Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?

Japanese translation v.1.0.1 Copyright © 2001-2006 Oskar Andreasson Copyright © 2005-2008 Tatsuya Nonogaki ãã®ææ¸ããããªã¼ã½ããã¦ã§ã¢è²¡å£çºè¡ã® GNU ããªã¼ææ¸å©ç¨è¨±è«¾å¥ç´æ¸ãã¼ã¸ã§ã³1.1 ãå®ããæ¡ä»¶ã®ä¸ã§è¤è£½ãé å¸ããããã¯æ¹å¤ãããã¨ã許å¯ãããåºæã¨ãã®å¯ç« ã¯å¤æ´ä¸å¯é¨åã§ããããOriginal Author: Oskar Andreassonãã¯è¡¨ã«ãã¼ããã¹ããè£ã«ãã¼ããã¹ãã¯æå®ããªãããã®å©ç¨è¨±è«¾å¥ç´æ¸ã®è¤è£½ç©ã¯ãGNU ããªã¼ææ¸å©ç¨è¨±è«¾å¥ç´æ¸ãã¨ããç« ã«å«ã¾ãã¦ããã ãã®ãã¥ã¼ããªã¢ã«ã«å«ã¾ãããã¹ã¦ã®ã¹ã¯ãªããã¯ããªã¼ã½ããã¦ã§ã¢ã§ããããªãã¯ããããããªã¼ã½ããã¦ã§ã¢è²¡å£ã«ãã£ã¦çºè¡ããã GNU ä¸è¬å ¬è¡å©ç¨è¨±è«¾å¥ç´æ¸ãã¼ã¸ã§ã³2ã®å®ããæ¡ä»¶ã®
管çä¸ã®ãµã¼ãã§è¡ã£ã¦ããã»ãã¥ãªãã£è¨å®ãå ¬éãã¾ããæ¬å½ã¯ãããããã¨ãå ¬éããã®ã¯ãããããªãã®ã§ãããèå¼±ãµã¼ãã氾濫ãã¦ããç¾ç¶ãããè¸ã¿å°ã¨ãªã£ã¦sshã¢ã¿ãã¯ãããã®ãè¿·æ極ã¾ããªãã®ã§ãæä½éãã£ã¨ãã¨ããå 容ã§ã¾ã¨ãã¾ããã*1 èµ·åãµã¼ãã¹ã¨æ¦è¦ iptables/Firewallã®è¨å® iptablesã®ä¸èº« limit-burstã«ã¤ã㦠hashlimitã«ã¤ã㦠hosts.allow/hosts.deny(TCP Wrapper)ã®è¨å® sshdã®è¨å® ãã®ä»ã®è¨å® Apacheã®è¨å® Postfixã®è¨å® Dovecotã®è¨å® ã¾ã¨ã èµ·åãµã¼ãã¹ã¨æ¦è¦ Apache (www) sshd smtp/pop bind (DNS) ntpd ããã¤ãã®æ³¨æç¹ã sftpã§ååãªã®ã§ftpdã¯ä½¿ããªããWinSCPçã使ãã°ffftpã«ä¾åããå¿ è¦ã¯ãªãã*2
iptables ã¨ã¯ãLinux ã«å®è£ ããããã±ãããã£ã«ã¿ãªã³ã°åã®ãã¡ã¤ã¢ã¦ã©ã¼ã«æ©è½ã§ããä»å¾ã®ã¡ã³ããã³ã¹ãèãã¦ã·ã§ã«ã¹ã¯ãªãããå©ç¨ãã¦é©ç¨ããæé ãæ¡ç¨ãã¾ãããã®æé ãæ®ãã¾ãã ã·ã§ã«ã¹ã¯ãªããã®ä½æ ãã¡ã¤ã«ã®ä½æ ã¹ã¯ãªãããè¨è¿°ããããã®ãã¡ã¤ã«ãä½æãã¾ããä½æãããã¡ã¤ã«ã¯ææè ã®ã¿å ¨ã¦ã®æ¨©éãä¸ãã¾ãã ã¹ã¯ãªããã®è¨è¿° ãã±ãããã£ã«ã¿ãªã³ã°ã«ã¼ã«ãé©ç¨ããã¹ã¯ãªããããã¡ã¤ã«ã«è¨è¿°ãã¾ããé©ç¨ããå 容ã«ã¤ãã¦ä¸è¨ã®ã¨ããã§ãã åä¿¡ã転éã¯ãã¹ã¦æå¦ãéä¿¡ã¯ãã¹ã¦è¨±å¯ å é¨ããè¡ã£ãã¢ã¯ã»ã¹ã«å¯¾ããå¤é¨ããã®è¿çã¢ã¯ã»ã¹ãè¨±å¯ TCP SYN Floodæ»æ対ç Smurfæ»æ対ç ICMP Redirectãã±ããã¯æå¦ Source Routedãã±ããã¯æå¦ ãã©ã°ã¡ã³ãåããããã±ããã¯ãã°ãè¨é²ãã¦ç ´æ£ NetBIOSé¢é£ã®ã¢ã¯ã»ã¹ã¯ãã°ã
å æ¥ãªãã¥ã¼ã¢ã«ãããããããã®VPSãã§Webãµã¼ãï¼LAMPï¼ãæ§ç¯ããéã®åºæ¬è¨å®ããã³ãã¬ã¼ãã¨ãã¦å ¬éãã¾ããåèã«ãªãã°ãããªã¨ã 管çè ã¢ã«ã¦ã³ãã®ä½æ # useradd -G wheel userName # passwd userName # vi /etc/pam.d/su -- 以ä¸ã®è¡ã®ã³ã¡ã³ãã¢ã¦ããå¤ã # auth required pam_wheel.so use_uid -- # visudo -- 以ä¸ã®è¡ã®ã³ã¡ã³ãã¢ã¦ããå¤ã # %wheel ALL=(ALL) ALL -- SSHè¨å® # mkdir /home/userName/.ssh # chown userName. /home/userName/.ssh ã¯ã©ã¤ã¢ã³ãå´ã§å ¬ééµãä½æãããµã¼ãã«å ¬ééµã転é -- $ ssh-keygen -t rsa $ scp .ssh/id_rs
以åã SSHã¸ã®ãã«ã¼ããã©ã¼ã¹ã¢ã¿ãã¯å¯¾çã§denyhostãå ¥ãã¾ããããdenyhostãèµ°ãã¾ã§ã®éã¢ã¿ãã¯ããç¶ããã®ãæ°ã«ãªãã®ã§ãiptablesã使ã£ã¦ãããã¯ãã¦ã¿ã¾ãã æ¹æ³SSH(ï¼ï¼)ã¸ã®æ¥ç¶ãï¼ï¼ç§ä»¥å ã§ï¼å以ä¸ã®å ´åã«ï¼ï¼åéæ¥ç¶ãå¶éããè¨å®ã¯ä¸ã®æ§ãªæãã§ç»é²ãã¾ãã #æ¥ç¶å¶éãã©ã°ç«ã¦ $iptables -N SSHAttacker $iptables -A SSHAttacker -m recent --set --name attacker -j LOG --log-level warn --log-prefix 'SSHAttaker:' $iptables -A SSHAttacker -j DROP #æ¥ç¶å¶éããã¦ããå ´åã¯ï¼ï¼åéæ¥ç¶æå¦ $iptables -A INPUT -p tcp --dport 22 -m state --s
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}