Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? ã¯ããã« Webãµã¼ãã¼ã使ãã¨ãã«ãNginxã¨Apacheã£ã¦è¨èããè³ã«ãã¾ãããã ãã ãã®éãã£ã¦ãã¾ãã¡è¯ãããããªããªãã§ããï¼ï¼ï¼åã ãã ã£ãããã¿ã¾ããç¬ï¼ ã¡ãªã¿ã«åã¯ãNginxã®æ¹ããªãã人æ°ã ãè¯ããããªæ°ãããããããã¨ããä½ã®æ ¹æ ããªãã¤ã¡ã¼ã¸ããæã£ã¦ãã¾ããã§ããã ãããã«ããå°ãã¡ããã¨çè§£ãããã¨æããä»åã¯ãã®éããè¨äºã«ãã¦ã¿ã¾ããã ãã²ãã²æå¾ã¾ã§èªãã§ã¿ã¦ãã ãããï¼ â»ã¡ãªã¿ã«Nginxã¨Apacheã¯ããããããã¨ã³ã¸ã³ã¨ãã¯ã¹ããã¢ããããã¨èªã¿ã¾ãã ããããNginxã¨Apac
äºè±¡ Ubuntu 18.04 apache2 (2.4.29-1ubuntu4.12) ã§ãapache2 ããã»ã¹ã次ã®ã¨ã©ã¼ã¡ãã»ã¼ã¸ãåãã¦è½ã¡ãã¨ããé£çµ¡ãåãã¦èª¿ã¹ã¾ãããããã¯ãã®åå ã¨å¯¾å¦æ³ã®ã¡ã¢ã§ãã [mpm_prefork:emerg] [pid 18633] (43)Identifier removed: AH00144: couldn't grab the accept mutex [mpm_prefork:emerg] [pid 18632] (43)Identifier removed: AH00144: couldn't grab the accept mutex [core:alert] [pid 18624] AH00050: Child 18632 returned a Fatal error... Apache is exiting! [:emerg
ä½ã£ããã®:Yaruki00/ansible_ubuntu_lamp ã¯ããã« ä»åä½ã£ããã®ã¯phansibleã¨ãããµã¤ãã§çæã§ããplaybookãå ã«ãã¦ãã¾ããã¨è¨ããã»ã¼ãã®ã¾ã¾ã§ãã ãã¨ãã¨ã¯Vagrantã使ã£ã¦ä»®æ³Ubuntuã«Ansibleã§LAMPãæ§ç¯ããããã«ãªã£ã¦ããã®ã§ãããããããVagranté¨åã¯åé¤ãã¦ã¾ãã ä»®æ³ç°å¢ã§ããããããã¨ãã人ã¯phansibleã§ãããããã¦playbookãçæãã¦ã¿ã¦ãã ããã ä¸èº«ã¯ã©ããªã£ã¦ããã® ãã£ã¬ã¯ããªæ§æ . âââ inventories â  âââ dev â  âââ local âââ playbook.yml âââ roles â  âââ apache â  â  âââ handlers â  â  â  âââ main.yml â  â  âââ tasks
ã¯ããã« Web Speech APIã使ã£ãã¢ããªã使ãããã¨ããã¨ãããã»ãã¥ãªãã£ã®é¢ä¿ã§HTTPã§ã¯ãã¤ã¯ã®è¨±å¯ãããã¾ããã§ãããããã§HTTPSéä¿¡ã§ããç°å¢ãæ§ç¯ãããã¨èãã¾ããã SSLéä¿¡ãè¡ãããã«SSLãµã¼ãè¨¼ææ¸ãè³¼å ¥ããå¿ è¦ãããã¾ãããä»åã¯èªå·±è¨¼ææ¸ã§ä»£ç¨ãã¾ãã CentOS7.5ã«Apache2.4ãã¤ã³ã¹ãã¼ã«ããã¨ããããå§ãã¾ãã è©°ã¾ã£ãã㨠å ã«èªåãè©°ã¾ã£ãé¨åãè¨è¼ãã¦ããã¾ãã ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®è¨å®ããã¦ããªãã£ãã㨠SElinuxã«ããã¨ã©ã¼ HTTPãµã¼ãã®æ§ç¯ ã¾ãã¯HTTPãµã¼ãã®ç°å¢ãæ§ç¯ãã¾ãã Apache2.4ãã¤ã³ã¹ãã¼ã« yumã使ã£ã¦ã¤ã³ã¹ãã¼ã«ãã¾ãã CentOS6ç³»ã¯æ¨æºã§ã¯Apache2.2ã¾ã§ãããªãã®ã§æ³¨æãã¦ãã ããã /* ãã¼ã¸ã§ã³ç¢ºèª */ # yum info httpd ... ãã¼ã¸ã§
ã¨ã°ã¼ã¯ãã£ããµã㪠PHPã®èå¼±æ§CVE-2018-17082ã¯XSSã¨ãã¦å ±åããã¦ããããç¾å®ã«ã¯XSSã¨ãã¦ã®æ»æçµè·¯ã¯ãªãã䏿¹ãApacheã®mod_cacheã«ãããã£ãã·ã¥æ©è½ãæå¹ã«ãã¦ãããµã¤ãã§ã¯ããã£ãã·ã¥æ±æã¨ããæ»æãåããå¯è½æ§ãããã æ¦è¦ PHPã®ç¾å¨ãµãã¼ãä¸ã®ãã¹ã¦ã®ãã¼ã¸ã§ã³ã«ã¤ãã¦ãXSSèå¼±æ§CVE-2018-17082ãä¿®æ£ããã¾ããã以ä¸ã¯å¯¾å¿ãã¼ã¸ã§ã³ã§ãããããããåã®ãã¹ã¦ã®ãã¼ã¸ã§ã³ãå½±é¿ãåãã¾ãããã ããApacheã¨ã®æ¥ç¶ã«Apache2handlerãç¨ãã¦ããå ´åã«éãã¾ãã PHP 5.6.38 PHP 7.0.32 PHP 7.1.22 PHP 7.2.10 PHP 5.5以åã対象ã§ããããããã¯èå¼±æ§ã¯ä¿®æ£ããã¦ãã¾ããã èå¼±æ§ãåç¾ããã¦ã¿ã ãã®èå¼±æ§ã®PoCã¯ãå½åé¡ã®ãã°ã¬ãã¼ãã«ããã¾ãã PHP ::
åé Apache/SSLãµã¼ãå°å ¥æé ã«ç¶ããèªå·±ãµã¼ãè¨¼ææ¸ãå°å ¥ãã¦èµ·åããã¾ã§ã®æé ã示ããé常ã¯CentOSããã©ã«ãã§ç¨æããã¦ããlocalhostè¨¼ææ¸ã§å åç¨ãè¶³ããã¯ããªã®ã§ãã®é ã¯å¿ ãããå¿ è¦ã§ã¯ãªãã SSL/TLSãµã¼ãè¨¼ææ¸ã®é ç½®å ´æã¨ä½æã³ãã³ã httpséä¿¡ãå¿ è¦ã¨ããWebãµã¤ã/ã¢ããªã®éçºã§ã¯ä»¥ä¸ã®ä½æ¥ãè¡ãã°å åç¨ãè¶³ãããæ¬¡ã¯èªå·±ãµã¼ãè¨¼ææ¸ãèªä½ããããç¨ãã¦Webãµã¼ããè¨å®ããæç¶ããç·´ç¿ãã¦ã¿ããã SSL/TLSè¨¼ææ¸ãå¾ãã«ã¯ openssl ã³ãã³ãã§ç§å¯éµã¨è¨¼ææ¸ã®ã»ããã使ããå¿ è¦ããããããã®ä½æ¥ãç°¡ç¥åãã Makefile ã openssl ããã±ã¼ã¸ã¨ã¨ãã«ã¤ã³ã¹ãã¼ã«ããã¦ããã®ã§ãããã§ã¯ããã使ç¨ããããã㯠/etc/pki/tls/certs ã«é ç½®ããã¦ããã [root@localhost ~]# cd
ã¯ããã« æ¬çªç°å¢ã«è¿ãéçºç°å¢ãæ§ç¯ãã¦ã¿ããã¨æããç°å¢æ§ç¯ããè¨é²ã®åå¿é²ã§ãã ä»å使ããéçºç°å¢ã®åã ã®version CentOS 7.2 Git 2.13.0 ruby 2.4.1 rails 5.1.1 apache 2.4.6 mysql 5.7 Vagrantã®ç«ã¡ä¸ã vagrantã¨virtualboxã¯ã¤ã³ã¹ãã¼ã«æ¸ã¿ã¨ãã¦é²ãã¦è¡ãã¾ãã®ã§ãã¾ã ã®æ¹ã¯ã¤ã³ã¹ãã¼ã«ããé¡ããã¾ãã ã¨ãããã¨ã§ãvagrantã®boxã®è¿½å ããè¡ãªã£ã¦ããã¾ãã # boxã®è¿½å $ vagrant box add centos72 https://github.com/CommanderK5/packer-centos-template/releases/download/0.7.2/vagrant-centos-7.2.box # 使¥ãã£ã¬ã¯ããªã®ä½æ $ mkdir ~
æ¬çªãhttpsã®éçºã§ãã¼ã«ã«ç°å¢ã ãhttpã§æ¥ç¶ãã¦ããã¨è²ã é¢åãããããããã¼ã«ã«ã®vagrantç°å¢ã§ãhttpsæ¥ç¶åºæ¥ãããã«èª¿æ´ãã¦ã¿ãã¡ã¢ã åæ OSã¯ubuntuãã¨ãããããã¤ãã®ããã«ãvagrantã®ç°å¢ã¯scotchboxã https://box.scotch.io/ åè 主ã«ä»¥ä¸ãåèã«ãã®ã¾ã¾ä½æ¥ããããããã¨ããããã¾ãã Vagrantã§Ubuntuãµã¼ã/Apache2ã®SSL(https) â orangeProseå¥é¤¨ ãã¹ãç¨ã®è¨¼ææ¸ã使 ã¾ãã¯ã¢ã¸ã¥ã¼ã«ãæå¹ã«ã
This directive enables operating system specific optimizations for a listening socket by the Protocol type. The basic premise is for the kernel to not send a socket to the server process until either data is received or an entire HTTP Request is buffered. Only FreeBSD's Accept Filters, Linux's more primitive TCP_DEFER_ACCEPT, and Windows' optimized AcceptEx() are currently supported. Using none fo
DoSæ»æã«å¯¾ããèæ§ã®å®é¨ã®åã«ããµã¤ã¼ã®è² è·ã«èããããµã¤ã¼ã®è¨å®ããããã¨ã ãããã¨ã£ã¦ã大äºã§ãã ãããªApacheã®è¨å®ã®å ¥ãæ¹ã«ã¤ãã¦ã話ãã¾ãã ã¨ãã£ã¦ããã¾ã ã¡ãã£ã¨ããã£ã¦ããªãã®ã§ãæ«å®çãªãåèç¨åº¦ã®å¤ã ã¨æã£ã¦ãã ããã ç®å®ç¨åº¦ã«ã¯ãªãã¨æããã§ããã©ãã ã¨ããããããããã«ã¡ãã£ã¨è² è·ãããããããã¡ã®ãµã¼ãããã¦ã³ãã¦ãã¾ãã¾ãã¦â¦æ³£ããªããè¨å®ãå¤ãã¾ããã ãªããç°å¢ã¯ãCentOS 5.8 x64 Hyper-Vä¸ã®ä»®æ³ãã·ã³ã§LinuxIC2.1å°å ¥æ¸ã¿ã CPUã¯ç©ççã«ã¯ E3-1220ã§ã4ã³ã¢ãå²ãå½ã¦ã ç©çã¡ã¢ãªã®å²ãå½ã¦ã¯ 1GB ã§ãã æåã®è¨å®ã¯ãããªãããã§ããã(ä»åã¯ãprefork ãã夿´ãã¦ããªããããããã®ã¿ç´¹ä»ãã¾ã) <IfModule prefork.c> StartServers 8 MinSpareS
å ãã¿ã¯ãã¡ãã Apache AddHandler madness all over the place Gentoo Bug 538822 ã©ããããã¨ã 次ã®ãããªæå®ã¯å±éºã§ããã AddHandler php5-script .php ãã®æã«æå®ããã.phpã¯ãã¡ã¤ã«åã®æ«å°¾ã§ããå¿ è¦ã¯ãªããä¾ãã°ã aaa.php.html bbb.php.pngãªã©ãphp5-scriptã¨ãã¦è§£éããã¦ãã¾ãã®ã ãããã¯.XXX.YYYã¨è¤æ°ã®æ¡å¼µåãæ¸ãããå ´åã.XXXã¨.YYYãAddHandlerã®å¯¾è±¡ã¨ãªããã¨ãåå ã ã¡ãªã¿ã«æ¬¡ã®ãããªå ´åã«ã¯php5-scriptã¨ãã¦è§£éãããªãã ccc.php_foo (.php_fooã¨ãã¦è§£éããããã) ddd.php_bar.html (.php_barã¨.htmlã¨ãã¦è§£éããããã)å®ã¯ãã®ãã¨ã¯Apacheã®ããã¥ã¡ã³
ã·ã³ããªãã¯ãªã³ã¯æ»æãé²ãããã® Apache HTTPD ã¢ã¸ã¥ã¼ã«ã®è§£èª¬ã¯ãã¡ã: Apache HTTPD: mod_allowfileowner https://fumiyas.github.io/apache/mod-allowfileowner.html èæ¯ ããªãããã®å ±æ Web ãµã¼ãã¹ä¸ã®ãµã¤ãæ¹ããäºä»¶ã§ã æ»æææ³ã®ä¸ã¤ã¨ã㦠ãä»ã¦ã¼ã¶ã¼ææã®ãã¡ã¤ã«ã¸ã®ã·ã³ããªãã¯ãªã³ã¯ãèªåã®ã³ã³ãã³ããã£ã¬ã¯ããªä¸ã«ä½ããApache HTTPD çµç±ã§ã¢ã¯ã»ã¹ãããæé ãå©ç¨ããããããã åè: http://blog.tokumaru.org/2013/09/symlink-attack.html å½ç¤¾ãµã¼ãã¹ãããªãããï¼ã¬ã³ã¿ã«ãµã¼ãã¼ãã¦ã¼ã¶ã¼ãµã¤ãã¸ã®ç¬¬ä¸è ã«ããå¤§è¦æ¨¡æ»æã«ã¤ã㦠http://lolipop.jp/info/news/4149/#090
ãã¾ã¾ã§ãªãã¼ã¹ãããã·ã®è¨å®ãããããã£ã¦ããªãã¦ããã§ã«åãã¦ãããµã¼ãã®è¨å®ãè¦ããè¦ã¾ãã§ä½¿ãåãã¦ãããã¡ããã¨çè§£ãããã¨æã£ã¦ãããã¥ã¢ã«ãèªã¿ç´ããããã£ã¨ããã£ããè¨å®ã®æ¹æ³ (How) ãããã£ããã¨ä»¥ä¸ã«ããªãããæ¸ãå¿ è¦ããããã¨ããçç± (Why) ãçè§£ã§ããã®ãå¬ãããä¹ ãã¶ãã«ãããã£ãï¼ãã¨å«ã³ãããªã£ããæåãå¿ããªããã¡ã«ãæãåºããããã«ãæ¸ãã¦ããã mod_proxy - Apache HTTP ãµã¼ã ãã¼ã¸ã§ã³ 2.2 ã Apache ã®ãããã·é¢é£ã®ããã¥ã¢ã«ã mod_proxy ã使ããã¨ã«ãªãã 大äºãªãã£ã¬ã¯ãã£ãã¯ã ProxyPass 㨠ProxyPassReverse ã®ãµãã¤ã ProxyPass ããããªãã¼ã¹ãããã·ãããä¸ã§ã®ã»ã¨ãã©ãã¹ã¦ã®ãã¨ããã£ã¦ããããå®ã¯è¦æ £ãã (ã³ãããæ £ãã) è¨å®ã§ã¯ãã®ãã£ã¬ã¯
DMZãªããã«ãããã·ãµã¼ããç«ã¦ã¦ãå¤é¨ãµã¼ãã®APIãªãããå¼ã³åºãããå ´åãªããã«ãApacheã§ãã©ã¯ã¼ããããã·ãç«ã¦ãã æ§æ APãµã¼ãâï¼DMZã®ï¼ãã©ã¯ã¼ããããã·ãµã¼ãâå¤é¨APIãµã¼ã ãã®æ§æã«ããçç± DMZãã¯ãããã¨ã§ãããã¯ã¼ã¯çãªã»ãã¥ãªãã£ãç¢ºä¿ åå¾ããã³ã³ãã³ãããã£ãã·ã¥ãããã¨ã§è² è·è»½æ¸ httpd.confã®è¨å®å¤æ´ ä¸è¨ã®ï¼ã¤ã®ã¢ã¸ã¥ã¼ã«ããã¼ãããã LoadModule proxy_module modules/mod_proxy.so LoadModule proxy_http_module modules/mod_proxy_http.so proxy ãã£ã¬ã¯ãã£ãã¨ãã¦ä»¥ä¸ãè¨å®ã # ãããOffã ã¨ãªãã¼ã¹ãããã·ã«ãªãã®ã§æ³¨æï¼ ProxyRequests On Order deny,allow Deny from all
Apacheã®mod_proxyã®è¨å®ãããã®ã§ã¡ã¢ãããã ä»åã¯ããªãã¼ã¹ãããã·ï¼ããç¹å®ã®ãã¹ã ããé¤å¤æ¡ä»¶ãæ¸ãã¦å¥ãµã¼ãã¼ã¸ãããã·ããã ã¤ã³ã¹ãã¼ã« takuya@host $ sudo aptitude install apache2 #apache2ã®ã¤ã³ã¹ãã¼ã« takuya@host $ sudo a2enmod proxy #mod_proxyãæå¹å takuya@host $ sudo a2enmod proxy_http #httpã®ãããã·ã使ã ãã®ã»ãã«ã proxy_balancerï¼ãããã·æ©è½ã使ã£ããã¼ããã©ã³ãµï¼ proxy_ftp ftpãµã¼ãã¼ã®ãããã·æ©è½ãããã proxy_ajp apache tomcat ã¢ããªã±ã¼ã·ã§ã³ééä¿¡ãããã·ãªã©ãããã proxy_connect #connect ã¡ã½ããï¼HTTPSã®ãããã·ã§ä½¿ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}