APACHE º¸¾È
1. À¥¹®¼µð·ºÅ丮(DocumentRoot)¿¡¼ ºÒÇÊ¿äÇÑ ¹®¼ Á¦°Å
¼Ò½º·Î ¾ÆÆÄÄ¡¸¦ ¼³Ä¡ÇÏ°Ô µÇ¸é ±âº» À¥ ¹®¼°¡ À§Ä¡ÇÏ´Â µð·ºÅ丮°¡ /usr/local/apache/htdocsÀÔ´Ï´Ù. htdocs µð·ºÅ丮¿¡´Â ¾ÆÆÄÄ¡ °ü·ÃÁ¤º¸°¡ µé¾îÀÖ´Â ¹®¼¿Í °ø°³µÉ ÇÊ¿ä°¡ ¾ø´Â ¹®¼°¡ À§Ä¡ÇÏ°í ÀÖ½À´Ï´Ù. ÀÌ ¹®¼µéÀ» Á¦°ÅÇÕ´Ï´Ù.
httpd.conf Áö½ÃÀÚ
DocumentRoot "/usr/local/apache/htdocs"
¸í·É¾î
¨ç [root@nextline ~]# cd /usr/local/apache/htdocs/
DocumentRoot µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.
¨è [root@nextline htdocs]# rm -rf *
rm ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© /usr/local/apache/htdocs/ ÇÏÀ§ÀÇ ¸ðµç ¹®¼¸¦ Á¦°ÅÇÕ´Ï´Ù.
¶Ç ´Ù¸¥ ¹æ¹ýÀ¸·Î´Â httpd.conf¿¡¼ DocumentRoot°ªÀ» »õ·Î¿î °æ·Î·Î ÁöÁ¤ÇÕ´Ï´Ù.
2. ºÒÇÊ¿äÇÑ CGI ½ºÅ©¸³Æ®Á¦°ÅÇϱâ
apache¸¦ ¼³Ä¡Çϸé cgi-bin µð·ºÅ丮¿¡ ±âº»À¸·Î CGI½ºÅ©¸³Æ®°¡ ¼³Ä¡µË´Ï´Ù. ÀÌ CGI ½ºÅ©¸³Æ®°¡ °ø°Ý¿¡ ÀÌ¿ëµÉ ¼öµµ Àֱ⠶§¹®¿¡ ¸ðµÎ Á¦°ÅÇϵµ·Ï ÇÕ´Ï´Ù. ƯÈ÷ Ãʱâ¹öÀüÀÎ °æ¿ì¿¡ php.cgiµîÀÌ Á¦°øµÇ¾ú´Âµ¥ ÇØÅ·ÀÇ ºô¹Ì¸¦ Á¦°øÇÏ¿´´Ù. cgi-bin µð·ºÅ丮¿¡ ÀÖ´Â ¸ðµç ÆÄÀÏÀ» Á¦°ÅÇÕ´Ï´Ù.
cgi-bin °æ·Î
/usr/local/apache/cgi-bin
¸í·É¾î
¨ç [root@nextline ~]# cd /usr/local/apache/cgi-bin
DocumentRoot µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.
¨è [root@nextline htdocs]# rm -rf *
rm ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© /usr/local/apache/cgi-bin ÇÏÀ§ÀÇ ¸ðµç ¹®¼¸¦ Á¦°ÅÇÕ´Ï´Ù.
3. DocumentRoot, »ç¿ëÀÚ È¨µð·ºÅ丮(/home)¿¡ ¼³Á¤ÇÏ´Â µð·ºÅ丮 ¿É¼Ç ¼³Á¤Çϱâ
±âº»ÀûÀÎ ¼³Á¤À» ¸ðµÎ Á¦°ÅÇÏ°í º¸¾È°ú °ü·ÃÀÖ´Â Ç׸ñ¸¸ ¿É¼ÇÀ¸·Î ÁöÁ¤ÇÕ´Ï´Ù.
httpd.conf Áö½ÃÀÚ
/usr/local/apache/htdocs/">
Options Indexes FollowSymLinks ExecCGI
AllowOverride All
Order allow,deny
Allow from all
Options Includes FollowSymLinks ExecCGI
AllowOverride All
Order allow,deny
Allow from all
/usr/local/apache/htdocs/">
tag¿¡ ÀÇÇÏ¿© °¢ directory¸¶´Ù ÀûÀýÇÏ°Ô permissionÀ» °É ¼ö°¡ ÀÖ½À´Ï´Ù.
¨ç Options Indexes FollowSymLinks ExecCGI
None
¾î¶² ¿É¼Çµµ ÀÌ¿ëÇÒ ¼ö ¾ø½À´Ï´Ù.
All
ÁöÁ¤ÇÑ directory¿¡¼ ¸ðµç ¸í·ÉÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
Indexes
URL¿¡ ÁöÁ¤µÈ µð·ºÅ丮¿¡ (index.html °°Àº) ÁöÁ¤µÈ ÆÄÀÏÀÌ ¾øÀ» °æ¿ì µð·ºÅ丮ÀÇ ÆÄÀÏ ¸ñ·ÏÀ» º¸¿©ÁÖ´Â ¿É¼ÇÀÔ´Ï´Ù.
Includes
¼¹öÃøÀÇ Ãß°¡ÀûÀÎ Á¤º¸¸¦ Á¦°øÇÒ ¼ö ÀÖ°Ô ÇÕ´Ï´Ù.
IncludesNoExec
¼¹öÃøÀÇ Ãß°¡ÀûÀÎ Á¤º¸¸¦ Á¦°øÇÒ ¼ö ÀÖ°Ô ÇÏÁö¸¸, ¾î¶°ÇÑ ½ÇÇà ÆÄÀÏÀ» ½ÇÇàÇÏ´Â °ÍÀ» ¹æÁöÇÕ´Ï´Ù.
FollowSymLinks
µð·ºÅ丮»óÀÇ ½Éº¼¸¯ ¸µÅ©¸¦ »ç¿ë °¡´ÉÇÏ°Ô ÇÕ´Ï´Ù.
ExecCGI
CGI ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇÕ´Ï´Ù.
MultiViews
All ¿É¼ÇÀÌ ¼³Á¤µÇ¾úÀ» ¶§¸¸ ÁöÁ¤µÈ ¸ñ·ÏÀÇ multiviews¸¦ Çã¿ëÇÕ´Ï´Ù.
¨è AllowOverride All
.htaccessÆÄÀÏÀº ¼¹öÀÇ °¢ µð·ºÅ丮¿¡ ¸¸µé¾î¼ °¢ µð·ºÅ丮¿¡ ´ëÇÑ Á¢±ÙÀ» Á¦¾îÇϱâ À§ÇÑ °ÍÀ¸·Î µð·ºÅ丮¿¡ .htaccessÆÄÀÏÀÌ ÀÖÀ¸¸é, ¼¹ö Àüü¿¡ ÀÛ¿ëÇÏ´Â access.conf º¸´Ù ¿ì¼±±ÇÀ» °¡Áý´Ï´Ù. .htaccessÆÄÀÏ¿¡ ´ëÇÑ Override¿¡ ´ëÇÑ ¿É¼ÇÀÔ´Ï´Ù.
None
.htaccessÆÄÀÏÀ» ÀÐÀ» ¼ö ¾ø°Ô ÇÕ´Ï´Ù.
All
¸ðµç ÁöÁ¤¿¡ ´ëÇØ °¡´ÉÇÏ°Ô ÇÕ´Ï´Ù.
Options
±ÔÁ¤µÈ µð·ºÅ丮 Çü½ÄÀ» ÄÜÆ®·ÑÇÏ´Â ÁöÁ¤ÀÇ »ç¿ëÀ» Çã¶ôÇÕ´Ï´Ù.
FileInfo
¹®¼Çü½ÄÀ» ÄÜÆ®·ÑÇÏ´Â ÁöÁ¤ÀÇ »ç¿ëÀ» Çã¿ëÇÕ´Ï´Ù.
AuthConfig
»ç¿ëÀÚ ÀÎÁõ ÁöÁ¤ÀÇ »ç¿ëÀ» Çã¿ëÇÕ´Ï´Ù. »ç¿ëÀÚ ÀÎÁõ º¯¼ö¸¦ »ç¿ëÇÕ´Ï´Ù.
Limit
È£½ºÆ® Á¢±ÙÀ» ÄÜÆ®·ÑÇÏ´Â ÁöÁ¤À» Çã¿ëÇÕ´Ï´Ù.
¨é Order
Limit¿¡ °ü·ÃµÈ ºÎºÐÀ» ¼³Á¤À» ÇÕ´Ï´Ù. ¼¹ö°¡ access controlÀ» ¼öÇàÇÏ´Â ¼ø¼¸¦ ³ªÅ¸³À´Ï´Ù. ¿©±â¼´Â allow±â´ÉÀ» ¸ÕÀú ¼öÇàÇÏ°í, deny±â´ÉÀ» ¼öÇàÇ϶ó´Â °ÍÀÔ´Ï´Ù.
deny, allow
deny Áö½ÃÀÚ ºÎÅÍ °Ë»çÇÏ°í allow Áö½ÃÀÚ¸¦ °Ë»ç ÇÕ´Ï´Ù.
allow, deny
allow Áö½ÃÀÚ ºÎÅÍ °Ë»çÇÏ°í deny Áö½ÃÀÚ¸¦ °Ë»ç ÇÕ´Ï´Ù.
mutual-failure
allow¸ñ·Ï¿¡ ¾ø´Â ¸ðµç host¿¡°Ô Á¢¼ÓÀ» °ÅºÎ ÇÕ´Ï´Ù.
allow from
³ª¿µÇ´Â Áּҵ鿡 ´ëÇÑ access controlÀ» °¡´ÉÇÏ°Ô ÇÕ´Ï´Ù. »ç¿ë °¡´ÉÇÑ ÁÖ¼Ò´Â µµ¸ÞÀÎ ³×ÀÓ, È£½ºÆ® À̸§ ÁÖ¼Ò, È£½ºÆ® ip ÁÖ¼Ò, ip ÁÖ¼ÒÀÇ ¾ÕºÎºÐ 3¹ÙÀÌÆ®, ¸ðµç ÁÖ¼Ò¿¡ ÇØ´çÇÏ´Â all ÀÌ ÀÖ½À´Ï´Ù.
deny from
allow from°ú ¹Ý´ëµÇ´Â °³³äÀ̸ç, »ç¿ë°¡´ÉÇÑ ÁÖ¼Ò´Â allow from°ú °°´Ù.
Require
»ç¿ëÀÚ, ±×·ì¿¡ ´ëÇÑ Á¢±ÙÀ» ÅëÁ¦ÇÒ ¼ö ÀÖ½À´Ï´Ù.
»ç¿ë¹æ¹ý : require entity en1 en2 ... enn
entity¿¡ µé¾î°¥ ¼ö ÀÖ´Â °ÍÀº user, group, valid-userÀÇ ¼¼°¡ÁöÀÌ´Ù.
User
ÁöÁ¤µÈ »ç¿ëÀڵ鿡°Ô¸¸ Á¢±ÙÀ» Çã¿ëÇÏ´Â °ÍÀ¸·Î, ÁöÁ¤µÈ »ç¿ëÀÚ¿¡ ´ëÇÑ Á¤º¸´Â AuthUserFile¿¡¼ ÁöÁ¤ÇÑ ÆÄÀÏ¿¡ ÀÖ½À´Ï´Ù.
Group
ÁöÁ¤µÈ ±×·ì¿¡°Ô¸¸ Á¢±ÙÀ» Çã¿ëÇÏ´Â °ÍÀ¸·Î, ÁöÁ¤µÈ ±×·ì¿¡ ´ëÇÑ Á¤º¸´Â
AuthGroupFile¿¡¼ ÁöÁ¤ÇÑ ÆÄÀÏ¿¡ ÀÖ½À´Ï´Ù.
valid-user
AuthUserFile¿¡ ÀÖ´Â ¸ðµç »ç¿ëÀÚ¿¡ ´ëÇØ Á¢±ÙÀ» Çã¿ëÇÕ´Ï´Ù.
4. ~ ÅÂ±× ÀÌ¿ëÇϱâ
ű״ °¢ µð·ºÅ丮º°·Î HTTP MethodÀÇ »ç¿ë¿©ºÎ¸¦ ÅëÁ¦Çϴ ű×ÀÔ´Ï´Ù. ÆÄÀÏÀÇ ¾÷·Îµå ¹× ÆÄÀÏÀÇ ¼öÁ¤, »èÁ¦¸¦ À§Çؼ »ç¿ëµÇ´Â HTTP Method´Â PUT°ú POST, DELETE °¡ Àִµ¥ ÀÌ Method¸¦ Á¦ÇÑÇÕ´Ï´Ù.
httpd.conf Áö½ÃÀÚ
Require valid-user
°³ÀÎ »ç¿ëÀÚ È¨µð·ºÅ丮¿¡¼ POST, PUT, DELETE Method¸¦ Æнº¿öµå ÆÄÀÏ¿¡ µî·ÏµÈ »ç¿ëÀÚ¸¸ÀÌ ÀÌ¿ë°¡´ÉÇϵµ·Ï Á¦ÇÑÇÑ °ÍÀÔ´Ï´Ù.
5. Çì´õ Á¤º¸ ¼û±â±â
Ŭ¶óÀ̾ðÆ®°¡ Apache À¥¼¹ö¿¡ Á¢¼ÓÇßÀ» ¶§ À¥¼¹ö¿¡¼´Â ÀÀ´ä ¸Þ½ÃÁöÀÇ Çì´õ¿¡ À¥¼¹ö ¹öÀü, ¼³Ä¡µÈ ÀÀ¿ëÇÁ·Î±×·¥ µî°ú °°Àº Á¤º¸¸¦ Àü´ÞÇÕ´Ï´Ù.
¨ç Çì´õ Á¤º¸ È®ÀÎÇϱâ
[root@nextline ~]# telnet xxx.xxx.xxx.xxx 80
Trying xxx.xxx.xxx.xxx...
Connected to xxx.xxx.xxx.xxx.
Escape character is '^]'.
GET / HTTP/1.1
HTTP/1.1 400 Bad Request
Date: Sat, 14 Dec 2002 14:24:11 GMT
Server: Apache/1.3.26 (Unix) PHP/4.2.2
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html; charset=iso-8859-1
ÀÌ Á¤º¸´Â °ø°ÝÀÚ¿¡ ÀÇÇØ Apache À¥¼¹ö ¹öÀü°ú ±¸µ¿µÇ°í ÀÖ´Â ÀÀ¿ëÇÁ·Î±×·¥ÀÇ ¹öÀüÀ» È®ÀÎÇÏ°í ¾Ë·ÁÁø Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÇϴµ¥ À¯¿ëÇÏ°Ô ÀÌ¿ëµÉ ¼ö ÀÖ½À´Ï´Ù.
¨è Çì´õ Á¤º¸ ¼û±â±â
Apache À¥¼¹ö¿¡¼´Â "ServerTokens"Áö½ÃÀÚ¸¦ ¼öÁ¤ÇÔÀ¸·Î½á Çì´õ¿¡ ÀÇÇØ Àü¼ÛµÇ´Â Á¤º¸¸¦ ¹Ù²Ü ¼ö ÀÖ½À´Ï´Ù.
httpd.conf Áö½ÃÀÚ
ServerTokens Å°¿öµå
¨é Å°¿öµå¿Í Á¦°øµÇ´Â Á¤º¸
Prod[ductOnly]
À¥¼¹ö Á¾·ù¸¸ Ç¥±âµË´Ï´Ù. ¿¹) Server:Apache
Min[imal]
Prod Å°¿öµå Á¦°øÁ¤º¸ + À¥¼¹ö ¹öÀü ¿¹) Server:Apache/1.3.26
OS
Min Å°¿öµå Á¦°ø Á¤º¸ + ¿î¿µÃ¼Á¦ ¿¹) Server:Apache/1.3.26 (Unix)
Full
OS Å°¿öµå Á¦°øÁ¤º¸ + ¼³Ä¡µÈ ¸ðµâ(ÀÀ¿ëÇÁ·Î±×·¥) Á¤º¸
¿¹) Server: Apache/1.3.26 (Unix) PHP/4.2.2
Âü°í: ServerTokenÀº apache 1.3À̻󿡼 °¡´ÉÇÏ°í ProductOnlyÅ°¿öµå´Â 1.3.12¹öÀü À̻󿡼¸¸ »ç¿ë°¡´ÉÇÏ´Ù. ÀϹÝÀûÀ¸·Î ServerTokensÀº httpd.conf¿¡ ¸í½ÃµÇ¾î ÀÖÁö ¾Ê´Â °æ¿ì°¡ ¸¹´Ù. ÀÌ·± °æ¿ì¿¡´Â ±âº»°ªÀÎ "ServerTokens Full"ÀÌ Àû¿ëµÇ¾î ¸ðµç Á¤º¸°¡ ÀÀ´ä Çì´õ¿¡ Æ÷ÇԵǾî Ŭ¶óÀ̾ðÆ®¿¡°Ô Àü¼ÛµË´Ï´Ù. ÃÖ¼ÒÇÑÀÇ Á¤º¸¸¦ ÁÖ±â À§Çؼ´Â "ServerTokens Prod"°¡ ÁÁ½À´Ï´Ù.
6. ±âº» »ç¿ëÀÚ ÀÎÁõ ¼³Á¤
±âº» »ç¿ëÀÚ ÀÎÁõ°ú ´ÙÀÌÁ¦½ºÆ® »ç¿ëÀÚ ÀÎÁõÀÇ ¼³Á¤ ¹æ¹ýÀº ¸Å¿ì À¯»çÇÏ´Ù. ´ÙÀ½°ú °°ÀÌ µÎ°¡Áö ÀýÂ÷¸¦ °ÅÃÄ ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.
* Æнº¿öµå ÆÄÀÏ »ý¼º
* Æнº¿öµå ÆÄÀÏÀ» »ç¿ëÇÒ ¼ö ÀÖµµ·Ï Apache ȯ°æ ¼³Á¤
¨ç Æнº¿öµå ÆÄÀÏ»ý¼º
[root@nextline ~]# cd /usr/local/apache/bin/
¾ÆÆÄÄ¡ bin µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.
[root@nextline ~]# ./htpasswd -c /usr/local/apache/password nextline
New password: (Æнº¿öµåÀÔ·Â)
Re-type new password: (Æнº¿öµåÀÔ·Â)
Æнº¿öµå ÆÄÀÏÀ» óÀ½ »ý¼ºÇÒ °æ¿ì¿¡´Â -c ¿É¼ÇÀ» »ç¿ëÇÏ¿© ¸¸µì´Ï´Ù.
[root@www /usr/local/apache/bin]# ./htpasswd /usr/local/apache/password nextline2
New password: (Æнº¿öµåÀÔ·Â)
Re-type new password: (Æнº¿öµåÀÔ·Â)
»ç¿ëÀÚ¸¦ Ãß°¡ÇÒ °æ¿ì¿¡´Â -c ¿É¼ÇÀ» »©°í »ç¿ëÇÏ¸é µË´Ï´Ù. ¸¸¾à -c ¿É¼ÇÀ» »ç¿ëÇÒ °æ¿ì¿¡´Â ±âÁ¸ÀÇ µîµ¶µÈ »ç¿ëÀÚµéÀº Áö¿öÁö¹Ç·Î ÁÖÀÇÇØ¾ß ÇÕ´Ï´Ù.
[root@www /usr/local/apache/bin]# cat ../password
nextline:LT30X3txYYEuY
nextline2:/RfZRDXV1N/Eo
Æнº¿öµå ÆÄÀÏÀ» È®ÀÎÇغ¸¸é »ç¿ëÀÚID¿Í Æнº¿öµå Çʵå·Î ±¸¼ºµÇ¾î Àִµ¥, Æнº¿öµå Çʵå´Â ¾ÏȣȵǾî ÀúÀåµË´Ï´Ù. ¶ÇÇÑ µÎ »ç¿ëÀÚ°¡ ¾ÏÈ£¸¦ µ¿ÀÏÇÏ°Ô ÀÔ·ÂÇصµ ¾ÏÈ£ÈµÈ °ª Àº ´Ù¸£°Ô ³ªÅ¸³³´Ï´Ù.
¨è Æнº¿öµå ÆÄÀÏÀ» »ç¿ë°¡´ÉÇϱâ À§ÇÑ È¯°æ¼³Á¤
httpd.confÆÄÀϳ»¿¡¼ µð·ºÅ丮º°·Î »ç¿ëÀÚ ÀÎÁõÀ» Çϱâ À§ÇÑ ¼³Á¤À» ÇÏ¸é µË´Ï´Ù.
httpd.conf Áö½ÃÀÚ
AllowOverride AuthConfig
»ç¿ëÀÚ ÀÎÁõÀÌ ÇÊ¿äÇÑ µð·ºÅ丮¿¡ ¾Æ·¡ÀÇ Áö½ÃÀÚµéÀÌ Æ÷ÇÔµÈ .htaccessÆÄÀÏÀ» »ý¼º ÇÕ´Ï´Ù.
Áö½ÃÀÚ
AuthType
ÀÎÁõÇüÅÂ(Basic ¶Ç´Â Digest)
AuthName
ÀÎÁõ¿µ¿ª(À¥ºê¶ó¿ìÀúÀÇ ÀÎÁõâ¿¡ Ç¥½ÃµÊ)
AuthUserFile
»ç¿ëÀÚ Æнº¿öµå ÆÄÀÏÀÇ À§Ä¡
AuthGroupFile
±×·ì ÆÄÀÏÀÇ À§Ä¡(¿É¼Ç)
Require
Á¢±ÙÀ» Çã¿ëÇÒ »ç¿ëÀÚ ¶Ç´Â ±×·ìÁ¤ÀÇ
¿¹¹®
¾ÕÀÇ Æнº¿öµå ÆÄÀÏ¿¡ µî·ÏµÈ nextline, nextline2¶ó´Â »ç¿ëÀÚ¸¸À» Á¤ÇØÁø µð·ºÅ丮¿¡ Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï ¼³Á¤Çغ¸ÀÚ.
[nextline@nextline ~]$ cat .htaccess
AuthType Basic
AuthName "Welcome nextline's Home
AuthUserFile /usr/local/apache/password
Require user nextline nextline // ¸¸¾à Æнº¿öµåÆÄÀÏ¿¡ µî·ÏµÈ ¸ðµç »ç¿ëÀÚ¸¦ Á¢±Ù°¡´ÉÇϵµ·Ï ¼³Á¤ÇÏ·Á¸é Require valid-user ¶ó°í ÇÏ¸é µË´Ï´Ù.
°ü·Ã¸í·É¾î
htpasswd
¾ÆÆÄÄ¡ »ç¿ëÀÚ ÀÎÁõÀ» À§ÇÑ ÆÄÀÏÀ» »ý¼ºÇϰųª ¾÷µ¥ÀÌÆ®¸¦ ÇÏ´Â ¸í·ÉÀÔ´Ï´Ù.
»ç¿ë¹ý
htpasswd [options] password_file username
options
-c
»õ·Î¿î Æнº¿öµå ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù.
[nextline@nextline ~]$ htpasswd -c /usr/local/apache/password nextline
password¶ó´Â ÆÄÀÏÀ» »ý¼ºÇÏ¸é¼ nextlineÀ̶ó´Â »ç¿ëÀÚ¸¦ µî·ÏÇÕ´Ï´Ù.
[nextline@nextline ~]$ htpasswd /usr/local/apache/password nextline2
nextline2 ¶ó´Â »ç¿ëÀÚ¸¦ µî·ÏÇÕ´Ï´Ù.
7. Á¢±ÙÅëÁ¦
Ŭ¶óÀ̾ðÆ®°¡ »ç¿ëÇϴ ȣ½ºÆ®ÀÇ IPÁÖ¼Ò³ª µµ¸ÞÀο¡ ÀÇÇؼ À¥¼¹öÀÇ µ¥ÀÌÅÍ¿¡ ´ëÇÑ Á¢±ÙÀ» ÅëÁ¦ÇÒ ¼ö ÀÖ½À´Ï´Ù.. ±âº»ÀûÀÎ ¼¹ö ¼³Á¤Àº DocumentRootÀÇ ³»¿ë¿¡ ´ëÇØ ´©±¸³ª Á¢¼Ó À» Çã¶ôÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ½À´Ï´Ù.
ApacheÀÇ "Allow"¿Í "Deny"Áö½ÃÀÚ´Â »ç¿ëÀÚ ½Ã½ºÅÛÀÇ È£½ºÆ® À̸§°ú È£½ºÆ® ÁÖ¼Ò¸¦ ±Ù°£À¸·Î Á¢¼ÓÀ» Çã¶ô ¶Ç´Â Â÷´ÜÇÒ ¼ö ÀÖµµ·Ï ÁöÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¶ÇÇÑ, "Allow"¿Í "Deny"Áö½ÃÀÚ¸¦ µ¿½Ã¿¡ »ç¿ëÇÒ °æ¿ì ±× ¼ø¼¸¦ Á¤ÇÏ´Â "Order" Áö½ÃÀÚ¸¦ »ç¿ëÇÏ¿© º¸´Ù Á¤±³ÇÑ Á¤Ã¥¼³Á¤À» ÇÒ ¼ö ÀÖ½À´Ï´Ù.
Order Deny,Allow
DenyÁö½ÃÀÚ°¡ AllowÁö½ÃÀÚº¸´Ù ¸ÕÀú °Ë»çµË´Ï´Ù. Á¢±ÙÀ» ±âº»ÀûÀ¸·Î Çã¿ëµË´Ï´Ù.
Áï, DenyÁö½ÃÀÚ³ª AllowÁö½ÃÀÚ¿¡ ÀÏÄ¡ÇÏÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®ÀÇ Á¢¼ÓÀ» Çã¿ëÇÕ´Ï´Ù.
Order Allow,Deny
AllowÁö½ÃÀÚ°¡ DenyÁö½ÃÀÚº¸´Ù ¸ÕÀú °Ë»çµË´Ï´Ù. Á¢±ÙÀ» ±âº»ÀûÀ¸·Î Â÷´ÜµË´Ï´Ù.
Áï, DenyÁö½ÃÀÚ³ª AllowÁö½ÃÀÚ¿¡ ÀÏÄ¡ÇÏÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®ÀÇ Á¢¼ÓÀº Â÷´ÜÇÕ´Ï´Ù.
Order Mutual-failure
Allow ¸®½ºÆ®¿¡ ÀÖ°í, Deny¸®½ºÆ®¿¡ ¾ø´Â È£½ºÆ®¸¸ Á¢±ÙÀ» Çã¿ëÇÕ´Ï´Ù.¼ø¼´Â "Allow,Deny"¶§¿Í °°´Ù.
(Âü°í) ÀϹÝÀûÀÎ FirewallÀ̳ª ¶ó¿ìÅÍÀÇ Á¢±ÙÅëÁ¦ RuleÀº ¼øÂ÷ÀûÀ¸·Î ºñ±³ÇÏ´Ù°¡ ÃÖÃÊ·Î ÀÏÄ¡ÇÏ´Â RuleÀ» Àû¿ëÇÏ°í ±× ÀÌÈÄ´Â ºñ±³ÇÏÁö ¾ÊÁö¸¸, Apache¿¡¼´Â Allow¿Í Deny¸¦ ÀÏ´Ü ¸ðµÎ ºñ±³ÇÏ°í µÑ Áß¿¡ Çϳª¶óµµ ÀÏÄ¡ÇÒ °æ¿ì Àû¿ëÇÕ´Ï´Ù´Â Á¡¿¡¼ Â÷ÀÌ°¡ ÀÖ½À´Ï´Ù.. ¶ÇÇÑ "Order"Áö½ÃÀÚ »ç¿ë½Ã Å°¿öµå(Allow ¶Ç´Â Deny)´Â ÄÞ¸¶(,)¿¡ ÀÇÇؼ¸¸ ºÐ¸®µÇ°í °ø¹éÀÌ µé¾î°¡¼´Â ¾ÈµË´Ï´Ù.
Order deny,allow
deny from all
allow from 172.16.10
"deny from"°ú "allow from"Áö½ÃÀڴ ȣ½ºÆ®, µµ¸ÞÀÎ À̸§, IPÁÖ¼Ò, ¼ºê³Ý¸¶½ºÅ©¸¦ °¡Áø ÁÖ¼Ò(¿¹¸¦ µé¸é 172.16.10.0/255.255.255.0), CIDR(Classes InterDomain Routing)¸¶½ºÅ©¸¦ °¡Áø IPÁÖ¼Ò(172.16.10.0/24)¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
8. ±ÇÇѺο©
±ÇÇѺο©´Â ƯÁ¤ÇÑ ÀÚ¿ø¿¡ Á¢±ÙÇÒ »ç¿ëÀÚ Æ۹̼ÇÀÌ À¯È¿ÇÑÁö¸¦ È®ÀÎÇÏ´Â °ÍÀÔ´Ï´Ù. ¾î¶² Æ۹̼ǿ¡ ÀÇÇØ Çã¶ôµÇ°í °ÅºÎµÉÁö´Â ÀÚ¿ø°ú ±× ÀÚ¿ø°ú °ü·ÃµÈ ±ÔÄ¢µé¿¡ µû¶ó¼ ´Ù¾çÇÏ´Ù. °¢ ÆÄÀÏ°ú µð·ºÅ丮±¸Á¶´Â ´Ù¸¥ Á¢±ÙÅëÁ¦³ª »ç¿ëÀÚÀÎÁõ ¹æ¹ýÀ» °¡Áú ¼ö ÀÖ½À´Ï´Ù. Á¢±ÙÅëÁ¦¿Í »ç¿ëÀÚ ÀÎÁõ¹æ¹ýÀ» »ç¿ëÇÏ¿© °¢ ÀÚ¿ø¿¡ ´ëÇÑ ´Ù¾çÇÑ ±ÇÇÑÀ» ºÎ¿©ÇÒ ¼ö ÀÖ½À´Ï´Ù. °¡·É ÀÎÅͳݿ¡¼ Á¢¼Ó ½Ã¿¡´Â »ç¿ëÀÚÀ̸§°ú Æнº¿öµå¸¦ È®ÀÎÇÏ°í ÀÎÆ®¶ó³Ý¿¡¼ Á¢¼Ó ½Ã¿¡´Â ¿ä±¸ÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ÀÌ´Â "Satisfy"Áö½ÃÀÚ¸¦ ÅëÇؼ ±¸ÇöÇÒ ¼ö ÀÖ½À´Ï´Ù.
Satisfy any | all
allÀº ÀÎÆ®¶ó³Ý »ç¿ëÀÚ¿¡ ´ëÇØ Æнº¿öµå¸¦ ¹¯Áö ¾Ê°í Á¢¼ÓÀÌ °¡´ÉÇÏ°Ô ÇÏ´Â °ÍÀÌ°í, any´ÂÀÎÆ®¶ó³Ý »ç¿ëÀÚ¶óµµ Æнº¿öµå¸¦ ¹¯´Â´Ù.
Order deny,allow
deny from all
allow from xxx.xxx.xxx.xxx
AuthType Basic
AuthName "Welcome Posein's Home"
AuthUserFile /usr/local/apache/password
Require nextline nextline2
Satisfy Any
AuthName Ç׸ñ¿¡¼ 1.3¹öÀü¿¡¼´Â °ãµû¿ÈÇ¥°¡ ¾ÕÂÊ¿¡ ÇϳªÀÌ°í, 2.0¹öÀü¿¡¼´Â °ãµû¿ÈÇ¥°¡ ¾ÕµÚ·Î µÎ°³¸¦ ½á¾ß ÇÕ´Ï´Ù.
|