ã·ãã³ããã¯ã¯2017å¹´4æ19æ¥ãå人åãã»ãã¥ãªãã£ãã©ã³ãã§ãããã¼ãã³ã®æ°è£½åçºè¡¨ä¼ãéå¬ãããæ¥æ¬ã§å©ç¨è ãå¤ãiOSåãã«æ©è½å¼·åããããã¼ãã³ ã¢ãã¤ã« ã»ãã¥ãªãã£ãã®ææ°çã§ãWebãµã¤ãã®å®å ¨æ§ã®å¤æããã¹ã¯ã¼ãã®èªåä½æã¨ä¿åãèªåå ¥åã®å¼·åãå³ã£ãã2017å¹´4æ20æ¥ãã販売éå§ããã
2016å¹´ 8æä¸æ¬ãããChromeï¼ã¦ã¼ã¶ã¼èª¿æ»ãã¨ç§°ãã Webä¸ã®ä¸å¯©ãªè¡¨ç¤ºã訴ãããããä¸ã®å£°ã Twitter ãå種 SNS ãªã©ã§è¦ããã¦ãã¾ãããã¬ã³ããã¤ã¯ãã§ãåæ§ã®åãåãããåãã¦ããã調æ»ã®çµæãChromeå©ç¨è ã ãã§ãªã PC ãã¢ãã¤ã«å©ç¨è å ¨ä½ã対象ã«ãæçµçã«å©ç¨è ã®ã¯ã¬ã¸ããã«ã¼ãæ å ±ãçããã£ãã·ã³ã°ã«ã¤ãªãããã¢ã³ã±ã¼ãè©æ¬ºãäºä¾ã§ãããã¨ã確èªãã¾ããããã®ããã«ã¢ã³ã±ã¼ãããã¬ã¼ã³ãå½é¸ã®åç®ã§å©ç¨è ãèªå°ããææ³ã¯ãæ¨å¹´ã«æ¬ããã°ã§åãä¸ãããå½é¸è©æ¬ºãã®äºä¾ãªã©ãå®æçã«ç¢ºèªããã¦ãããããã°ãããè©æ¬ºã®ã常ã¨ãæ段ãã¨è¨ãã¾ããä»åã®ã¢ã³ã±ã¼ããå½è£ ããæå£ãæ¢ã«æ°å¹´åããç¹°ãè¿ãè¦ããã¦ããææ³ã§ãããã®ãããªå¸¸ã¨ãåãã¦ããæ»æã«é¢ãã¦ã¯ãã®æå£ãå¨ç¥ãããã¨ãæå¹ãªå¯¾çã®1ã¤ã¨ãªãã¾ãã®ã§ãæ¬ããã°è¨äºã«ããç¹°ãè¿ãããæå£ã®æ³¨æ
æ¬ããã°è¨äºã§ã¯ãããã¾ã§ãã¢ãã¤ã«å©ç¨è ãè ããæ§ã ãªãµã¤ãã¼è å¨ã«ã¤ãã¦ãä¼ããã¦ãã¾ãããããã大ããªè¢«å®³äºä¾ãç¶ç¶ãã¦å ±åããã¦ãã PC ã®å±éºã¨æ¯ã¹ãã¢ãã¤ã«ç«¯æ«ãå©ç¨ããéã®å±éºã«ã¤ãã¦ã¯ã¾ã ã¾ã 浸éãã¦ããªãã®ãç¾ç¶ã§ã¯ãªãã§ãããããæ¬é£è¼ã§ã¯ãã¬ã³ããã¤ã¯ãã®äºä»¶å¯¾å¿ã¨èª¿æ»åæããå¤æãã¦ãããææ°ã®ã¢ãã¤ã«è å¨äºæ ããä¼ããããã¾ãã第1åã¯è å¨ã®ä¾µå ¥çµè·¯ã¨ãã¦ã¢ãã¤ã«ã§ããçããã¦ããWebçµç±ãã®æ»æã«ã¤ãã¦ãã¾ã¨ãã¾ãã ãµã¤ãã¼ç¯ç½ªè ãã¤ã³ã¿ã¼ãããå©ç¨è ãæ»æããéã®çµè·¯ã¯ãã»ã¼2ã¤ã«éç´ããã¾ããé»åã¡ã¼ã«çµç±ã¨ Webçµç±ã§ããPC ã®å ´åãé»åã¡ã¼ã«ã®æ·»ä»ãã¡ã¤ã«ã«ããä¸æ£ããã°ã©ã ã®æ¡æ£ã¯å¤§ããªè¢«å®³ã«ç¹ãã£ã¦ãã¾ããããããä¸è¬çãªã¢ãã¤ã«å©ç¨è ã«ããã¦ãé»åã¡ã¼ã«ã§æ·»ä»ãã¡ã¤ã«ãéããåãåã£ã¦éãã¨ããå¦çã¯ãã¾ãé »ç¹ã«è¡ããã¨ã§ã¯ãªãããã§ãã
# æå¹ãªè¨å®ãç¢ºèª >>> firewall-cmd --list-services --zone=public --permanent dhcpv6-client # è¨å®è¿½å (sshã¨mysqlã追å ) firewall-cmd --add-service=ssh --zone=public --permanent firewall-cmd --add-service=mysql --zone=public --permanent # è¨å®åé¤(sshãåé¤) firewall-cmd --remove-service=ssh --zone=public --permanent # è¨å®ä¸è¦§ã表示 ls -lta /usr/lib/firewalld/services/ # åè¨å®æ¯ã®å å®¹ç¢ºèª cat /usr/lib/firewalld/services/ssh.xml # è¨å®ã
é害ãèµ·ããWebãµã¼ãã¹ã¯å人ã§éå¶ãã¦ãããµã¼ãã¹ã§ãã 2016å¹´2æãé害ãã20æ¥å¾ã«ãµã¼ãã¹åéãã¾ãããã¢ã¯ãã£ãã¦ã¼ã¶ã¯ä»¥åã®18%ã§ããæªã å復ã®ç®å¦ã¯ç«ã£ã¦ãã¾ãããåé·åãã¦ããªããµã¼ããã¦ã¤ã«ã¹ææãããã®å¾ã®å¯¾å¿ãå¾æå¾æã«åã£ã¦ãã¾ãã¾ããã 2016å¹´1ææ«ã«èµ·ããã¹ããã¦èµ·ãã£ãé害ã«ã¤ãã¦è¨äºã«ãã¦ã¿ã¾ããããè¿·æããæããã¦ãã¾ãæ¬å½ã«ç³ã訳ããã¾ããã â ã¦ã¼ã¶ã¯ãããæ»ã£ã¦ããªã ã©ããªã¦ã¤ã«ã¹ã«ææããã®ã SYNãã©ããæ»æï¼SYN Flood Attackï¼ãä»ã®Webãµã¤ãã«è¡ãã¦ã¤ã«ã¹ã«ææãã¦ã確èªãã¦ãã¾ãããä»ã®ãµã¼ãã¹ãSYNãã©ããæ»æãã¦ããã¨æãã¾ããã¾ãã¦ã¤ã«ã¹æææã«ãµã¼ãã®sshdãæ¸ãæãããsshã§æ¥ç¶ã§ããªããªãã¾ãããææå¾ã«ã³ã³ã½ã¼ã«ãã°ã¤ã³ãã¦æ¸ãæããããéã authorized_keys ãè¦ãæã¾ã
ãµã¼ãã¼ã¨ã³ã¸ãã¢ã®ã¹ãã«ã¢ããæ¥è¨ãµã¼ãã¨ã³ã¸ãã¢ãã¬ã³ã¿ã«ãµã¼ãã¼ã使ã£ã¦è©¦è¡é¯èª¤ããªããå種ãµã¼ãã¹ãåä½ãããã¹ãã«ã¢ããããæ¥ã ãèªãã¾ãã Piwikãã¤ã³ã¹ãã¼ã«ãã¦ä½¿ããããã«ãªãã¾ããããæ©è½ããããããã使ãæ¹ããããããã¾ãããã¾ãã¯ãPiwikã®ã¦ã¼ã¶ã¼ããã¥ã¢ã«ãè¦ã¦ã使ç¨æ¹æ³ã確èªãã¾ãã å ¬å¼ãµã¤ãã®ä¸è¨æ å ±ã確èªãã¦ãã¾ãã User GuideãâãPiwik Installation & OptimizationãâãOptimize & Secure PiwikâSetup a Secure Piwik server Use .htaccess to restrict access to a few files only, and restrict by IP address .htaccessã§ã¢ã¯ã»ã¹ã§ãããã¡ã¤ã«ãæ¥ç¶å IPãå¶é ã»Webãµã¼ã
ç®æ¬¡ 1. Matomo(Piwik) ãå®å ¨ã«ç¶æãããã³ã 2. Matomo(Piwik) ãããã§ãã·ã§ãã«ç®¡çè ã®ããã®ãã¹ããã©ã¯ãã£ã¹ä¸è¦§ Matomo(Piwik) ãã¼ã ã¯ãMatomo(Piwik) ã½ã¼ã¹ã³ã¼ãã確å®ã«å®å ¨ãªãã®ã«ãããããæåãå°½ããã¦ãã¾ãããã®ãããç§ãã¡ã¯ä»¥ä¸ã®ãã¨ãè¡ã£ã¦ãã¾ã: ã»ãã°ã®çºè¦ããç 究è ã¸ã®ç©æ¥µçãªå ±é ¬ããã°ã©ã ã»å¤é¨ã®ãããã§ãã·ã§ãã«ã»ãã¥ãªãã£ã¬ãã¥ã¼ã®å®æ½ããã³ãµãã¼ã ã»ã³ãããã§ã®ã³ã¼ãã¬ãã¥ã¼ã®å®æ½ ããããªããããããã®ã»ãã¥ãªãã£ã¹ãããã¯ãMatomo(Piwik) ã½ããã¦ã§ã¢ã«éå®ããã¦ãã¾ããMatomo(Piwik) ããã¦ã³ãã¼ããã¦ã¤ã³ã¹ãã¼ã«ããããããå¤ãã®å®å ¨ä¸ã®ãªã¹ã¯è¦å ã訪ããå¯è½æ§ãããã¾ããããã§ä»¥ä¸ãå¿ ãã確èªãã ããã Matomo(Piwik) ã®å®å ¨ãç¶æãããã³ã ãã¼
ä¸æ£ã¢ã¿ãã¯ãé²ãããã« è²ã ã¨èª¿ã¹ã¦ã¿ãçµæãä¸å®åæ°ä»¥ä¸ãã°ã¤ã³ã«å¤±æããIPãrootã§ç´æ¥ãã°ã¤ã³ãããã¨ããIPãã/etc/hosts.denyãã«ç»é²ï¼ãã©ãã¯ãªã¹ãã¿ãããªããã§ããªï¼ãã¦ã以éã®æ¥ç¶ãæå¦ããæ¹æ³ãçºè¦ãã¾ããã®ã§å®è¡ããã¨å ±ã«åå¿é²ã¨ãã¦ã DenyHostsã¨ã¯ ãã®ã½ãããä¸ã§æ¸ããã¨ããä¸æ£ã¢ã¿ãã¯ãä»æããã¨æããIPã¢ãã¬ã¹ããã©ãã¯ãªã¹ãã«ç»é²ãã¦æ¬¡å以éã·ã£ããã¢ã¦ãï¼ãã¦ãããå¿å¼·ããã®ã§ãã ä½åã®ã¢ã¿ãã¯å¤±æã§ãã©ãªç»é²ãããããä½åå¾ã«ãªã¹ãããåé¤ããªã©æè»ãªè¨å®ãå¯è½ãªããã§ãã®ã§æ©éã¤ã³ã¹ãã¼ã«ãã¦ã¿ã¾ãã ã¾ãã¯ã¤ã³ã¹ãã¼ã« # apt-get update # apt-get install denyhosts ããã§ãµã¯ã£ã¨ã¤ã³ã¹ãã¼ã«å®äºãç¶ãã¦è¨å®ãè¡ãã¾ãã è¨å®ãã¡ã¤ã«ã®ç·¨é è¨å®ãã¡ã¤ã«ã®ãã¹ã¯ã/etc/de
ä¾ãã°openSUSE 10.0ã§/var/log/messagesãè¦ãã¨æã Mar 26 22:01:32 linux sshd[18645]: Invalid user test12 from 65.205.238.12 Mar 26 22:01:34 linux sshd[18647]: Invalid user test12 from 65.205.238.12 Mar 26 22:01:35 linux sshd[18649]: Invalid user test12 from 65.205.238.12 Mar 26 22:01:37 linux sshd[18651]: Invalid user test12 from 65.205.238.12 Mar 26 22:01:38 linux sshd[18653]: Invalid user test12 from 65.
ConoHaã«ã¯åºç¤å´ã«ãã±ãããã£ã«ã¿ãåãã£ã¦ãããTCPãã¼ããã½ã¼ã¹IPã¢ãã¬ã¹ã«ãããã£ã«ã¿ãªã³ã°ãè¡ãã¾ããä»®æ³ãµã¼ãã¼ãæ¥ç¶ããã¦ããä»®æ³ã¹ã¤ããã§ãã£ã«ã¿ãªã³ã°ãããã®ã§ãOSã®è¨å®ã«ä¾åããªãç°¡æçãªãã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã®ããã«ä½¿ãã¾ããããã£ã«ã¿ãªã³ã°ã«ã¼ã«ããã»ãã¥ãªãã£ã°ã«ã¼ããã¨ããå½¢ã§ã¾ã¨ãã¦ãè¤æ°ãµã¼ãã¼ã«ã¾ã¨ãã¦é©ç¨ããããã§ããã®ã§å°æ°ãå¢ããã¨ãã®ç®¡çã楽ã§ãã ãã ãè¨å®ããã«ã¯ConoHaã®APIãå©ãå¿ è¦ãããã詳ããã¯ä¸è¨ã®ã¨ã³ããªãªã©ã§è§£èª¬ããã¦ãã¾ãã ConoHa APIã§ã»ãã¥ãªãã£ã°ã«ã¼ããè¨å®ãã https://blog.noldor.info/2015/11/conoha-api-security-group ConoHa API ãå©ãã¦ã¤ã³ãã©å´ã§ Firewall ãè¨å® - ConoHa 㧠KUSANAGI ãã®4 htt
ã¯ããã« Linux ã®ã»ãã¥ãªãã£è¨å®ã£ã¦ãªããªãã¾ã¨ã¾ã£ããã®ããªãã®ã§ãããããªãµã¤ããåèã«ããªããè¨å®ãã¾ã¨ãã¦ã¿ã¾ãããæ³å®ã¯Web ãµã¼ãã¼ã§ã使ç¨ãã¦ãã Linux 㯠CentOS 6.2 ã§ãã è¨å®å 容ã¯ä»¥ä¸ã®ããã«ãªãã¾ãã å ¨ããã±ã¼ã¸ã®ã¢ãããã¼ã ãªã¢ã¼ãããã® root ãã°ã¤ã³ãç¡å¹ã«ãã å ¬ééµæå·æ¹å¼ã使ç¨ãã SSH ãã°ã¤ã³è¨å® iptables è¨å® SSH ãã¼ãçªå·ã®å¤æ´ ä¸è¦ãªãµã¼ãã¹ãåæ¢ ãã°ç£è¦è¨å® ãã¡ã¤ã«æ¹ããæ¤ç¥ãã¼ã«è¨å® ã¦ã£ã«ã¹å¯¾çã½ããè¨å® Apache ã®è¨å® å ¨ããã±ã¼ã¸ã®ã¢ãããã¼ã æåã«ä»¥ä¸ã®ã³ãã³ããå®è¡ãã¦ãå ¨ããã±ã¼ã¸ãææ°ã®ç¶æ ã«ããã # yum ây update å¾ã¯èå¼±æ§ãçºè¦ãããæãã¾ãã¯å®æçã«ããã±ã¼ã¸ã®ã¢ãããã¼ããè¡ãã ãªã¢ã¼ãããã® root ãã°ã¤ã³ãç¡å¹ã«ãã ãªã¢ã¼ãããã¡
Web ãµã¤ãã常æ SSL åããå ´åã«ãæä½éç¥ã£ã¦ãããªããã°ãªããªãç¥èãã注æç¹ãå®éã®è¨å®æ¹æ³ã¾ã§ãã²ã¨éãã¾ã¨ãã¦ã¿ã¾ãããã¡ãªããããã¡ãªããã証ææ¸ã®ç¨®å¥ãããªãã¤ã¬ã¯ãè¨å®ãªã©ã«ã¤ãã¦ã解説ãã¦ãã¾ãã HTTPS ãã©ã³ãã³ã°ã·ã°ãã«ã«ä½¿ç¨ãã¾ã㨠Google ãå ¬å¼ã«çºè¡¨ããããããããWeb ãµã¤ãã® SSL 対å¿ãç¹ã« Google ãæ¨å¥¨ãã¦ãã Web ãµã¤ãããã¹ã¦ HTTPS ã§é ä¿¡ãããæè¬ ã常æ SSL åã ã«ã¤ãã¦ã®è©±ãèããããå®éã«ã客æ§ããç¸è«ããããããã±ã¼ã¹ãå¢ãã¦ãã¾ããã ããã§ãããæ©ä¼ã ããã®è¾ºã«é¢ããæ å ±ãã¾ã¨ãã¦ãããããªï½ ã¨æã£ã¦æ¸ãã¦ã¿ããæä¾ã® ï¼ï¼ï¼ 5åã§ãããã·ãªã¼ãºãæ¸ãçµãã£ã¦è¦ãã¨ãã絶対㫠5åããç¡çã£ã¦ããæç« éã«ãªã£ã¦ã¦ã©ããããããªãã¨ãæã£ããã§ãããæ°ã«ããå ¬éãã¦ã¿ã¾ãã 常æ SSL
index.html 以å¤ãããã©ã«ããã¡ã¤ã«ã«ããã«ã¯ é常ãã¹ã©ãã·ã¥(/) ã§çµããã¢ã¯ã»ã¹ããã£ãã¨ãã¯ãindex.html ãã¡ã¤ã«ã代æ¿ãã¦å¼ã°ãã¾ãããDirectoryIndex ãè¨å®ãããã¨ã§ index.html 以å¤ã®ãã¡ã¤ã«ãå¼ã³åºããã¨ãã§ãã¾ãã DirectoryIndex index.cgi index.html index.shtml top.htm ã¹ã©ãã·ã¥(/) ã§çµããã¢ã¯ã»ã¹ããã£ãã¨ãããµã¼ã㯠DirectoryIndex ã§è¨è¿°ããã¦ãããã¡ã¤ã«ãé ã«æ¢ãã¦ãããè¦ã¤ããã°ãã®ãã¡ã¤ã«ã表示ãã¾ãã ãã£ã¬ã¯ããªã®ãã¡ã¤ã«ä¸è¦§è¡¨ç¤ºãä¸æ¢ããã«ã¯ é常ãã¹ã©ãã·ã¥(/) ã§çµããã¢ã¯ã»ã¹ããã£ãã¨ãã«ãindex.html ãã¡ã¤ã«ã代æ¿ãã¦å¼ã°ãã¾ãããindex.html ãã¡ã¤ã«ãè¦ã¤ãããªãå ´åã«ã次ã®ãããªãã£ã¬ã¯ããªã®ãã¡ã¤ã«
çéã§ã»ããã¢ãããå®äºããããã極åã³ããã§è¨å®ã§ããããã«ãã¦ã¿ããï¼ã»âã»ï¼ åä½æ¤è¨¼ã¯ããããã®VPSã§æ¨æºOSãã¤ã³ã¹ãã¼ã«ãã¦è¡ã£ããè¨äºå·çæç¹ã§ã¯CentOS6.6ãã¤ã³ã¹ãã¼ã«ããããã # cat /etc/issue CentOS release 6.6 (Final) # uname -rs Linux 2.6.32-504.3.3.el6.x86_64 ãç¥ãã æ¬è¨äºã®å 容ãFabricåããã¹ã¯ãªãããå ¬éï¼ãã²è©¦ãã¦ã¿ã¦ãã â è¶ éã§CentOS6.6ï¼ãããã®VPSï¼ãã»ããã¢ãããã俺å²ä¸æå¼·ã®Fabricã¹ã¯ãªãããããã rootã®ãã¹ã¯ã¼ãå¤æ´ã¨ä½æ¥ç¨ã¦ã¼ã¶ã®ä½æ ã¾ãã¯ãã³ã³ã½ã¼ã«ããSSHã§æ¥ç¶ãããã [localhost ~]$ ssh [email protected] ãªãããµã¼ããèµ·åãã¦ãªãå ´åã¯ãäºåã«ç®¡çç»é¢ãããµã¼ããèµ·åãã
10. ã»ãã¥ãªãã£å¯¾çã®éè¦æ§ ã·ã¹ãã ã®ãã°ã¤ã³èªè¨¼ãã° /var/log/secure 15:12:12 sshd[27259]: Failed password for bin from 69.94.125.45 port 35312 ssh2 15:12:12 sshd[27259]: Received disconnect from 69.94.125.45: 11: Bye Bye [preauth] 15:12:13 sshd[27266]: reverse mapping checking getaddrinfo for nyfishpix.nyfishpix.com [69.94.125.45] failed - POSSIBLE BREAK-IN ATTEMPT! 15:12:13 sshd[27266]: pam_unix(sshd:auth): authentic
ãããã®VPSãããServersMan@VPS ããã®åºç¾ã§ããããã¨æ·å± ã®ããã£ãæã®ãã VPS ã ããè¨ããã®ãµã¼ãããçµVPSã§éç¨ããã¦ãããã§ãããVPSãæ¢åã®ã¬ã³ãµãæè¦ã§ä½¿ã£ã¦ã人ã«ããã¦ãããããã®ã»ãã¥ãªãã£è¨å®ã¯ãã£ã¦ãããã»ããè¯ããã£ã¦ããã話ã§ãã ä»åã対象ã«ãã OS 㯠CentOS ã§ãã ãããVPS åã㦠Ubuntu ã¨ããå¥ã® OS ã§éç¨ãããããªä¸ä¸ç´è ã¯èªåã§ã§ããããã ãªã¢ã¼ãããã® root ãã°ã¤ã³ãç¡å¹ã«ãã ssh çµç±ã§ root ã§ãã°ã¤ã³ãã¦ä½æ¥ããããã¦ã¾ãããï¼ ãã root ãã¹ã¯ã¼ããç ´ããããããµã¼ããä¹ã£åããã¡ããã®ã§ã大å¤ã«å±éºã§ãã root ãã°ã¤ã³ãç¡å¹ã«ãã¦ã権éã®ããã¦ã¼ã¶ã§ãã°ã¤ã³ãã¦ãã sudo or su ãã¦ä½æ¥ããããã«ãã¾ãããã root ãã°ã¤ã³ãç¡å¹ã«ããæ¹æ³ã¯ããã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}