס
××× ×¡×ך ×Š× ×¢× ×§×š××€ÖŒ× ×Ö· ××× ×¡××Ö·×××š× ××¢×××Ö·× / ×עך××××Ö·×××× ×€×ַךש׀֌ך××××× ×, ××ך ××Ö·×š×€Ö¿× ×Š× ××ַ׀֌ע ×× ×Š×××¢×ך××× ×Š×¢×××××× × ×Š× ×Ö· ×××ך×××Ö·× ×××֞ק ××××, ×ַך××עך׀××š× ×¢×¡ ×Š× ×× ××Ö·×€ÖŒ× GNU / ××× ×קס ××סק ××× ×× ×¡××Ö·×××š× / ק×Ö·× ×€×××עך GRUB2. ×××× ××ך ××Öž× × ×× ××Öž×× ×Ö· × ×Ö·×§×¢× ××¢××Ö·× ×¡×¢×š××עך ××× ××ך ×××¢×š× ×××× ×Š×××, ××ך ××Ö·×š×€Ö¿× ×Š× × ××Š× ×× GUI, ××× ×š××Ö¿ ×€×× ×× ×××֞ק××Ö·× ×§×Ö·××Ö·× ×× ××סקך×××× ××× ×× ××¢× ×¢× ××¢× × ×Š× ××××€× ××× "Chuck-Norris ××Öž××¢".
B1. ××××× × ×€ÖŒ××¡× ×€Ö¿×× ××¢×× ××¡× GNU / ××× ×קס
"×€××š× ×Ö· קך××€ÖŒ××Öž ׀֌ך×Öž××¢ ×€Ö¿×ַך ××Ö·×× ×××Ö·×š× ×€×֞ךש××¢××× ×"
lscpu && Ñryptsetup benchmark
×××× ××ך ××¢× × ×עך ×××ק××¢× ××Ö·××׊עך ×€×× ×Ö· ש××ַךק ××ַש×× ××× AES ××Ö·×× ×××Ö·×š× ×©××׊×, ×× × ×××¢×š× ×××¢×× ×§××§× ××× ×× ×š×¢×× ×××Ö·× ×€×× ×× ×××֞ק××Ö·×; ×××× ××ך ××¢× × ×Ö· ×××ק××¢× ××Ö·××׊עך, ×Öž×עך ××× ×Ö·× ××ק ××Ö·×× ×××ַך×, ×× × ×××¢×š× ×××¢×× ×§××§× ××× ×× ××× ×§×¡ ×××Ö·×.
×2. ××סק ×€ÖŒ×ַך××ש×Ö·× ×× ×. ××Ö·×× ××× × / ×€×֞ך××Ö·×××× × fs ××Ö·××ש×ק×Ö·× ××סק ××× ×Š× ×¢×§×¡×4 (××€ÖŒ×ַך××¢×)
×2.1. ש×Ö·×€Ö¿× ×Ö· ×¢× ×§×š××€ÖŒ××× sda7 ׊ע×××××× × ××¢×עך×× × ×°×¢ × ×××©×š×²× × × × × ×¢××¢ × ×€× × × × ×××׊×ת , × × ×× × ×°×²×עך , ×××× × ×ײ × ×€×ך×ײע × ××ש , ×°× × ×× × ×× × ××××עךש×× . ×××× ×××× ××סק ×××ס××××, ××ך ×××× ×€×ַך×××Ö·×× ×××× ×Š×¢×××××× × × ×¢××¢×.
××Ö·××ש×ק×Ö·× ×ך×××× ×¢× ×§×š×׀֌ש×Ö·× ××Ö·×€ÖŒ×× × (/dev/sda7 > /dev/mapper/sda7_crypt).
# ×ך×× × ×©×Ö·×€×× × ×€×× ×Ö· "LUKS-AES-XTS ׊ע×××××× ×"
cryptsetup -v -y luksFormat /dev/sda7
×֞׀֌׊×עס:
* luksFormat - ×× ××××Ö·××××Ö·×××Öž× ×€×× LUKS ××¢×עך;
* -× -×€ÖŒ×ַסס׀ך×ַסע (× ×× ×©×××¡× / ×עקע);
* -v -××עך××Ö·××××Ö·×××Öž× (××××Ö·×× ××ק ××× ×€Ö¿×֞ך××ַ׊××¢ ××× ×× ×××֞ק××Ö·×);
* /dev/sda7 - ×××× ××Ö·××ש×ק×Ö·× ××סק ×€Ö¿×× ×× ×¢×§×¡××¢× ××¢× ×Š×¢×××××× × (××× ×¢×¡ ××× ×€ÖŒ××Ö·× × ×¢× ×Š× ×ַך××עך׀××š× / ×¢× ×§×š××€ÖŒ× GNU / ××× ×קס).
×€×¢××ק××Ö·× ×¢× ×§×š×׀֌ש×Ö·× ×Ö·××עך×××Ö·× <×UKS1: aes-xts-plain64, ש××ס×: 256 ×××¥, LUKS ××¢×עך ××ַש×× ×: sha256, RNG: /dev/urandom> (××¢×€ÖŒ×¢× ×ס ××××£ ×× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ ××עךס××¢).
#ÐÑПвеÑка default-алгПÑОÑЌа ÑОÑÑПваМОÑ
cryptsetup --help #ÑÐ°ÐŒÐ°Ñ Ð¿ÐŸÑлеЎМÑÑ ÑÑÑПка в вÑвПЎе ÑеÑЌОМала.
×××× ×¢×¡ ××× ×§××× ××Ö·×× ×××Ö·×š× ×©×××Š× ×€Ö¿×ַך AES ××××£ ×× ×§×€ÖŒ×, ×עך ×עס×עך ×ך××š× ×××Öž×× ×××× ×Š× ×©×Ö·×€Ö¿× ×Ö·× ×¢×§×¡××¢× ××¢× "LUKS-Twofish-XTS-partition".
×2.2. ×Ö·×××Ö·× ×¡×ך××¢ ש×Ö·×€×× × ×€×× "LUKS-Twofish-XTS-partition"
cryptsetup luksFormat /dev/sda7 -v -y -c twofish-xts-plain64 -s 512 -h sha512 -i 1500 --use-urandom
×֞׀֌׊×עס:
* luksFormat - ×× ××××Ö·××××Ö·×××Öž× ×€×× LUKS ××¢×עך;
* /dev/sda7 ××× ×××× ×Š×ק×× ×€Ö¿× ×× ×§×š××€ÖŒ××× ××Ö·××ש×ק×Ö·× ××סק;
* -×× ××עך××Ö·×××××ש×Ö·×;
* -× ×€ÖŒ×ַס׀ך×ַסע;
* -C ×××סק×××Ö·×× ××Ö·×× ×¢× ×§×š×׀֌ש×Ö·× ×Ö·××עך×××Ö·×;
* -ס ×¢× ×§×š×׀֌ש×Ö·× ×©×××¡× ×ך××ס;
* -× ××ַש×× × ×Ö·××עך×××Ö·× / קך××€ÖŒ××Öž ×€Ö¿×× ×§×Š××¢, ×š× × ××¢××××× × (--× ×׊×-×ך×Ö·× ××Öž×) ×Š× ×××©×¢× ×¢×š××× ×Ö· ××× ×Š×ק ×¢× ×§×š×׀֌ש×Ö·× / ×עקך××€ÖŒ×××Öž× ×©×××¡× ×€Ö¿×ַך ×× ××Ö·××ש×ק×Ö·× ××סק ××¢×עך, ×Ö· ׊××××××ק ××¢×עך ש×××¡× (קסץ); ×Ö· ××× ×Š×ק ××¢× ×©×××¡× ×¡××Öž×š× ××× ×× ×¢× ×§×š××€ÖŒ××× ××סק ××¢×עך, ×Ö· ׊××××××ק XTS ש××ס×, ×Ö·××¢ ×× ××¢××Ö·××Ö·××Ö· ××× ×Ö·× ×¢× ×§×š×׀֌ש×Ö·× ×š×××× ×××֞ס, × ××Š× ×× ××¢× ×©×××¡× ××× ×× ×Š××××××ק XTS ש××ס×, ×¢× ×§×š××€ÖŒ× / ×עקך××€ÖŒ× ×§××× ××Ö·×× ××××£ ×עך ׊ע×××××× × (×××¥ ××¢× ×××× ×€×× ×Öž×€ÖŒ×××××× ×) ס××Öž×š× ××× ~ 3 ×× ××××£ ×× ×××ס×עק×××× ×©××עך ××סק ׊ע×××××× ×.
* -× ××עך××ש×Ö·× × ××× ××××סעק×Ö·× ××, ×Ö·× ×©××Öž× ×€×× "ס×××" (×× ×Š××× ×€×ַך××Ö·××× ×××¢× ×€ÖŒ×š×ַסעס×× × ×× ×€ÖŒ×ַס׀ך×ַסע ×ַ׀עקץ ×× ××Öž×××× × ×€×× ×× ×ַס ××× ×× ×§×š××€ÖŒ××Öž×ך×Ö·×€×ק ש××ַךק××Ö·× ×€×× ×× ×©××ס××¢×). ×Š× ××Ö·××× ×Ö· ×××Öž× ×€×× ×§×š××€ÖŒ××Öž×ך×Ö·×€×ק ש××ַךק×××, ××× ×Ö· ׀֌ש×× ×€ÖŒ×ַך×Öž× ××× "ך×ס×ש" ××ך ××Ö·×š×€Ö¿× ×Š× ×€×ַך××š×¢×¡×¢×š× ×× -(×××) ××עך×; ××× ×Ö· ק×Öž××€ÖŒ×עקס ×€ÖŒ×ַך×Öž× ××× "?8dƱob/Þfh" ×× ×××¢×š× ×§×¢× ×¢× ×××× ××קך×ס×.
* â× ×׊×-×ך×Ö·× ××Öž× ×ך×Ö·×€ × ××עך ××¢× ×¢×š×Ö·××֞ך, ×××©×¢× ×¢×š×××¥ ש××ס××¢× ××× ××Ö·××¥.
× ×Öž× ××Ö·×€ÖŒ×× × ×× ×Öž×€ÖŒ×××××× × sda7> sda7_crypt (×× ×֞׀֌עך×ַ׊××¢ ××× ×©× ×¢×, ××××Ö·× ×Ö· ×¢× ×§×š××€ÖŒ××× ××¢×עך ××× ××ש××€× ××× ~ 3 ××¢××××××× ××¢××Ö·××Ö·××Ö· ××× ××֞ס ××× ×Ö·××¢), ××ך ××Ö·×š×€Ö¿× ×Š× ×€Ö¿×֞ך××Ö·× ××× ×Öž× ×§××Ö·×€ÖŒ× ×× sda7_crypt ×עקע ס×ס××¢×.
×2.3. ×€×ַך××××Ö·×
cryptsetup open /dev/sda7 sda7_crypt
#вÑпПлМеМОе ЎаММПй ÐºÐŸÐŒÐ°ÐœÐŽÑ Ð·Ð°Ð¿ÑаÑÐžÐ²Ð°ÐµÑ Ð²Ð²ÐŸÐŽ ÑекÑеÑМПй паÑПлÑМПй ÑÑазÑ.
×֞׀֌׊×עס:
* ×¢×€×¢× ×¢× - ××××Ö·×× ×× ×Öž×€ÖŒ×××××× × "××× × ×Öž××¢×";
* /dev/sda7 -××Öž××ק×Ö·× ××סק;
* sda7_crypt - × ×Öž××¢× ××Ö·×€ÖŒ×× × ×××֞ס ××× ××¢× ××Š× ×Š× ×Öž× ×§××Ö·×€ÖŒ× ×× ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ×Öž×עך ×× ×ש×Ö·×××× ×¢×¡ ×××¢× ×× ×ַס ש××.
×2.4. ×€×֞ך××Ö·×××× × ×× sda7_crypt ×עקע ס×ס××¢× ×Š× ext4. ××Öž×× ××× × ×Ö· ××סק ××× ×× ×ַס(××Ö·×עךק×× ×: ××ך ×××¢× × ××©× ×§×¢× ×¢× ×Š× ×ַך××¢×× ××× ×Ö· ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ××× Gparted)
#ÑПÑЌаÑОÑПваМОе блПÑМПгП ÑОÑÑПваММПгП ÑÑÑÑПйÑÑва
mkfs.ext4 -v -L DebSHIFR /dev/mapper/sda7_crypt
×֞׀֌׊×עס:
* -×× -××עך××Ö·×××××ש×Ö·×;
* -L - ×€×֞ך ×€×ך××¢ (×××֞ס ××× ××¢××××× ××× Explorer ׊××××©× ×× ×עךע ×ך×××××).
××××Ö·×עך, ××ך ××Öž× ×Öž× ×§××Ö·×€ÖŒ× ×× ×××ך×××Ö·× ×× ×§×š××€ÖŒ××× ×××֞ק ×××× /dev/sda7_crypt ×Š× ×× ×¡×ס××¢×
mount /dev/mapper/sda7_crypt /mnt
×ך××¢×× ××× ×עקעס ××× ×× / mnt ×עקע ×××¢× ×××××Öž××Ö·××ש ×× ×§×š××€ÖŒ× / ×עקך××€ÖŒ× ××Ö·×× ××× sda7.
עס ××× ×עך ××ַק×××¢× ×Š× ××ַ׀֌ע ××× ×Öž× ×§××Ö·×€ÖŒ× ×× ×Š×¢×××××× × ××× Explorer (× ×Öž×××××ס / ק×Ö·××ש×Ö· GUI), ×× ×Š×¢×××××× × ×××¢× ×©××× ×××× ××× ×× ××סק סע×עק׊××¢ ךש×××, ×Ö·××¢ ×××֞ס ×××××× ××× ×Š× ×ַך××Ö·× ×× ×€ÖŒ×ַס׀ך×ַסע ×Š× ×¢×€Ö¿×¢× ×¢× / ×עקך××€ÖŒ× ×× ××סק. ×× ××Ö·××©× × ×Öž××¢× ×××¢× ×××× ×××ס×עק×××× ×××××Öž××Ö·××ש ××× × ××©× "sda7_crypt", ×Öž×עך ע׀֌עס ××× /dev/mapper/Luks-xx-xx ...
×2.5. ××סק ××¢×עך ××ַק×Ö·×€ÖŒ (~3MB ××¢××Ö·××Ö·××Ö·)×××× ×¢×š ×€×× ×× ××¢×š×¡× ××××××ק ×ַ׀֌עך××ש×Ö·× × ×××֞ס ××Ö·×š×€Ö¿× ×Š× ×××× ××¢××× ×Öž× ×€×ַך××Ö·××× - ×Ö· ××ַק×Ö·×€ÖŒ ק×Öž×€ÖŒ××¢ ×€×× ââââ×× "sda7_crypt" ××¢×עך. ×××× ××ך ×Öž×××עךך××× / שע×××§× ×× ××¢×עך (××ש×, ×× ×¡××Öž××× × GRUB2 ××××£ ×× sda7 ׊ע×××××× ×, ×××"× ×), ×× ×× ×§×š××€ÖŒ××× ××Ö·×× ×××¢× ×××× ××֞ך ×€×ַך׀×Ö·×× ×Öž× ×§××× ××¢×××¢×ק××× ×Š× ×Š×ך×קקך××× ×¢×¡, ××××Ö·× ×¢×¡ ×××¢× ×××× ×××××¢×××¢× ×Š× ×©××Ö·×¢×-×××©×¢× ×¢×š××š× ×× ××¢×××¢ ש××ס××¢×; ×× ×©××ס××¢× ××¢× ×¢× ××ש××€× ××× ×Š×ק.
#ÐÑкап загПлПвка ÑазЎела
cryptsetup luksHeaderBackup --header-backup-file ~/ÐÑкап_DebSHIFR /dev/sda7
#ÐПÑÑÑаМПвлеМОе загПлПвка ÑазЎела
cryptsetup luksHeaderRestore --header-backup-file <file> <device>
×֞׀֌׊×עס:
* luksHeaderBackup -header-backup-file -backup ××Ö·×€Ö¿×¢×;
* luksHeaderRestore -header-backup-file-restore ××Ö·×€Ö¿×¢×;
* ~/Backup_DebSHIFR - ××ַק×Ö·×€ÖŒ ×עקע;
* /dev/sda7 - ׊ע×××××× × ×××¢××¢× ×¡ ×× ×§×š××€ÖŒ××× ××סק ××¢×עך ××ַק×Ö·×€ÖŒ ק×Öž×€ÖŒ××¢ ××× ×Š× ×××× ×עך×××¢×××¢×.
××× ××¢× ×©×š×× ××× ××¢×¢× ××ק×.
B3. ×€ÖŒ×֞ך××× × GNU / ××× ×קס ×ַס (sda4) ×Š× ×Ö· ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × (sda7)
ש×Ö·×€Ö¿× ×Ö· ×עקע /mnt2 (××Ö·×עךק×× × - ××ך ××¢× ×¢× × ×Öž× ×ך××¢×× ××× ××¢×× ×ס×, sda7_crypt ××× ××Öž×× ××¢× ×××Ö· / mnt), ××× ×Öž× ×§××Ö·×€ÖŒ× ××× ××עך GNU/Linux ××× /mnt2, ×××֞ס ××ַךף ×××× ×× ×§×š××€ÖŒ×××.
mkdir /mnt2
mount /dev/sda4 /mnt2
××ך ××ך××€××š× ×š××××ק ×ַס ×ַך××עך׀××š× × ××Š× Rsync ××××××××ך×
rsync -avlxhHX --progress /mnt2/ /mnt
Rsync ×֞׀֌׊×עס ××¢× ×¢× ××סקך×××× ××× ×€ÖŒ×ַך×Ö·×ך×Ö·×£ E1.
××××Ö·×עך ××× × ××××ק ×ע׀ך×Ö·×××¢× × ×Ö· ××Ö·××ש×ק×Ö·× ××סק ׊ע×××××× ×
e4defrag -c /mnt/ #пПÑле пÑПвеÑкО, e4defrag вÑЎаÑÑ, ÑÑП ÑÑÐµÐ¿ÐµÐœÑ ÐŽÐµÑÑагЌеМÑаÑОО ÑазЎела~"0", ÑÑП заблÑжЎеМОе, кПÑПÑПе ÐŒÐŸÐ¶ÐµÑ Ð²Ð°ÐŒ ÑÑПОÑÑ ÑÑÑеÑÑвеММПй пПÑеÑО пÑПОзвПЎОÑелÑМПÑÑО!
e4defrag /mnt/ #пÑПвПЎОЌ ЎеÑÑагЌеМÑаÑÐžÑ ÑОÑÑПваММПй GNU/Linux
××Ö·×× ×¢×¡ ×Ö· ×עךש×: ××Öž× e4defrag ××××£ ×¢× ×§×š××€ÖŒ××× GNU / Linux ×€Ö¿×× ×Š××× ×Š× ×Š××× ×××× ××ך ××Öž×× ×Ö· ×××.
×× ×ַך××עך׀××š× ××× ×¡×× ×קך×Ö·× ×Ö·×××ש×Ö·× [GNU/Linux> GNU/Linux-×¢× ×§×š××€ÖŒ×××] ××× ××¢×¢× ×××§× ××× ××¢× ×©×š××.
AT 4. ××ַש××¢×××§× GNU / Linux ××××£ ×Ö· ×× ×§×š××€ÖŒ××× sda7 ׊ע×××××× ×
× ×Öž× ×׊××× ×ך×Ö·× ×¡×€×¢×š×× × ×× OS /dev/sda4> /dev/sda7, ××ך ××Ö·×š×€Ö¿× ×Š× ×§××Öž×¥ ××× GNU/Linux ××××£ ×× ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ××× ××ך××€××š× ××××Ö·×עך ק×Ö·× ×€×××עך××ש×Ö·×. (×Öž× ×š×¢××Öž×Öž××× × ×€ÖŒ×ס×) ק×֞ךע×× ×Š× ×Ö· ×× ×§×š××€ÖŒ××× ×¡×ס××¢×. ×Ö·× ×××, ×××× ××× ××¢×× ×ס×, ×Öž×עך ××ס׀××š× ×§×Ö·××Ö·× ×× "ךע××Ö·×××× ×Š× ×עך ×××Öž×š×Š× ×€×× ×× ×× ×§×š××€ÖŒ××× ×ַס." "×שך×Öž×Öž×" ×××¢× ×¡××××××š× ×Ö· ×¢× ××¢× ×¡××××ַ׊××¢. ×Š× ×עש×××× × ××ַק×××¢× ××× ×€Ö¿×֞ך××ַ׊××¢ ××××£ ×××֞ס ×ַס ××ך ×××Š× ×ַך××¢× ××× (×¢× ×§×š××€ÖŒ××× ×Öž×עך × ×ש×, ××× × ×× ××Ö·×× ××× sda4 ××× sda7 ××¢× ×¢× ×¡×× ×קך×Ö·× ××××), ×עס×× ×שך×Öž× ×××¢ ×× ×ַס. ש×Ö·×€Ö¿× ××× ×××Öž×š×Š× ××ךעק×עך×× (sda4/sda7_crypt) ×××××ק ××ַךקעך ×עקעס, ××ש×, /mnt/encryptedOS ××× /mnt2/decryptedOS. ק×Öž× ×ך×Öž×××š× ×עש×××× × ×××֞ס ×ַס ××ך ××¢× × ××××£ (×ַך××Ö·× ×עךע×× × ×€Ö¿×ַך ×× ×Š×ק×× ×€Ö¿×):
ls /<Tab-Tab>
×4.1. "ס××××Ö·×××ש×Ö·× ×€×× ××Öž××× × ××× ×Ö· ×× ×§×š××€ÖŒ××× ×ַס"
mount --bind /dev /mnt/dev
mount --bind /proc /mnt/proc
mount --bind /sys /mnt/sys
chroot /mnt
×4.2. ××עך×Ö·×€×××× × ×Ö·× ×ַך××¢× ××× ××¢×€××š× ×××ס קע×× ×Ö· ×× ×§×š××€ÖŒ××× ×¡×ס××¢×
ls /mnt<Tab-Tab>
#О вОЎОЌ Ñайл "/ÑОÑÑПваММаÑÐС"
history
#в вÑвПЎе ÑеÑЌОМала ЎПлжМа пПÑвОÑÑÑÑ ÐžÑÑПÑÐžÑ ÐºÐŸÐŒÐ°ÐœÐŽ su ÑабПÑей ÐС.
×4.3. קך×××××× × / ק×Ö·× ×€×××עך×× × ×× ×§×š××€ÖŒ××× ××ס×××Ö·××, ×¢××××× × crypttab / fstab××× × ×× ××ס×××Ö·×× ×עקע ××× ×€×֞ך××Ö·×××¢× ××¢×עך ××Öž× ×××¢× ×× ×ַס ס××ַךץ, עס ××× ×§××× ××× ×¢× ×Š× ×©×Ö·×€Ö¿× ××× ××ַ׀֌ע ××ס×××Ö·×× ×Š× ×Ö· ××Ö·××ש×ק×Ö·× ××סק ××׊×, ××× ×××€ÖŒ ק×Ö·××Ö·× ×× ××× ××× ×€ÖŒ×ַך×Ö·×ך×Ö·×£ B2.2. ×€Ö¿×ַך ס×××Ö·×€ÖŒ, ×××× ×××××¢× ×¢ ׊×××××××××××¢ ×¢× ×§×š×׀֌ש×Ö·× ×©××ס××¢× ×××¢× ×××× ×××××Öž××Ö·××ש ×××©×¢× ×¢×š××××Ö·× ××× ××¢×עך ×Öž× ××××. ××¢×× ×Š××§× ×€×× ××ס×××Ö·×× ×©××ס××¢×: ×× ××Öž×× ××× × / ×× ××Öž×× ××× × ××ס×××Ö·×× ×Š×¢×××××× × (+ ך××× ×ק×× × ××ַך×Ö·×); ×Öž×עך ך×ס××Ö·×š× ×× ×ַס. ××ַש××¢×××§× ×ַך×××£ ××ס×××Ö·××, ×¢×€× ×× ×עקע ×€×ַך×Ö·× ××××֞ך×××¢× ×€Ö¿×ַך ×× ×§×Ö·× ×€×××עך××ש×Ö·× ×€×× ×××֞ק ×× ×§×š××€ÖŒ××× ××¢×××סעס (×Ö·× ×Ö·××Öž× ×Š× ×Ö· ׀ס××Ö·× ×עקע, ×Öž×עך ×€×ַך×Ö·× ××××֞ך×××¢× ×€Ö¿×ַך קך××€ÖŒ××Öž).
nano /etc/crypttab
××× ×××
#"׊×× × ×Öž××¢×" "×ק×ך ××××" "ש×××¡× ×עקע" "×֞׀֌׊×עס"
××ס×××Ö·×× / ××¢×× / ס××Ö·8 / ××¢×× / ×ך×Ö·× ××Öž× ××ס×××Ö·××, ס×׀עך = ׊×××××€×ש-קסץ-×€ÖŒ××Ö·××64, ×ך××ס = 512, ××ַש = ש×Ö·512
×֞׀֌׊×עס
* ××ס×××Ö·×× - ××Ö·×€ÖŒ× × ×Öž××¢× ×××¢× ×¢× ×§×š××€ÖŒ××× × /dev/mapper/swap.
* /dev/sda8 - × ××Š× ×××× ××Ö·××ש×ק×Ö·× ×Š×¢×××××× × ×€Ö¿×ַך ××ס×××Ö·××.
* /dev/urandom - ××¢× ×¢×š×Ö·××֞ך ×€×× ×ך×Ö·×€ ×¢× ×§×š×׀֌ש×Ö·× ×©××ס××¢× ×€Ö¿×ַך ××ס×××Ö·×× (××× ××¢×עך × ××Ö· ×ַס ש×××××, × ××Ö· ש××ס××¢× ××¢× ×¢× ××ש××€×). ×× /dev/urandom ××¢× ×¢×š×Ö·××֞ך ××× ××××× ×קעך ×ך×Ö·×€ ××× /dev/random, × ×Öž× ×Ö·××¢, /dev/random ××× ××¢× ××Š× ×××¢× ×ך××¢×× ××× ×ע׀עך××¢× ×€ÖŒ×ַך×Ö·× ×Öž×× ×Š×ש××× ××. ×××¢× ××Öž×××× × ×× ×ַס, /dev/random ס××Öž×× ×ַך×Öž×€ÖŒ ×× ××Öž×××× × ×€Ö¿×ַך ×¢×××¢××¢ ± ××× ×× (××¢× ×¡×ס××¢× ×Ö·× ×Ö·××ס×ס).
* ××ס×××Ö·××, ס××׀עך=××××Öž×€×ש-קסץ-×€ÖŒ××Ö·××64, ×ך××ס=512, ××ַש=ש×Ö·512: -×× ×Š×¢×××××× × ×××××¡× ×Ö·× ×¢×¡ ××× ××ס×××Ö·×× ××× ××× ×€Ö¿×֞ך××Ö·×××š× "××××"; ×¢× ×§×š×׀֌ש×Ö·× ×Ö·××עך×××Ö·×.
#ÐÑкÑÑваеЌ О пÑавОЌ fstab
nano /etc/fstab
××× ×××
# ××ס×××Ö·×× ××× ××¢×××¢× ××××£ / ××¢×× / ס××Ö· 8 ×עש×ַס ×× ×¡××Ö·××ך×× ×
/dev/mapper/swap ק××× ××ס×××Ö·×× ×¡×× 0 0
/dev/mapper/swap ××× ×עך × ×Öž××¢× ×××֞ס ××× ××ַש×××× ××× ×§×š××€ÖŒ××Ö·×.
×× ×עך ×ך××š× ×× ×§×š××€ÖŒ××× ××ס×××Ö·××
×××× ×€Ö¿×ַך ×¢×××¢××¢ ס××× ××ך ××Öž× × ××©× ×××¢×× ×Š× ××¢×× ×Ö· ××Ö·× ×¥ ׊ע×××××× × ×€Ö¿×ַך ×Ö· ××ס×××Ö·×× ×עקע, ××ך ×§×¢× ×¢× ×××× ×Ö·× ×Öž×××¢×š× ×Ö·×××× ××× ×עסעך ×××¢×: ש×Ö·×€Ö¿× ×Ö· ××ס×××Ö·×× ×עקע ××× ×Ö· ×עקע ××××£ ×Ö· ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ××× ×× ×ַס.
fallocate -l 3G /swap #ÑПзЎаМОе Ñайла ÑазЌеÑПЌ 3Ðб (пПÑÑО ÐŒÐ³ÐœÐŸÐ²ÐµÐœÐœÐ°Ñ ÐŸÐ¿ÐµÑаÑОÑ)
chmod 600 /swap #МаÑÑÑПйка пÑав
mkswap /swap #Оз Ñайла ÑПзЎаÑÐŒ Ñайл пПЎкаÑкО
swapon /swap #вклÑÑаеЌ ÐœÐ°Ñ swap
free -m #пÑПвеÑÑеЌ, ÑÑП Ñайл пПЎкаÑкО акÑОвОÑПваМ О ÑабПÑаеÑ
printf "/swap none swap sw 0 0" >> /etc/fstab #пÑО МеПбÑ
ПЎОЌПÑÑО пПÑле пеÑезагÑÑзкО swap бÑÐŽÐµÑ Ð¿ÐŸÑÑПÑММÑй
×× ××ס×××Ö·×× ×Š×¢×××××× × ×¡×¢××Ö·×€ÖŒ ××× ××Ö·× ×¥.
×4.4. ××ַש××¢×××§× ×¢× ×§×š××€ÖŒ××× GNU / Linux (×¢××××× × ×§×š××€ÖŒ×××Ö·× / ׀ס××Ö·× ×עקעס)×× /etc/crypttab ×עקע, ××× ×עשך××× ×××××, ××שך×××× ×¢× ×§×š××€ÖŒ××× ×××֞ק ××¢×××סעס ×××֞ס ××¢× ×¢× ×§×Ö·× ×€××××¢×š× ×עש×ַס ס×ס××¢× ×©×××××.
#пÑавОЌ /etc/crypttab
nano /etc/crypttab
×××× ××ך ××××Ö·×× ×× sda7>sda7_crypt ×Öž×€ÖŒ×××××× × ××× ××× ×€ÖŒ×ַך×Ö·×ך×Ö·×£ B2.1
# "׊×× × ×Öž××¢×" "×ק×ך ××××" "ש×××¡× ×עקע" "×֞׀֌׊×עס"
sda7_crypt UUID=81048598-5bb9-4a53-af92-f3f9e709e2f2 none luks
×××× ××ך ××××Ö·×× ×× sda7>sda7_crypt ×Öž×€ÖŒ×××××× × ××× ××× ×€ÖŒ×ַך×Ö·×ך×Ö·×£ B2.2
# "׊×× × ×Öž××¢×" "×ק×ך ××××" "ש×××¡× ×עקע" "×֞׀֌׊×עס"
sda7_crypt UUID=81048598-5bb9-4a53-af92-f3f9e709e2f2 none cipher=twofish-xts-plain64,size=512,hash=sha512
×××× ××ך ××Ö·××©× ×× sda7>sda7_crypt ×Öž×€ÖŒ×××××× × ××× ××× ×€ÖŒ×ַך×Ö·×ך×Ö·×£ B2.1 ×Öž×עך B2.2, ×Öž×עך ××Öž× × ××©× ×××¢×× ×Š× ×ַך××Ö·× ×× ×€ÖŒ×ַך×Öž× ×Š× ×׀ש×××¡× ××× ×©××××× ×× ×ַס, ×Ö·× ×©××Öž× ×€×× ×× ×€ÖŒ×ַך×Öž×, ××ך ×§×¢× ×¢× ×€×ַך×××Ö·×× ×Ö· ס×× ×©×××¡× / ×ך×Ö·×€ - ×עקע
# "׊×× × ×Öž××¢×" "×ק×ך ××××" "ש×××¡× ×עקע" "×֞׀֌׊×עס"
sda7_crypt UUID=81048598-5bb9-4a53-af92-f3f9e709e2f2 /etc/skey luks
××ַשך××Ö·××× ×
* ××Öž×š× ×× - ך××€ÖŒ×֞ךץ ×Ö·× ×××¢× ××Öž×××× × ×× ×ַס, ×ַך××Ö·× ×Ö· ס×× ×€ÖŒ×ַס׀ך×ַסע ××× ×€×ך××× ×× ×Š× ×׀ש×××¡× ×× ×××֞ך׊×.
* UUID - ׊ע×××××× × ×××¢× ×××€×עך. ×Š× ××¢×€Ö¿×× ×¢× ×××× ×©××Ö·×, ×ַך××Ö·× ×× ×××֞ק××Ö·× (×עך××Öž× ×× × ×Ö·× ×€Ö¿×× ××¢× ×Š××× ×€×֞ך××ס, ××ך ×ַך××¢× ××× ×Ö· ×××֞ק××Ö·× ××× ×Ö· ×שך×Öž×Öž× ×¡××××××¢, ××× × ××©× ××× ×× ×× ×עך ××¢×× ××¡× ×××֞ק××Ö·×).
fdisk -l #пÑПвеÑка вÑеÑ
ÑазЎелПв
blkid #ЎПлжМП бÑÑÑ ÑÑП-ÑП пПЎПбМПе
/dev/sda7: UUID=«81048598-5bb9-4a53-af92-f3f9e709e2f2» TYPE=«crypto_LUKS» PARTUUID=«0332d73c-07»
/dev/mapper/sda7_crypt: LABEL=«DebSHIFR» UUID=«382111a2-f993-403c-aa2e-292b5eac4780» TYPE=«ext4»
×× ×©××š× ××× ×§×¢× ××ק ×××¢× ××ך ××¢×× ××ק×× ×€Ö¿×× ×× ××¢×× ××¡× ×××֞ק××Ö·× ××× sda7_crypt ××Öž×× ××¢×).
××ך × ×¢××¢× ×× UUID ×€Ö¿×× ×××× sdaX (× ×× sdaX_crypt!, UUID sdaX_crypt - ×××¢× ×××× ×××××Öž××Ö·××ש ××× ×§×¡ ×××¢× ×××©×¢× ×¢×š××××× × ×× grub.cfg ק×Ö·× ×€×××עך××ש×Ö·×).
* cipher=twofish-xts-plain64, size=512,hash=sha512-luks ×¢× ×§×š×׀֌ש×Ö·× ××× ×Ö·×××Ö·× ×¡×ך××¢ ××Öž××¢.
* /etc/skey - ס×× ×©×××¡× ×עקע, ×××֞ס ××× ×× ×¡×¢×š××Ö·× ×××××Öž××Ö·××ש ×Š× ×׀ש×××¡× ×× ×ַס ש××××× (×Ö·× ×©××Öž× ×ַך××Ö·× ×× 3 ×€ÖŒ×ַך×Öž×). ××ך ×§×¢× ×¢× ×¡×€ÖŒ×¢×Š××€×׊××š× ×§××× ×עקע ×ַך×××£ ×Š× 8 ××, ×Öž×עך ×× ××Ö·×× ×××¢× ×××× ××××¢× ×¢× <1 ××.
#СПзЎаМОе "геМеÑаÑОÑ" ÑлÑÑайМПгП Ñайла <ÑекÑеÑМПгП клÑÑа> ÑазЌеÑПЌ 691б.
head -c 691 /dev/urandom > /etc/skey
#ÐПбавлеМОе ÑекÑеÑМПгП клÑÑа (691б) в 7-й ÑÐ»ÐŸÑ Ð·Ð°Ð³ÐŸÐ»ÐŸÐ²ÐºÐ° luks
cryptsetup luksAddKey --key-slot 7 /dev/sda7 /etc/skey
#ÐÑПвеÑка ÑлПÑПв "паÑПлО/клÑÑО luks-ÑазЎела"
cryptsetup luksDump /dev/sda7
עס ×××¢× ×§××§× ×¢×€ÖŒ×¢×¡ ××× ××֞ס:
(××Öž× ×¢×¡ ××× ××× ××¢× ×€Ö¿×ַך ×××).
cryptsetup luksKillSlot /dev/sda7 7 #ÑЎалеМОе клÑÑа/паÑÐŸÐ»Ñ ÐžÐ· 7 ÑлПÑа
/etc/fstab ×ÖŒ××× ××סקך××€ÖŒ×××× ××× ×€Ö¿×֞ך××ַ׊××¢ ×××¢×× ×€×ַךש××× ×עקע ס×ס××¢××¢×.
#ÐÑавОЌ /etc/fstab
nano /etc/fstab
# "×עקע ס×ס××¢×" "×××š× ×€×× ×" "×××€ÖŒ" "×֞׀֌׊×עס" "××Ö·××€ÖŒ" "×€×֞ך×"
# / ××× ××¢×××¢× ××××£ / ××¢×× / ס××Ö· 7 ×עש×ַס ×× ×¡××Ö·××ך×× ×
/dev/mapper/sda7_crypt / ext4 עךך×֞ךס = ךע××Öž×× ×-ך×Öž 0 1
×֞׀֌׊××¢
* /dev/mapper/sda7_crypt - ×עך × ×Öž××¢× ×€×× ×× sda7>sda7_crypt ××Ö·×€ÖŒ×× ×, ×××֞ס ××× ×¡×€ÖŒ×¢×¡××€××¢× ××× ×× /etc/crypttab ×עקע.
×× crypttab / fstab סע××Ö·×€ÖŒ ××× ××Ö·× ×¥.
×4.5. ×¢××××× × ×§×Ö·× ×€×××עך××ש×Ö·× ×עקעס. ש×××¡× ××Öž××¢× ××4.5.1. ×¢××××× × ×× ×§×Ö·× ×€×××עך××ש×Ö·× /etc/initramfs-tools/conf.d/resume
#ÐÑлО Ñ Ð²Ð°Ñ ÑаМее бÑл акÑОвОÑПваМ swap ÑазЎел, ПÑклÑÑОÑе егП.
nano /etc/initramfs-tools/conf.d/resume
××× ××Ö·××¢×š×§× ×××ס (×××× ×¢×¡ ×××) "#" ש××š× "× ×¢××¢× ××× ××××עך". ×× ×עקע ×××× ×××× ××֞ך ×××××ק.
×4.5.2. ×¢××××× × ×× ×§×Ö·× ×€×××עך××ש×Ö·× /etc/initramfs-tools/conf.d/cryptsetup
nano /etc/initramfs-tools/conf.d/cryptsetup
××Öž× ××××Ö·××
# /etc/initramfs-tools/conf.d/cryptsetup
CRYPTSETUP = ××Öž
×ַך××ס׀××š× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ
×4.5.3. ×¢××××× × ×× /etc/default/grub config (××¢× ×§×Öž× ×€×× ××× ×€×ַך×Ö·× ××××֞ך×××¢× ×€Ö¿×ַך ×× ×€×××ק××× ×Š× ×××©×¢× ×¢×š××× grub.cfg ×××¢× ×ך××¢×× ××× ×× ×§×š××€ÖŒ××× / ש×××××)
nano /etc/default/grub
×××× ×× ×©××š× "GRUB_ENABLE_CRYPTODISK = y"
×××¢×š× 'y', grub-mkconfig ××× grub-install ×××¢×× ×§×Öž× ×ך×Öž×××š× ×€Ö¿×ַך ×× ×§×š××€ÖŒ××× ×ך××××× ××× ×××©×¢× ×¢×š××× × ×Öž× ×§×Ö·××Ö·× ×× ×Š× ×ַקסעס ××× ××× ×©××××× ×Š××× (×× ×¡××Öž× ×ס ).
עס ××× ×××× ×Ö·× ×¢× ××¢×ק×××
GRUB_DEFAULT = 0
GRUB_TIMEOUT = 1
GRUB_DISTRIBUTOR=`lsb_release -i -s 2> /dev/null || echo Debian`
GRUB_CMDLINE_LINUX_DEFAULT = "acpi_backlight = ×€×ַךק××׀עך"
GRUB_CMDLINE_LINUX = "ש××× ×©×€ÖŒ×š××Š× ×§××× ×Ö·×××Öž××Öž×× ×"
GRUB_ENABLE_CRYPTODISK=×
×4.5.4. ×¢××××× × ×× ×§×Öž× ×€×× /etc/cryptsetup-initramfs/conf-hook
nano /etc/cryptsetup-initramfs/conf-hook
×שעק ×Ö·× ×× ×©××š× ××× ×§×Ö·××¢× ××Ö·× ×××ס .
××× ×עך ׊×ק×× ×€Ö¿× (××× ××€××× ××׊×, ×עך ×€ÖŒ×ַך×Ö·××¢×עך ×××¢× × ××©× ××Öž×× ×§××× ×××Ö·×ש, ×Öž×עך ××× ×¢×¡ ×× ×עך׀××š× ××× ×Ö·×€ÖŒ×××××× × ×× initrd.img ××××).
×4.5.5. ×¢××××× × ×× ×§×Öž× ×€×× /etc/cryptsetup-initramfs/conf-hook
nano /etc/cryptsetup-initramfs/conf-hook
×××× ×Š×
KEYFILE_PATTERN="/etc/skey"
UMASK=0077
××֞ס ×××¢× ×€ÖŒ×Ö·×§× ×× ×¡×× ×©×××¡× "ש×××" ××× initrd.img, ×עך ש×××¡× ××× ××ךף ×Š× ×׀ש×××¡× ×× ×××Öž×š×Š× ×××¢× ×× ×ַס ש×× (×××× ××ך ××Öž× × ××©× ×××¢×× ×Š× ×ַך××Ö·× ×× ×€ÖŒ×ַך×Öž× ××××עך, ×× "ש××ס×" ש×××¡× ××× ×¡×Ö·×ס××Ö·××××Ö·× ×€Ö¿×ַך ×× ××ַש××).
×4.6. ×עך×××Ö·× ×××§× /boot/initrd.img [××עךס××¢]×Š× ×€ÖŒ×Ö·×§× ×× ×¡×× ×©×××¡× ××× initrd.img ××× ×Š×××××× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ ×€×קס××, ×עך×××Ö·× ×××§× ×× ××××
update-initramfs -u -k all
×××¢× ×Ö·×€ÖŒ×××××× × initrd.img (××× ××× ××Öž×× "עס ××× ××¢×××¢×, ×Öž×עך עס ××× × ××©× ×××עך") ×××Öž×š× ×× ×× ×©××Ö·××ת ×Š× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ ×××¢× ×עךש××Ö·× ×¢×, ×Öž×עך, ×€Ö¿×ַך ×××ַש׀֌××, ×Ö· ×Öž× ××Öž× ×××¢×× ×× ×Öž× ××עך ×€×× × ××××××Ö· ××Ö·××ש××× - ××֞ס ××× × ×֞ך××Ö·×. × ×Öž× ×Ö·×€ÖŒ×××××× × ×× ×עקע, ק×Öž× ×ך×Öž×××š× ×Ö·× ×¢×¡ ××× ×ַק×ש×Ö·×××Ö·×× ×עך×××Ö·× ××ק×, ××¢× ×× ×Š××× (ק×֞ךע×× ×Š× chroot ס××××××¢./boot/initrd.img). ××××š×¢× ×× ×! ××××עך [update-initramfs -u -k all] ×××× ×××עך ×Š× ×§×Öž× ×ך×Öž×××š× ×Ö·× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ ××× ×Öž×€× /dev/sda7 sda7_crypt - ××֞ס ××× ×עך × ×Öž××¢× ×××֞ס ××× ×ך××ס ××× /etc/crypttab, ×Ö·× ×עךש × ×Öž× ×š×¢××Öž×Öž× ×¢×¡ ×××¢× ×××× ×Ö· ×€×Ö·×š× ×××¢× ××֞קס ××¢×ת)
××× ××¢× ×©×š××, ××ַש××¢×××§× ×× ×§×Ö·× ×€×××עך××ש×Ö·× ×עקעס ××× ××Ö·× ×¥.
[C] ×× ×¡××Öž××× × ××× ×§×Ö·× ×€×××עך GRUB2 / ׀֌ך×Ö·×עקש×Ö·×
C1. ×××× × ××××ק, ×€Ö¿×֞ך××Ö·× ×× ××¢××ַק××××Ö·× ×Š×¢×××××× × ×€Ö¿×ַך ×× ××Öž×Öž×××Öž×Ö·×עך (×Ö· ׊ע×××××× × ××ַךף ×××Ö· ××× ×ס×עך 20MB)
mkfs.ext4 -v -L GRUB2 /dev/sda6
C2. ×××š× /dev/sda6 ×Š× /mnt×Ö·××× ××ך ×ַך××¢×× ××× chroot, עס ×××¢× ×××× ×§××× / mnt2 ×××¢×××××Ö·×עך ××× ×עך ×××֞ך׊×, ××× ×× / mnt ×עקע ×××¢× ×××× ×××××ק.
×Öž× ×§××Ö·×€ÖŒ× ×× GRUB2 ׊ע×××××× ×
mount /dev/sda6 /mnt
×××× ××ך ××Öž×× ×Ö·× ×¢××עךע ××עךס××¢ ×€×× ââGRUB2 ××× ×¡××Ö·××ך×, ××× ×× /mnt/boot/grub/i-386-pc ×××¢×××××Ö·×עך (×× ×עךע ×€ÖŒ××Ö·××€×֞ך××¢ ××× ××¢×××¢×, ×€Ö¿×ַך ×××ַש׀֌××, × ××©× "i386-pc") ק××× ×§×š××€ÖŒ××Öž ××Ö·××ש××× (××× ×§×ךץ, ×עך ×עקע ××Öž× ×Ö·× ×××Ö·××× ××Ö·××ש×××, ×ַך××Ö·× ×עךע×× × ×× .××Öž×: cryptodisk; luks; gcry_twofish; gcry_sha512; signature_test.mod), ××× ××¢× ×€×Ö·×, GRUB2 ××ַךף ×××× ××××€××¢×ך××ס××.
apt-get update
apt-get install grub2
××××××ק! ×××¢× ××ך ×Ö·×€ÖŒ×××××× × ×× GRUB2 ×€ÖŒ×¢×§× ×€Ö¿×× ×× ×š××€ÖŒ×Ö·××Ö·××֞ך×, ×××¢× ××ך ××Öž× ×ע׀ךע×× "×××¢×× ×ש×××× ×" ××× ×Š× ×× ×¡××Ö·×××š× ×× ××Öž×Öž×××Öž×Ö·×עך, ××ך ×××× ×Öž×€ÖŒ××Öž×× ×× ×× ×¡××Ö·××ך×× × (ס××× - ׀֌ך×××× ×Š× ×× ×¡××Ö·×××š× GRUB2 - ××× "MBR" ×Öž×עך ××××£ ××¢×× ×ס×). ×Ö·× ×עךש ××ך ×××¢× ×©×¢×××§× ×× VeraCrypt ××¢×עך / ××Öž××עך. × ×Öž× ×Ö·×€ÖŒ×××××× × ×× GRUB2 ×€ÖŒ×ַק×Ö·××ש×Ö·× ××× ×§×Ö·× ×¡×Ö·××× × ×× ×× ×¡××Ö·××ך×× ×, ×× ×©××××× ××Öž××עך ×××× ×××× ××× ×¡××Ö·×××š× ××Ö·× ×××Ö·×× ××××£ ×× ××Ö·××ש×ק×Ö·× ××סק ××× × ××©× ××× ×× MBR. ×××× ×××× ×š××€ÖŒ×Ö·××Ö·××Öž×š× ××× ×Ö·× ×Ö·×××××××× ××עךס××¢ ×€×× ââGRUB2, ׀֌ך×××ך×
C3. ×× ×¡××Öž××× × GRUB2 ××× ×Ö·× ×¢×§×¡××¢× ××¢× ×Š×¢×××××× × [sda6]××ך ×××× ××Öž×× ×Ö· ××Öž×× ××¢× ×Š×¢×××××× × [× ××עך C.2]
grub-install --force --root-directory=/mnt /dev/sda6
×֞׀֌׊×עס
* â×€×֞ךס - ×× ×¡××Ö·××ך×× × ×€×× ×× ××Öž×Öž×××Öž×Ö·×עך, ××××€ÖŒ×ַס×× × ×Ö·××¢ ×××Öž×š× ×× ×× ×Ö·× ×ÖŒ××¢× ×©××¢× ××ק עקס×ס×××š× ××× ×€×ַךש׀֌×Ö·×š× ×× ×¡××Ö·××ך×× × (×€×ך××× ×× ×€×Öž×).
* --root-directory - ש××¢×× ×× ×××¢×××××Ö·×עך ×Š× ×עך ×××Öž×š×Š× ×€×× sda6.
* /dev/sda6 - ×××× sdaÐ¥ ׊ע×××××× × (××Öž× × ×× ×€×¢×× ×× ×Š××××©× /mnt /dev/sda6).
C4. ש×Ö·×€Ö¿× ×Ö· ק×Ö·× ×€×××עך××ש×Ö·× ×עקע [grub.cfg]×€×ך××¢×¡× ××¢× ××Ö·×€Ö¿×¢× "update-grub2" ××× × ××Š× ×× ××Ö·×€Ö¿×¢×× ×€×× ×× ×€×× ×§×Ö·× ×€×××עך××ש×Ö·× ×עקע ××ך
grub-mkconfig -o /mnt/boot/grub/grub.cfg
× ×Öž× ×§×Ö·××€ÖŒ××××× × ×× ××ך / ×Ö·×€ÖŒ×××××× × ×€×× ×× grub.cfg ×עקע, ×עך ךע×××××Ö·× ×××֞ק××Ö·× ××Öž× ×Ö·× ×××Ö·××× ×©××š× (s) ××× ×× ×ַס ××¢×€Ö¿×× ×¢× ××××£ ×× ××סק ("grub-mkconfig" ×××¢× ××ס××Öž××¢ ××¢×€Ö¿×× ×¢× ××× ×§×××Ö·×× ×× ×ַס ×€Ö¿×× ×Ö· ××¢×× ×ס×, ×××× ××ך ××Öž×× ×Ö· ×××××××Öž×Öž× ××××¥ ×€×֞ך ××× Windows 10 ××× ×Ö· ××× ×× ×€×× ××¢×× ××ס×ך××××ש×Ö·× × - ××֞ס ××× × ×֞ך××Ö·×). ×××× ×עך ×××֞ק××Ö·× ××× "×××××ק" ××× ×× "grub.cfg" ×עקע ××× × ××©× ×××©×¢× ×¢×š××××Ö·×, ××֞ס ××× ×עך ××¢×××קעך ×€×Ö·× ×××¢× ×¢×¡ ××¢× ×¢× GRUB ××Ö·×× ××× ×× ×¡×ס××¢× (××× ×š××Ö¿ ×סת֌×× ×× ××Öž××עך ×€×× ×× ×€ÖŒ×š××××š× ×Š××××Ö·× ×€×× ×× ×š××€ÖŒ×Ö·××Ö·××֞ך×), ך××× ×¡××Ö·× GRUB2 ×€Ö¿×× ×ך×ַס××× ×§×××××.
×× "׀֌ש×× ×§×Ö·× ×€×××עך××ש×Ö·×" ×× ×¡××Ö·××ך×× × ××× GRUB2 סע××Ö·×€ÖŒ ××× ××Ö·× ×¥.
C5. ×עך××××Ö·×-׀֌ך××××š× ×€×× ×¢× ×§×š××€ÖŒ××× GNU/Linux OS××ך ×€×Ö·×š×¢× ×××§× ×× ×§×š××€ÖŒ××Öž ××ס××¢ ך××××ק. קעך׀×Ö·×× ××Öž×× ×× ×× ×§×š××€ÖŒ××× GNU / ××× ×קס (×ַך××ס××Ö·× × ×שך×Öž×Öž× ×¡××××××¢).
umount -a #ÑазЌПМÑОÑПваМОе вÑеÑ
ÑЌПМÑОÑПваММÑÑ
ÑазЎелПв ÑОÑÑПваММПй GNU/Linux
Ctrl+d #вÑÑ
ПЎ Оз ÑÑÐµÐŽÑ chroot
umount /mnt/dev
umount /mnt/proc
umount /mnt/sys
umount -a #ÑазЌПМÑОÑПваМОе вÑеÑ
ÑЌПМÑОÑПваММÑÑ
ÑазЎелПв Ма live usb
reboot
× ×Öž× ×š×ס××ַך××× × ×× ×€ÖŒ×ס×, ×× VeraCrypt ××Öž×Öž×××Öž×Ö·×עך ××Öž× ××Öž××.
* ×ַך××Ö·× ×× ×€ÖŒ×ַך×Öž× ×€Ö¿×ַך ×× ×ַק×××× ×Š×¢×××××× × ×××¢× ×Öž× ××××× ××Öž×××× × Windows.
* ×ך×× ×××¢× ×× "עסק" ש×××¡× ×××¢× ×ַך××עך׀××š× ×§×Öž× ×ך×Öž× ×Š× GRUB2, ×××× ××ך ×××סק×××Ö·×× ×¢× ×§×š××€ÖŒ××× GNU/Linux - ×Ö· ×€ÖŒ×ַך×Öž× (sda7_crypt) ×××¢× ×××× ×€×ך××× ×× ×Š× ×׀ש×××¡× /boot/initrd.img (×××× grub2 שך×××× ×××× "× ×× ××¢×€Ö¿×× ×¢×" - ××֞ס ××× ×Ö· ׀֌ך×Öž×××¢× ××× ×× grub2 ××Öž×Öž×××Öž×Ö·×עך, עס ××Öž× ×××× ×š××× ×¡××Ö·××, ××ש×, ×€Ö¿×× ××¢×¡× ×Š××××Ö·× / ס××Ö·××× ×¢×ק.).
* ××¢×€ÖŒ×¢× ××× × ××××£ ××× ××ך ק×Ö·× ×€××××¢×š× ×× ×¡×ס××¢× (××¢× ×€ÖŒ×ַך×Ö·×ך×Ö·×£ B4.4/4.5), × ×Öž× ×ַך××Ö·× ×× ×š××××ק ×€ÖŒ×ַך×Öž× ×Š× ×׀ש×××¡× ×× /boot/initrd.img ××××, ××ך ×××¢× ××Ö·×š×€Ö¿× ×Ö· ×€ÖŒ×ַך×Öž× ×Š× ××Öž×× ×× ×ַס ×§×¢×š× / ×××Öž×š×Š× ×Öž×עך ×× ×¡××. ש×××¡× ×××¢× ×××× ×××××Öž××Ö·××ש ס×Ö·×ס××Ö·××××Ö·× "סק××", ×××××Ö·× ××××× × ×× × ××× ×Š× ×©××Ö·×¢×-×ַך××Ö·× ×× ×€ÖŒ×ַסס׀ך×ַסע.
(×€×ַךש××¢×× "×Öž××Ö·××Ö·××ק ס×Ö·×ס××××ש×Ö·× ×€×× ×Ö· ס×× ×©××ס×").
* ××¢×š× ×Öž× ×עך ××ַק×Ö·× × ×€ÖŒ×š×֞׊עס ×€×× ××Öž×××× × GNU / ××× ×קס ××× ××Ö·× ×׊עך ×ש××× ×Öž××¢× ××ַק××ש×Ö·× ×××¢× × ×Öž××€×Öž×××.
* × ×Öž× ××Ö·× ×׊עך ×עך×××××¢× ×ש ××× ××Öž××× ×Š× ×× ×ַס, ××ך ××Ö·×š×€Ö¿× ×Š× ×עך×××Ö·× ×××§× /boot/initrd.img ××××עך (××¢× B4.6).
update-initramfs -u -k all
××× ××× ×€×Ö·× ×€×× ×¢×§×¡×ךע ש×ך×ת ××× ×× GRUB2 ××¢× ×× (×€×× OS-m ×€ÖŒ×ק×Ö·×€ÖŒ ××× ××¢×× ×ס×) ××ַק×××¢× ××ַ׀ך××Ö·×¢× ×€×× ×××
mount /dev/sda6 /mnt
grub-mkconfig -o /mnt/boot/grub/grub.cfg
× ×©× ×¢× ×§×׊עך ×€×× GNU / ××× ×קס ס×ס××¢× ×¢× ×§×š×׀֌ש×Ö·×:
- GNU/Linuxinux ××× ××֞ך ×× ×§×š××€ÖŒ×××, ×ַך××Ö·× ×עךע×× × /boot/kernel ××× initrd;
- ×עך ס×× ×©×××¡× ××× ×€ÖŒ×ַק××××©× ××× initrd.img;
- קך×Ö·× × ×עך×××××¢× ×ש ס××¢××¢ (×ַך××Ö·× ×× ×€ÖŒ×ַך×Öž× ×Š× ×׀ש×××¡× ×× ×× ××ך×; ×€ÖŒ×ַך×Öž× / ש×××¡× ×Š× ×©××××× ×× ×ַס; ×€ÖŒ×ַך×Öž× ×€Ö¿×ַך ×Öž×עך××××× × ×× ××× ×קס ×ש×××).
"Simple GRUB2 Configuration" ס×ס××¢× ×¢× ×§×š×׀֌ש×Ö·× ×€×× ×× ×××֞ק ׊ע×××××× × ××× ××Ö·× ×¥.
C6. ×Ö·×××Ö·× ×¡×ך××¢ GRUB2 ק×Ö·× ×€×××עך××ש×Ö·×. ××Öž×Öž×××Öž×Ö·×עך ש××¥ ××× ××××××Ö·× ×ס×××¢ + ×Öž××¢× ××ַק××ש×Ö·× ×©××¥GNU / Linux ××× ××֞ך ×× ×§×š××€ÖŒ×××, ×Öž×עך ×× ××Öž×Öž×××Öž×Ö·×עך ×§×¢× ×¢× × ×× ×××× ×× ×§×š××€ÖŒ××× - ××¢× ×Š×ש××Ö·× × ××× ××ק×××××× ×××š× ×× ××××Öž×ס. ×€Ö¿×ַך ××¢× ×¡×××, ×Ö· ×ש××× × ×¢× ×§×š××€ÖŒ××× ×©××××× ×€×× GRUB2 ××× × ×× ××¢×××¢×, ×Öž×עך ×Ö· ׀֌ש×× ×ש××× × ×©××××× ××× ××¢×××¢× / ×× ××׊×, ×Öž×עך ×€Ö¿×× ×Ö· ×××עך×××× ×€×× × ×€×× ×××× ×× × ×¢×¡ ××× × ×× × ××××ק [××¢× ×€ ×€].
×€Ö¿×ַך ×× "ש׀֌×ךע××××ק" GRUB2, ×× ××¢×××¢××֞׀֌עךס ×××€ÖŒ××Ö·××¢× ×Ö·× ×Ö· "ס××× ×Ö·××ךע / ×Öž××¢× ××ַק××ש×Ö·×" ××Öž×Öž×××Öž×Ö·×עך ש××¥ ×Ö·××עך×××Ö·×.
- ×××¢× ×× ××Öž×Öž×××Öž×Ö·×עך ××× ×€ÖŒ×š×Öž×עק××¢× ×××š× "×××× ×××××¢× ×¢ ××××××Ö·× ×ס×××¢," ×€×× ×ך×××¡× ××ק ××Öž×××€×ק×Ö·×××Öž× ×€×× ×עקעס, ×Öž×עך ×Ö·× ×€ÖŒ×š×××× ×Š× ××Öž×× × ×Öž× ××Ö·××ש××× ××× ××¢× ××Öž×Öž×××Öž×Ö·×עך, ×××¢× ×€××š× ×Š× ×××Ö·×§× ×× ×©××××× ×€ÖŒ×š×֞׊עס.
- ×××¢× ××ך ××ַש××Š× ×× ××Öž×Öž×××Öž×Ö·×עך ××× ×Öž××¢× ××ַק××ש×Ö·×, ×Š× ×¡×¢×עק×××š× ××Öž×××× × ×Ö· ×€×ַךש׀֌ך××××× × ×Öž×עך ×ַך××Ö·× × ×Öž× ×§×Ö·××Ö·× ×× ××× ×× CLI, ××ך ××Ö·×š×€Ö¿× ×Š× ×ַך××Ö·× ×× ××Öž××× ××× ×€ÖŒ×ַך×Öž× ×€×× ×× ×¡×׀֌עך×סעך-GRUB2.
C6.1. ××Öž×Öž×××Öž×Ö·×עך ×Öž××¢× ××ַק××ש×Ö·× ×©×ץק×Öž× ×ך×Öž×××š× ×Ö·× ××ך ×ַך××¢× ××× ×Ö· ×××֞ק××Ö·× ××××£ ×Ö· ×× ×§×š××€ÖŒ××× ×ַס
ls /<Tab-Tab> #ПбМаÑÑжОÑÑ Ñайл-ЌаÑкеÑ
ש×Ö·×€Ö¿× ×Ö· ס×׀֌עך×סעך ×€ÖŒ×ַך×Öž× ×€Ö¿×ַך ×עך×××××¢× ×ש ××× GRUB2
grub-mkpasswd-pbkdf2 #ввеЎОÑе/пПвÑПÑОÑе паÑÐŸÐ»Ñ ÑÑпеÑпПлÑзПваÑелÑ.
××ַק×××¢× ×× ×€ÖŒ×ַך×Öž× ××ַש. ע׀֌עס ××× ××֞ס
grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8
×Öž× ×§××Ö·×€ÖŒ× ×× GRUB ׊ע×××××× ×
mount /dev/sda6 /mnt
ךע××Ö·×××š× ×× ×§×Öž× ×€××
nano -$ /mnt/boot/grub/grub.cfg
ק×Öž× ×ך×Öž×××š× ×× ×עקע ×××× ×Ö·× ×¢×¡ ××¢× ×¢× ×§××× ×€××Ö·×ס עך××¢×¥ ××× "grub.cfg" ("-×Ö·× ×š×ס×ך×ק×××" "-××Ö·× ×׊עך",
××××× ××× ×× ×¡××£ (××××עך ×× ×©××š× ### END /etc/grub.d/41_custom ###)
"ש××¢×× ×¡×׀֌עך×סעךס = ×××֞ך׊×"
password_pbkdf2 ×××Öž×š×Š× ××ַש."
עס ××Öž× ×××× ×¢×€ÖŒ×¢×¡ ××× ××֞ס
# ×× ×עקע ××× ×Ö·× ×ך×× × ×××¢× ×Š× ××××× ×× ×× ××¢× ×× ×××× ×¡×. ׀ש×× ×ַך××Ö·× ××
# ××¢× ×× ×××× ×¡× ××ך ××××× ×Š× ××××× × ×Öž× ××¢× ××Ö·×עךק×× ×. ×××× ×Öž×€ÖŒ××¢××× × ×× ×Š× ×××ש×
# ×× ×©××š× 'עקסעק עק' ×××××.
### END /etc/grub.d/40_custom ###### BEGIN /etc/grub.d/41_custom ###
×××× [-f ${config_directory}/custom.cfg]; ××¢××Öž××
×ק×ך ${config_directory}/custom.cfg
×¢×××£ [-× "${ק×Öž× ×€××_××ךעק××֞ך×}" -×Ö· -×€ $׀֌ךע׀×קס/ק×ַס××Ö·×.ק׀×]; ××¢××Öž××
×ק×ך $ ׀֌ךע׀×קס / ק×ַס××Ö·×.ק׀×;
fi
ש××¢×× ×¡×׀֌עך×סעךס = "ש×ךש"
password_pbkdf2 root grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8
### END /etc/grub.d/41_custom ###
#
×××× ××ך ×Öž×€× × ××Š× ×× ××Ö·×€Ö¿×¢× "grub-mkconfig -o /mnt/boot/grub/grub.cfg" ××× ××Öž× × ××©× ×××¢×× ×Š× ××Ö·×× ×¢× ×עך×× ××¢× ×Š× grub.cfg ××¢×עך ××Öž×, ×ַך××Ö·× ×× ××××× ×©×ך×ת (××Öž×××: ×€ÖŒ×ַך×Öž×) ××× ×× GRUB ××Ö·× ×׊עך שך××€× ××× ×× ×× ×Öž
nano /etc/grub.d/41_custom
ק×Ö·×¥ <<EOF
ש××¢×× ×¡×׀֌עך×סעךס = "ש×ךש"
password_pbkdf2 root grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8
EOF
×××¢× ×××©×¢× ×¢×š××××× × ×× ×§×Ö·× ×€×××עך××ש×Ö·× "grub-mkconfig -o /mnt/boot/grub/grub.cfg", ×× ×©×ך×ת ×€×ַך×Ö·× ××××֞ך×××¢× ×€Ö¿×ַך ×Öž××¢× ××ַק××ש×Ö·× ×××¢× ×××× ××ס××£ ×××××Öž××Ö·××ש ×Š× grub.cfg.
×עך שך×× ×§×Ö·××€ÖŒ×××¥ ×× GRUB2 ×Öž××¢× ××ַק××ש×Ö·× ×¡×¢××Ö·×€ÖŒ.
C6.2. ××Öž×Öž×××Öž×Ö·×עך ש××¥ ××× ××××××Ö·× ×ס××עעס ××× ×× ××¢× ×××¢× ×Ö·× ××ך ש××× ××Öž×× ×××× ×€×¢×š××¢× ××¢××¢ ×€ÖŒ××€ÖŒ ×¢× ×§×š×׀֌ש×Ö·× ×©×××¡× (×Öž×עך ××Ö·×× ×Ö·××Ö· ×Ö· ש××ס×). ×× ×¡×ס××¢× ×××× ××Öž×× ×§×š××€ÖŒ××Öž×ך×Ö·×€×ק ×××××××××š× ××× ×¡××Ö·××ך×: gnuPG; ק××¢×Öž×€ÖŒ×Ö·×ך×Ö· / ××€ÖŒ×Ö·; סע×Ö·××֞ךסע. קך××€ÖŒ××Öž ×××××××××š× ×××¢× ××Ö·×× ×××× ××¢×× ×€×× ×ך×× ×עך ××× ×Ö·××¢ ×Ö·××Ö· ×¢× ×× ××. סע×Ö·××֞ךסע - ס××Ö·××× ××עךס××¢ ×€×× ââ××¢× ×€ÖŒ×¢×§× 3.14.0 (××עךס×עס ××¢×עך, ××ש×, ××3.20, ××¢× ×¢× ×ע׀עק×××××¢ ××× ××Öž×× ××Ö·×××××ק ××Ö·××).
×× PGP ש×××¡× ××ַךף ×××× ×××©×¢× ×¢×š××××Ö·× / ××Öž× ××©× / ׊×××¢××¢×× ××××× ××× ×× ×¡× ×¡××××××¢!
×××©×¢× ×¢×š××× ×€ÖŒ×¢×š××¢× ××¢× ×¢× ×§×š×׀֌ש×Ö·× ×©××ס×
gpg - -gen-key
×ַך××ס׀××š× ×××× ×©××ס×
gpg --export -o ~/perskey
×Öž× ×§××Ö·×€ÖŒ× ×× ××Ö·××ש×ק×Ö·× ××סק ××× ×× ×ַס ×××× ×¢×¡ ××× × ××©× ×©××× ××Öž×× ××¢×
mount /dev/sda6 /mnt #sda6 â ÑазЎел GRUB2
ך××× ×× GRUB2 ׊ע×××××× ×
rm -rf /mnt/
×× ×¡××Ö·×××š× GRUB2 ××× sda6, ש××¢×× ×××× ×€ÖŒ×š××××Ö·× ×©×××¡× ××× ×× ××××€ÖŒ× GRUB ×××× "core.img"
grub-install --force --modules="gcry_sha256 gcry_sha512 signature_test gcry_dsa gcry_rsa" -k ~/perskey --root-directory=/mnt /dev/sda6
×֞׀֌׊×עס
* --×€×֞ךס - ×× ×¡××Ö·×××š× ×× ××Öž×Öž×××Öž×Ö·×עך, ××××€ÖŒ×ַס×× × ×Ö·××¢ ×× ×××Öž×š× ×× ×× ×××֞ס ש××¢× ××ק עקס×ס×××š× (×€×ך××× ×× ×€×Öž×).
* â××Öž×××עס = "gcry_sha256 gcry_sha512 signature_test gcry_dsa gcry_rsa" - ×× ×¡×ך×ַקץ GRUB2 ×Š× ×€ÖŒ×š×¢××Öž×Ö·× ×× × ××××ק ××Ö·××ש××× ×××¢× ×× ×€ÖŒ××¡× ×¡××ַךץ.
* -ק ~/׀֌עךסק×× -×€ÖŒ×Ö·× ×Š× ×× "PGP ש××ס×" (× ×Öž× ×€ÖŒ×ַק×× × ×× ×©×××¡× ××× ×× ××××, עס ×§×¢× ×¢× ×××× ×××ס××¢×עק×).
* --root-directory - ש××¢×× ×× ×©××××× ×××¢×××××Ö·×עך ×Š× ×עך ×××Öž×š×Š× ×€×× sda6
/dev/sda6 - ×××× sdaX ׊ע×××××× ×.
×××©×¢× ×¢×š××××× × / ×Ö·×€ÖŒ×××××× × grub.cfg
grub-mkconfig -o /mnt/boot/grub/grub.cfg
×××× ×× ×©××š× "trust /boot/grub/perskey" ×Š× ×× ×¡××£ ×€×× ×× "grub.cfg" ×עקע (קך×Ö·×€× × ××Š× ×€×× ×€ÖŒ××€ÖŒ ש××ס×.) ××× × ××ך ××Öž×× ××× ×¡××Ö·×××š× GRUB2 ××× ×Ö· ××Ö·× × ×€×× ××Ö·××ש×××, ×ַך××Ö·× ×עךע×× × ×× ×ס×××¢ ××Öž××××¢ "signature_test.mod", ××֞ס ×××××Ö·× ×××¥ ×× × ××× ×Š× ××××× ×§×Ö·××Ö·× ×× ××× "×¡×¢× ×שעק_ס××× ×Ö·××©×¢×š× = ×¢× ×€×֞ךס" ×Š× ×× ×§×Öž× ×€××.
עס ××Öž× ×§××§× ×¢×€ÖŒ×¢×¡ ××× ××֞ס (ס××£ ש×ך×ת ××× grub.cfg ×עקע)
### BEGIN /etc/grub.d/41_custom ###
×××× [-f ${config_directory}/custom.cfg]; ××¢××Öž××
×ק×ך ${config_directory}/custom.cfg
×¢×××£ [-× "${ק×Öž× ×€××_××ךעק××֞ך×}" -×Ö· -×€ $׀֌ךע׀×קס/ק×ַס××Ö·×.ק׀×]; ××¢××Öž××
×ק×ך $ ׀֌ךע׀×קס / ק×ַס××Ö·×.ק׀×;
fi
׊××ך×× /boot/grub/perskey
ש××¢×× ×¡×׀֌עך×סעךס = "ש×ךש"
password_pbkdf2 root grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8
### END /etc/grub.d/41_custom ###
#
×עך ××š× ×Š× "/boot/grub/perskey" ××ַךף × ×× ×××× ×©×€ÖŒ×׊×ק ×Š× ×Ö· ס׀֌ע׊××€×ש ××סק ׊ע×××××× ×, ×××©× HD0,6; ×€Ö¿×ַך ×× ××Öž×Öž×××Öž×Ö·×עך ×××, "ש×ךש" ××× ×× ×€×¢××ק××Ö·× ××š× ×€×× ×× ×Š×¢×××××× × ××××£ ×××֞ס GRUB2 ××× ××× ×¡××Ö·×××š× (××¢× ×©××¢×× ×š×Öž×=..).
ס××× ×× × GRUB2 (×Ö·××¢ ×עקעס ××× ×Ö·××¢ / GRUB ××ךעק×עך××) ××× ×××× ×©×××¡× "׀֌עךסק××".
× ×€ÖŒ×©×× ×××××× × ××××£ ××× ×Š× ×Š×××× (×€Ö¿×ַך nautilus/caja explorer): ×× ×¡××Ö·×××š× ×× "סע×Ö·××֞ךסע" ×עש׀֌ך××× ×€Ö¿×ַך Explorer ×€Ö¿×× ×× ×š××€ÖŒ×Ö·××Ö·××֞ך×. ×××× ×©×××¡× ×××× ×××× ××ס××£ ×Š× ×× ×¡× ×¡××××××¢.
×¢×€Ö¿× Explorer ××× ×¡×××Öž "/mnt/boot" - RMB - ׊××××. ××××£ ××¢× ×¢×§×š×Ö·× ×¢×¡ ק××§× ××× ××֞ס
×עך ש×××¡× ××× ××× "/mnt/boot/grub/perskey" (ק×Öž×€ÖŒ× ×Š× ×ך×× ×××¢×××××Ö·×עך) ×××× ×××× ×××× ××¢×ת××¢× ××× ×××× ××××× ×ס×××¢. ק×ק ×Ö·× ×× [*.ס××] ×עקע ס××× ×Ö·××©×¢×š× ×עךש××Ö·× ×¢× ××× ×× ×××¢×××××Ö·×עך / ס××××ךעק××֞ך×עס.
× ××Š× ××¢× ×××€Ö¿× ××סקך×××× ×××××, ׊×××× "/ ש×××××" (××× ××עך קעך×, ×× ××ך×). ×××× ×××× ×Š××× ××× ×××¢×š× ×¢×€ÖŒ×¢×¡, ×עך ×××€Ö¿× ×××××Ö·× ×××¥ ×× × ××× ×Š× ×©×š××Ö·×× ×Ö· ××ַש שך××€× ×Š× ×Š×××× "×Ö· ×€ÖŒ××Ö·×¥ ×€×× ×עקעס."
×Š× ××Ö·×××Ö·×××§× ×Ö·××¢ ××Öž×Öž×××Öž×Ö·×עך ס××× ×Ö·××©×¢×š× (×××× ×¢×€ÖŒ×¢×¡ ××× ×€×Ö·×ש)
rm -f $(find /mnt/boot/grub -type f -name '*.sig')
××× ×¡×ך × ××©× ×Š× ×Š×××× ×× ××Öž×Öž×××Öž×Ö·×עך × ×Öž× ×Ö·×€ÖŒ×××××× × ×× ×¡×ס××¢×, ××ך ׀ך××š× ×Ö·××¢ ×עך×××Ö·× ×××§× ×€ÖŒ×ַק×Ö·××ש×Ö·× ×©××Ö·××ת ×Š× GRUB2.
apt-mark hold grub-common grub-pc grub-pc-bin grub2 grub2-common
××× ××¢× ×©×š×× ×Ö·×××Ö·× ×¡×ך××¢ ק×Ö·× ×€×××עך××ש×Ö·× ×€×× GRUB2 ××× ××¢×¢× ××ק×.
C6.3. ×עך××××Ö·×-׀֌ך××××š× ×€×× ×× GRUB2 ××Öž×Öž×××Öž×Ö·×עך, ׀֌ך×Öž×עק××¢× ×××š× ××××××Ö·× ×ס×××¢ ××× ×Öž××¢× ××ַק××ש×Ö·×GRUB2. ×××¢× ×¡×Ö·×עק××× × ×§××× GNU / ××× ×קס ×€×ַךש׀֌ך××××× × ×Öž×עך ×ַך××Ö·× ×× CLI (ק×Ö·××Ö·× × ×©×ך×) ס×׀֌עך×סעך ×עך×××××¢× ×ש ×××¢× ×××× ×€×ך××× ××. × ×Öž× ×ַך××Ö·× ×× ×š××××ק × ×××¢× / ×€ÖŒ×ַך×Öž×, ××ך ×××¢× ××Ö·×š×€Ö¿× ×× ×× ×××š× ×€ÖŒ×ַך×Öž×
×¡×§×š×¢×¢× ×©×Öž× ×€×× ×עך×Öž×× ×Öž××¢× ××ַק××ש×Ö·× ×€×× ×× GRUB2 ס×׀֌עך×סעך.
×××× ××ך ××Ö·×׀֌עך ××× ×§××× ×€×× ×× GRUB2 ×עקעס / ××Ö·×× ×¢× ×עך×× ××¢× ×Š× grub.cfg, ×Öž×עך ××ס××¢×§× ×× ×עקע / ×ס×××¢, ×Öž×עך ××Öž×× ×Ö· ×××××¢ module.mod, ×Ö· ק×֞ך×ַס׀֌×Ö·× ××× × ××××š×¢× ×× × ×××¢× ×עךש××Ö·× ×¢×. GRUB2 ×××¢× ×€ÖŒ××××¢ ××Öž×××× ×.
×¡×§×š×¢×¢× ×©×Öž×, ×Ö·× ×€ÖŒ×š×××× ×Š× ×ַך××Ö·× ×××©× ××× ××× GRUB2 "×€×× ×ַך××ס".
×עש×ַס "× ×֞ך××Ö·×" ××××× × "×Öž× ×× ×ך××ש×Ö·×", ×× ×¡×ס××¢× ×ַך××ס××Ö·× × ×§×Öž× ×¡××Ö·××ס ××× "0". ×עך××עך, עס ××× ×××××ַק×Ö·× × ×Š× ×× ×©××¥ ×ַך××¢× ×Öž×עך × ××©× (××֞ס ×××, "××× ×Öž×עך ×Öž× ××Öž×Öž×××Öž×Ö·×עך ×ס×××¢ ש××¥" ×עש×ַס × ×֞ך××Ö·× ××Öž×××× × ×× ×¡××Ö·××ס ××× ×עך ××¢×××קעך "0" - ××֞ס ××× ×©××¢××).
××× ×Š× ×§×Öž× ×ך×Öž×××š× ××××××Ö·× ×ס×××¢ ש××¥?
×Ö· ××××ַק×××¢× ×××¢× ×Š× ×§×Öž× ×ך×Öž××ך×: ש×××× ×× / ×ַך×Öž×€ÖŒ× ×¢××¢× ×Ö· ××Öž××××¢ ××¢× ××Š× ×××š× GRUB2, ××ש×, ×ַך×Öž×€ÖŒ× ×¢××¢× ×× ×ס×××¢ luks.mod.sig ××× ××ַק×××¢× ×Ö· ××¢×ת.
×× ×š××××ק ×××¢×: ×××× ×Š× ×× ××Öž×Öž×××Öž×Ö·×עך CLI ××× ×××€ÖŒ ×× ××Ö·×€Ö¿×¢×
trust_list
××× ×¢× ×׀עך, ××ך ××Öž× ××ַק×××¢× ×Ö· "׀֌עךסק××" ×€×× ×עך׀֌ך×× ×; ×××× ×× ×¡××Ö·××ס ××× "0," ×ס×××¢ ש××¥ ××× × ××©× ×ַך××¢××, ××Öž×€ÖŒ× ×שעק ×€ÖŒ×ַך×Ö·×ך×Ö·×£ C6.2.
××× ××¢× ×©×š××, ×× ×Ö·×××Ö·× ×¡×ך××¢ ק×Ö·× ×€×××עך××ש×Ö·× "׀֌ך×Ö·×עק××× × GRUB2 ××× ××××××Ö·× ×ס×××¢ ××× ×Öž××¢× ××ַק××ש×Ö·×" ××× ××¢×¢× ××ק×.
C7 ×Ö·×××¢×š× ×Ö·×××××¢ ×××€Ö¿× ×€×× ×€ÖŒ×š×Ö·×עק××× × ×× GRUB2 ××Öž×Öž×××Öž×Ö·×עך × ××Š× ××ַש×× ××× "CPU Boot Loader Protection / Authentication" ×××€Ö¿× ××סקך×××× ××××× ××× ×Ö· ק××ַס×ש. ךע×× ×Š× ×× ××׀֌עך׀עקש×Ö·× × ×€×× GRUB2, ××× ×€ÖŒ×ַך×Ö·× ×Öž×× ×× ×Öž×× ×¢×¡ ××× ×¡×ַסע׀֌××Ö·××Ö·× ×Š× ×Ö· ×€×ַק××ש ××Ö·×€×Ö·××, ×××֞ס ××× ×××¢× ××¢×× ××× ×× ××× ×€ÖŒ×ַך×Ö·×ך×Ö·×£ [F]. ××× ×Ö·××ש×Ö·×, × ×Öž× ×Ö·×€ÖŒ×××××× × ×× ×ַס / קעך×, ×× ××Öž×Öž×××Öž×Ö·×עך ×××× ×××× ×©××Ö·×¢×-××¢×ת××¢×.
׀֌ך×Ö·×עק××× × ×× GRUB2 ××Öž×Öž×××Öž×Ö·×עך × ××Š× ××ַש×× ×
×Ö·××××Ö·× ××Ö·×עס ×××עך ק××ַס×ש:
- ××¢×עך ××ך×× ×€×× ×š×××××Ö·××××Ö·×× (××ַש×× × / ××עך×Ö·×€×ַק××ש×Ö·× × ×¢×× ×Öž×š× ××××× ×€×× ×Ö· ×× ×§×š××€ÖŒ××× ××××¢ ××××. ×× ××× ×Š×¢ ×Ö·××ַק××××× ×Š×¢×××××× × ××× ×עך GRUB2 ××× ×§×Ö·× ×ך×Öž××× ×€Ö¿×ַך ק××× ×¢× ×עך×× ××¢×, ××× ×Ö·××¥ ×Ö·× ×עךש ××× ×× ×§×š××€ÖŒ×××; ××× ×עך ק××ַס×ש ס××¢××¢ ××× ×§×€ÖŒ× ××Öž×עך ש××¥ / ×Öž××¢× ××ַק××ש×Ö·×, ××××× ×עקעס ××¢× ×¢× ×§×Ö·× ×ך×Öž×××, ×Öž×עך × ××©× ×€×š×× ×€ÖŒ××Ö·×¥, ××× ×××֞ס "ע׀֌עס" ע׀֌עס ××××" ×§×¢× ×¢× ×××× ×Š×××¢××¢××).
- ×¢× ×§×š××€ÖŒ××× ××Öž××× × (×Ö· ××¢× ×ש-×××× ×¢××××ק ׀֌עך××¢× ××¢× ×× ×§×š××€ÖŒ××× ×§××Öž×¥ ××× ××ס××£ ×Š× ×× ×¡××¢××¢).
- ×××ק××Ö·× (ש××¥ / ××עך×Ö·×€×ַק××ש×Ö·× ×€×× ×Ö· ××Ö·× ×¥ ׊ע×××××× × ×Ö·××ַק××××× ×€Ö¿×ַך GRUB2 ×Ö·×§×¢×š× ×ÖŒ××¢× ×××קעף).
- ×Öž××Ö·×××ש×Ö·× ×€×× ×Ö·××¢ קך××€ÖŒ××Öž×ך×Ö·×€×ק ׀֌ך×ַסעס×Ö·×.
××ס×Ö·××××Ö·× ××××ש×× ×××עך ×× ×§××ַס×קס.
- ××׊×× × ×€×× ×ת××× (×××¢×֞ךע××ק×Ö·×××, עס ××× ××¢×××¢× ×Š× ××¢×€Ö¿×× ×¢× ×Ö· ××ַש ×€Ö¿×× ×§×Š××¢ ׊×× ××׀ש×××ס).
- ××¢××××§×¡× ×©××עך×ק××× ××ך×× (ק×Ö·××€ÖŒ×¢×š× ×Š× ×§××ַס×ש, ×Ö· ×××¡× ×עך סק××× ××× GNU / Linux OS ××¢× ×¢× ×€×ך××× ××).
××× ×× GRUB2 / ׊ע×××××× × ××ַש×× × ××¢××Ö·× ×§ ×ַך××¢×
×× GRUB2 ׊ע×××××× × ××× "××¢×ת××¢×"; ×××¢× ×× ×ַס ש××, ×× ×©××××× ××Öž××עך ׊ע×××××× × ××× ×Öž×€ÖŒ×עש××¢×× ×€Ö¿×ַך ××××××Ö·××××××, × ××××¢××× ××¢× ×××š× ××Öž××× × ××× ×Ö· ×××עך (×¢× ×§×š××€ÖŒ×××) ס××××××¢. ×××× ×× ××Öž×Öž×××Öž×Ö·×עך ×Öž×עך ×××× ×Š×¢×××××× × ××× ×§×Ö·×׀֌ך×Ö·×××××, ××× ×Ö·××ש×Ö·× ×Š× ×× ×× ×ך××ש×Ö·× ×§××Öž×¥, ×× ×€××××¢× ××¢ ××× ××Öž× ×ש×:
××Ö·×.
× ×¢× ××¢× ×שעק ×Ö·×§×¢×š× ×€×ך ××× ×Ö· ××Öž×, ×××֞ס ××× × ××©× ××ַסע ס×ס××¢× ×š×¢×¡×ךס×.
× ××Š× ×× "-$ check_GRUB" ××Ö·×€Ö¿×¢×, ×Ö· ךע××¢ ×שעק ×Ö·×§×¢×š× ××× ×§××× ×Š××× ×Öž× ××Öž××× ×, ×Öž×עך ××× ××× ×€Ö¿×֞ך××ַ׊××¢ ךע×××××Ö·× ×Š× ×× CLI.
× ××Š× ×× ××Ö·×€Ö¿×¢× "-$ sudo signature_GRUB", ×× GRUB2 ש××××× ××Öž××עך / ׊ע×××××× × ××× ××××× ×©××Ö·×¢×-××¢×ת××¢× ××× ×עך×××Ö·× ×××§× ××Öž××× × (× ××××ק × ×Öž× ×ַס / ש××××× ×עך×××Ö·× ××ק×), ××× ××¢×× ×××× ××××£.
×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×€×× ×Ö· ××ַש×× × ×××€Ö¿× ×€Ö¿×ַך ×× ××Öž×Öž×××Öž×Ö·×עך ××× ×××Ö·× ×Öž×€ÖŒ×××××× ×
0) ××Öž××ך ׊×××× ×× GRUB ××Öž×Öž×××Öž×Ö·×עך / ׊ע×××××× × ×××š× ×¢×š×©×עך ××Ö·×× ××× × ×¢×¡ ××× / ××¢×××¢ / × ×××¢×
-$ hashdeep -c md5 -r /media/username/GRUB > /podpis.txt
1) ××ך ××Ö·×× ×Ö· שך××€× ×Öž× ×Ö· ×€×ַך××¢× ×עך×× × ××× ×עך ×××Öž×š×Š× ×€×× ×× ×× ×§×š××€ÖŒ××× ×ַס ~/×€ÖŒ×Öž××€ÖŒ×ס, ׊×××××× ×× × ××××ק 744 ×××עך×××× ×š×¢×× ××× ×€××׀֌ך×Öž×Öž×£ ש××¥ ×Š× ×¢×¡.
×€×××× × ×××Ö·× ××× ××Ö·××
#!/bin/bash
#ÐÑПвеÑка вÑегП ÑазЎела вÑЎелеММПгП пПЎ загÑÑзÑОк GRUB2 Ма МеОзЌеММПÑÑÑ.
#ÐеЎеÑÑÑ Ð»ÐŸÐ³ "П вÑПÑжеМОО/ÑÑпеÑМПй пÑПвеÑке каÑалПга", кПÑПÑе гПвПÑÑ Ð²ÐµÐŽÐµÑÑÑ Ð¿ÐŸÐ»ÐœÑй лПг Ñ ÑÑПйМПй веÑбалОзаÑОей. ÐМОЌаМОе! ПбÑаÑОÑÑ Ð²Ð·ÐŸÑ ÐœÐ° пÑÑО: Ñ
ÑаМОÑÑ ÐŠÐ GRUB2 ÑПлÑкП Ма заÑОÑÑПваММПЌ ÑазЎеле OS GNU/Linux.
echo -e "******************************************************************n" >> '/var/log/podpis.txt' && date >> '/var/log/podpis.txt' && hashdeep -vvv -a -k '/podpis.txt' -r '/media/username/GRUB' >> '/var/log/podpis.txt'
a=`tail '/var/log/podpis.txt' | grep failed` #Ме ОÑпПлÑзПваÑÑ "cat"!!
b="hashdeep: Audit failed"
#УÑлПвОе: в ÑлÑÑае лÑбÑÑ
какОÑ
-лОбП ОзЌеМеМОй в ÑазЎеле вÑЎелеММПЌ пПЎ GRUB2 к Ð¿ÐŸÐ»ÐœÐŸÐŒÑ Ð»ÐŸÐ³Ñ Ð¿ÐžÑеÑÑÑ Ð²ÑПÑПй ПÑЎелÑÐœÑй кÑаÑкОй лПг "ÑПлÑкП П вÑПÑжеМОО" О вÑвПЎОÑÑÑ ÐœÐ° ЌПМОÑÐŸÑ ÐŒÐžÐ³Ð°ÐœÐžÐµ gif-кО "warning".
if [[ "$a" = "$b" ]]
then
echo -e "****n" >> '/var/log/vtorjenie.txt' && echo "vtorjenie" >> '/var/log/vtorjenie.txt' && date >> '/var/log/vtorjenie.txt' & sudo -u username DISPLAY=:0 eom '/warning.gif'
fi
××××€× ×× ×©×š××€× ×€Ö¿×× su, ×× ××ַש×× × ×€×× ×× GRUB ׊ע×××××× × ××× ×××Ö·× ××Öž×Öž×××Öž×Ö·×עך ×××¢× ×××× ×Öž×€ÖŒ×עש××¢××, ך×Ö·××¢×××¢× ×× ×§××Öž×¥.
××Öž××ך ש×Ö·×€Ö¿× ×Öž×עך × ×Öž×××Ö·××, ××ש×, ×Ö· "×××××¢ ×עקע" [virus.mod] ×Š× ×× GRUB2 ׊ע×××××× × ××× ××××€× ×Ö· ׊××Ö·×××××Ö·××ק ××עךק××§× / ׀֌ך×Öž××¢:
-$ hashdeep -vvv -a -k '/podpis.txt' -r '/media/username/GRUB
×× CLI ×××× ××¢× ×Ö·× ×× ×××Ö·×××¢ ×€×× ââ××× ××עך -ס×××Ö·××¢×-# ×ך××××¢× ×§××Öž×¥ ××× CLI
Ð¡Ñ ÑМв 2 11::41 MSK 2020
/media/username/GRUB/boot/grub/virus.mod: Moved from /media/username/GRUB/1nononoshifr
/media/username/GRUB/boot/grub/i386-pc/mda_text.mod: Ok
/media/username/GRUB/boot/grub/grub.cfg: Ok
hashdeep: Audit failed
Input files examined: 0
Known files expecting: 0
Files matched: 325
Files partially matched: 0
Files moved: 1
New files found: 0
Known files not found: 0
# ××× ××ך ×§×¢× ×¢× ××¢×, "×€××עס ×ך××עך××¢×€×ך×: 1 ××× ×§×Öž× ×ך×Öž×××š× × ×× ×Ö·× ×עךש", ×××֞ס ×××× ×Ö·× ×× ×שעק ××× ××ך××עק×Öž××.
ךע×× ×Š× ×עך × ×Ö·××ך ×€×× ×× ×עס××¢× ×Š×¢×××××× ×, ×Ö·× ×©××Öž× ×€×× "× ××Ö·×¢ ×עקעס ××¢×€Ö¿×× ×¢×"> "Files ×ך××עך××¢×€×ך×"
2) ש××¢×× ×× ×××£ ××Öž > ~/warning.gif, ש××¢×× ×× ×€ÖŒ×¢×š××ש×Ö·× × ×Š× 744.
3) ק×Ö·× ×€×××עך ׀ס××Ö·× ×Š× ×Ö·×××Öž××Öž×× × ×× GRUB ׊ע×××××× × ××× ×©×××××
-$ sudo nano /etc/fstab
LABEL = GRUB / ××¢×××¢ / × ×××¢× / GRUB ext4 ×××€×Öž××¥ 0 0
4) ך×Öž××××××× × ×× ×§××Öž×¥
-$ sudo nano /etc/logrotate.d/podpis
/var/log/podpis.txt {
××¢×××¢×
×ך×××¢× 50
×ך××ס 5 ×
××Ö·×עעקס×
ק×Öž×׀֌ךעס
××¢×××ַק×Öž×׀֌ךעסס
olddir /var/log/old
}/var/log/vtorjenie.txt {
××××עש××¢×
×ך×××¢× 5
×ך××ס 5 ×
××Ö·×עעקס×
olddir /var/log/old
}
5) ×××× ×Ö· ×ַך××¢× ×Š× ×§×š×Ö·×
-$ sudo crontab -e
ךע××Öž×Öž× '/×Ö·××Öž× ×¢××¢× ×'
0 */6 * * * '/ ×€ÖŒ×Öž××€ÖŒ×ס
6) ש××€× ×©××¢× ××ק ×××××ַס××
-$ sudo su
-$ echo "alias пПЎпОÑÑ_GRUB='hashdeep -c md5 -r /media/username/GRUB > /podpis.txt'" >> /root/.bashrc && bash
-$ echo "alias пÑПвеÑка_GRUB='hashdeep -vvv -a -k '/podpis.txt' -r /media/username/GRUB'" >> .bashrc && bash
× ×Öž× OS ×עך×××Ö·× ×××§× -$ apt-get upgrade
ש××Ö·×¢×-׊×××× ××× ××עך GRUB ׊ע×××××× ×
-$ пПЎпОÑÑ_GRUB
××× ××¢× ×€×× ×, ××ַש×× × ×©××¥ ×€×× ×× GRUB ׊ע×××××× × ××× ××Ö·× ×¥.
[×] ×××××€ÖŒ×× × - ׊עש×עך×× × ×€×× ×Ö·× ×¢× ×§×š××€ÖŒ××× ××Ö·××
××ס××¢×§× ×××× ×€×¢×š××¢× ××¢××¢ ×עקעס ×Ö·××× ××֞ך ×Ö·× "× ×× ××€××× ××Öž× ×§×¢× ×¢× ××××¢× ×¢× ×××," ×××× ×ך×× ×§×ך××××× ×¢ ס׀֌×Öž×קס××Ö·× ×ך×× ××Öž××××.
××× ××¢××××× ×××¢×, עס ××¢× ×¢× ×€×ַךש××× "×××ס ×××
× ×Öž× ×׊××× ×ך×Ö·× ×¡×€×¢×š×× × GNU / Linux ×Š× ×Ö· ×× ×§×š××€ÖŒ××× ×Š×¢×××××× ×, ×× ×Ö·×× ×§×Öž×€ÖŒ××¢ ×××× ×××× ×××ס××¢××¢×§× ×Öž× ×× ××¢×××¢×ק××× ×€×× ××Ö·×× ×Öž×€ÖŒ×××. ×× ×××עךס×Ö·× ×š××× ×ק×× × ×××€Ö¿×: ×××××××××š× ×€Ö¿×ַך Windows / Linux ׀ך×× GUI ××××××××ך×
×©× ×¢× ×€Ö¿×֞ך××Ö·× ×× ×Öž×€ÖŒ×××××× ×, ×× ××Ö·×× ××××£ ×××֞ס ××ַךף ×Š× ×××× ×ך××Ö¿ (×××š× Gparted) ק×Ö·×עך BleachBit, סע×עק×××š× "ך××× ×€×š×× ×€ÖŒ××Ö·×¥" - סע×עק×××š× ××¢× ×Š×¢×××××× × (×××× sdaX ××× ×Ö· ׀ך×עך×××§× ×§×Öž×€ÖŒ××¢ ×€×× ââââGNU/Linux), ×× ×¡×ך××€ÖŒ×× × ×€ÖŒ×š×֞׊עס ×××¢× ×Öž× ×××××. BleachBit - ××××׀֌ס ×× ××סק ××× ×××× ×€×Öž×š× - ××֞ס ××× ×××֞ס "××ך ××ַך׀ֿ×", ×Öž×עך! ××֞ס ×ַך××¢× ××××× ××× ××¢×֞ך××¢ ×××× ××ך ×€×֞ך××Ö·×××¢× ××¢× ××סק ××× ×š××× ×¢×¡ ××× BB v2.0 ××××××××ך×.
××€×עךק××Ö·×ק××Ö·×! BB ××××׀֌ס ××¢× ××סק ××× ××Öž×× ××¢××Ö·××Ö·××Ö·; ×עקע × ×¢××¢× ××¢× ×¢× ××€××¢××× ×××¢× ××Ö·×× ××¢× ×¢× ×××××Ö·× ××××Ö·× (Ccleaner - ××× × ××©× ××Öž×× ××¢××Ö·××Ö·××Ö·).
××× ×עך ××××֞ס ×××¢×× ×× ××¢×××¢×ק××× ×€×× ××Ö·×× ×Öž×€ÖŒ××× ××× × ××©× ××¢××Ö·×ךע ×Ö· ××××֞ס.Bleachbit V2.0-2 עךש××¢ ×Ö·× ×¡×××××Ö·× ×ַס ××¢×××Ö·× ×€ÖŒ×¢×§× (××× ×§××× ×× ×עךע ×¢× ××¢× ××××××××ך×: sfill; ×××ש×-Nautilus - ××¢× ×¢× ×××× ××××¢×š×§× ××× ××¢× ×ך×Öž× ×עשע׀×) ×ַקש×× ××× ×Ö· קך×××ש ×ש×ק: ×× "׀ך×× ×€ÖŒ××Ö·×¥ ×€ÖŒ×Öž×××Ö·× ×¢" ×€Ö¿×× ×§×Š××¢ עס ×ַך××¢× ×€×Ö·×ש ××××£ ××× / ×€××ַש ×ך××××× (ntfs/ext4). ×××××××××š× ×€×× ××¢× ×××, ×××¢× ×§××ך×× × ×€×š×× ×€ÖŒ××Ö·×¥, ××× × ××©× ×Öž×××עךך××× ×× ××× ×Š×¢ ××סק, ××× ×€×××¢ ××××¢×š× ×ך×Ö·×××. ××× ×¢×××¢××¢ (×€×××¢) ×××ס××¢××¢×§× ××Ö·×× ×ַס / ×××××××××š× ×××× ×× ××Ö·×× ××× × ××-×××ס××¢××¢×§× / ××Ö·× ×׊עך ××Ö·×× ××× ×××¢× ×š××× ×ק×× × "×֞ס׀֌" עס סק×׀֌ס ×× ×עקעס. ×× ×€ÖŒ×š×Öž×××¢× ××× ×Ö·× × ×Öž× ×Ö·××Ö· ×Ö· ××Ö·× × ×Š××Ö·×, ך××× ×ק×× × ×× ××סק "×××ס××¢××¢×§× ×עקעס" ×§×¢× ×¢× ×××× ×š×ק×Ö·×××¢×š× ××€××× × ×Öž× 3+ ×€ÖŒ×ַס×× ×€×× ××××©× ×× ××סק.
××××£ GNU/Linux ××× Bleachbit 2.0-2 ×× ×€×Ö·× ×קש×Ö·× × ×€×× ×€ÖŒ×¢×š××Ö·× ×Ö·× ××× ××××××× × ×עקעס ××× ×××ךעק×עך×× ×ַך××¢× ×š×××××Ö·×××, ×Öž×עך × ××©× ×§××ך×× × ×€×š×× ×€ÖŒ××Ö·×¥. ×€Ö¿×ַך ×€×ַך××××Ö·×: ××××£ Windows ××× CCleaner ×× "OSP for ntfs" ×€Ö¿×× ×§×Š××¢ ×ַך××¢× ×š×¢××, ××× ××Öž× ××ַקע ×××¢× × ××©× ×§×¢× ×¢× ×Š× ××××¢× ×¢× ×××ס××¢××¢×§× ××Ö·××.
××× ×Ö·×××, ×Š× ×× ×××š× ××Ö·×××Ö·×××§× "ק×Öž×׀֌ך×Öž××ס×" ×Ö·×× ×Ö·× ×¢× ×§×š××€ÖŒ××× ××Ö·××, Bleachbit ××ַךף ×××š×¢×§× ×ַקסעס ×Š× ×× ××Ö·××, ××¢×š× ×Öž×, × ××Š× ×× "ש××¢× ××ק ××ס××¢×§× ×עקעס / ××ךעק×עך××" ×€Ö¿×× ×§×Š××¢.
×Š× ××Ö·×××Ö·×××§× "×××ס××¢××¢×§× ×עקעס × ××Š× × ×֞ך××Ö·× ×ַס ××ש×ך××" ××× Windows, × ××Š× CCleaner / BB ××× ×× "OSP" ×€Ö¿×× ×§×Š××¢. ××× GNU / ××× ×קס ×××עך ××¢× ×€ÖŒ×š×Öž×××¢× (××¢×§× ×××ס××¢×עק××¢ ×עקעס) ××ך ××Ö·×š×€Ö¿× ×Š× ××ַק×××¢× ×€×ך ××××£ ×××× ××××× (××××××× × ××Ö·×× + ×Ö· ׀ך××Ö· ׀֌ך×××× ×Š× ×××§×¢×š× ×¢×¡ ××× ××ך ××Öž× × ××©× ×€×ַך××Öž×× ××× ×× ×××××××××š× ××עךס××¢ (×××× × ××©× ×Ö· ××××¢× - ׊××××, ××¢××Öž×× ×Ö· ×ש×ק)), ××××× ××× ××¢× ×€×Ö·× ××ך ×§×¢× ×¢× ×€Ö¿×ַךש×××× ×× ×עק×Ö·× ×××Ö·× ×€×× ××¢× ×€ÖŒ×š×Öž×××¢× ××× ××ַק×××¢× ××ַ׀ך××Ö·×¢× ×€×× ×× ×××ס××¢××¢×§× ××Ö·×× ××֞ך.
××× ××× × ××©× ×עס××¢× Bleachbit v3.0, ×עך ׀֌ך×Öž×××¢× ×§×¢× ×××× ×©××× ×€×ַך׀עס××ק×.
Bleachbit v2.0 ×ַך××¢× ××Öž× ×¢×¡×××.
××× ××¢× ×©×š××, ××סק ×××××€ÖŒ×× × ××× ××Ö·× ×¥.
[E] ×× ×××עךס×Ö·× ××ַק×Ö·×€ÖŒ ×€×× ×× ×§×š××€ÖŒ××× ×ַס
××¢×עך ××Ö·× ×׊עך ××× ×××עך ××××× ×××€Ö¿× ×€×× ××ַק×× × ×ַך×××£ ××Ö·××, ×Öž×עך ×× ×§×š××€ÖŒ××× ×¡×ס××¢× ×ַס ××Ö·×× ×š×ק×××××¢×š× ×Ö· ×××¡× ×Ö·× ×עךש ׊×××Ö·× × ×Š× ×× ×ַך××¢×. ××× ×Ö·×€××× ××××××××ך×, ×Ö·××Ö· ××× Clonezilla ××× ×¢× ××¢× ××××××××ך×, ×§×¢× ×¢× × ××©× ×ַך××¢×× ××××Ö·× ××× ×× ×§×š××€ÖŒ××× ××Ö·××.
×עךק×עך×× × ×€×× ×× ×€ÖŒ×š×Öž×××¢× ×€×× ××ַק×× × ×ַך×××£ ×× ×§×š××€ÖŒ××× ×××֞ק ××¢×××סעס:
- ×× ×××עךס×Ö·×××× - ×עך ××¢×××קעך ××ַק×Ö·×€ÖŒ ×Ö·××עך×××Ö·× / ×××××××××š× ×€Ö¿×ַך Windows / ××× ×קס;
- ×× ×€×××ק××× ×Š× ×ַך××¢×× ××× ×× ×§×Ö·× ×¡×Öž×× ××× ×§××× ××¢×× ××¡× GNU / ××× ×קס ×Öž× ×× × ××× ×€Ö¿×ַך × ×Öž× ×××××××××š× ××Ö·×× ××Öž××× (×Öž×עך × ×Öž× ×š×¢×§×Öž××¢× ×××š× GUI);
- ×××עך×××× ×€×× ××ַק×Ö·×€ÖŒ ק××€×עס - ס××Öž×š× "××××עך" ×××× ×××× ×× ×§×š××€ÖŒ××× / ×€ÖŒ×ַך×Öž×-׀֌ך×Öž×עק××¢×;
- ×× ×ך××ס ×€×× ×× ×× ×§×š××€ÖŒ××× ××Ö·×× ×××× ×©××××¢× ×Š× ×× ×ך××ס ×€×× ×× ×€×ַק××ש ××Ö·×× ×§×Ö·×€ÖŒ××;
- ××ַק×××¢× ×קס×ך×ַקש×Ö·× ×€×× × ××××ק ×עקעס ×€×× ×Ö· ××ַק×Ö·×€ÖŒ ק×Öž×€ÖŒ××¢ (ק××× ×€×Öž×עך×× × ×Š× ×עקך××€ÖŒ× ×× ××× ×Š×¢ ×Öž×€ÖŒ×××××× × ×¢×š×©×עך).
×€Ö¿×ַך ×××ַש׀֌××, ××ַק×Ö·×€ÖŒ / ×××§×¢×š× ×××š× ×× "××" × ×׊×
dd if=/dev/sda7 of=/пÑÑÑ/sda7.img bs=7M conv=sync,noerror
dd if=/пÑÑÑ/sda7.img of=/dev/sda7 bs=7M conv=sync,noerror
עס ק×֞ך×ַס׀֌×Ö·× ×× ×Š× ×ÖŒ××¢× ×Ö·××¢ ×€×× ×§×× ×€×× ×עך ×ַך××¢×, ×Öž×עך ×××× ×Š× ×€×× × 4 עס ××× × ××©× ×©×××× ×ַך×××£ ×Š× ×§×š×××ק, ××××Ö·× ×¢×¡ ק×Ö·×€ÖŒ×× ×× ××× ×Š×¢ ××סק ׊ע×××××× ×, ×ַך××Ö·× ×עךע×× × ×€×š×× ×€ÖŒ××Ö·×¥ - × ×× ×ש×ק×Ö·×××¢.
×€Ö¿×ַך ×××ַש׀֌××, ×Ö· GNU/Linux ××ַק×Ö·×€ÖŒ ×××š× ×× ×ַך×ש×××עך [××ַך" | gpg] ××× ××ַק×××¢×, ×Öž×עך ×€Ö¿×ַך Windows ××ַק×Ö·×€ÖŒ ××ך ××Ö·×š×€Ö¿× ×Š× ×§××§× ×€Ö¿×ַך ×× ×× ×עך ×××××× × - ××֞ס ××× × ××©× ×ש×ק×Ö·×××¢.
E1. ×× ×××עךס×Ö·× Windows / ××× ×קס ××ַק×Ö·×€ÖŒ. ××× ×§ rsync (Grsync) + VeraCrypt ××Ö·× ××Ö·××עך×××Ö·× ×€Ö¿×ַך קך×××××× × ×Ö· ××ַק×Ö·×€ÖŒ ק×Öž×€ÖŒ××¢:
- קך×××××× × ×Ö· ×× ×§×š××€ÖŒ××× ×§×Ö·× ×××× ×¢×š (××× × / ×עקע) ××עך×ַקך××€ÖŒ× ×€Ö¿×ַך ×ַס;
- ×ַך××עך׀××š× / ס×× ×קך×Ö·× ××× ×× ×ַס × ××Š× Rsync ×××××××××š× ××× ×× VeraCrypt קך××€ÖŒ××Öž ק×Ö·× ×××× ×¢×š;
- ×××× × ××××ק, ××€ÖŒ××Öž×Ö·××× × ×× VeraCrypt ××Ö·× × ×Š× ××××××.
קך×××××× × ×Ö· ×× ×§×š××€ÖŒ××× VeraCrypt ק×Ö·× ×××× ×¢×š ××× ×××× ×××××¢× ×¢ קעך×ַק×עך×ס××קס:
ש××€× ×Ö· ××× ×Ö·××ש ××Ö·× × (ש×Ö·×€×× × ×€×× DT ××× ××××× ×× ×××Š× ××× Windows, ×§×¢× ×¢× ×××× ×××× ××¢××××× × ××× GNU / Linux);
ש×Ö·×€Ö¿× ×Ö· ךע×××עך ××Ö·× ×, ×Öž×עך עס ××× ×Ö· ×€×Öž×עך×× × ×€×× ×Ö· "×€ÖŒ×ַך×Ö·× ×Öž×× ××ַך×ַק×עך" (×××× ×× ××¢×××¢××֞׀֌עך) - ×€Ö¿×֞ך××Ö·××ך×× × ×€×× ×§×Ö·× ×××× ×¢×š.
× ××× ×Ö·××ש ××Ö·× × ××× ××ש××€× ×ÖŒ××¢× ×××קעף ××× Windows, ×Öž×עך ×××¢× ×§×Ö·×€ÖŒ××× × ××Ö·×× ×€Ö¿×× GNU / Linux> VeraCrypt DT, ×× ×§××××¢×××ק ×€×֞ךש××¢××× × ×€×× ×× ××ַק×Ö·×€ÖŒ ×֞׀֌עך×ַ׊××¢ ××קך×ס×Ö·× ×××××××ק.
× ×š×¢×××עך 70 GB Twofish ××Ö·× × ××× ××ש××€× (××Öž××ך × ×֞ך ××Öž××, ××××£ ××ך××©× ××××¢× ×€ÖŒ××¡× ××Ö·××) ×Š× ××× ~ ××× ××Ö·×× ×Ö· ×©×¢× (×Öž××עךך××××× × ×× ×¢×š×©××¢ ק×Ö·× ×××× ×¢×š ××Ö·×× ××× ×××× ×€×Öž×š× ××× ×š×¢×× ×Š× ×××עך×××× ×š×¢×§×××ךע××¢× ×¥). ×× ×€×× ×§×Š××¢ ×€×× ââââ××× ×€×֞ך××Ö·×××× × ×Ö· ××Ö·× × ×××¢× ×§×š×××××× × ×¢×¡ ××× ×Ö·××עק××¢× ×××¢× ×€×× VeraCrypt Windows / Linux, ×Ö·××× ×§×š×××××× × ×Ö· ק×Ö·× ×××× ×¢×š ××× ××××× ××¢×××¢× ×××š× "××××-×€×Öž×š× ×š×ך××××× ×" ×Öž×עך קך×××××× × ×Ö· × ××עך×ק-×€×֞ךש××¢××× × ××× ×Ö·××ש ××Ö·× ×.
ש×Ö·×€Ö¿× ×Ö· ךע×××עך VeraCrypt ××Ö·× × (× ×× ××× ×Ö·××ש / ntfs), עס ××Öž× × ××©× ×××× ×§××× ×€×š××××¢××¢×.
ק×Ö·× ×€×××עך / ש×Ö·×€Ö¿× / ×¢×€Ö¿×¢× ×¢× ×Ö· ק×Ö·× ×××× ×¢×š ××× VeraCrypt GUI> GNU / Linux ××¢×× ××¡× (×עך ××Ö·× × ×××¢× ×××× ×Ö·×××Öž××Öž×× ××¢× ×Š× / media/veracrypt2, ×× Windows OS ××Ö·× × ×××¢× ×××× ××Öž×× ××¢× ×Š× / media/veracrypt1). קך×××××× × ×Ö· ×× ×§×š××€ÖŒ××× ××ַק×Ö·×€ÖŒ ×€×× Windows OS × ××Š× GUI rsync (×ךס×× ×§)×××š× ×שעק ×× ××֞קסעס.
×××ַך×× ×€Ö¿×ַך ×× ×€ÖŒ×š×֞׊עס ×Š× ×€×Ö·×š×¢× ××ק×. ×Ö·××Öž× ×× ××ַק×Ö·×€ÖŒ ××× ××Ö·× ×¥, ××ך ×××¢×× ××Öž×× ×××× ×× ×§×š××€ÖŒ××× ×עקע.
ס×××××ַך××, ××Ö·×× ×Ö· ××ַק×Ö·×€ÖŒ ק×Öž×€ÖŒ××¢ ×€×× ââ×× GNU / ××× ×קס ×ַס ×××š× ×× ×שעקק ×× "×××× ××Öž×× ×§×Ö·××€ÖŒ×Ö·××Ö·××××Ö·××" ×שעקק××֞קס ××× ×× rsync GUI.
××€×עךק××Ö·×ק××Ö·×! ש×Ö·×€Ö¿× ×Ö· ××עך×ַק××€ÖŒ× ×§×Ö·× ×××× ×¢×š ×€Ö¿×ַך "GNU / Linux ××ַק×Ö·×€ÖŒ" ××× ×עך ×עקע ס×ס××¢× ×¢×§×¡××§×¡× ××קס. ×××× ××ך ××Ö·×× ×Ö· ××ַק×Ö·×€ÖŒ ×Š× ×Ö· ntfs ק×Ö·× ×××× ×¢×š, ×××¢× ××ך ×××§×¢×š× ×Ö·××Ö· ×Ö· ק×Öž×€ÖŒ××¢, ××ך ×××¢× ×€×ַך×××š× ×Ö·××¢ ךע×× / ×ך×׀֌עס ×Š× ×Ö·××¢ ×××× ××Ö·××.
×Ö·××¢ ×ַ׀֌עך××ש×Ö·× × ×§×¢× ×¢× ×××× ××ך××עק×Öž×× ××× ×× ×××֞ק××Ö·×. ×קעך××ק ×֞׀֌׊×עס ×€Ö¿×ַך rsync:
* -× -××× ×ך×׀֌עס;
* -P â ׀֌ך×Öž×ךעס â ס××Ö·××ס ×€×× ×× ×Š××× ×€×ך×ך××× ×ך××¢×× ××××£ ×עך ×עקע;
* -× - ק×Öž×€ÖŒ××¢ ××ַך×××× ×§×¡ ××× ×××;
* -×Ö· -×ַךק×××× ××Öž××¢ (ק×××€× rlptgoD ×€××Ö·×ס);
* -×× -××עך××Ö·×××××ש×Ö·×.
×××× ××ך ××××× ×Š× ×Öž× ×§××Ö·×€ÖŒ× ×Ö· "Windows VeraCrypt ××Ö·× ×" ×××š× ×× ×§×Ö·× ×¡×Öž×× ××× ×× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ ××××××××ך×, ××ך ×§×¢× ×¢× ××Ö·×× ×Ö·× ×Ö·×××ַס (ס×)
echo "alias veramount='cryptsetup open --veracrypt --tcrypt-system --type tcrypt /dev/sdaX Windows_crypt && mount /dev/mapper/ Windows_crypt /media/veracrypt1'" >> .bashrc && bash
×××Š× ×× "××עך×Ö·××Ö·×× × ××××עך" ××Ö·×€Ö¿×¢× ×××¢× ×€ÖŒ×× ×××¢× ××ך ×Š× ×ַך××Ö·× ×Ö· ×€ÖŒ×ַסס׀ך×ַסע, ××× ×× ×× ×§×š××€ÖŒ××× Windows ס×ס××¢× ××Ö·× × ×××¢× ×××× ××Öž×× ××¢× ××× ×× ×ַס.
××ַ׀֌ע / ×××š× VeraCrypt ס×ס××¢× ××Ö·× × ××× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ ××Ö·×€Ö¿×¢×
cryptsetup open --veracrypt --tcrypt-system --type tcrypt /dev/sdaX Windows_crypt
mount /dev/mapper/Windows_crypt /mnt
××ַ׀֌ע / ×××š× ××עך×ַקך××€ÖŒ× ×Š×¢×××××× × / ק×Ö·× ×××× ×¢×š ××× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ ××Ö·×€Ö¿×¢×
cryptsetup open --veracrypt --type tcrypt /dev/sdaY test_crypt
mount /dev/mapper/test_crypt /mnt
×Ö·× ×©××Öž× ×€×× ×Ö·×××ַס, ××ך ×××¢×× ××××× (×Ö· שך××€× ×Š× ×¡××ַך××Ö·×€ÖŒ) ×Ö· ס×ס××¢× ××Ö·× × ××× Windows OS ××× ×Ö· ××Ö·××ש×ק×Ö·× ×¢× ×§×š××€ÖŒ××× ntfs ××סק ×Š× GNU / Linux ס××ַך××Ö·×€ÖŒ
ש×Ö·×€Ö¿× ×Ö· שך××€× ××× ×š×Ö·××¢×××¢× ×¢×¡ ××× ~/VeraOpen.sh
printf 'Ym9i' | base64 -d | cryptsetup open --veracrypt --tcrypt-system --type tcrypt /dev/sda3 Windows_crypt && mount /dev/mapper/Windows_crypt /media/Winda7 #ЎекПЎОÑÑеЌ паÑÐŸÐ»Ñ ÐžÐ· base64 (bob) О ПÑпÑавлÑеЌ егП Ма запÑÐŸÑ Ð²Ð²ÐŸÐŽÐ° паÑÐŸÐ»Ñ Ð¿ÑО ЌПМÑОÑПваМОО ÑОÑÑеЌМПгП ЎОÑка ÐС Windows.
printf 'Ym9i' | base64 -d | cryptsetup open --veracrypt --type tcrypt /dev/sda1 ntfscrypt && mount /dev/mapper/ntfscrypt /media/ÐПМÑейМеÑÐÑÑÑ #аМалПгОÑМП, МП ЌПМÑОÑÑеЌ лПгОÑеÑкОй ЎОÑк ntfs.
××ך ×€×ַךש׀֌ך×××× ×× "ך××××××¢" ךע××:
sudo chmod 100 /VeraOpen.sh
ש×Ö·×€Ö¿× ×Š×××× ××××¢× ×ק×Ö·× ×עקעס (××¢×××קעך × ×Öž××¢×!) ××× /etc/rc.local ××× ~/etc/init.d/rc.local
×€×××× × ×× ×עקעס
#!/bin/sh -e
#
# rc.local
#
# This script is executed at the end of each multiuser runlevel.
# Make sure that the script will «exit 0» on success or any other
# value on error.
#
# In order to enable or disable this script just change the execution
# bits.
#
# By default this script does nothing.
sh -c "sleep 1 && '/VeraOpen.sh'" #пПÑле загÑÑзкО ÐС, жЎÑÐŒ ~ 1Ñ Ðž ÑПлÑкП пПÑПЌ ЌПМÑОÑÑеЌ ЎОÑкО.
exit 0
××ך ×€×ַךש׀֌ך×××× ×× "ך××××××¢" ךע××:
sudo chmod 100 /etc/rc.local && sudo chmod 100 /etc/init.d/rc.local
×Ö·× ×¡ עס, ×××Š× ×××¢× ××Öž×××× × GNU / ××× ×קס ××ך ××Öž× × ×× ××Ö·×š×€Ö¿× ×Š× ×ַך××Ö·× ×€ÖŒ×ַס××עך×× ×Š× ×Öž× ×§××Ö·×€ÖŒ× ×× ×§×š××€ÖŒ××× ntfs ××סקס, ×× ××סקס ××¢× ×¢× ××Öž×× ××¢× ×××××Öž××Ö·××ש.
× ××Ö·×עךק×× × ×עק×׊עך ×××¢×× ×××֞ס ××× ××סקך×××× ××××× ××× ×€ÖŒ×ַך×Ö·×ך×Ö·×£ E1 שך×× ×××š× ×©×š×× (×Öž×עך ×××Š× ×€Ö¿×ַך OS GNU / Linux)
1) ש×Ö·×€Ö¿× ×Ö· ××Ö·× × ××× fs ext4> 4gb (×€Ö¿×ַך ×עקע) ××× ×קס ××× ××עך×ַק××€ÖŒ× [קך××€ÖŒ×××֞קס].
2) ךע××Öž×Öž× ×Š× ××¢×× ×ס×.
3) ~$ קך××€ÖŒ×סע××Ö·×€ÖŒ ×¢×€×¢× ×¢× /dev/sda7 Lunux #××Ö·×€ÖŒ×× × ×¢× ×§×š××€ÖŒ××× ×Š×¢×××××× ×.
4) ~$ ×××š× /dev/mapper/Linux /mnt #×××š× ×× ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ×Š× /mnt.
5) ~$ mkdir mnt2 # קך×××××× × ×Ö· ×××¢×××××Ö·×עך ×€Ö¿×ַך ×Ö· ׊×ק×× ×€Ö¿× ××ַק×Ö·×€ÖŒ.
6) ~$ קך××€ÖŒ×סע××Ö·×€ÖŒ ×¢×€×¢× ×¢× âveracrypt â×××€ÖŒ tcrypt ~/CryptoBox CryptoBox && ×Öž× ×§××Ö·×€ÖŒ× /dev/mapper/CryptoBox /mnt2 #××ַ׀֌ע ×Ö· ××עך×ַק××€ÖŒ× ××Ö·× × ×××× × ×Öž××¢× "CryptoBox" ××× ×Öž× ×§××Ö·×€ÖŒ× ×× CryptoBox ×Š× /mnt2.
7) ~$ rsync -avlxhHX â ׀֌ך×Öž×ךעס / mnt / mnt2/ # ××ַקק××€ÖŒ ×֞׀֌עך×ַ׊××¢ ×€×× ââ×Ö· ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ×Š× ×Ö· ×× ×§×š××€ÖŒ××× ××עך×ַק××€ÖŒ× ××Ö·× ×.
(×€ÖŒ/ש/ ××€×עךק××Ö·×ק××Ö·×! ×××× ××ך ×ַך××עך׀××š× ×¢× ×§×š××€ÖŒ××× GNU / ××× ×קס ×€×× ×××× ×ַךק×Ö·×עק×שעך / ××ַש×× ×Š× ×× ×עך×, ××ש×, Intel> AMD (××֞ס ×××, ×××€ÖŒ××××× × ×Ö· ××ַק×Ö·×€ÖŒ ×€×× ×××× ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ×Š× ×× ×× ×עך ×× ×§×š××€ÖŒ××× Intel> AMD ׊ע×××××× ×), ×× ××××¡× × ××©× ×€×ַך××¢×¡× × ×Öž× ×ך×Ö·× ×¡×€×¢×š×× × ×× ×× ×§×š××€ÖŒ××× ×ַס, ךע××Ö·×××š× ×× ×¡×× ×€×ַך×ךע×עך ש×××¡× ×Ö·× ×©××Öž× ×€×× ×× ×€ÖŒ×ַך×Öž×, ×׀ֿשך. ×עך ׀ך×עך××קעך ש×××¡× ~/etc/skey - ×××¢× × ×× ×עך ×€ÖŒ×ַס×ק ×× ×× ×עך ×× ×§×š××€ÖŒ××× ×Š×¢×××××× ×, ××× ×¢×¡ ××× × ××©× ×§×¢×××Ö·×ק ×Š× ×©×Ö·×€Ö¿× ×Ö· × ××Ö·×¢ ש×××¡× "cryptsetup luksAddKey" ×€Ö¿×× ××× ×עך chroot - ×Ö· ××××ש ××× ××¢×××¢×, × ×֞ך ××× ~/etc/crypttab ס׀֌ע׊××€×׊××š× ×Ö·× ×©××Öž× ×€×× "/etc/skey" ××¢×׀֌עךעך×Ö·×× "ק×××" ", × ×Öž× ×š×¢××Öž×Öž× ××× ××Öž××× × ××× ×× ×ַס, ך×קך×××× ×××× ×¡×× ×××××ק×Ö·×š× ×©×××¡× ××××עך).
××× ×¢×¡ ×××¢×עך×Ö·× ×¡, ××¢××¢× ×§×¢× ×Š× ××Ö·×× ××ַק×ַ׀֌ס סע׀֌עך×Ö·××× ×€×× ×× ××¢××¢×š× ×€×× ×× ×§×š××€ÖŒ××× Windows / Linux OS ×€ÖŒ×ַך××ש×Ö·× ×, ×Öž×עך ×× ×¢× ×§×š×׀֌ש×Ö·× ×××¢× ×§×¢×š ××× ×§×¢×× ××ך.
××× ××¢× ×©×š××, ×× ××ַק×Ö·×€ÖŒ ×€×× ×× ×× ×§×š××€ÖŒ××× ×ַס ××× ××¢×¢× ××ק×.
[F] ××Ö·×€×Ö·×× ××××£ ×× GRUB2 ××Öž×Öž×××Öž×Ö·×עך
׀ך××××××× ××ך ××Öž× ×€ÖŒ×š×Öž×עק××¢× ×××× ××Öž×Öž×××Öž×Ö·×עך ××× ×Ö· ××××××Ö·× ×ס×××¢ ××× / ×Öž×עך ×Öž××¢× ××ַק××ש×Ö·× (××¢× ×€×× × C6.), ××¢××Öž×× ××֞ס ×××¢× × ××©× ××ַש××Š× ×§×¢×× ×ש×××ת ×ַקסעס. ×¢× ×§×š××€ÖŒ××× ××Ö·×× ×××¢× × ×Öž× ×××× ×× ×ַקסעס×Ö·××Ö·×, ×Öž×עך ×× ×©××¥ ×××¢× ×××× ××××€ÖŒ×Ö·×¡× (××ַש××¢××ק ××××××Ö·× ×ס×××¢ ש××¥) GRUB2 ×Ö·××Ö·×× ×Ö· ס×××עך ך×֞שע ×Š× ×ַך××Ö·× ×©×€ÖŒ×š××Š× ×××× ×§×Öž× ××× ×× ××Öž×Öž×××Öž×Ö·×עך ×Öž× ×š××××× × ××©× (ס××Ö·×× ×עך ××Ö·× ×׊עך ××Ö·× ×××Ö·×× ××Öž× ×××֞ךס ×× ××Öž×Öž×××Öž×Ö·×עך ש××Ö·×, ×Öž×עך ק××× ××× ×××עך ××××× ××¢××× × ×ַך×××ך×ַך×ש שך××€× ×§×Öž× ×€Ö¿×ַך grub.cfg).
××Ö·×€×Ö·×× ×Ö·××עך×××Ö·×. ×× ×ך××עך
* ×××¥ ×€ÖŒ××¡× ×€Ö¿×× ××¢×× ×ס×. ק××× ×¢× ×עך×× × (××¢××עך) ×עקעס ×××¢× ××¢×× ×Š× ××××¡× ×× ×€×ַק××ש ××Ö·××׊עך ×€×× ×× ×€ÖŒ××¡× ×××¢×× ×× ×× ×ך××ש×Ö·× ××× ×× ××Öž×Öž×××Öž×Ö·×עך. ×Öž×עך ×Ö· ׀֌ש×× ×š××× ×¡××Ö·×××Ö·×××Öž× ×€×× GRUB2 ××¢××¢×¡×§×¢× grub.cfg (××× ×× ×¡×Ö·×ס×ַק×××Ö·× × ×€×××ק××× ×Š× ×š×¢××Ö·×××š× ×¢×¡) ×××¢× ××Öž×× ×Ö·× ×Ö·××ַקעך ×Š× ×š×¢××Ö·×××š× ×§××× ×עקעס (××× ××¢× ×¡××××ַ׊××¢, ×××¢× ××Öž×××× × GRUB2, ×עך ×€×ַק××ש ××Ö·× ×׊עך ×××¢× × ××©× ×××× × ×Öž×××Ö·×€×××. ×עך ס××Ö·××ס ××× ×עך ××¢×××קעך )
* ××Ö·×× ×¥ ×Ö·× ×Ö·× ×¢× ×§×š××€ÖŒ××× ×Š×¢×××××× ×, ס××Öž×š× "/mnt/boot/grub/grub.cfg".
* ך××× ×¡××Ö·× ×× ××Öž×Öž×××Öž×Ö·×עך (ך××××××× × "׀֌עךסק××" ×€×× ×× core.img ××××)
grub-install --force --root-directory=/mnt /dev/sda6
* ךע×××š× ×¡ "grub.cfg"> "/mnt/boot/grub/grub.cfg", ךע××Ö·×××š× ×¢×¡ ×××× × ××××ק, ×€Ö¿×ַך ×××ַש׀֌××, ×Ö·××× × ×××× ××Öž××××¢ "keylogger.mod" ×Š× ×עך ×עקע ××× ××Öž××עך ××Ö·××ש×××, ××× "grub.cfg" > ש××š× "×× ×¡××Öž× ×§××××Öž××עך". ×Öž×עך, ×€Ö¿×ַך ×××ַש׀֌××, ×××× ×× ×€××Ö·× × ××× ×××ךע, ××¢××Öž×× × ×Öž× ×š××× ×¡××Ö·× ×ך××2 (×××¢ ס××× ×Ö·××©×¢×š× ×××××× ××× ×€ÖŒ××Ö·×¥) עס ××××¢× ×× ××××€ÖŒ× GRUB2 ×××× × ××Š× "grub-mkimage ××× ×֞׀֌׊××¢ (-c)." ×× "-c" ×֞׀֌׊××¢ ×××¢× ××Öž×× ××ך ×Š× ××Öž×× ×××× ×§×Ö·× ×€×××עך ××××עך ××Öž×××× × ×× ××××€ÖŒ× "grub.cfg". ×× ×§×Ö·× ×€×××עך××ש×Ö·× ×§×¢× ×¢× ×Š×× ××׀ש××¢×× ××× ×€×× ××××× ×××× ×©×ך×: ך××עךעקש×Ö·× ×Š× ×§××× "modern.cfg", ××¢××ש×, ××ש×, ××× ~ 400 ×עקעס (××Öž×××עס + ס××× ×Ö·×שעך×) ××× ×עך ×עקע "/boot/grub/i386-pc". ××× ××¢× ×€×Ö·×, ×Ö· ×Ö·××ַקעך ×§×¢× ×¢× ×ַך××Ö·× ××××× ×ַך×××ך×ַך×ש ק×Öž× ××× ××Öž×× ××Ö·××ש××× ×Öž× ×ַ׀עק××× × "/boot/grub/grub.cfg", ××€××× ×××× ×עך ××Ö·× ×׊עך ××Öž× ××¢×××¢× ×× "hashsum" ×Š× ×עך ×עקע ××× ××¢×׀֌עךעך×Ö·×× ××¢××××× ×¢×¡ ××××£ ××¢× ×¢×§×š×Ö·×.
×Ö· ×Ö·××ַקעך ×××¢× × ××©× ××Ö·×š×€Ö¿× ×Š× ××ַק ×× GRUB2 ס×׀֌עך×סעך ××Öž××× / ×€ÖŒ×ַך×Öž×; עך ×××¢× × ×֞ך ××Ö·×š×€Ö¿× ×Š× × ×Öž×××Ö·×× ×× ×©×ך×ת (×€×ַך×Ö·× ××××֞ך×××¢× ×€Ö¿×ַך ×Öž××¢× ××ַק××ש×Ö·×) "/boot/grub/grub.cfg" ×Š× ×××× "modern.cfg"
ש××¢×× ×¡×׀֌עך×סעךס = "ש×ךש"
password_pbkdf2 root grub.pbkdf2.sha512.10000.DE10E42B01BB6FEEE46250FC5F9C3756894A8476A7F7661A9FFE9D6CC4D0A168898B98C34EBA210F46FC10985CE28277D0563F74E108FCE3ACBD52B26F8BA04D.27625A4D30E4F1044962D3DD1C2E493EF511C01366909767C3AF9A005E81F4BFC33372B9C041BE9BA904D7C6BB141DE48722ED17D2DF9C560170821F033BCFD8
××× ×× ×€ÖŒ××¡× ××Ö·××׊עך ×××¢× × ×Öž× ×××× ×Öž××¢× ××ַק××××Ö·× ××× ×× GRUB2 ס×׀֌עך×סעך.
ק××× ××Öž×××× × (××Öž×Öž×××Öž×Ö·×עך ××Öž××× ×× ×× ×עך ××Öž×Öž×××Öž×Ö·×עך), ××× ××× ×עשך××× ×××××, ××× × ××©× ××Ö·×× ××× ×¢× (עס ××× ×××¢× ×€Ö¿×ַך ×Ö· ×Ö·× ×עךש ׊××). ×¢× ×§×š××€ÖŒ××× ××Öž×Öž×××Öž×Ö·×עך ×§×¢× ×¢× × ×× ×××× ××Öž×××× ×š×¢×× ×Š× ××××Öž×ס (ק××× ×©××××× ×š×ס××Ö·×š× GRUB2> ×¢× ×§×š××€ÖŒ××× GRUB2, ××¢×ת!). ×Öž×עך, ×××× ××ך × ×Öž× × ××Š× ××¢× ××¢××Ö·× ×§ ×€×× ××Öž×××× × ×§×××, ××ך ×§×¢× ×¢× ×××× ×××עך ×Ö·× ×¢×¡ ××× ×× ×× ×§×š××€ÖŒ××× ×××× ×¢×š ×××֞ס ××× ××Öž××××. (× ×× ××Ö·××¢×š× ××××) "grub.cfg" ×€Ö¿×× ×× ×× ×§×š××€ÖŒ××× ×Š×¢×××××× ×. ××× ××֞ס ××× ×××× ×Ö· ×€×Ö·×ש ××¢×€×× ×€×× ×××עך××××, ××××Ö·× ×Ö·××¥ ×××֞ס ××× ×× ××¢××××× ××× ×× ×× ×§×š××€ÖŒ××× "grub.cfg" (××Öž××××¢ ××Öž×××× ×) ××ס××£ ×ַך×××£ ×Š× ××Ö·××ש××× ×××֞ס ××¢× ×¢× ××Öž×××× ×€Ö¿×× ×Ö·× ×¢× ×§×š××€ÖŒ××× GRUB2.
×××× ××ך ××××× ×Š× ×§×Öž× ×ך×Öž×××š× ××¢×, ×Ö·××ַק××× / ×¢× ×§×š××€ÖŒ× ×× ×× ×עך ׊ע×××××× × sday, ק×Öž×€ÖŒ××¢ GRUB2 ×Š× ×¢×¡ (×ך××-×× ×¡××Ö·×××š× ×֞׀֌עך×ַ׊××¢ ××××£ ×Ö· ×× ×§×š××€ÖŒ××× ×Š×¢×××××× × ××× × ×× ××¢×××¢×) ××× ××× "grub.cfg" (×× ×¢× ×§×š××€ÖŒ××× ×§×Ö·× ×€×××עך××ש×Ö·×) ××××©× ×©×ך×ת ××× ××
menuentry 'GRUBx2' --class papegaai --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-simple-382111a2-f993-403c-aa2e-292b5eac4780' {
load_video
insmod gzio
×××× [קס$ ×ך××_×€ÖŒ××Ö·××€×֞ך××¢ = קססע×]; ××¢××Öž×× insmod xzio; insmod lzopio; fi
×× ×¡××Öž× ×€ÖŒ×ַך×_×ס××֞ס
×× ×¡××Öž× ×§×š××€ÖŒ××Öž××סק
insmod lux
×× ×¡××Öž× ×קך×_××××Öž×€×ש
×× ×¡××Öž× ×קך×_××××Öž×€×ש
×× ×¡××Öž× gcry_sha512
×× ×¡××Öž× ×¢×§×¡× 2
cryptomount -u 15c47d1c4bd34e5289df77bcf60ee838
set root=âcryptouuid/15c47d1c4bd34e5289df77bcf60ee838â²
× ×֞ך××Ö·× /boot/grub/grub.cfg
}
ש×ך×ת
* ×× ×¡××Öž× - ××Öž×××× × ×× × ××××ק ××Ö·××ש××× ×€Ö¿×ַך ×ך××¢×× ××× ×Ö· ×× ×§×š××€ÖŒ××× ××סק;
* GRUBx2 - × ×Öž××¢× ×€×× ×× ×©××š× ××¢××××× ××× ×× GRUB2 ש××××× ××¢× ××;
* קך××€ÖŒ××Öž××Öž×× × -u 15c47d1c4bd34e5289df77bcf60ee838 -××¢×. fdisk -l (sda9);
* ש××¢×× ×××Öž×š×Š× - ×× ×¡××Ö·×××š× ×××֞ך׊×;
* × ×֞ך××Ö·× /boot/grub/grub.cfg - עקסעק×××Ö·×××¢ ק×Ö·× ×€×××עך××ש×Ö·× ×עקע ××××£ ×Ö· ×× ×§×š××€ÖŒ××× ×Š×¢×××××× ×.
××××× ×Ö·× ×¢×¡ ××× ×× ×× ×§×š××€ÖŒ××× "grub.cfg" ×××֞ס ××× ××Öž×××× ××× ×Ö· positive ×¢× ×׀עך ×Š× ×ַך××Ö·× ×× ×€ÖŒ×ַך×Öž× / ×Ö·× ××ַק×× × "ס××Ö·×" ×××¢× ×¡×¢××× × ×× ×©××š× "GRUBx2" ××× ×× GRUB ××¢× ××.
×××¢× ××ך ×ַך××¢× ××× ×× CLI, ×Ö·××× × ××©× ×Š× ×Š×¢×××©× (××× ×שעק ×××× ×× "ש××¢×× ×××֞ך׊×" ס××××××¢ ×××Ö·××¢××××ק ××¢×ך××¢×), ש×Ö·×€Ö¿× ×××××ק ס×××¢× ×עקעס, ×€Ö¿×ַך ×××ַש׀֌××, ××× ×× ×× ×§×š××€ÖŒ××× ×Öž×€ÖŒ×××××× × "/shifr_grub", ××× ×× ×Ö·× ×¢× ×§×š××€ÖŒ××× ×Öž×€ÖŒ×××××× × "/noshifr_grub". ×שעק ××× ×× CLI
cat /Tab-Tab
××× ×עך××× × ×××××, ××֞ס ×××¢× × ××©× ××¢××€× ×Š× ××Ö·×× ××Öž×××× × ×××××¢ ××Ö·××ש××× ×××× ×Ö·××Ö· ××Ö·××ש××× ×¢× ×××§× ××××£ ×××× ×€ÖŒ×ס×. ×€Ö¿×ַך ×××ַש׀֌××, ×Ö· ק××××Öž××עך ×××֞ס ×××¢× ×§×¢× ×¢× ×Š× ×š×Ö·××¢×××¢× ×§×ס×ך×Öž×קס ×Š× ×Ö· ×עקע ××× ×××©× ×¢×¡ ××× ×× ×עךע ×עקעס ××× "~/i386" ××× ×¢×¡ ××× ××Ö·×× ××Öž×××× ×××š× ×Ö· ×Ö·××ַקעך ××× ×ש×××ת ×ַקסעס ×Š× ×× ×€ÖŒ×ס×.
×× ××××Ö·×¡× ×××¢× ×Š× ××ַש××¢×××§× ×Ö·× ××××××Ö·× ×ס×××¢ ש××¥ ××× ×ַק×××××× ×ך××¢×× (× ××©× ××ַש××¢××ק), ××× ×§××× ×××× ×¢×š ××× ×× ××××××× ×× ××Öž×Öž×××Öž×Ö·×עך, ×ַך××Ö·× ×× ××Ö·×€Ö¿×¢× ××× ×× CLI
list_trusted
××× ×¢× ×׀עך ××ך ××ַק×××¢× ×Ö· ק×Öž×€ÖŒ××¢ ×€×× ââ××× ××עך "׀֌עךסק××", ×Öž×עך ××ך ××ַק×××¢× ××Öž×š× ××©× ×××× ××ך ××¢× ×¢× ×§×¢×× (××ך ×××× ××Ö·×š×€Ö¿× ×Š× ×§×Öž× ×ך×Öž×××š× "×¡×¢× ×שעק_ס××× ×Ö·××ךע = ×¢× ×€×֞ךסע").
× ××Ö·×××××ק ××ס×Öž×š× ×€×× ××¢× ×©×š×× ××× ×ַך××Ö·× ×§×Ö·××Ö·× ×× ××Ö·× ×××Ö·××. ×××× ××ך ××××× ××¢× ××Ö·×€Ö¿×¢× ×Š× "grub.cfg" ××× ××ַש××Š× ×× ×§×Öž× ×€×× ××× ×Ö· ××××××Ö·× ×ס×××¢, ×× ×€ÖŒ×š×××××Ö·× ×¢×š× ×š×¢×××××Ö·× ×€×× ×× ×©×××¡× ××Öž××¢× ××××× ××××£ ××¢× ×¢×§×š×Ö·× ××× ×Š× ×§×ךץ ××× ×××××× ×, ××× ××ך ×§×¢× × ××©× ××Öž×× ×Š××× ×Š× ××¢× ×× ×š×¢×××××Ö·× × ×Öž× ××Öž×××× × GRUB2 .
עס ××× ×§××× ×××× ×¢×š ××× ××Ö·××× ×עך ×Š× ××Ö·×× ×§××××× ×Š×: ×עך ××¢×××¢××֞׀֌עך ××× ××××
"××Ö·×עךק×× × ×Ö·× ××€××× ××× GRUB ×€ÖŒ×ַך×Öž× ×©××¥, GRUB ××× ×§×¢× × ××©× ×€×ַך××××× ×¢×ע׊עך ××× ×€×××ש ×ַקסעס ×Š× ×× ××ַש×× ×€×× ×¢× ××¢×š× ×× ×€×ך××××ַךע ×€×× ââ×× ××ַש×× (×××©× ×§×֞ךע××Öž×Öž× ×Öž×עך ××××Öž×ס) ק×Ö·× ×€×××עך××ש×Ö·× ×Š× ×€×ַךש×Ö·×€× ×× ××ַש×× ×Š× ×©××××× ×€Ö¿×× ×Ö· ×Ö·× ×עךש (×Ö·××ַקעך ק×Ö·× ×ך×Öž×××) ××××. GRUB ××× ××× ×עס×עך ××××× ×××× ××× ×§ ××× ×Ö· ×××עך ש××××× ×§×××."
GRUB2 ××× ×Š× ×Öž×××עך××Öž×××× ××× ×€×Ö·× ×קש×Ö·× × ×××֞ס ×§×¢× ×¢× ××¢×× ×Ö· ××¢×€×× ×€×× ×€×Ö·×ש ×××עך××××, ××× ×××× ×Ö·× ××××ק××× × ××× ×©××× ×Ö·××ס×ך××€ÖŒ× MS-DOS ××× ×עך××× ×¢× ×€×× ×€×Ö·× ×קש×Ö·× ×Ö·××××, ×Öž×עך עס ××× × ×֞ך ×Ö· ××Öž×Öž×××Öž×Ö·×עך. עס ××× ××Öž×× ×¢ ×Ö·× GRUB2 - "××֞ך××" ×§×¢× ×¢× ×××¢×š× ×× ×ַס, ××× ××Öž×Öž××Ö·×××¢ GNU / Linux ×××ך×××Ö·× ××ש×× ×¢× ×€Ö¿×ַך עס.
× ×§×ךץ ×××××¢× ×××¢×× ××× ××× ××ַש××¢××ק ×× GRUB2 ××××××Ö·× ×ס×××¢ ש××¥ ××× ×עךק××¢×š× ×××× ×× ×ך××ש×Ö·× ×Š× ×Ö· ×€×ַק××ש ××Ö·× ×׊עך (××× ××Öž× ××ך ×עךשך×֞ק×, ×Öž×עך ×Ö·× ×©××Öž× ×€×× ×××֞ס ××× ××¢××××× ××× ×× ×××××¢×, ××ך ×§×¢× ×¢× ×©×š××Ö·×× × ××-×שע×××¢× ×ַך×××ך×ַך×ש ק×Öž× /.××Öž×).
ק×Ö·× ×§×××ש×Ö·× ×:
1) ×€×ַךש׀֌×Ö·×š× ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·× ×€Ö¿×ַך Windows ××× ×ך×× ×עך ×Š× ×× ×¡×ך×××¢× ×, ××× ×©××¥ ××× ×××× ×€ÖŒ×ַך×Öž× ××× ×עך ××ַק×××¢× ××× ×©××¥ ××× ×¢×××¢××¢ ×€ÖŒ×ַס××עך×× ××× GNU/Linux ×××֞ק ס×ס××¢× ×¢× ×§×š×׀֌ש×Ö·×, ×Š× ×××× ×©×××: ×× ××¢× ×¢×š ××× ×Öž××Ö·××××××.
2) ××× ×עשך××× ××¢× ×ַך×××§× ××× ××Ö·×××Ö·××ק ××× ××××××× simple ×Ö· ×××¢×××××Ö·×עך ×Š× ×€××-××סק ×¢× ×§×š×׀֌ש×Ö·× VeraCrypt / LUKS ××××£ ×××× ×××× ××ַש××, ×××֞ס ××× ××× ××××Ö·× ×עך ×עס×עך ××× RuNet (IMHO). ×עך ×€×ךעך ××× > 50 ק ××ת××ת ××Ö·× ×, ×Ö·××× ×¢×¡ ××× × ××©× ××¢×§× ×¢×××¢××¢ ×ש×ק×Ö·×××¢ ×ש×Ö·×€ÖŒ×עך×: קך××€ÖŒ××Öž×ך×ַ׀עךס ×××֞ס ×€×ַךש×××× ×× / ××Ö·××× ××× ×× ×©×Ö·××Öž××; ×××¢×× ××¢× ×××ס ××× ×€×ךש×××¢× ×¢ ×× ×/××× ×קס ×××עך שך×××× ××¢× ××××× ×× / שך×××× × ××©× ×××¢×× ×§×š××€×××ך××€××¢; ×××¢×× ×ַך×××§× 51 ×€×× ×× ×§×Öž× ×¡×××××××Öž× ×€×× ×× ×š×ס×שע ×€×¢×עך××ש×Ö·×; ×Öž
3) ××Ö·× ×¥ ××סק ×¢× ×§×š×׀֌ש×Ö·× ××× ××ך××עק×Öž×× ××××£ Windows 7 64; GNU/Linux Parrot 4x; GNU/Debian 9.0/9.5.
4) ×××€ÖŒ××Ö·××¢× ××Ö·× ×Ö· ×׊××× ××Ö·×€×Ö·×× ××××£ ×××× GRUB2 ××Öž×Öž×××Öž×Ö·×עך.
5) ××××֞ך××Ö·× ××× ××¢×××¢× ××ש××€× ×Š× ××¢××€× ×Ö·××¢ ×× ×€ÖŒ×ַך×Ö·× ×Öž×× ××¢× ××©× ××× ×× ×¡×ס, ××× ×ך××¢×× ××× ×¢× ×§×š×׀֌ש×Ö·× ××× ×עך××××× ××××£ ×× ××¢××ס××Ö·×××××¢ ××ך××. ××× ××€Ö¿×š× ×€Ö¿×ַך ××¢× ×¢ ×××֞ס ××××× ×Š× ××סש×××¡× ×€××-××סק ×¢× ×§×š×׀֌ש×Ö·× ×Öž× ××××Ö·××ש×× × ×××עך ק×Ö·× ×€××××¢×š× ×¡×ס××¢××¢×.
6) ך××××¢×š×§× ××× ×עך×××Ö·× ×××§× ×××× ××Ö·× ××Ö·×, ×××֞ס ××× ××Ö·×××Ö·××ק ××× 2020.
[×] × ×׊×ק ××ַק××××¢× ×××ש×Ö·×
TrueCrypt ××Ö·× ×׊עך ×××× (×€×¢×ך××ך 2012 ך×)VeraCrypt ××֞ק×××¢× ××Ö·×××Öž× - /usr/share/doc/cryptsetup(-run) [××××¢ ××××] (××Ö·×Ö·××עך ××××××× ××ַק××××¢× ×××ש×Ö·× ××××£ ××ַש××¢×××§× GNU / ××× ×קס ×¢× ×§×š×׀֌ש×Ö·× × ××Š× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ)
××Ö·×Ö·××עך FAQ קך××€ÖŒ×סע××Ö·×€ÖŒ (ק×ךץ ××ַק××××¢× ×××ש×Ö·× ××××£ ××ַש××¢×××§× GNU / ××× ×קס ×¢× ×§×š×׀֌ש×Ö·× × ××Š× ×§×š××€ÖŒ×סע××Ö·×€ÖŒ)LUKS ×××× ×¢× ×§×š×׀֌ש×Ö·× (×ַך×ש××× ×קס ××ַק××××¢× ×××ש×Ö·×)××××××× ××ַשך××Ö·××× × ×€×× ×§×š××€ÖŒ×סע×××€ÖŒ ס×× ××ַקס (×ַך×ש ××¢× ×ש ×××Ö·×)××××××× ××ַשך××Ö·××× × ×€×× ×§×š××€ÖŒ××Ö·× (×ַך×ש ××¢× ×ש ×××Ö·×)××Ö·×Ö·××עך GRUB2 ××ַק××××¢× ×××ש×Ö·× .
××Ö·×ס: ×€×× ××סק ×¢× ×§×š×׀֌ש×Ö·×, ׊ע×××××× × ×¢× ×§×š×׀֌ש×Ö·×, ××× ×קס ×€×× ××סק ×¢× ×§×š×׀֌ש×Ö·×, LUKS1 ×€×× ×¡×ס××¢× ×¢× ×§×š×׀֌ש×Ö·×.
××××× ×š×¢××ס×ך××š× × ×׊עךס ×§×¢× ×¢× ×Öž× ×××× × ×¢××¢× ××× ×× ××עך×××ק.
××¢× × ××ך ×¢× ×§×š××€ÖŒ××× ×?
-
×§×¡× ××קס%××× ×¢× ×§×š××€ÖŒ× ×Ö·××¥ ××× ×§×¢× ×¢×. ××× ××× ×€ÖŒ×ַך×Ö·× ×Öž××.14
-
×§×¡× ××קס%××× × ×֞ך ×¢× ×§×š××€ÖŒ× ××××××ק ××Ö·××Ö·.28
-
×§×¡× ××קס%××× ××× ×¢× ×§×š××€ÖŒ×, ××× ××× ×€×ַך×עס×.12
-
×§×¡× ××קס%× ×××, ××× ××Öž× × ×× ×× ×§×š××€ÖŒ×, עס ××× ××××ַק×××¢× ××× ×××ַעך.28
82 ××× ×׊עך ×××× ×עש××××. 22 ××× ×׊עך ×××× ××× ××€××¢×××××.
×ק×ך: www.habr.com