â [twitter] ä»å¹´ã®ä¸æå ä»å¹´ä¸çªã¤ã¶ãããã®ã¯å¦»ã ã£ããæ¯æ¥å¼å½ã¿ã¤ã ã¨ãã®ä»ã§ã¤ã¶ããã¦ãããããããããã ããªã¼ã¨ããçµæãä»ã«ã¯çå¸ã¨ãä¼ç¤¾ã¨ãã â [redis][iptables] redis 㨠iptables ã§ã¯ã¾ã£ãã¨ãã話 redis ã®ç°å¢ãæ§ç¯ãã¦ãã¦ãã¤ã³ã¹ãã¼ã«ã¯ç¡äºçµãã£ããã®ã® resque ã® worker ã timeout ãã¦æ»ãã§ãã¾ã£ãããredis-cli ãå©ãã¦ããªã«ãèµ·ããªãç¾è±¡ãçºçãã¦ãã¦æ°æéã¯ã¾ã£ã¦ãããã ãã©ãiptables 㧠TCP port 6379 ãéãã¦ããªãã®ãåå ã ã£ããã¨ã»ã»ã çµå±ãä¸ã®ããã« 6379 ãã¼ããéãããã¨ã§ã ãããå ¨é¨ãåãããã«ãªã£ãã iptables -A INPUT -p tcp --dport 6379 -j ACCEPT æ®æ®µãã®è¾ºã¯æèããªãããé£ããããã
ã¹ãã¼ããã«ãã±ãããã£ã«ã¿ã使ã£ããµã¼ãã¹ã®å ¬é é£è¼ï¼ç¿ãããæ £ããï¼ iptablesãã³ãã¬ã¼ãéï¼1ï¼ãåå¿è ã«ã¨ã£ã¦ãiptablesã¯é£ãããããã§ãå¦ç¿ã®ç¬¬1æ©ã¨ãã¦ãã³ãã¬ã¼ããèªåã®ç°å¢ã«é©å¿ããããã¨ããå§ããã
è£è¶³ï¼ãã¾ãªãrecentãããªãã¦hashlimitã使ã£ãæ¹ããããã 以ä¸ã®æç« ã¯recentã«ã¤ãã¦ãªã®ã§ãhashlimitã«ã¤ãã¦è¿½è¨ãã id:hirose31:20060421 ãè¦ã¦ããã£ãæ¹ãããã¨æããã SSHã®brute forceã¢ã¿ãã¯ããããã®ã§ãiptablesã§æªãåã¯DROPããããã«ããã OpenSSHã®ãã°ãã¿ã¦ã ä¸å®æéã«ä¸å®åæ°é£ç¶ã§ã¢ã¯ã»ã¹ã«å¤±æãã¦ãããã¤ã¯DROPããããã«ãã¦ã atã§ç¶ãã¹ãæéãçµã£ãã解é¤ããããã« ãããããªãã¨æã£ãããiptablesã«ã¯ipt_recentãªãã¦ä¾¿å©ããã®ãããã®ãããã£ãã Debian GNU/Linux 3.1(sarge)éç¨ãã¼ã SuSE Security mailinglist: Re: [suse-security] SSH attacks. iptables(8) âã
ããããã¤å¯ã㨠ä»å¹´ã®ã¯ããã«ãããããã¨ãªã¹ããä½ã£ããä»è¦ãã50é ç®ãããªã¹ãã®ãã¡25åãéææ¸ã¿ã ã£ããã¡ããã©ååãããããã¨ããã£ãã¨ãããã¨ã ãç§ã«ãã¦ã¯ã¾ãã¾ãã®çµæã ã¨æããæºè¶³ã ãããããã¨ãªã¹ãã«ãããã®ã®ãã¡ããããé£ã¹ãããç³»ã¯æ¦ãã¯ãªã¢ãâ¦
仲æ¥ã¯ãã£ããã¨éãéãã å¯ã¦èµ·ããã3æã§ãããä»æ¥ã®æ±äº¬ã®æé«æ°æ¸©ã¯20度ãè¶ ãã¦ãããæ£æã®ã¤ã³ãã«ã¨ã³ã¶ãå®æ²»ãã¦ãããã§ãã£ã¨å¥åº·ã§æåçãªæ¬å¹´åº¦ãå§ããããããã¨ææ°è¾¼ãã ã®ãæã®éãä»åº¦ã¯åå ä¸æã®é«ç±ãåºãã¦1é±éå¯è¾¼ãã ã è³ãã°ãã°ãç ®ããé³ãè´ãããããªã»ã©â¦
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}