å¾ã
ã«å¾©æ´»æ°å³ã ãã
å¹´æ«å¹´å§ãããmod_securityã«ã¤ãã¦èª¿ã¹ã¦ã¿ãã§ãããã¨ããããããã¥ã¢ã«é¢¨ã¡ã¢ä½æããã®ã§åèã¾ã§ã«è¼ãã¦ããã¾ããももいさんとこã«ã¯ãä¸è©±ã«ãªãã¾ããm(_ _)m
CentOS5.1ã§mod_securityã®2.xãã¤ã³ã¹ãã¼ã«ããæãåææ¡ä»¶ã¨ãªãã®ã¯ä»¥ä¸ã§ãã
- apacheã«mod_unique_idã¨ããã¢ã¸ã¥ã¼ã«ãçµã¿è¾¼ã¾ãã¦ãããã¨
- OSã«libxml2ã¨ããã©ã¤ãã©ãªãã¤ã³ã¹ãã¼ã«ããã¦ãããã¨
- ãã¼ã¸ã§ã³ãããã³ã°
apacheã®ãã¼ã¸ã§ã³ mod_securityã®ãã¼ã¸ã§ã³ 1.3.* 1.9.*ä»¥ä¸ 2ä»¥ä¸ 2.*
ããã§ã¯apache2.*ã«mod_securityã®2.*ãçµã¿è¾¼ãæé ã«ã¤ãã¦èª¬æãã¾ãã
apacheã«mod_unique_idãçµã¿è¾¼ãã«ã¯ãã½ã¼ã¹ããã³ã³ãã¤ã«ããå¿
è¦ãããã¾ããã½ã¼ã¹ã¯www.apache.orgãªã©ã§å
¥æãã¾ãã
ã½ã¼ã¹ã解åãããã£ã¬ã¯ããªã§ã
# ./configure --enable-unique-id
ã¨å ¥åãããã¨ã¯makeããã³make installãå®æ½ãã¾ãããªãããã£ã¬ã¯ããªãã¬ãã£ãã¯ã¹ãæå®ããã«configureã¹ã¯ãªãããå®è¡ããããã¤ã³ã¹ãã¼ã«å ã¯/usr/local/apache2ã¨ãªãã¾ãã
ã¾ããapacheã«çµã¿è¾¼ã¾ãã¦ããã¢ã¸ã¥ã¼ã«ã確èªããã«ã¯ã
# httpd -l
ã¨å ¥åãã¾ãã
mod_securityãã³ã³ãã¤ã«ããéãlibxml2ã®ã¤ã³ã¯ã«ã¼ãï¼ãããï¼ãã¡ã¤ã«ãåç
§ããå¿
è¦ãããã¾ãããããé常includeãã¡ã¤ã«ãç½®ããã¦ãããã£ã¬ã¯ããªï¼/usr/includeã/usr/local/includeãªã©ï¼ã«xml2é¢é£ã®ãã¡ã¤ã«ãè¦ããããªããªãã°ãlibxml2ï¼http://xmlsoft.org/ï¼ã®ã½ã¼ã¹ãå
¥æãã解åãã¾ãã
ãã®å¾ãmod_securityã解åãããã£ã¬ã¯ããªä¸ã«apache2ã¨ãããã£ã¬ã¯ããªãåå¨ãã¾ããããã®ä¸ã«ããMakefileã®ã
INCLUDES = -I /usr/include/libxml2
ã¨ããè¡ã
INCLUDES = -I /root/software/libxml2-2.6.30/include
ãªã©ãå®éã«ã¤ã³ã¯ã«ã¼ããã¡ã¤ã«ã解åããã¦ç½®ããã¦ãããã£ã¬ã¯ããªã«å¤æ´ããmakeãã¾ãï¼ãã¼ã¸ã§ã³ã¯2008å¹´1æç¾å¨ï¼ã
åç
§ãå¿
è¦ãªãã¡ã¤ã«ã¯ä»¥ä¸ã®ã¨ããã§ãã
msc_xml.h:#includemsc_xml.h:#include re_variables.c:#include "libxml/xpathInternals.h"
ã¤ã³ã¯ã«ã¼ããã¡ã¤ã«ã¯åç §ããã ããªã®ã§ãlibxml2ããã§ã«ã¤ã³ã¹ãã¼ã«ããã¦ããã®ã§ããã°ãæ¹ãã¦ã¤ã³ã¹ãã¼ã«ãç´ãå¿ è¦ã¯ããã¾ãããï¼ãã¼ã¸ã§ã³ãå¤å°ç°ãªã£ã¦ãããã®ã¾ã¾ä½¿ç¨ã§ãã¾ããï¼
make installã¾ã§çµãã£ãããapacheã®httpd.confã«ä»¥ä¸ã®è¡ã追å ãã¾ãã
LoadFile /usr/lib/libxml2.so.2ã*1 LoadModule security2_module modules/mod_security2.soã*2
以ä¸ã®æµãã¯ãapacheãmod_securityã追å ã§ã¤ã³ã¹ãã¼ã«ããå ´åã®ãã®ã§ããapacheã«ã¢ã¸ã¥ã¼ã«ã追å ããå¿ è¦ãããããã½ã¼ã¹ããã¤ã³ã¹ãã¼ã«ãè¡ã£ã¦ãã¾ãããOSã¤ã³ã¹ãã¼ã«æãªã©ã«apacheãå°å ¥ããã¨ãã¤ã³ã¹ãã¼ã«ããããã£ã¬ã¯ããªã/usr/sbinã/etc/httpdã«ãªããªã©ãã½ã¼ã¹ãããã¬ãã£ãã¯ã¹æå®ç¡ãã§å ¥ããå ´åï¼/usr/local/apache2ï¼ã¨ç°ãªãã¾ããapacheç°å¢ã«ãã£ã¦mod_securityãã¤ã³ã¹ãã¼ã«ãããã£ã¬ã¯ããªãå¤æ´ããå ´åãç´æ¥apache2/Makefileå ã®top_dirå¤æ°ã®æå®å¤ãç·¨éã»å¤æ´ãã¦ãã ããã
*1:æ°ãã«libxml2ãã¤ã³ã¹ãã¼ã«ããå ´åã«ã¯ãä¾ãã°/usr/local/lib/libxml2.soãªã©ã¨æå®ãã¾ã
*2:apacheã®ã¤ã³ã¹ãã¼ã«ãã£ã¬ã¯ããªä¸ãmodulesãã£ã¬ã¯ããªã®ä¸ã«ã¢ã¸ã¥ã¼ã«ãåå¨ãããã¨ãåæã§ã