#!/bin/bash
set -ex
export DEBIAN_FRONTEND=noninteractive
apt update
apt install -y mosh ufw unzip dnsutils vim screen
# 关闭tcp 53端口(systemd-resolved服务)
sed -i "s/#DNS=/DNS=1.1.1.1/" /etc/systemd/resolved.conf
sed -i "s/#DNSStubListener=yes/DNSStubListener=no/" /etc/systemd/resolved.conf
# 关闭tcp 6010端口(X11 forwarding)
sed -i "s/X11Forwarding yes/X11Forwarding no/" /etc/ssh/sshd_config
# 安装xfce4桌面环境
apt install -y xfce4
# 安装firefox
apt install -y snapd
apt install -y firefox
# 安装中文输入法
apt install -y language-pack-zh-hans
apt install -y fonts-wqy-zenhei
#apt install -y fcitx
#apt install -y fcitx-pinyin fcitx-sunpinyin
apt install -y fcitx5 fcitx5-chinese-addons fcitx5-frontend-gtk4 fcitx5-frontend-gtk3 fcitx5-frontend-gtk2 fcitx5-frontend-qt5
# 安装xrdp
apt install -y xrdp
# 配置防火墙
# 禁止自动添加ipv6的规则
sed -i "s/IPV6=yes/IPV6=no/" /etc/default/ufw
# 增加端口限制
ufw allow 26424/tcp # ssh
ufw allow 443/tcp
ufw allow 32768/tcp
ufw allow 80/tcp
ufw allow 3389/tcp # xrdp
ufw allow 60000:61000/udp # mosh
ufw default deny incoming
ufw enable
wget --no-check-certificate -O ${HOME}/Xray-script.sh https://raw.githubusercontent.com/zxcvos/Xray-script/main/reality.sh && bash ${HOME}/Xray-script.sh
reboot
搬瓦工系统设置
于 2024-02-23 16:59:20 首次发布