å ¬ééµèªè¨¼ã使ã£ããã«ã¼ããã©ã¼ã¹ã¢ã¿ãã¯å¯¾ç
ãã®æãbrute forceã¢ã¿ãã¯ãããã®ãæãããã£ãã®ã§ãèªå® ãµã¼ãã¼ã® sshd ã¯ã22 以å¤ã®é©å½ãªãã¼ãã«ãã¦ã¾ããããããããããsshd ã®ãã¼ãå¤ããã¨ãXming ã¨ããåããªãã£ãããã¦(port 22以å¤ã§Xming使ãæ¹æ³ããããã)ãªã«ãã«ä¸ä¾¿ãããã§ãå ¬ééµèªè¨¼ã®ã¿ã§ ssh æ¥ç¶ã§ããããã«ããã¨ãã®ã¡ã¢ã
å ¬ééµèªè¨¼ã¨ã¯ãå ¬ééµã¨ç§å¯éµãä½æãããµã¼ãã¼å´ã«å ¬ééµãç½®ãã¦ãã°ã¤ã³æã«ç§å¯éµãç¨ãã¦èªè¨¼ãè¡ãããæ¹ã§ããç°¡åã«æé ãæ¸ãã¨ãâãããªæãã
local> ssh-keygen -t dsa # SSH 2 DSA éµä½æï¼ãã¹ãã¬ã¼ãºå ¥å local> scp ~/.ssh/id_dsa.pub server:~/temp/ # ãµã¼ãã¼ã®~/temp/ã«å ¬ééµãã³ãã¼ local> ssh server # ãµã¼ãã¼ã«ãã°ã¤ã³ server> cat temp/id_rsa.pub >> ./ssh/authorized_keys # å ¬ééµã追å server> exit local> eval `ssh-agent` # ssh-agent ãèµ·å local> ssh-add # ç§å¯éµãèªã¿è¾¼ã local> ssh server # serverã«ãã°ã¤ã³ãã¦ã¿ãã Enter passphrase for key '/home/hoge/.ssh/id_dsa': # ãã¹ãã¬ã¼ãºãèãããããã«ãªã£ã
local ã¯ãæå ã®ãã·ã³ãserver ã¯ããªã¢ã¼ããã°ã¤ã³ããããã·ã³ã¨ç½®ãæãã¦ãã ãããããã¾ã§ã§ãå ¬ééµèªè¨¼ã¯åºæ¥ã¦ããç¶æ ã§ããã¨ãã¾ãã
次ã«ããã¹ã¯ã¼ãèªè¨¼ãç¦æ¢ã«ãã¾ãã/etc/ssh/sshd_config ã以ä¸ã®ããã«ä¿®æ£ãã¾ãã
PermitRootLogin no # root ã§ã®ãªã¢ã¼ããã°ã¤ã³ã¯å½ç¶ç¦æ¢ PasswordAuthentication no # ãã¹ã¯ã¼ãèªè¨¼ã«ãã ssh ã¢ã¯ã»ã¹ã¯ç¦æ¢ PubkeyAuthentication yesã# å ¬ééµèªè¨¼ãè¨±å¯ RhostsAuthentication noã # rhostèªè¨¼ãç¦æ¢ ChallengeResponseAuthentication no # ãã£ã¬ã³ã¸ã¬ã¹ãã³ã¹èªè¨¼ãç¡å¹ UserPAM no # PAMã«ããèªè¨¼ãç¡å¹
ã¡ãªã¿ã«PAMã¨ã¯ãPluggable Authentication Modules ç¥ã§ããã¾ãã¾ãªUNIXã§å©ç¨ããã¦ããã¦ã¼ã¶ã¼èªè¨¼ã®ä»çµã¿ã®ãã¨ã§ãã詳ããã¯ãUser Authentication HOWTOãåç §ãã¦ãã ããã
è¨å®ãä¿®æ£ãããã
sudo /usr/sbin/sshd -t
ãã¦ãè¨å®ãæ£ããããã¹ãããã¾ããééããç¡ããã°ã
sudo /etc/rc.d/sshd restart
ã¨ã㦠sshd ãåèµ·åãã¾ãã以ä¸ã§ãssh ã使ã£ããã¹ã¯ã¼ãèªè¨¼ã¯ã§ããªããªãã¾ãããããã§å¤é¨ããä¾µå ¥ããããã¨ã¯ãªãã§ããããããéµãæ¼ããªãéããããããã®ã¾ã¾ã§ã¯ãã¢ã¿ãã¯ããã㨠sshd ã«è² è·ãããã£ã¦ãã°ãè¨ãä¸ãã£ã¦ã¤ã¤ã³ãªã®ã¯å¤ãããªãã®ã§ããã£ã±ãã¡ãããã±ãããã£ã«ã¿ããªãã¨ãã¡ã§ããªã»ã»ã»ã
追è¨:
Brute Force Attack対çã«ã¤ãã¦ãã¨ã¦ãããã¾ã¨ã¾ã£ã¦ããµã¤ããè¦ã¤ãã¾ããã
- ç¹å®IPã¢ãã¬ã¹ã®ã¿ããã®ã¢ã¯ã»ã¹ã許å¯ããä»ã¯å ¨æå¦ãã
- sshd ã® listen port ã 22/tcp ããä»ã®ä»»æã® port ã«å¤æ´ãã
- sshd.conf ã® Port 22 ã 22 以å¤ã®ä»»æã®æ°åã«å¤æ´
- ãããã¯port 22 ã« knockd ã使ã
- ãã¹ã¯ã¼ãã«ããèªè¨¼ãç¦æ¢ãã (PasswordAuthentication no, ChallengeResponseAuthentication no)
- ç·å½ããæ»æã®é²å¾¡ã¹ã¯ãªãããå°å ¥ããã
- ãã°ããæ»æãæ¤ç¥ããlibwrap ã iptables, ipf çã§æå¦
- iptables ã®æ©è½ã使ã£ã¦åãIP空ã®é£ç¶ã¢ã¯ã»ã¹ãèªåæå¦
ãã®ã¨ã³ããªã¯ãä¸è¨ã®ãªã³ã¯å ã«æ¸ããã¦ããã3. ãã¹ã¯ã¼ãã«ããèªè¨¼ãç¦æ¢ãããã®æé ãæ¸ãããã®ã§ãã