The Open Web SSO project (OpenSSO) provides core identity services to simplify the implementation of transparent single sign-on (SSO) as a security component in a network infrastructure. OpenSSO provides the foundation for integrating diverse web applications that might typically operate against a disparate set of identity repositories and are hosted on a variety of platforms such as web and appli
SAMLã¨ã¯ãç°ãªãã·ã¹ãã éã«ãããèªè¨¼æ å ±ã®äº¤æãããã³ã«ã§ãã以åã®AuthXML (Authentication XML) ã¨S2MLï¼Security Services Markup LanguageãNetegrity社ä»æ°ç¤¾ãéçºï¼ãçµ±åãããæ°ããæ©è½ã追å ããã¦SAMLã¨ãªãã¾ããã2002å¹´11æã«1.0çãOASISæ¨æºã¨ãã¦æ¿èªãããç¾å¨2.0çãéçºä¸ã§ãã (http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security) SAMLã¨ã¯ä½ãï¼ ä½ããè³¼å ¥ãããå ´åããããµã¤ãã§ã¦ã¼ã¶åããã¹ã¯ã¼ãçã®æ å ±ãå ¥åãã¦ãµã¤ã³ãªã³ãã¦ããå¥ã®ãµã¤ãã«ãµã¤ã³ãªã³ããã¨ãã«ã¯æ°ãã«å ¥åãç´ããªããã°ãªãã¾ãããä¸åº¦ãããµã¤ãã«ãµã¤ã³ãªã³ããã°ä»ã®ãµã¤ãã§ãå ¥åä½æ¥ãªãã§å©ç¨ã§ããã¨ã¦ã¼ã¶ã«ã¨ã£ã¦ã¯ã¨ã¦
ãã¤ã³ã âã±ã«ããã¹ï¼Kerberosï¼èªè¨¼ã¨ã¯ï¼è¤æ°ã®ãµã¼ãã¼ã¨è¤æ°ã®ã¦ã¼ã¶ã¼ã®èªè¨¼æ å ±ãä¸å 管çããã®ã«é©ããããã¿ã§ãããããã¨ãããéä¿¡ãæå·åããæ©è½ããã âã±ã«ããã¹èªè¨¼ãå®è£ ããã«ã¯ï¼ã³ã³ãã¼ãã³ãéã§æå»åæãå¿ è¦ âã·ã³ã°ã«ãµã¤ã³ãªã³ã¨ã¯ï¼1åã®èªè¨¼ã§è¤æ°ã®ãµã¼ãã¹ãå©ç¨ã§ããããã«ããããã¿ã®ã㨠ããã¾ã§ã«ãããã¯ã¼ã¯ç°å¢ã§å©ç¨ããã¦ããèªè¨¼æ¹å¼ãè¦ã¦ãã¾ãããï¼ä»åã¯ã±ã«ããã¹èªè¨¼ã¨ããæè¡ãå¦ã³ã¾ããã¦ã¼ã¶ã¼æ å ±ãä¸å 管çãï¼ä¸åº¦åããèªè¨¼æ å ±ãã»ãã®ãµã¼ãã¼ã¸ã¢ã¯ã»ã¹ããã¨ãã«ãå¼ãç¶ããããã«ããä»çµã¿ã§ãã社å ããããªã©ã«å¤æ°ã®ã¦ã¼ã¶ã¼ã¨ãµã¼ãã¼ãåå¨ãï¼åã ã®ã¦ã¼ã¶ã¼ã¯åæã«è¤æ°å°ã®ãµã¼ãã¼ã¸ã¢ã¯ã»ã¹ããå¿ è¦ãããæã«å¨åãçºæ®ãã¾ãã PPPãRADIUSã¨ã¯éã ååã¾ã§ãããã¯ã¼ã¯ç°å¢ã§å©ç¨ãããèªè¨¼æ¹å¼ãããã¤ãç´¹ä»ãã¦ãã¾ãããããã§ç°¡åã«æ´
ã«ã¼ããããã®åé¡ã話é¡ã«ãªãä¸æ¹ã§ï¼ã«ã¼ããããã®ä¾µå ¥ã妨ããã»ãã¥ãªãã£ã»ãã¼ã«ãå¢å ãã¦ãããä»åã¯ï¼8ææçµé±ã®æ®µéã§çè ãææ¡ãã¦ããï¼ã¹ã¿ã³ãã»ã¢ãã³ã®ã«ã¼ããããæ¤åºï¼åé¤ãã¼ã«ã13æ¬ç´¹ä»ããããã¦ã¤ã«ã¹å¯¾çã½ãããã¹ãã¤ã¦ã¨ã¢å¯¾çã½ããã¨åãã§ï¼1ã¤ã®ã«ã¼ããããåé¤ãã¼ã«ã§ï¼ãã¹ã¦ã®ã«ã¼ãããããåé¤ããã®ã¯ä¸å¯è½ã ãè¤æ°ã®ãã¼ã«ãçµã¿åãããã®ãæã¾ããã ãªãç´¹ä»ãããã¼ã«ã®ãªãã§ï¼èè ã¯ãRootkitRevealerããF-Secure BlackLightããSophos Anti-RootkitããIceSwordãã使ã£ããã¨ããããããããèè ãããç¥ã£ã¦ãããã³ãã¼ã®ãã¼ã«ã§ããï¼ãããªãã«ä¿¡ç¨ã§ããã¨æã£ã¦ä½¿ç¨ããã ä¸é¨ã®ãã¼ã«ï¼ãGMERããDarkSpyããRootkit Unhookerãï¼ã¯é¢ç½ããã ãï¼ä½è ã誰ãªã®ãåãããªããï¼ãã¼ã«ã®
èªåããã¯ã¢ããå¦çãããããã ã·ã§ã«æ¨©éãä¸ããããªãã¨ãã¨ãã«ä½¿ããæã ããæ¹ã¯ç°¡å㧠$HOME/.ssh/authorized_keys ã® "ã³ãã³ããå¶éãããå ¬ééµ" ã®è¡ã®å é ã« å®è¡ããããã³ãã³ããè¨è¿°ããã°ããã ãã®ã¨ãã®ãã©ã¼ãããã¯ã ããã以ä¸ã®ããã«ãªãã command="å®è¡ããããã³ãã³ã",sshã®ãªãã·ã§ã³ãã«ã³ãåºåãã§æ¸ã command=hoge ã¨ããã®ãä»ã足ããã¨ã«ãã£ã¦ ãã®å ¬ééµã§ã¢ã¯ã»ã¹ããã£ãã¨ãã« æå®ããã³ãã³ããå®è¡ããããã¨ãã§ããã ãã¨ãã°ãuptime ãå®è¡ããããã¨ãã¯ã 以ä¸ã®ããã«ããã°ããã command="uptime",no-pty,no-port-forwarding,no-X11-forwarding,no-agent-forwarding ssh-rsa AAAABbBFERTWER....
ãªã¼ãã³ã½ã¼ã¹ã§éçºããã¦ãããå ¨ã¦ã®è¨å®ã»ç®¡çããã©ã¦ã¶ããã§ããããã«ãªã£ã¦ãããã°ã©ãä½ææ©è½ãæ¨æºã§æè¼ãåãã¼ãã®æ å ±åéãç°å¸¸æ¤ç¥ãé害/復æ§éç¥ã詳細ãªã¢ã©ã¼ãéç¥æ©è½ãããSNMPv1ãv2ãv3ããµãã¼ãããUnixãLinuxãBSDãWindowsãMacOS XãNetWareãªã©ã§åä½ãCPUãã¡ã¢ãªããã£ã¹ã¯ããããã¯ã¼ã¯ãããã»ã¹ã®ç¶æ ãªã©ã®ç£è¦ãå¯è½ã§ãApacheãTomcatãOracleãªã©ã®ã¢ããªã±ã¼ã·ã§ã³ã®ç£è¦ãå¯è½ããªããªãå¼·åã 詳細ã¯ä»¥ä¸ã®éãã ZABBIX-JP - Un-Official Support Page http://www.zabbix.jp/ ZABBIX-JP - ZABBIXã¨ã¯ http://www.zabbix.jp/modules/main0/index.php?id=1 ZABBIX-JP - ç¹å¾´ http:
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}