Linuxåå¼·ä¸ã§ãã ä»æ¥ã¯iptablesã試ãã¦ã¿ã¾ãã åèæ¸ç±ã¯ãã¡ãã Ubuntuã§ä½ãLinuxãµã¼ãã¼ (æ¥çµBPãã½ã³ã³ãã¹ãã ãã¯) ä½è : æ¥çµLinuxåºç社/ã¡ã¼ã«ã¼: æ¥çµBPåºçã»ã³ã¿ã¼çºå£²æ¥: 2008/12/12ã¡ãã£ã¢: 大åæ¬è³¼å ¥: 6人 ã¯ãªãã¯: 369åãã®ååãå«ãããã° (11件) ãè¦ã ããããããã®æ¬ãªã¹ã¹ã¡ã§ãã ã¿ã¤ãã«ã«ãããã¨ããããµã¼ãæ§ç¯ãã¡ã¤ã³ã§ãã¦ã å 容ãæµ ããããæ·±ãããã¡ããã©ããã§ãã æãªäººã¯æ¬å±ããã¸GOã ã§ãåå¼·ããå 容ãã¾ã¨ãã¾ãã iptablesã¨ã¯ iptablesã¯ãã±ãããã£ã«ã¿ãªã³ã°æ©è½ããã¤ã½ããã¦ã§ã¢ã§ãã ãã¡ã¤ã¢ã¦ã©ã¼ã«ãNATã¨ãã¦å©ç¨ã§ãã¾ãã CentOSã®å ´åã¯ãããã©ã«ãã§ã¤ã³ã¹ãã¼ã«ããã¦ããã ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®è¨å®ãããã©ã«ãã§æå¹ã«ãªã£ã¦ãã¾ãã iptables
1.iptablesã¨ã¯ iptablesã³ãã³ãã使ç¨ãããã¨ã§Linuxã«ã¼ãã«ã®IPãã£ã«ã¿ãNATãè¨å®ã§ããã 2.ãã¼ãã«ã¨ãã§ã¼ã³ iptablesã«ã¯ãã¼ãã«ã¨ãã§ã¼ã³ã¨å¼ã°ãããã®ããããIPãã£ã«ã¿ãNATãªã©ã®åç¨éã«å¿ãã¦filter,nat,mangleã®ãã¼ãã«ããã(表-1ãã«ã¼ãã«ã®configã«ãä¾åãã)ãåãã¼ãã«ã®ä¸ã«ãã§ã¼ã³ããããã§ã¼ã³ã®ä¸ã«ãã£ã«ã¿ãªã©ã®ã«ã¼ã«ãé£ãªã£ã¦ããããã§ã¼ã³ã¯è¤æ°ãããã±ããã®ç¨®é¡ã«ãã£ã¦ã©ã®ãã§ã¼ã³ã使ç¨ããããã¯ç°ãªããä¾ãã°filterãã¼ãã«ã®INPUTãã§ã¼ã³ã¯èªã·ã¹ãã å®ã®ãã±ããã«å¯¾ãã¦é©ç¨ãããOUTPUTãã§ã¼ã³ã¯èªã·ã¹ãã ãéä¿¡ãããã±ããã«ã¤ãã¦é©ç¨ããã(表-2)ããã§ã¼ã³ã¯èªåã§æ°ããå®ç¾©ãã¦ãæ¢åã®ãã§ã¼ã³ããå¼ã³åºããã¨ãã§ããã
ãã±ãããã£ã«ã¿ãªã³ã°ã¨ã¯ï¼ ãã±ããã®ãããã¼é¨åãè¦ã¦ã è¨å®ããæ¡ä»¶ï¼éä¿¡å IPã¢ãã¬ã¹ãå®å IPã¢ãã¬ã¹ããã¼ãçªå·ãªã©ï¼ã¨ä¸è´ãããã©ãããå¤ å®ãã¦ã ä¸è´ããå ´åã¯è¨å®ããã¢ã¯ã·ã§ã³ï¼è»¢éãç ´æ£ãã¢ãã¬ã¹æ¸ãæããªã©ï¼ãè¡ããã®ã§ããã ã¢ãã¬ã¹å¤æã¨ã¯ï¼ ãã±ããã®ãããã¼é¨åãè¦ã¦ãè¨å®ããæ¡ä»¶ã¨ä¸è´ãããã©ãããå¤å®ãã ä¸è´ããå ´åã¯ãããã¼ã®IPã¢ãã¬ã¹ããã¼ãçªå·ãæ¸ãæãããã®ã§ããã
éå½ï¼.krï¼ã»ä¸å½ï¼.cnï¼ã»å°æ¹¾ï¼.twï¼ã»é¦æ¸¯ï¼.hkï¼çï¼ã¢ã¸ã¢å°åããã®ã¢ã¯ã»ã¹ã ãã£ã«ã¿ãªã³ã°ããããã® iptables ãç¨ããã·ã§ã«ã¹ã¯ãªããã§ãããã¡ãã Linux å°ç¨ã§ãã APNIC ã® IP ã¢ãã¬ã¹å²ãå½ã¦ãªã¹ã ã«æ²è¼ããã¦ããä¸è¨ã®å½ã¨å°åã®ãããã¯ã¼ã¯ããã® TCP æ¥ç¶ãé®æãã¾ãã ãã ãï¼èªåããä¸è¨ã®å½ã¨å°åã®ãããã¯ã¼ã¯ã¸æ¥ç¶ãããã¨ã¯ã§ãã¾ãã FreeBSD ãã使ãã§ãããï¼æ°´ç¡å·ç 究æããã® ipfwã¨BINDã«ããNaverRobot対çãã£ã«ã¿ ãåèã«ãªãã¨æãã¾ãï¼ã¨ãããç¥ã£ã¦ã人ã§ããâ¦â¦ï¼ã æ¥æ¬ã® IP é åã«ã¢ã¯ã»ã¹ãã¦ããã¯ã¼ã ã¯ï¼ããããä¸è¨ã®å½ã¨å°åããã®ãã®ã§ããç¹ã«éå½ãããã²ã©ãã¨ããã¾ãã ã¾ãï¼éå½ã«ã¯ï¼æªåé«ã NaverRobot ããã« DoS ã¾ããã®ã¢ã¯ã»ã¹ãä»æãã¦ããèªç§°ãµ
Apache 2.0ã®å¿ é è¨å®ã¨åºæ¬ã»ãã¥ãªãã£å¯¾çï¼å®ç¨ Apache 2.0éç¨ã»ç®¡çè¡ï¼1ï¼ï¼1/3 ãã¼ã¸ï¼ æ¬é£è¼ã§ã¯ãApache 2.0ã®éç¨ã管çæ¹æ³ã解説ããã第1åã§ã¯ããã®ä¸æºåã¨ãã¦å¿ é ã®è¨å®ã¨åºæ¬çãªã»ãã¥ãªãã£å¯¾çãè¡ããä»å¾ã®éç¨ã«åãããï¼ç·¨éé¨ï¼ Webãµã¼ãã®ããã¡ã¯ãã¹ã¿ã³ãã¼ãApache Webãµã¼ãã¨èãã¦ãApache Webãµã¼ãï¼ä»¥ä¸Apacheï¼ãæãæµ®ãã¹ãªãLinuxã¦ã¼ã¶ã¼ã¯ããªãã§ãããããã¾ããApacheã¯Webãµã¼ãã®ããã¡ã¯ãã¹ã¿ã³ãã¼ãã¨ããå°ä½ã確ç«ãã¦ãã¾ããNetcraft社ã®2005å¹´7æã®èª¿æ»ï¼http://news.netcraft.com/archives/2005/07/ï¼ã«ããã¨ãWebãµã¼ãã«ãããApacheã®ã·ã§ã¢ã¯7å²ã«åãã§ãã¾ãã HTTPï¼HTTPSãeãã¸ãã¹ã®åºç¤ã¨ãã¦ä½¿ç¨ãããããã«
Mac OS X åãã¢ããªã±ã¼ã·ã§ã³éçºãä»äºã¨ãã¦ããæ°¸é 製ä½æããæ¥ã ã®éçºã§ã¤ãããã£ãåé¡ç¹ããã¡ãã£ã¨ããTipsãã¡ã¢ãã¦ãããã¨è¨ããèªååæãªè¦ãæ¸ãããã°ã ã»ãã¥ãªãã£ç®çã§ãå¤é¨ãããã¯ã¼ã¯ã«åãã¦ç©ºãã¦ãããã¼ããå¶éãã¦ãããµã¤ãã«ãããµã¼ãã¼ããã¤ã³ã¿ã¼ãããçµç±ã§JavaMonitorã§å¶å¾¡ããæ¹æ³ã ãããã¯ã¼ã¯ããã®sshã¢ã¯ã»ã¹ã許ããã¦ããå ´åãJavaMonitorãç¹å®ãã¼ã¨çªå·ã§èµ·åãã¦ããã®ãã¼ããsshã®ãã¼ããçµç±ãã¦ãããã¯ã¼ã¯è¶ãã«ãããã¹ãã«å ¬éãããã¨ãã§ãããssh port forwardã¨ãsshãã³ãã«ã¨ããããæè¡ã ã ãã¼ã«ã«å´ã®ãã·ã³ä¸ã®ã¿ã¼ããã«ãã以ä¸ã®ãããªã³ãã³ããæã¡è¾¼ãã local$ ssh -2 -N -f -L 50080:localhost:50180 [email protected] -2ï¼ãã
GT Nitro: Car Game Drag Raceã¯ãå ¸åçãªã«ã¼ã²ã¼ã ã§ã¯ããã¾ãããããã¯ã¹ãã¼ãããã¯ã¼ãã¹ãã«å ¨éã®ã«ã¼ã¬ã¼ã¹ã²ã¼ã ã§ãããã¬ã¼ãã¯å¿ãã¦ãããã¯ãã©ãã°ã¬ã¼ã¹ããã¤ãã¼ï¼å¤å ¸çãªã¯ã©ã·ãã¯ããæªæ¥çãªãã¼ã¹ãã¾ã§ãæãã¯ã¼ã«ã§éãè»ã¨ã«ã¼ã¬ã¼ã¹ã§ãã¾ããã¹ãã£ãã¯ã·ããããã¹ã¿ã¼ããããããè³¢ã使ã£ã¦ç«¶äºãæã¡ç ´ãå¿ è¦ãããã¾ãããã®ã«ã¼ã¬ã¼ã¹ã²ã¼ã ã¯ãã®ãªã¢ã«ãªç©çå¦ã¨ç´ æ´ãããã°ã©ãã£ãã¯ã¹ã§ããªãã®å¿ãççºããã¾ããããã¾ã§ãã¬ã¤ãããã¨ã®ãªããããªãã®ã§ãã GT Nitroã¯ããªãã¬ãã¯ã¹ã¨ã¿ã¤ãã³ã°ã試ãã«ã¼ã¬ã¼ã¹ã²ã¼ã ã§ããæ£ããç¬éã«ã®ã¢ãã·ããããã¬ã¹ãæãåãè¸ãå¿ è¦ãããã¾ããã¾ãã大ç©ãã¡ã¨ç«¶ãã¤ã¤ãè»ã®ãã¥ã¼ãã³ã°ã¨ã¢ããã°ã¬ã¼ããè¡ããªããã°ãªãã¾ãããä¸çä¸ã§æé«ã®ãã©ã¤ãã¼ã¨è»ã¨ã«ã¼ã¬ã¼ã¹ã«æããã¨ã«ãªãããã©ãã°ã¬ã¼ã¹ã®çå
sshã¯ã©ã¤ã¢ã³ãã®è¨å®ãã¡ã¤ã«(~/.ssh/config)ãå©ç¨ãã¦ä¾¿å©ãªsshã©ã¤ãããconfigãã¡ã¤ã«ãå©ç¨ããäºã§ãæ¥ç¶å sshãµã¼ãã®aliasãä½ããããè¤æ°ã®ç§å¯éµã使ãåãããã§ãããã¯ã©ã¤ã¢ã³ãç°å¢ã¯mac OS X 10.5 ä¾ãã°æ®æ®µ ssh -l user1 example.comã§æ¥ç¶ãã¦ã人ã¯ãconfigãã¡ã¤ã«ã« Host ex HostName example.com User user1ã¨ããã°ã ssh exã§æ¥ç¶ã§ããï¼ ããã«ãexample.jp ã¸ã¯ãã¦ã¼ã¶å user2 id_rsa.exjp ã¨ããç§å¯éµã§æ¥ç¶ãããå ´å㯠Host ex-jp HostName example.jp User user2 IdentityFile .ssh/id_rsa.exjpã¨ãã㨠ssh ex-jpã§æ¥ç¶å¯ã«ï¼ä¾¿å©ï¼¾ï¼¾ ãã£ã¨è©³ããæ å ±ã¯ m
éµäº¤ææ¹å¼ã®sshã§ã¢ã¯ã»ã¹ããã«ã¯ã§ã¯ãPuTTYç¨ã®éµçæã½ããputtygen.exeã使ã£ãããLinuxã§ãéµãä½æãããã¨ãã§ãããWindowsã§éµãä½æããã¨ãOpenSSHã§èªèã§ããããã«å¤æããä½æ¥ãå¿ è¦ã¨ãªãããputtygen.exeã«ã¯OpenSSHã®éµãèªã¿è¾¼ãæ©è½ãããã®ã§ãLinuxã§éµãä½æããæ¹ãæéã¯å°ãªãã¦æ¸ãã Linuxã§éµãä½æããã«ã¯ãssh-keygenã³ãã³ãã使ç¨ãããRSAæå·æ¹å¼ã®éµãä½æããã¨ãã¯ã-t rsaããªãã·ã§ã³ããDSAæå·æ¹å¼ã®éµãä½æããã¨ãã¯ã-t dsaããªãã·ã§ã³ãä»å ããã $ ssh-keygen -t rsaãâRSAæå·æ¹å¼ã®éµãä½æ Generating public/private rsa key pair. Enter file in which to save the key (/home/
ã/etc/hosts.allowããã¡ã¤ã«ãªã©ã§ã¢ã¯ã»ã¹å¶éãªã©ãè¡ã£ã¦ãã¦ããç¸æ¬¡ãã¢ã¿ãã¯ã«é ãæ©ã¾ãã¦ããªãã ããããsyslogã«ã¢ã¿ãã¯ã®çè·¡ãä½è¡ãæ®ã£ã¦ãããã¨ã«ãæ°ã«ãªã£ã¦ãã管çè ã¯å¤ãã¯ãã ã ã»ãã¥ã¢ã·ã§ã«ã½ããã®1ã¤ãOpenSSHããå©ç¨ãã¦ããå ´åã«ã¯ãä¸æ£ãªã¢ã¿ãã¯ãç«ã¦ç¶ãã«è¡ãããéã次ã®ããã«è¨å®ãããã¨ã§ã¢ã¯ã»ã¹å ã«å¶éãæãããã¨ãã§ããã ãMaxStartupsãã«ã¯3ã¤ã®æ°å¤ãã:ãã«åºåããã¦è¨è¿°ããã¦ãããSSHãã¼ã¢ã³ã¸ã®èªè¨¼è¦æ±æ°ãæå³ããã ä¸è¨ã®è¨å®ä¾ã§ã¯ãã2ãã¤ã¾ã§ã®æ¥ç¶è¦æ±ãåãä»ãã3ã¤ãè¶ ãããã以éã®è¦æ±ãã80ãï¼ ã®å²åã§æå¦ããããã«è¦æ±ãå¢ãç¶ãã¦ã5ãã¤ãè¶ ããã¨ä»¥éãã¹ã¦ãæå¦ããã¨ããæå³ã ãèªåã®ãµã¼ãç°å¢ã«å¿ãã¦æ°å¤ãå¤ããã¨ããã ãããå¤æ´å¾ã¯ãã¼ã¢ã³ãåèµ·åãããå¿ è¦ãããã
OpenSSH SSH ãã¼ã¢ã³ è¨å®ãã¡ã¤ã« æ¸å¼ /etc/ssh/sshd_config 説æ sshd (8) ã¯/etc/ssh/sshd_config(ãããã¯ã³ãã³ãã©ã¤ã³ãã-f ãªãã·ã§ã³ã§æå®ãããã¡ã¤ã«) ããè¨å®ãèªã¿è¾¼ã¿ã¾ãããã®ãã¡ã¤ã«ã®åè¡ã¯"ãã¼ã¯ã¼ã å¼æ°"ã®å½¢å¼ã«ãªã£ã¦ããã空è¡ããã㯠# ã§å§ã¾ãè¡ã¯ã³ã¡ã³ãã¨ã¿ãªããã¾ãã空ç½ãå«ãå¼æ°ã¯ããã«ã¯ã©ã¼ã ã§å²ãã§è¡¨ç¾ãããã¨ãã§ãã¾ãã 使ç¨ã§ãããã¼ã¯ã¼ãã¨ãã®èª¬æã¯ä»¥ä¸ã®éãã§ã(ãã¼ã¯ã¼ãã§ã¯å¤§æåå°æåã¯åºå¥ããã¾ããããå¼æ°ã§ã¯åºå¥ããããã¨ã«æ³¨æãã¦ãã ãã): AcceptEnv (åãä»ããç°å¢å¤æ°) ã¯ã©ã¤ã¢ã³ãããéãããç°å¢å¤æ°ã®ãã¡ãã©ãããã®ã»ãã·ã§ã³ã®environ (7) ã«ã³ãã¼ããããæå®ãã¾ããã¯ã©ã¤ã¢ã³ãå´ãã©ã®ããã«è¨å®ãããã«ã¤ãã¦ã¯ssh_config (
GUIã§ããã¨ç°¡åã ã·ã¹ãã ç°å¢è¨å®âå ±æãã¨é¸ã³ã"ãªã¢ã¼ããã°ã¤ã³"ã«ãã§ãã¯ãã¤ããã 以ä¸ã ã³ãã³ãã§ãããããããã¨ãã㨠mac ã®èµ·åããã»ã¹ãç¥ããªãã¨åºæ¥ãªãã詳細ã¯ãã¡ãã http://www.itmedia.co.jp/enterprise/articles/0704/26/news009.html è¨å®æ¹æ³ã¯ãå¤å "/System/Library/LaunchDaemons/ssh.plist" ã®ä¸ã®ä»¥ä¸ãæ¶ãã ãã§ããããããªãããªã Disabled ã»ãã¥ã¢ãªè¨å®ã«ããããããã¹ã¯ã¼ãèªè¨¼ããã£ã¬ã³ã¸ã»ã¬ã¹ãã³ã¹èªè¨¼ã¯ç¦æ¢ããå ¬ééµèªè¨¼ã ãã«ãããLinuxã«ã¤ãã¦ã§ãã mac ãåããã¾ããæ¥ç¶ã¦ã¼ã¶ãéå®ããæ¹ãããã»ãã¥ã¢ã§ãããããã¼ã®ä½æçã«ã¤ãã¦ã¯ããã¡ãã http://www.atmarkit.co.jp/flinux/rensai
# Uncomment the following line to require a user to be in the "wheel" group. ### modify 2008/01/19 #auth required pam_wheel.so use_uid auth required pam_wheel.so use_uid â ã³ã¡ã³ããã¯ãã [logon_user@localhost ~]$ cd [logon_user@localhost ~]$ ssh-keygen -t rsa â SSH2ã®å ´åãRSAéµãä½æãã Generating public/private rsa1 key pair. Enter file in which to save the key (/home/logon_user/.ssh/id_rsa): â ããã©ã«ãã§OKã®ããããªã¿ã¼
ææã§éç¨ãã¦ãããµã¼ãã®è©±ãªãã§ãããå²ã¨"SSH Brute Force Attack"ããããã対çãè¡ããªãã¨ãããªããã§ããããã®åã«ãã£ãããªã®ã§ãæ»æè ãã©ããªã¦ã¼ã¶åã§ãã°ã¤ã³ã試ã¿ã¦ãããã®çµ±è¨ãåã£ã¦ã¿ã¾ããã ã¨ããããã§ããã°ã¤ã³ã«å¤±æããåæ°ãä¸ä½10ã¦ã¼ã¶åã®ä¸è¦§ãåå¾ããã¯ã³ã©ã¤ãã¼ã # cat /var/log/secure* | grep 'Invalid' | awk '{print $8}' | sort | uniq -c | sort -nr | head -n 10çµæã¯ãã ãããäºæ³éãã§ãããâã®ãããªæãã§ãã 1474 admin 1399 test 1059 123456 751 oracle 703 user 570 guest 416 web 380 www 370 info 359 backupã¨ããããã§ã"admin"ã¨ã"
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}