CentOS 6.5 ã« kippo ãã¤ã³ã¹ãã¼ã«ãã¦ã¿ã
digitalOceanã¯ã©ã¦ãä¸ã«å®ãç°¡åã«kippoããã¼ããããæ§ç¯ãã | 徳丸浩ã®æ¥è¨
http://blog.tokumaru.org/2014/01/digitaloceankippo.html
sshããã¼ããããkippoã§ä½ã£ã¦ã¿ã - ãã°é»åãè©°ã¾ã£ã¦ãã
http://d.hatena.ne.jp/ozuma/20130829/1377703104
ãããã®VPSã«æ¥ãæªã人ã観å¯ãã ãã®ï¼
http://www.slideshare.net/ozuma5119/vps-28984029
ãã®è¾ºãã®è¨äºãèªãã§ã¨ã¦ãé¢ç½ããã ã£ãã®ã§ãSSH ããã¼ãããã® kippo ã CentOS 6.5 ç°å¢ã«ã¤ã³ã¹ãã¼ã«ãã¦ã¿ã¾ããã
ä¾åã©ã¤ãã©ãªã®ã¤ã³ã¹ãã¼ã«
ã¾ã㯠kippo ãåããããã®ã©ã¤ãã©ãªçãã¤ã³ã¹ãã¼ã«ãã¦ããã¾ãã
yum ãã gcc, python-devel, setuptools ãã¤ã³ã¹ãã¼ã«ã
# yum install -y gcc python-devel python-setuptools
setuptools ãå ¥ããã¨ä½¿ããããã«ãªã easy_install ã³ãã³ã㧠pip ãã¤ã³ã¹ãã¼ã«ãã¾ãã
# easy_install pip
pip ãã pyasn1, pycrypto, twisted ããã±ã¼ã¸ãã¤ã³ã¹ãã¼ã«ã
# pip install pyasn1 pycrypto twisted
ããã§å¿ è¦ãªã©ã¤ãã©ãªã¯ä¸éãå ¥ãã¾ããã
SSH ãã¼ãçªå·ã®å¤æ´
SSH ã®æ¨æºãã¼ã 22 çªã¯ kippo ã§ä½¿ç¨ãããã®ã§ãæ¬æ¥ã® sshd ã使ç¨ãããã¼ãçªå·ãå¤æ´ãã¾ãã
# vi /etc/ssh/sshd_config
ããã§ã¯å¾³ä¸¸ããã®è¨äºã«ç¿ã£ã¦ 10022 çªãã¼ãã«å¤æ´ãã¾ããã
#Port 22 Port 10022
å¤æ´ããã sshd ãåèµ·åãã¾ãã
# service sshd restart
â» æå ã® TeraTerm ã§ã¯ãã㧠sshd ãåèµ·åãã¦ãç¹ã«åé¡ãªãä½æ¥ãç¶è¡ã§ãã¾ããããVPS ãªã©ã§è©¦ãã¦ããå ´åãããä¸å®ãªãå ã«ä»¥ä¸ãå®è¡ãã¦ãiptables ã§å¤æ´å¾ã® SSH ãã¼ãã空ãã¦ãããæ¹ãç¡é£ããç¥ãã¾ããã
iptables ã®è¨å®
iptables ã§å¤æ´å¾ã® sshd ç¨ãã¼ã㨠kippo ã® LISTEN ãã¼ããéæ¾ãã¾ãã
ããã§ã¯ CentOS ã®ããã©ã«ãã®ã«ã¼ã«ããã®ã¾ã¾ã«ãã¦ããã®ã§ã-A ã§æ«å°¾ã«è¿½å ãã¦ãä¸æãåãã¾ããã
ãªã®ã§ -I ã§å
é ã«ã«ã¼ã«ã追ãã¦ãã¾ãã
# iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport 2222 -j ACCEPT # iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport 10022 -j ACCEPT
ãã¼ã 22 ã kippo ã®ããã©ã«ããã¼ã 2222 ã«ãªãã¤ã¬ã¯ãããããã«ä»¥ä¸ã®ã«ã¼ã«ã追å ãã¾ãã
# iptables -t nat -A PREROUTING -p tcp --dport 22 -j REDIRECT --to-port 2222
kippo ã®ã¤ã³ã¹ãã¼ã«
ãããã kippo ãã¤ã³ã¹ãã¼ã«ãã¾ãã
ã¾ã㯠kippo ã®èµ·åç¨ã¦ã¼ã¶ã追å ãã¾ãã
# useradd kippo
ä½æãã kippo ã¦ã¼ã¶ã«ãªãããã¦ã³ãã¼ããã¦å±éãã¾ãã
# su - kippo $ wget https://kippo.googlecode.com/files/kippo-0.8.tar.gz $ tar xzf kippo-0.8.tar.gz $ cd kippo-0.8
ãã°ãæå¹ã«ãããããè¨å®ãã¡ã¤ã«ãç·¨éãã¾ãã
$ vi kippo.cfg
ãã¡ã¤ã«æ«å°¾ã®ä»¥ä¸ã®è¡ã®ã³ã¡ã³ãã¢ã¦ãã解é¤ã
[database_textlog] logfile = kippo-textlog.log
ã¾ããkippo ã§ãã°ã¤ã³ãå¯è½ã¨ããã¦ã¼ã¶ã以ä¸ã®ãã¡ã¤ã«ã§å®ç¾©ããã¦ãã¾ãã
$ cat data/userdb.txt root:0:123456
ããã©ã«ãã§ã¯ä¸è¨ã®ããã« root ã¦ã¼ã¶ããã¹ã¯ã¼ãã123456ãã§å®ç¾©ããã¦ãã¾ãã
ãã®ãã¡ã¤ã«ãå¤æ´ãããã¨ã§ã¦ã¼ã¶ã追å ãããããã¹ã¯ã¼ããå¤æ´ãããã¨ãã£ãäºãã§ãã¾ãã
æºåãã§ããã kippo ãèµ·åãã¦ã¿ã¾ãã
$ ./start.sh
Starting kippo in background...Loading dblog engine: textlog
Generating RSA keypair...
done.
ç¡äºèµ·åã§ãã¾ããã
èµ·åã§æ¥ããå ã»ã©è¨å®ãã¡ã¤ã«ã§æå¹ã«ãã以ä¸ã®ãã°ã tail ãã¦ããã¾ãã
$ tail -f ./kippo-textlog.log
ãã®ç¶æ
ã§å¥ã® SSH ã¯ã©ã¤ã¢ã³ããèµ·åãã¦ãã¼ã 22 ã«æ¥ç¶ããroot / 123456 ã§ãã°ã¤ã³ãããã¨ãã§ãã¾ãã
ãã°ã¤ã³å¾ãã³ãã³ããå®è¡ãã¦ã¿ã㨠kippo-textlog.log ã«ä»¥ä¸ã®ããã«ä½ãå®è¡ããããè¨é²ããã¦ããäºãåããã¾ãã
$ tail -f ./kippo-textlog.log b52fc974918911e3b432000c29ca5f43 [2014-02-09 21:57:18]: New connection: 192.168.81.1:50270 b52fc974918911e3b432000c29ca5f43 [2014-02-09 21:57:26]: Login succeeded [root/123456] b52fc974918911e3b432000c29ca5f43 [2014-02-09 21:57:26]: Terminal size: 150x45 b52fc974918911e3b432000c29ca5f43 [2014-02-09 21:57:29]: Command [w] b52fc974918911e3b432000c29ca5f43 [2014-02-09 21:57:32]: Command [ls] b52fc974918911e3b432000c29ca5f43 [2014-02-09 21:57:37]: Command [ls -l]
åãããã試ããã®ã¯ããã¾ã§ã
CentOS ã§ãçµæ§ç°¡åã«å°å
¥åºæ¥ãäºãåãã£ãã®ã§ãããããéãã§ã¿ããã¨æãã¾ãã