2011ǯ03·î20Æü
ftp Àܳ¤Ë»þ´Ö¤¬¤«¤«¤ë
/etc/proftpd.conf
¢¨°ìÈÖ²¼¤Î¹Ô¤ËÄɲÃ
¢£¥í¥°¥¤¥ó»þ´Ö¤Îû½Ì²½
UseReverseDNS off¡¡¡¡¡¡(DNSµÕ°ú¤¤òÄä»ß¡§»þ´Öû½Ì¤Ë¤Ï¤µ¤Û¤É¸ú²Ì¤Ê¤·)
IdentLookups off¡¡¡¡¡¡(Ident¤ÎÄä»ß¡§xinet.dÀßÄê¤ÎÊѹ¹¤Ë¤è¤ê¥Ñ¥é¥á¡¼¥¿¤¬Í¸ú¤Ë¤Ê¤ë¡£¸ú²ÌÀäÂç)
proftpd.conf¤Îͤë¾ì½ê¤Ï¡¢
/usr/local/etc/
¤Î¾ì¹ç¤â¤¢¤ë
¢¨°ìÈÖ²¼¤Î¹Ô¤ËÄɲÃ
¢£¥í¥°¥¤¥ó»þ´Ö¤Îû½Ì²½
UseReverseDNS off¡¡¡¡¡¡(DNSµÕ°ú¤¤òÄä»ß¡§»þ´Öû½Ì¤Ë¤Ï¤µ¤Û¤É¸ú²Ì¤Ê¤·)
IdentLookups off¡¡¡¡¡¡(Ident¤ÎÄä»ß¡§xinet.dÀßÄê¤ÎÊѹ¹¤Ë¤è¤ê¥Ñ¥é¥á¡¼¥¿¤¬Í¸ú¤Ë¤Ê¤ë¡£¸ú²ÌÀäÂç)
proftpd.conf¤Îͤë¾ì½ê¤Ï¡¢
/usr/local/etc/
¤Î¾ì¹ç¤â¤¢¤ë
¥³¥á¥ó¥È¹Ô°Ê³°¤òɽ¼¨
egrep -v '^$|^#' /etc/httpd/conf/httpd.conf
egrep -v '^$|^#' /etc/apache2/conf/httpd.conf
egrep -v '^$|^#' /etc/apache2/conf/httpd.conf
awk»ÈÍÑÎã¡¡¥Õ¥¡¥¤¥ë̾¤Î¤ßÀÚ¤ê½Ð¤·
ls -l | grep 7·î | awk -F " " '{print $9}'
ls -l | grep 11·î | awk -F " " '{print $9}'
ls -l | grep 11·î | awk -F " " '{print $9}'
2007ǯ03·î10Æü
ICMP¥á¥Ã¥»¡¼¥¸
=================================
ICMP¥á¥Ã¥»¡¼¥¸
=================================
ICMP¤Î¥Ø¥Ã¥ÀÃæ¤Ë¤¢¤ë¡Ö¥³¡¼¥É¡×Éôʬ¤Ë¤Ï¡¢¥¨¥é¡¼¤ÎÍ×°ø¤òɽ¤¹¿ôÃͤ¬¥»¥Ã¥È¤µ¤ì¡¢
Á÷¿®¤µ¤ì¤ë¡£¶ñÂÎŪ¤Ë¤Ï¡¢¼¡¤Î¤è¤¦¤Ê¥¨¥é¡¼Í×°ø¤¬¤¢¤ë¡£
¥¿¥¤¥× µ¡Ç½
0 ¥¨¥³¡¼±þÅú¡Êecho reply¡Ë
3 ¤¢¤ÆÀèÉÔã¡Êdestination unreachable¡Ë
4 ¥½¡¼¥¹¡¦¥¯¥¨¥ó¥Á¡Êsource quench¡¢Á÷¿®¸µÍÞÀ©¡Ë
5 ¥ê¥À¥¤¥ì¥¯¥ÈÍ×µá¡Êredirect¡¢·ÐÏ©Êѹ¹Í×µá¡Ë
8 ¥¨¥³¡¼Í×µá¡Êecho request¡Ë
11 »þ´ÖͲá¡Êtime exceeded¡Ë
12 ¥Ñ¥é¥á¡¼¥¿°Û¾ï¡Êparameter problem¡Ë
13 ¥¿¥¤¥à¥¹¥¿¥ó¥×Í×µá¡Êtimestamp request¡Ë
14 ¥¿¥¤¥à¥¹¥¿¥ó¥×±þÅú¡Êtimestamp reply¡Ë
15 ¾ðÊóÍ×µá¡Êinformation request¡Ë
16 ¾ðÊó±þÅú¡Êinformation reply¡Ë
17 ¥¢¥É¥ì¥¹¡¦¥Þ¥¹¥¯Í×µá¡Êaddress mask request¡Ë
18 ¥¢¥É¥ì¥¹¡¦¥Þ¥¹¥¯±þÅú¡Êaddress mask reply¡Ë
¥¿¥¤¥×3¡½¤¢¤ÆÀèÉÔã
¥³¡¼¥É °ÕÌ£
0 ¥Í¥Ã¥È¥ï¡¼¥¯¤¬Åþã¤Ç¤¤Ê¤¤¡§¥ë¡¼¥È¤¬ÄêµÁ¤µ¤ì¤Æ¤¤¤Ê¤¤
1 ¥Û¥¹¥È¤ËÅþã¤Ç¤¤Ê¤¤¡§¥¿¡¼¥²¥Ã¥È¤È¤Ê¤ë¥Þ¥·¥ó¤¬¸«¤Ä¤«¤é¤Ê¤¤
2 ¥×¥í¥È¥³¥ë¤ËÅþã¤Ç¤¤Ê¤¤¡§»ØÄꤵ¤ì¤¿¥×¥í¥È¥³¥ë¤¬ÍøÍѤǤ¤Ê¤¤
3 ¥Ý¡¼¥È¤ËÅþã¤Ç¤¤Ê¤¤¡§»ØÄꤵ¤ì¤¿¥Ý¡¼¥È¤ÇÂÔ¤Á¼õ¤±¾õÂ֤ˤʤäƤ¤¤Ê¤¤
4 DF¥Õ¥é¥°¤¬¥»¥Ã¥È¤µ¤ì¤Æ¤¤¤Æ¥Õ¥é¥°¥á¥ó¥È¤Ç¤¤Ê¤¤¡§IP¥Õ¥é¥°¥á¥ó¥Æ¡¼¥·¥ç¥ó¤¬
ɬÍפÀ¤¬¡¢DF¥Õ¥é¥°¤¬¥»¥Ã¥È¤µ¤ì¤Æ¤¤¤ë¤Î¤Ç¡¢IP¥Ñ¥±¥Ã¥È¤ò¥Õ¥é¥°¥á¥ó¥È¤¹¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤¡£
¤Ê¤ªRFC1191¡ÊPMTU discovery¡Ë¤Ç¤Ï¡¢¤³¤Î¥á¥Ã¥»¡¼¥¸¤òÊÖ¤¹¾ì¹ç¤Ë¡¢Àµ¤·¤¤MTUÃͤò
ICMP¥Ø¥Ã¥ÀÃæ¤Ë³ÊǼ¤¹¤ë¤³¤È¤òµá¤á¤Æ¤¤¤ë
5 ¥½¡¼¥¹¡¦¥ë¡¼¥È¤Î¼ºÇÔ¡§IP¥Ñ¥±¥Ã¥ÈÃæ¤Ë¥½¡¼¥¹¡¦¥ë¡¼¥È¡Ê·Ðͳ¤¹¤ë¥ë¡¼¥È¤Î»ØÄê¡Ë
¤¬´Þ¤Þ¤ì¤Æ¤¤¤ë¤¬¡¢¤½¤Î¥ë¡¼¥È¤Ø¥ë¡¼¥Æ¥£¥ó¥°¤¹¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤
7¡Á ¤½¤Î¤Û¤«¤Î¤µ¤Þ¤¶¤Þ¤ÊÍýͳ¡ÊÍ¥ÀèÅÙ»ØÄê¤ä¥µ¡¼¥Ó¥¹¡¦¥¿¥¤¥×¤Î»ØÄê¤Ê¤É¤¬Àµ¤·¤¯¤Ê¤¤¤Ê¤É¡Ë
¤Ë¤è¤Ã¤ÆIP¥Ñ¥±¥Ã¥È¤ò¤¢¤ÆÀè¤Þ¤ÇÆÏ¤±¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤¡£7°Ê¾å¤Î¥³¡¼¥É¤Ï¡¢
¥ª¥ê¥¸¥Ê¥ë¤ÎRFC¡ÊRFC792¡Ë¤Ç¤ÏÄêµÁ¤µ¤ì¤Æ¤ª¤é¤º¡¢¤½¤Î¸å¤Î³ÈÄ¥¤Ë¤è¤Ã¤ÆÄêµÁ¤µ¤ì¤Æ¤¤¤ë
ICMP¥á¥Ã¥»¡¼¥¸
=================================
ICMP¤Î¥Ø¥Ã¥ÀÃæ¤Ë¤¢¤ë¡Ö¥³¡¼¥É¡×Éôʬ¤Ë¤Ï¡¢¥¨¥é¡¼¤ÎÍ×°ø¤òɽ¤¹¿ôÃͤ¬¥»¥Ã¥È¤µ¤ì¡¢
Á÷¿®¤µ¤ì¤ë¡£¶ñÂÎŪ¤Ë¤Ï¡¢¼¡¤Î¤è¤¦¤Ê¥¨¥é¡¼Í×°ø¤¬¤¢¤ë¡£
¥¿¥¤¥× µ¡Ç½
0 ¥¨¥³¡¼±þÅú¡Êecho reply¡Ë
3 ¤¢¤ÆÀèÉÔã¡Êdestination unreachable¡Ë
4 ¥½¡¼¥¹¡¦¥¯¥¨¥ó¥Á¡Êsource quench¡¢Á÷¿®¸µÍÞÀ©¡Ë
5 ¥ê¥À¥¤¥ì¥¯¥ÈÍ×µá¡Êredirect¡¢·ÐÏ©Êѹ¹Í×µá¡Ë
8 ¥¨¥³¡¼Í×µá¡Êecho request¡Ë
11 »þ´ÖͲá¡Êtime exceeded¡Ë
12 ¥Ñ¥é¥á¡¼¥¿°Û¾ï¡Êparameter problem¡Ë
13 ¥¿¥¤¥à¥¹¥¿¥ó¥×Í×µá¡Êtimestamp request¡Ë
14 ¥¿¥¤¥à¥¹¥¿¥ó¥×±þÅú¡Êtimestamp reply¡Ë
15 ¾ðÊóÍ×µá¡Êinformation request¡Ë
16 ¾ðÊó±þÅú¡Êinformation reply¡Ë
17 ¥¢¥É¥ì¥¹¡¦¥Þ¥¹¥¯Í×µá¡Êaddress mask request¡Ë
18 ¥¢¥É¥ì¥¹¡¦¥Þ¥¹¥¯±þÅú¡Êaddress mask reply¡Ë
¥¿¥¤¥×3¡½¤¢¤ÆÀèÉÔã
¥³¡¼¥É °ÕÌ£
0 ¥Í¥Ã¥È¥ï¡¼¥¯¤¬Åþã¤Ç¤¤Ê¤¤¡§¥ë¡¼¥È¤¬ÄêµÁ¤µ¤ì¤Æ¤¤¤Ê¤¤
1 ¥Û¥¹¥È¤ËÅþã¤Ç¤¤Ê¤¤¡§¥¿¡¼¥²¥Ã¥È¤È¤Ê¤ë¥Þ¥·¥ó¤¬¸«¤Ä¤«¤é¤Ê¤¤
2 ¥×¥í¥È¥³¥ë¤ËÅþã¤Ç¤¤Ê¤¤¡§»ØÄꤵ¤ì¤¿¥×¥í¥È¥³¥ë¤¬ÍøÍѤǤ¤Ê¤¤
3 ¥Ý¡¼¥È¤ËÅþã¤Ç¤¤Ê¤¤¡§»ØÄꤵ¤ì¤¿¥Ý¡¼¥È¤ÇÂÔ¤Á¼õ¤±¾õÂ֤ˤʤäƤ¤¤Ê¤¤
4 DF¥Õ¥é¥°¤¬¥»¥Ã¥È¤µ¤ì¤Æ¤¤¤Æ¥Õ¥é¥°¥á¥ó¥È¤Ç¤¤Ê¤¤¡§IP¥Õ¥é¥°¥á¥ó¥Æ¡¼¥·¥ç¥ó¤¬
ɬÍפÀ¤¬¡¢DF¥Õ¥é¥°¤¬¥»¥Ã¥È¤µ¤ì¤Æ¤¤¤ë¤Î¤Ç¡¢IP¥Ñ¥±¥Ã¥È¤ò¥Õ¥é¥°¥á¥ó¥È¤¹¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤¡£
¤Ê¤ªRFC1191¡ÊPMTU discovery¡Ë¤Ç¤Ï¡¢¤³¤Î¥á¥Ã¥»¡¼¥¸¤òÊÖ¤¹¾ì¹ç¤Ë¡¢Àµ¤·¤¤MTUÃͤò
ICMP¥Ø¥Ã¥ÀÃæ¤Ë³ÊǼ¤¹¤ë¤³¤È¤òµá¤á¤Æ¤¤¤ë
5 ¥½¡¼¥¹¡¦¥ë¡¼¥È¤Î¼ºÇÔ¡§IP¥Ñ¥±¥Ã¥ÈÃæ¤Ë¥½¡¼¥¹¡¦¥ë¡¼¥È¡Ê·Ðͳ¤¹¤ë¥ë¡¼¥È¤Î»ØÄê¡Ë
¤¬´Þ¤Þ¤ì¤Æ¤¤¤ë¤¬¡¢¤½¤Î¥ë¡¼¥È¤Ø¥ë¡¼¥Æ¥£¥ó¥°¤¹¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤
7¡Á ¤½¤Î¤Û¤«¤Î¤µ¤Þ¤¶¤Þ¤ÊÍýͳ¡ÊÍ¥ÀèÅÙ»ØÄê¤ä¥µ¡¼¥Ó¥¹¡¦¥¿¥¤¥×¤Î»ØÄê¤Ê¤É¤¬Àµ¤·¤¯¤Ê¤¤¤Ê¤É¡Ë
¤Ë¤è¤Ã¤ÆIP¥Ñ¥±¥Ã¥È¤ò¤¢¤ÆÀè¤Þ¤ÇÆÏ¤±¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤¡£7°Ê¾å¤Î¥³¡¼¥É¤Ï¡¢
¥ª¥ê¥¸¥Ê¥ë¤ÎRFC¡ÊRFC792¡Ë¤Ç¤ÏÄêµÁ¤µ¤ì¤Æ¤ª¤é¤º¡¢¤½¤Î¸å¤Î³ÈÄ¥¤Ë¤è¤Ã¤ÆÄêµÁ¤µ¤ì¤Æ¤¤¤ë
2007ǯ03·î08Æü
ipv4¤Ë´Ø¤¹¤ëÀßÄê -1-
=====================================
ipv4ÀßÄê -¤½¤Î£±-
=====================================
/proc/sys/net/ipv4/¤Î²¼¤Ëipv4¤Ë´Ø¤¹¤ëÀßÄ꤬¤¢¤ë¡£
¢£/proc/sys/net/ipv4/icmp_destunreach_rate
¥Ñ¥±¥Ã¥ÈÇË´þ¤·¤¿¾ì¹ç¤Ë¤½¤Î¥Ñ¥±¥Ã¥È¤Îȯ¿®¸µ¤ËICMP¥á¥Ã¥»¡¼¥¸ÊÖ¤¹
¤³¤Î»þ¤Î®ÅÙ¤òÀßÄê¡£
¢£/proc/sys/net/ipv4/icmp_echo_ignore_all
echo ¥Ñ¥±¥Ã¥È¤ËÈ¿±þ¤·¤Þ¤»¤ó¡£
DoS ¹¶·â¤Ë¤¢¤Ã¤¿¾ì¹ç¤Ë"1"¤òÀßÄꤹ¤ë¤È±þÅú¤·¤Ê¤¯¤Ê¤ê¤Þ¤¹¡£
¢£/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
¥Í¥Ã¥È¥ï¡¼¥¯¤Î¥Ö¥í¡¼¥É¥¥ã¥¹¥È¥¢¥É¥ì¥¹¤Ë ping ¤¹¤ë¤È¡¢¤¹¤Ù¤Æ¤Î¥Û¥¹¥È¤¬±þÅú¤¹¤ë¤³¤È¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£
¤³¤ì¤ò»È¤¦¤È¾¯¤Ê¤¤¥Ñ¥±¥Ã¥È¤Ç¿¤¯¤Î¥È¥é¥Õ¥£¥Ã¥¯¤òȯÀ¸¤Ç¤¤Þ¤¹¡£
¡Ö 1¡× ¤Ë¤·¤Æ¡¢¤³¤Î¤è¤¦¤Ê¥Ö¥í¡¼¥É¥¥ã¥¹¥È¥á¥Ã¥»¡¼¥¸¤Ï̵»ë¤Ç¤¤Þ¤¹¡£
¢£/proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
¤³¤ì¤òÀßÄꤹ¤ë¤È¡¢¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Î¥Û¥¹¥È¤¬¡¢¥Ö¥í¡¼¥É¥¥ã¥¹¥È¥¢¥É¥ì¥¹¸þ¤±
¤È¤ß¤Ê¤·¤¿¥Õ¥ì¡¼¥à¤ËÂФ·¤ÆÉÔÀµ¤ËÈ¿±þ¤·¤¿¤¿¤á¤Ëȯ¤·¤¿ ICMP error ¤ò̵»ë¤·¤Þ¤¹¡£
¢£/proc/sys/net/ipv4/igmp_max_memberships
¤³¤Î¥Û¥¹¥È¤ÇÂÔ¤Á¼õ¤±¤¹¤ë igmp (¥Þ¥ë¥Á¥¥ã¥¹¥È) ¥½¥±¥Ã¥È¤ÎºÇÂç¿ô¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§20
¢£/proc/sys/net/ipv4/inet_peer_gc_maxtime
¥¬¥Ù¡¼¥¸¥³¥ì¥¯¥·¥ç¥ó¤ò¹Ô¤¦ºÇÂç´Ö³Ö¡£¤³¤Î´Ö³Ö¤Ï¡¢¥×¡¼¥ë¾å¤Î¥á¥â¥êÉé²Ù¤¬Ä㤤
¾ì¹ç¤Ë¸úÎϤò»ý¤Á¤Þ¤¹¡£ jiffies ñ°Ì¤Ç¤¹¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§120
¢£/proc/sys/net/ipv4/inet_peer_gc_mintime
¥¬¥Ù¡¼¥¸¥³¥ì¥¯¥·¥ç¥ó¤ò¹Ô¤¦ºÇ¾®´Ö³Ö¡£¤³¤Î´Ö³Ö¤Ï¡¢¥×¡¼¥ë¾å¤Î¥á¥â¥êÉé²Ù¤¬¹â¤¤¾ì¹ç¤Ë¸úÎϤò»ý¤Á¤Þ¤¹¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§10
¢£/proc/sys/net/ipv4/inet_peer_maxttl
¥¨¥ó¥È¥ê¤Î time-to-live ¤ÎºÇÂçÃÍ¡£
»È¤ï¤ì¤Ê¤«¤Ã¤¿¥¨¥ó¥È¥ê¤Ï¡¢¥×¡¼¥ë¤Ë¥á¥â¥êÉé²Ù¤¬¤Ê¤¤¾ì¹ç
(¤Ä¤Þ¤ê¥×¡¼¥ë¤Î¥¨¥ó¥È¥ê¿ô¤¬Èó¾ï¤Ë¾®¤µ¤¤¾ì¹ç)¡¢¤³¤Î´ü´Ö¤¬¤¹¤®¤ë¤È´ü¸ÂÀÚ¤ì¤È¤Ê¤ê¤Þ¤¹¡£ jiffies ñ°Ì¤Ç¤¹¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§600
¢£/proc/sys/net/ipv4/inet_peer_minttl
¥¨¥ó¥È¥ê¤Î time-to-live ¤ÎºÇ¾®ÃÍ¡£
¥Ñ¥±¥Ã¥È¤ÎºÆ¹½À®¤ò¹Ô¤¦Â¦¤Ç¤Ï¡¢¥Õ¥é¥°¥á¥ó¥È¤Î time-to-live ¤ò¥«¥Ð¡¼¤Ç¤¤ë½½Ê¬¤ÊÂ礤µ¤Ë¤·¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£
¤³¤Î time-to-live ¤ÎºÇ¾®Ãͤϡ¢¥×¡¼¥ë¤Î¥µ¥¤¥º¤¬ inet_peer_threshold ¤è¤ê¾®¤µ¤¤¾ì¹ç¤ËÊݾڤµ¤ì¤Þ¤¹¡£ jiffies ñ°Ì¤Ç¤¹¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§120
¢£/proc/sys/net/ipv4/ip_default_ttl
¥Ñ¥±¥Ã¥È¤Î Time To Live ÃͤǤ¹¡£ ¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§64
µðÂç¤Ê¥Í¥Ã¥È¥ï¡¼¥¯¤Ç¤ÏÁý¤ä¤¹¾ì¹ç¤â¤¢¤ê¤Þ¤¹¤¬¡¢¶½Ì£¤À¤±¤ÇÁý¤ä¤µ¤Ê¤¤¤è¤¦¤Ë¡£
·ÐÏ©¤Î¥ë¡¼¥×¤¬¤¢¤Ã¤¿¾ì¹çÈï³²¤¬Â礤¯¤Ê¤ê¤Þ¤¹¡£
ipv4ÀßÄê -¤½¤Î£±-
=====================================
/proc/sys/net/ipv4/¤Î²¼¤Ëipv4¤Ë´Ø¤¹¤ëÀßÄ꤬¤¢¤ë¡£
¢£/proc/sys/net/ipv4/icmp_destunreach_rate
¥Ñ¥±¥Ã¥ÈÇË´þ¤·¤¿¾ì¹ç¤Ë¤½¤Î¥Ñ¥±¥Ã¥È¤Îȯ¿®¸µ¤ËICMP¥á¥Ã¥»¡¼¥¸ÊÖ¤¹
¤³¤Î»þ¤Î®ÅÙ¤òÀßÄê¡£
¢£/proc/sys/net/ipv4/icmp_echo_ignore_all
echo ¥Ñ¥±¥Ã¥È¤ËÈ¿±þ¤·¤Þ¤»¤ó¡£
DoS ¹¶·â¤Ë¤¢¤Ã¤¿¾ì¹ç¤Ë"1"¤òÀßÄꤹ¤ë¤È±þÅú¤·¤Ê¤¯¤Ê¤ê¤Þ¤¹¡£
¢£/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
¥Í¥Ã¥È¥ï¡¼¥¯¤Î¥Ö¥í¡¼¥É¥¥ã¥¹¥È¥¢¥É¥ì¥¹¤Ë ping ¤¹¤ë¤È¡¢¤¹¤Ù¤Æ¤Î¥Û¥¹¥È¤¬±þÅú¤¹¤ë¤³¤È¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£
¤³¤ì¤ò»È¤¦¤È¾¯¤Ê¤¤¥Ñ¥±¥Ã¥È¤Ç¿¤¯¤Î¥È¥é¥Õ¥£¥Ã¥¯¤òȯÀ¸¤Ç¤¤Þ¤¹¡£
¡Ö 1¡× ¤Ë¤·¤Æ¡¢¤³¤Î¤è¤¦¤Ê¥Ö¥í¡¼¥É¥¥ã¥¹¥È¥á¥Ã¥»¡¼¥¸¤Ï̵»ë¤Ç¤¤Þ¤¹¡£
¢£/proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
¤³¤ì¤òÀßÄꤹ¤ë¤È¡¢¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Î¥Û¥¹¥È¤¬¡¢¥Ö¥í¡¼¥É¥¥ã¥¹¥È¥¢¥É¥ì¥¹¸þ¤±
¤È¤ß¤Ê¤·¤¿¥Õ¥ì¡¼¥à¤ËÂФ·¤ÆÉÔÀµ¤ËÈ¿±þ¤·¤¿¤¿¤á¤Ëȯ¤·¤¿ ICMP error ¤ò̵»ë¤·¤Þ¤¹¡£
¢£/proc/sys/net/ipv4/igmp_max_memberships
¤³¤Î¥Û¥¹¥È¤ÇÂÔ¤Á¼õ¤±¤¹¤ë igmp (¥Þ¥ë¥Á¥¥ã¥¹¥È) ¥½¥±¥Ã¥È¤ÎºÇÂç¿ô¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§20
¢£/proc/sys/net/ipv4/inet_peer_gc_maxtime
¥¬¥Ù¡¼¥¸¥³¥ì¥¯¥·¥ç¥ó¤ò¹Ô¤¦ºÇÂç´Ö³Ö¡£¤³¤Î´Ö³Ö¤Ï¡¢¥×¡¼¥ë¾å¤Î¥á¥â¥êÉé²Ù¤¬Ä㤤
¾ì¹ç¤Ë¸úÎϤò»ý¤Á¤Þ¤¹¡£ jiffies ñ°Ì¤Ç¤¹¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§120
¢£/proc/sys/net/ipv4/inet_peer_gc_mintime
¥¬¥Ù¡¼¥¸¥³¥ì¥¯¥·¥ç¥ó¤ò¹Ô¤¦ºÇ¾®´Ö³Ö¡£¤³¤Î´Ö³Ö¤Ï¡¢¥×¡¼¥ë¾å¤Î¥á¥â¥êÉé²Ù¤¬¹â¤¤¾ì¹ç¤Ë¸úÎϤò»ý¤Á¤Þ¤¹¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§10
¢£/proc/sys/net/ipv4/inet_peer_maxttl
¥¨¥ó¥È¥ê¤Î time-to-live ¤ÎºÇÂçÃÍ¡£
»È¤ï¤ì¤Ê¤«¤Ã¤¿¥¨¥ó¥È¥ê¤Ï¡¢¥×¡¼¥ë¤Ë¥á¥â¥êÉé²Ù¤¬¤Ê¤¤¾ì¹ç
(¤Ä¤Þ¤ê¥×¡¼¥ë¤Î¥¨¥ó¥È¥ê¿ô¤¬Èó¾ï¤Ë¾®¤µ¤¤¾ì¹ç)¡¢¤³¤Î´ü´Ö¤¬¤¹¤®¤ë¤È´ü¸ÂÀÚ¤ì¤È¤Ê¤ê¤Þ¤¹¡£ jiffies ñ°Ì¤Ç¤¹¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§600
¢£/proc/sys/net/ipv4/inet_peer_minttl
¥¨¥ó¥È¥ê¤Î time-to-live ¤ÎºÇ¾®ÃÍ¡£
¥Ñ¥±¥Ã¥È¤ÎºÆ¹½À®¤ò¹Ô¤¦Â¦¤Ç¤Ï¡¢¥Õ¥é¥°¥á¥ó¥È¤Î time-to-live ¤ò¥«¥Ð¡¼¤Ç¤¤ë½½Ê¬¤ÊÂ礤µ¤Ë¤·¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£
¤³¤Î time-to-live ¤ÎºÇ¾®Ãͤϡ¢¥×¡¼¥ë¤Î¥µ¥¤¥º¤¬ inet_peer_threshold ¤è¤ê¾®¤µ¤¤¾ì¹ç¤ËÊݾڤµ¤ì¤Þ¤¹¡£ jiffies ñ°Ì¤Ç¤¹¡£
¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§120
¢£/proc/sys/net/ipv4/ip_default_ttl
¥Ñ¥±¥Ã¥È¤Î Time To Live ÃͤǤ¹¡£ ¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§64
µðÂç¤Ê¥Í¥Ã¥È¥ï¡¼¥¯¤Ç¤ÏÁý¤ä¤¹¾ì¹ç¤â¤¢¤ê¤Þ¤¹¤¬¡¢¶½Ì£¤À¤±¤ÇÁý¤ä¤µ¤Ê¤¤¤è¤¦¤Ë¡£
·ÐÏ©¤Î¥ë¡¼¥×¤¬¤¢¤Ã¤¿¾ì¹çÈï³²¤¬Â礤¯¤Ê¤ê¤Þ¤¹¡£
2007ǯ03·î07Æü
¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤ÎÊѹ¹ÊýË¡
¡Öuseradd¡×¥³¥Þ¥ó¥É¤ÇÆÃÊ̤ʥª¥×¥·¥ç¥ó»ØÄê¤ò¤»¤º¤Ë¥æ¡¼¥¶¡¼Äɲäò¤·¤¿¾ì¹ç¡¢Red Hat¤Ç¤Ïɸ½à¤Ç/home/¥Ç¥£¥ì¥¯¥È¥ê²¼¤Ë¥æ¡¼¥¶¡¼Ì¾¤Î¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤¬ºî¤é¤ì¤ë¡£
¥æ¡¼¥¶¡¼Ì¾¡Öaaa¡×¤Ç¿·¤·¤¤¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¡Ö/home2/aaa¡×¤ËÊѹ¹¤µ¤»¤¿¤¤¾ì¹ç¤Ë¤Ï¡¢¡Ö-d¡×¥ª¥×¥·¥ç¥ó¤Ë³¤¡¢¿·¤·¤¤¥Ç¥£¥ì¥¯¥È¥ê̾¡¢¥æ¡¼¥¶¡¼Ì¾¤ò²Ã¤¨¤ë¡£
# usermod -d /home2/aaa aaa
¡¦usermod »²¹Í¾ðÊó
# which usermod
/usr/sbin/usermod
# rpm -qf /usr/sbin/usermod
shadow-utils-20000902-12.8
¥æ¡¼¥¶¡¼Ì¾¡Öaaa¡×¤Ç¿·¤·¤¤¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¡Ö/home2/aaa¡×¤ËÊѹ¹¤µ¤»¤¿¤¤¾ì¹ç¤Ë¤Ï¡¢¡Ö-d¡×¥ª¥×¥·¥ç¥ó¤Ë³¤¡¢¿·¤·¤¤¥Ç¥£¥ì¥¯¥È¥ê̾¡¢¥æ¡¼¥¶¡¼Ì¾¤ò²Ã¤¨¤ë¡£
# usermod -d /home2/aaa aaa
¡¦usermod »²¹Í¾ðÊó
# which usermod
/usr/sbin/usermod
# rpm -qf /usr/sbin/usermod
shadow-utils-20000902-12.8
2007ǯ03·î06Æü
¥¤¥ó¥¹¥È¡¼¥ëÃæ¤Î²èÌ̤ò¥¥ã¥×¥Á¥ã
¡ÖRed Hat Linux 9¡×¤«¤é¤Ï¡¢Anaconda¤Î¥Ð¡¼¥¸¥ç¥ó°Í¸¤Ë¤è¤ë¤â¤Î¤Î¡¢¥¤¥ó¥¹¥È¡¼¥ëÃæ¤Ç¤â¥¡¼Áàºî¡ÖShift¡×¡Ü¡ÖPrtScn¡×¡ÊPrint Screen¡Ë¤Ë¤è¤ê²èÌÌ¥¥ã¥×¥Á¥ã¤¬²Äǽ¡£¤³¤Î¥¡¼Áàºî¤ò¹Ô¤¦¤È¥¦¥£¥ó¥É¥¦¤¬¥Ý¥Ã¥×¥¢¥Ã¥×¤·¡¢
¡Ö/root/anaconda-screenshots/¡×¥Ç¥£¥ì¥¯¥È¥ê²¼¤ËPNG¥Õ¥©¡¼¥Þ¥Ã¥È¤ÇÊݸ¤µ¤ì¤ë¡£
¡Ö/root/anaconda-screenshots/¡×¥Ç¥£¥ì¥¯¥È¥ê²¼¤ËPNG¥Õ¥©¡¼¥Þ¥Ã¥È¤ÇÊݸ¤µ¤ì¤ë¡£
2007ǯ03·î05Æü
¥³¥Þ¥ó¥É¤¬¤É¤ÎRPM¥Ñ¥Ã¥±¡¼¥¸¤Ë´Þ¤Þ¤ì¤Æ¤¤¤ë¤Î¤«
-----------------------------------------
¥³¥Þ¥ó¥É¤¬¤É¤ÎRPM¥Ñ¥Ã¥±¡¼¥¸¤Ë¤¢¤ë¤Î¤«ÃΤꤿ¤¤
-----------------------------------------
¥³¥Þ¥ó¥É̾¤¬¥Ñ¥Ã¥±¡¼¥¸Ì¾¤È¥¤¥³¡¼¥ë¤Ç¤Ï¤Ê¤¤¾ì¹ç¡¢¼¡¤Î¤è¤¦¤Ë¡Ö-qf¡×¥ª¥×¥·¥ç¥ó¤Ç
rpm¥³¥Þ¥ó¥É¤ò»ØÄꤹ¤ì¤Ð¤è¤¤¡£
Î㤨¤Ð¡¢¡Ödig¡×¥³¥Þ¥ó¥É¤Î¥Ñ¥¹Àè¤òÄ´¤Ù¡¢¤½¤Î¥Ñ¥Ã¥±¡¼¥¸¼ýÏ¿¸µ¤òÄ´¤Ù¤ë¡£
# which dig
/usr/bin/dig
# rpm -qf /usr/bin/dig
bind-utils-9.2.1-9
¥³¥Þ¥ó¥É¤¬¤É¤ÎRPM¥Ñ¥Ã¥±¡¼¥¸¤Ë¤¢¤ë¤Î¤«ÃΤꤿ¤¤
-----------------------------------------
¥³¥Þ¥ó¥É̾¤¬¥Ñ¥Ã¥±¡¼¥¸Ì¾¤È¥¤¥³¡¼¥ë¤Ç¤Ï¤Ê¤¤¾ì¹ç¡¢¼¡¤Î¤è¤¦¤Ë¡Ö-qf¡×¥ª¥×¥·¥ç¥ó¤Ç
rpm¥³¥Þ¥ó¥É¤ò»ØÄꤹ¤ì¤Ð¤è¤¤¡£
Î㤨¤Ð¡¢¡Ödig¡×¥³¥Þ¥ó¥É¤Î¥Ñ¥¹Àè¤òÄ´¤Ù¡¢¤½¤Î¥Ñ¥Ã¥±¡¼¥¸¼ýÏ¿¸µ¤òÄ´¤Ù¤ë¡£
# which dig
/usr/bin/dig
# rpm -qf /usr/bin/dig
bind-utils-9.2.1-9
2007ǯ03·î04Æü
find¥³¥Þ¥ó¥É
---------------------------
find¥³¥Þ¥ó¥É
---------------------------
find¥³¥Þ¥ó¥É¤Ï¡¢¤µ¤Þ¤¶¤Þ¤Ê¾ò·ï¤Ë¤è¤Ã¤Æ¥Õ¥¡¥¤¥ë
¤ä¥Ç¥£¥ì¥¯¥È¥ê¤ò¸¡º÷¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£
¸¡º÷¤¹¤ë¥Õ¥¡¥¤¥ë̾¤Ë¥ï¥¤¥ë¥É¥«¡¼¥É¤ò»ÈÍѤ¹¤ë¾ì¹ç¤Ï¡¢"*.txt"¤Î¤è¤¦¤Ë¡¢¡Ö"¡×¤Ç°Ï¤àɬÍפ¬¤¢¤ë.
$ find / -name "*.txt"
-size n
¥Õ¥¡¥¤¥ë¥µ¥¤¥º¤òn¤Ç»ØÄꤷ¤Æ¸¡º÷¤¹¤ë¡£
n¤Îñ°Ì¤Ï¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï512bytes¤Î¥Ö¥í¥Ã¥¯¡£
¥µ¥¤¥º¤Î¸å¤Ëc¤òÉÕ¤±¤ë¤Èbytes¤Ë¡¢k¤òÉÕ¤±¤ë¤ÈKbytes¤Ë¤Ê¤ë¡£
¤Þ¤¿¡¢¥µ¥¤¥º¤ÎÁ°¤Ë+¤òÉÕ¤±¤ë¤È»ØÄꥵ¥¤¥º¤òͤ¨¤ë¥Õ¥¡¥¤¥ë¤ò¡¢-¤òÉÕ¤±¤ë¤È»ØÄꥵ¥¤¥ºÌ¤Ëþ¤Î¥Õ¥¡¥¤¥ë¤ò¼¨¤¹¡£
Î㤨¤Ð¡¢
$ find . -size +10k
¤È¤¹¤ë¤È¡¢¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Ë¤¢¤ë10Kbytes°Ê¾å¤Î¥Õ¥¡¥¤¥ë¤ò¸¡º÷¤¹¤ë¡£
-atime n
¡¡ºÇ¸å¤Ë¥¢¥¯¥»¥¹¤µ¤ì¤¿»þ´Ö¡ÊÆü¤Ë¤Á¡Ë¤ò»ØÄꤷ¤Æ¸¡º÷¤¹¤ë¡£n¤Îñ°Ì¤Ï1Æü¡Ê24»þ´Ö¡Ë¡£Î㤨¤Ð¡¢
$ find . -atime 3
¤È¤¹¤ë¤È¡¢¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Ë¤¢¤ë¥Õ¥¡¥¤¥ë¤Î¤¦¤Á¡¢3Æü°Ê¾å¥¢¥¯¥»¥¹¤µ¤ì¤Æ¤¤¤Ê¤¤¥Õ¥¡¥¤¥ë¤ò¸¡º÷¤¹¤ë¡£
find¥³¥Þ¥ó¥É
---------------------------
find¥³¥Þ¥ó¥É¤Ï¡¢¤µ¤Þ¤¶¤Þ¤Ê¾ò·ï¤Ë¤è¤Ã¤Æ¥Õ¥¡¥¤¥ë
¤ä¥Ç¥£¥ì¥¯¥È¥ê¤ò¸¡º÷¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£
¸¡º÷¤¹¤ë¥Õ¥¡¥¤¥ë̾¤Ë¥ï¥¤¥ë¥É¥«¡¼¥É¤ò»ÈÍѤ¹¤ë¾ì¹ç¤Ï¡¢"*.txt"¤Î¤è¤¦¤Ë¡¢¡Ö"¡×¤Ç°Ï¤àɬÍפ¬¤¢¤ë.
$ find / -name "*.txt"
-size n
¥Õ¥¡¥¤¥ë¥µ¥¤¥º¤òn¤Ç»ØÄꤷ¤Æ¸¡º÷¤¹¤ë¡£
n¤Îñ°Ì¤Ï¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï512bytes¤Î¥Ö¥í¥Ã¥¯¡£
¥µ¥¤¥º¤Î¸å¤Ëc¤òÉÕ¤±¤ë¤Èbytes¤Ë¡¢k¤òÉÕ¤±¤ë¤ÈKbytes¤Ë¤Ê¤ë¡£
¤Þ¤¿¡¢¥µ¥¤¥º¤ÎÁ°¤Ë+¤òÉÕ¤±¤ë¤È»ØÄꥵ¥¤¥º¤òͤ¨¤ë¥Õ¥¡¥¤¥ë¤ò¡¢-¤òÉÕ¤±¤ë¤È»ØÄꥵ¥¤¥ºÌ¤Ëþ¤Î¥Õ¥¡¥¤¥ë¤ò¼¨¤¹¡£
Î㤨¤Ð¡¢
$ find . -size +10k
¤È¤¹¤ë¤È¡¢¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Ë¤¢¤ë10Kbytes°Ê¾å¤Î¥Õ¥¡¥¤¥ë¤ò¸¡º÷¤¹¤ë¡£
-atime n
¡¡ºÇ¸å¤Ë¥¢¥¯¥»¥¹¤µ¤ì¤¿»þ´Ö¡ÊÆü¤Ë¤Á¡Ë¤ò»ØÄꤷ¤Æ¸¡º÷¤¹¤ë¡£n¤Îñ°Ì¤Ï1Æü¡Ê24»þ´Ö¡Ë¡£Î㤨¤Ð¡¢
$ find . -atime 3
¤È¤¹¤ë¤È¡¢¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Ë¤¢¤ë¥Õ¥¡¥¤¥ë¤Î¤¦¤Á¡¢3Æü°Ê¾å¥¢¥¯¥»¥¹¤µ¤ì¤Æ¤¤¤Ê¤¤¥Õ¥¡¥¤¥ë¤ò¸¡º÷¤¹¤ë¡£
2007ǯ03·î03Æü
ssh¤Î¹¶·â¤Ë»ÈÍѤ·¤Æ¤¤¤ë¼½ñ¤òÈ´¤½Ð¤·¤Æ¤ß¤ë¡£
=====================================
ssh¤Î¹¶·â¤Ë»ÈÍѤ·¤Æ¤¤¤ë¼½ñ¤òÈ´¤½Ð¤·¤Æ¤ß¤ë¡£
=====================================
ssh¤Î¹¶·â¤Ë»ÈÍѤ·¤Æ¤¤¤ë¼½ñ¤òÈ´¤½Ð¤·¤Æ¤ß¤ë¡£
¢£/var/log/secure¤Ë¹¶·â¤ÎLog¤¬»Ä¤Ã¤Æ¤¤¤ë
Log¤è¤êinput_userauth_request¤Î¹Ô¤Ë»î¤·¤¿¥æ¡¼¥¶ID¤Îº¯Àפ¬»Ä¤Ã¤Æ¤¤¤ë¡£
Feb 25 11:13:24 sshd[3018]: Received disconnect from 210.51.171.70: 11: Bye Bye
Feb 25 11:13:25 sshd[3019]: Could not reverse map address 210.51.171.70.
Feb 25 11:13:25 sshd[3019]: User root not allowed because not listed in AllowUsers
Feb 25 11:13:25 sshd[3019]: input_userauth_request: illegal user root
Feb 25 11:13:28 sshd[3019]: Failed password for illegal user root from 210.51.171.70
port 50124 ssh2
¡¥æ¡¼¥¶ID¹Ô¤ÎÀÚ¤ê½Ð¤·
grep "input" /var/log/secure |perl -pe 's/.*user\s//g' > user1.txt
¢½ÅÊ£¹Ô¤Îºï½ü
sort user1.txt | uniq > user.txt
¤Ç¤â¤Ã¤Æuser.txt¤Ë¹¶·â¤Ë»ÈÍѤ·¤¿¼½ñ¤¬¼è¤ê½Ð¤»¤ë¡£
ssh¤Î¹¶·â¤Ë»ÈÍѤ·¤Æ¤¤¤ë¼½ñ¤òÈ´¤½Ð¤·¤Æ¤ß¤ë¡£
=====================================
ssh¤Î¹¶·â¤Ë»ÈÍѤ·¤Æ¤¤¤ë¼½ñ¤òÈ´¤½Ð¤·¤Æ¤ß¤ë¡£
¢£/var/log/secure¤Ë¹¶·â¤ÎLog¤¬»Ä¤Ã¤Æ¤¤¤ë
Log¤è¤êinput_userauth_request¤Î¹Ô¤Ë»î¤·¤¿¥æ¡¼¥¶ID¤Îº¯Àפ¬»Ä¤Ã¤Æ¤¤¤ë¡£
Feb 25 11:13:24 sshd[3018]: Received disconnect from 210.51.171.70: 11: Bye Bye
Feb 25 11:13:25 sshd[3019]: Could not reverse map address 210.51.171.70.
Feb 25 11:13:25 sshd[3019]: User root not allowed because not listed in AllowUsers
Feb 25 11:13:25 sshd[3019]: input_userauth_request: illegal user root
Feb 25 11:13:28 sshd[3019]: Failed password for illegal user root from 210.51.171.70
port 50124 ssh2
¡¥æ¡¼¥¶ID¹Ô¤ÎÀÚ¤ê½Ð¤·
grep "input" /var/log/secure |perl -pe 's/.*user\s//g' > user1.txt
¢½ÅÊ£¹Ô¤Îºï½ü
sort user1.txt | uniq > user.txt
¤Ç¤â¤Ã¤Æuser.txt¤Ë¹¶·â¤Ë»ÈÍѤ·¤¿¼½ñ¤¬¼è¤ê½Ð¤»¤ë¡£
2007ǯ03·î02Æü
½ÅÊ£¹Ô¤Îºï½ü¡¡uniq
=====================================
½ÅÊ£¹Ô¤Îºï½ü¡¡uniq
=====================================
uniq ¤Ï¡¢ÆÉ¤ß½Ð¤·¤ò¹Ô¤¤¤Ê¤¬¤é¹Ô¤òÈæ³Ó¤·¡¢Ï¢Â³¤¹¤ë2¹Ô°Ê¾å¤òºï½ü¤¹¤ë¤À¤±¤Ê¤Î¤Ç¡¢
sort¤ò»È¤Ã¤Æ¤¢¤é¤«¤¸¤áʤÙÊѤ¨¤Æ¤ª¤¯¡£
#sort ¥Õ¥¡¥¤¥ë̾ | uniq
1¹Ô¤·¤«¤Ê¤¤¹Ô (unique lines) ¤À¤±¤òÈ´¤½Ð¤¹¾ì¹ç¤Ï¡¢
-u (unique) ¥ª¥×¥·¥ç¥ó¤òÍѤ¤¤ë¡£
¤â¤·¤¯¤Ï¡¢½ÅÊ£¤Î¤¢¤ë¹Ô (duplicate lines) ¤À¤±¤òÈ´¤½Ð¤¹¾ì¹ç¤Ï¡¢
-d (duplicate) ¥ª¥×¥·¥ç¥ó¤òÍѤ¤¤ë¡£
# sort ¥Õ¥¡¥¤¥ë̾ | uniq -u
# sort ¥Õ¥¡¥¤¥ë̾ | uniq -d
-c ¥ª¥×¥·¥ç¥ó¤òꤍ¤ë¤È¡¢Åý·×¤òɽ¼¨¤µ¤»¤ë¤³¤È¤â¤Ç¤¤ë¡£
¢¨uniq¤ò»ÈÍѤ·¤Æ¤âLog¤Ê¤É¤ò°·¤¦¾ì¹ç»þ´Ö¤Î¥Õ¥£¡¼¥ë¥É¤¬
ÊѲ½¤¹¤ë¤Î¤Ç¡¢¤¹¤Ù¤Æ°ã¤¦¹Ô°·¤¤¤ò¤µ¤ì¤ë»þ´Ö¤Î¥Õ¥£¡¼¥ë¥É¤ò
¸«¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤Ë¤Ï¡¢
Feb 25 11:13:48 tako sshd(pam_unix)[3026]: check pass; user unknown
¢£»þ´Ö¥Õ¥£¡¼¥ë¥É¤òÈô¤Ð¤¹¡£
uniq -f 3 /var/log/messages
¢£Ê¸»úÎó¤òÈô¤Ð¤¹¡£
»ØÄꤷ¤¿Ê¸»ú¿ô¤À¤±Èô¤Ð¤¹-s ¥ª¥×¥·¥ç¥ó¤È¤¤¤¦¤Î¤â¤¢¤ë¡£
»ØÄꤷ¤¿Ê¸»ú¿ô¤À¤±¤ÇÈæ³Ó¤ò¹Ô¤¤¤¿¤¤¾ì¹ç¡£-w ¥ª¥×¥·¥ç¥ó¤ò»ÈÍÑ¡£
½ÅÊ£¹Ô¤Îºï½ü¡¡uniq
=====================================
uniq ¤Ï¡¢ÆÉ¤ß½Ð¤·¤ò¹Ô¤¤¤Ê¤¬¤é¹Ô¤òÈæ³Ó¤·¡¢Ï¢Â³¤¹¤ë2¹Ô°Ê¾å¤òºï½ü¤¹¤ë¤À¤±¤Ê¤Î¤Ç¡¢
sort¤ò»È¤Ã¤Æ¤¢¤é¤«¤¸¤áʤÙÊѤ¨¤Æ¤ª¤¯¡£
#sort ¥Õ¥¡¥¤¥ë̾ | uniq
1¹Ô¤·¤«¤Ê¤¤¹Ô (unique lines) ¤À¤±¤òÈ´¤½Ð¤¹¾ì¹ç¤Ï¡¢
-u (unique) ¥ª¥×¥·¥ç¥ó¤òÍѤ¤¤ë¡£
¤â¤·¤¯¤Ï¡¢½ÅÊ£¤Î¤¢¤ë¹Ô (duplicate lines) ¤À¤±¤òÈ´¤½Ð¤¹¾ì¹ç¤Ï¡¢
-d (duplicate) ¥ª¥×¥·¥ç¥ó¤òÍѤ¤¤ë¡£
# sort ¥Õ¥¡¥¤¥ë̾ | uniq -u
# sort ¥Õ¥¡¥¤¥ë̾ | uniq -d
-c ¥ª¥×¥·¥ç¥ó¤òꤍ¤ë¤È¡¢Åý·×¤òɽ¼¨¤µ¤»¤ë¤³¤È¤â¤Ç¤¤ë¡£
¢¨uniq¤ò»ÈÍѤ·¤Æ¤âLog¤Ê¤É¤ò°·¤¦¾ì¹ç»þ´Ö¤Î¥Õ¥£¡¼¥ë¥É¤¬
ÊѲ½¤¹¤ë¤Î¤Ç¡¢¤¹¤Ù¤Æ°ã¤¦¹Ô°·¤¤¤ò¤µ¤ì¤ë»þ´Ö¤Î¥Õ¥£¡¼¥ë¥É¤ò
¸«¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤Ë¤Ï¡¢
Feb 25 11:13:48 tako sshd(pam_unix)[3026]: check pass; user unknown
¢£»þ´Ö¥Õ¥£¡¼¥ë¥É¤òÈô¤Ð¤¹¡£
uniq -f 3 /var/log/messages
¢£Ê¸»úÎó¤òÈô¤Ð¤¹¡£
»ØÄꤷ¤¿Ê¸»ú¿ô¤À¤±Èô¤Ð¤¹-s ¥ª¥×¥·¥ç¥ó¤È¤¤¤¦¤Î¤â¤¢¤ë¡£
»ØÄꤷ¤¿Ê¸»ú¿ô¤À¤±¤ÇÈæ³Ó¤ò¹Ô¤¤¤¿¤¤¾ì¹ç¡£-w ¥ª¥×¥·¥ç¥ó¤ò»ÈÍÑ¡£
2007ǯ03·î01Æü
ssh¤Î¥Ý¡¼¥È¤Ë¹¶·â¤·¤Æ¤¯¤ëÇÚ¤ÎIP¥¢¥É¥ì¥¹°ìÍ÷
ssh¤Î¥Ý¡¼¥È¤Ë¹¶·â¤·¤Æ¤¯¤ëÇÚ¤ÎIP¥¢¥É¥ì¥¹°ìÍ÷
¢£/var/log/secure¤Ë¹¶·â¤ÎLog¤¬»Ä¤Ã¤Æ¤¤¤ë
#grep "Received" /var/log/secure | perl -pe 's/.*from\s//g' | awk -F : '{print $1}' | sort | uniq > ipip.txt
¤Çipip.txt¥Õ¥¡¥¤¥ë¤ËIP¥¢¥É¥ì¥¹°ìÍ÷¤¬¤Ç¤¤ë¡£
¢£/var/log/secure¤Ë¹¶·â¤ÎLog¤¬»Ä¤Ã¤Æ¤¤¤ë
#grep "Received" /var/log/secure | perl -pe 's/.*from\s//g' | awk -F : '{print $1}' | sort | uniq > ipip.txt
¤Çipip.txt¥Õ¥¡¥¤¥ë¤ËIP¥¢¥É¥ì¥¹°ìÍ÷¤¬¤Ç¤¤ë¡£
2007ǯ02·î28Æü
ping±þÅú¤òµñÈÝ
-------------------------------------
ICMP ECHO¥Ñ¥±¥Ã¥È¤Î±þÅú¤òµñÈݤ·¤¿¤¤
-------------------------------------
ping¤Ê¤É¤ÎÌ䤤¹ç¤ï¤»¤ËÂФ·¡¢ÊÖÅú¤ò¹Ô¤¦¤«Èݤ«¤¬
ÀßÄê²Äǽ¤Ç¤¹¡£
¼¡¤Î¤è¤¦¤ËÀßÄꤹ¤ë¤È¡¢¥«¡¼¥Í¥ë¤Ï¡¢¤¢¤é¤æ¤ë
¥Û¥¹¥È¤«¤é¤Î¥Ö¥í¡¼¥É¥¥ã¥¹¥È¤ª¤è¤Ó¥Þ¥ë¥Á¥¥ã¥¹¥È¥¢¥É¥ì¥¹¤«¤é¤ÎICMP ECHO¥Ñ¥±¥Ã¥È¤ò̵»ë¤¹¤ë¡£
# echo "1" > /proc/sys/net/ipv4/icmp_echo_ignore_all
¤Ê¤ª¡¢¡Öicmp_echo_ignore_broadcasts¡×¥Õ¥¡¥¤¥ë¤âƱ¥Ç¥£¥ì¥¯¥È¥ê¤Ë¸ºß¤¹¤ë¤¬
¡¢
¤³¤ì¤Ï¥Õ¥¡¥¤¥ë̾¤ÎÄ̤ê¥Ö¥í¡¼¥É¥¥ã¥¹¥È°¸¤ÎICMP¤òÀ©¸æ¤¹¤ë¤â¤Î¤À¡£
ICMP ECHO¥Ñ¥±¥Ã¥È¤Î±þÅú¤òµñÈݤ·¤¿¤¤
-------------------------------------
ping¤Ê¤É¤ÎÌ䤤¹ç¤ï¤»¤ËÂФ·¡¢ÊÖÅú¤ò¹Ô¤¦¤«Èݤ«¤¬
ÀßÄê²Äǽ¤Ç¤¹¡£
¼¡¤Î¤è¤¦¤ËÀßÄꤹ¤ë¤È¡¢¥«¡¼¥Í¥ë¤Ï¡¢¤¢¤é¤æ¤ë
¥Û¥¹¥È¤«¤é¤Î¥Ö¥í¡¼¥É¥¥ã¥¹¥È¤ª¤è¤Ó¥Þ¥ë¥Á¥¥ã¥¹¥È¥¢¥É¥ì¥¹¤«¤é¤ÎICMP ECHO¥Ñ¥±¥Ã¥È¤ò̵»ë¤¹¤ë¡£
# echo "1" > /proc/sys/net/ipv4/icmp_echo_ignore_all
¤Ê¤ª¡¢¡Öicmp_echo_ignore_broadcasts¡×¥Õ¥¡¥¤¥ë¤âƱ¥Ç¥£¥ì¥¯¥È¥ê¤Ë¸ºß¤¹¤ë¤¬
¡¢
¤³¤ì¤Ï¥Õ¥¡¥¤¥ë̾¤ÎÄ̤ê¥Ö¥í¡¼¥É¥¥ã¥¹¥È°¸¤ÎICMP¤òÀ©¸æ¤¹¤ë¤â¤Î¤À¡£
2007ǯ02·î27Æü
apt-get¥³¥Þ¥ó¥É
=====================================
apt-get¥³¥Þ¥ó¥É
=====================================
Vine¤Ï¡¢¥Ñ¥Ã¥±¡¼¥¸´ÉÍý¤Ëapt¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£
¢£APT ÍѤΥǡ¼¥¿¥Ù¡¼¥¹¤ò¹¹¿·
# apt-get update
¢£¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤Ë¤Ï
# apt-get install ¥Ñ¥Ã¥±¡¼¥¸Ì¾
¢£¥¤¥ó¥¹¥È¡¼¥ë²Äǽ¤Ê¥Ñ¥Ã¥±¡¼¥¸Ì¾¤ò¸¡º÷¡¢¥Ñ¥Ã¥±¡¼¥¸¤Î¾ÜºÙ¾ðÊó¤òɽ¼¨
# apt-cache search ¸¡º÷̾
gencaches ¡§¥Ñ¥Ã¥±¡¼¥¸¾ðÊó¤ò¼ý½¸¡¢¹¹¿·
show ¥Ñ¥Ã¥±¡¼¥¸Ì¾ ¡§¥Ñ¥Ã¥±¡¼¥¸¾ðÊó¤òɽ¼¨
showpkg ¥Ñ¥Ã¥±¡¼¥¸Ì¾ ¡§¥Ñ¥Ã¥±¡¼¥¸¤Î°Í¸´Ø·¸¤Ê¤É¤òɽ¼¨
search ¥¡¼¥ï¡¼¥É ¡§¥¡¼¥ï¡¼¥É¤ò¸µ¤Ë¥Ñ¥Ã¥±¡¼¥¸¤ò¸¡º÷
apt-get¥³¥Þ¥ó¥É
=====================================
Vine¤Ï¡¢¥Ñ¥Ã¥±¡¼¥¸´ÉÍý¤Ëapt¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£
¢£APT ÍѤΥǡ¼¥¿¥Ù¡¼¥¹¤ò¹¹¿·
# apt-get update
¢£¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤Ë¤Ï
# apt-get install ¥Ñ¥Ã¥±¡¼¥¸Ì¾
¢£¥¤¥ó¥¹¥È¡¼¥ë²Äǽ¤Ê¥Ñ¥Ã¥±¡¼¥¸Ì¾¤ò¸¡º÷¡¢¥Ñ¥Ã¥±¡¼¥¸¤Î¾ÜºÙ¾ðÊó¤òɽ¼¨
# apt-cache search ¸¡º÷̾
gencaches ¡§¥Ñ¥Ã¥±¡¼¥¸¾ðÊó¤ò¼ý½¸¡¢¹¹¿·
show ¥Ñ¥Ã¥±¡¼¥¸Ì¾ ¡§¥Ñ¥Ã¥±¡¼¥¸¾ðÊó¤òɽ¼¨
showpkg ¥Ñ¥Ã¥±¡¼¥¸Ì¾ ¡§¥Ñ¥Ã¥±¡¼¥¸¤Î°Í¸´Ø·¸¤Ê¤É¤òɽ¼¨
search ¥¡¼¥ï¡¼¥É ¡§¥¡¼¥ï¡¼¥É¤ò¸µ¤Ë¥Ñ¥Ã¥±¡¼¥¸¤ò¸¡º÷
2007ǯ02·î26Æü
Linux LAN¤Î¾õ¶·¤ò¸«¤ë
============================
Linux LAN¤Î¾õ¶·¤ò¸«¤ë
============================
# /sbin/ifconfig -a
eth0 ¥ê¥ó¥¯ÊýË¡:¥¤¡¼¥µ¥Í¥Ã¥È ¥Ï¡¼¥É¥¦¥§¥¢¥¢¥É¥ì¥¹ 00:13:20:19:43:BD
inet¥¢¥É¥ì¥¹:192.168.1.xx ¥Ö¥í¡¼¥É¥¥ã¥¹¥È:192.168.1.255 ¥Þ¥¹¥¯:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX¥Ñ¥±¥Ã¥È:355787222 ¥¨¥é¡¼:0 »¼º:0 ¥ª¡¼¥Ð¥é¥ó:0 ¥Õ¥ì¡¼¥à:0
TX¥Ñ¥±¥Ã¥È:443491598 ¥¨¥é¡¼:0 »¼º:0 ¥ª¡¼¥Ð¥é¥ó:0 ¥¥ã¥ê¥¢:0
¾×ÆÍ(Collisions):0 TX¥¥å¡¼Ä¹:1000
RX bytes:1386691145 (1322.4 Mb) TX bytes:515589289 (491.7 Mb)
³ä¤ê¹þ¤ß:16
lo ¥ê¥ó¥¯ÊýË¡:¥í¡¼¥«¥ë¥ë¡¼¥×¥Ð¥Ã¥¯
inet¥¢¥É¥ì¥¹:127.0.0.1 ¥Þ¥¹¥¯:255.0.0.0
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX¥Ñ¥±¥Ã¥È:2560 ¥¨¥é¡¼:0 »¼º:0 ¥ª¡¼¥Ð¥é¥ó:0 ¥Õ¥ì¡¼¥à:0
TX¥Ñ¥±¥Ã¥È:2560 ¥¨¥é¡¼:0 »¼º:0 ¥ª¡¼¥Ð¥é¥ó:0 ¥¥ã¥ê¥¢:0
¾×ÆÍ(Collisions):0 TX¥¥å¡¼Ä¹:0
RX bytes:168769 (164.8 Kb) TX bytes:168769 (164.8 Kb)
Linux LAN¤Î¾õ¶·¤ò¸«¤ë
============================
# /sbin/ifconfig -a
eth0 ¥ê¥ó¥¯ÊýË¡:¥¤¡¼¥µ¥Í¥Ã¥È ¥Ï¡¼¥É¥¦¥§¥¢¥¢¥É¥ì¥¹ 00:13:20:19:43:BD
inet¥¢¥É¥ì¥¹:192.168.1.xx ¥Ö¥í¡¼¥É¥¥ã¥¹¥È:192.168.1.255 ¥Þ¥¹¥¯:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX¥Ñ¥±¥Ã¥È:355787222 ¥¨¥é¡¼:0 »¼º:0 ¥ª¡¼¥Ð¥é¥ó:0 ¥Õ¥ì¡¼¥à:0
TX¥Ñ¥±¥Ã¥È:443491598 ¥¨¥é¡¼:0 »¼º:0 ¥ª¡¼¥Ð¥é¥ó:0 ¥¥ã¥ê¥¢:0
¾×ÆÍ(Collisions):0 TX¥¥å¡¼Ä¹:1000
RX bytes:1386691145 (1322.4 Mb) TX bytes:515589289 (491.7 Mb)
³ä¤ê¹þ¤ß:16
lo ¥ê¥ó¥¯ÊýË¡:¥í¡¼¥«¥ë¥ë¡¼¥×¥Ð¥Ã¥¯
inet¥¢¥É¥ì¥¹:127.0.0.1 ¥Þ¥¹¥¯:255.0.0.0
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX¥Ñ¥±¥Ã¥È:2560 ¥¨¥é¡¼:0 »¼º:0 ¥ª¡¼¥Ð¥é¥ó:0 ¥Õ¥ì¡¼¥à:0
TX¥Ñ¥±¥Ã¥È:2560 ¥¨¥é¡¼:0 »¼º:0 ¥ª¡¼¥Ð¥é¥ó:0 ¥¥ã¥ê¥¢:0
¾×ÆÍ(Collisions):0 TX¥¥å¡¼Ä¹:0
RX bytes:168769 (164.8 Kb) TX bytes:168769 (164.8 Kb)
2007ǯ02·î25Æü
ApacheÀǽ¬Äê
==========================
ApacheÀǽ¬Äê
==========================
http¥µ¡¼¥Ð¤ÎApache¤Ç¤Ï¡¢¡ÖApacheBench¡×¤È¸Æ¤Ð¤ì¤ë¥Ù¥ó¥Á¥Þ¡¼¥¯¥Ä¡¼¥ë¤¬ÉÕ°¤µ¤ì¤Æ¤¤¤ë¡£
¢£¥³¥Þ¥ó¥É³Îǧ¡§
# which ab
/usr/bin/ab
¼Â¹ÔÊýË¡¤Ï¼¡¤ÎÄ̤ꡣ
#ab -n100 -c300 http://¥Æ¥¹¥È¤·¤¿¤¤¥Û¥¹¥È̾/
¡¡ab -n [Ϣ³¥¢¥¯¥»¥¹¿ô] -c [Ʊ»þ¥¢¥¯¥»¥¹¿ô] http://{¥¢¥¯¥»¥¹Àè}:¥Ý¡¼¥ÈÈÖ¹æ/
¼¡¤ÎÎã¤Ï¡¢100·ï¤Î¥ê¥¯¥¨¥¹¥È¡¢10¤ÎƱ»þÀܳ¤Ç10²ó¹Ô¤¦¤È¤¤¤¦»ØÄê¤Ë¤Ê¤ë
¡ÊÎ㤨¤Ð¡¢-n 100000 -c 500¤Ç¤Ï¡¢100000²ó¤Î¥¢¥¯¥»¥¹¤ò500¸ÄƱ»þ¤Ë200²ó¤È¤¤¤¦
°ÕÌ£¡Ë¡£
Ä̾ï¤Ï¤³¤ÎÊýË¡¤Ç¿ôÃͤòÄ´À°¤¹¤ì¤Ð¤è¤¤¤¬¡¢¥Ñ¥é¥á¡¼¥¿¡¼¤òGET¤Ç¤Ï¤Ê¤¯
POST¤ÇÁ÷¿®¤·¤¿¤¤¾ì¹ç¤Ë¤Ï¡¢¡Ö-n¡×¤Ç¤Ê¤¯¡Ö-p¡×¤È¤·¤ÆÃÖ¤´¹¤¨¤ì¤Ð¤è¤¤¡£
ApacheÀǽ¬Äê
==========================
http¥µ¡¼¥Ð¤ÎApache¤Ç¤Ï¡¢¡ÖApacheBench¡×¤È¸Æ¤Ð¤ì¤ë¥Ù¥ó¥Á¥Þ¡¼¥¯¥Ä¡¼¥ë¤¬ÉÕ°¤µ¤ì¤Æ¤¤¤ë¡£
¢£¥³¥Þ¥ó¥É³Îǧ¡§
# which ab
/usr/bin/ab
¼Â¹ÔÊýË¡¤Ï¼¡¤ÎÄ̤ꡣ
#ab -n100 -c300 http://¥Æ¥¹¥È¤·¤¿¤¤¥Û¥¹¥È̾/
¡¡ab -n [Ϣ³¥¢¥¯¥»¥¹¿ô] -c [Ʊ»þ¥¢¥¯¥»¥¹¿ô] http://{¥¢¥¯¥»¥¹Àè}:¥Ý¡¼¥ÈÈÖ¹æ/
¼¡¤ÎÎã¤Ï¡¢100·ï¤Î¥ê¥¯¥¨¥¹¥È¡¢10¤ÎƱ»þÀܳ¤Ç10²ó¹Ô¤¦¤È¤¤¤¦»ØÄê¤Ë¤Ê¤ë
¡ÊÎ㤨¤Ð¡¢-n 100000 -c 500¤Ç¤Ï¡¢100000²ó¤Î¥¢¥¯¥»¥¹¤ò500¸ÄƱ»þ¤Ë200²ó¤È¤¤¤¦
°ÕÌ£¡Ë¡£
Ä̾ï¤Ï¤³¤ÎÊýË¡¤Ç¿ôÃͤòÄ´À°¤¹¤ì¤Ð¤è¤¤¤¬¡¢¥Ñ¥é¥á¡¼¥¿¡¼¤òGET¤Ç¤Ï¤Ê¤¯
POST¤ÇÁ÷¿®¤·¤¿¤¤¾ì¹ç¤Ë¤Ï¡¢¡Ö-n¡×¤Ç¤Ê¤¯¡Ö-p¡×¤È¤·¤ÆÃÖ¤´¹¤¨¤ì¤Ð¤è¤¤¡£
2007ǯ02·î24Æü
sendmail¤ÇFrom(ȯ¿®¼Ô)¥¢¥É¥ì¥¹¤ÎÊѹ¹ÊýË¡
=========================================
sendmail¤ÇFrom(ȯ¿®¼Ô)¥¢¥É¥ì¥¹¤ÎÊѹ¹ÊýË¡
=========================================
/usr/share/sendmail-cf/cf
¡From¤ò½ñ¤´¹¤¨¤ë¡£°Ê²¼¤Î¥»¥Ã¥È¤Çưºî¤¹¤ë¡£
dnl ## [Rewrite From]
MASQUERADE_AS(`aaa.co.jp')dnl¡¡¡¡¡¡#¤³¤ÎÀßÄê¤Ë½ñ¤´¹¤¨¤ë
MASQUERADE_DOMAIN(`bbb.co.jp')dnl #¤³¤Î¥É¥á¥¤¥ó¤Ç¤¤¿¥á¡¼¥ë¤òAS¤ÇÀßÄê
¤·¤¿Ãͤ˽ñ¤´¹¤¨¤ë¡£
FEATURE(`masquerade_entire_domain')dnl¡¡#
FEATURE(`masquerade_envelope')dnl¡¡¡¡¡¡¡¡#¥¨¥ó¥Ù¥í¥Ã¥×¤ÎFrom¤â½ñ¤´¹¤¨¤ë
½ñ´¹¤Î»î¸³ÊýË¡
>/tryflags HS
>/try smtp xxx@bbb.co.jp
Trying header sender address xxx@bbb.co.jp for mailer smtp
canonify input: xxx @ bbb . co . jp
Canonify2 input: xxx < @ bbb . co . jp >
Canonify2 returns: xxx < @ bbb . co . jp . >
canonify returns: xxx < @ bbb . co . jp . >
1 input: xxx < @ bbb . co . jp . >
1 returns: xxx < @ bbb . co . jp . >
HdrFromSMTP input: xxx < @ bbb . co . jp . >
PseudoToReal input: xxx < @ bbb . co . jp . >
PseudoToReal returns: xxx < @ bbb . co . jp . >
MasqSMTP input: xxx < @ bbb . co . jp . >
MasqSMTP returns: xxx < @ bbb . co . jp . >
MasqHdr input: xxx < @ bbb . co . jp . >
MasqHdr returns: xxx < @ aaa . co . jp . >¡¡<=MasqHdr¤Ç¥É¥á¥¤¥ó¤Î½ñ´¹¤¬¹Ô¤ï¤ì¤Æ¤¤¤ë¡£
HdrFromSMTP returns: xxx < @ aaa . co . jp . >
final input: xxx < @ aaa . co . jp . >
final returns: xxx @ aaa . co . jp
Rcode = 0, addr = xxx@aaa.co.jp
Ãí°Õ¡§log¤Ç¤Ï¡¢½ñ´¹¤ëÁ°¤ÎFrom:¥¢¥É¥ì¥¹¤ÇµÏ¿¤µ¤ì¤ë°Ù³Îǧ¤Ë¤Ï¤Ê¤é¤Ê¤¤¡£
¢¨sendmail¤Ç¤Ï¡¢¡÷º¸ÊÕ¤ò´Êñ¤Ë½ñ¤´¹¤¨¤é¤ì¤Ê¤¤¡£
postfix¤Ç¤Ï¡¢/etc/postfix/sender_canonical¡¡¤Ç´Êñ¤Ë½ñ¤´¹¤¨¤é¤ì¤ë¤Î¤Ç¡¢
Ãæ·Ñ»þÉÔ㥨¥é¡¼¥á¡¼¥ëÅù¤ÎÊÖ¿®Àè¤ò¼«Í³¤ËÄ´À°¤Ç¤¤ë¡£
# less /etc/postfix/sender_canonical
root xxx@bbb.co.jp
root@xxx.bbb.co.jp xxx@ccc.co.jp
root@xxx.int.bbb.co.jp xxx@ccc.co.jp
root@ddd.co.jp xxx@ccc.co.jp
sendmail¤ÇFrom(ȯ¿®¼Ô)¥¢¥É¥ì¥¹¤ÎÊѹ¹ÊýË¡
=========================================
/usr/share/sendmail-cf/cf
¡From¤ò½ñ¤´¹¤¨¤ë¡£°Ê²¼¤Î¥»¥Ã¥È¤Çưºî¤¹¤ë¡£
dnl ## [Rewrite From]
MASQUERADE_AS(`aaa.co.jp')dnl¡¡¡¡¡¡#¤³¤ÎÀßÄê¤Ë½ñ¤´¹¤¨¤ë
MASQUERADE_DOMAIN(`bbb.co.jp')dnl #¤³¤Î¥É¥á¥¤¥ó¤Ç¤¤¿¥á¡¼¥ë¤òAS¤ÇÀßÄê
¤·¤¿Ãͤ˽ñ¤´¹¤¨¤ë¡£
FEATURE(`masquerade_entire_domain')dnl¡¡#
FEATURE(`masquerade_envelope')dnl¡¡¡¡¡¡¡¡#¥¨¥ó¥Ù¥í¥Ã¥×¤ÎFrom¤â½ñ¤´¹¤¨¤ë
½ñ´¹¤Î»î¸³ÊýË¡
>/tryflags HS
>/try smtp xxx@bbb.co.jp
Trying header sender address xxx@bbb.co.jp for mailer smtp
canonify input: xxx @ bbb . co . jp
Canonify2 input: xxx < @ bbb . co . jp >
Canonify2 returns: xxx < @ bbb . co . jp . >
canonify returns: xxx < @ bbb . co . jp . >
1 input: xxx < @ bbb . co . jp . >
1 returns: xxx < @ bbb . co . jp . >
HdrFromSMTP input: xxx < @ bbb . co . jp . >
PseudoToReal input: xxx < @ bbb . co . jp . >
PseudoToReal returns: xxx < @ bbb . co . jp . >
MasqSMTP input: xxx < @ bbb . co . jp . >
MasqSMTP returns: xxx < @ bbb . co . jp . >
MasqHdr input: xxx < @ bbb . co . jp . >
MasqHdr returns: xxx < @ aaa . co . jp . >¡¡<=MasqHdr¤Ç¥É¥á¥¤¥ó¤Î½ñ´¹¤¬¹Ô¤ï¤ì¤Æ¤¤¤ë¡£
HdrFromSMTP returns: xxx < @ aaa . co . jp . >
final input: xxx < @ aaa . co . jp . >
final returns: xxx @ aaa . co . jp
Rcode = 0, addr = xxx@aaa.co.jp
Ãí°Õ¡§log¤Ç¤Ï¡¢½ñ´¹¤ëÁ°¤ÎFrom:¥¢¥É¥ì¥¹¤ÇµÏ¿¤µ¤ì¤ë°Ù³Îǧ¤Ë¤Ï¤Ê¤é¤Ê¤¤¡£
¢¨sendmail¤Ç¤Ï¡¢¡÷º¸ÊÕ¤ò´Êñ¤Ë½ñ¤´¹¤¨¤é¤ì¤Ê¤¤¡£
postfix¤Ç¤Ï¡¢/etc/postfix/sender_canonical¡¡¤Ç´Êñ¤Ë½ñ¤´¹¤¨¤é¤ì¤ë¤Î¤Ç¡¢
Ãæ·Ñ»þÉÔ㥨¥é¡¼¥á¡¼¥ëÅù¤ÎÊÖ¿®Àè¤ò¼«Í³¤ËÄ´À°¤Ç¤¤ë¡£
# less /etc/postfix/sender_canonical
root xxx@bbb.co.jp
root@xxx.bbb.co.jp xxx@ccc.co.jp
root@xxx.int.bbb.co.jp xxx@ccc.co.jp
root@ddd.co.jp xxx@ccc.co.jp
2007ǯ02·î22Æü
apache¤Î¾ï»þÁȤ߹þ¤Þ¤ì¤Æ¤¤¤ë¥â¥¸¥å¡¼¥ë
=========================
apache¤Î¾ï»þÁȤ߹þ¤Þ¤ì¤Æ¤¤¤ë¥â¥¸¥å¡¼¥ë
=========================
apache¤Î¾ï»þÁȤ߹þ¤Þ¤ì¤Æ¤¤¤ë¥â¥¸¥å¡¼¥ë¤Ï¡¤¼¡¤Î¤è¤¦¤Ë»ØÄꤹ¤ì¤Ð³Îǧ¤¹¤ë¤³¤È¤¬¤Ç¤¤ë
# which httpd
/usr/sbin/httpd
#/usr/sbin/httpd -l
Compiled in modules:
core.c
prefork.c
http_core.c
mod_so.c
apache¤Î¾ï»þÁȤ߹þ¤Þ¤ì¤Æ¤¤¤ë¥â¥¸¥å¡¼¥ë
=========================
apache¤Î¾ï»þÁȤ߹þ¤Þ¤ì¤Æ¤¤¤ë¥â¥¸¥å¡¼¥ë¤Ï¡¤¼¡¤Î¤è¤¦¤Ë»ØÄꤹ¤ì¤Ð³Îǧ¤¹¤ë¤³¤È¤¬¤Ç¤¤ë
# which httpd
/usr/sbin/httpd
#/usr/sbin/httpd -l
Compiled in modules:
core.c
prefork.c
http_core.c
mod_so.c
2007ǯ02·î21Æü
apache¤Î¥Ð¡¼¥¸¥ç¥óɽ¼¨À©¸æ
=============================
apache¤Î¥Ð¡¼¥¸¥ç¥óɽ¼¨À©¸æ
=============================
# telnet localhost 80
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
HEAD /index.html HTTP/1.1
HTTP/1.1 400 Bad Request
Date: Mon, 19 Feb 2007 03:22:14 GMT
Server: Apache/1.3.33 (Unix) (Vine/Linux) mod_ssl/2.8.22 OpenSSL/0.9.7d
PHP/4.4.4
Connection: close
Content-Type: text/html; charset=iso-8859-1
Connection closed by foreign host.
¤³¤Îɽ¼¨ÆâÍÆ¤òÀ©¸Â¤·¤¿¤¤¾ì¹ç¤Ë¤Ï¡¢ÀßÄê¥Õ¥¡¥¤¥ë¡Êhttpd.conf¡Ë
Æâ¤Ç¡ÖServerTokens¡×¹Ô¤òÊÔ½¸¤¹¤ì¤Ð¤è¤¤¡£
²¿¤âÀßÄꤵ¤ì¤Æ¤¤¤Ê¤¤¾ì¹ç¤Ë¤Ï¡ÖFull¡×¤È²ò¼á¤µ¤ì¤ë¤¬¡¢
Apache2.0¡ÊRed Hat Linux 8.0¤Ê¤É¤ÎRPM¡Ë¤Ç¤Ï¡ÖOS¡×
¤¬É¸½àÀßÄê¤È¤Ê¤Ã¤Æ¤¤¤ë¡£
# vi /etc/httpd/conf/httpd.conf
...ÃæÎ¬...
ServerTokens [ÀßÄêʸ»úÎó]
---------------------------
¡¦4¤Ä¤ÎÀßÄêʸ»úÎó
ServerTokens ProductOnly
Apache¡¡¢«É½¼¨·ë²Ì
ServerTokens Minimal
Apache/1.3.26¡¡¢«É½¼¨·ë²Ì
ServerTokens OS
Apache/1.3.26 (Red Hat Linux)¡¡¢«É½¼¨·ë²Ì
ServerTokens Full
Apache/1.3.26 (Red Hat Linux) mod_throttle/3.1.2 mod_ruby/0.9.7 Ruby/1.6.4
¡¡¢«É½¼¨·ë²Ì
¤Þ¤¿¡¢¥¤¥ó¥Ç¥Ã¥¯¥¹É½¼¨¤ä¡¢¥¨¥é¡¼¥Ú¡¼¥¸¤òɽ¼¨¤¹¤ëºÝ¤Ë¤â
¥Ð¡¼¥¸¥ç¥ó¤¬É½¼¨¤µ¤ì¤ë¡£¤³¤ì¤òÀ©¸Â¤¹¤ë¤¿¤á¤Ë¤Ï¼¡¤Î¤è¤¦¤Ë»ØÄꤷ¤è¤¦¡£
ServerSignature Off
apache¤Î¥Ð¡¼¥¸¥ç¥óɽ¼¨À©¸æ
=============================
# telnet localhost 80
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
HEAD /index.html HTTP/1.1
HTTP/1.1 400 Bad Request
Date: Mon, 19 Feb 2007 03:22:14 GMT
Server: Apache/1.3.33 (Unix) (Vine/Linux) mod_ssl/2.8.22 OpenSSL/0.9.7d
PHP/4.4.4
Connection: close
Content-Type: text/html; charset=iso-8859-1
Connection closed by foreign host.
¤³¤Îɽ¼¨ÆâÍÆ¤òÀ©¸Â¤·¤¿¤¤¾ì¹ç¤Ë¤Ï¡¢ÀßÄê¥Õ¥¡¥¤¥ë¡Êhttpd.conf¡Ë
Æâ¤Ç¡ÖServerTokens¡×¹Ô¤òÊÔ½¸¤¹¤ì¤Ð¤è¤¤¡£
²¿¤âÀßÄꤵ¤ì¤Æ¤¤¤Ê¤¤¾ì¹ç¤Ë¤Ï¡ÖFull¡×¤È²ò¼á¤µ¤ì¤ë¤¬¡¢
Apache2.0¡ÊRed Hat Linux 8.0¤Ê¤É¤ÎRPM¡Ë¤Ç¤Ï¡ÖOS¡×
¤¬É¸½àÀßÄê¤È¤Ê¤Ã¤Æ¤¤¤ë¡£
# vi /etc/httpd/conf/httpd.conf
...ÃæÎ¬...
ServerTokens [ÀßÄêʸ»úÎó]
---------------------------
¡¦4¤Ä¤ÎÀßÄêʸ»úÎó
ServerTokens ProductOnly
Apache¡¡¢«É½¼¨·ë²Ì
ServerTokens Minimal
Apache/1.3.26¡¡¢«É½¼¨·ë²Ì
ServerTokens OS
Apache/1.3.26 (Red Hat Linux)¡¡¢«É½¼¨·ë²Ì
ServerTokens Full
Apache/1.3.26 (Red Hat Linux) mod_throttle/3.1.2 mod_ruby/0.9.7 Ruby/1.6.4
¡¡¢«É½¼¨·ë²Ì
¤Þ¤¿¡¢¥¤¥ó¥Ç¥Ã¥¯¥¹É½¼¨¤ä¡¢¥¨¥é¡¼¥Ú¡¼¥¸¤òɽ¼¨¤¹¤ëºÝ¤Ë¤â
¥Ð¡¼¥¸¥ç¥ó¤¬É½¼¨¤µ¤ì¤ë¡£¤³¤ì¤òÀ©¸Â¤¹¤ë¤¿¤á¤Ë¤Ï¼¡¤Î¤è¤¦¤Ë»ØÄꤷ¤è¤¦¡£
ServerSignature Off
2007ǯ02·î20Æü
BIND¤Î¥Ð¡¼¥¸¥ç¥ó³Îǧ
=========================
BIND¤Î¥Ð¡¼¥¸¥ç¥ó³Îǧ
=========================
¥»¥¥å¥ê¥Æ¥£ÀßÄê¤Ë´Å¤¤DNS¤Ï°Ê²¼¤ÎÌä¹ç¤»¤Ç¥Ð¡¼¥¸¥ç¥ó¾ðÊó¤òɽ¼¨¤·¤Þ¤¹¡£
#nslookup
> server ss.ness.com.
Default server: ss.ness.com.
Address: 1XX.X.2X.2X4#53
> set type=txt
> set class=chaos
> version.bind
Server: ss.ness.com.
Address: 1XX.X.2X.2X4#53
VERSION.BIND text = "8.1.2"
>
¥Ð¡¼¥¸¥ç¥ó¾ðÊó¤òɽ¼¨¤·¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ë¤Ï¡¢
named.conf
options {
version "Unknown" ;
};
$ dig @219.124.25.168 chaos txt version.bind
; <<>> DiG 9.2.1 <<>> @219.124.25.168 chaos txt version.bind
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 55667
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;version.bind. CH TXT
;; ANSWER SECTION:
VERSION.BIND. 0 CH TXT "8.2.4-REL"
;; Query time: 37 msec
;; SERVER: 219.124.25.168#53(219.124.25.168)
;; WHEN: Wed Sep 8 16:36:51 2004
;; MSG SIZE rcvd: 64
BIND¤Î¥Ð¡¼¥¸¥ç¥ó³Îǧ
=========================
¥»¥¥å¥ê¥Æ¥£ÀßÄê¤Ë´Å¤¤DNS¤Ï°Ê²¼¤ÎÌä¹ç¤»¤Ç¥Ð¡¼¥¸¥ç¥ó¾ðÊó¤òɽ¼¨¤·¤Þ¤¹¡£
#nslookup
> server ss.ness.com.
Default server: ss.ness.com.
Address: 1XX.X.2X.2X4#53
> set type=txt
> set class=chaos
> version.bind
Server: ss.ness.com.
Address: 1XX.X.2X.2X4#53
VERSION.BIND text = "8.1.2"
>
¥Ð¡¼¥¸¥ç¥ó¾ðÊó¤òɽ¼¨¤·¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ë¤Ï¡¢
named.conf
options {
version "Unknown" ;
};
$ dig @219.124.25.168 chaos txt version.bind
; <<>> DiG 9.2.1 <<>> @219.124.25.168 chaos txt version.bind
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 55667
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;version.bind. CH TXT
;; ANSWER SECTION:
VERSION.BIND. 0 CH TXT "8.2.4-REL"
;; Query time: 37 msec
;; SERVER: 219.124.25.168#53(219.124.25.168)
;; WHEN: Wed Sep 8 16:36:51 2004
;; MSG SIZE rcvd: 64

