¹ØÓÚ·À±¸OpenClaw£¨¡°ÁúϺ¡±£©¿ªÔ´ÖÇÄÜÌ尲ȫ·çÏյġ°ÁùÒªÁù²»Òª¡±½¨Òé
°ä²¼¹¦·ò 2026-03-11Õë¶Ô¡°ÁúϺ¡±µäÐÍÀûÓ󡾰ϵݲȫ·çÏÕ£¬¹¤ÒµºÍÐÅÏ¢»¯²¿ÍøÂ簲ȫÍþвºÍ·ì϶ÐÅÏ¢¹²ÏíÆ½Ì¨£¨NVDB£©×éÖ¯ÖÇÄÜÌåÌṩÉÌ¡¢¡¢¡¢·ìÏ¶ÍøÂçÆ½Ì¨ÔËÓªµ¥Ôª¡¢¡¢¡¢ÍøÂ簲ȫÆóÒµµÈ£¬×êÑÐÌá³ö¡°ÁùÒªÁù²»Òª¡±½¨Òé¡£¡£
Ò»¡¢¡¢¡¢µäÐÍÀûÓó¡¾°°²È«·çÏÕ
£¨Ò»£©ÖÇÄܰ칫³¡¾°ÖØÒª´æÔÚ¹©¸øÁ´¹¥»÷ºÍÆóÒµÄÚÍøÉøÈëµÄ͹¹Î·çÏÕ
1.³¡¾°ÃèÊö£º£º£ºÍ¨¹ýÔÚÆóÒµÄÚ²¿²¿Êð¡°ÁúϺ¡±£¬¶Ô½ÓÆóÒµÒÑÓÐÖÎÀíϵͳ£¬ÊµÏÖÖÇÄÜ»¯Êý¾Ý·ÖÎö¡¢¡¢¡¢Îĵµ´¦Öᢡ¢¡¢ÐÐÕþÖÎÀí¡¢¡¢¡¢²ÆÕþ¸¨ÖúºÍ֪ʶÖÎÀíµÈ¡£¡£
2.°²È«·çÏÕ£º£º£ºÒýÈëÒì³£²å¼þ¡¢¡¢¡¢¡°¼¼Êõ°ü¡±µÈÒý·¢¹©¸øÁ´¹¥»÷£»£»£»ÍøÂ簲ȫ·çÏÕÔÚÄÚÍøºáÏòÀ©É¢£¬Òý·¢ÒѶԽӵÄϵͳƽ̨¡¢¡¢¡¢Êý¾Ý¿âµÈÃô¸ÐÐÅϢй¶»òÃÔʧ£»£»£»²»×ãÉó¼ÆºÍ×·Òä»úÖÆÇé¿öÏÂÒ×Òý·¢ºÏ¹æ·çÏÕ¡£¡£
3.Ó¦¶ÔÕ½Êõ£º£º£º¶ÀÁ¢Íø¶Î²¿Êð£¬Óë¹Ø¼ü³ö²ú»·¾³¸ôÀëÔËÐУ¬²»ÈÝÔÚÄÚ²¿ÍøÂçʹÓÃδÉóÅúµÄ¡°ÁúϺ¡±ÖÇÄÜÌåÖÕ¶Ë£»£»£»²¿Êðǰ½øÐгä·Ö°²È«²âÊÔ£¬²¿Êðʱ²ÉÈ¡×îС»¯È¨ÏÞÊÚÓ裬²»ÈݷDZØÒªµÄ¿çÍø¶Î¡¢¡¢¡¢¿çÉ豸¡¢¡¢¡¢¿çϵͳ½Ó¼û£»£»£»Áô´æÆëÈ«²Ù×÷ºÍÔËÐÐÈÕÖ¾£¬È·±£Âú×ãÉó¼ÆµÈºÏ¹æÒªÇ󡣡£
£¨¶þ£©¿ª·¢ÔËά³¡¾°ÖØÒª´æÔÚϵͳÉ豸Ãô¸ÐÐÅϢй¶ºÍ±»½Ù³Ö½ÚÖÆµÄ͹¹Î·çÏÕ
1.³¡¾°ÃèÊö£º£º£ºÍ¨¹ýÆóÒµ»òСÎÒ²¿Êð¡°ÁúϺ¡±£¬½«ÌìȻ˵»°×ª»¯Îª¿ÉÖ´ÐÐÖ¸Á¸¨Öú½øÐдúÂë±àд¡¢¡¢¡¢´úÂëÔËÐС¢¡¢¡¢É豸Ѳ¼ì¡¢¡¢¡¢ÅäÖñ¸·Ý¡¢¡¢¡¢ÏµÍ³¼à¿Ø¡¢¡¢¡¢ÖÎÀí¹ý³ÌµÈ¡£¡£
2.°²È«·çÏÕ£º£º£º·ÇÊÚȨִÐÐϵͳºÅÁÉ豸ÔâÍøÂç¹¥»÷½Ù³Ö£»£»£»ÏµÍ³Õ˺źͶ˿ÚÐÅϢ¶³ö£¬Ôâ·êÍⲿ¹¥»÷»ò¿ÚÁî±¬ÆÆ£»£»£»ÍøÂçÍØÆË¡¢¡¢¡¢ÕË»§¿ÚÁî¡¢¡¢¡¢API½Ó¿ÚµÈÃô¸ÐÐÅϢй¶¡£¡£
3.Ó¦¶ÔÕ½Êõ£º£º£ºÔ¤·À³ö²ú»·¾³Ö±½Ó²¿ÊðʹÓã¬ÓÅÏÈÔÚÐé¹¹»ú»òɳÏäÖÐÔËÐУ»£»£»²¿Êðǰ½øÐгä·Ö°²È«²âÊÔ£¬²¿Êðʱ²ÉÈ¡×îС»¯È¨ÏÞÊÚÓ裬²»ÈÝÊÚÓèÖÎÀíԱȨÏÞ£»£»£»³ÉÁ¢¸ßΣºÅÁîºÚÃûµ¥£¬ÖØÒª²Ù×÷ÆôÓÃÈËΪÉóÅú»úÖÆ¡£¡£
£¨Èý£©Ð¡ÎÒÖúÊÖ³¡¾°ÖØÒª´æÔÚСÎÒÐÅÏ¢±»ÇÔºÍÃô¸ÐÐÅϢй¶µÄ͹¹Î·çÏÕ
1.³¡¾°ÃèÊö£º£º£ºÍ¨¹ýСÎÒ¼´Ê±Í¨Ñ¶Èí¼þµÈÔ¶³Ì½ÓÈë±¾µØ»¯²¿ÊðµÄ¡°ÁúϺ¡±£¬ÌṩСÎÒÐÅÏ¢ÖÎÀí¡¢¡¢¡¢ÈÕ³£ÊÂÎñ´¦Öᢡ¢¡¢Êý×Ö×ʲúÕû¶ÙµÈ£¬²¢¿É×÷Ϊ֪ʶѧϰºÍÉúÑÄÓéÀÖÖúÊÖ¡£¡£
2.°²È«·çÏÕ£º£º£ºÈ¨ÏÞ¹ý¸ßµ¼Ö¶ñÒâ¶Áд¡¢¡¢¡¢É¾³ýËÁÒâÎļþ£»£»£»»¥ÁªÍø½ÓÈëÇé¿öÏÂÔâ·êÍøÂç¹¥»÷ÈëÇÖ£»£»£»Í¨¹ýÌáÐÑ´Ê×¢ÈëÎóÖ´ÐÐΣÏÕºÅÁÉõÖÁÊÕÊÜÖÇÄÜÌ壻£»£»Ã÷ÎÄ´æ´¢ÃÜÔ¿µÈµ¼ÖÂСÎÒÐÅϢй¶»ò±»ÇÔÈ¡¡£¡£
3.Ó¦¶ÔÕ½Êõ£º£º£º¼ÓǿȨÏÞÖÎÀí£¬½öÔÊÐí½Ó¼û±ØÒªÄ¿Â¼£¬²»ÈݽӼûÃô¸ÐĿ¼£»£»£»ÓÅÏÈͨ¹ý¼ÓÃÜͨµÀ½ÓÈ룬²»ÈݷDZØÒª»¥ÁªÍø½Ó¼û£¬²»ÈݸßΣ²Ù×÷Ö¸Áî»òÔö³¤¶þ´ÎÈ·ÈÏ£»£»£»Ñϸñͨ¹ý¼ÓÃÜ·½Ê½´æ´¢APIÃÜÔ¿¡¢¡¢¡¢ÅäÖÃÎļþ¡¢¡¢¡¢Ð¡ÎÒÖØÒªÐÅÏ¢µÈ¡£¡£
£¨ËÄ£©½ðÈÚÂòÂô³¡¾°ÖØÒª´æÔÚÒý·¢ÃýÎóÂòÂôÉõÖÁÕË»§±»ÊÕÊܵÄ͹¹Î·çÏÕ
1.³¡¾°ÃèÊö£º£º£ºÍ¨¹ýÆóÒµ»òСÎÒ²¿Êð¡°ÁúϺ¡±£¬Å²ÓýðÈÚÓйØÀûÓýӿڣ¬½øÐÐ×Ô¶¯»¯ÂòÂôÓë·çÏÕ½ÚÖÆ£¬Ìá¸ßÁ¿»¯ÂòÂô¡¢¡¢¡¢ÖÇÄÜͶÑм°×ʲú×éºÏÖÎÀíЧÄÜ£¬ÊµÏÖÊг¡Êý¾Ýץȡ¡¢¡¢¡¢Õ½Êõ·ÖÎö¡¢¡¢¡¢ÂòÂôÖ¸ÁîÖ´ÐеÈÖ°ÄÜ¡£¡£
2.°²È«·çÏÕ£º£º£ºÓ°ÏóͶ¶¾µ¼ÖÂÃýÎóÂòÂô£¬Éí·ÝÈÏÖ¤ÈÆ¹ýµ¼ÖÂÕË»§±»·¸·¨ÊÕÊÜ£»£»£»ÒýÈëÔ̺¬¶ñÒâ´úÂëµÄ²å¼þµ¼ÖÂÂòÂôƾ֤±»ÇÔÈ¡£¡£»£»£»¼«¶ËÇé¿öÏÂÒò²»×ãÈÛ¶Ï»òÓ¦¼±»úÖÆ£¬µ¼ÖÂÖÇÄÜÌåʧ¿ØÆµÈÔϵ¥µÈ·çÏÕ¡£¡£
3.Ó¦¶ÔÕ½Êõ£º£º£ºÖ´ÐÐÍøÂç¸ôÀëÓë×îСȨÏÞ£¬¹Ø±Õ·Ç±ØÒª»¥ÁªÍø¶Ë¿Ú£»£»£»³ÉÁ¢ÈËΪ¸´ºËºÍÈÛ¶ÏÓ¦¼±»úÖÆ£¬¹Ø¼ü²Ù×÷Ôö³¤¶þ´ÎÈ·ÈÏ£»£»£»Ç¿»¯¹©¸øÁ´ÉóºË£¬Ê¹Óùٷ½×é¼þ²¢¶¨ÆÚÐÞ¸´·ì϶£»£»£»ÂäʵȫÁ´Â·Éó¼ÆÓ밲ȫ¼à²â£¬ÊµÊ±·¢ÏÖ²¢´ëÖð²È«·çÏÕ¡£¡£
¶þ¡¢¡¢¡¢°²È«Ê¹Óý¨Òé
£¨Ò»£©Ê¹Óùٷ½×îа汾¡£¡£Òª´Ó¹Ù·½ÇþµÀÏÂÔØ×îв»±ä°æ±¾£¬²¢¿ªÆô×Ô¶¯¸üÐÂÌáÐÑ£»£»£»ÔÚÉý¼¶Ç°±¸·ÝÊý¾Ý£¬Éý¼¶ºóÖØÆô·þÎñ²¢ÑéÖ¤²¹¶¡ÊÇ·ñÉúЧ¡£¡£²»ÒªÊ¹ÓõÚÈý·½¾µÏñ°æ±¾»òº¹Çà°æ±¾¡£¡£
£¨¶þ£©Ñϸñ½ÚÖÆ»¥ÁªÍøÂ¶³öÃæ¡£¡£Òª¶¨ÆÚ×Ô²éÊÇ·ñ´æÔÚ»¥ÁªÍøÂ¶³öÇé¿ö£¬Ò»µ©·¢ÏÖÁ¢¼´ÏÂÏßÕû¸Ä¡£¡£²»Òª½«¡°ÁúϺ¡±ÖÇÄÜÌåʵÀý¶³öµ½»¥ÁªÍø£¬È·Ð軥ÁªÍø½Ó¼ûµÄÄܹ»Ê¹ÓÃSSHµÈ¼ÓÃÜͨµÀ£¬²¢Ï޶ȽӼûÔ´µØÖ·£¬Ê¹ÓÃÇ¿ÃÜÂë»òÖ¤Êé¡¢¡¢¡¢Ó²¼þÃÜÔ¿µÈÈÏÖ¤·½Ê½¡£¡£
£¨Èý£©¶ÔÖÅ×îСȨÏÞ×¼Ôò¡£¡£ÒªÆ¾¾ÝÒµÎñ±ØÒªÊÚÓèʵÏÖ¹¤×÷±ØÐëµÄ×îСȨÏÞ£¬¶Ôɾ³ýÎļþ¡¢¡¢¡¢·¢ËÍÊý¾Ý¡¢¡¢¡¢Åú¸ÄϵͳÅäÖõÈÖØÒª²Ù×÷½øÐжþ´ÎÈ·ÈÏijÈËΪÉóÅú¡£¡£ÓÅÏÈ˼¿¼ÔÚÈÝÆ÷»òÐé¹¹»úÖиôÀëÔËÐУ¬ÐγɶÀÁ¢µÄȨÏÞÇøÓò¡£¡£²»ÒªÔÚ²¿ÊðʱʹÓÃÖÎÀíԱȨÏÞÕ˺𣡣
£¨ËÄ£©ÉóÉ÷ʹÓü¼ÊõÊг¡¡£¡£ÒªÉóÉ÷ÏÂÔØClawHub¡°¼¼Êõ°ü¡±£¬²¢ÔÚ×°ÖÃǰÉó²é¼¼Êõ°ü´úÂë¡£¡£²»ÒªÊ¹ÓÃÒªÇó¡°ÏÂÔØZIP¡±¡¢¡¢¡¢¡°Ö´ÐÐshell¾ç±¾¡±»ò¡°ÊäÈëÃÜÂ롱µÄ¼¼Êõ°ü¡£¡£
£¨Î壩·À±¸Éç»á¹¤³Ìѧ¹¥»÷ºÍä¯ÀÀÆ÷½Ù³Ö¡£¡£ÒªÊ¹ÓÃä¯ÀÀÆ÷ɳÏä¡¢¡¢¡¢ÍøÒ³¹ýÂËÆ÷µÈÀ©´ó×èÖ¹¿ÉÒɾ籾£¬ÆôÓÃÈÕÖ¾Éó¼ÆÖ°ÄÜ£¬Óöµ½¿ÉÒÉÐÐΪÁ¢¼´¶Ï¿ªÍø¹Ø²¢ÖØÖÃÃÜÂë¡£¡£²»Òªä¯ÀÀÀ´Àú²»Ã÷µÄÍøÕ¾¡¢¡¢¡¢µã»÷İÉúµÄÍøÒ³Á´½Ó¡¢¡¢¡¢¶ÁÈ¡²»³ÉÐÅÎĵµ¡£¡£
£¨Áù£©³ÉÁ¢³¤Ð§·À»¤»úÖÆ¡£¡£Òª¶¨ÆÚ²é³²¢ÐÞ²¹·ì϶£¬ÊµÊ±¹Ø×¢OpenClaw¹Ù·½°²È«²¼¸æ¡¢¡¢¡¢¹¤ÒµºÍÐÅÏ¢»¯²¿ÍøÂ簲ȫÍþвºÍ·ì϶ÐÅÏ¢¹²ÏíÆ½Ì¨µÈ·ì϶¿âµÄ·çÏÕÔ¤¾¯¡£¡£µ³Õþ»ú¹Ø¡¢¡¢¡¢ÆóÊÂÒµµ¥ÔªºÍСÎÒÓû§Äܹ»½áºÏÍøÂ簲ȫ·À»¤¹¤¾ß¡¢¡¢¡¢Ö÷Á÷ɱ¶¾Èí¼þ½øÐÐʵʱ·À»¤£¬ÊµÊ±´ëÖÿÉÄÜ´æÔڵݲȫ·çÏÕ¡£¡£²»Òª½ûÓþßÌåÈÕÖ¾Éó¼ÆÖ°ÄÜ¡£¡£
¸½Â¼£º£º£º²¿ÃŰ²È«»ùÏß¼°ÅäÖòο¼
Ò»¡¢¡¢¡¢ÖÇÄÜÌ岿Êð
´´½¨OpenClawרÓÐЧ»§£¬ÇÐÎðʹÓÃsudo×飺£º£º
sudo adduser --shell /bin/rbash --disabled-password clawuser
ͨ¹ý´´½¨µÄרÓÐЧ»§µÇ¼²Ù×÷ϵͳ¡£¡£
´´½¨ÊÜÏ޵ĺÅÁîĿ¼£¬²»ÈÝrm¡¢¡¢¡¢mv¡¢¡¢¡¢dd¡¢¡¢¡¢format¡¢¡¢¡¢powershellµÈ£º£º£º
sudo mkdir -p /home/clawuser/bin
sudo ln -s /bin/ls /home/clawuser/bin/ls
sudo ln -s /bin/echo /home/clawuser/bin/echo
Ç¿ÖÆÉèÖà PATH ²¢Ö»¶Á£¬ÈçÔÚ /etc/profile.d/restricted_clawuser.shÅú¸ÄÅäÖ㺣º£º
echo 'if [ "$USER" = "clawuser" ]; then export PATH=/home/clawuser/bin; readonly PATH; fi' | sudo tee /etc/profile.d/restricted_clawuser.sh
sudo chmod 644 /etc/profile.d/restricted_clawuser.sh
½ûÓÃrootµÇ¼£º£º£º
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config
sudo systemctl restart sshd
¶þ¡¢¡¢¡¢ÏÞ¶È»¥ÁªÍø½Ó¼û
£¨Ò»£©Linux·þÎñÆ÷ÅäÖÃ
´´½¨×Ô½ç˵Á´£º£º£º
sudo iptables -N ALLOWED_IPS
Ôö³¤ÔÊÐíµÄIP£¨IPµØÖ·ÎªÊ¾Àý£¬²Ù×÷ʱÐè´úÌæÎªÏÖʵIPµØÖ·£©£º£º£º
sudo iptables -A ALLOWED_IPS -s 192.168.1.100 -j ACCEPT
sudo iptables -A ALLOWED_IPS -s 10.0.0.5 -j ACCEPT
sudo iptables -A ALLOWED_IPS -s 172.24.57.160 -j ACCEPT
sudo iptables -A ALLOWED_IPS -j RETURN
ÀûÓõ½SSH¶Ë¿Ú£º£º£º
sudo iptables -A INPUT -p tcp --dport 22 -j ALLOWED_IPS
sudo iptables -A INPUT -p tcp --dport 17477 -j ALLOWED_IPS
´ËÍ⣬¿É²Î¿¼ÉÏÊöºÅÁî¹Ø±ÕÒÔ϶˿ڻ¥ÁªÍø½Ó¼û»òÉèÖÃIPµØÖ·°×Ãûµ¥£º£º£ºTelnet£¨23£©¡¢¡¢¡¢WindowsÎļþ¹²Ïí£¨135¡¢¡¢¡¢137¡¢¡¢¡¢138¡¢¡¢¡¢139¡¢¡¢¡¢445£©¡¢¡¢¡¢WindowsÔ¶³Ì×ÀÃæ£¨3389£©¡¢¡¢¡¢Ô¶³Ì×ÀÃæ½ÚÖÆ£¨5900-5910£©¡¢¡¢¡¢Êý¾Ý¿âÀà¶Ë¿Ú£¨3306¡¢¡¢¡¢5432¡¢¡¢¡¢6379¡¢¡¢¡¢27017£©¡£¡£
£¨¶þ£©VPN½ÓÈëµÄÇé¿öÏÂÅäÖÃ
½«OpenClaw Gateway°ó¶¨127.0.0.1£¬ÇÐÎðÖ±½Ó°ó¶¨µ½0.0.0.0¡£¡£
¹Ø±Õ18789¶Ë¿Ú£º£º£º
sudo ufw deny 18789
Ô¶³Ì½Ó¼ûÊ±Ç¿ÖÆÊ¹ÓÃVPN²¢ÆôÓÃGatewayÈÏÖ¤£¨ÔÚopenclaw.jsonÖÐÉèÖÃgateway.auth.mode: "token"¼°Ç¿ÁîÅÆ£©¡£¡£
Èý¡¢¡¢¡¢¿ªÆô¾ßÌåÈÕÖ¾
¿ªÆôÈÕÖ¾¼Í¼£º£º£º
openclaw gateway --log-level debug >> /var/log/openclaw.log 2>&1
ËÄ¡¢¡¢¡¢Îļþϵͳ½Ó¼û½ÚÖÆ
ÔÚDocker²¿ÊðÅäÖÃÎļþ(docker-compose.yml)ÖУ¬ÀûÓÃvolumes²ÎÊý½«ÏµÍ³¹Ø¼üĿ¼¹ÒÔØÎª:ro£¨Ö»¶Á£©Ä£Ê½£¬½ö±£ÁôÌØ¶¨µÄ/workspaceΪ¿Éд״̬¡£¡£
ÔÚËÞÖ÷»úϵͳ²ã£¬Í¨¹ýchmod 700Ö¸Áî¶Ô˽ÃÜÊý¾ÝĿ¼ִÐÐÇ¿ÖÆ½Ó¼û½ÚÖÆ£º£º£º
sudo chmod 700 /path/to/your/workspace
Îå¡¢¡¢¡¢µÚÈý·½¼¼ÊõÉó²é
×°ÖÃǰִÐм¼ÊõÉó²éºÅÁ£º£º
openclaw skills info
²¢Éó²é~/.openclaw/skills/
ÓÅÏÈÑ¡ÓÃÄÚÖÃ55¸öSkill»òÉçÇø¾«Ñ¡ÁÐ±í£¨Èçawesome-openclaw-skills£©¡£¡£
Áù¡¢¡¢¡¢°²È«×Ô¼ì
¶¨ÆÚÔËÐа²È«Éó¼ÆºÅÁ£º£º
openclaw security audit
Õë¶ÔÉ󼯷¢ÏֵݲȫÒþ»¼£¬ÈçÍø¹ØÈÏ֤¶³ö¡¢¡¢¡¢ä¯ÀÀÆ÷½ÚÖÆÂ¶³öµÈ£¬ÊµÊ±ÒÀÕÕÉÏÊö°²È«»ùÏß¼°ÅäÖòο¼¡¢¡¢¡¢¹Ù·½ÊÖ²áµÈ½øÐдëÖᣡ£
Æß¡¢¡¢¡¢¸üа汾
ÔËÐа汾¸üкÅÁ£º£º
openclaw update
°Ë¡¢¡¢¡¢Ð¶ÔØ
´ò¿ªÖÕ¶Ë£¬Ö´ÐÐɾ³ýºÅÁ£º£º
openclaw uninstall
ʹÓÃÊó±ê¸ßµÍÒÆ¶¯¹â±ê£¬°´¿Õ¸ñ¼ü¹´Ñ¡ËùÓÐÑ¡Ï¶øºó°´»Ø³µ¼üÈ·ÈÏ¡£¡£
Ñ¡Ôñyes²¢°´»Ø³µ£¬´ËºÅÁî»á×Ô¶¯É¾³ýOpenClawµÄ¹¤×÷Ŀ¼¡£¡£
Ð¶ÔØnpm°ü£º£º£º
1. ʹÓÃnpm×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ£º£º
npm rm -g openclaw
2. ÈôÊÇʹÓÃpnpm×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ£º£º
pnpm remove -g openclaw
3. ÈôÊÇʹÓÃbun×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ£º£º
bun remove -g openclaw


¾©¹«Íø°²±¸11010802024551ºÅ