Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?
ã¬ããããã製å Red Hat Enterprise Linuxãã¯ãããã³ã³ãããã©ãããã©ã¼ã ãèªååãã©ãããã©ã¼ã ãªã©ãã¨ã³ã¿ã¼ãã©ã¤ãºé åã§å©ç¨ããããªã¼ãã³ã½ã¼ã¹ã½ããã¦ã§ã¢ã®ã½ãªã¥ã¼ã·ã§ã³ãæä¾ãããã¾ãã Red Hat Enterprise Linux ãµã¤ãªã¹OSSãããç¸è«å®¤ ããµã¤ãªã¹OSSãããç¸è«å®¤ãã¯ããµã¤ãªã¹ãã¯ããã¸ã¼ã伿¥åãã«ãªã¼ãã³ã½ã¼ã¹ã»ã½ããã¦ã§ã¢ï¼OSSï¼ã®ãµãã¼ãã宿½ãç¶ãã¦ããä¸ã§å¹ãããæè¡åã¨ãã¬ãã¸ããæä¾ããã客æ§ã®OSSç©æ¥µæ´»ç¨ãæ¯æ´ãããµãã¼ããµã¼ãã¹ã§ããææ°ã®OSSã«ãåãçµãã§ãããåç¨è£½åã®ãµãã¼ãå質ã«å¹æµããæåããµã¼ãã¹ãå種OSSã§ãå©ç¨ããã ãã¾ãã
ã¯ããã« ã¢ãã¤ã«ã¢ããªãããã¤ããµã¼ãã¹ãé²ãã§ãã¦ããæ¨ä»ã«ããã¦ããªã¯ã¨ã¹ãå ã¨ãªã¯ã¨ã¹ãå ã®ãã¡ã¤ã³ãå¿ ãåãã¨ã¯éããªãç¶æ³ãå¤ã ããã¨æãã¾ãã ããã§ãJavascriptã ã¨åé¿çã¨ãã¦JSONP使ããCORSè¨å®ãããï¼ãã¡ã¸ã£ã¼ã©ããã§ãããä»åã¯å¾è ã®CORSè¨å®ã«ã¤ãã¦ã§ãã HTTPãµã¼ãã¼ã¯Nginxãå©ç¨ãã¦ãã¾ãã ç´é¢ããäº Nginxã§CORSè¨å®ãã¦ãã¦ãä½ããã®åå ãä¾ãã°ãµã¼ãã¼ãµã¤ãã®ããã°ã©ã ã«ã¨ã©ã¼ããã£ã¦500çªã®HTTPã¬ã¹ãã³ã¹ãè¿ãããã¨ãã¾ãããã®å ´åã«ããªããCORSã®ã¨ã©ã¼ãåºãã¨ãã£ãç¾è±¡ã«ééãã¾ããã localhost:5555âlocalhost:1000 ã«ãªã¯ã¨ã¹ãããæã«502 BadGatewayãããã¨çºçããã¦ãããããã¨ã¢ã¯ã»ã¹å ã®ãã©ã¦ã¶ã§ã¯CORSã®ã¨ã©ã¼ãåºã¾ãã Javascriptã§éçºãã¦ãã
â» ãã®ã¨ã³ããªã¯ãã¯ã¦ãªã°ã«ã¼ãçµäºã«ä¼´ãããµãããã°ããã®å¼è¶ã¨ã³ããª(2011/07)ã§ãã â» æ å ±ãå¤ãå¯è½æ§ãããã¾ãã®ã§ããçæãã ããã ãã¨ãã°ãGET ã¡ã½ãã以å¤ã®ãªã¯ã¨ã¹ãããã°ã«åºåããããå ´åã¯ãè¨å®ã«ä»¥ä¸ã®ããã«æ¸ãã # 鬼ã®ããã«ãã©ãã£ãã¯ãããµã¤ãã¨ããã»ã»ã»ã location / { root /path/to; access_log logs/access.log; if ( $request_method = GET ) { access_log off; } }ãã°ã®åºåæç¡ä»¥å¤ã«ããä¸è¨ã®ãããªæãã§ã if ( $request_method = GET ) { (è¨å®ãè¨è¿°) }ãªã¯ã¨ã¹ãã¡ã½ãããæ¡ä»¶ã«ãã¦è¨å®ãè¨è¿°ã§ããã ã¡ã½ããã®æå®é¨åã¯ããã¡ããæ£è¦è¡¨ç¾ã使ããã®ã§ãè¤æ°æ¡ä»¶ãOKã
nginxã¨PHP-FPMã使ç¨ããWebãµã¼ãã¼ã¯ãç¹å®ã®æ¡ä»¶ä¸ã§ãã®æ¬ é¥ã«å¯¾ãã¦èå¼±ã§ãã èæ¯ 10æ22æ¥ãã»ãã¥ãªãã£ç ç©¶è ã®Omar Ganievæ°ã¯ãPHPã®FastCGI Process Managerï¼FPMï¼ã§ããPHP-FPMã«ããããããããé©ç¨ãããã°ãããã®ãªã¢ã¼ãã³ã¼ãå®è¡ã®èå¼±æ§ã«é¢ãããã¤ã¼ããå ¬éãã¾ããã ãã®ãã¤ã¼ãã«ã¯ãèå¼±æ§ã®æ¦å¿µå®è¨¼ï¼PoCï¼ãå ¬éãããGitHubãªãã¸ããªã¸ã®ãªã³ã¯ãå«ã¾ãã¦ãã¾ãã Freshly patched RCE in PHP-FPM:https://t.co/kaVsCStBJx Exploit:https://t.co/VLmhxMWVxo Many nginx+PHP configurations vulnerable, watch out! â BECHED (@ahack_ru) October 22,
nginxã403ãè¿ãçç±ã¯æ§ã ã§ãã ã¾ãã¯ãã¡ããããã£ã¨åç §ããæ°ã«ãªããã¤ã³ãããã£ãã試ãã¦ã¿ã¾ããã: www.1and1.com åã¯æã ã¯ã·ã³ããªãã¯ãªã³ã¯ãè¨å®ãã¦403ã«ãªã£ã¦ãã¾ãé ãæ±ãã¦ãã¾ãã¾ããæ°å¹´ã«ä¸åãããã®ãã¼ã¹ã§ããããã®ã§ãæ¯åã°ã°ã£ã¦ããã§ãããã ãã¨ãã°ä»¥ä¸ã®ããã«ãyour-project 以ä¸ã«åå¨ãã assets ãã£ã¬ã¯ããªã https://localhost/assets ã§ã¢ã¯ã»ã¹ã§ããããã«ãããã¨ãã¦ãã·ã³ããªãã¯ãªã³ã¯ãè¨å®ããã¨403ã«ãªã£ãããã¾ãã $ cd your-project $ ln -s assets /usr/local/var/www/assets ãã®å ´å㯠nginx.conf ã« location /assets/ ã追å ããã¨è¯ãã§ãããã location /assets/ { root
ãNginx ã® location ã®æ¸ãæ¹ãããããªãï¼ãããæã£ããã¨ã¯ããã¾ãããï¼ ãã¹ãããã¨ãããããªã åãé層ã«ãããã¡ä¸ã¤ããé©ç¨ãããªã åãé層ã®locationãã£ã¬ã¯ãã£ãã®æ¼ç®åããã¹ã¦ãã§ãã¯ããªãã¨ãã©ããé©ç¨ããããããããªã ãã®ããã«ãNginx ã® locationãã£ã¬ã¯ãã£ãã¯ç´æçã§ã¯ãªããã¯ã»ã®ããåä½ããã¾ãã ä»åã¯ã¨ã¦ãã«ã³ã¿ã³ã§ããã¡ã¤ã«åå²ç®¡çãæ¥½ã«ãªãããæ¹ããç´¹ä»ãã¾ãã locationã®åºç¤äºé ã¾ãlocationã®åºç¤ç¥èã§ãããlocationã¯ä¸¦åãã¦æ¸ããã¦ããå ´åãã©ããä¸ã¤ã®ã¿é©ç¨ããã¾ããã©ããé©ç¨ããããã¯æ¼ç®åã«ããã¾ãã ã=ã^~ã~ã~*ããªããã®é ã«é©ç¨ããã¾ãã =å®å ¨ä¸è´ ^~åæ¹ä¸è´~case-sensitive*1ãªæ£è¦è¡¨ç¾ ~*case-insensitive*2ãªæ£è¦è¡¨ç¾ ãªãåæ¹ä¸è´
http { : log_format json escape=json '{"time": "$time_iso8601",' '"host": "$remote_addr",' '"vhost": "$host",' '"user": "$remote_user",' '"status": "$status",' '"protocol": "$server_protocol",' '"method": "$request_method",' '"path": "$request_uri",' '"req": "$request",' '"size": "$body_bytes_sent",' '"reqtime": "$request_time",' '"apptime": "$upstream_response_time",' '"ua": "$http_user_agent",'
ã¯ããã« åã¯ç²ç®çã«unicornãèµ·åããããã ãã«nginxã使ã£ã¦ãã¦ãè¨å®ãã¡ã¤ã«ã®å 容ã¨ããã»ã¨ãã©ç¥ããªãã ãªã®ã§ãããã«nginxã®è¨å®å 容ãã¾ã¨ããäºã§èªåèªèº«ãè¦ãããã¨æãã æ®æ®µä½¿ã大æµã®è¨å®ã¯è¨è¼ãã¦ããã¤ããã§ãã è¨è¼å 容ã¯å®éã«è©¦ãããã®ã¨è©¦ãã¦ãªããã®ãæ··å¨ãã¦ãã®ã§ã誤ã£ãè¨å®ãªã©ããããããããªãã®ã§ãã®è¾ºã¯ã³ã¡ã³ãã§ãææããã ããã¨å©ããã¾ãã ã¤ã³ã¹ãã¼ã« ã¤ã³ã¹ãã¼ã«ã«ã¤ãã¦ã¯åãæ¸ãããä»ã®äººã®è¨äºãè¦ãæ¹ãããã¨æãã centosã«å ¥ãããªã以ä¸ã®è¨äºãåèã«ãªãã CentOS6.xã«ã¦nginxã®ææ°çãã¤ã³ã¹ãã¼ã«ããæé CentOS 6.5ã§nginxãåããçºã®æä½éã®è¨å® ã¾ãchefã§ã¤ã³ã¹ãã¼ã«ããå ´åã¯ä»¥ä¸ã®è¨äºãå½¹ã«ãã¤ã Chefã§nginxãå°å ¥ãã¦ã¿ã Chefã§Nginxãã¤ã³ã¹ãã¼ã«ããã¨ãã«ããã£ã c
以忏ããã¨ãããApacheã§ã¯ãªãã¼ã¹ãããã·ã§ããã¯ã¨ã³ãã¨HTTP2éä¿¡ãããã¨ãã§ãã¾ãã asnokaze.hatenablog.com Nginxã®å ´åã¯ãéçºè ã®ã¡ã¼ãªã³ã°ãªã¹ãã§Googleã®äººãæ¸ãã¦ããngx_http_v2_upstreamãããããå©ç¨ãããã¨ã§ããã¯ã¨ã³ã(upstream)ã¨HTTP2éä¿¡ãããã¨ãåºæ¥ãããã«ãªãã¾ãã ããã [PATCH 01 of 14] Output chain: propagate last_buf flag to c->send_chain() [PATCH 02 of 14] Upstream keepalive: preserve c->data [PATCH 03 of 14] HTTP/2: add debug logging of control frames [PATCH 04 of 14] HTTP/
nginx-buildã¨ããGo製ã®ã½ããã¦ã§ã¢ãããã¾ããååã®éãnginxãbuildããããã«ä½¿ç¨ããã½ããã¦ã§ã¢ã§ãããã®nginx-buildã§LibreSSLã®éçãªã³ã¯ãç°¡åã«ã§ããããã«ããPRããã¼ã¸ãã¦ãããã¾ããã ã³ã¡ã³ãã«ãæ¸ããããã«ãä»ã¾ã§ã®ã³ã¼ãã¯ã³ã³ãã¤ã«ãªãã·ã§ã³ã«æ¸¡ããªãã·ã§ã³åã¨ã½ããã¦ã§ã¢åãä¸è´ãã¦ããäºãåæã«ãªã£ã¦ãã¾ããããããLibreSSLã®ãªãã·ã§ã³å㯠â with-opensslã§ä¸è´ãã¾ãããã¾ãOpenSSLã¨åæ§ã®ãªãã·ã§ã³ãä»ä¸ããªããã°ãªããªãã®ã§ã¨ããã©ããç¹å¥æ±ããã¦ãã¾ãããã®è¾ºããä¸çç¸ã§ã¯è¡ããªãã®ã§å°ãé¢åã§ããã nginxã¨LibreSSLã«ã¤ãã¦å°ãæ¸ãã¦ã¿ã¾ãã nginxã¯å¤§ä½ã®OSã®æ¨æºããã±ã¼ã¸ã§å ¥ãã®ã§é©å½ã«å©ç¨ãããã ããªãæ¨æºããã±ã¼ã¸ããå ¥ããã°ååã§ãããããnginxã¯Apache
ã¿ã¤ãã«ã¯é£ãããã¤ãèªåã®ããã®åå¿é²ã§ãã ãã¤ã¯ããµã¼ãã¹ã¢ã¼ããã¯ãã£ã§ãµã¼ãã¹ãæ§ç¯ããã¨ãAPIãµã¼ãããµã¼ãã¹ãã¨ã«ç«ã¦ãããã§ããã ãã©ã¦ã¶ä¸ã®JSã¨ã³ã¸ã³ããAPIãµã¼ããå©ãæã«é¿ãã¦éããªãã®ããSame-Origin Policyï¼åä¸çæå ããªã·ã¼ï¼ã«ããCORS (Cross-Origin Resource Sharing)å¶éã§ãã ãããåé¿ããã«ã¯ãAPIãµã¼ãå´ã§Access-Control-*ããããé©åã«è¿ãå¿ è¦ãããã¾ãããã©ãè¨å®ããã¹ããã®æ å ±ãæå¤ã¨å°ãªãã®ã§ï¼èªåçï¼ãããæ±ºå®çï¼ãã¨ããè¨å®ãèãã¦ã¿ã¾ããã çµè« nginxã®å ´åã®è¨å®ä¾ã§ãã server { listen 80; server_name site.localhost; charset utf-8; root /var/www/app/public; locatio
ä»åã¯ãªãã¼ã¹ãããã·ã«ã¤ãã¦åå¼·ãã¦ã¿ã¾ããã ããªãã¼ã¹ãããã·ã£ã¦ãªããªã®ããã¨ããæ¹ã¯ä¸ç·ã«æãåãããªããã覧ãã ããã ãªããä»åã®ç®çã¯ããã¾ã§ããããã·ãµã¼ãã¨ã¯ãªã«ããçè§£ãããã¨ããªã®ã§ãå®éã«éç¨ããã¨ãã«å¤§äºãªè¨å®ããã£é£ã°ããããã¦ãã¾ãã ãã®ãããã®è©³ç´°ã®çè§£ã«ã¤ãã¦ã¯åèãªã³ã¯ãªã©ããã¨ã«ãã¦æ·±ãã¦ããã ããã°ã¨æãã¾ãã ã¾ããããªãã¼ã¹ãããã·ãã¨ã¯ãªã«ã ã²ã¨ã¾ãæç´ã«Wikipediaã§èª¿ã¹ã¦ã¿ã¾ãããã ãªãã¼ã¹ãããã·ï¼è±: Reverse proxyï¼ã¾ãã¯éãããã·ã¯ãç¹å®ã®ãµã¼ãã¸ã®è¦æ±ãå¿ ãçµç±ããããã«è¨ç½®ããããããã·ãµã¼ããä¸è¬çãªãããã·ã¨ã¯ç°ãªãä¸ç¹å®å¤æ°ã®ãµã¼ãã対象ã¨ããªãããªãã¼ã¹ãããã·ã¯ãä¸ç¹å®å¤æ°ã®ã¯ã©ã¤ã¢ã³ãããå¯ããããè¦æ±ã«å¯¾ãã¦ãå¿çãè©ä»£ãããããã¨ã«ããç¹å®ã®ãµã¼ãã®è² æ ã軽æ¸ããããã¢ã¯ã»ã¹ãå¶éããã
æè¿ Fluentd ã®éä¿¡ãããã³ã«ã¾ãããã¢ãããã¼ãããããã«ããããããã£ã¦ãã*1ãã ãã©ãããã¯ãããã fluent-plugin-secure-forward ããµãã¼ããã¦ããå 容ã Fluentd çµè¾¼ã¿ã® forward plugin ã§ããµãã¼ããã¾ãããã¨ãããã®ã«ãªãã ãã§åé¡ãªã®ã secure-forward 㯠SSL/TLS ã§ã®æ¥ç¶ã®ã¿ãããµãã¼ããã¦ãªãã£ããã ãã© forward ã§ã¯çã® TCP ã§éä¿¡ãã*2ã®ã§ãæ¬å½ã« secure-forward 㨠forward ããããã®å®è£ éã§äºææ§ãä¿ããã¦ããã®ããç´æ¥çã«ã¯ç¢ºèªããææ®µããªããã¨ãããã¨ã«ãªã£ã¦ãã¾ãã TCP server ã® SSL/TLS å 䏿¹ä¸ã®ä¸ã«ã¯ SSL/TLS ã¿ã¼ããã¼ã¿ã¨ããæ©è½ããã£ã¦ããã¨ãã°ãã¼ããã©ã³ãµãªããããã®æ©è½ãæã£ã¦ãããä½ããããã¨
OpenRestyã¯nginxã®ã»ãã«ngx_luaãã¯ããã¨ããCã§æ¸ãããå種ãµã¼ããã¼ãã£ã¢ã¸ã¥ã¼ã«ã¨ngx_luaã®APIãå©ç¨ããrestyã¢ã¸ã¥ã¼ã«ãããã¦Lua/LuaJITã§æ§æããã¦ãã¾ãã OpenRestyã«å«ã¾ãã¦ããnginxèªä½ã¯æ¬å®¶ã®nginxã¨åºæ¬åããªã®ã§ãå¥ã«OpenRestyãå©ç¨ããªãã¦ãèªåã§ngx_luaãçµã¿è¾¼ãã ãããµã¼ãä¸ã«restyã¢ã¸ã¥ã¼ã«ãé å¸ãããã¨ã§ä¼¼ããããªç°å¢ãæ§ç¯ãããã¨ã¯å¯è½ã§ãããOpenRestyã§ããã°ä¸»è¦ãªã¢ã¸ã¥ã¼ã«ãã©ã¤ãã©ãªã./configureãmakeãmake installã®ä¸é£ã®æµãã§ãã¹ã¦ã´ã½ãã¨ã¤ã³ã¹ãã¼ã«ããã¾ãããOpenRestyã®configureã¹ã¯ãªããã¯nginxã®configureã¹ã¯ãªãããç¶æ¿ãããã®ãªã®ã§nginxã®configureãªãã·ã§ã³ãã»ã¼ãã®ã¾ã¾å©ç¨ãããã¨ãã§
第5åãããããã¯ã«ã³ãã¡ã¬ã³ã¹ãã¤ã³ãã©ã¨ã³ã¸ãã¢å¤§ç¹éã ã§çºè¡¨ããè³æã§ã http://pepabo.connpass.com/event/30348/
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã¡ã³ããã³ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}