iptables ã§ã®å¯¾ç
ã©ããæè¿ãssh ã«å¯¾ãããã«ã¼ããã©ã¼ã¹ã»ã¢ã¿ãã¯ãã¯ãã£ã¦ããããããåã«ãï¼æéåãã®ã®éãã¢ã¿ãã¯ããã¦ãããã®ãæ¸ããããä»åº¦ã¯ 7/21 18:56:24ï¼æ¥æ¬æéï¼ãã 23:48:24ãç´ï¼æéã«æ¸¡ã£ã¦ãã¼ã£ã¨ãã ããªã¢ã¿ãã¯ããã¦ãã¾ããããã¶ããã¼ã«ã¯åãã§ãã¢ã¿ãã¯ã«ä½¿ãè¾æ¸ãè±å¯ã«ãªã£ã¦ãã¦ããªãã ãããã©ãç¹°ãè¿ãã¾ãããæã家㮠ssh ãµã¼ãã¯å ¬ééµèªè¨¼ä»¥å¤ãæããªã®ã§ãåãªããã°ã¤ã³èªè¨¼ãç¹°ãè¿ãã¦ããæ°¸é ã«å ¥ãããã¨ã¯ããã¾ããã®ã§ããããããã
ãã ããããé·æéã«ããã£ã¦ç¶ããããã¨ãããã¤ã®ããã«å¸¯åãåããã¦ããã¨ããã®ãçªã«éããå¥ã«ãå®å®³ã¯ç¡ããã ãã©ããã¯ãæ°åãæªããOpenSSH ã§èªè¨¼ã«å¤±æããå ´åã«ãã ãã ãèªè¨¼çµæã®ã¬ã¹ãã³ã¹ãé ããªããããªä»çµã¿ãããã°ããããè¨å®ãããã®ã ããèªè¨¼é¨åã PAM ã«æ¸¡ãã¦ãPAM å´ã§é 延ãçºçãããæ¹æ³ã¯ããã¿ããã ãã©ãå ¬ééµèªè¨¼ã§ã¯åºæ¥ãªãã¿ããã
ã§ãããããæ¢ããçµæãiptables ã§è½ã¨ãæ¹æ³ã§è¯ãä¾ãçºè¦ãhttp://www.musicae.ath.cx/diary/?200506c&to=200506272#200506272 ã«æ¸ããã¦ããæ¹æ³ã§ã
#!/bin/sh IPTABLES="/sbin/iptables" EXTIF="eth0" $IPTABLES -N LSSHBRUTEFORCE $IPTABLES -A LSSHBRUTEFORCE -m recent --name badSSH --set -j LOG --log-level DEBUG --log-prefix "iptables SSH REJECT " $IPTABLES -A LSSHBRUTEFORCE -j REJECT $IPTABLES -N SSHACCEPT $IPTABLES -A SSHACCEPT -p tcp ! --syn -m state --state ESTABLISHED,RELATED -j ACCEPT $IPTABLES -A SSHACCEPT -p tcp --syn -m recent --name badSSH --rcheck --seconds 300 -j REJECT $IPTABLES -A SSHACCEPT -p tcp --syn -m recent --name sshconn --rcheck --seconds 60 --hitcount 5 -j LSSHBRUTEFORCE $IPTABLES -A SSHACCEPT -p tcp --syn -m recent --name sshconn --set $IPTABLES -A SSHACCEPT -p tcp --syn -j ACCEPT $IPTABLES -A INPUT -i $EXTIF -p tcp --dport 22 -j SSHACCEPT
ãããå®è¡ãã¦ãservice iptables save ã§è¨å®ãä¿åããè¦äºï¼ ãªãªã¸ãã«ã®ä½è ã«æè¬ï¼ï¼
å®ã¯ãå ã®ï¼æéè¿ãã¢ã¿ãã¯ã¯ããã®ãã£ã«ã¿ãè¨å®ãã¦æ¢ããã®ã§ãæ¾ã£ã¦ãããããããã«è¨é²ã伸ã°ãã¦ãããã(^^;ã