¹ØÓÚ·À±¸OpenClaw£¨¡°ÁúϺ¡±£©¿ªÔ´ÖÇÄÜÌ尲ȫ·çÏյġ°ÁùÒªÁù²»Òª¡±½¨Òé
°ä²¼¹¦·ò 2026-03-11Õë¶Ô¡°ÁúϺ¡±µäÐÍÀûÓ󡾰ϵݲȫ·çÏÕ£¬¹¤ÒµºÍÐÅÏ¢»¯²¿ÍøÂ簲ȫÍþвºÍ·ì϶ÐÅÏ¢¹²ÏíÆ½Ì¨£¨NVDB£©×éÖ¯ÖÇÄÜÌåÌṩÉÌ¡¢·ìÏ¶ÍøÂçÆ½Ì¨ÔËÓªµ¥Ôª¡¢ÍøÂ簲ȫÆóÒµµÈ£¬×êÑÐÌá³ö¡°ÁùÒªÁù²»Òª¡±½¨Òé¡£
Ò»¡¢µäÐÍÀûÓó¡¾°°²È«·çÏÕ
£¨Ò»£©ÖÇÄܰ칫³¡¾°ÖØÒª´æÔÚ¹©¸øÁ´¹¥»÷ºÍÆóÒµÄÚÍøÉøÈëµÄ͹¹Î·çÏÕ
1.³¡¾°ÃèÊö£ºÍ¨¹ýÔÚÆóÒµÄÚ²¿²¿Êð¡°ÁúϺ¡±£¬¶Ô½ÓÆóÒµÒÑÓÐÖÎÀíϵͳ£¬ÊµÏÖÖÇÄÜ»¯Êý¾Ý·ÖÎö¡¢Îĵµ´¦Öá¢ÐÐÕþÖÎÀí¡¢²ÆÕþ¸¨ÖúºÍ֪ʶÖÎÀíµÈ¡£
2.°²È«·çÏÕ£ºÒýÈëÒì³£²å¼þ¡¢¡°¼¼Êõ°ü¡±µÈÒý·¢¹©¸øÁ´¹¥»÷£»ÍøÂ簲ȫ·çÏÕÔÚÄÚÍøºáÏòÀ©É¢£¬Òý·¢ÒѶԽӵÄϵͳƽ̨¡¢Êý¾Ý¿âµÈÃô¸ÐÐÅϢй¶»òÃÔʧ£»²»×ãÉó¼ÆºÍ×·Òä»úÔìÇé¿öÏÂÒ×Òý·¢ºÏ¹æ·çÏÕ¡£
3.Ó¦¶ÔÕ½Êõ£º¶ÀÁ¢Íø¶Î²¿Êð£¬Óë¹Ø¼ü³ö²ú»·¾³¸ôÀëÔËÐУ¬²»ÈÝÔÚÄÚ²¿ÍøÂçʹÓÃδÉóÅúµÄ¡°ÁúϺ¡±ÖÇÄÜÌåÖÕ¶Ë£»²¿Êðǰ½øÐгä·Ö°²È«²âÊÔ£¬²¿Êðʱ²ÉÈ¡×îÓ×»¯È¨ÏÞÊÚÓ裬²»ÈݷDZØÒªµÄ¿çÍø¶Î¡¢¿çÉ豸¡¢¿çϵͳ½Ó¼û£»Áô´æÆëÈ«²Ù×÷ºÍÔËÐÐÈÕÖ¾£¬È·±£Âú×ãÉó¼ÆµÈºÏ¹æÒªÇó¡£
£¨¶þ£©¿ª·¢ÔËά³¡¾°ÖØÒª´æÔÚϵͳÉ豸Ãô¸ÐÐÅϢй¶ºÍ±»½Ù³Ö½ÚÔìµÄ͹¹Î·çÏÕ
1.³¡¾°ÃèÊö£ºÍ¨¹ýÆóÒµ»òÓ×ÎÒ²¿Êð¡°ÁúϺ¡±£¬½«ÌìȻ˵»°×ª»¯Îª¿ÉÖ´ÐÐÖ¸Á¸¨Öú½øÐдúÂë±àд¡¢´úÂëÔËÐÓ×¢É豸Ѳ¼ì¡¢ÅäÖñ¸·Ý¡¢ÏµÍ³¼à¿Ø¡¢ÖÎÀí¹ý³ÌµÈ¡£
2.°²È«·çÏÕ£º·ÇÊÚȨִÐÐϵͳºÅÁÉ豸ÔâÍøÂç¹¥»÷½Ù³Ö£»ÏµÍ³Õ˺źͶ˿ÚÐÅϢ¶³ö£¬Ôâ·ê±í²¿¹¥»÷»ò¿ÚÁî±¬ÆÆ£»ÍøÂçÍØÆË¡¢ÕË»§¿ÚÁî¡¢API½Ó¿ÚµÈÃô¸ÐÐÅϢй¶¡£
3.Ó¦¶ÔÕ½Êõ£ºÔ¤·À³ö²ú»·¾³Ö±½Ó²¿ÊðʹÓã¬ÓÅÏÈÔÚÐé¹¹»ú»òɳÏäÖÐÔËÐУ»²¿Êðǰ½øÐгä·Ö°²È«²âÊÔ£¬²¿Êðʱ²ÉÈ¡×îÓ×»¯È¨ÏÞÊÚÓ裬²»ÈÝÊÚÓèÖÎÀíԱȨÏÞ£»³ÉÁ¢¸ßΣºÅÁîºÚÃûµ¥£¬³ÁÒª²Ù×÷ÆôÓÃÈËΪÉóÅú»úÔì¡£
£¨Èý£©Ó×ÎÒ¸±ÊÖ³¡¾°ÖØÒª´æÔÚÓ×ÎÒÐÅÏ¢±»ÇÔºÍÃô¸ÐÐÅϢй¶µÄ͹¹Î·çÏÕ
1.³¡¾°ÃèÊö£ºÍ¨¹ýÓ×ÎÒ¼´Ê±Í¨Ñ¶Èí¼þµÈÔ¶³Ì½ÓÈë±¾µØ»¯²¿ÊðµÄ¡°ÁúϺ¡±£¬ÌṩÓ×ÎÒÐÅÏ¢ÖÎÀí¡¢ÈÕ³£ÊÂÎñ´¦Öá¢Êý×Ö×ʲúÕû¶ÙµÈ£¬²¢¿É×÷Ϊ֪ʶ½ø½¨ºÍÉúÑÄÓéÀÖ¸±ÊÖ¡£
2.°²È«·çÏÕ£ºÈ¨ÏÞ¹ý¸ßµ¼Ö¶ñÒâ¶Áд¡¢É¾³ýËÁÒâÎļþ£»»¥ÁªÍø½ÓÈëÇé¿öÏÂÔâ·êÍøÂç¹¥»÷ÈëÇÖ£»Í¨¹ýÌáÐÑ´Ê×¢ÈëÎóÖ´ÐÐΣÏÕºÅÁÉõÖÁÊÕÊÜÖÇÄÜÌ壻Ã÷ÎÄ´æ´¢ÃÜÔ¿µÈµ¼ÖÂÓ×ÎÒÐÅϢй¶»ò±»ÇÔÈ¡¡£
3.Ó¦¶ÔÕ½Êõ£º¼ÓǿȨÏÞÖÎÀí£¬½öÔÊÐí½Ó¼û±ØÒªÄ¿Â¼£¬²»ÈݽӼûÃô¸ÐĿ¼£»ÓÅÏÈͨ¹ý¼ÓÃÜͨ·½ÓÈ룬²»ÈݷDZØÒª»¥ÁªÍø½Ó¼û£¬²»ÈݸßΣ²Ù×÷Ö¸Áî»òÔö³¤¶þ´ÎÈ·ÈÏ£»Ñϸñͨ¹ý¼ÓÃÜ·½Ê½´æ´¢APIÃÜÔ¿¡¢ÅäÖÃÎļþ¡¢Ó×ÎÒ³ÁÒªÐÅÏ¢µÈ¡£
£¨ËÄ£©½ðÈÚÂòÂô³¡¾°ÖØÒª´æÔÚÒý·¢ÃýÎóÂòÂôÉõÖÁÕË»§±»ÊÕÊܵÄ͹¹Î·çÏÕ
1.³¡¾°ÃèÊö£ºÍ¨¹ýÆóÒµ»òÓ×ÎÒ²¿Êð¡°ÁúϺ¡±£¬Å²ÓýðÈÚÓйØÀûÓýӿڣ¬½øÐÐ×Ô¶¯»¯ÂòÂôÓë·çÏÕ½ÚÔ죬Ìá¸ßÁ¿»¯ÂòÂô¡¢ÖÇÄÜͶÑм°×ʲú×éºÏÖÎÀíЧÄÜ£¬ÊµÏÖÊг¡Êý¾Ýץȡ¡¢Õ½Êõ·ÖÎö¡¢ÂòÂôÖ¸ÁîÖ´ÐеÈÖ°ÄÜ¡£
2.°²È«·çÏÕ£ºÓ°ÏóͶ¶¾µ¼ÖÂÃýÎóÂòÂô£¬Éí·ÝÈÏÖ¤ÈÆ¹ýµ¼ÖÂÕË»§±»·¸·¨ÊÕÊÜ£»ÒýÈëÔ̺¬¶ñÒâ´úÂëµÄ²å¼þµ¼ÖÂÂòÂôƾ֤±»ÇÔÈ¡£»¼«¶ËÇé¿öÏÂÒò²»×ãÈÛ¶Ï»òÓ¦¼±»úÔ죬µ¼ÖÂÖÇÄÜÌåʧ¿ØÆµÈÔϵ¥µÈ·çÏÕ¡£
3.Ó¦¶ÔÕ½Êõ£ºÖ´ÐÐÍøÂç¸ôÀëÓë×îÓ×ȨÏÞ£¬¹Ø¹Ø·Ç±ØÒª»¥ÁªÍø¶Ë¿Ú£»³ÉÁ¢ÈËΪ¸´ºËºÍÈÛ¶ÏÓ¦¼±»úÔ죬¹Ø¼ü²Ù×÷Ôö³¤¶þ´ÎÈ·ÈÏ£»Ç¿»¯¹©¸øÁ´ÉóºË£¬Ê¹Óùٷ½×é¼þ²¢¶¨ÆÚ½¨¸´·ì϶£»ÂäʵȫÁ´Â·Éó¼ÆÓ밲ȫ¼à²â£¬ÊµÊ±·¢ÏÖ²¢´ëÖð²È«·çÏÕ¡£
¶þ¡¢°²È«Ê¹Óý¨Òé
£¨Ò»£©Ê¹Óùٷ½×îа汾¡£Òª´Ó¹Ù·½Çþ·ÏÂÔØ×îв»±ä°æ±¾£¬²¢¿ªÆô×Ô¶¯¸üÐÂÌáÐÑ£»ÔÚÉý¼¶Ç°±¸·ÝÊý¾Ý£¬Éý¼¶ºó³ÁÆô·þÎñ²¢ÑéÖ¤²¹¶¡ÊÇ·ñÉúЧ¡£²»ÒªÊ¹ÓõÚÈý·½¾µÏñ°æ±¾»òº¹Çà°æ±¾¡£
£¨¶þ£©Ñϸñ½ÚÔ컥ÁªÍøÂ¶³öÃæ¡£Òª¶¨ÆÚ×Ô²éÊÇ·ñ´æÔÚ»¥ÁªÍøÂ¶³öÇé¿ö£¬Ò»µ©·¢ÏÖÁ¢¼´ÏÂÏßÕû¸Ä¡£²»Òª½«¡°ÁúϺ¡±ÖÇÄÜÌåÊ·ý¶³öµ½»¥ÁªÍø£¬È·Ð軥ÁªÍø½Ó¼ûµÄÄܹ»Ê¹ÓÃSSHµÈ¼ÓÃÜͨ·£¬²¢Ï޶ȽӼûÔ´µØÖ·£¬Ê¹ÓÃÇ¿ÃÜÂë»òÖ¤Êé¡¢Ó²¼þÃÜÔ¿µÈÈÏÖ¤·½Ê½¡£
£¨Èý£©¶ÔÖÅ×îÓ×ȨÏÞ×¼Ôò¡£ÒªÆ¾¾ÝÒµÎñ±ØÒªÊÚÓèʵÏÖ¹¤×÷±ØÐëµÄ×îÓ×ȨÏÞ£¬¶Ôɾ³ýÎļþ¡¢·¢ËÍÊý¾Ý¡¢Åú¸ÄϵͳÅäÖõȳÁÒª²Ù×÷½øÐжþ´ÎÈ·ÈÏijÈËΪÉóÅú¡£ÓÅÏÈ˼¿¼ÔÚÈÝÆ÷»òÐé¹¹»úÖиôÀëÔËÐУ¬ÐγɶÀÁ¢µÄȨÏÞÇøÓò¡£²»ÒªÔÚ²¿ÊðʱʹÓÃÖÎÀíԱȨÏÞÕ˺š£
£¨ËÄ£©ÉóÉ÷ʹÓü¼ÊõÊг¡¡£ÒªÉóÉ÷ÏÂÔØClawHub¡°¼¼Êõ°ü¡±£¬²¢ÔÚ×°ÖÃǰÉó²é¼¼Êõ°ü´úÂë¡£²»ÒªÊ¹ÓÃÒªÇó¡°ÏÂÔØZIP¡±¡¢¡°Ö´ÐÐshell¾ç±¾¡±»ò¡°ÊäÈëÃÜÂ롱µÄ¼¼Êõ°ü¡£
£¨Î壩·À±¸Éç»á¹¤³Ìѧ¹¥»÷ºÍä¯ÀÀÆ÷½Ù³Ö¡£ÒªÊ¹ÓÃä¯ÀÀÆ÷ɳÏä¡¢ÍøÒ³¹ýÂËÆ÷µÈÀ©´ó×èÖ¹¿ÉÒɾ籾£¬ÆôÓÃÈÕÖ¾Éó¼ÆÖ°ÄÜ£¬Óöµ½¿ÉÒÉÐÐΪÁ¢¼´¶Ï¿ªÍø¹Ø²¢³ÁÖÃÃÜÂë¡£²»Òªä¯ÀÀÀ´Àú²»Ã÷µÄÍøÕ¾¡¢µã»÷İÉúµÄÍøÒ³Á´½Ó¡¢¶ÁÈ¡²»³ÉÐÅÎĵµ¡£
£¨Áù£©³ÉÁ¢³¤Ð§·À»¤»úÔì¡£Òª¶¨ÆÚ²é³²¢½¨²¹·ì϶£¬ÊµÊ±¹Ø×¢OpenClaw¹Ù·½°²È«²¼¸æ¡¢¹¤ÒµºÍÐÅÏ¢»¯²¿ÍøÂ簲ȫÍþвºÍ·ì϶ÐÅÏ¢¹²ÏíÆ½Ì¨µÈ·ì϶¿âµÄ·çÏÕÔ¤¾¯¡£µ³Õþ»ú¹Ø¡¢ÆóÊÂÒµµ¥ÔªºÍÓ×ÎÒÓû§Äܹ»½áºÏÍøÂ簲ȫ·À»¤¹¤¾ß¡¢Ö÷Á÷ɱ¶¾Èí¼þ½øÐÐʵʱ·À»¤£¬ÊµÊ±´ëÖÿÉÄÜ´æÔڵݲȫ·çÏÕ¡£²»Òª½ûÓþßÌåÈÕÖ¾Éó¼ÆÖ°ÄÜ¡£
¸½Â¼£º²¿ÃŰ²È«»ùÏß¼°ÅäÖòο¼
Ò»¡¢ÖÇÄÜÌ岿Êð
´´½¨OpenClawרÓÐЧ»§£¬ÇÐÎðʹÓÃsudo×飺
sudo adduser --shell /bin/rbash --disabled-password clawuser
ͨ¹ý´´½¨µÄרÓÐЧ»§µÇ¼²Ù×÷ϵͳ¡£
´´½¨ÊÜÏ޵ĺÅÁîĿ¼£¬²»ÈÝrm¡¢mv¡¢dd¡¢format¡¢powershellµÈ£º
sudo mkdir -p /home/clawuser/bin
sudo ln -s /bin/ls /home/clawuser/bin/ls
sudo ln -s /bin/echo /home/clawuser/bin/echo
Ç¿ÔìÉèÖà PATH ²¢Ö»¶Á£¬ÈçÔÚ /etc/profile.d/restricted_clawuser.shÅú¸ÄÅäÖãº
echo 'if [ "$USER" = "clawuser" ]; then export PATH=/home/clawuser/bin; readonly PATH; fi' | sudo tee /etc/profile.d/restricted_clawuser.sh
sudo chmod 644 /etc/profile.d/restricted_clawuser.sh
½ûÓÃrootµÇ¼£º
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config
sudo systemctl restart sshd
¶þ¡¢ÏÞ¶È»¥ÁªÍø½Ó¼û
£¨Ò»£©Linux·þÎñÆ÷ÅäÖÃ
´´½¨×Ô½ç˵Á´£º
sudo iptables -N ALLOWED_IPS
Ôö³¤ÔÊÐíµÄIP£¨IPµØÖ·ÎªÊ¾Àý£¬²Ù×÷ʱÐè´úÌæÎªÏÖʵIPµØÖ·£©£º
sudo iptables -A ALLOWED_IPS -s 192.168.1.100 -j ACCEPT
sudo iptables -A ALLOWED_IPS -s 10.0.0.5 -j ACCEPT
sudo iptables -A ALLOWED_IPS -s 172.24.57.160 -j ACCEPT
sudo iptables -A ALLOWED_IPS -j RETURN
ÀûÓõ½SSH¶Ë¿Ú£º
sudo iptables -A INPUT -p tcp --dport 22 -j ALLOWED_IPS
sudo iptables -A INPUT -p tcp --dport 17477 -j ALLOWED_IPS
´Ë±í£¬¿É²Î¿¼ÉÏÊöºÅÁî¹Ø¹ØÒÔ϶˿ڻ¥ÁªÍø½Ó¼û»òÉèÖÃIPµØÖ·°×Ãûµ¥£ºTelnet£¨23£©¡¢WindowsÎļþ¹²Ïí£¨135¡¢137¡¢138¡¢139¡¢445£©¡¢WindowsÔ¶³Ì×ÀÃæ£¨3389£©¡¢Ô¶³Ì×ÀÃæ½ÚÔ죨5900-5910£©¡¢Êý¾Ý¿âÀà¶Ë¿Ú£¨3306¡¢5432¡¢6379¡¢27017£©¡£
£¨¶þ£©VPN½ÓÈëµÄÇé¿öÏÂÅäÖÃ
½«OpenClaw Gateway°ó¶¨127.0.0.1£¬ÇÐÎðÖ±½Ó°ó¶¨µ½0.0.0.0¡£
¹Ø¹Ø18789¶Ë¿Ú£º
sudo ufw deny 18789
Ô¶³Ì½Ó¼ûʱǿÔìʹÓÃVPN²¢ÆôÓÃGatewayÈÏÖ¤£¨ÔÚopenclaw.jsonÖÐÉèÖÃgateway.auth.mode: "token"¼°Ç¿ÁîÅÆ£©¡£
Èý¡¢¿ªÆô¾ßÌåÈÕÖ¾
¿ªÆôÈÕÖ¾¼Í¼£º
openclaw gateway --log-level debug >> /var/log/openclaw.log 2>&1
ËÄ¡¢Îļþϵͳ½Ó¼û½ÚÔì
ÔÚDocker²¿ÊðÅäÖÃÎļþ(docker-compose.yml)ÖУ¬ÀûÓÃvolumes²ÎÊý½«ÏµÍ³¹Ø¼üĿ¼¹ÒÔØÎª:ro£¨Ö»¶Á£©Ä£Ê½£¬½ö±£ÁôÌØ¶¨µÄ/workspaceΪ¿Éд״̬¡£
ÔÚËÞÖ÷»úϵͳ²ã£¬Í¨¹ýchmod 700Ö¸Áî¶Ô˽ÃÜÊý¾ÝĿ¼ִÐÐÇ¿Ôì½Ó¼û½ÚÔ죺
sudo chmod 700 /path/to/your/workspace
Îå¡¢µÚÈý·½¼¼ÊõÉó²é
×°ÖÃǰִÐм¼ÊõÉó²éºÅÁ
openclaw skills info
²¢Éó²é~/.openclaw/skills/
ÓÅÏÈÑ¡ÓÃÄÚÖÃ55¸öSkill»òÉçÇø¾«Ñ¡ÁÐ±í£¨Èçawesome-openclaw-skills£©¡£
Áù¡¢°²È«×Ô¼ì
¶¨ÆÚÔËÐа²È«Éó¼ÆºÅÁ
openclaw security audit
Õë¶ÔÉ󼯷¢ÏֵݲȫÒþ»¼£¬ÈçÍø¹ØÈÏ֤¶³ö¡¢ä¯ÀÀÆ÷½ÚÔì¶³öµÈ£¬ÊµÊ±ÒÀÕÕÉÏÊö°²È«»ùÏß¼°ÅäÖòο¼¡¢¹Ù·½ÊÖ²áµÈ½øÐдëÖá£
Æß¡¢¸üа汾
ÔËÐа汾¸üкÅÁ
openclaw update
°Ë¡¢Ð¶ÔØ
´ò¿ªÖÕ¶Ë£¬Ö´ÐÐɾ³ýºÅÁ
openclaw uninstall
ʹÓÃÊó±ê¸ßµÍÒÆ¶¯¹â±ê£¬°´¿Õ¸ñ¼ü¹´Ñ¡ËùÓÐÑ¡Ï¶øºó°´»Ø³µ¼üÈ·ÈÏ¡£
Ñ¡Ôñyes²¢°´»Ø³µ£¬´ËºÅÁî»á×Ô¶¯É¾³ýOpenClawµÄ¹¤×÷Ŀ¼¡£
Ð¶ÔØnpm°ü£º
1. ʹÓÃnpm×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ
npm rm -g openclaw
2. ÈôÊÇʹÓÃpnpm×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ
pnpm remove -g openclaw
3. ÈôÊÇʹÓÃbun×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ
bun remove -g openclaw


¾©¹«Íø°²±¸11010802024551ºÅ