Home | Data Center | Contact US | Login

Á¦¸ñ ¸®´ª½º º¸¾ÈÁöħ ¸Þ´º¾ó
÷ºÎÆÄÀÏ ¸®´ª½º º¸¾ÈÁöħ ¸Þ´º¾ó.pdf ÀÛ¼ºÀÏ 2008-03-27 16:20:07

ÀÛ¼ºÀÚ : ±â¼úÁö¿øºÎ ±è »ï ¼ö kiss@nextline.co.kr
 
¸®´ª½º ÃÖÀûÈ­ ¹× º¸¾ÈÁöħ
 
¸ñÂ÷
 
OS ¼³Ä¡
1. ¸®´ª½º ¼³Ä¡
2. ÆÄƼ¼Ç ³ª´©±â
3. ÆÐÅ°Áö ¼±ÅÃ
 
OS ¼³Ä¡ÈÄ ±âº»¼³Á¤
1. ½Ã½ºÅÛÁ¤º¸ È®ÀÎ
2. Ãʱ⠽ÇÇà µ¥¸ó ¼±ÅÃ
3. ºÒÇÊ¿äÇÑ ÆÐÅ°Áö Á¦°Å
4. ½Ã½ºÅÛ ¹× CMOS ½Ã°£µ¿±âÈ­
5. yumÀ» ÀÌ¿ëÇÑ ÃÖ½ÅÆÐÅ°Áö ¾÷µ¥ÀÌÆ®
6. grub.conf ¼³Á¤
7. ½Ã½ºÅÛ ¸®ºÎÆÃ
8. HDD ¼ÓµµÃ¼Å©
 
½Ã½ºÅÛ ¿î¿µ ½ºÅ©¸³Æ® È°¿ë
1. addon »ç¿ëÀÚ°ü¸® ¸í·É¾î
2. mail ¸ÞÀÏ°èÁ¤°ü¸® ¸í·É¾î
3. dbadd µðºñ°èÁ¤ °ü¸®¸í·É¾î
5. APACHE, PHP, MYSQL ¿¬µ¿ ÀÚµ¿ÀνºÅç
 
½Ã½ºÅÛ º¸¾È ¼³Á¤
1. logout ½Ã command history »èÁ¦Çϱâ
2. ÀÚµ¿ ·Î±×¾Æ¿ô ȯ°æº¯¼ö ¼³Á¤
3. su ¸í·É¾î Á¦ÇÑÇϱâ
4. PAM ¹× ulimit¸¦ È°¿ëÇÑ ¸®¼Ò½º(resource) Á¦ÇÑ
5. SUID¿Í SGID ÆÄÀÏ ¹× µð·ºÅ丮
6. ¹«¼Ò¼Ó ÆÄÀÏã¾Æ ¼ÒÀ¯±Ç ºÎ¿©Çϱâ
7. /dev ¿¡ device ÆÄÀÏ¿ÜÀÇ °ÍÀÌ ÀÖ´ÂÁö È®ÀÎ
8. ¿ø°ÝÁ¢¼ÓÇã¿ëÆÄÀÏ »ý¼º ¿©ºÎ Á¡°Ë
9. ¼û±èÆÄÀÏ ¶Ç´Â ºñÁ¤»óÀûÀÎ ÆÄÀÏ Á¸Àç ¿©ºÎ Á¡°Ë
10. ÆÄÀϽýºÅÛ ¸¶¿îÆ®
11. ch_permÀ» ÅëÇÑ ÆÄÀÏ ¹× µð·ºÅ丮 ±ÇÇÑ ¼³Á¤
12. ssh ¹«Â÷º° dos °ø°Ý¿¡ ´ëÇÑ ¹æ¾î
14. ³Ø½ºÆ®¶óÀÎ ¹æÈ­º®(next_firewall) Á¤Ã¥¼³Á¤
15. Ä¿³Î º¯¼ö Á¶Á¤
16. ½Ã½ºÅÛ ÀÌ»ó½Ã ±âº»ÀûÀÎ Á¡°Ë »çÇ× ¹× ¸í·É¾î
17. TCP-Wrapper ±¸¼º
 
¼­ºñ½ºº¸¾È
1. APACHE º¸¾È
2. PHP º¸¾È
3. SSH º¸¾È
4. FTP º¸¾È
5. SENDMAIL º¸¾È
6. MYSQL º¸¾È
7. BIND º¸¾È
 
º¸¾ÈÇÁ·Î±×·¥
1. À¥ ¾îÇø®ÄÉÀÌ¼Ç º¸¾È KWST (KISA Web Security Template)
2. ¾ÆÆÄÂ÷ º¸¾È ¸ðµâ
 
---------------------------------------------------------------
¸®´ª½º ÃÖÀûÈ­ ¹× º¸¾ÈÁöħ
 
1. OS ¼³Ä¡

1) ¸®´ª½º ¼³Ä¡
¸®´ª½º¸¦ ¼³Ä¡ÇÒ ¶§ ½Ã½ºÅÛÀ» ¾î¶² ¿ëµµ·Î »ç¿ëÇÒ °ÍÀΰ¡¿¡ µû¶ó ÆÄƼ¼Ç±¸¼º ¹× ÆÐÅ°Áö ¼±ÅÃÀÌ ´Þ¶óÁú ¼ö ÀÖ½À´Ï´Ù. ¼­¹ö´Â ¿©·¯ »ç¿ëÀÚ¿¡°Ô ¼­ºñ½º¸¦ Á¦°øÇÏ´Â °ÍÀ» ¸ñÀûÀ¸·Î ÇÔÀ¸·Î½á X-windows³ª ÄÄÆÄÀÏ·¯, °ÔÀÓ µî ºÒÇÊ¿äÇÑ ÆÐÅ°Áö´Â ¼³Ä¡ÇÏÁö ¾Êµµ·Ï ÇÕ´Ï´Ù.
 
2) ÆÄƼ¼Ç ³ª´©±â
2-1 ÆÄƼ¼Ç´× ¸ñÀû
µð½ºÅ© ÆÄƼ¼Ç´×À» ÇÏ´Â °ÍÀº ½Ã½ºÅÛ º¸¾ÈÀÇ ½ÃÀÛÀÌÀÚ ±âº»ÀÌ¸ç ½Ã½ºÅÛ ¿µ¿ª°ú »ç¿ëÀÚ ¿µ¿ªÀ» ±¸ºÐÇÏ¿© ÆÄƼ¼ÇÀ» ³ª´©´Â ¸ñÀûÀº ´ÙÀ½°ú °°½À´Ï´Ù.
¨ç µð½ºÅ©°ø°£ °í°¥ À¯ÇüÀÇ DoS(Denial of Service) °ø°Ý¿¡ ´ëÇÑ ¹æ¾î
¨è SUID ÇÁ·Î±×·¥¿¡ ´ëÇÑ º¸È£
¨é ¹é¾÷°ú ¾÷±×·¹ÀÌµå °ü¸®°¡ ¿ëÀÌ
¨ê ºü¸¥ºÎÆÃ
¨ë °¢ ÆÄÀϽýºÅÛ¿¡ ´ëÇÑ ¸¶¿îÆ® ¹æ¹ý Á¦¾î °¡´É
¨ì Çϵ帵ũ¸¦ ÅëÇÑ ÇØÅ·¹æÁö
¨í °¢ ÆÄƼ¼Çº° º¸¾È¼³Á¤
 
2-2 ±âº» ÆÄƼ¼Ç
ÆÄƼ¼Ç
±ÇÀå¿ë·®
¼³¸í
Swap
1 ~ 2G
Virtual memoryÀ» Áö¿øÇϱâ À§ÇÑ °ø°£À¸·Î, ÀÐ°í ¾²±â°¡ °¡Àå ºü¸¥ HDD½Ç¸°´õÀÇ °¡Àå ¹Ù±ùºÎºÐ¿¡ ¸¸µì´Ï´Ù.
/
5G
½Ã½ºÅÛ ·çÆ®ÆÄƼ¼ÇÀ¸·Î, µð½ºÅ©°ø°£ °í°¥·Î ÀÎÇÑ ½Ã½ºÅÛ ´Ù¿î¹æÁö
/usr
5G
À¯Æ¿¸®Æ¼ ¹× ½© ¸í·É¾îµéÀÌ ÀúÀåµÇ´Â °÷ÀÔ´Ï´Ù.
/var
5G
Mail ¹× log µ¥ÀÌÅÍ°¡ ½×ÀÌ´Â °ø°£À̸ç, DoS °ø°Ý¿¡ ÀÌ¿ëµÉ °¡´É¼ºÀÌ ÀÖÀ¸¹Ç·Î ¹Ýµå½Ã ÆÄƼ¼Ç´× ÇÕ´Ï´Ù.
/tmp
1G
´©±¸³ª ÀÐ°í ¾µ ¼ö ÀÖ´Â µð·ºÅ丮·Î °ø°ÝÀÚµéÀÌ ÀϹÝÀ¯Àú ±ÇÇÑÀ» ¾òÀº °æ¿ì ÀÌ°÷¿¡ ÇØÅ·¼Ò½º¸¦ ±¸ÃàÇÏ´Â °æ¿ì°¡ ¸¹À¸¹Ç·Î ¹Ýµå½Ã ÆÄƼ¼Ç´×ÇÕ´Ï´Ù.
/home
¿©À¯°ø°£ ¸ðµÎ ÇÒ´ç
ÀÏ¹Ý À¯ÀúÀÇ È¨µð·ºÅ丮ÀÔ´Ï´Ù.







 
3) ÆÐÅ°Áö ¼±ÅÃ
Custom ¸ðµå·Î kernel,gcc,glib ¿Ü¿¡ ¼­¹ö¿î¿µ¿¡ ÇÊ¿äÄ¡ ¾ÊÀº X-windoiws, °ÔÀÓ, ÆÐÅ°ÁöµîÀ» ¸ðµÎ Á¦°ÅÇÏ¿© ¼­¹ö¿î¿µ¿¡ ÃÖÀûÈ­ µÉ ¼ö ÀÖµµ·Ï ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù. ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â ÆÐÅ°Áö ¸®½ºÆ®´Â /root/nextinstall.log¿¡ ±â·ÏµÇ¾î ÀÖ½À´Ï´Ù.
 
---------------------------------------------------------------------------------------

2. OS ¼³Ä¡ÈÄ ±âº»¼³Á¤
1) ½Ã½ºÅÛÁ¤º¸ È®ÀÎ
pstree, ifconfig, netstat –anp, df –h, cat /rpoc/cpuinfo, cat /proc/meminfo, uname –a µîÀÇ ¸í·ÉÀ¸·Î OS¼³Ä¡ÈÄÀÇ ½Ã½ºÅÛÀÇ ±âº»Á¤º¸¸¦ üũÇÕ´Ï´Ù.
 
¨ç Ä¿³Î ¹öÀü È®ÀÎ
[root@nextline ~]# uname –a

 
 
¨è ÇöÀç ¿ÀÇÂµÈ Æ÷Æ®¿Í ¼­ºñ½º È®ÀÎ
[root@nextline ~]# netstat –anp
[root@nextline ~]# netstat -anp|grep LISTEN
tcp   0 0 0.0.0.0:3306   0.0.0.0:*    LISTEN 16561/mysqld  
tcp   0 0 0.0.0.0:110    0.0.0.0:*    LISTEN 2579/xinetd   
tcp   0 0 0.0.0.0:21   0.0.0.0:*     LISTEN 2579/xinetd   
tcp   0 0 61.100.191.46:53     0.0.0.0:*     LISTEN 2525/named    
tcp   0 0 127.0.0.1:53    0.0.0.0:*   LISTEN 2525/named    
tcp   0 0 0.0.0.0:22   0.0.0.0:*      LISTEN 2579/xinetd   
tcp   0 0 0.0.0.0:25    0.0.0.0:*     LISTEN 2598/sendmail: acce
tcp   0 0 127.0.0.1:953  0.0.0.0:*    LISTEN 2525/named    
tcp   0 0 :::80   :::* LISTEN 16205/httpd
 
apache, mysql, bind, sendmail, pop3, ssh, ftp ¼­ºñ½º°¡ ±¸µ¿ÁßÀÓÀ» È®ÀÎÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
 
¨é ÇöÀç ½ÇÇàÁßÀÎ ÇÁ·Î¼¼½º¸¦ Æ®¸®±¸Á¶·Î º¸±â
[root@nextline ~]# pstree
 

 
 
 
¨ê ³×Æ®¿öÅ© ÀÎÅÍÆäÀ̽º¿¡ ¼³Á¤µÈ ¾ÆÀÌÇÇ ÁÖ¼Ò È®ÀÎ
[root@nextline ~]# ifconfig
HWaddr 00:0B:6A:DC:4B:FE # ÀÎÅÍÆäÀ̽ºÀÇ MAC ÁÖ¼Ò
Inet addr: 10.0.0.52      # ÀÎÅÍÆäÀ̽º¿¡ ÇÒ´çµÈ ÁÖ¼Ò
Bcast : 10.0.0.255             # ºê·Îµåij½ºÆ® ÁÖ¼Ò
Mask : 255.255.255.0     # ¼­ºê³Ý¸¶½ºÅ© ºñÆ®
MTU : 1500     # ÃÖ´ë Àü¼Û´ÜÀ§(Maximum Transfer Unit)
# ºÎÆà ÈÄ ÇöÀç±îÁö ¹ÞÀº ÆÐŶÁ¤º¸
RX packets:473988 errors: 0 dropped:0 overruns:0 frame:0
# ºÎÆà ÈÄ ÇöÀç±îÁö º¸³½ ÆÐŶÁ¤º¸
RX packets:473988 errors: 0 dropped:0 overruns:0 frame:0
Collisions:0 : # Ãæµ¹³­ ÆÐŶ ¼ö

 
 
¨ë µð½ºÅ© ¿ë·®À» È®ÀÎ
[root@nextline ~]# df –h


 
¨ì CPU Á¤º¸ È®ÀÎ
[root@nextline ~]# cat /proc/cpuinfo

 
 
¨í ¸Þ¸ð¸® Á¤º¸ È®ÀÎ
[root@nextline ~]# cat /proc/meminfo

 

½Ç ¸Þ¸ð¸®¿Í ÇöÀç »ç¿ëÁßÀÎ ¸Þ¸ð¸® ¿ë·® È®ÀÎ
[root@nextline ~]# free –m
½Ç ¸Þ¸ð¸® ¿ë·® : 768M
ÇöÀç »ç¿ëÁßÀÎ ¸Þ¸ð¸® ¿ë·® : 94M

 
 
2) Ãʱ⠽ÇÇà µ¥¸ó ¼±ÅÃ
ntsysvÀ» ÅëÇØ cron, network, xinetd, syslog ÀÌ¿Ü ½Ã½ºÅÛ¿¡ ºÒÇÊ¿äÇÑ µ¥¸óÀº ÁßÁö½Ãŵ´Ï´Ù.
[root@nextline bin]# ntsysv

 
ºÎÆýà ÇØ´ç ¼­ºñ½º°¡ ±¸µ¿µÇµµ·Ï ÇϽ÷Á¸é ÇØ´ç ¼­ºñ½º Ç׸ñ¿¡ ½ºÆäÀ̽º¹Ù¸¦ ÀÌ¿ëÇÏ¿©[*] ¸¦ üũÇÏ¿© ÁÖ½Ã¸é µË´Ï´Ù.

 
 
 
3) ºÒÇÊ¿äÇÑ ÆÐÅ°Áö Á¦°Å
½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â ÆÐÅ°Áö ¸®½ºÆ®´Â /root/nextinstall.log ¿¡ ±â·ÏµÇ¾î ÀÖ½À´Ï´Ù.
rpm ¸í·É¾î¸¦ ÅëÇØ ÆÐÅ°Áö¸¦ »èÁ¦ÇÕ´Ï´Ù.
 
rpm ¸í·É¾î ¹× ¿É¼Ç
»õ·Î¿î ÆÐÅ°Áö¸¦ ¼³Ä¡Çϰųª ¾÷±×·¹À̵å, »èÁ¦½Ã »ç¿ë
 
ÆÐÅ°Áö ¼³Ä¡ ¿É¼Ç
-i : »õ·Î¿î ÆÐÅ°Áö¸¦ ¼³Ä¡ÇÒ ¶§ »ç¿ë  (--install)
-U : ±âÁ¸ÀÇ ÆÐÅ°Áö¸¦ »õ·Î¿î ¹öÀüÀÇ ÆÐÅ°Áö·Î ¾÷±×·¹À̵åÇÒ ¶§ »ç¿ëÇÏ°í ¼³Ä¡µÈ ÆÐÅ°Áö°¡
  ¾øÀ» °æ¿ì ÆÐÅ°Áö¸¦ ¼³Ä¡( -i ¿É¼Ç°ú °°À½)
-F : ÀÌÀü ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °æ¿ì¿¡¸¸ ¼³Ä¡ (--freshen)
-v : ¸Þ½ÃÁö¸¦ ÀÚ¼¼È÷ º¸¿©ÁÜ
-h : '#'±âÈ£·Î Ç¥½ÃÇØ ÁÜ
 
--force : ±âÁ¸¿¡ ¼³Ä¡µÈ ÆÐÅ°Áö¿Í °ü°è¾øÀÌ °­Á¦·Î ¼³Ä¡ ÇÕ´Ï´Ù.
--nodeps : ÀÇÁ¸¼º °ü°è¸¦ ¹«½ÃÇÏ°í ¼³Ä¡ ÇÕ´Ï´Ù.
-vv : ¸Þ½ÃÁö¸¦ ¾ÆÁÖ ÀÚ¼¼È÷ º¸ÁÝ´Ï´Ù.
--oldpackage : ±¸¹öÀüÀ¸·Î ´Ù¿î±×·¹À̵åÇÒ ¶§ »ç¿ëÇÕ´Ï´Ù.
--rebuilddb : ƯÁ¤ÇÑ ÆÐÅ°Áö ¼³Ä¡ÈÄ¿¡ rpmÆÐÅ°Áö·Î °Ë»öÇßÀ¸³ª ³ªÅ¸³ªÁö ¾ÊÀ» ¶§ rpmµ¥ÀÌ
Åͺ£À̽º¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù
 
Á¤¸®
-ivh : »õ·Î¿î ÆÐÅ°Áö ¼³Ä¡
-Uvh : ¾÷±×·¹À̵åÇϰųª »õ·Î¿î ÆÐÅ°Áö ¼³Ä¡
-Fvh : ÀÌÀü ¹öÀüÀÇ ÆÐÅ°Áö°¡ ÀÖ´Â °æ¿ì¿¡¸¸ ÆÐÅ°Áö ¼³Ä¡
 
rpm ¸í·É¾î »ç¿ë ¿¹Á¦
 
proftpd ÆÐÅ°Áö¸¦ ¼³Ä¡Çϰųª ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù.
[root@nextline ~]# rpm -Uvh proftpd-1.2.9-1.9.i386.rpm
 
ÆÐÅ°Áö Á¦°Å¿É¼Ç
 
¿É¼Ç
-e : ¼³Ä¡µÈ ÆÐÅ°Áö¸¦ Á¦°ÅÇÕ´Ï´Ù.
--nodeps : Á¦°Å½Ã ÀÇÁ¸¼ºÀ» ¹«½ÃÇÏ°í Á¦°ÅÇÕ´Ï´Ù.(ÇØ´ç ¿É¼Ç »ç¿ë½Ã ÀÇÁ¸¼º °ü·Ã ÆÐÅ°ÁöµéÀÌ ¿À·ù°¡ ¹ß»ýÇÒ ¼ö ÀÖÀ¸´Ï ÁÖÀÇ ÇϽñ⠹ٶø´Ï´Ù.)
 
rpm ÆÐÅ°Áö Á¦°Å ¿É¼Ç »ç¿ë ¿¹Á¦
 
sendmail ÆÐÅ°Áö ¸®½ºÆ®¸¦ È®ÀÎÇÕ´Ï´Ù.
[root@nextline ~]# rpm -qa | grep sendmail 
sendmail-devel-8.11.6-27.73
sendmail-8.11.6-27.73
sendmail-cf-8.11.6-27.73
 
sendmail-devel-8.11.6-27.73 ¶ó´Â rpm ÆÐÅ°Áö¸¦ »èÁ¦ ÇÕ´Ï´Ù
[root@nextline ~]# rpm -e sendmail-devel-8.11.6-27.73
 
proftpd ÆÐÅ°Áö¿¡ ÀÇÁ¸¼ºÀÌ ÀÖ´õ¶óµµ ¹«½ÃÇÏ°í Á¦°ÅÇÕ´Ï´Ù.
[root@nextline ~]# rpm -e proftpd --nodeps
 
rpm ÆÐÅ°Áö °Ë»ö ¿É¼Ç
¼³Ä¡µÈ ÆÐÅ°Áö¿Í °¢ ÆÐÅ°Áö¿¡ Æ÷ÇÔµÈ ÆÄÀϵéÀ» °Ë»öÇÏ¿© È®ÀÎÇØ º¼ ¼ö ÀÖ½À´Ï´Ù.
 
°ü·Ã¿É¼Ç
-q : ÁúÀǽÿ¡ ²À ½á¾ßÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù. ÆÐÅ°Áö¸¦ ãÀ¸¸é ÆÐÅ°ÁöÀ̸§°ú ¹öÀü¸¸ Ç¥½ÃÇÕ´Ï´Ù.
-i : ¼³Ä¡µÈ ÆÐÅ°ÁöÀÇ Á¤º¸¸¦ º¸¿©ÁØ´Ù. -p¿É¼Ç°ú »ç¿ëÇϸé ÆÐÅ°Áö ÆÄÀÏÁ¤º¸¸¦ º¸¿©ÁÝ´Ï´Ù.
-l : ÆÐÅ°Áö¿¡ Æ÷ÇÔµÈ ¸ðµç ÆÄÀÏÀ» º¸¿©ÁØ´Ù. ¿ª½Ã -p¿Í »ç¿ëÇÏ·Á¸é Á¤È®ÇÑ ÆÄÀϸíÀ» º¸¿©ÁÝ´Ï´Ù. (--list)
-p ÆÄÀϸí: ÆÐÅ°ÁöÀÇ ÆÄÀÏ¿¡ ´ëÇÑ Á¤º¸¸¦ º¸¿©ÁÝ´Ï´Ù.  Á¤È®ÇÑ À̸§À» ÀÔ·ÂÇØ¾ß ÇÕ´Ï´Ù.
-a : ½Ã½ºÅÛ¿¡ ¼³Ä¡µÈ ¸ðµç ÆÐÅ°Áö¸ñ·ÏÀ» º¸¿©ÁÝ´Ï´Ù. (--all)
ÆÐÅ°Áö¸íÀ» Àß ¸ð¸£´Â °æ¿ì¿¡´Â '| grep ÆÐÅ°Áö¸í'À» ºÙ¿© »ç¿ëÇϸé À¯¿ëÇÕ´Ï´Ù.
-f ÆÄÀϸí: ÁöÁ¤µÈ ÆÄÀÏÀÌ Æ÷ÇÔµÈ ÆÐÅ°Áö¸¦ Ãâ·ÂÇÕ´Ï´Ù.
-c : ÇØ´çÆÐÅ°ÁöÀÇ ¼³Á¤ÆÄÀÏÀ̳ª ½ºÅ©¸³Æ®ÆÄÀÏÀ» º¸¿©ÁÝ´Ï´Ù.
-d : ÇØ´çÆÐÅ°ÁöÀÇ ¹®¼­ÆÄÀÏÀ» Ãâ·ÂÇÕ´Ï´Ù.
-R : ¾î¶² ÆÐÅ°Áö¿¡ ÀÇÁ¸ÇÏ°í ÀÖ´ÂÁö¸¦ º¸¿©ÁÝ´Ï´Ù. (--requires)
 
rpm ÆÐÅ°Áö °Ë»ö ¿É¼Ç »ç¿ë ¿¹Á¦
 
¼³Ä¡µÈ sendmailÀÇ ÆÐÅ°ÁöÀ̸§°ú ¹öÀüÀ» º¸¿©ÁØ´Ù.
[root@nextline ~]# rpm -q sendmail
sendmail-8.11.6-27.73
 
ÇöÀç ¼³Ä¡µÈ ¸ðµç ÆÐÅ°Áö¸¦ º¸¿©ÁØ´Ù.
[root@nextline ~]# # rpm –qa
 
sendmail°ü·Ã ÆÐÅ°Áö¸¦ º¸¿©ÁØ´Ù.
[root@nextline ~]# rpm -qa |grep sendmail
sendmail-devel-8.11.6-27.73
sendmail-8.11.6-27.73
sendmail-cf-8.11.6-27.73
 
sendmailÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °æ·Î¸¦ º¸¿©ÁØ´Ù.
[root@nextline ~]# rpm -ql sendmail
 
4) ½Ã½ºÅÛ ¹× CMOS ½Ã°£µ¿±âÈ­
/root/bin/timesync ½ºÅ©¸³Æ®¸¦ ÅëÇØ ÀÎÅÍ³Ý ½Ã°£¼­¹ö¿Í ¸ÅÀÏ 04½Ã¿¡ ½Ã½ºÅÛ ¹× Çϵå¿þ¾î ½Ã°£ÀÇ µ¿±âÈ­ ÀÛ¾÷ÀÌ ÀÌ·ç¾îÁý´Ï´Ù.
 
timesync ½ºÅ©¸³Æ®´Â /root/bin/timesync °æ·Î¿¡ Á¸ÀçÇÕ´Ï´Ù.

 
 
timesync ½ºÅ©¸³Æ®´Â crontab¿¡ ÀÇÇØ ¸ÅÀÏ 04½Ã¿¡ ÀÎÅÍ³Ý ½Ã°£¼­¹ö¿Í µ¿±âÈ­ µÉ ¼ö ÀÖµµ·Ï ¼³Á¤µÇ¾îÀÖ½À´Ï´Ù.

 
 
5) yumÀ» ÀÌ¿ëÇÑ ÃÖ½ÅÆÐÅ°Áö ¾÷µ¥ÀÌÆ®
ºÒÇÊ¿äÇÑ ÆÐÅ°Áö Á¦°Å ÈÄ yum ¼­¹ö¸¦ ÅëÇØ ÃÖ½ÅÆÐÅ°Áö·Î ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù.
 
YumÀº ÁöÁ¤µÈ ¼­¹öÁּҷκÎÅÍ ¾÷µ¥ÀÌÆ®µÈ ÆÐÅ°ÁöµéÀ» °Ë»çÇÏ¿© ´Ù¿î·ÎµåÇÏ°í ¼³Ä¡±îÁö ó¸®ÇØÁÖ´Â ÅؽºÆ® ±â¹ÝÀÇ ¾÷µ¥ÀÌÆ® ÇÁ·Î±×·¥ÀÔ´Ï´Ù. ¶ÇÇÑ ÀÇÁ¸¼º ¹®Á¦µµ °°ÀÌ °Ë»çÇÏ¿© °ü·Ã ÆÐÅ°ÁöµéÀ» ÀÚµ¿À¸·Î ¼³Ä¡ÇØÁֱ⠶§¹®¿¡ ÀÌÀü¿¡ ´Ù¼Ò ºÒÆíÇÏ´ø RPM ±â¹ÝÀÇ ÇÁ·Î±×·¥ ¼³Ä¡ ¹× ¾÷µ¥ÀÌÆ®¸¦ ´ëÆø °³¼±ÇÑ ÆÐÅ°Áö °ü¸®ÀÚÀÔ´Ï´Ù.
 
¨ç ¼³Á¤ È®ÀÎ
 
yum ¾÷µ¥ÀÌÆ®¸¦ À§Çؼ­´Â ¾÷µ¥ÀÌÆ® ¼­¹öÀÇ URL¿Í ±âŸ ¼¼ºÎÀûÀÎ ¼³Á¤»çÇ×µéÀ» È®ÀÎÇØ¾ß ÇÕ´Ï´Ù. yum µ¿ÀÛ¿¡ ÇÊ¿äÇÑ ¼³Á¤Àº /etc/yum.conf ÆÄÀÏ¿¡ ±â·ÏµÇ¾î ÀÖÀ¸¹Ç·Î, ÅؽºÆ® ÆíÁý±â µîÀ» ÅëÇØ yum ¼³Á¤³»¿ëÀ» È®ÀÎÇÕ´Ï´Ù. ¾÷µ¥ÀÌÆ® ÁÖ¼Ò´Â /etc/yum.repos.d/CentOS-Base.repo ÆÄÀÏ¿¡¼­ È®ÀÎ ¹× ¼öÁ¤ ÇÒ ¼ö ÀÖ½À´Ï´Ù.
 
 
¨è ¾÷µ¥ÀÌÆ®
À§¿Í °°ÀÌ ¼³Á¤»çÇ׿¡ ÀÌ»óÀÌ ¾ø´Ù¸é ¹Ù·Î ¾÷µ¥ÀÌÆ® ¸í·ÉÀ» ÅëÇØ ÆÐÅ°Áö¸¦ ¾÷µ¥ÀÌÆ® ÇÒ ¼ö ÀÖ½À´Ï´Ù.
 
[root@nextline ~]# yum -y update

 
 
À§ÀÇ ¸í·ÉÀ» ÀÔ·ÂÇÏ¸é ¼³Á¤ÆÄÀÏ¿¡ ÀÖ´Â °æ·Î¸¦ Âü°íÇÏ¿© ¾÷µ¥ÀÌÆ® ¼­¹ö¿¡ Á¢¼ÓÇÑ µÚ, ÇöÀç ½Ã½ºÅÛÀÇ ÆÐÅ°Áöµé°ú ¾÷µ¥ÀÌÆ® ¼­¹öÀÇ ÆÐÅ°ÁöµéÀ» ºñ±³ÇÏ¿© ÃÖ½ÅÀÇ ÆÐÅ°Áö¸¦ ¸ðµÎ ¾÷µ¥ÀÌÆ® ÇÏ°Ô µË´Ï´Ù. À§ÀÇ ¸í·ÉÀº ¼Õ½±°Ô ¸ðµç ÆÐÅ°ÁöµéÀ» ¾÷µ¥ÀÌÆ® ÇÒ ¼ö Àֱ⿡ °¡Àå ¸¹ÀÌ »ç¿ëµÇ´Â ¾÷µ¥ÀÌÆ® ¹æ¹ýÀÔ´Ï´Ù. ¸¸ÀÏ Æ¯Á¤ÇÑ ÆÐÅ°Áöµé¸¸ ¾÷µ¥ÀÌÆ® ÇÏ°íÀÚ ÇÏ´Â °æ¿ì¿¡´Â ¾Æ·¡¿Í °°ÀÌ ¿øÇÏ´Â ÆÐÅ°Áö¸¦ º°µµ·Î ÁöÁ¤ÇØ ÁÝ´Ï´Ù.
 
[root@localhost ~] # yum update [package_name1] [package_name2]...
 
ÆÐÅ°Áö¸¦ ¾÷µ¥ÀÌÆ®Çϱâ Àü¿¡ ¾÷µ¥ÀÌÆ®µÈ ÆÐÅ°Áö°¡ ÀÖ´ÂÁö¸¦ üũÇϱâ À§Çؼ­´Â ¾Æ·¡¿Í °°ÀÌ Ã¼Å© ¿É¼ÇÀ» »ç¿ëÇÕ´Ï´Ù.
 
[rootlocalhost ~] # yum check-update
 
´Ü, check-updateÀÇ °æ¿ì ÇöÀç ½Ã½ºÅÛ¿¡ ¼³Ä¡µÈ ÆÐÅ°Áö¸¦ ±âÁØÀ¸·Î ¾÷µ¥ÀÌÆ® ¸ñ·ÏÀ» Ãâ·ÂÇØÁֱ⠶§¹®¿¡ ¾÷µ¥ÀÌÆ® ¼­¹ö¿¡´Â µî·ÏµÇ¾î ÀÖÁö¸¸ ÇöÀç ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇÁö ¾ÊÀº ÆÐÅ°Áö ¸ñ·ÏÀº º¼ ¼ö ¾ø½À´Ï´Ù. ÀÌ·² °æ¿ì ¾Æ·¡¿Í °°ÀÌ list ¸í·ÉÀ» »ç¿ëÇؼ­ ¾÷µ¥ÀÌÆ® ¼­¹ö¿¡ ÀÖ´Â ¸ðµç ÆÐÅ°Áö ¸ñ·ÏÀ» È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
 
[root@localhost ~] # yum list
 
¹Ý´ë·Î ÇöÀç ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â ÆÐÅ°Áö ¸ñ·ÏÀ» È®ÀÎÇϱâ À§Çؼ­´Â ¾Æ·¡¿Í °°Àº ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
 
[root@localhost ~] # yum list installed
 
¨é ½Å±Ô¼³Ä¡
 
yumÀ» ÀÌ¿ëÇÏ¸é ±âÁ¸ ¼³Ä¡µÇ¾î ÀÖ´Â ÇÁ·Î±×·¥ÀÇ ¾÷µ¥ÀÌÆ® »Ó¸¸ ¾Æ´Ï¶ó ½Ã½ºÅÛ¿¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾ÊÀº »õ·Î¿î ÆÐÅ°Áöµéµµ °Ë»çÇÏ¿© ¼³Ä¡°¡ °¡´ÉÇÕ´Ï´Ù. ¾Õ¼­ ¸»ÇÑ yum list ¸í·ÉÀ¸·Î ¾÷µ¥ÀÌÆ® ¼­¹ö¿¡ ÀÖ´Â ÆÐÅ°Áö ¸®½ºÆ®¸¦ È®ÀÎÇÑ ´ÙÀ½, ¼³Ä¡¸¦ ¿øÇÏ´Â »õ·Î¿î ÆÐÅ°Áö°¡ ÀÖ½À´Ï´Ù.¸é install ¸í·ÉÀ¸·Î ¼³Ä¡¸¦ ÁøÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.
[root@localhost ~] # yum install package_name
 
¿©·¯ ÆÐÅ°ÁöµéÀ» ÇÑ ¹ø¿¡ ¼³Ä¡Çϱ⸦ ¿øÇÕ´Ï´Ù¸é ÇØ´ç ÆÐÅ°Áö¸¦ °è¼ÓÇؼ­ Àû¾î ÁÝ´Ï´Ù. (install ¿É¼Ç¿¡¼­´Â ±âº»ÀûÀ¸·Î Çϳª ÀÌ»óÀÇ ÆÐÅ°Áö¸¦ ÁöÁ¤ÇØ¾ß ÇÕ´Ï´Ù.)
 
[root@localhost ~] # yum install package_name1 [package_name2] ...
 
¨ê ÆÐÅ°Áö »èÁ¦
 
yumÀ» ÀÌ¿ëÇÏ¿© ÆÐÅ°Áö¸¦ ¾÷µ¥ÀÌÆ®ÇÏ°í ½Å±Ô ¼³Ä¡ÇÏ´Â °Í ÀÌ¿Ü¿¡ ÆÐÅ°Áö¸¦ »èÁ¦ÇÏ´Â ±â´Éµµ ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.
 
[root@localhost ~] # yum remove package_name
¿©·¯ ÆÐÅ°ÁöµéÀ» »èÁ¦ÇÏ°íÀÚ ÇÕ´Ï´Ù¸é, ½Å±Ô¼³Ä¡ÀÇ °æ¿ì¿Í °°ÀÌ »èÁ¦ ¸í·É µÚ¿¡ ÇØ´ç ÆÐÅ°Áö¸¦ °è¼ÓÇؼ­ ÁöÁ¤ÇØÁÖ¸é µË´Ï´Ù.
 
¨ë ±âŸ ±â´É
 
¾÷µ¥ÀÌÆ® ¼­¹ö¿¡ µî·ÏµÇ¾î ÀÖ´Â ÆÐÅ°Áö¿¡ ´ëÇÑ »ó¼¼ÇÑ Á¤º¸¸¦ º¸±â À§Çؼ­´Â ¾Æ·¡¿Í °°Àº ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
[root@localhost ~] # yum info package_name
 
ÃÖ±Ù¿¡ ¾÷µ¥ÀÌÆ®ÇÑ ÆÐÅ°Áö¿¡ ´ëÇÑ Á¤º¸´Â ¾Æ·¡ ¸í·ÉÀ¸·Î È®ÀÎÇÕ´Ï´Ù.
[root@localhost ~] # yum info updates
 
6) grub.conf ¼³Á¤
¾÷µ¥ÀÌÆ® µÈ Ä¿³Î·Î ºÎÆÃÇϱâ À§ÇØ grub.conf ÆÄÀÏÀ» ¼öÁ¤ÇÕ´Ï´Ù.
[root@localhost ~] # vi /etc/grub.conf

 
 
 
Ç׸ñ¼³¸í
default=0
±âº»°ªÀ¸·Î ºÎÆõǵµ·Ï ¼³Á¤ÇÏ´Â ºÎºÐÀÔ´Ï´Ù. grub ¼±ÅÃÈ­¸é¿¡¼­ Ưº°È÷ ¼±ÅÃÇÏÁö ¾ÊÀ¸¸é
¿©±â¿¡ ¼³Á¤µÇ¾îÁø °ª¿¡ ÇØ´çÇÏ´Â ¿î¿µÃ¼Á¦¸¦ ·ÎµùÇÕ´Ï´Ù. ÇöÀç ¼³Á¤ÀÎ 0°ªÀº ¾Æ·¡ Ç׸ñÁß
¿¡¼­ Á¦ÀÏ ¸ÕÀú ¼³Á¤µÇ¾î ÀÖ´Â ¿î¿µÃ¼Á¦¸¦ ¸»ÇÕ´Ï´Ù.
 
timeout=10
grub ºÎƮȭ¸é¿¡¼­ÀÇ ´ë±â½Ã°£ÀÔ´Ï´Ù. ´ÜÀ§´Â ÃÊÀÔ´Ï´Ù. ÇöÀç ¼³Á¤Àº 10ÃÊ°£ ¼±ÅÃÀÌ ¾øÀ¸¸é
default¿¡ ¼³Á¤µÈ °ªÀ¸·Î ºÎÆõ˴ϴÙ.
 
splashimage=(hd0,3)/boot/grub/splash.xpm.gz
ºÎÆ® È­¸éÀÇ ¹è°æÀ̹ÌÁö¸¦ ÁöÁ¤ÇÏ´Â ºÎºÐÀÔ´Ï´Ù. xpmÇüÅÂÀÇ ±×¸²À̹ÌÁö¸¦ ¾ÐÃàÇÑ xpm.gzÆÄÀÏ
À» »ç¿ëÇÕ´Ï´Ù. (hd0,3)ÀÇ ¶æÀº /dev/hda4¶ó´Â ¶æÀÔ´Ï´Ù.
 
±âº»±¸Á¶
title ºÎÆ®_¿£Æ®¸®_¼³¸í
root (Çϵåµð½ºÅ©µð¹ÙÀ̽º¸í,ºÎÆ®ÆÄƼ¼Ç¸í)
kernel /Ä¿³ÎÀ̹ÌÁö°æ·Î ro root=·çÆ®µð¹ÙÀ̽º¸í
initrd /ÃʱâÈ­¿¡_ÇÊ¿äÇÑ_À̹ÌÁö°æ·Î
 
7) ½Ã½ºÅÛ ¸®ºÎÆÃ
¾÷µ¥ÀÌÆ®µÈ ÃÖ½ÅÄ¿³Î·Î ºÎÆÃÇÕ´Ï´Ù.
 
8) HDD ¼ÓµµÃ¼Å©
Ä¿³Î¾÷µ¥ÀÌÆ® ÈÄ Çϵåµð½ºÅ© ¼ÓµµÃ¼Å©¸¦ ÇÕ´Ï´Ù.
UDMA(Ultra DMA) »ç¿ë¿©ºÎ üũ
¹ö½º¸¦ ÅëÇÏ¿© Çϵåµð½ºÅ© µå¶óÀ̺ê¿Í ·¥°£¿¡ µ¥ÀÌÅ͸¦ Àü¼ÛÇϱâ À§ÇÑ ÇÁ·ÎÅäÄݷμ­, ÀÌÀüÀÇ DMA ÀÎÅÍÆäÀ̽º º¸´Ù 2¹è ÀÌ»óÀÇ ¼Óµµ¸¦ Çâ»ó½ÃÄÑ ÁÝ´Ï´Ù.

 
 
 
UDMA(Ultra DMA) ¼³Á¤

 
 
 
UDMA(Ultra DMA) ÇØÁ¦

 
 
 
HDD Àб⠼ӵµ üũ
´ÙÀ½Àº ÃÊ´ç 24MByte Àб⠼ӵµ¸¦ ³ªÅ¸³»°í ÀÖ½À´Ï´Ù.

 
 
--------------------------------------------------------------------------------------- 
 
3. ½Ã½ºÅÛ ¿î¿µ ½ºÅ©¸³Æ® È°¿ë

1) addon »ç¿ëÀÚ°ü¸® ¸í·É¾î
addon ¸í·É¾î´Â ÀÏ¹Ý ½©°èÁ¤ »ý¼º, ¾ÆÆÄÄ¡ VirtualHost ¹× /etc/mail/local-host-names µî·ÏÀ» Çѹø¿¡ ¼³Á¤ÇÒ ¼ö ÀÖ´Â ¸í·É¾îÀÔ´Ï´Ù.
½ºÅ©¸³Æ® °æ·Î : /root/bin/addon

 
 
 
¨ç »ç¿ë¹æ¹ý
[root@nextline bin]# /root/bin/addon nextline[°èÁ¤¸í] nextline.co.kr[µµ¸ÞÀÎ]
À§¿¡¼­ ÀÔ·ÂÇÑ °èÁ¤(nextline)ÀÇ È¨µð·ºÅ丮°¡ µµ¸ÞÀÎ(nextline.co.kr)ÀÇ DocumentRoot ·Î ±âº» ¼³Á¤µË´Ï´Ù.
-> nextline ÀÇ ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϽʽÿÀ : ***** [»ý¼ºÇÑ °èÁ¤ÀÇ ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.]
-> ¼³Ä¡¿Ï·á! [À¥ + ¸ÞÀϼ­¹ö Àç°¡µ¿ ¿ä¸Á] [addon ¸í·É¾î ½ÇÇà ÈÄ ¾ÆÆÄÄ¡¿Í sendmail¿¡ Àû¿ëµÉ ¼ö ÀÖµµ·Ï µ¥¸óÀ» Àç°¡µ¿ ÇϽñ⠹ٶø´Ï´Ù.]

 
 
¨è °èÁ¤»ý¼º È®ÀÎ
ftpÀ» ÀÌ¿ëÇÏ¿© nextline °èÁ¤ÀÌ Á¤»óÀûÀ¸·Î »ý¼ºµÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.

 
 
 
»ý¼ºµÈ nextline °èÁ¤À¸·Î Á¤»óÀûÀ¸·Î ftp¿¡ Á¢¼ÓµÈ È­¸éÀÔ´Ï´Ù.[µµ¸ÞÀÎ ¸®Á®ºù ŸÀÓÀ¸·Î ÀÎÇØ ¿¬°áµÇÁö ¾ÊÀ» ½Ã FTPÁÖ¼Ò¶õ¿¡ ¾ÆÀÌÇǸ¦ ±âÀÔÇϽñ⠹ٶø´Ï´Ù.]

 
 
 
¨é ¾ÆÆÄÄ¡ ¼³Á¤È®ÀÎ(httpd.conf)

 
 
addon ¸í·É¾î¸¦ ÅëÇØ ¼³Á¤ÇÑ nextline.co.kr µµ¸ÞÀÎÀÌ VirtualHost¿¡ ÀÚµ¿ µî·ÏµÇ¾î ÀÖ½À´Ï´Ù.

DocumentRoot /home/nextline/public_html
ServerName nextline.co.kr
ServerAlias www.nextline.co.kr


 
 
 
¨ê /etc/mail/ local-host-names È®ÀÎ

 
¨ë µ¥¸ó Àç°¡µ¿
¾ÆÆÄÄ¡ µ¥¸ó Àç°¡µ¿
[root@nextline ~]# /usr/local/apache/bin/apachectl restart
Sendmail µ¥¸ó Àç°¡µ¿
[root@nextline ~]# /etc/rc.d/init.d/sendmail restart

 
 
2) mail ¸ÞÀÏ°èÁ¤°ü¸® ¸í·É¾î
mailadd ¸í·É¾î´Â ¸ÞÀÏ°èÁ¤À» ÀÚµ¿ »ý¼º½ÃÄÑÁÖ´Â ¸í·É¾îÀÔ´Ï´Ù.
¨ç »ç¿ë¹æ¹ý
[root@nextline ~]# /root/bin/mailadd next[°èÁ¤¸í] nextline@nextline.co.kr[¸ÞÀÏÁÖ¼Ò]   
next ÀÇ ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϽʽÿÀ: ***** [»ý¼ºÇÑ ¸ÞÀÏ°èÁ¤ÀÇ ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.]   
¼³Ä¡¿Ï·á! [¸ÞÀϼ­¹ö Àç°¡µ¿ ¿ä¸Á] [¸ÞÀϼ­¹ö¿¡ Àû¿ëÇϱâÀ§ÇØ sendmailÀ» Àç°¡µ¿ÇÕ´Ï´Ù.]

 
 
¨è /etc/mail/virtusertable È®ÀÎ ¹× sendmail µ¥¸ó Àç°¡µ¿

 
 
¨é ¸ÞÀÏ°èÁ¤ ÀÛµ¿È®ÀÎ
»ý¼ºÇÑ ¸ÞÀÏ°èÁ¤ÀÌ Á¤»óÀûÀ¸·Î ÀÛµ¿ÇÏ´ÂÁö ¾Æ¿ô·è ¼ÂÆÃÀ» ÅëÇØ È®ÀÎÇÕ´Ï´Ù.
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­(Outlook-Express, Microsoft Outlook ¼³Á¤Çϱâ)
http://nextline.net/?inc=support&html=manual#z
 
3) dbadd µðºñ°èÁ¤ °ü¸®¸í·É¾î
µ¥ÀÌÅÍ º£À̽º °èÁ¤ ¹× µðºñ¸¦ ÀÚµ¿»ý¼ºÇØÁÖ´Â ¸í·É¾î ÀÔ´Ï´Ù.
¨ç »ç¿ë¹ý
[root@nextline ~]# /root/bin/dbadd nextline[µ¥ÀÌÅͺ£À̽º¸í] nextline[Æнº¿öµå]
Enter password: [mysql root Æнº¿öµåÀ» ÀÔ·ÂÇÕ´Ï´Ù.]
µ¥ÀÌÅͺ£À̽º¸íÀ¸·Î ÀÔ·ÂÇÑ nextline°¡ µðºñÀ¯Àú¸í°ú µ¿ÀÏÇÏ°Ô ¼³Á¤µË´Ï´Ù.

 
¨è µ¥ÀÌÅͺ£À̽º °èÁ¤ È®ÀÎ
À§¿¡¼­ »ý¼ºÇÑ nextline °èÁ¤À¸·Î µ¥ÀÌÅͺ£À̽º¿¡ Á¤»óÀûÀ¸·Î ·Î±×ÀÎ µÇ´Â È­¸éÀÔ´Ï´Ù.
[root@nextline ~]# mysql -u nextline -p
Enter password:[nextline µ¥ÀÌÅͺ£À̽º Æнº¿öµåÀ» ÀÔ·ÂÇÕ´Ï´Ù.]

 
 
4) set_dns Ãʱ⠳×ÀÓ¼­¹ö°ü¸® ¸í·É¾î
set_dns ½ºÅ©¸³Æ®´Â ÀÚü³×ÀÓ¼­¹ö¸¦ ±¸ÃàÇÒ ½Ã »ç¿ëµÇ´Â ¸í·É¾î·Î Ãʱ⠳×ÀÓ¼­¹ö ¼³Á¤À» ÀÚµ¿À¸·Î ¼³Á¤ÇØÁÖ´Â ¸í·É¾îÀÔ´Ï´Ù.

¨ç »ç¿ë¹æ¹ý
[root@nextline ~]# /root/bin/set_dns nextline.co.kr
set_dns ´Â Ãʱ⠳×ÀÓ¼­¹ö ¼ÂÆÃÅøÀÔ´Ï´Ù -> set_dns ·Î ³×ÀÓ¼­¹ö ¼Â¾÷À» ÁøÇàÇϽðڽÀ´Ï±î ? [y/n]: [±âº»°ª n]: y [y¸¦ ÀÔ·ÂÇÏ¿© set_dnsÀ» ÀÌ¿ëÇØ ³×ÀÓ¼­¹ö ¼³Á¤À» ÇÕ´Ï´Ù.]
¼³Ä¡¿Ï·á! [³×ÀÓ¼­¹ö Àç°¡µ¿ ¿ä¸Á][³×ÀÓ¼­¹ö¿¡ Àû¿ëÇϱâÀ§ÇØ namedÀ» Àç°¡µ¿ ÇÕ´Ï´Ù.]

 
   
¨è /etc/named.conf È®ÀÎ

 
 

 
 
¨é zone ÆÄÀÏÈ®ÀÎ
[root@nextline ~]# cat /var/named/zone-nextline.co.kr

 
   
¨ê named µ¥¸ó Àç°¡µ¿
³×ÀÓ¼­¹ö¿¡ nextline.co.kr µµ¸ÞÀÎÀÇ ¼³Á¤³»¿ëÀ» Àû¿ë½ÃÅ°±â À§ÇØ named µ¥¸óÀ» Àç°¡µ¿ ÇÕ´Ï´Ù.
[root@nextline ~]# /etc/rc.d/init.d/named restart

 
   
5) APACHE, PHP, MYSQL ¿¬µ¿ ÀÚµ¿ÀνºÅç
¨ç apm_install¸¦ ÀÌ¿ëÇÑ A.P.M ÀÚµ¿¼³Ä¡(Ãʱ⠼³Ä¡¿¡ »ç¿ë)
½ºÅ©¸³Æ®°æ·Î : [root@nextline ~]# /root/bin/apm/apm_install

 
 
 
apm_install¸¦ ÀÌ¿ëÇÑ A.P.M ÀÚµ¿¼³Ä¡ (³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­)
http://nextline.net/?inc=support&html=pds_view&no=108&name=¸®´ª½º&home=Apache
¨è apm_reinstall¸¦ ÀÌ¿ëÇÑ A.P.M ÀÚµ¿¼³Ä¡(A.P.M »èÁ¦ ÈÄ À缳ġ½Ã »ç¿ë)
apm_install ¿¡¼­ º¸¾È¼³Á¤ÀÌ Á¦¿ÜµÈ ½ºÅ©¸³Æ®ÀÔ´Ï´Ù. Ãʱâ apm_install ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÏ¿© ¼³Ä¡ÇϽŠ°æ¿ì º¸¾È ¼³Á¤ÀÌ ÀÌ¹Ì ¿Ï·áµÈ »óÅÂÀ̹ǷΠº¸¾È ¼³Á¤ Áߺ¹À¸·Î ÀÎÇÑ ¿À·ù¸¦ ¹ß»ýµÇÁö ¾Êµµ·Ï Ãʱ⠼³Ä¡¸¦ Á¦¿ÜÇÑ A.P.M À缳ġ½Ã¿¡´Â apm_reinstall ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÏ¿© ¼³Ä¡ÇÕ´Ï´Ù.
½ºÅ©¸³Æ®°æ·Î : [root@nextline ~]# /root/bin/apm/apm_install

 
 
¨é apm_uninstall¸¦ ÀÌ¿ëÇÑ A.P.M ÀÚµ¿»èÁ¦
½ºÅ©¸³Æ®°æ·Î : [root@nextline ~]# /root/bin/apm/apm_uninstall

 
   
apm_uninstall¸¦ ÀÌ¿ëÇÑ A.P.M ÀÚµ¿»èÁ¦ (³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­)
http://nextline.net/?inc=support&html=pds_view&no=110&name=¸®´ª½º&home=Apache
¨ê apm_phpupdate¸¦ ÀÌ¿ëÇÑ PHP ÀÚµ¿¾÷±×·¹À̵å
½ºÅ©¸³Æ®°æ·Î : [root@nextline ~]# /root/bin/apm/apm_phpupdate

 
 
apm_phpupdate¸¦ ÀÌ¿ëÇÑ PHP ÀÚµ¿¾÷±×·¹À̵å (³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­)
http://nextline.net/?inc=support&html=pds_view&no=109&name=¸®´ª½º&home=PHP
¨ë APM ¼Ò½º¼³Ä¡
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=116&name=¸®´ª½º&home=Apache
 
--------------------------------------------------------------------------------------- 
4. ½Ã½ºÅÛ º¸¾È ¼³Á¤
 
1) logout ½Ã command history »èÁ¦Çϱâ
root·Î ·Î±×ÀνúÎÅÍ »ç¿ëÇß´ø ¸í·É¾îÀÇ »ç¿ë±â·ÏÀ» ·Î±×¾Æ¿ô½Ã¿¡´Â ¹Ýµå½Ã Áö¿ìµµ·Ï ¼³Á¤ÇÕ´Ï´Ù.
¼³Á¤ÆÄÀÏ : /root/.bash_logout
/etc/skel/.bash_logout ¿¡ µî·ÏÇϸé ÀϹݰèÁ¤ »ý¼º½Ã¿¡µµ Àû¿ëµË´Ï´Ù.

 

 
   
2) ÀÚµ¿ ·Î±×¾Æ¿ô ȯ°æº¯¼ö ¼³Á¤
·Î±×ÀÎÈÄ ¾Æ¹«·± ÀÔ·ÂÀÌ ¾øÀ» °æ¿ìÀÇ ÀÚµ¿ ·Î±×¾Æ¿ô½Ã°£ µîÀÇ ¼³Á¤À» Ãß°¡ÇÕ´Ï´Ù.
[root@nextline ~]# vi /etc/profile

 
 
º¯°æµÈ profileÀ» Àû¿ëÇÕ´Ï´Ù.
[root@nextline ~]# source /etc/profile
 
3) su ¸í·É¾î Á¦ÇÑÇϱâ
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=51&name=¸®´ª½º&home=º¸¾È
 
4) PAM ¹× ulimit¸¦ È°¿ëÇÑ ¸®¼Ò½º(resource) Á¦ÇÑ
½Ã½ºÅÛ ÀÚ¿øÀ» ³Ê¹« ¸¹ÀÌ »ç¿ëÇϴ ƯÁ¤ÇÑ À¯Àú³ª ÇÁ·Î±×·¥ÀÇ ¹«ÇÑ·çÇÁ¹æÁöÇϱâ À§ÇÑ ¼³Á¤ÀÔ´Ï´Ù. ¼­ºñ½º °ÅºÎ°ø°Ý(ÇÁ·Î¼¼½º¼ö, ¸Þ¸ð¸®»ç¿ë·® µî) ¿¹¹æ
#»ç¿ëÀÚ°¡ ·Î±×Àνà Àû¿ëµÊ
[root@nextline ~]# vi /etc/pam.d/login

 
 
[root@nextline ~]# vi /etc/security/pam_limits.so

 
 
*     soft    core    0  #CORE ÆÄÀÏÀ» »ý¼ºÇÏÁö ¾Ê½À´Ï´Ù.
*     hard    rss     10000   #»ç¿ë °¡´ÉÇÑ ¸Þ¸ð¸®¸¦ 5M·Î Á¦ÇÑÇÕ´Ï´Ù.
@     hard    nproc   20 # »ý¼º ÇÁ·Î¼¼½º¸¦ 20°³·Î Á¦ÇÑÇÕ´Ï´Ù.
@nextline  soft    nproc   10 # »ý¼º ÇÁ·Î¼¼½º¸¦ 10°³·Î Á¦ÇÑÇÕ´Ï´Ù.
@nextline  hard    nproc   30 # »ý¼º ÇÁ·Î¼¼½º¸¦ 30°³·Î Á¦ÇÑÇÕ´Ï´Ù.
@nextline  hard    maxlogins    4  # µ¿½ÃÁ¢¼ÓÀ» 4°³·Î Á¦ÇÑÇÕ´Ï´Ù.
*     hard    maxlogins    6  # µ¿½ÃÁ¢¼ÓÀ» 6°³·Î Á¦ÇÑÇÕ´Ï´Ù.
* : ¸ðµçÀ¯Àú
@users : users¶ó´Â ±×·ì¿¡ ¼ÓÇÏ´Â À¯Àú
hard : Àý´ë ÇѰ踦 ³ÑÀ» ¼ö ¾øÀ½
 
maxlogins ¿¡ ¼³Á¤µÈ °ª ÀÌ»ó Á¢¼Ó½Ã /var/log/messages ¿¡ ´ÙÀ½°ú °°Àº ·Î±×°¡ ±â·ÏµË´Ï´Ù.
Mar 20 00:31:45 ns pam_limits[29668]: Too many logins (max 4) for nextline
 
5) SUID¿Í SGID ÆÄÀÏ ¹× µð·ºÅ丮
ÀÏ¹Ý À¯Àú ±ÇÇÑÀ¸·Î suid/sgid°¡ ¼³Á¤µÈ ÆÄÀÏÀ» ½ÇÇàÇÒ ¶§¿¡´Â ÇØ´ç ÆÄÀÏÀÇ ¼ÒÀ¯ÀÚ ¶Ç´Â ¼ÒÀ¯±×·ì ±ÇÇÑÀ¸·Î ÀÛµ¿ÇÏ°Ô µÇ¹Ç·Î suid/sgid´Â º¸¾ÈÀûÀÎ °üÁ¡¿¡¼­ ¸Å¿ì Áß¿äÇÑ ¿ªÇÒÀ» ÇÕ´Ï´Ù. ÀÌ ¶§¹®¿¡ /usr/sbin/sendmail°ú °°ÀÌ ÀüÅëÀûÀ¸·Î root ±ÇÇÑÀÇ suid/sgid°¡ ¼³Á¤µÈ ÆÄÀÏ¿¡¼­ º¸¾È Ãë¾à¼ºÀÌ ¸¹ÀÌ ¹ß°ßµÈ °ÍÀÌ »ç½ÇÀÔ´Ï´Ù. µû¶ó¼­ Ãʱ⠽ýºÅÛ ±¸Ãà½Ã »Ó¸¸ ¾Æ´Ï¶ó Á¤±âÀûÀ¸·Î ½Ã½ºÅÛ¿¡¼­ suid/sgid°¡ ¼³Á¤µÈ ÆÄÀÏÀ» ¸ð´ÏÅ͸µ ÇÏ¿© suid/sgid°¡ ºÒÇÊ¿äÇÏ´Ù¸é ÆÄÀÏ ÀÚü¸¦ »èÁ¦ Çϰųª sºñÆ®¸¦ ÇØÁ¦ÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù.
 
[root@nextline ~]# find / -type f \( -perm 4000 –o –perm -2000 \)
¶Ç´Â
[root@nextline ~]# find / -type f –perm +6000 –ls
 
À§ ¸í·É¾î ´ÙÀ½°ú °°Àº ÆÄÀϵéÀÌ Ãâ·ÂµË´Ï´Ù.(¹èÆ÷ÆÇÀ̳ª ¹öÀü¿¡ µû¶ó °á°ú°¡ ´Ù¸¦ ¼ö ÀÖ½À´Ï´Ù.)
 
CenOS 4.5 (2.6.9-67.0.4.ELsmp) ±âÁØ
/usr/lib/mc/cons.saver
/usr/sbin/lockdev
/usr/sbin/sendmail.sendmail
/usr/sbin/utempter
/usr/sbin/ccreds_validate
/usr/libexec/pt_chown
/usr/libexec/openssh/ssh-keysign
/usr/kerberos/bin/ksu
/usr/bin/ssh-agent
/usr/bin/lppasswd
/usr/bin/lockfile
/usr/bin/slocate
/usr/bin/sg
/usr/bin/jfbterm
/bin/su
/sbin/pam_timestamp_check
 
suid°¡ ¼³Á¤µÈ ÆÄÀÏ¿¡¼­ sºñÆ® ÇØÁ¦
[root@nextline ~]# chmod u-s /usr/sbin/suid_file
suid°¡ ¼³Á¤µÈ ÆÄÀÏ¿¡¼­ sºñÆ® ¼³Á¤
[root@nextline ~]# chmod u+s /usr/sbin/suid_file
sgid°¡ ¼³Á¤µÈ ÆÄÀÏ¿¡¼­ sºñÆ® ÇØÁ¦
[root@nextline ~]# chmod g-s /usr/sbin/suid_file
sgid°¡ ¼³Á¤µÈ ÆÄÀÏ¿¡¼­ sºñÆ® ¼³Á¤
[root@nextline ~]# chmod g+s /usr/sbin/suid_file
 
6) ¹«¼Ò¼Ó ÆÄÀÏã¾Æ ¼ÒÀ¯±Ç ºÎ¿©Çϱâ
[root@nextline ~]# find / -nouser -o –nogroup
[root@nextline ~]# find / \( -nouser -o -nogroup \) \-exec chown root.root {} \;
 
7) /dev ¿¡ device ÆÄÀÏ¿ÜÀÇ °ÍÀÌ ÀÖ´ÂÁö È®ÀÎ
[root@nextline ~]# find /dev -type f
/dev/MAKEDEV µî°ú °°ÀÌ device ¸¦ °ü¸®ÇÏ°íÀÚ ÇÏ´Â ÆÄÀÏ ÀÌ¿ÜÀÇ °ÍÀÌ °Ë»öµÇ¸é ÀÏ´Ü ÀǽÉÇغÁ¾ß ÇÕ´Ï´Ù.
CenOS 4.5 (2.6.9-67.0.4.ELsmp) ±âÁØ

 
 
8) ¿ø°ÝÁ¢¼ÓÇã¿ëÆÄÀÏ »ý¼º ¿©ºÎ Á¡°Ë
.rhosts ÆÄÀÏÀº ¿ø°Ý¿¡¼­ Æнº¿öµå ÀÎÁõ¾øÀÌ ¹Ù·Î Á¢¼ÓÇϱâ À§Çؼ­ »ç¿ëµÇ´Â ÆÄÀÏÀÔ´Ï´Ù.
 
[root@nextline ~]# find / -name .rhosts -exec ls -l {} \;
[root@nextline ~]# find / -name .rhosts -exec cat {} \;
 
9) ¼û±èÆÄÀÏ ¶Ç´Â ºñÁ¤»óÀûÀÎ ÆÄÀÏ Á¸Àç ¿©ºÎ Á¡°Ë
[root@nextline ~]# find / -name ".. " -print -xdev
[root@nextline ~]# find / -name ".*" -print -xdev | cat -v
[root@nextline ~]# find / -name ".*" \-exec ls -alF {} \;
 
10) ÆÄÀϽýºÅÛ ¸¶¿îÆ®
À¥ÇØÅ·½Ã ÇØÅ·¿¡ ÇÊ¿äÇÑ ÆÄÀÏÀ̳ª ¹éµµ¾î ½ÇÇà ÆÄÀÏÀÌ ¾÷·ÎµåµÇ´Â °÷À¸·Î /tmp¿Í /dev/shm µð·ºÅ丮°¡ ÁÖ·Î ÀÌ¿ëµË´Ï´Ù.
ÀÌ µð·ºÅ丮´Â ´©±¸³ª ÀÐ°í ¾µ ¼ö ÀÖ´Â °÷À¸·Î °ø°ÝÀÚµéÀÌ ÀÏ¹Ý À¯Àú ±ÇÇÑÀ» ¾òÀº °æ¿ì ÀÌ µð·ºÅ丮¿¡ base ±âÁö¸¦ ±¸Ãà ÇÏ´Â °æ¿ì°¡ ¸¹½À´Ï´Ù. ±×·¯¹Ç·Î, /tmp ´Â ¼­¹öÀÇ °æ¿ì ¹Ýµå½Ã º°µµÀÇ ÆÄƼ¼ÇÀ¸·Î ³ª´©¾î noexec, nosuid, nodev ¿É¼ÇÀ» ¼³Á¤ÇÏ¿© ÇØÅ·¿¡ ÀÌ¿ëµÇ´Â ÆÄÀÏÀÌ ¾÷·Îµå µÇ´õ¶óµµ ½ÇÇàÀ» ±ÝÁö½ÃÄÑ ¹éµµ¾î Æ÷Æ®°¡ ¿ÀǵǴ °ÍÀ» ¸·µµ·Ï ÇÕ´Ï´Ù.
¸¶¿îÆ® ¿É¼Ç ¼³¸í
 
ÆÄÀϽýºÅÛ ¸¶¿îÆ® : fstab
¼³Á¤È­ÀÏ °æ·Î : /etc/fstab
LABEL=/  /  ext3    defaults   1 1
none     /dev/pts     devpts  gid=5,mode=620  0 0
none     /proc   proc    defaults   0 0
none     /sys    sysfs   defaults   0 0
LABEL=/usr    /usr    ext3    defaults,nodev   1 2
LABEL=/var    /var    ext3    defaults,nodev   1 2
/dev/sda2     swap    swap    defaults   0 0
none     /dev/shm     tmpfs   defaults,noexec   0 0
LABEL=/home   /home  ext3   defaults,nosuid,usrquota,data=journal,noatime   1 2
LABEL=/tmp    /tmp    ext3    defaults,noexec,nosuid        1 2
 
[ÆÄÀϽýºÅÛ ÀåÄ¡¸í] [¸¶¿îÆ® Æ÷ÀÎÆ®] [ÆÄÀϽýºÅÛ Á¾·ù] [¿É¼Ç] [dump°ü·Ã¼³Á¤] [ÆÄÀÏÁ¡°Ë ¿É¼Ç]
 
-ÆÄÀϽýºÅÛ ÀåÄ¡¸í : ÀåÄ¡¸íÀ» ÁöÁ¤
ex) /dev/hda2
 
-¸¶¿îÆ® Æ÷ÀÎÆ® : ÀåÄ¡°¡ ¿¬°áµÈ ¸¶¿îÆ® ÁöÁ¡
ex) /home
 
-ÆÄÀϽýºÅÛ Á¾·ù : ÆÄƼ¼ÇÀÌ »ç¿ëÇÏ´Â ÆÄÀϽýºÅÛ ÁöÁ¤
ex) ext2, ext3
 
-¿É¼Ç : ÆÄÀϽýºÅÛÀÇ ¼Ó¼ºÀ» ¼³Á¤ÇÏ´Â ¿É¼Ç
defaults (rw, nouser,auto,exec suid ¼Ó¼ºÀ» ¸ðµÎ °¡Áö´Â ¿É¼Ç)
auto : ºÎÆýà ÀÚµ¿ ¸¶¿îÆ®
noauto : ºÎÆýà ÀÚµ¿¸¶¿îÆ® ¾ÈÇÔ
exec : ½ÇÇàÆÄÀÏÀÌ ½ÇÇàµÇ´Â °ÍÀ» Çã¿ë
no exec : ½ÇÇàÆÄÀÏÀÌ ½ÇÇàµÇ´Â °ÍÀ» Çã¿ë ¾ÈÇÔ
suid : setuid, setgidÀÇ »ç¿ëÀ» Çã¿ëÇÏ´Â ¿É¼Ç
nosuid : setuid, setgidÀÇ »ç¿ëÀ» °ÅºÎ
ro (read only) : Àбâ Àü¿ë
rw (ead write) : ÀÐ°í ¾²±â °¡´É
user : ÀÏ¹Ý °èÁ¤ »ç¿ëÀڵ鵵 ¸¶¿îÆ® ÇÒ ¼ö ÀÖ´Â ¿É¼Ç
nouser : root¸¸ mount °¡´É
usrquota : ÀÏ¹Ý »ç¿ëÀÚ quotaÀû¿ë
grpquota : ±×·ì quota Àû¿ë
 
-dump °ü·Ã ¼³Á¤ : 0 ¶Ç´Â 1À» ÁöÁ¤
0 : ´ýÇÁµÇÁö ¾ÊÀº ÆÄÀϽýºÅÛ
1 : µ¥ÀÌÅÍ ¹é¾÷À» À§ÇØ dump°¡´É
 
-ÆÄÀÏÁ¡°Ë ¿É¼Ç :0,1,2°ªÀ» ÁöÁ¤
0 : ºÎÆýà fsck¸¦ »ç¿ëÇÏÁö ¾ÊÀ½
1 : ·çÆ® ÆÄÀϽýºÅÛÀ» ÀǹÌ
2 : ·çÆ® ÆÄÀϽýºÅÛ ÀÌ¿ÜÀÇ ÆÄÀϽýºÅÛÀ» ÀǹÌ
 
11) ch_permÀ» ÅëÇÑ ÆÄÀÏ ¹× µð·ºÅ丮 ±ÇÇÑ ¼³Á¤
ch_perm ½ºÅ©¸³Æ®¿¡ ÀÇÇØ kill, /etc/service, µî ÁÖ¿ä ¼³Á¤ÆÄÀÏ ¹× ¸í·É¾î¿¡ ´ëÇÑ ÆÛ¹Ì¼Ç º¸¾ÈÀÌ crontab¿¡ ÀÇÇØ ÁÖ±âÀûÀ¸·Î ½ÇÇàµË´Ï´Ù.
 
ch_perm ½ºÅ©¸³Æ®´Â /root/bin/ch_perm °æ·Î¿¡ Á¸ÀçÇÕ´Ï´Ù.

 
 
ch_perm ½ºÅ©¸³Æ®´Â crontab¿¡ ÀÇÇØ ¸ÅÀÏ 03½Ã¿¡ ÁÖ±âÀûÀ¸·Î °»½ÅµÇ¾î ½© ¸í·É¾î ¹× ÁÖ¿ä ÆÄƼ¼ÇÀÇ Æ۹̼ÇÀ» Àç¼³Á¤ÇÕ´Ï´Ù.

 
 
ch_perm ÆÛ¹Ì¼Ç Á¶Á¤ ³»¿ë
rm /usr/sbin/adduser > /dev/null 2>&1
rm -rf /var/tmp /usr/tmp > /dev/null 2>&1
chattr +i /etc/services > /dev/null 2>&1
chmod 751 / > /dev/null 2>&1
chmod 701 /bin > /dev/null 2>&1
chmod 700 /boot > /dev/null 2>&1
chmod 1777 /tmp > /dev/null 2>&1
chmod 701 /dev > /dev/null 2>&1
chmod 755 /dev/shm > /dev/null 2>&1
chmod 751 /etc > /dev/null 2>&1
chmod 751 /home > /dev/null 2>&1
chmod 751 /lib/modules > /dev/null 2>&1
chmod 700 /mnt > /dev/null 2>&1
chmod 700 /root > /dev/null 2>&1
chmod 751 /sbin > /dev/null 2>&1
chmod 751 /usr > /dev/null 2>&1
chmod 751 /usr/local > /dev/null 2>&1
chmod 701 /usr/local/apache/cgi-bin > /dev/null 2>&1
chmod 700 /usr/local/apache/conf > /dev/null 2>&1
chmod 705 /usr/local/apache/htdocs > /dev/null 2>&1
chmod 701 /usr/local/apache/logs > /dev/null 2>&1
chmod 751 /usr/local/bin > /dev/null 2>&1
chmod 751 /usr/local/sbin > /dev/null 2>&1
chmod 700 /usr/local/src > /dev/null 2>&1
chmod 751 /usr/sbin > /dev/null 2>&1
chmod 750 /usr/src > /dev/null 2>&1
chmod 751 /var > /dev/null 2>&1
chmod 750 /var/log > /dev/null 2>&1
chmod 751 /var/named > /dev/null 2>&1
chmod 751 /var/run > /dev/null 2>&1
chmod 755 /var/tmp > /dev/null 2>&1
chmod 750 /etc/cron.* > /dev/null 2>&1
chmod 640 /etc/crontab > /dev/null 2>&1
chmod 750 /etc/default > /dev/null 2>&1
chmod 600 /etc/exports > /dev/null 2>&1
chmod 600 /etc/fstab > /dev/null 2>&1
chmod 600 /etc/hosts.allow > /dev/null 2>&1
chmod 600 /etc/hosts.deny > /dev/null 2>&1
chmod 600 /etc/inittab > /dev/null 2>&1
chmod 400 /etc/issue > /dev/null 2>&1
chmod 400 /etc/issue.net > /dev/null 2>&1
chmod 600 /etc/login.defs > /dev/null 2>&1
chmod 750 /etc/logrotate.d > /dev/null 2>&1
chmod 600 /etc/mtab > /dev/null 2>&1
chmod 650 /etc/my.cnf > /dev/null 2>&1
chmod 750 /etc/rc.d > /dev/null 2>&1
chmod 600 /etc/redhat-release > /dev/null 2>&1
chmod 750 /etc/rpm > /dev/null 2>&1
chmod 600 /etc/rpc > /dev/null 2>&1
chmod 600 /etc/securetty > /dev/null 2>&1
chmod 751 /etc/security > /dev/null 2>&1
chmod 700 /etc/skel > /dev/null 2>&1
chmod 750 /etc/ssh > /dev/null 2>&1
chmod 750 /etc/sysconfig > /dev/null 2>&1
chmod 750 /etc/xinetd.d > /dev/null 2>&1
chmod 750 /etc/vsftpd > /dev/null 2>&1
chown named /etc/named.conf > /dev/null 2>&1
chown named /etc/rndc.* > /dev/null 2>&1
chmod 700 /sbin/netreport > /dev/null 2>&1
chmod 111 /usr/bin/sudo > /dev/null 2>&1
chmod 550 /usr/bin/last > /dev/null 2>&1
chmod 550 /usr/bin/uptime > /dev/null 2>&1
chmod 700 /usr/sbin/groupdel > /dev/null 2>&1
chmod 600 /etc/httpd/conf/httpd.conf > /dev/null 2>&1
chmod 600 /etc/lilo.conf* > /dev/null 2>&1
chmod 600 /etc/logrotate.conf > /dev/null 2>&1
chmod 600 /etc/mail/access > /dev/null 2>&1
chmod 600 /etc/mail/local-host-names > /dev/null 2>&1
chmod 600 /etc/mail/virtusertable > /dev/null 2>&1
chmod 600 /etc/proftpd.conf > /dev/null 2>&1
chmod 600 /usr/local/apache/conf/*.conf > /dev/null 2>&1
chmod 600 /usr/local/apache/logs/*_log > /dev/null 2>&1
chmod 600 /var/log/httpd/*_log > /dev/null 2>&1
chmod 640 /etc/named.conf > /dev/null 2>&1
chmod 700 /bin/cat > /dev/null 2>&1
chmod 550 /bin/df > /dev/null 2>&1
chmod 550 /bin/dmesg > /dev/null 2>&1
chmod 700 /bin/echo > /dev/null 2>&1
chmod 700 /bin/kill > /dev/null 2>&1
chmod 700 /bin/ln > /dev/null 2>&1
chmod 700 /bin/mail > /dev/null 2>&1
chmod 700 /bin/mount > /dev/null 2>&1
chmod 550 /bin/netstat > /dev/null 2>&1
chmod 500 /bin/ping > /dev/null 2>&1
chmod 550 /bin/ps > /dev/null 2>&1
chmod 700 /bin/rpm > /dev/null 2>&1
chmod 700 /bin/touch > /dev/null 2>&1
chmod 700 /bin/umount > /dev/null 2>&1
chmod 700 /bin/uname > /dev/null 2>&1
chmod 700 /etc/logrotate.d > /dev/null 2>&1
chmod 700 /etc/rc.d/init.d/* > /dev/null 2>&1
chmod 700 /sbin/fdisk > /dev/null 2>&1
chmod 700 /sbin/ifconfig > /dev/null 2>&1
chmod 700 /sbin/pwdb_chkpwd > /dev/null 2>&1
chmod 700 /sbin/route > /dev/null 2>&1
chmod 700 /sbin/unix_chkpwd > /dev/null 2>&1
chmod 700 /usr/bin/at > /dev/null 2>&1
chmod 700 /usr/bin/c++ > /dev/null 2>&1
chmod 700 /usr/bin/chage > /dev/null 2>&1
chmod 700 /usr/bin/chattr > /dev/null 2>&1
chmod 700 /usr/bin/chfn > /dev/null 2>&1
chmod 700 /usr/bin/chsh > /dev/null 2>&1
chmod 700 /usr/bin/crontab > /dev/null 2>&1
chmod 700 /usr/bin/curl > /dev/null 2>&1
chmod 700 /usr/bin/file > /dev/null 2>&1
chmod 550 /usr/bin/find > /dev/null 2>&1
chmod 700 /usr/bin/free > /dev/null 2>&1
chmod 700 /usr/bin/ftp > /dev/null 2>&1
chmod 700 /usr/bin/gcc > /dev/null 2>&1
chmod 700 /usr/bin/gpasswd > /dev/null 2>&1
chmod 751 /usr/bin/host > /dev/null 2>&1
chmod 700 /usr/bin/lsattr > /dev/null 2>&1
chmod 700 /usr/bin/make > /dev/null 2>&1
chmod 700 /usr/bin/man > /dev/null 2>&1
chmod 700 /usr/bin/mc > /dev/null 2>&1
chmod 700 /usr/bin/msgfmt > /dev/null 2>&1
chmod 700 /usr/bin/nc > /dev/null 2>&1
chmod 700 /usr/bin/ncftp > /dev/null 2>&1
chmod 700 /usr/bin/ncftpbatch > /dev/null 2>&1
chmod 700 /usr/bin/ncftpbookmarks > /dev/null 2>&1
chmod 700 /usr/bin/ncftpget > /dev/null 2>&1
chmod 700 /usr/bin/ncftpls > /dev/null 2>&1
chmod 700 /usr/bin/ncftpput > /dev/null 2>&1
chmod 700 /usr/bin/newgrp > /dev/null 2>&1
chmod 700 /usr/bin/nmap > /dev/null 2>&1
chmod 700 /usr/bin/nslookup > /dev/null 2>&1
chmod 700 /usr/bin/objdump > /dev/null 2>&1
chmod 700 /usr/bin/oldps > /dev/null 2>&1
chmod 700 /usr/bin/passwd > /dev/null 2>&1
chmod 700 /usr/bin/patch > /dev/null 2>&1
chmod 700 /usr/bin/pmake > /dev/null 2>&1
chmod 750 /usr/bin/pstree > /dev/null 2>&1
chmod 700 /usr/bin/python > /dev/null 2>&1
chmod 750 /usr/bin/rcp > /dev/null 2>&1
chmod 700 /usr/bin/rlog > /dev/null 2>&1
chmod 750 /usr/bin/rlogin > /dev/null 2>&1
chmod 750 /usr/bin/rsh > /dev/null 2>&1
chmod 700 /usr/bin/scp > /dev/null 2>&1
chmod 700 /usr/bin/ncftpbatch > /dev/null 2>&1
chmod 700 /usr/bin/ncftpbookmarks > /dev/null 2>&1
chmod 700 /usr/bin/ncftpget > /dev/null 2>&1
chmod 700 /usr/bin/ncftpls > /dev/null 2>&1
chmod 700 /usr/bin/ncftpput > /dev/null 2>&1
chmod 700 /usr/bin/newgrp > /dev/null 2>&1
chmod 700 /usr/bin/nmap > /dev/null 2>&1
chmod 700 /usr/bin/nslookup > /dev/null 2>&1
chmod 700 /usr/bin/objdump > /dev/null 2>&1
chmod 700 /usr/bin/oldps > /dev/null 2>&1
chmod 700 /usr/bin/passwd > /dev/null 2>&1
chmod 700 /usr/bin/patch > /dev/null 2>&1
chmod 700 /usr/bin/pmake > /dev/null 2>&1
chmod 750 /usr/bin/pstree > /dev/null 2>&1
chmod 700 /usr/bin/python > /dev/null 2>&1
chmod 750 /usr/bin/rcp > /dev/null 2>&1
chmod 700 /usr/bin/rlog > /dev/null 2>&1
chmod 750 /usr/bin/rlogin > /dev/null 2>&1
chmod 750 /usr/bin/rsh > /dev/null 2>&1
chmod 700 /usr/bin/scp > /dev/null 2>&1
chmod 700 /usr/bin/sftp > /dev/null 2>&1
chmod 700 /usr/bin/skill > /dev/null 2>&1
chmod 700 /usr/bin/ssh > /dev/null 2>&1
chmod 750 /usr/bin/telnet > /dev/null 2>&1
chmod 550 /usr/bin/top > /dev/null 2>&1
chmod 700 /usr/bin/users > /dev/null 2>&1
chmod 700 /usr/bin/vmstat > /dev/null 2>&1
chmod 550 /usr/bin/w > /dev/null 2>&1
chmod 700 /usr/bin/wget > /dev/null 2>&1
chmod 700 /usr/bin/whereis > /dev/null 2>&1
chmod 700 /usr/bin/which > /dev/null 2>&1
chmod 550 /usr/bin/who > /dev/null 2>&1
chmod 700 /usr/bin/whoami > /dev/null 2>&1
chmod 700 /usr/bin/whois > /dev/null 2>&1
chmod 700 /usr/bin/yes > /dev/null 2>&1
chmod 700 /usr/local/bin/php > /dev/null 2>&1
chmod 700 /usr/sbin/ping6 > /dev/null 2>&1
chmod 700 /usr/sbin/sshd > /dev/null 2>&1
chmod 700 /usr/sbin/tcpdump > /dev/null 2>&1
chmod 700 /usr/sbin/traceroute > /dev/null 2>&1
chmod 700 /usr/sbin/traceroute6 > /dev/null 2>&1
chmod 550 /usr/sbin/useradd > /dev/null 2>&1
chmod 550 /usr/sbin/userdel > /dev/null 2>&1
chmod 700 /usr/sbin/userhelper > /dev/null 2>&1
chmod 700 /usr/sbin/usermod > /dev/null 2>&1
chmod 700 /usr/sbin/usernetctl > /dev/null 2>&1
chmod 750 /bin/chmod > /dev/null 2>&1
chmod 500 /usr/bin/wall > /dev/null 2>&1
chmod 700 /usr/bin/write > /dev/null 2>&1
chmod 750 /usr/include > /dev/null 2>&1
chmod 751 /etc/mail > /dev/null 2>&1
chmod 751 /usr/local > /dev/null 2>&1
chmod 751 /usr/local/bin > /dev/null 2>&1
chmod 751 /usr/local/mysql > /dev/null 2>&1
chmod 751 /var/log > /dev/null 2>&1
chmod 751 /var/named > /dev/null 2>&1
chown root.users /bin/chmod > /dev/null 2>&1
ln -s /tmp /var/tmp > /dev/null 2>&1
 
12) ssh ¹«Â÷º° dos °ø°Ý¿¡ ´ëÇÑ ¹æ¾î
/var/log/secure ·Î±×¸¦ »ìÆ캸¸é ÀÏÁ¤ÇÑ ID¸¦ ÀÌ¿ëÇؼ­ SSH Á¢¼Ó ½Ãµµ¸¦ ÇÏ´Â °ÍÀ» º¼ ¼ö ÀÖÀ¸¸ç ÀÌ·± °ø°ÝÀº SSH Bruteforce(¹«Â÷º° °ø°Ý)·Î¼­, Æнº¿öµå »çÀü ÆÄÀÏÀ» ÀÌ¿ëÇؼ­ ¹Ì¸® ÁöÁ¤ÇÑ ¾ÆÀ̵ð¿Í ´ëÀÔÇÏ¿©, Á¢¼Ó °èÁ¤À» ¾Ë¾Æ ³»´Â ÇØÅ· ¹æ¹ýÀÔ´Ï´Ù.
 
SSH Bruteforce(¹«Â÷º° °ø°Ý)À» Â÷´ÜÇϱâ À§ÇØ ³Ø½ºÆ®¶óÀο¡¼­´Â ssh_dos_block.sh ½ºÅ©¸³Æ®¸¦ crontab¿¡ ÀÇÇØ ÁÖ±âÀûÀ¸·Î °ø°Ý½Ãµµ µ¥ÀÌÅ͸¦ ÁÖ±âÀûÀ¸·Î ¾÷µ¥ÀÌÆ® ÈÄ ÇØ´ç ¾ÆÀÌÇǸ¦ ÀÚµ¿ Â÷´Ü½ÃÅ°´Â ÅøÀ» Á¦°øÇÏ°í ÀÖ½À´Ï´Ù.
 
ssh_dos_block.sh ½ºÅ©¸³Æ®´Â /root/bin/ssh_dos_block.sh °æ·Î¿¡ Á¸ÀçÇÕ´Ï´Ù.

 
 
 
ssh_dos_block.sh ½ºÅ©¸³Æ®°¡ ¸Å 30Ãʸ¶´Ù ½ÇÇàµÇµµ·Ï crontab¿¡ µî·ÏµÇ¾î ÀÖ½À´Ï´Ù.

 
 
13) ¹éµµ¾î³ª ·çƮŶ ¹æ¾î¸¦ À§ÇÑ rkhunter ¹æ¾î
¹éµµ¾î³ª ·çƮŶÀ» ŽÁöÇÏ¿© ÀϹÝÀûÀ¸·Î ·çƮŶÀÌ »ç¿ëÇÏ´Â ÆÄÀÏ ¹× ¼û±è ÆÄÀÏÀÇ Á¸Àç¿©
ºÎ¸¦ ÆǺ°ÇØÁÖ¸ç, ½ÇÇà ½Ã °ü¸®ÀÚ¿¡°Ô °¢ ÆÄÆ®º°·Î üũ»çÇ×À» º¸¿©ÁÖ´Â ¸®Æ÷Æ®±â´ÉÀ» Á¦°øÇÏ´Â ÅøÀÔ´Ï´Ù.
 
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­(rkhunterÀ» ÅëÇÑ ½Ã½ºÅÛ ¹«°á¼º üũÇϱâ)
http://nextline.net/?inc=support&html=pds_view&no=125&name=¸®´ª½º&home=±âŸ
 
ÁÖ±âÀûÀ¸·Î rkhunter DBÀ» ¾÷µ¥ÀÌÆ® ÇÏ¿© ½ÅÁ¾ ·çƮŶÀ̳ª ¹éµµ¾î¿¡ ´ëºñÇÒ ¼ö ÀÖµµ·Ï  crontab¿¡ µî·ÏµÇ¾î ÀÖ½À´Ï´Ù.

 
 
14) ³Ø½ºÆ®¶óÀÎ ¹æÈ­º®(next_firewall) Á¤Ã¥¼³Á¤
¼³Á¤µµ±¸ : iptables
¹æÈ­º® °æ·Î : /root/bin/next_firewall

 
 
 
±âº» ·ê¼Â :
inbound  : ¿ÜºÎ¿¡¼­ ¼­¹ö·ÎÀÇ Á¢¼ÓÀº ´ÙÀ½ ¼­ºñ½ºÆ÷Æ®¿¡ ´ëÇؼ­¸¸ Çã¿ëÇÕ´Ï´Ù.
ftp (21)/ ssh(22) / smtp(25) / dns(53) / http(80) / pop3(110) / mysql(3306) / ping
outbound : ¼­¹ö¿¡¼­ ¿ÜºÎ·Î´Â ¸ðµç ¼­ºñ½ºÆ÷Æ®¸¦ Çã¿ëÇÕ´Ï´Ù.
 
Next_firewall
### ·ê¼Â ÃʱâÈ­
$IPTABLES -F
 
### ±âº»Á¤Ã¥ ¼³Á¤
$IPTABLES -P INPUT DROP
$IPTABLES -P FORWARD DROP
$IPTABLES -P OUTPUT ACCEPT
 
### Loopback Æ®·¡ÇÈ Çã¿ë
$IPTABLES -A INPUT -i lo -j ACCEPT
 
### ÀÚ±âÀÚ½ÅÀ» ¼Ò½º·Î ÇÏ´Â Æ®·¡ÇÈ Â÷´Ü
$IPTABLES -A INPUT -i eth0 -s $IP_ADDR -j DROP
$IPTABLES -A INPUT -i eth0 -s 127.0.0.0/8 -j DROP
 
### »óÅÂÃßÀû ¼³Á¤
$IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A INPUT -p tcp ! --syn -m state --state NEW -j DROP
$IPTABLES -A INPUT -p all -m state --state INVALID -j DROP
 
### ºñÁ¤»óÀû tcp-flags Â÷´Ü
$IPTABLES -A INPUT -p tcp --tcp-flags ACK,FIN FIN -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL NONE -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL PSH,FIN -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL URG,PSH,FIN -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,ACK,FIN -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,FIN,PSH -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,FIN,RST -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,FIN,RST,PSH -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,FIN,ACK,RST -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,ACK,FIN,RST,PSH -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags FIN,RST FIN,RST -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ACK,PSH PSH -j DROP
$IPTABLES -A INPUT -p tcp --tcp-flags ACK,URG URG -j DROP
 
### ¼­ºñ½ºÆ÷Æ® Ãß°¡/Á¦°Å¸¦ À§Çؼ­´Â, ¹Ýµå½Ã ¾Æ·¡ÀÇ ¼³Á¤¸¸ ¼öÁ¤ÇϽñ⠹ٶø´Ï´Ù.
### $IPTABLES ±¸¹®¾ÕÀÇ (#)ÁÖ¼® Á¦°ÅÈÄ, next_firewall ¸¦ Àç°¡µ¿ÇϽøé ÇØ´çÆ÷Æ®´Â È°¼ºÈ­ µË´Ï´Ù..
 
### ftp servive
$IPTABLES -A INPUT -p tcp --sport 1024: --dport 20 -m state --state NEW -j ACCEPT
$IPTABLES -A INPUT -p tcp --sport 1024: --dport 370 -m state --state NEW -j ACCEPT
 
### ssh servive
$IPTABLES -A INPUT -p tcp --sport 1024: --dport 37 -m state --state NEW -j ACCEPT
 
### telnet servive
#$IPTABLES -A INPUT -p tcp --sport 1024: --dport 23 -m state --state NEW -j ACCEPT
 
### smtp servive
$IPTABLES -A INPUT -p tcp --sport 1024: --dport 25 -m state --state NEW -j ACCEPT
 
### dns servive
$IPTABLES -A INPUT -p tcp --sport 1024: --dport 53 -m state --state NEW -j ACCEPT
$IPTABLES -A INPUT -p udp --sport 1024: --dport 53 -m state --state NEW -j ACCEPT
 
### http servive
$IPTABLES -A INPUT -p tcp --sport 1024: --dport 80 -m state --state NEW -j ACCEPT
 
### pop3 servive
$IPTABLES -A INPUT -p tcp --sport 1024: --dport 110 -m state --state NEW -j ACCEPT
 
### identd servive
$IPTABLES -A INPUT -p tcp --syn --dport 113 -j REJECT --reject-with tcp-reset
 
### imap servive
#$IPTABLES -A INPUT -p tcp --sport 1024: --dport 143 -m state --state NEW -j ACCEPT
 
### snmp servive
#$IPTABLES -A INPUT -p udp --sport 1024: --dport 161 -m state --state NEW -j ACCEPT
 
### https servive
#$IPTABLES -A INPUT -p tcp --sport 1024: --dport 443 -m state --state NEW -j ACCEPT
 
### rsync servive
#$IPTABLES -A INPUT -p tcp --sport 1024: --dport 873 -m state --state NEW -j ACCEPT
 
### mysql servive
$IPTABLES -A INPUT -p tcp --sport 1024: --dport 3306 -m state --state NEW -j ACCEPT
 
### ping servive
$IPTABLES -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
 
³Ø½ºÆ®¶óÀÎ ±âº»·ê¼Â ÀÌ¿Ü Æ÷Æ® Ãß°¡Çϱâ
 
### ¼­ºñ½º¸í
$IPTABLES -A INPUT -p tcp --sport 1024: --dport "Æ÷Æ®" -m state --state NEW -j ACCEPT
 
¹æÈ­º®(next_firewall) »ç¿ë¹ý :
¹æÈ­º® ½ÃÀÛ   : next_firewall start

 
¹æÈ­º® ÁßÁö   : next_firewall stop

 
¹æÈ­º® Àç°¡µ¿ : next_firewall restart

 
 
15) Ä¿³Î º¯¼ö Á¶Á¤
arp ½ºÇªÇÎ ¹× DDOS °ø°ÝÀ» Â÷´ÜÇϱâ À§ÇÑ Ä¿³Îº¯¼öµéÀÌ ¼³Á¤µÇ¾îÀÖ½À´Ï´Ù.
¼³Á¤È­ÀÏ °æ·Î : /etc/sysctl.conf
Àû¿ë¹æ¹ý : sysctl –p

 
# proxy arp¸¦ ¼³Á¤ÇÏÁö ¾Ê½À´Ï´Ù.
net.ipv4.conf.eth0.proxy_arp=0
net.ipv4.conf.lo.proxy_arp=0
net.ipv4.conf.default.proxy_arp=0
net.ipv4.conf.all.proxy_arp=0
 
# °ÔÀÌÆ®¿þÀ̷κÎÅÍÀÇ redirect¸¦ Çã¿ëÇÏÁö ¾ÊÀ½À¸·Î½á ½ºÇªÇÎÀ» ¸·±â À§ÇØ ¼³Á¤ÇÕ´Ï´Ù.
net.ipv4.conf.eth0.secure_redirects=0
net.ipv4.conf.lo.secure_redirects=0
net.ipv4.conf.default.secure_redirects=0
net.ipv4.conf.all.secure_redirects=0
 
# ½ºÇªÇÎÀ» ¸·±â À§ÇØ source route ÆÐŶÀ» Çã¿ëÇÏÁö ¾Ê½À´Ï´Ù.
net.ipv4.conf.eth0.accept_source_route=0
net.ipv4.conf.lo.accept_source_route=0
net.ipv4.conf.default.accept_source_route=0
net.ipv4.conf.all.accept_source_route=0
 
# Broadcast·ÎºÎÅÍ ¿À´Â ÇÎÀ» Â÷´ÜÇÔ(Smurt °ø°ÝÀ» Â÷´ÜÇÔ).
net.ipv4.icmp_echo_ignore_broadcasts=1
 
# IP ³ª TCP Çì´õ°¡ ±úÁø bad icmp packetÀ» ¹«½ÃÇÕ´Ï´Ù.
net.ipv4.icmp_ignore_bogus_error_responses=1
 
# ÀÚ½ÅÀÇ ³×Æ®¿öÅ©°¡ ½ºÇªÇÎµÈ °ø°ÝÁöÀÇ ¼Ò½º·Î ¾²ÀÌ´Â °ÍÀ» Â÷´ÜÇÕ´Ï´Ù.
net.ipv4.conf.eth0.rp_filter=2
net.ipv4.conf.lo.rp_filter=2
net.ipv4.conf.default.rp_filter=2
net.ipv4.conf.all.rp_filter=2
 
# bootp ÆÐŶÀ» Çã¿ëÇÏÁö ¾Ê½À´Ï´Ù.
net.ipv4.conf.eth0.bootp_relay=0
net.ipv4.conf.lo.bootp_relay=0
net.ipv4.conf.default.bootp_relay=0
net.ipv4.conf.all.bootp_relay=0
 
# ½ºÇªÇÎµÈ ÆÐŶÀ̳ª ¼Ò½º¶ó¿ìÆÃ, Redirect ÆÐŶ¿¡ ´ëÇØ ·Î±×ÆÄÀÏ¿¡ Á¤º¸¸¦ ³²±ä´Ù.
net.ipv4.conf.eth0.log_martians=1
net.ipv4.conf.lo.log_martians=1
net.ipv4.conf.default.log_martians=1
net.ipv4.conf.all.log_martians=1
 
# 1/100ÃÊ¿¡ ¹Þ¾ÆµéÀÌ´Â igmp "memberships"ÀÇ ¼ö
net.ipv4.igmp_max_memberships=1
 
# ¸Å¿ì º¹ÀâÇÑ »çÀÌÆ®¿¡¼­´Â ÀÌ °ªÀ» ´Ã¸®´Â °Íµµ °¡´ÉÇÏÁö¸¸ 64·Î µÎ´Â °ÍÀÌ Àû´çÇϸç
# ´õ ´Ã·ÈÀ» °æ¿ì¿¡´Â Å« ¹®Á¦°¡ ¹ß»ýÇÒ ¼öµµ ÀÖ½À´Ï´Ù..
net.ipv4.ip_default_ttl=64
 
# °ÔÀÌÆ®¿þÀÌ ¼­¹ö°¡ ¾Æ´Ñ ÀÌ»ó ÆÐŶÀ» Æ÷¿öµù ÇÒ ÇÊ¿ä´Â ¾ø´Ù.
net.ipv4.ip_forward=0
 
# fragmented packetÀÌ ¸Þ¸ð¸®¿¡ Á¸ÀçÇÏ´Â ½Ã°£À» 15ÃÊ·Î ¼³Á¤ÇÕ´Ï´Ù.
net.ipv4.ipfrag_time=15
 
# SYN_Flooding °ø°Ý¿¡ ´ëÇÑ ´ëºñ·Î ¹é·Î±×Å¥(Backlog Queue)°¡ °¡µæÂ÷¸é ´Ù¸¥ Á¢¼Ó ¿ä±¸¸¦ ¹Þ¾ÆµéÀÌÁö ¸øÇÕ´Ï´Ù.
net.ipv4.tcp_max_syn_backlog=1024
 
# TCP ¿¬°á¿¡¼­ Three-way Handshake°¡ ¼º°øÀûÀ¸·Î ÀÌ·ç¾îÁöÁö ¾ÊÀ¸¸é ´õ ÀÌ»ó ¼Ò½º °æ·Î¸¦ °Å½½·¯ ¿Ã¶ó°¡Áö ¾Êµµ·ÏÇÕ´Ï´Ù.
# µû¶ó¼­ ÀûÀýÇÑ ¿¬°á ¿äû¿¡ ´ëÇؼ­¸¸ ¿¬°áÀ» ¸Î´Â´Ù.
# syncookies°¡ ÀÛµ¿ÇÒ ¶§ SYN Flooding °ø°ÝÀÌ ÀÖÀ¸¸é messages ÆÄÀÏ¿¡ ¾Æ·¡¿Í °°Àº ³»¿ëÀÌ Ãâ·ÂµË´Ï´Ù.
# possible SYN flooding on port 80. Sending cookies.
net.ipv4.tcp_syncookies=1
 
# ÀÏÁ¤ÇÑ ½Ã°£°ú IPº°·Î º¸³»°í ¹Þ´Â SYN Àç½Ãµµ Ƚ¼ö¸¦ 3ȸ·Î Á¦ÇÑÇÕ´Ï´Ù.
# ÀÌ ¿É¼ÇÀº ½ºÇªÇεÈ(À§Á¶µÈ) ÁÖ¼Ò·Î ¿À´Â SYN ¿¬°áÀÇ ¾çÀ» ÁÙ¿©ÁØ´Ù.
# ±âº» °ªÀº 5(180 ÃÊ¿¡ ´ëÀÀ)À̸ç 255¸¦ ³ÑÁö ¾Ê¾Æ¾ß ÇÕ´Ï´Ù.
net.ipv4.tcp_syn_retries=3
 
# passive TCP Á¢¼Ó½Ãµµ°¡ ÀçÁ¢¼ÓÀ» Çϱâ À§ÇÑ SYNACKsÀÇ °ªÀ» Á¤ÇÕ´Ï´Ù. 255 º¸´Ù ³ô
# °Ô ÁöÁ¤ÇÒ ¼ö ¾ø´Ù. ±âº»°ªÀº 5À̸ç, 180ÃÊ¿¡ ´ëÀÀÀÌ µË´Ï´Ù.
net.ipv4.tcp_synack_retries=3
 
# ¹«¾ð°¡ ¹®Á¦°¡ ÀÖÀ» ¶§ ¿¬°áÀ» À§ÇØ Àç½Ãµµ ÇÒ È½¼ö, ÃÖ¼Ò °ª°ú ±âº» °ªÀº 3ÀÔ´Ï´Ù.
net.ipv4.tcp_retries1=3
 
# TCP ¿¬°áÀ» ²÷±â Àü¿¡ Àç½ÃµµÇÒ È½¼ö.
net.ipv4.tcp_retries2=7
 
# ¿¬°áÀ» Á¾·á½Ã ¼Ò¿äµÇ´Â ½Ã°£À» ÁÙ¿©ÁØ´Ù(±âº» ¼³Á¤°ª: 60).
net.ipv4.tcp_fin_timeout=20
 
# µ¿½Ã¿¡ À¯Áö °¡´ÉÇÑ timewait ¼ÒÄÏÀÇ ¼öÀÔ´Ï´Ù.
# ¸¸¾à ÁöÁ¤µÈ ¼ýÀÚ¸¦ ÃÊ°úÇÏ¿´À» °æ¿ì¿¡´Â timewait ¼ÒÄÏÀÌ ¾ø¾îÁö¸ç °æ°í ¸Þ½ÃÁö°¡ Ãâ·ÂµË´Ï´Ù.
# ÀÌ Á¦ÇÑÀº ´Ü¼øÇÑ DoS °ø°ÝÀ» Â÷´ÜÇϱâ À§ÇØ Á¸ÀçÇϴµ¥, ÀÓÀÇ·Î ÀÌ °ªÀ» ÁÙ¿©¼­´Â ¾ÈµÇ¸ç
# ¸Þ¸ð¸®°¡ ÃæºÐÇÏ´Ù¸é ÀûÀýÇÏ°Ô ´Ã·ÁÁÖ´Â °ÍÀÌ ÁÁÀºµ¥, 64M ¸¶´Ù 180000À¸·Î ¼³Á¤ÇÏ¸é µË´Ï´Ù.
# µû¶ó¼­ 256MÀÏ °æ¿ì¿¡´Â 256/4=4 4*180000=720000
 
# 64M -> 180000
# 128M -> 360000
# 256M -> 720000
# 512M -> 1440000
# 1G -> 2880000
# 2G -> 5760000
 
net.ipv4.tcp_max_tw_buckets=2880000
 
# ¿¬°áÀÌ ²÷¾îÁ³´Ù°í ÆÇ´ÜÇÒ ¶§±îÁö, ¾ó¸¶³ª keepalive probe ¸¦ º¸³¾Áö °áÁ¤. ±âº»°ª 9ȸ
# °£´ÜÇÑ DoS °ø°ÝÀ» ¸·¾ÆÁØ´Ù.
net.ipv4.tcp_keepalive_probes=2
 
# keepalive °¡ È°¼ºµÇ µÇ¾î ÀÖÀ» °æ¿ì, ¾ó¸¶³ª ÀÚÁÖ TCP °¡ keepalive ¸Þ¼¼Áö¸¦ º¸
# ³»°Ô ÇÒ °ÍÀÎÁö¸¦ ¼³Á¤.
net.ipv4.tcp_keepalive_time=30
 
# keepalive_probes ¸¦ º¸³¾ °£°ÝÀ» Á¤ÇÔ. probe ¸¦ º¸³½ ÈÄ, probes * intvl ÀÇ ½Ã
# °£ÀÌ Áö³ªµµ·Ï ÀÀ´äÀÌ ¾øÀ¸¸é ¿¬°áÀÌ ÇØÁ¦µÈ °ÍÀ¸·Î °£ÁÖÇÏ°Ô µÊ. ±âº» °ªÀÇ »ç¿ë
# ½Ã 11ºÐ 15ÃÊ µ¿¾È Àç½Ãµµ¸¦ ÇÏ°í ¿¬°áÀ» Ãë¼ÒÇÔ. °ªÀº ÃÊ´ÜÀ§
net.ipv4.tcp_keepalive_intvl=10
 
# ¼­¹ö ÂÊ¿¡¼­ ´ÝÀº TCP ¿¬°áÀ» ²÷±â Àü¿¡ È®ÀÎÇϴ Ƚ¼ö¸¦ Á¤ÇÕ´Ï´Ù. ±âº» °ªÀº 7 ·Î
# RTO 50 ÃÊ¿¡¼­ 16 ºÐ »çÀÌ¿¡ ÇØ´çÇÕ´Ï´Ù. À¥ ¼­¹ö°¡ ¿î¿µ Áß À̶ó¸é ÀÌ °ªÀ» ÁÙ¿©¼­
# ¼ÒÄÏ µîÀÌ ±ÍÇÑ ¸®¼Ò½º¸¦ ¼ÒºñÇÏÁö ¾Êµµ·Ï ÇÒ ¼öµµ ÀÖ½À´Ï´Ù..
net.ipv4.tcp_orphan_retries=2
 
# SYN ÆÐŶÀ» Àü¼ÛÇÑ ÈÄ¿¡ ·Î½º°¡ ¹ß»ýÀ» ÇÏ¿© ACK ¸¦ ÀϺΠ¹ÞÁö ¸øÇßÀ» °æ¿ì, ¼±ÅÃ
# ÀûÀ¸·Î (selected) ¹ÞÁö¸øÇÑ ACK ¸¸ ¹Þµµ·Ï ¿äûÇÏ´Â °ÍÀ» Çã¶ôÇÕ´Ï´Ù. ·Î½º°¡ ¸¹Àº
# ³×Æ®¿öÅ©¿¡¼­´Â »ó´çÈ÷ Áß¿äÇÑ ¿ªÇÒÀ» ÇÕ´Ï´Ù.
net.ipv4.tcp_sack=1
 
16) ½Ã½ºÅÛ ÀÌ»ó½Ã ±âº»ÀûÀÎ Á¡°Ë »çÇ× ¹× ¸í·É¾î
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=190&name=¸®´ª½º&home=º¸¾È
 
17) TCP-Wrapper ±¸¼º
 
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=126&name=¸®´ª½º&home=±âŸ

 
--------------------------------------------------------------------------------------- 
5. ¼­ºñ½ºº¸¾È
 
1) APACHE º¸¾È
 
¸®´ª½º¸¦ »ç¿ëÇÏ´Â °¡Àå Å« ÀÌÀ¯´Â À¥¼­¹ö¸¦ ¿î¿µÇϱâ À§Çؼ­ÀÔ´Ï´Ù. ÀÌ À¥¼­¹ö¸¦ °¡´ÉÇÏ°Ô ÇØÁÖ´Â ÇÁ·Î±×·¥ÀÌ ¾ÆÆÄÄ¡ÀÔ´Ï´Ù. ¾ÆÆÄÄ¡ÀÇ º¸¾È¿¡ ´ëÇØ ¾Ë¾Æº¸µµ·Ï ÇÕ´Ï´Ù.

º¸¾È¼³Á¤ ÀÌ¿ÜÀÇ httpd.conf »ó¼¼ÇÑ ¼³Á¤³»¿ëÀº ³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­¸¦ ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù.

³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­ - httpd.conf ȯ°æ¼³Á¤
http://www.nextline.net/?inc=support&html=pds_view&no=204&name=¸®´ª½º&home=


APACHE ¼³Á¤ÆÄÀÏ : httpd.conf
¼Ò½º ¼³Ä¡ ¼³Á¤ÆÄÀÏ °æ·Î : /usr/local/apache/conf/httpd.conf
rpm ¼³Ä¡ ¼³Á¤ÆÄÀÏ °æ·Î : /etc/httpd/conf/httpd.conf
 

APACHE º¸¾È

 

1. À¥¹®¼­µð·ºÅ丮(DocumentRoot)¿¡¼­ ºÒÇÊ¿äÇÑ ¹®¼­ Á¦°Å

¼Ò½º·Î ¾ÆÆÄÄ¡¸¦ ¼³Ä¡ÇÏ°Ô µÇ¸é ±âº» À¥ ¹®¼­°¡ À§Ä¡ÇÏ´Â µð·ºÅ丮°¡ /usr/local/apache/htdocsÀÔ´Ï´Ù. htdocs µð·ºÅ丮¿¡´Â ¾ÆÆÄÄ¡ °ü·ÃÁ¤º¸°¡ µé¾îÀÖ´Â ¹®¼­¿Í °ø°³µÉ ÇÊ¿ä°¡ ¾ø´Â ¹®¼­°¡ À§Ä¡ÇÏ°í ÀÖ½À´Ï´Ù. ÀÌ ¹®¼­µéÀ» Á¦°ÅÇÕ´Ï´Ù.

 

httpd.conf Áö½ÃÀÚ

DocumentRoot "/usr/local/apache/htdocs"

 

¸í·É¾î

¨ç [root@nextline ~]# cd /usr/local/apache/htdocs/

DocumentRoot µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.

 

¨è [root@nextline htdocs]# rm -rf *

rm ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© /usr/local/apache/htdocs/ ÇÏÀ§ÀÇ ¸ðµç ¹®¼­¸¦ Á¦°ÅÇÕ´Ï´Ù.

 

¶Ç ´Ù¸¥ ¹æ¹ýÀ¸·Î´Â httpd.conf¿¡¼­ DocumentRoot°ªÀ» »õ·Î¿î °æ·Î·Î ÁöÁ¤ÇÕ´Ï´Ù.

 

2. ºÒÇÊ¿äÇÑ CGI ½ºÅ©¸³Æ®Á¦°ÅÇϱâ

apache¸¦ ¼³Ä¡Çϸé cgi-bin µð·ºÅ丮¿¡ ±âº»À¸·Î CGI½ºÅ©¸³Æ®°¡ ¼³Ä¡µË´Ï´Ù. ÀÌ CGI ½ºÅ©¸³Æ®°¡ °ø°Ý¿¡ ÀÌ¿ëµÉ ¼öµµ Àֱ⠶§¹®¿¡ ¸ðµÎ Á¦°ÅÇϵµ·Ï ÇÕ´Ï´Ù. ƯÈ÷ Ãʱâ¹öÀüÀÎ °æ¿ì¿¡ php.cgiµîÀÌ Á¦°øµÇ¾ú´Âµ¥ ÇØÅ·ÀÇ ºô¹Ì¸¦ Á¦°øÇÏ¿´´Ù. cgi-bin µð·ºÅ丮¿¡ ÀÖ´Â ¸ðµç ÆÄÀÏÀ» Á¦°ÅÇÕ´Ï´Ù.

 

cgi-bin °æ·Î

/usr/local/apache/cgi-bin

 

¸í·É¾î

¨ç [root@nextline ~]# cd /usr/local/apache/cgi-bin

DocumentRoot µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.

 

¨è [root@nextline htdocs]# rm -rf *

rm ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© /usr/local/apache/cgi-bin ÇÏÀ§ÀÇ ¸ðµç ¹®¼­¸¦ Á¦°ÅÇÕ´Ï´Ù.

 

3. DocumentRoot, »ç¿ëÀÚ È¨µð·ºÅ丮(/home)¿¡ ¼³Á¤ÇÏ´Â µð·ºÅ丮 ¿É¼Ç ¼³Á¤Çϱâ

±âº»ÀûÀÎ ¼³Á¤À» ¸ðµÎ Á¦°ÅÇÏ°í º¸¾È°ú °ü·ÃÀÖ´Â Ç׸ñ¸¸ ¿É¼ÇÀ¸·Î ÁöÁ¤ÇÕ´Ï´Ù.

 

httpd.conf Áö½ÃÀÚ 

/usr/local/apache/htdocs/">

  Options Indexes FollowSymLinks ExecCGI

AllowOverride All

Order allow,deny

  Allow from all

 

     Options Includes FollowSymLinks ExecCGI

     AllowOverride All

     Order allow,deny

     Allow from all

/usr/local/apache/htdocs/">

tag¿¡ ÀÇÇÏ¿© °¢ directory¸¶´Ù ÀûÀýÇÏ°Ô permissionÀ» °É ¼ö°¡ ÀÖ½À´Ï´Ù.

 

¨ç Options Indexes FollowSymLinks ExecCGI

 

None

¾î¶² ¿É¼Çµµ ÀÌ¿ëÇÒ ¼ö ¾ø½À´Ï´Ù.

 

All

ÁöÁ¤ÇÑ directory¿¡¼­ ¸ðµç ¸í·ÉÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

 

Indexes

URL¿¡ ÁöÁ¤µÈ µð·ºÅ丮¿¡ (index.html °°Àº) ÁöÁ¤µÈ ÆÄÀÏÀÌ ¾øÀ» °æ¿ì µð·ºÅ丮ÀÇ ÆÄÀÏ ¸ñ·ÏÀ» º¸¿©ÁÖ´Â ¿É¼ÇÀÔ´Ï´Ù.

 

Includes

¼­¹öÃøÀÇ Ãß°¡ÀûÀÎ Á¤º¸¸¦ Á¦°øÇÒ ¼ö ÀÖ°Ô ÇÕ´Ï´Ù.

 

IncludesNoExec

¼­¹öÃøÀÇ Ãß°¡ÀûÀÎ Á¤º¸¸¦ Á¦°øÇÒ ¼ö ÀÖ°Ô ÇÏÁö¸¸, ¾î¶°ÇÑ ½ÇÇà ÆÄÀÏÀ» ½ÇÇàÇÏ´Â °ÍÀ» ¹æÁöÇÕ´Ï´Ù.

 

FollowSymLinks

µð·ºÅ丮»óÀÇ ½Éº¼¸¯ ¸µÅ©¸¦ »ç¿ë °¡´ÉÇÏ°Ô ÇÕ´Ï´Ù.

 

ExecCGI

CGI ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇÕ´Ï´Ù.

 

MultiViews

All ¿É¼ÇÀÌ ¼³Á¤µÇ¾úÀ» ¶§¸¸ ÁöÁ¤µÈ ¸ñ·ÏÀÇ multiviews¸¦ Çã¿ëÇÕ´Ï´Ù.

 

¨è AllowOverride All

.htaccessÆÄÀÏÀº ¼­¹öÀÇ °¢ µð·ºÅ丮¿¡ ¸¸µé¾î¼­ °¢ µð·ºÅ丮¿¡ ´ëÇÑ Á¢±ÙÀ» Á¦¾îÇϱâ À§ÇÑ °ÍÀ¸·Î µð·ºÅ丮¿¡ .htaccessÆÄÀÏÀÌ ÀÖÀ¸¸é, ¼­¹ö Àüü¿¡ ÀÛ¿ëÇÏ´Â access.conf º¸´Ù ¿ì¼±±ÇÀ» °¡Áý´Ï´Ù. .htaccessÆÄÀÏ¿¡ ´ëÇÑ Override¿¡ ´ëÇÑ ¿É¼ÇÀÔ´Ï´Ù.

 

None

.htaccessÆÄÀÏÀ» ÀÐÀ» ¼ö ¾ø°Ô ÇÕ´Ï´Ù.

 

All

¸ðµç ÁöÁ¤¿¡ ´ëÇØ °¡´ÉÇÏ°Ô ÇÕ´Ï´Ù.

 

Options

±ÔÁ¤µÈ µð·ºÅ丮 Çü½ÄÀ» ÄÜÆ®·ÑÇÏ´Â ÁöÁ¤ÀÇ »ç¿ëÀ» Çã¶ôÇÕ´Ï´Ù.

 

FileInfo

¹®¼­Çü½ÄÀ» ÄÜÆ®·ÑÇÏ´Â ÁöÁ¤ÀÇ »ç¿ëÀ» Çã¿ëÇÕ´Ï´Ù.

 

AuthConfig

»ç¿ëÀÚ ÀÎÁõ ÁöÁ¤ÀÇ »ç¿ëÀ» Çã¿ëÇÕ´Ï´Ù. »ç¿ëÀÚ ÀÎÁõ º¯¼ö¸¦ »ç¿ëÇÕ´Ï´Ù.

 

Limit

È£½ºÆ® Á¢±ÙÀ» ÄÜÆ®·ÑÇÏ´Â ÁöÁ¤À» Çã¿ëÇÕ´Ï´Ù.

 

¨é Order

Limit¿¡ °ü·ÃµÈ ºÎºÐÀ» ¼³Á¤À» ÇÕ´Ï´Ù. ¼­¹ö°¡ access controlÀ» ¼öÇàÇÏ´Â ¼ø¼­¸¦ ³ªÅ¸³À´Ï´Ù. ¿©±â¼­´Â allow±â´ÉÀ» ¸ÕÀú ¼öÇàÇÏ°í, deny±â´ÉÀ» ¼öÇàÇ϶ó´Â °ÍÀÔ´Ï´Ù.

 

deny, allow

deny Áö½ÃÀÚ ºÎÅÍ °Ë»çÇÏ°í allow Áö½ÃÀÚ¸¦ °Ë»ç ÇÕ´Ï´Ù.

 

allow, deny

allow Áö½ÃÀÚ ºÎÅÍ °Ë»çÇÏ°í deny Áö½ÃÀÚ¸¦ °Ë»ç ÇÕ´Ï´Ù.

 

mutual-failure

allow¸ñ·Ï¿¡ ¾ø´Â ¸ðµç host¿¡°Ô Á¢¼ÓÀ» °ÅºÎ ÇÕ´Ï´Ù.

 

allow from

³ª¿­µÇ´Â Áּҵ鿡 ´ëÇÑ access controlÀ» °¡´ÉÇÏ°Ô ÇÕ´Ï´Ù»ç¿ë °¡´ÉÇÑ ÁÖ¼Ò´Â µµ¸ÞÀÎ ³×ÀÓ, È£½ºÆ® À̸§ ÁÖ¼Ò, È£½ºÆ® ip ÁÖ¼Ò, ip ÁÖ¼ÒÀÇ ¾ÕºÎºÐ 3¹ÙÀÌÆ®, ¸ðµç ÁÖ¼Ò¿¡ ÇØ´çÇÏ´Â all ÀÌ ÀÖ½À´Ï´Ù.

 

deny from

allow from°ú ¹Ý´ëµÇ´Â °³³äÀ̸ç, »ç¿ë°¡´ÉÇÑ ÁÖ¼Ò´Â allow from°ú °°´Ù.

 

Require

»ç¿ëÀÚ, ±×·ì¿¡ ´ëÇÑ Á¢±ÙÀ» ÅëÁ¦ÇÒ ¼ö ÀÖ½À´Ï´Ù.

»ç¿ë¹æ¹ý : require entity en1 en2 ... enn

entity¿¡ µé¾î°¥ ¼ö ÀÖ´Â °ÍÀº user, group, valid-userÀÇ ¼¼°¡ÁöÀÌ´Ù.

 

User

ÁöÁ¤µÈ »ç¿ëÀڵ鿡°Ô¸¸ Á¢±ÙÀ» Çã¿ëÇÏ´Â °ÍÀ¸·Î, ÁöÁ¤µÈ »ç¿ëÀÚ¿¡ ´ëÇÑ Á¤º¸´Â AuthUserFile¿¡¼­ ÁöÁ¤ÇÑ ÆÄÀÏ¿¡ ÀÖ½À´Ï´Ù.

 

Group

ÁöÁ¤µÈ ±×·ì¿¡°Ô¸¸ Á¢±ÙÀ» Çã¿ëÇÏ´Â °ÍÀ¸·Î, ÁöÁ¤µÈ ±×·ì¿¡ ´ëÇÑ Á¤º¸´Â

AuthGroupFile¿¡¼­ ÁöÁ¤ÇÑ ÆÄÀÏ¿¡ ÀÖ½À´Ï´Ù.

 

valid-user

AuthUserFile¿¡ ÀÖ´Â ¸ðµç »ç¿ëÀÚ¿¡ ´ëÇØ Á¢±ÙÀ» Çã¿ëÇÕ´Ï´Ù.

 

4. ~ ÅÂ±× ÀÌ¿ëÇϱâ

ű״ °¢ µð·ºÅ丮º°·Î HTTP MethodÀÇ »ç¿ë¿©ºÎ¸¦ ÅëÁ¦Çϴ ű×ÀÔ´Ï´Ù. ÆÄÀÏÀÇ ¾÷·Îµå ¹× ÆÄÀÏÀÇ ¼öÁ¤, »èÁ¦¸¦ À§Çؼ­ »ç¿ëµÇ´Â HTTP Method´Â PUT°ú POST, DELETE °¡ Àִµ¥ ÀÌ Method¸¦ Á¦ÇÑÇÕ´Ï´Ù.

 

httpd.conf Áö½ÃÀÚ

Require valid-user

°³ÀÎ »ç¿ëÀÚ È¨µð·ºÅ丮¿¡¼­ POST, PUT, DELETE Method¸¦ Æнº¿öµå ÆÄÀÏ¿¡ µî·ÏµÈ »ç¿ëÀÚ¸¸ÀÌ ÀÌ¿ë°¡´ÉÇϵµ·Ï Á¦ÇÑÇÑ °ÍÀÔ´Ï´Ù.

 

5. Çì´õ Á¤º¸ ¼û±â±â

Ŭ¶óÀ̾ðÆ®°¡ Apache À¥¼­¹ö¿¡ Á¢¼ÓÇßÀ» ¶§ À¥¼­¹ö¿¡¼­´Â ÀÀ´ä ¸Þ½ÃÁöÀÇ Çì´õ¿¡ À¥¼­¹ö ¹öÀü, ¼³Ä¡µÈ ÀÀ¿ëÇÁ·Î±×·¥ µî°ú °°Àº Á¤º¸¸¦ Àü´ÞÇÕ´Ï´Ù.

 

¨ç Çì´õ Á¤º¸ È®ÀÎÇϱâ

[root@nextline ~]# telnet xxx.xxx.xxx.xxx 80

     Trying xxx.xxx.xxx.xxx...

     Connected to xxx.xxx.xxx.xxx.

     Escape character is '^]'.

     GET / HTTP/1.1

 

     HTTP/1.1 400 Bad Request

     Date: Sat, 14 Dec 2002 14:24:11 GMT

     Server: Apache/1.3.26 (Unix) PHP/4.2.2

     Connection: close

     Transfer-Encoding: chunked

     Content-Type: text/html; charset=iso-8859-1

 

ÀÌ Á¤º¸´Â °ø°ÝÀÚ¿¡ ÀÇÇØ Apache À¥¼­¹ö ¹öÀü°ú ±¸µ¿µÇ°í ÀÖ´Â ÀÀ¿ëÇÁ·Î±×·¥ÀÇ ¹öÀüÀ» È®ÀÎÇÏ°í ¾Ë·ÁÁø Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÇϴµ¥ À¯¿ëÇÏ°Ô ÀÌ¿ëµÉ ¼ö ÀÖ½À´Ï´Ù.

 

¨è Çì´õ Á¤º¸ ¼û±â±â

Apache À¥¼­¹ö¿¡¼­´Â "ServerTokens"Áö½ÃÀÚ¸¦ ¼öÁ¤ÇÔÀ¸·Î½á Çì´õ¿¡ ÀÇÇØ Àü¼ÛµÇ´Â Á¤º¸¸¦ ¹Ù²Ü ¼ö ÀÖ½À´Ï´Ù.

 

httpd.conf Áö½ÃÀÚ

ServerTokens Å°¿öµå

 

¨é Å°¿öµå¿Í Á¦°øµÇ´Â Á¤º¸

 

Prod[ductOnly]

À¥¼­¹ö Á¾·ù¸¸ Ç¥±âµË´Ï´Ù. ¿¹) Server:Apache

 

Min[imal]

Prod Å°¿öµå Á¦°øÁ¤º¸ + À¥¼­¹ö ¹öÀü ¿¹) Server:Apache/1.3.26

 

OS

Min Å°¿öµå Á¦°ø Á¤º¸ + ¿î¿µÃ¼Á¦ ¿¹) Server:Apache/1.3.26 (Unix)

 

Full

OS Å°¿öµå Á¦°øÁ¤º¸ + ¼³Ä¡µÈ ¸ðµâ(ÀÀ¿ëÇÁ·Î±×·¥) Á¤º¸

¿¹) Server: Apache/1.3.26 (Unix) PHP/4.2.2

Âü°í: ServerTokenÀº apache 1.3À̻󿡼­ °¡´ÉÇÏ°í ProductOnlyÅ°¿öµå´Â 1.3.12¹öÀü À̻󿡼­¸¸ »ç¿ë°¡´ÉÇÏ´Ù. ÀϹÝÀûÀ¸·Î ServerTokensÀº httpd.conf¿¡ ¸í½ÃµÇ¾î ÀÖÁö ¾Ê´Â °æ¿ì°¡ ¸¹´Ù. ÀÌ·± °æ¿ì¿¡´Â ±âº»°ªÀÎ "ServerTokens Full"ÀÌ Àû¿ëµÇ¾î ¸ðµç Á¤º¸°¡ ÀÀ´ä   Çì´õ¿¡ Æ÷ÇԵǾî Ŭ¶óÀ̾ðÆ®¿¡°Ô Àü¼ÛµË´Ï´Ù. ÃÖ¼ÒÇÑÀÇ Á¤º¸¸¦ ÁÖ±â À§Çؼ­´Â   "ServerTokens Prod"°¡ ÁÁ½À´Ï´Ù.

 

6. ±âº» »ç¿ëÀÚ ÀÎÁõ ¼³Á¤

±âº» »ç¿ëÀÚ ÀÎÁõ°ú ´ÙÀÌÁ¦½ºÆ® »ç¿ëÀÚ ÀÎÁõÀÇ ¼³Á¤ ¹æ¹ýÀº ¸Å¿ì À¯»çÇÏ´Ù. ´ÙÀ½°ú °°ÀÌ µÎ°¡Áö ÀýÂ÷¸¦ °ÅÃÄ ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.

* Æнº¿öµå ÆÄÀÏ »ý¼º

* Æнº¿öµå ÆÄÀÏÀ» »ç¿ëÇÒ ¼ö ÀÖµµ·Ï Apache ȯ°æ ¼³Á¤

 

¨ç Æнº¿öµå ÆÄÀÏ»ý¼º

[root@nextline ~]# cd /usr/local/apache/bin/

¾ÆÆÄÄ¡ bin µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.

[root@nextline ~]# ./htpasswd -c /usr/local/apache/password nextline

New password: (Æнº¿öµåÀÔ·Â)

Re-type new password: (Æнº¿öµåÀÔ·Â)

Æнº¿öµå ÆÄÀÏÀ» óÀ½ »ý¼ºÇÒ °æ¿ì¿¡´Â -c ¿É¼ÇÀ» »ç¿ëÇÏ¿© ¸¸µì´Ï´Ù.

[root@www /usr/local/apache/bin]# ./htpasswd  /usr/local/apache/password nextline2

New password: (Æнº¿öµåÀÔ·Â)

Re-type new password: (Æнº¿öµåÀÔ·Â)

»ç¿ëÀÚ¸¦ Ãß°¡ÇÒ °æ¿ì¿¡´Â -c ¿É¼ÇÀ» »©°í »ç¿ëÇÏ¸é µË´Ï´Ù. ¸¸¾à -c ¿É¼ÇÀ» »ç¿ëÇÒ °æ¿ì¿¡´Â ±âÁ¸ÀÇ µîµ¶µÈ »ç¿ëÀÚµéÀº Áö¿öÁö¹Ç·Î ÁÖÀÇÇØ¾ß ÇÕ´Ï´Ù.

 

[root@www /usr/local/apache/bin]# cat ../password

nextline:LT30X3txYYEuY

nextline2:/RfZRDXV1N/Eo

Æнº¿öµå ÆÄÀÏÀ» È®ÀÎÇغ¸¸é »ç¿ëÀÚID¿Í Æнº¿öµå Çʵå·Î ±¸¼ºµÇ¾î Àִµ¥, Æнº¿öµå  Çʵå´Â ¾ÏȣȭµÇ¾î ÀúÀåµË´Ï´Ù. ¶ÇÇÑ µÎ »ç¿ëÀÚ°¡ ¾ÏÈ£¸¦ µ¿ÀÏÇÏ°Ô ÀÔ·ÂÇصµ ¾ÏȣȭµÈ °ª Àº ´Ù¸£°Ô ³ªÅ¸³³´Ï´Ù.

 

¨è Æнº¿öµå ÆÄÀÏÀ» »ç¿ë°¡´ÉÇϱâ À§ÇÑ È¯°æ¼³Á¤

httpd.confÆÄÀϳ»¿¡¼­ µð·ºÅ丮º°·Î »ç¿ëÀÚ ÀÎÁõÀ» Çϱâ À§ÇÑ ¼³Á¤À» ÇÏ¸é µË´Ï´Ù.

 

httpd.conf Áö½ÃÀÚ

AllowOverride AuthConfig

 

»ç¿ëÀÚ ÀÎÁõÀÌ ÇÊ¿äÇÑ µð·ºÅ丮¿¡ ¾Æ·¡ÀÇ Áö½ÃÀÚµéÀÌ Æ÷ÇÔµÈ .htaccessÆÄÀÏÀ» »ý¼º ÇÕ´Ï´Ù.

 

Áö½ÃÀÚ

AuthType

ÀÎÁõÇüÅÂ(Basic ¶Ç´Â Digest)

 

AuthName

ÀÎÁõ¿µ¿ª(À¥ºê¶ó¿ìÀúÀÇ ÀÎÁõâ¿¡ Ç¥½ÃµÊ)

 

AuthUserFile

»ç¿ëÀÚ Æнº¿öµå ÆÄÀÏÀÇ À§Ä¡

 

AuthGroupFile

±×·ì ÆÄÀÏÀÇ À§Ä¡(¿É¼Ç)

 

Require

Á¢±ÙÀ» Çã¿ëÇÒ »ç¿ëÀÚ ¶Ç´Â ±×·ìÁ¤ÀÇ

 

¿¹¹®

¾ÕÀÇ Æнº¿öµå ÆÄÀÏ¿¡ µî·ÏµÈ nextline, nextline2¶ó´Â »ç¿ëÀÚ¸¸À» Á¤ÇØÁø µð·ºÅ丮¿¡ Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï ¼³Á¤Çغ¸ÀÚ.

   [nextline@nextline ~]$ cat .htaccess

   AuthType Basic

   AuthName "Welcome nextline's Home

   AuthUserFile /usr/local/apache/password

   Require user nextline nextline   // ¸¸¾à Æнº¿öµåÆÄÀÏ¿¡ µî·ÏµÈ ¸ðµç »ç¿ëÀÚ¸¦ Á¢±Ù°¡´ÉÇϵµ·Ï ¼³Á¤ÇÏ·Á¸é Require valid-user ¶ó°í ÇÏ¸é µË´Ï´Ù.

 

°ü·Ã¸í·É¾î

htpasswd

¾ÆÆÄÄ¡ »ç¿ëÀÚ ÀÎÁõÀ» À§ÇÑ ÆÄÀÏÀ» »ý¼ºÇϰųª ¾÷µ¥ÀÌÆ®¸¦ ÇÏ´Â ¸í·ÉÀÔ´Ï´Ù.

 

»ç¿ë¹ý

htpasswd [options] password_file username

 

options

-c

»õ·Î¿î Æнº¿öµå ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù.

 

[nextline@nextline ~]$ htpasswd -c /usr/local/apache/password nextline

password¶ó´Â ÆÄÀÏÀ» »ý¼ºÇϸ鼭 nextlineÀ̶ó´Â »ç¿ëÀÚ¸¦ µî·ÏÇÕ´Ï´Ù.

[nextline@nextline ~]$ htpasswd /usr/local/apache/password nextline2

nextline2 ¶ó´Â »ç¿ëÀÚ¸¦ µî·ÏÇÕ´Ï´Ù.

 

7. Á¢±ÙÅëÁ¦

Ŭ¶óÀ̾ðÆ®°¡ »ç¿ëÇϴ ȣ½ºÆ®ÀÇ IPÁÖ¼Ò³ª µµ¸ÞÀο¡ ÀÇÇؼ­ À¥¼­¹öÀÇ µ¥ÀÌÅÍ¿¡ ´ëÇÑ Á¢±ÙÀ» ÅëÁ¦ÇÒ ¼ö ÀÖ½À´Ï´Ù.. ±âº»ÀûÀÎ ¼­¹ö ¼³Á¤Àº DocumentRootÀÇ ³»¿ë¿¡ ´ëÇØ ´©±¸³ª Á¢¼Ó À» Çã¶ôÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ½À´Ï´Ù.

ApacheÀÇ "Allow"¿Í "Deny"Áö½ÃÀÚ´Â »ç¿ëÀÚ ½Ã½ºÅÛÀÇ È£½ºÆ® À̸§°ú È£½ºÆ® ÁÖ¼Ò¸¦ ±Ù°£À¸·Î Á¢¼ÓÀ» Çã¶ô ¶Ç´Â Â÷´ÜÇÒ ¼ö ÀÖµµ·Ï ÁöÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¶ÇÇÑ, "Allow"¿Í "Deny"Áö½ÃÀÚ¸¦ µ¿½Ã¿¡ »ç¿ëÇÒ °æ¿ì ±× ¼ø¼­¸¦ Á¤ÇÏ´Â "Order" Áö½ÃÀÚ¸¦ »ç¿ëÇÏ¿© º¸´Ù Á¤±³ÇÑ Á¤Ã¥¼³Á¤À» ÇÒ ¼ö ÀÖ½À´Ï´Ù.

 

Order Deny,Allow

DenyÁö½ÃÀÚ°¡ AllowÁö½ÃÀÚº¸´Ù ¸ÕÀú °Ë»çµË´Ï´Ù. Á¢±ÙÀ» ±âº»ÀûÀ¸·Î Çã¿ëµË´Ï´Ù.

Áï, DenyÁö½ÃÀÚ³ª AllowÁö½ÃÀÚ¿¡ ÀÏÄ¡ÇÏÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®ÀÇ Á¢¼ÓÀ» Çã¿ëÇÕ´Ï´Ù.

 

Order Allow,Deny

AllowÁö½ÃÀÚ°¡ DenyÁö½ÃÀÚº¸´Ù ¸ÕÀú °Ë»çµË´Ï´Ù. Á¢±ÙÀ» ±âº»ÀûÀ¸·Î Â÷´ÜµË´Ï´Ù.

Áï, DenyÁö½ÃÀÚ³ª AllowÁö½ÃÀÚ¿¡ ÀÏÄ¡ÇÏÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®ÀÇ Á¢¼ÓÀº Â÷´ÜÇÕ´Ï´Ù.

 

Order Mutual-failure

Allow ¸®½ºÆ®¿¡ ÀÖ°í, Deny¸®½ºÆ®¿¡ ¾ø´Â È£½ºÆ®¸¸ Á¢±ÙÀ» Çã¿ëÇÕ´Ï´Ù.¼ø¼­´Â "Allow,Deny"¶§¿Í °°´Ù.

 

(Âü°í) ÀϹÝÀûÀÎ FirewallÀ̳ª ¶ó¿ìÅÍÀÇ Á¢±ÙÅëÁ¦ RuleÀº ¼øÂ÷ÀûÀ¸·Î ºñ±³ÇÏ´Ù°¡ ÃÖÃÊ·Î ÀÏÄ¡ÇÏ´Â RuleÀ» Àû¿ëÇÏ°í ±× ÀÌÈÄ´Â ºñ±³ÇÏÁö ¾ÊÁö¸¸, Apache¿¡¼­´Â Allow¿Í Deny¸¦ ÀÏ´Ü ¸ðµÎ ºñ±³ÇÏ°í µÑ Áß¿¡ Çϳª¶óµµ ÀÏÄ¡ÇÒ °æ¿ì Àû¿ëÇÕ´Ï´Ù´Â Á¡¿¡¼­ Â÷ÀÌ°¡ ÀÖ½À´Ï´Ù.. ¶ÇÇÑ "Order"Áö½ÃÀÚ »ç¿ë½Ã Å°¿öµå(Allow ¶Ç´Â Deny)´Â ÄÞ¸¶(,)¿¡ ÀÇÇؼ­¸¸ ºÐ¸®µÇ°í °ø¹éÀÌ µé¾î°¡¼­´Â ¾ÈµË´Ï´Ù.

 

Order deny,allow

deny from all

allow from 172.16.10

"deny from"°ú "allow from"Áö½ÃÀڴ ȣ½ºÆ®, µµ¸ÞÀÎ À̸§, IPÁÖ¼Ò, ¼­ºê³Ý¸¶½ºÅ©¸¦  °¡Áø ÁÖ¼Ò(¿¹¸¦ µé¸é 172.16.10.0/255.255.255.0), CIDR(Classes InterDomain Routing)¸¶½ºÅ©¸¦ °¡Áø IPÁÖ¼Ò(172.16.10.0/24)¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

 

8. ±ÇÇѺο©

±ÇÇѺο©´Â ƯÁ¤ÇÑ ÀÚ¿ø¿¡ Á¢±ÙÇÒ »ç¿ëÀÚ Æ۹̼ÇÀÌ À¯È¿ÇÑÁö¸¦ È®ÀÎÇÏ´Â °ÍÀÔ´Ï´Ù. ¾î¶² Æ۹̼ǿ¡ ÀÇÇØ Çã¶ôµÇ°í °ÅºÎµÉÁö´Â ÀÚ¿ø°ú ±× ÀÚ¿ø°ú °ü·ÃµÈ ±ÔÄ¢µé¿¡ µû¶ó¼­ ´Ù¾çÇÏ´Ù. °¢ ÆÄÀÏ°ú µð·ºÅ丮±¸Á¶´Â ´Ù¸¥ Á¢±ÙÅëÁ¦³ª »ç¿ëÀÚÀÎÁõ ¹æ¹ýÀ» °¡Áú ¼ö ÀÖ½À´Ï´Ù. Á¢±ÙÅëÁ¦¿Í »ç¿ëÀÚ ÀÎÁõ¹æ¹ýÀ» »ç¿ëÇÏ¿© °¢ ÀÚ¿ø¿¡ ´ëÇÑ ´Ù¾çÇÑ ±ÇÇÑÀ» ºÎ¿©ÇÒ ¼ö ÀÖ½À´Ï´Ù. °¡·É ÀÎÅͳݿ¡¼­ Á¢¼Ó ½Ã¿¡´Â »ç¿ëÀÚÀ̸§°ú Æнº¿öµå¸¦ È®ÀÎÇÏ°í ÀÎÆ®¶ó³Ý¿¡¼­ Á¢¼Ó ½Ã¿¡´Â  ¿ä±¸ÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ÀÌ´Â "Satisfy"Áö½ÃÀÚ¸¦ ÅëÇؼ­ ±¸ÇöÇÒ ¼ö ÀÖ½À´Ï´Ù.

 

Satisfy any | all

allÀº ÀÎÆ®¶ó³Ý »ç¿ëÀÚ¿¡ ´ëÇØ Æнº¿öµå¸¦ ¹¯Áö ¾Ê°í Á¢¼ÓÀÌ °¡´ÉÇÏ°Ô ÇÏ´Â °ÍÀÌ°í, any´ÂÀÎÆ®¶ó³Ý »ç¿ëÀÚ¶óµµ Æнº¿öµå¸¦ ¹¯´Â´Ù.

 

     Order deny,allow

     deny from all

     allow from xxx.xxx.xxx.xxx

     AuthType Basic

     AuthName "Welcome Posein's Home"

     AuthUserFile /usr/local/apache/password

     Require nextline nextline2

     Satisfy Any

 

AuthName Ç׸ñ¿¡¼­ 1.3¹öÀü¿¡¼­´Â °ãµû¿ÈÇ¥°¡ ¾ÕÂÊ¿¡ ÇϳªÀÌ°í, 2.0¹öÀü¿¡¼­´Â °ãµû¿ÈÇ¥°¡ ¾ÕµÚ·Î µÎ°³¸¦ ½á¾ß ÇÕ´Ï´Ù.

 



 
SSL/TLS ÀÎÁõ
¾Õ¿¡ ¿­°ÅµÈ »ç¿ëÀÚ ÀÎÁõ±â¹ýµéÀº ¸ðµç À¥ ÄÁÅÙÃ÷¸¦ ¾ÏȣȭÇÏÁö ¾Ê½À´Ï´Ù´Â ´ÜÁ¡ÀÌ ÀÖ½À´Ï´Ù..ÃÖ±Ù ÀÎÅÍ³Ý ¹ðÅ·µî°ú °°ÀÌ Àü¼Û·Î»ó¿¡ Àü¼ÛµÇ´Â À¥ÄÁÅÙÃ÷ ¿ª½Ã º¸È£µÇ¾îÁ®¾ß ÇÏ´Â °æ¿ì°¡ ¸¹´Ù. SSL/TLS´Â »ç¿ëÀÚÀÎÁõ°ú À¥¼­¹ö µ¥ÀÌÅÍ¿Í ÄÁÅÙÃ÷¸¦ ¾ÏȣȭÇÏ´Â ¼ö´ÜÀÔ´Ï´Ù. SSLÀ» Áö¿øÇϱâ À§Çؼ­ Apache´Â Mod_SSL ¸ðµâÀ» °¡Áö°í ÀÖ°í, ÀÌ ¸ðµâÀº SSL v2, v3 ±×¸®°í »õ·Î¿î TLSÀ» »ç¿ëÇÏ´Â °­·ÂÇÑ ¾Ïȣȭ¸¦ Á¦°øÇÕ´Ï´Ù. ÇöÀç ÀÌ ¸ðµâÀº °­·ÂÇÑ 128bit¾Ïȣȭ¿Í RSA, Diffie-Hellman¾Ïȣȭ¸¦ Á¦°øÇÕ´Ï´Ù.
µ¿ÀÛ¿ø¸®: ÃÖÃÊ Çڵ彦ÀÌÅ© ÈÄ¿¡ SSLÀº ºñ¹ÐÅ°¸¦ »ý¼ºÇÏ°í ÀÌ ´ëĪŰ ¾Ïȣȭ°¡ µ¥ÀÌÅÍ ¾Ïȣȭ¸¦ À§ÇØ »ç¿ëµË´Ï´Ù. °ø°³Å°(ºñ´ëĪŰ)´Â ´Ü¸»ÀÇ ½Å¿ø ÀÎÁõ°ú ´ëĪŰ ±³È¯¿¡ »ç¿ëµË´Ï´Ù.     ¸Þ½ÃÁö ¹«°á¼ºÀº MAC(Massage Authentication Code)¿¡ ÀÇÇØ Á¦°øµÇ°í ½Å·ÚµÈ Á¢¼ÓÀ»     °¡´ÉÇÏ°Ô ÇÕ´Ï´Ù.
SSL ÇÁ·ÎÅäÄÝÀÌ Á¦°øÇÏ´Â ÁÖ¿ä±â´É
* »ç¼³Á¢¼Ó°ú µ¥ÀÌÅÍ ¾Ïȣȭ
* ¼­¹ö¿¡ Åë½ÅÇÏ´Â ´Ü¸» ÀÎÁõ
* ½Å·ÚµÈ Á¢¼Ó
 
SSL º¸¾È¼­¹ö ¼³Ä¡
º¸¾È¼­¹ö SSL Linux Apache 1.X¹öÀü
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=165&name=¸®´ª½º&home=º¸¾È
 
º¸¾È¼­¹ö SSL ( Linux Apache 2.X ¹öÀü)
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=155&name=¸®´ª½º&home=º¸¾È
 
Apache SSL ¼³Ä¡¹æ¹ý
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=164&name=¸®´ª½º&home=º¸¾È
 
2) PHP º¸¾È
php.ini º¸¾È¼³Á¤
 

º¸¾È¼³Á¤ ÀÌ¿ÜÀÇ php.ini »ó¼¼ÇÑ ¼³Á¤³»¿ëÀº ³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­¸¦ ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù.

³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­ - php.ini ȯ°æ¼³Á¤
http://nextline.net/?inc=support&html=pds_view&no=207&name=¸®´ª½º&home=PHP

¼³Á¤ÆÄÀÏ °æ·Î : /usr/local/lib/php.ini

 

 

php.ini º¸¾È¼³Á¤

 

safe_mode - On

safe_mode On ÀÏ °æ¿ì ÆÄÀÏÀ» ÀÌ µð·ºÅ丮 ¹× ±× ÇÏÀ§·ÎºÎÅÍ include ÇÏ´Â °æ¿ì´Â UID/GID ÀÇ Ã¼Å©°¡ ½ºÅµµË´Ï´Ù. ÀÌ·¯ÇÑ µð·ºÅ丮´Â include_path ¿¡ Æ÷ÇԵǵµ·Ï Çϰųª ¶Ç´Â include ½Ã¿¡ Àý´ë °æ·Î¸¦ »ç¿ëÇØ¾ß ÇÕ´Ï´Ù. exec°ü·ÃÀÇ ÇÔ¼ö¸¦ ÅëÇØ ½ÇÇàÇÒ ¼ö ÀÖ´Â ±ÇÇÑÀ» safe_mode_include_dir¿¡ ÀÖ´Â ½ÇÇàÆÄÀϸ¸À¸·Î ¼³Á¤ÇÕ´Ï´Ù.

 

ÀÌ °ªÀ» OnÀ¸·Î ¼³Á¤Çϸé PHP¿¡ ÀÇÇÑ ÆÄÀÏ ¾×¼¼½º ½Ã ±ÇÇÑÀ» Á¡°ËÇÕ´Ï´Ù. À¥ ÇÁ·Î±×·¥ÀÌ /etc/passwd µî ÁÖ¿ä ½Ã½ºÅÛ ÆÄÀÏÀ» ¾×¼¼½º ÇÏÁö ¸øÇϵµ·Ï Á¦ÇÑÇÒ ¼ö ÀÖÀ¸³ª, ÀÌ·Î ÀÎÇØ À¥ ÇÁ·Î±×·¥ÀÌ Á¤»ó ÀÛµ¿ÇÏÁö ¾ÊÀ» ¼ö ÀÖÀ¸´Ï ÁÖÀÇÇÏ¿©¾ß ÇÕ´Ï´Ù.

 

display_errors = On

Error Page ¶Ç´Â Warning Page ³ëÃâÀ» ÇÇÇϱâ À§ÇÑ °ÍÀÔ´Ï´Ù. °ø°ÝÀÚµéÀº ÀϺη¯ ¿¡·¯¸¦ ¹ß»ýÇÏ¿© ¼­¹ö¿¡ ´ëÇÑ Á¤º¸¸¦ È®ÀÎÇÕ´Ï´Ù. À̸¦ ¸·±â À§ÇØ ¾Æ·¡¿Í °°ÀÌ ¼öÁ¤ÇÕ´Ï´Ù.

On À¸·Î ÇßÀ» ½Ã À¥»çÀÌÆ®ÀÇ ÆÄÀÏ Á¤º¸³ª µ¥ÀÌŸº£À̽º ½ºÅ°¸¶µîÀÇ ½ÃÅ¥¸®Æ¼ Á¤º¸¸¦ Á¢¼Ó »ç¿ëÀÚ¿¡°Ô Ç¥Ãâ µÉ ¼öµµ Àֱ⠶§¹®ÀÔ´Ï´Ù. ÀÌ ¿É¼ÇÀ» OnÀ¸·Î ¼³Á¤ÇÏ´Â °æ¿ì PHP ½ÇÇà Áß ¹ß»ýÇÏ´Â ¿¡·¯ Á¤º¸°¡ »ç¿ëÀÚ ºê¶ó¿ìÀú¿¡ ¹ÝȯµË´Ï´Ù. ÀÌ Á¤º¸¿¡´Â À¥ ¼­¹ö »óÀÇ Àý´ë °æ·Î, SQL Äõ¸® µî °ø°ÝÀÚ¿¡°Ô À¯¿ëÇÑ Á¤º¸°¡ Æ÷ÇԵǾî ÀÖÀ¸¹Ç·Î, ¹Ýµå½Ã ÀÌ °ªÀ» Off·Î ¼³Á¤ÇÏ¿©¾ß ÇÕ´Ï´Ù.

 

register_globals = On

Ȥ½Ã¶óµµ ³·Àº ¹öÀüÀ» »ç¿ëÇÏ´Â °æ¿ì´Â ÀÌ ºÎºÐÀÌ µðÆúÆ®·Î On µÇ¾îÀִµ¥, Ưº°ÇÑ ÀÌÀ¯°¡ ¾ø´Ù¸é Off ·Î ¼³Á¤ÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù.

ÀÌ °ªÀ» OnÀ¸·Î ¼³Á¤Çϸé PHP°¡ ÀÔ·ÂÀ¸·Î ¹Þ¾ÆµéÀÌ´Â °ª(ȯ°æ º¯¼ö, GET, POST, ÄíÅ°, Server º¯¼ö)À» ¹«Á¶°Ç Àü¿ª(Global)º¯¼ö·Î ´Ù·ç°Ô µË´Ï´Ù. Àü¿ª º¯¼ö°¡ °íÀüÀûÀÎ C ÇÁ·Î±×·¥¿¡¼­ ¾ó¸¶³ª ¸¹Àº ¹ö±×¸¦ ¹ß»ý½ÃÄ×´ÂÁö ¾Æ½Å´Ù¸é, ÀÌ °ªÀ» Off·Î ¼³Á¤ÇÏ´Â °ÍÀÌ ¿Ö ¹Ù¶÷Á÷ÇÑÁö ÁüÀÛÇÒ ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù. Àü¿ª º¯¼ö´Â ÇÁ·Î±×·¥ÀÇ µ¿ÀÛ Áß ¾îµð¼­³ª º¯¼ö°ªÀÌ ¹Ù²ð ¼ö Àֱ⠶§¹®¿¡, À¥ ÇÁ·Î±×·¥ÀÇ ÀÎÀÚ Á¶ÀÛ, ¿¹±âÄ¡ ¸øÇÑ ¿Àµ¿ÀÛ µî ´Ù¾çÇÑ º¸¾È ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. PHP 4.2.0 ÀÌÈķδ º¸¾È»óÀÇ ¹®Á¦¸¦ °í·ÁÇØ µðÆúÆ®·Î Off·Î ¼³Á¤µÇ¾î ³ª¿ÀÁö¸¸, ¾ÆÁ÷ ¸¹Àº ÇÁ·Î±×·¥ÀÌ On »óÅ¿¡¼­¸¸ ÀÛµ¿Çϵµ·Ï °³¹ßµÇ¾î ÀÖ¾î ¼­¹ö °ü¸®ÀÚµéÀÌ OnÀ¸·Î º¯°æÇÏ´Â °æ¿ì°¡ ¸¹½À´Ï´Ù. On °ª¿¡ ÀÇÁ¸ÇÏ´Â ÇÁ·Î±×·¥ÀÌ ÀÖÀ¸¸é °³¹ßÀÚ¿¡°Ô ÇØ´ç ¹®Á¦¸¦ ¾Ë¸®°í ¼öÁ¤À» ¿ä±¸ÇϽô °ÍÀÌ ¹Ù¶÷Á÷ÇÕ´Ï´Ù

 

safe_mode_gid - Off

À§ÀÇ ¼³Á¤°ú ÇÔ²² ÆÄÀÏ ¾×¼¼½º ½Ã ±ÇÇÑÀ» Á¡°ËÇÕ´Ï´Ù. ÀÌ·Î ÀÎÇØ À¥ ÇÁ·Î±×·¥ÀÌ Á¤»ó ÀÛµ¿ÇÏÁö ¾ÊÀ» ¼ö ÀÖÀ¸´Ï ÁÖÀÇÇÏ¿©¾ß ÇÕ´Ï´Ù.

 

expose_php - Off

À¥ ºê¶ó¿ìÀúÀÇ ¿äû¿¡ ´ëÇØ PHP Á¤º¸¸¦ º¸³»Áö ¾Ê½À´Ï´Ù. ±×·¯³ª PHP È®ÀåÀÚ ¼³Á¤À» º¯°æÇÏ´Â µî Ãß°¡ÀûÀÎ Á¶Ä¡¸¦ ÃëÇÏÁö ¾Ê½À´Ï´Ù¸é, ¿©·¯ºÐÀÌ PHP¸¦ »ç¿ë ÁßÀ̶ó´Â »ç½ÇÀÌ ¼Õ½±°Ô ³ëÃâµÉ ¼ö ÀÖÀ¸¹Ç·Î º¸¾È»ó Å« µµ¿òÀÌ µÇÁö ¾Ê½À´Ï´Ù.

 

file_uploads - Off

ÇØ´ç »çÀÌÆ®ÀÇ PHP ÇÁ·Î±×·¥µéÀÌ ÆÄÀÏ ¾÷·Îµå¸¦ ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â´Ù¸é ÀÌ °ªÀ» Off·Î ¼³Á¤ÇÏ¿©, ÆÄÀÏ ¾÷·Îµå °ø°ÝÀÇ ¹ß»ý °¡´É¼ºÀ» ³·Ãâ ÇÊ¿ä°¡ ÀÖ½À´Ï´Ù. ÆÄÀÏ ¾÷·Îµå¸¦ ÅëÇÑ »çÀÌÆ® Àå¾ÇÀº ¸Å¿ì ºó¹øÇÏ°Ô ¹ß»ýÇÕ´Ï´Ù.

allow_url_fopen Off ÀÌ ¿É¼ÇÀ» OnÀ¸·Î ¼³Á¤Çϸé ÆÄÀÏ ¾×¼¼½º ½Ã ¿ÜºÎ »çÀÌÆ®ÀÇ ÆÄÀÏÀ» ºÒ·¯¿Ã ¼ö ÀÖ½À´Ï´Ù. ÀÌ ±â´ÉÀº ºÐ»ê ÄÄÇ»Æðú °³¹ß, °ü¸® Ãø¸é¿¡¼­ ¸Å¿ì Æí¸®ÇÏÁö¸¸, ¿ÜºÎ °ø°ÝÀÚ¿¡ ÀÇÇØ ¼­¹ö¸¦ ħŻ´çÇÏ°Ô µÇ´Â ÁÖ¿ä ¿øÀÎÀÌ µÇ¾î ¿Ô½À´Ï´Ù. ƯÈ÷ include(), require() °è¿­ÀÇ ÇÔ¼ö »ç¿ë½Ã ½É°¢ÇÑ º¸¾È »óÀÇ ¹®Á¦¸¦ À¯¹ßÇÏ°Ô µË´Ï´Ù. Ư¼öÇÑ °æ¿ì¸¦ Á¦¿ÜÇÏ°í´Â ÀÌ ±â´ÉÀÌ ÇÊ¿äÄ¡ ¾ÊÀ¸¹Ç·Î ÀÌ ¿É¼ÇÀ» ¹Ýµå½Ã Off·Î ¼³Á¤ÇϽñ⠹ٶø´Ï´Ù.

 

magic_quotes_gpc = Off

Sql Injection °ú °°Àº °ø°ÝÀ» ¸·´Âµ¥ µµ¿òÀÌ µË´Ï´Ù. GET/POST/Cookie ÀÇ ÀÔ·Â µ¥ÀÌÅÍ¿¡ °üÇؼ­ Ư¼ö ¹®ÀÚ¸¦ À̽ºÄÉÀÌÇÁ Get ¹æ½ÄÀ¸·Î ÀԷµǴ ".." ´Â ÀϹÝÀûÀ¸·Î ÇÊÅ͸µ Çϵµ·Ï ¼³°èµÇ°í ÀÖ½À´Ï´Ù. ½©¿¡´Â ".\./"´Â ".."°ú µ¿ÀÏÇÏ°Ô °£Áֵ˴ϴÙ. Ư¼ö¹®ÀÚ¿¡ ´ëÇÑ ÀüüÀûÀÎ Á¦ÇÑÀÌ ÇÊ¿äÇÏ´Ù.

 

ÀÌ ¿É¼ÇÀ» OnÀ¸·Î ¼³Á¤Çϸé PHP°¡ ÀÔ·ÂÀ¸·Î ¹Þ¾ÆµéÀÌ´Â °ª(ȯ°æ º¯¼ö, GET, POST, ÄíÅ°, Server º¯¼ö)¿¡ ´ÜÀÏ ÀÎ¿ë ºÎÈ£('), ÀÌÁß ÀÎ¿ë ºÎÈ£("), ¹é½½·¡½¬(), ³Î¹®ÀÚ(NUL)°¡ Æ÷ÇÔµÈ °æ¿ì ÀÚµ¿À¸·Î ÇØ´ç ¹®ÀÚ ¾Õ¿¡ ¹é½½·¡½¬¸¦ Ãß°¡ÇÏ¿© Ư¼ö ¹®ÀÚ Ã³¸®¸¦ ÇÕ´Ï´Ù. ÀÌ·Î ÀÎÇØ À¥ ÇÁ·Î±×·¥ÀÇ ÀÎÀÚ¸¦ º¯°æÇÏ´Â SQL ±¸¹® »ðÀÔ(injection) °ø°ÝÀÇ ¼º°ø·üÀ» ³·ÃçÁÝ´Ï´Ù. ÀÌ °ªÀ» Off·Î ¼³Á¤Çϸé /etc/passwd%00 °ú °°ÀÌ ³Î ¹®ÀÚ¸¦ »ç¿ëÇØ ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» ¿­¶÷ÇÒ ¼ö ÀÖÀ¸´Ï ¹Ýµå½Ã OnÀ¸·Î ¼³Á¤ÇÏ¿©¾ß ÇÕ´Ï´Ù.

 

magic_quotes_sybase - Off

Sybase »ç¿ëÀÚÀÇ Á¤»óÀûÀÎ DB Á¢¼ÓÀ» À§ÇØ ¸¸µé¾îÁø ±â´ÉÀÌÁö¸¸,

ÀÌ ±â´ÉÀº magic_quotes_gpc ¼³Á¤À» ¹«·ÂÈ­ÇÕ´Ï´Ù. ¿©·¯ºÐÀÌ Sybase »ç¿ëÀÚ°¡ ¾Æ´Ï¶ó¸é ¹Ýµå½Ã ÀÌ °ªÀ» Off·Î ¼³Á¤ÇÏ¿©¾ß ÇÕ´Ï´Ù. Sybase »ç¿ëÀÚ´Â PHP°¡ ÀÔ·ÂÀ¸·Î ¹Þ¾ÆµéÀÌ´Â ¸ðµç º¯¼ö¿¡ ´ëÇØ addslashes() ÇÔ¼ö¸¦ »ç¿ëÇÏ¿© ¸í½ÃÀûÀ¸·Î Ư¼ö ¹®ÀÚ Ã³¸®¸¦ ÇÏ¿©¾ß ÇÕ´Ï´Ù.

 

open_basedir - µð·ºÅ͸®

ÀÌ ¿É¼Ç¿¡ ÀûÀýÇÑ µð·ºÅ͸®¸¦ ¼³Á¤Çϸé, PHPÀÇ ÆÄÀÏ ¾×¼¼½º ½Ã ÁöÁ¤µÈ µð·ºÅ͸®(¹× ÇÏÀ§ µð·ºÅ͸®)¸¦ ¹þ¾î³­ ÆÄÀÏÀº ¾×¼¼½º ÇÒ ¼ö ¾ø°Ô µË´Ï´Ù.

 

safe_mode_exec_dir - µð·ºÅ͸®

ÀÌ ¿É¼ÇÀ» ÁöÁ¤Çϸé system(), exec(), passthru() µî ¿ÜºÎ ¸í·É¾î ½ÇÇà ½Ã ÁöÁ¤µÈ µð·ºÅ͸®¿¡ Á¸ÀçÇÏÁö ¾Ê´Â ÇÁ·Î±×·¥Àº ½ÇÇàÇÒ ¼ö ¾ø°Ô µË´Ï´Ù. °ø°ÝÀÚ°¡ ÀÓÀÇ·Î ¾÷·Îµå ÇÑ °ø°Ý µµ±¸³ª wget, xterm µî °ø°Ý¿¡ »ç¿ëµÉ ¸¸ÇÑ ¸í·É¾î¸¦ ½ÇÇàÇÒ ¼ö ¾øµµ·Ï ¸·À» ¼ö ÀÖ½À´Ï´Ù.

 

allow_url_fopen = On

URL(http:// ³ª ftp:// )À» ÆÄÀϷμ­ Ãë±ÞÇÒÁö¸¦ °áÁ¤ÇÕ´Ï´Ù.

¸¹ÀÌ ¹ß»ýÇÏ°í ÀÖ´Â ´ë±Ô¸ð ȨÆäÀÌÁö º¯Á¶´Â phpÀÇ ¿ÜºÎ»çÀÌÆ® ¼Ò½º ½ÇÇà±â´ÉÀ» ÀÌ¿ëÇÏ¿© ¾ÇÀÇÀûÀÎ ÇÁ·Î±×·¥À» ½ÇÇà½ÃÅ´À¸·Î½á ¹ß»ý½Ãŵ´Ï´Ù.

 

ÇÊ¿ä ½Ã Æ¯Á¤ ȨÆäÀÌÁö¸¸ ¿ÜºÎ »çÀÌÆ®ÀÇ ¼Ò½º ½ÇÇà Çã¿ëÀ» ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.

   

    

    ServerAdmin webmaster@nextline.co.kr

    DocumentRoot /home/nextline/public_html

    ServerName nextline.co.kr

    php_admin_flag allow_url_fopen On     <---------- ¶óÀÎ Ãß°¡

    ErrorLog logs/nextline.co.kr-error_log

    CustomLog logs/nextline.co.kr-access_log common

   

 


 
3) SSH º¸¾È
 
¨ç ¼³Á¤ÆÄÀÏ º¸¾ÈÀû¿ë

 
º¸¾È¼³Á¤ ÀÌ¿ÜÀÇ sshd_conf »ó¼¼ÇÑ ¼³Á¤³»¿ëÀº ³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­¸¦ ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù.

³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­ - SSH ȯ°æ¼³Á¤
http://nextline.net/?inc=support&html=pds_view&no=203&name=¸®´ª½º&home=±âŸ


 
¼³Á¤ÆÄÀÏ °æ·Î : /etc/sshd/sshd_conf
 

 

sshd_conf º¸¾È¼³Á¤

 

Port 22

ssh°¡ »ç¿ëÇÒ ±âº» Æ÷Æ®¸¦ ÁöÁ¤ÇÕ´Ï´Ù. Æ÷Æ® º¯°æ ½Ã /etc/services ÆÄÀÏ¿¡¼­ sshd °ü·Ã Æ÷Æ® ¿ª½Ã º¯°æÇÒ Æ÷Æ®·Î º¯°æÇØ ÁÖ¾î¾ß ÇÕ´Ï´Ù.

 

AllowUsers root nextline   

·Î±×ÀÎ Çã¶ôÇÒ °èÁ¤ nextline¿Í root µÎ °èÁ¤¿¡°Ô¸¸ ·Î±×ÀÎ Çã¿ë ÇÕ´Ï´Ù.

 

PermitRootLogin no

root ·Î±×ÀÎ Çã¿ë¿©ºÎ¸¦ °áÁ¤ÇÏ´Â °ÍÀÔ´Ï´Ù. yes, no, without-password¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. ÇöÀç no·Î µÇ¾î Àֱ⠶§¹®¿¡ Á÷Á¢  root·Î Á¢¼ÓÀÌ ºÒ°¡´ÉÇÕ´Ï´Ù. À̿ɼÇÀ» yes ·Î Çϱ⺸´Ù´Â ÀϹݰèÁ¤À¸·Î ·Î±×ÀÎÈÄ su ¸í·ÉÀ¸·Î root·Î ÀüȯÇÏ´Â °ÍÀÌ º¸¾È»ó ¾ÈÀüÇÕ´Ï´Ù.

 

ListenAddress 0.0.0.0

sshd°¡ ±Í¸¦ ±â¿ïÀÏ ÁÖ¼Ò¸¦ Á¤ÇØÁÝ´Ï´Ù. 0.0.0.0Àº ¸ðµç °÷À¸·Î ºÎÅÍ Á¢¼Ó À» ¹Þ¾ÆµéÀÌ°Ú´Ù´Â ÀǹÌÀÔ´Ï´Ù. ÇÏÁö¸¸ ÆÐŰ¡À» ÇÒ¶§ ¾î¶»°Ô ÇÑ°ÍÀÎÁö´Â ¸ð¸£°ÚÁö¸¸ tcp-wrapperÀÇ ¿µÇâÀ» ¹Þ¾Æ¼­ hosts.deny¿¡¼­ ¸·Çô ÀÖÀ¸¸é Á¢¼ÓÀÌ ¾ÈµÇ´Ï hosts.allow¿Í hosts.deny¿¡¼­ sshd2 Ç׸ñÀ¸·Î Á¦¾î¸¦ ÇÒ¼ö°¡ ÀÖ½À´Ï´Ù.

 

AllowedAuthentications   publickey,password

Sshd2°¡ Á¦°øÇÏ´Â ÀÎÁõÀº password¿Í publickey ±×¸®°í hostbased ¹æ½ÄÀÌ Àִµ¥, ±âº» ÀûÀ¸·Î public,password°¡ »ç¿ëµË´Ï´Ù. ÀÌ´Â ¼ø¼­´ë·Î ÀÎÁõÇÏ´Â ¹æ¹ýÀ» º¸¿©Áִµ¥, ¸ÕÀú publickey·Î ÀÎÁõÇÏ°í, µÎ ¹ø°·Î password·Î ÀÎÁõÇÑ´Ù´Â ÀǹÌÀÔ´Ï´Ù.

 

DenyUsers  nextline, 3737

Á¢±ÙÀ» °ÅºÎÇÒ ·ÎÄÃÀÇ À¯Àú¸¦ ÁöÁ¤ÇÕ´Ï´Ù. À§ ¼³Á¤Àº nextline ¹× uid°¡ 3737ÀÎ °èÁ¤À¸·Î ssh Á¢¼Ó ½ÃµµÇÒ °æ¿ì Á¢±ÙÀÌ °ÅºÎµË´Ï´Ù.

 

DenyGroups

¸í½ÃµÈ ±×·ìÀº ssh¼­ºñ½º¿¡ Á¢±ÙÇÒ ¼ö ¾øµµ·Ï ÇÏ´Â ±â´É ÀÔ´Ï´Ù.

(DenyGroups sysadmin accounting) ¿ÍÀϵåÄ«µå°¡ Áö¿øµÇ¸ç °ø¹é ¹®ÀÚ·Î ±×·ìÀ» ±¸ºÐÇÕ´Ï´Ù.

 

DenyHosts

¸í½ÃµÈ È£½ºÆ®´Â ssh¼­ºñ½º¿¡ Á¢±ÙÇÒ ¼ö ¾øµµ·Ï ÇÏ´Â ±â´É ÀÔ´Ï´Ù.

(Deny Hosts shell.ourcompany.net).È£½ºÆ® IP¸¦ ¾²°Å³ª È£½ºÆ® ¸íÀ» ¾µ ¼ö ÀÖÀ¸¸ç ¿Í Àϵå Ä«µå°¡ Áö¿øµÇ°í °ø¹é ¹®ÀڷΠȣ½ºÆ®¸¦ ±¸ºÐÇÕ´Ï´Ù.

 

AllowHosts   1.2.3.0/24 192.168.1.3

·Î±×ÀÎÀ» Çã°¡ÇÒ IP ¶Ç´Â IP ´ë¿ªÀ» ÁöÁ¤ÇÕ´Ï´Ù. ¿©·¯ °³ÀÏ °æ¿ì¿¡´Â °ø¶õÀ̳ª "," ·Î ±¸ºÐÇÏ¿© ³ª¿­ÇÏ¸é µÇ°í µµ¸ÞÀÎ À̸§ÀÏ °æ¿ì¿¡´Â reverse mappingÀÌ Á¦°øµÇ¾î¾ß ÇÕ´Ï´Ù.

 

AllowGroups

ssh¼­ºñ½º¿¡ Á¢±Ù °¡´ÉÇÑ ±×·ìÀ» ¸í½ÃÇÕ´Ï´Ù.

(¿¹ : AllowGroups sysadmin accounting) ¿ÍÀϵåÄ«µå°¡ Áö¿øµÇ¸ç °ø¹é¹®ÀÚ·Î ±×·ìÀ» ±¸ºÐÇÕ´Ï´Ù.

 

MaxConnections   0

ÃÖ´ë ¸î°³ÀÇ Á¢¼ÓÀ» Çã¶ôÇÒÁö¸¦ ÁöÁ¤ÇÕ´Ï´Ù. 0Àº Á¦ÇÑÀ» ÇÏÁö ¾Ê½À´Ï´Ù.

 

PasswordGuesses   3

¾ÏÈ£ÀÎÁõ ¹æ½ÄÀ¸·Î ÀÎÁõÇÒ ¶§ ÃÖ´ë ¸î Â÷·Ê ½Ãµµ¸¦ Çã¿ëÇÒ °ÍÀÎÁö ÁöÁ¤ÇÕ´Ï´Ù.

 

ssh1Compatibility   no

Ŭ¶óÀ̾ðÆ®°¡ ssh1¸¸ Áö¿øÇÒ °æ¿ì ssh1 µ¥¸óÀ» ½ÇÇàÇÒ °ÍÀÎÁö ¿©ºÎ¸¦ ÁöÁ¤ÇÕ´Ï´Ù. ssh1Àº º¸¾È»ó Ãë¾àÇϹǷΠno·Î ÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù.

 


 
¨è Prevent-SSH Bruteforce(¹«Â÷º° °ø°Ý) ¹æ¾î Åø
 
SSH Bruteforce(¹«Â÷º° °ø°Ý) ¹æ¾î Åø
 
Prevent À̶õ?
/var/log/secure ·Î±×¸¦ »ìÆ캸¸é ÀÏÁ¤ÇÑ ID¸¦ ÀÌ¿ëÇؼ­ SSH Á¢¼Ó ½Ãµµ¸¦ ÇÏ´Â °ÍÀ» º¼ ¼ö ÀÖÀ¸¸ç ÀÌ·± °ø°ÝÀº SSH Bruteforce(¹«Â÷º° °ø°Ý)·Î¼­, Æнº¿öµå »çÀü ÆÄÀÏÀ» ÀÌ¿ëÇؼ­ ¹Ì¸® ÁöÁ¤ÇÑ ¾ÆÀ̵ð¿Í ´ëÀÔÇÏ¿©, Á¢¼Ó °èÁ¤À» ¾Ë¾Æ ³»´Â ÇØÅ· ¹æ¹ýÀÔ´Ï´Ù. PreventÀº /var/log/secure ·Î±×ÀÇ ½Ç½Ã°£ ºÐ¼®ÇÏ¿© ƯÁ¤ ¾ÆÀÌÇÇ¿¡¼­ ÀÏÁ¤È½¼ö ÀÌ»ó Á¢¼Ó ½ÇÆа¡ ÀÌ·ç¾îÁö¸é °ø°Ý ¾ÆÀÌÇÇ¿¡ ´ëÇÑ clipping levelÀ» ÁöÁ¤Çؼ­ 5 levelÀÌ»ó ¿Ã¶ó°¡¸é ¾ÆÀÌÇÇÀ» ºí·Ï ½ÃÅ°´Â ÅøÀÔ´Ï´Ù.
 
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=187&name=¸®´ª½º&home=º¸¾È
 
¨é SSH root Á¢±Ù±ÝÁö
 
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=158&name=¸®´ª½º&home=±âŸ

4) VSFTP º¸¾È

º¸¾È¼³Á¤ ÀÌ¿ÜÀÇ vsftpd.conf »ó¼¼ÇÑ ¼³Á¤³»¿ëÀº ³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­¸¦ ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù.

³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­ - vsftp ȯ°æ¼³Á¤
http://nextline.net/?inc=support&html=pds_view&no=202&name=¸®´ª½º&home=±âŸ

 
¼³Á¤ÆÄÀÏ °æ·Î : /etc/vsftpd/vsftpd.conf

 

vsftp.conf º¸¾È¼³Á¤

 

chroot_local_user=YES (±âº»°ª = NO)

¸ðµç °èÁ¤ »ç¿ëÀÚ°¡ ÀÚ½ÅÀÇ È¨»óÀ§ µð·ºÅ丮¸¦ Á¢±ÙÇÒ ¼ö ¾øµµ·Ï ¼³Á¤ÇÕ´Ï´Ù.

FTP »ç¿ëÀÚ°¡ ½Ã½ºÅÛ¿¡ Á¢±ÙÇÒ ¼ö ÀÖÀ¸¸é À§ÇèÇϹǷΠ¹Ýµå½Ã È°¼ºÈ­ Çϴ°ÍÀÌ ÁÁ½À´Ï´Ù.

 

passwd_chroot_enable=NO (±âº»°ª = NO)

SSH·Î Á¢¼ÓÇßÀ» ¶§ ÀÚ½ÅÀÇ È¨ »óÀ§ µð·ºÅ丮¸¦ Á¢±ÙÇÒ ¼ö ¾øµµ·Ï ¼³Á¤ÇÕ´Ï´Ù.

chroot_local_user ¿É¼ÇÀÌ È°¼ºÈ­µÇ¾ú°í, OpenSSH¿¡ ÆÐÄ¡¸¦ ÇßÀ»°æ¿ì, SSH ¶ÇÇÑ ÀÚ½ÅÀÇȨ»óÀ§ µð·ºÅ丮¸¦ Á¢±ÙÇÒ ¼ö ¾øµµ·Ï ¼³Á¤ÇÒ ¼ö ÀÖÀ¸¸ç, /etc/passwd ÆÄÀÏÀÇ È¨ µð·ºÅ丮ÇʵåÀÇ /home/»ç¿ëÀÚ/./¿Í °°ÀÌ "/./"¸¦ ºÙ¿© »ç¿ëÀÚ¸¦ Ȩµð·ºÅ丮¿¡ Á¦ÇÑÇÏ°Ô ÇÕ´Ï´Ù.

 

chroot_list_enable=NO (±âº»°ª = NO)

¸í½ÃµÈ »ç¿ëÀÚ°¡ ÀÚ½ÅÀÇ È¨»óÀ§ µð·ºÅ丮¸¦ Á¢±ÙÇÒ ¼ö ¾øµµ·Ï ¼³Á¤ÇÕ´Ï´Ù.

ÀÌ ¿É¼ÇÀº chroot_local_user ¿É¼ÇÀÌ ºñÈ°¼ºÈ­µÇ¾î ÀÖ¾î¾ß »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. Àüü Àû¿ëÀÌ ¾Æ´Ï¶ó ÀϺΠ»ç¿ëÀÚ¸¸ Á¦ÇÑÇÒ ¶§ ÆíÇÏÁö¸¸, °³º° Àû¿ëÀº º¸¾È»ó ÁÁÁö ¾Ê½À´Ï´Ù.

 

chroot_list_file=/etc/vsftpd.chroot_list (±âº»°ª =/etc/vsftpd.chroot_list)

»ç¿ëÀÚÀÇ È¨»óÀ§ µð·ºÅ丮¸¦ ¼³Á¤ÇÑ ÆÄÀÏÀ» ÁöÁ¤ÇÕ´Ï´Ù.

chroot_list_enable ¿É¼ÇÀ» È°¼ºÈ­ÇßÀ» °æ¿ì¿¡ ¸®½ºÆ®¸¦ Àоî¿Ã ÆÄÀÏÀ» ÁöÁ¤ÇÕ´Ï´Ù.

 

secure_chroot_dir=/usr/share/empty (±âº»°ª = /usr/share/empty)

secure chroot()¿¡ »ç¿ëµÉ µð·ºÅ丮¸¦ ÁöÁ¤ÇÕ´Ï´Ù. ÀÌ ¿É¼Ç¿¡¼­ ÁöÁ¤µÈ µð·ºÅ丮´Â ºñ¾î ÀÖ¾î¾ß µÇ¸ç, ftp »ç¿ëÀÚ¿¡ ´ëÇØ ¾²±â ±ÇÇÑÀÌ ¾ø¾î¾ß µË´Ï´Ù.

 

 
5) SENDMAIL º¸¾È

¨ç ¹öÀü Á¤º¸ ¼û±â±â
sendmailÀÌ ¸®½¼ÇÏ°í ÀÖ´Â 25¹øÀ¸·Î Á¢¼ÓÇÏ¸é ¾Æ·¡¿Í °°ÀÌ sendmailÀÇ ¹öÀü Á¤º¸¸¦ ¾Ë ¼öÀִµ¥, ±»ÀÌ º¸¿©ÁÙ ÇÊ¿ä°¡ ¾øÀ¸¹Ç·Î ÀÌ Á¤º¸¸¦ »èÁ¦Çϰųª ´Ù¸¥ Á¤º¸·Î º¸¿©ÁÖµµ·Ï ÇÕ´Ï´Ù.
 
 
 
 
À̸¦ À§Çؼ­´Â ¾Æ·¡¿Í °°ÀÌ ÁÖ¼®À» Á¦°ÅÇÑ ÈÄ °ü·Ã ºÎºÐÀ» »èÁ¦Çϰųª ÀÓÀÇÀÇ ¹®ÀÚ¿­À» Ãß°¡ÇÑ ÈÄ sendmailÀ» Àç°¡µ¿ ÇÕ´Ï´Ù.
¼³Á¤ÆÄÀÏ °æ·Î : /etc/mail/sendmail.cf
º¯°æÀü)

 
º¯°æÈÄ)

 
sendmail Àç°¡µ¿
[root@nextline ~]# /etc/rc.d/init.d/sendmail restart
25¹øÀ¸·Î Á¢¼Ó ½Ã ¹öÀüÁ¤º¸°¡ Ãâ·ÂµÇÁö ¾Ê½À´Ï´Ù. ±×·¯³ª ÀÌ »óÅ¿¡¼­ HELP¸¦ ÀÔ·ÂÇÏ¸é ¾Æ·¡¿Í °°ÀÌ Á¤º¸°¡ Ç¥½ÃµË´Ï´Ù.

helpfile ÆÄÀÏÀ» »èÁ¦Çϰųª ´Ù¸¥ À̸§À¸·Î º¯°æÇϸé HELP ÀԷ½ÿ¡µµ ¹öÀü Á¤º¸°¡ Ç¥½ÃµÇÁö ¾Ê½À´Ï´Ù.
/etc/mail/helpfile ÆÄÀÏ¸í º¯°æ

  
helpfile ÆÄÀÏ¸í º¯°æÈÄ HELP ÀԷ½ÿ¡µµ ¹öÀü Á¤º¸°¡ Ç¥½ÃµÇÁö ¾Ê½À´Ï´Ù.

 
¨è procmailÀ» ÀÌ¿ëÇÑ ½ºÆÔ ÇÊÅ͸µ
 
Sendmail + Procmail + Hcode ¿¬µ¿¼³Ä¡
´Ù¿î·Îµå : rpmfind.net
 
¸®´ª½º ¼³Ä¡½Ã ±âº»ÀûÀ¸·Î sendmail, procmail ÆÐÅ°Áö´Â ¼³Ä¡µÇ¾î ÀÖÀ¸¹Ç·Î Çѱ۵ðÄÚµù¿¡ ÇÊ¿äÇÑ hcode ÆÐÅ°Áö¸¦ Ãß°¡ ¼³Ä¡Çϸç sendmail, procmail ÀÌ ¼³Ä¡µÇ¾î ÀÖÁö ¾ÊÀ»°æ¿ì 3°¡Áö ÆÐÅ°Áö¸¦ ¸ðµÎ ¼³Ä¡ÇÕ´Ï´Ù.
 
hcode ´Ù¿î·Îµå

 
hcode ¼³Ä¡

 
sendmail + procmail + hcode ¿¬µ¿ È®ÀÎ
 

 
 
 
define(`PROCMAIL_MAILER_PATH',`/usr/bin/procmail')dnl
FEATURE(local_procmail,`',`procmail -t -Y -a $h -d $u')dnl
MAILER(procmail)dnl
 
À§ ³»¿ëÀÌ Ãâ·ÂµÇÁö ¾Ê°Å³ª ´Ù¸£°Ô Ãâ·ÂµÈ´Ù¸é ÀûÀýÈ÷ ¼öÁ¤ÇÏ°í ´ÙÀ½À» ½ÇÇàÇÕ´Ï´Ù.
 
[root@nextline mail]# su -
Password:
[root@nextline mail]# cd /etc/mail
[root@nextline mail]# vi /etc/mail/sendmail.mc
[root@nextline mail]# make
[root@nextline mail]# /etc/rc.d/init.d/sendmail restart
 
/etc/procmailrc ÆÄÀÏ»ý¼º ¹× ¼³Á¤³»¿ë
[root@nextline mail]# vi /etc/procmailrc
 
procmailrc ¼³Á¤
 
FILTERREASON = "100"
 
# ȯ°æº¯¼ö¼³Á¤
 
# LOGFILE=/dev/null
# VERBOSE=on
VERBOSE=off
# DROPPRIVS=yes
PATH=/usr/bin:/usr/local/bin:/bin
SHELL=/bin/sh
FORMAIL=/usr/bin/formail
 
NL = "
"
TAB = "   "
NOW = `date +"%Y-%m-%d %H:%M"`
 
# ¸ÞÀϼ­¹ö ÇØÅ·¹æÁö (Á¦¸ñÀÌ 1024ÀÚ ÀÌ»óÀÎ°Í »èÁ¦)
 
:0
* -1024^0
* ^Subject:\/.*
* 1^1 $MATCH ?? .
/dev/null
 
:0
* -19^0
* 1^1 $DEFAULT ?? .
{
    TAB = "    "
}
 
 
# Çѱ۵ðÄÚµù
 
:0 fhw
* ^(Subject|From|Cc|To):.*=\?EUC-KR\?(B|Q)\?
| $FORMAIL -c | hcode -dk -m
 
:0 fh w
* ^(Subject|From|Cc|To):.*=\?EUC_KR\?(B|Q)\?
| $FORMAIL -c | hcode -dk -m
 
:0 fh w
* ^(Subject|From|Cc|To):.*=\?ks_c_5601-1987\?(B|Q)\?
| $FORMAIL -c | hcode -dk -m
 
# Á¦¸ñ ±¸Çϱâ
 
EMAILSUBJECT = ""
REPLYSUBJECT = ""
 
:0
* ^Subject:\/.*
{
    ORGSUBJECT = "$MATCH"
    REPLYSUBJECT = "Re: $MATCH"
    EMAILSUBJECT = "$NL$MATCH$NL"
}
 
# ¹Ý¼Û¸ÞÀÏ ÇÊÅ͸µ(»èÁ¦)
 
:0
* EMAILSUBJECT ?? Returned mail: see transcript for details
* $ ^To:.*@$HOST
/dev/null
 
# ¼­¹ö¿¡¼­ ¹ß¼ÛµÈ ¸ÞÀÏÀº ±×´ë·Î Àü¼Û
 
:0
* ^FROM_DAEMON
$DEFAULT
 
# ¸Þ½ÃÁö ¾ÆÀ̵ð Á¸Àç¿©ºÎ È®ÀÎ
# ÆĶõ¸ÞÀÏ°ú ¸ð³×Ÿµî ¸î¸î »çÀÌÆ®ÀÇ À߸øµÈ °³¹ß·Î Ãß°¡µÈ Ç׸ñÀÔ´Ï´Ù.
 
HASMESSAGEID = "no"
 
:0
* ^Message-ID:
* $ ! ^Message-ID:( )*[<][0-9]+[.][0-9a-zA-Z]+@$HOST[>]
{
  HASMESSAGEID = "yes"
}
 
:0
* ^X-Mailer: .*(ParanMail Web|Netpion Enterprise|Office Outlook)
*
{
   HASMESSAGEID = "yes"
}
 
# ¼ö½ÅÀÚÀÇ ¼º¸í Á¸Àç¿©ºÎ È®ÀÎ(±¤°í¸ÞÀÏÀº ¼ö½ÅÀÚÀÇ À̸§À» ¸ð¸¥´Ù.)
 
HASRECEIVERNAME = "no"
 
:0
* ^To:.*[<].*[>]
* ! ^To:( )*[<].*[>]
{
   HASRECEIVERNAME = "yes"
}
 
# ¹ß½ÅÀÚÀÇ ¼º¸í Á¸Àç¿©ºÎ È®ÀÎ
 
HASSENDERNAME = "no"
 
:0
* ^From:.*[<].*[>]
* ! ^From:( )*[<].*[>]
{
   HASSENDERNAME = "yes"
}
 
# Á¦¸ñÀÌ Æ¯¼öÇÑ ÇüÅÂÀΰ¡(¿¹¸¦µé¸é "[¿¡ÇǼҵå]..." µîµî)
 
ISFORMATTEDSUBJECT = "no"
 
:0
* EMAILSUBJECT ?? ^( )*[[(<]+.*[])>]+
{
   ISFORMATTEDSUBJECT = "yes"
}
 
:0
* EMAILSUBJECT ?? ^( )*(ÀÐÀ½|Re|Fw):
{
   ISFORMATTEDSUBJECT = "yes"
}
 
# ¸ÞÀÏÀü¼Û°æ·Î°¡ ¼¼°³ ÀÌ»óÀΰÍ(±¤°í/¹ÙÀÌ·¯½º¸ÞÀÏÀº ¹Ù·Î Àü¼ÛµÇ¾î °æ·Î°¡ Àû½À´Ï´Ù.)
# sendmail Àº ¸ÞÀÏÆ÷¸äÆÃÀ» Çϱ⶧¹®¿¡ ±âº»ÀûÀ¸·Î ÇÑ °³ÀÌ»óÀÔ´Ï´Ù.
# µû¶ó¼­ qmail ÀÏ °æ¿ì "* -2^0" ¸¦ "* -1^0" ·Î º¯°æÇϴ°ÍÀÌ ÁÁ½À´Ï´Ù.
 
HASMULTIPATH = "no"
 
:0
* -2^0
* 1^1 ^Received:.*$
{
   HASMULTIPATH = "yes"
}
 
# ·Î±×È­ÀÏ º¯°æ
 
LOGFILE=/var/log/procmail
 
# ±¤°íÇ¥½Ã¸ÞÀÏ ¼ºÀΰü·Ã¸ÞÀÏ ÇÊÅ͸µ
 
ISSPAM = "no"
 
:0
* ! ISSPAM ?? yes
* ! EMAILSUBJECT ?? [[(<£¨]+(±¤.*°í|ÎÆ.*ͱ|È«.*º¸|µ¿.*ÀÇ|±Ý.*À¶)[])>]+
* ! EMAILSUBJECT ?? @( )*$
* ! EMAILSUBJECT ?? (¼ºÀα¤°í|¼ºÀÎÁ¤º¸|¸ôÄ«|Æ÷¸£³ë|½º¿ÍÇÎ|ºü±¸¸®|¹«»èÁ¦|³ë¸ðÀÚÀÌÅ©|ÀÚÀ§ÇÑ´Ù|ÀÚÀ§ÇÏ´Â|»Ç¸£³ë|Æä´Ï½º|½ß¼î|¼½½º)
* ! EMAILSUBJECT ?? (Ä«[.-]+µå|½Å[.-]+¿ë|´ë[.-]+Ãâ|ÃÖ[.-]+Àú[.-]+±Ý[.-]+¸®)
* ! EMAILSUBJECT ?? ((±¤°í)
{ }
 
:0 E
{
    ISSPAM = "yes"
    FILTERREASON = "201"
}
 
:0
* ISSPAM ?? yes
{
    LOG = "[$NOW] [Del$FILTERREASON] $DEFAULT$TAB$ORGSUBJECT$NL"
    LOGFILE
 
    :0
    /dev/null
}
 
# 100k ÀÌ»óÀÇ ¸ÞÀÏ
# ÷ºÎÈ­ÀÏÀÌ ÀÖÀ¸¸ç, Á¤»óÀû À̸ÞÀÏÇüÅ°¡ ¾Æ´Ñ°Í ÇÊÅ͸µ
# ±âŸ¸ÞÀÏ Åë°ú
 
ISVIRUS = "no"
 
:0
* ISVIRUS ?? no
* > 100000
* HASMESSAGEID ?? no
* HASRECEIVERNAME ?? no
* HASSENDERNAME ?? no
* HASMULTIPATH ?? no
* ^Content-Type: multipart[/]mixed
{
    ISVIRUS = "yes"
    FILTERREASON = "301"
}
 
:0
* ISVIRUS ?? yes
{
    LOG = "[$NOW] [Blk$FILTERREASON] $DEFAULT$TAB$ORGSUBJECT$NL"
    LOGFILE
 
    :0
    * ! ^Precedence:.*junk
    * ! ^X-Loop:.*
    /var/spool/mail/spam
 
    :0
    /dev/null
}
 
:0
* > 100000
{
    LOG = "[$NOW] [Pas$FILTERREASON] $DEFAULT$TAB$ORGSUBJECT$NL"
    LOGFILE
 
    :0
    $DEFAULT
}
 
# 15k - 100k »çÀÌÀÇ ¸ÞÀÏ
# ÷ºÎÈ­ÀÏÀÌ ÀÖÀ¸¸ç, Á¤»óÀû À̸ÞÀÏÇüÅ°¡ ¾Æ´Ï¸ç, ÷ºÎÈ­ÀϸíÀÌ ÇѱÛÀÌ ¾Æ´Ñ°Í ÇÊÅ͸µ
# ±âŸ¸ÞÀÏ Åë°ú
 
ISVIRUS = "no"
 
:0 B
* ISVIRUS ?? no
* > 15000
* ^Content-Type: audio[/]x-wav;
* ^.*(file)?name="?[a-z0-9 ._-]+\.(bat|cmd|com|cpl|exe|hta|scr|pif|vbs|zip)"?$
{
    ISVIRUS = "yes"
    FILTERREASON = "302"
}
 
:0 B
* ISVIRUS ?? no
* > 15000
* ^Content-Disposition: (attachment|inline);
* ^.*(file)?name="?[a-z0-9 ._-]+\.(bat|cmd|com|cpl|hta|scr|pif|vbs)"?$
{
    ISVIRUS = "yes"
    FILTERREASON = "303"
}
 
:0 B
* ISVIRUS ?? no
* > 15000
* < 65000
* ^Content-Disposition: (attachment|inline);
* ^.*(file)?name="?[a-z0-9 ._-]+\.(exe|zip)"?$
{
    ISVIRUS = "yes"
    FILTERREASON = "304"
}
 
:0
* ISVIRUS ?? yes
* > 15000
* < 65000
* ^Content-Disposition: (attachment|inline);
* ^.*(file)?name="?[a-z0-9 ._-]+\.(exe|vbs|zip)"?$
{
    :0
    * ! HASMULTIPATH ?? no
    { }
 
    :0 E
    {
    ISVIRUS = "no"
    FILTERREASON = "100"
    }
}
 
:0
* ISVIRUS ?? yes
{
    LOG = "[$NOW] [Vir$FILTERREASON] $DEFAULT$TAB$ORGSUBJECT$NL"
    LOGFILE
 
    :0
    * !
    * ! ^Precedence:.*junk
    * ! ^X-Loop:.*
    /var/spool/mail/spam
 
    :0
    /dev/null
}
 
:0
* > 15000
{
    LOG = "[$NOW] [Pas$FILTERREASON] $DEFAULT$TAB$ORGSUBJECT$NL"
    LOGFILE
 
    :0
    $DEFAULT
}
 
# 0k - 15k »çÀÌÀÇ ¸ÞÀÏ
# ÷ºÎÈ­ÀÏÀÌ ¾ø´Â ¹ÙÀÌ·¯½º¸ÞÀÏ ÇÊÅ͸µ
 
ISVIRUS = "no"
 
:0
* ISVIRUS ?? no
* < 5000
* HASMESSAGEID ?? no
* HASMULTIPATH ?? no
* H ?? ^Content-Type:( )*multipart/mixed
* 2^0
* -1^1 B ?? ^Content-Type:
{
    ISVIRUS = "yes"
    FILTERREASON = "305"
}
 
:0
* ISVIRUS ?? yes
{
    LOG = "[$NOW] [Vir$FILTERREASON] $DEFAULT$TAB$ORGSUBJECT$NL"
    LOGFILE
 
    :0
    * !
    * ! ^Precedence:.*junk
    * ! ^X-Loop:.*
    /var/spool/mail/spam
 
    :0
    /dev/null
}
 
# 0-15k »çÀÌÀÇ ¸ÞÀÏ ÇÊÅ͸µ
 
ISSPAM = "no"
 
:0
* !
* ISSPAM ?? no
* HASMESSAGEID ?? no
* HASRECEIVERNAME ?? no
* ISFORMATTEDSUBJECT ?? no
* HASMULTIPATH ?? no
{
    ISSPAM = "yes"
}
 
:0
* !
* ISSPAM ?? no
* ^Received: from [0-9]+\.[0-9]+\.[0-9]+\.[0-9]+ [(][[][0-9]+\.[0-9]+\.[0-9]+\.[0-9]+[]][)]
{
    ISSPAM = "yes"
}
 
:0
* !
* ISSPAM ?? no
* < 8000
* ^Received: from .*[0-9]+-[0-9]+-[0-9]
{
    ISSPAM = "yes"
}
 
:0
* ISSPAM ?? no
* EMAILSUBJECT ?? (Ä«µå( )*(´ë³³|°í¹Î|ºú|¿¬Ã¼|´ëÃâ|¼ÒÀ¯ÀÚ|¼ÒÁöÀÚ)|(±ä±Þ|±ÞÇÑ)( )*ÀÚ±Ý|Á÷ÀåÀÎ.*°ø¹«¿ø|°ø¹«¿ø.*Á÷ÀåÀÎ)
{
    ISSPAM = "yes"
    FILTERREASON = "202"
}
 
:0
* ISSPAM ?? no
* EMAILSUBJECT ?? (µ¹·Á¸·|¿¬Ã¼.*±Ý¸®|±Ý¸®.*¿¬Ã¼|¸¸¿ø.*ÀºÇà|ÀºÇà.*¸¸¿ø|1[%]´ë±Ý¸®|Á÷ÀåÀÎ.*¿©¼º¿ì´ë|[(][0-9]*¸¸¿ø[)])
{
    ISSPAM = "yes"
    FILTERREASON = "202"
}
 
:0
* ISSPAM ?? no
* EMAILSUBJECT ?? [a-z ][a-z ][a-z ][a-z ][a-z ]$
* ISFORMATTEDSUBJECT ?? no
* ! EMAILSUBJECT ?? ^( )*(Re|Fw):
* ! EMAILSUBJECT ?? ^( )*[a-z0-9*?+[($^-]+
{
    ISSPAM = "yes"
    FILTERREASON = "203"
}
 
:0
* ISSPAM ?? no
* < 10000
* H ?? ^Content-Type:( )*multipart/alternative
* 2^0
* -1^1 B ?? ^Content-Type:
{
    ISSPAM = "yes"
    FILTERREASON = "204"
}
 
:0
* ISSPAM ?? no
* < 8000
{
    :0
    * ! ^From: .*@(paypal.com|mortghelper.com|blocjunk.com|mail2Maggie.com|blocspam.com|worldbusinesslink.org)
    * ! ^From: .*@(bisops.com|teadrive.com|superpowerball.com|proxad.net|jsivey.com|dbz.com|alapaz.com)
    { }
 
    :0 E
    {
   ISSPAM = "yes"
   FILTERREASON = "205"
    }
}
 
:0
* ISSPAM ?? no
* < 8000
{
    :0
    * ! HB ?? (Pain Relief|rx refill|rx meds|obesity|Viagra|Cialis|Xanax|Valium|Amvien|schlong|Prozac|V-I-A-G-R-A)
    * ! HB ?? (sexual health|porn|orgasm)
    * ! HB ?? (mor( )?t( )?g( )?a( )?g( )?e)
    { }
 
    :0 E
    {
   ISSPAM = "yes"
   FILTERREASON = "206"
    }
}
 
:0
* ISSPAM ?? no
* < 8000
* -2^0
* 1^1 HB ?? (meds|Medication|drug)
{
    ISSPAM = "yes"
    FILTERREASON = "207"
}
 
:0
* ISSPAM ?? no
* < 8000
* -5^0
* 1^1 HB ?? [.](com|net|org)"[>][<][/]a[>]
{
    ISSPAM = "yes"
    FILTERREASON = "208"
}
 
:0
* ISSPAM ?? yes
{
    LOG = "[$NOW] [Blk$FILTERREASON] $DEFAULT$TAB$ORGSUBJECT$NL"
    LOGFILE
 
    :0
    * ! ^Precedence:.*junk
    * ! ^X-Loop:.*
    /var/spool/mail/spam
 
    :0
    /dev/null
}
 
:0
{
    LOG = "[$NOW] [Pas$FILTERREASON] $DEFAULT$TAB$ORGSUBJECT$NL"
    LOGFILE
 
    :0
    $DEFAULT
}
 
sendmail Àç°¡µ¿
procmail ¿¬µ¿À» À§ÇØ sendmail ¸¦ Àç°¡µ¿ ÇÕ´Ï´Ù.
[root@nextline ~]# /etc/rc.d/init.d/sendmail restart
 
ÇÊÅ͸µ ¸ÞÀÏ°èÁ¤ spam
/etc/procmailrc ÆÄÀÏ¿¡ ÀÇÇØ ÇÊÅ͸µµÈ ¸ÞÀϵéÀÌ spam °èÁ¤À¸·Î ½×ÀÌ°Ô µË´Ï´Ù.

 
 
 
procmail ·Î±×ÆÄÀÏ
/etc/procmailrc ¿¡ ¼³Á¤ÇÑ´ë·Î /var/log/procmail ÆÄÀÏ¿¡ ·Î±×°¡ ±â·ÏµË´Ï´Ù.

 
 
 
¨é Clam AntiVirus¸¦ ÀÌ¿ëÇÑ ¸ÞÀϼ­¹ö ¹ÙÀÌ·¯½º Â÷´Ü
 
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=142&name=¸®´ª½º&home=º¸¾È
 
¨ê AUTH ¼³Á¤
sendmail·Î ¾Æ¿ô·èÀ» »ç¿ë½Ã º¸³»´Â ¸ÞÀÏ(SMTP)ÀÇ ÀÎÁõ ¼³Á¤ ºÎºÐÀÌ ÀÖ½À´Ï´Ù.
/etc/mail/access ¿¡¼­ ¾Æ¿ô·èÀÌ Á¢¼ÓµÇ´Â IP´ë¿ªÀ» ¼³Á¤ÇÏ¸é µÇÁö¸¸, ¾î´À °÷¿¡¼­µµ Á¢¼ÓÀ» °¡´ÉÇÏ°Ô ÇÏ·Á¸é SMTP Auth¸¦ ÅëÇÏ¿© °èÁ¤ ÀÎÁõÀ» ÅëÇÑ ÀÎÁõÀÌ À¯¿ëÇÕ´Ï´Ù.
 
¼³Á¤ÆÄÀÏ °æ·Î : /etc/mail/sendmail.mc
 
¼öÁ¤Àü
dnl TRUST_AUTH_MECH(`EXTERNAL DIGEST-MD5 CRAM-MD5 LOGIN PLAIN')dnl
¼öÁ¤ÈÄ (ÁÖ¼® dnl Á¦°Å)
TRUST_AUTH_MECH(`EXTERNAL DIGEST-MD5 CRAM-MD5 LOGIN PLAIN')dnl
 
¼öÁ¤Àü
dnl define(`confAUTH_MECHANISMS', `EXTERNAL GSSAPI DIGEST-MD5 CRAM-MD5 LOGIN
PLAIN')dnl
¼öÁ¤ÈÄ (ÁÖ¼® dnl Á¦°Å)
define(`confAUTH_MECHANISMS', `EXTERNAL GSSAPI DIGEST-MD5 CRAM-MD5 LOGIN PLAIN')dnl
 
¼öÁ¤Àü
dnl # DAEMON_OPTIONS(`Port=smtp,Addr=127.0.0.1, Name=MTA')dnl
¼öÁ¤ÈÄ (ÁÖ¼® dnl Á¦°Å Addr=0.0.0.0 º¯°æ)
DAEMON_OPTIONS(`Port=smtp,Addr=0.0.0.0, Name=MTA')dnl
 
sendmail.cf »ý¼º
[root@nextline ~]# m4 /etc/mail/sendmail.mc > /etc/mail/sendmail.cf
 
sasl2 ¼³Á¤È®ÀÎ
[root@nextline ~]# cat /usr/lib/sasl2/Sendmail.conf
pwcheck_method:saslauthd
 
/etc/sysconfig/saslauthd ÆíÁý
MECH=shadow ÀÌ ºÎºÐÀÇ °ªÀ» pamÀ¸·Î º¯°æ
 
sendmail Àç°¡µ¿
[root@nextline ~]# /etc/rc.d/init.d/sendmail resetart
 
saslauthd Àç°¡µ¿
[root@nextline ~]# /etc/rc.d/init.d/salauthd restart
 
6) MYSQL º¸¾È
 
¨ç ¸®¸ðÆ® ¿¢¼¼½º Â÷´Ü
 
¸ÕÀú MySQLÀÌ µðÆúÆ®·Î ¸®½º´×ÇÏ´Â 3306/tcp Æ÷Æ®¸¦ Â÷´ÜÇØ µ¥ÀÌÅͺ£À̽º°¡ ·ÎÄ÷Π¼³Ä¡µÈ PHP ¾îÇø®ÄÉÀ̼ǿ¡ ÀÇÇؼ­¸¸ »ç¿ëµÇ°Ô ÇÕ´Ï´Ù. 3306/tcp Æ÷Æ®¸¦ ¸®½º´×ÇÏÁö ¸øÇÏ°Ô ÇÏ¸é ´Ù¸¥ È£½ºÆ®·ÎºÎÅÍ Á÷Á¢ TCP/IP Á¢¼ÓÀ» Çؼ­ MySQL µ¥ÀÌÅͺ£À̽º¸¦ °ø°ÝÇÒ °¡´É¼ºÀÌ ÁÙ¾îµì´Ï´Ù. ±×·¯³ª mysql.sock socket À» ÅëÇÑ ·ÎÄà Ŀ¹Â´ÏÄÉÀ̼ÇÀº ¿©ÀüÈ÷ °¡´ÉÇÕ´Ï´Ù. 3306/tcp Æ÷Æ®¸¦ ¸®½º´×ÇÏÁö ¸øÇÏ°Ô ÇÏ·Á¸é /etc/my.cnfÀÇ [mysqld] ºÎºÐ¿¡ ´ÙÀ½À» Ãß°¡ÇÏ¿© mysqlÀ» Àç°¡µ¿ÇÕ´Ï´Ù.
 
skip-networking
¶Ç´Â
[root@nextline ~]# /usr/local/mysql/bin/mysqld_safe –skip-networking &
 
¸®¸ðÆ®·Î µ¥ÀÌÅÍ ¹é¾÷À» ÇÑ´ÙµçÁö µîÀÇ ÀÌÀ¯·Î µ¥ÀÌÅͺ£À̽º¸¦ ¸®¸ðÆ® ¿¢¼¼½º Çؾ߸¸ ÇÏ´Â °æ¿ì ¾Æ·¡¿Í °°ÀÌ SSH ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÕ´Ï´Ù.
 
[root@nextline ~]# ssh mysqlserver /usr/local/mysql/bin/mysqldump -A > backup
 
¨è µðÆúÆ® »ç¿ëÀÚ/µ¥ÀÌÅͺ£À̽º »èÁ¦
 
¼³Ä¡½Ã ±âº»ÀûÀ¸·Î ¼³Ä¡µÇ´Â test µðºñ ¹× ·çÆ® ¾îÄ«¿îÆ®¸¦ Á¦¿ÜÇÑ ¸ðµç ¾îÄ«¿îÆ®¸¦ »èÁ¦ÇÕ´Ï´Ù. ÀÌ·¸°Ô Çϸé À͸í Á¢¼ÓÀ¸·Î µ¥ÀÌÅͺ£À̽º¸¦ ¼³Á¤ÇÏ´Â °ÍÀ» ¸·À» ¼ö ÀÖ½À´Ï´Ù.
 
[root@nextline ~]# mysql -u root -p
Enter password:
 
mysql> use mysql;
Database changed
mysql> drop database test;
Query OK, 0 rows affected (0.08 sec)
 
mysql> use mysql;
Database changed
mysql> delete from db;
Query OK, 3 rows affected (0.03 sec)
 
mysql> delete from user where not(host="localhost" and user="root");
Query OK, 4 rows affected (0.01 sec)
 
mysql> flush privileges;
Query OK, 0 rows affected (0.02 sec)
 
7) BIND º¸¾È
 
¨ç Bind ÃֽŠÆÐÅ°Áö ¾÷µ¥ÀÌÆ®
 
8.x ÀÌÀü ¹öÀüÀº Àß ¾Ë·ÁÁø º¸¾È¹ö±×°¡ ÀÖÀ¸¹Ç·Î ÃֽŠBIND ¹öÀüÀ¸·Î ¾÷±×·¹À̵带 Çϵµ·Ï ÇÕ´Ï´Ù. ¶ÇÇÑ, ¹öÀüº°º¸¾È Ãë¾àÁ¡ÀÌ Á¸ÀçÇÒ ¼ö ÀÖÀ¸¹Ç·Î
http://www.isc.org/products/BIND/bind-security.html ¿¡ ÁÖ±âÀûÀ¸·Î ¹æ¹®ÇÏ¿© »ìÆ캸±æ ¹Ù¶ø´Ï´Ù.
 
¨è Bind-chroot ȯ°æ Àû¿ë
 
BIND´Â root °èÁ¤ ´ë½Å named °èÁ¤À¸·Î ½ÇÇàÇÕ´Ï´Ù. ¶ÇÇÑ, chroot ȯ°æÀ» ±¸¼ºÇÏ¿© ³×ÀÓ¼­¹öÀÇ º¸¾È Ãë¾àÁ¡À¸·Î °ø°Ý´çÇÏ´õ¶óµµ ³×ÀÓ¼­¹ö°¡ ƯÁ¤ µð·ºÅ丮 ÀÌ»óÀÇ »óÀ§·Î ¹þ¾î³ªÁö ¸øÇÏ°Ô ¼³Á¤ÇÕ´Ï´Ù.
 
´Ù¿î·Îµå : rpmfind.net
bind-chroot ÆÐÅ°Áö ¼³Ä¡

 
 
 
zone ÆÄÀÏ°æ·Î

 
 
 
--------------------------------------------------------------------------------------- 
 
6. º¸¾ÈÇÁ·Î±×·¥
 
1) À¥ ¾îÇø®ÄÉÀÌ¼Ç º¸¾È Åø
 
À¥ ¾îÇø®ÄÉÀÌ¼Ç º¸¾ÈÅÛÇø´ (PHP ¹öÀü)
 
KWST (KISA Web Security Template)
Ãֱ٠ȨÆäÀÌÁö¿¡ Á¸ÀçÇÏ´Â À¥ ¾îÇø®ÄÉÀ̼ÇÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© SQL Injection, iframe »ðÀÔ µîÀÇ °ø°ÝÀÌ ºñ¹øÈ÷ ÀÌ·ç¾îÁö°í ÀÖÀ¸¸ç, ÀÌ·¯ÇÑ À¥ ÇØÅ·À¸·Î ÀÎÇÏ¿© ȨÆäÀÌÁö º¯Á¶, µ¥ÀÌÅÍÀ¯½Ç, ½ÉÁö¾î ½Ã½ºÅÛ±îÁö ÇØÅ·¿¡ ³ëÃâµÇ¾î ¸·´ëÇÑ ÇÇÇظ¦ ÀÔ´Â »ç·Ê°¡ º¸°íµÇ°í ÀÖ½À´Ï´Ù.
À¥ ¾îÇø®ÄÉÀ̼ÇÀÇ Ãë¾àÁ¡À» º¸¿ÏÇϱâ À§Çؼ­´Â Ãë¾àÁ¡ÀÇ ¿øÀÎÀÌ µÇ´Â ȨÆäÀÌÁö ¼Ò½º¸¦ Á÷Á¢ ¼öÁ¤ÇØ¾ß Çϳª ´ëºÎºÐÀÇ Áß¼Ò È¨ÆäÀÌÁöÀÇ °æ¿ì, °³¹ßÀηÂÀÇ ¹Ìºñ·Î ÀÎÇØ Ä§ÇØ»ç°í°¡ Áö¼ÓÀûÀ¸·Î Àç¹ßÇÏ´Â ¹®Á¦°¡ ¹ß»ýÇÏ°í ÀÖ½À´Ï´Ù. KWST´Â À¥ÀÎÅÍÆäÀ̽º¸¦ ÀÌ¿ëÇÑ °£´ÜÇÑ ¼³Á¤À¸·Î ȨÆäÀÌÁö ¼Ò½º¿¡ SQL Injection, iframe, XSS, ¼Ò½ºº¯Á¶, ¾ÆÀÌÇÇ Â÷´Ü µîÀÇ º¸¾È¼³Á¤À» ÇÒ ¼ö ÀÖ´Â º¸¾È ÅøÀÔ´Ï´Ù.
 
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=194&name=¸®´ª½º&home=º¸¾È
 
2) ¾ÆÆÄÄ¡ º¸¾È ¸ðµâ
 
ModSecurity¸¦ ÀÌ¿ëÇÑ ¾ÆÆÄÄ¡ À¥¼­º¸ º¸¾È ±¸Ãà
Mod Security´Â Apache À¥ ¼­¹ö¸¦ À§ÇÑ ¿ÀÇ ¼Ò½º À¥ ¹æÈ­º®ÀÔ´Ï´Ù.
 
³Ø½ºÆ®¶óÀÎ ±â¼ú¹®¼­
http://nextline.net/?inc=support&html=pds_view&no=130&name=¸®´ª½º&home=º¸¾È
 
 
  find ¸í·É¾î »ç¿ë¹ý
  À©µµ¿ì º¸¾ÈÁöħ ¸Þ´º¾ó





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ