- Á¢±ÙÅëÁ¦
- ¾ÈÀüÇÑ µ¥ÀÌŸ ±³È¯ / Åë½Å
- ³×Æ®¿÷ ±¸¼º¿ä¼Ò
- °¡¿ë¼º
Á¢±ÙÅëÁ¦
ÇÁ¸°ÆÃ Á¢±ÙÅëÁ¦
- °íÀ¯ÀÇ lpd ½Ã½ºÅÛÀ» »ç¿ëÇÏ´Â BSD ½Ã½ºÅÛÀº /etc/hosts.lpd¸¦ »ç¿ëÇÏ¿© È£½ºÆ®º°·Î ÇÁ¸°ÅÍ Á¢±ÙÀ» ÅëÁ¦ÇÒ ¼ö ÀÖ´Ù. hosts.equiv º¸´Ù ÀÌ ÆÄÀÏÀ» »ç¿ëÇÏ¿© ÇÁ¸°ÅÍ Á¢±ÙÀ» Á¦ÇÑÇÏ´Â °ÍÀÌ ÇÊ¿äÇÏ´Ù.
- SYSV: "lpadmin -u" ¸í·É¾î¸¦ »ç¿ëÇÏ¿© »ç¿ëÀÚº°·Î ÇÁ¸°ÅÍ Á¢±ÙÀ» Á¦ÇÑÇÒ ¼ö ÀÖ´Ù.
- ´ëºÎºÐÀÇ ½Ã½ºÅÛ¿¡¼ ÇÁ¸°ÅÍ ¼ºê½Ã½ºÅÛÀº ÁöÁ¤ Àü¿ë»ç¿ëÀÚ (e.g. lp) ¾Æ·¡¼ µ¹¾Æ°£´Ù. ÀÌ °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå´Â Â÷´ÜµÇ¾î¾ß ÇÑ´Ù. ƯÈ÷ IRIX´Â ÆÐ½º¿öµå ¾ø´Â lp À¯´Ð½º °èÁ¤À» °¡Áö°í ÀÖ´Ù. ¼³Ä¡ Áï½Ã ÀÌ °èÁ¤À» ¸·¾Æ³õ´Â´Ù. CERT CA-95:15.lp.vul. ÂüÁ¶
¾îÇø®ÄÉÀÌ¼Ç Á¢±ÙÅëÁ¦
À¯´Ð½º (Sun) ½Ã½ºÅÛÀº ¾î¶² ¾îÇø®ÄÉÀ̼ÇÀÌ ¾î¶² »ç¿ëÀڵ鿡 ÀÇÇØ ½ÇÇà °¡´ÉÇÑÁö Á¦ÇÑÇϱâ À§ÇÑ ACLÀ» (¾ÆÁ÷) Á¦°øÇÏÁö ¾Ê´Â´Ù.
=&g; ±×·¯³ª, ÇÁ·Î±×·¥ÀÇ ½ÇÇàÀ» ¼ÒÀ¯ÁÖ¿Í ±×·ìÀ¸·Î Á¦ÇÑÇÏ°í »ç¿ëÀÚµéÀ» ±× ±×·ì¿¡ Ãß°¡ÇÔÀ¸·Î½á, °°Àº È¿°ú¸¦ ¾òÀ» ¼ö ÀÖ´Ù. ÀÌ ¹æ¹ýÀº ±×·¯³ª À¯Áö°ü¸®°¡ Èûµé´Ù.
Ç÷ÎÇÇ µå¶óÀ̺ê Á¢±ÙÅëÁ¦
Ç÷ÎÇÇ µå¶óÀ̺ê´Â Á¤º¸¸¦ ±³È¯ÇÏ´Â µ¥ ¸Å¿ì À¯¿ëÇϳª, º¸´Ù ¾ÈÀüÇÑ ½Ã½ºÅÛÀ» À§Çؼ´Â ±Ù½ÉÀÇ ¿øÃµÀÌ´Ù. µî±ÞÀÌ»ó ½Ã½ºÅ۵鿡 ´ëÇØ¼´Â À̸¦ ±ÇÀåÇÏÁö ¾Ê´Â´Ù.
¿öÅ©½ºÅ×À̼ǿ¡¼ Ç÷ÎÇÇ µå¶óÀ̺긦 »ç¿ëÇÒ ¼ö ¾øµµ·Ï ÇϵçÁö, "½Å·ÚµÇ´Â °³ÀÎ"µéÀÇ ¿öÅ©½ºÅ×À̼ǿ¡¼¸¸ Çã¿ëÇÑ´Ù:
- Solaris 1 - /usr/kvm/sys/sun4m/conf/KERNEL_NAME À» ÆíÁýÇÏ¿© ´ÙÀ½ ¶óÀεéÀ» ÁÖ¼® ó¸®ÇÑ´Ù:
#options PCFS
#device-driver fd
±×¸®°í Ä¿³ÎÀ» À籸¼ºÇÑ ÈÄ (À§ µð·ºÅ丮ÀÇ README ÂüÁ¶), ÀçºÎÆÃÇÑ´Ù
- Solaris 2 - /etc/system¿¡ exclude fd ¸¦ Ãß°¡Çϰí, device¸¦ »èÁ¦ ÈÄ ÀçºÎÆÃÇÑ´Ù.
ÀåÄ¡ Á¢±ÙÅëÁ¦
¿ÜºÎ ÀåÄ¡¸¦ ¿öÅ©½ºÅ×ÀÌ¼Ç SCSI ¹ö½º¿¡ ¿¬°áÇÏÁö ¸»µµ·Ï ÇÑ´Ù.
- ÀåÄ¡´Â /dev ³ª /devices ¿¡ ÀÖ¾î¾ß ÇÑ´Ù/li>
- Ư¼öÇÑ ¾îÇø®ÄÉÀ̼Ç(e.g. µ¥ÀÌŸº£À̽º)¿¡ »ç¿ëµÇ´Â (¿ø½Ã[Raw]) µð½ºÅ© ÀåÄ¡µéÀº ¾îÇø®ÄÉÀÌ¼Ç »ç¿ëÀÚ¸¸ Àбâ & ¾²±â °¡´ÉÇØ¾ß ÇÑ´Ù.
- Solaris ¿¡¼´Â, /etc/logindevpermÀÌ º¯°æµÇÁö ¾ÊÀº ÇÑ ½Ã½ºÅÛ ÀåÄ¡µé(Űº¸µå, ¸¶¿ì½º, ½ºÅ©¸° / ÇÁ·¹ÀÓ ¹öÆÛ, ½ºÇÇÄ¿ / ¿Àµð¿À ÀåÄ¡)¿¡ ´ëÇÑ ·Î±×ÀÎ »ç¿ëÀÚÀÇ Á¢±ÙÀÌ Á¦ÇѵǾî ÀÖ´Ù .
- ´ç½ÅÀÇ ½Ã½ºÅÛ¿¡¼´Â Ư¼öÀåÄ¡µé (Űº¸µå, ¸¶¿ì½º, ½ºÅ©¸°, ½ºÇÇÄ¿, ¸¶ÀÌÅ©, Ä«¸Þ¶ó, Å͹̳Î, ÄܼÖ, ÇÁ·¹ÀÓ ¹öÆÛ ...) ÀÌ ¾î¶»°Ô º¸È£µÇ°í Àִ°¡?
- ´Ù¸¥ »ç¿ëÀÚµéÀÌ Å°º¸µå³ª ÇÁ·¹ÀÓ ¹öÆÛ¸¦ ÀÐÀ» ¼ö Àִ°¡? SunOS (/dev/fbtab) ¿Í Solaris (/etc/logindevperm) ¿¡¼´Â »ç¿ëÇã°¡¸¦ ¼³Á¤ÇÒ ¼ö ÀÖÀ¸¸ç È®ÀÎÇØ¾ß ÇÑ´Ù.
·Î±×ÀÎ Á¢±Ù ÅëÁ¦
- ÆÄÀÏ /etc/nologin ÀÌ Á¸ÀçÇϸé, ¾î¶² ÇÁ·Î±×·¥µé (e.g. ssh, xdm ¹× Solaris 2.5 À̻󿡼 rlogin) Àº »ç¿ëÀÚ Á¢±ÙÀ» °ÅºÎÇϰí ÀÌ ÆÄÀÏÀÇ ³»¿ëÀ» »ç¿ëÀÚ ´Ü¸»¿¡ »Ñ¸°´Ù. ÀÌ ±â´ÉÀº ¼¹ö À¯Áö°ü¸®¿¡ ÀϹÝÀûÀ¸·Î »ç¿ëµÈ´Ù. ·çÆ® °èÁ¤Àº º¸Åë ±×·¡µµ ·Î±×ÀÎÇÒ ¼ö ÀÖ´Ù.
- ³×Æ®¿÷À» ÅëÇØ, ¶Ç´Â ÄܼÖÀÌ ¹°¸®ÀûÀ¸·Î ¾ÈÀüÇÑ ¿µ¿ª¿¡ ÀÖ´Â °æ¿ì°¡ ¾Æ´Ï¸é Äֿܼ¡¼µµ, ·çÆ®·Î Á÷Á¢ ·Î±×ÀÎÀº ºÒ°¡´ÉÇØ¾ß ÇÑ´Ù. ¶ÇÇÑ, ´ÜÀÏ »ç¿ëÀÚ ¸ðµå·Î µé¾î°¡·Á¸é ·çÆ® ÆÐ½º¿öµå°¡ ÀԷµǾî¾ß ÇÑ´Ù.
Solaris 1 (/etc/ttytab):
- ·çÆ®´Â Äֿܼ¡¼¸¸ ·Î±×ÀÎÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù:
console "/usr/etc/getty cons8" sun on local secure
´Ù¸¥ ¸ðµç ÁÙ¿¡¼´Â secure ¸¦ ¾ø¾Ø´Ù.
- ´Ù¸¥ °÷¿¡¼´Â ·çÆ® ·Î±×ÀÎÀ» Çã¿ëÇÏÁö ¸»°í, ´ÜÀÏ »ç¿ëÀÚ ¸ðµå·Î µé¾î°¡·Á¸é ·çÆ® ÆÐ½º¿öµå°¡ ÀԷµǾî¾ß¸¸ ÇÑ´Ù:
¸ðµç ÁÙ¿¡¼ secure ¸¦ »èÁ¦ÇÑ´Ù.
Solaris 2 (/etc/default/login):
- Äֿܼ¡¼ ·çÆ® ·Î±×ÀÎ Çã¿ë:
CONSOLE=/dev/console
- ´Ù¸¥°÷¿¡¼´Â ·çÆ® ·Î±×ÀÎ ºÒÇã:
CONSOLE=/dev/null
´Ù¸¥ ½Ã½ºÅ۵鿡¼´Â, /etc/ttys (e.g. OSF/1 & BSDI) ¶Ç´Â /etc/security ¶Ç´Â /etc/securetty (HP-UX) ¸¦ ã¾Æº»´Ù. ÀÌ ÆÄÀÏÀº ¹Ýµå½Ã ·çÆ®°¡ ¼ÒÀ¯Çϵµ·Ï ÇÏ°í »ç¿ëÇã°¡´Â 644·Î ÇÑ´Ù.
ÀÛ¾÷ ½ºÄÉÁì·¯ (at / cron) Á¢±ÙÅëÁ¦
Ç¥ÁØ À¯´Ð½º ½ºÄÉÁì·¯ at °ú cron Àº ½ÅÁßÇÏ°Ô ±¸¼ºµÇ¾î¾ß ÇÑ´Ù. ±¸¼ºÆÄÀϵéÀº /var/spool/cron¿¡ ÀÖ´Ù.
- at ¸í·É¾î¿¡ÀÇ »ç¿ëÀÚ Á¢±ÙÀº at.deny ¿¡ »ç¿ëÀÚ¸¦ Ãß°¡ÇÏ¿© Á¦ÇÑÇÒ ¼ö ÀÖ´Ù.
- cron ÇÁ·Î±×·¥ Á¢±ÙÀº cron.allow & cron.deny ¸¦ ÀÌ¿ëÇÏ¿© Á¦¾îÇÒ ¼ö ÀÖ´Ù. Solaris 2.x ¿¡¼´Â, smtp, bin µî°ú °°Àº ½Ã½ºÅÛ °èÁ¤Àº µðÆúÆ®·Î cron.deny ¿¡ µé¾î ÀÖ°í ÀÏ¹Ý »ç¿ëÀÚµéÀº cron À» ¾µ ¼ö ÀÖ´Ù.
- ½Ã½ºÅÛ crontabs ´Â ¹Ýµå½Ã ¼ÒÀ¯ÁÖ¸¸ ÀÐÀ» ¼ö ÀÖµµ·Ï ÇÑ´Ù:
chmod og-rwx /var/spool/cron/crontabs/*
ÆÄÀϽýºÅÛ º¸¾È
Ç¥ÁØ À¯´Ð½º ÆÄÀϽýºÅÛ:
- SUID ¶Ç´Â SGID ½ºÅ©¸³Æ®µéÀº »ç¿ëÇÏÁö ¸»¾Æ¾ß ÇÑ´Ù. ÄÄÆÄÀÏµÈ ÇÁ·Î±×·¥À̳ª (tainted) Perl À» »ç¿ëÇϵµ·Ï ÇÑ´Ù. SUID ½ºÅ©¸³Æ® »ç¿ëÀ» ÇÇÇÒ ¼ö°¡ ¾ø´Â °æ¿ì, wrapper ¸¦ »ç¿ëÇÏ¿© ½ºÅ©¸³Æ®¸¦ º¸È£ÇÑ´Ù (ºÎ·Ï D ÂüÁ¶).
- ½Ã½ºÅÛÀ» ÁÖ±âÀûÀ¸·Î °Ë»çÇÏ¿© SUID/SGID ½ºÅ©¸³Æ®°¡ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù (¸ÅÁÖ, ¸ÅÀÏ). ½Ã½ºÅÛ µð·ºÅ丮¿¡ ±×·± ÆÄÀϵéÀÌ ¾øµµ·Ï °æ°èÇÑ´Ù. e.g.
ncheck -s /dev/DISK_DEV_NAME (Solaris 2)
¶Ç´Â
/bin/find / -type f \( -perm -004000 -o -perm 002000 \) -exec ls -alg {} \;
- (¼ÒÀ¯ÁÖ) À̸§À̳ª ±×·ìÀÌ ¾ø´Â ÆÄÀϵéÀÌ ÀÖ´ÂÁö ½Ã½ºÅÛÀ» ÁÖ±âÀûÀ¸·Î °Ë»çÇÑ´Ù (¸ÅÁÖ, ¸ÅÀÏ).
/bin/find / -nouser -o -nogroup -print
- ÀÌ»óÇÑ ÆÄÀÏÀ̳ª µð·ºÅ丮 À̸§ÀÌ ÀÖ´ÂÁö ÁÖ±âÀûÀ¸·Î ½Ã½ºÅÛÀ» °Ë»çÇÑ´Ù (¸ÅÁÖ, ¸ÅÀÏ), e.g. "...", ".. ", ".. ^B", " " µîµî.
±×·± µð·ºÅ丮°¡ ¹ß°ßµÇ¸é ncheck -I INODE DEVICE À» »ç¿ëÇÏ¿© ÀÌ °´Ã¼¿¡ ´ëÇÑ ´Ù¸¥ ¸µÅ©µéÀ» º»´Ù (ºÎ·Ï DÀÇ kill_baddies.pl ½ºÅ©¸³Æ® ÂüÁ¶).
- ½Ã½ºÅÛÀ» ÁÖ±âÀûÀ¸·Î °Ë»çÇÏ¿© ¸ðµç »ç¿ëÀÚ°¡ ¾²±â °¡´ÉÇÑ ÆÄÀÏ & µð·ºÅ丮°¡ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù (¸ÅÁÖ, ¸ÅÀÏ). e.g. /bin/find / -type f -perm -22 -exec ls -l {} \;
/bin/find / -type d -perm -22 -exec ls -ld {} \;
- ¸ðµÎ ¾²±â °¡´ÉÇÑ µð·ºÅ丮¿¡´Â sticky ºñÆ®¸¦ ¼³Á¤ÇÑ´Ù. À̰ÍÀº ÇÑ »ç¿ëÀÚ°¡ ´Ù¸¥ »ç¿ëÀÚÀÇ ÆÄÀÏÀ» ÀÐÀ» ¼ö´Â À־ Áö¿ìÁö´Â ¸øÇÏ°Ô ÇØÁØ´Ù.
e.g. chmod 1777 /var/tmp
- /tmp ¿¡ sticky ºñÆ®¸¦ ¼³Á¤ÇÑ´Ù. e.g. chmod 1777 /tmp
- Solaris 2.1-2.4: /tmp ´Â ÀϹÝÀûÀ¸·Î swap ¿¡ ÀÖ°í µðÆúÆ®·Î sticky ºñÆ®°¡ ³»·ÁÁ® ÀÖ´Ù (2.5 ¿¡¼ ¼öÁ¤µÊ). À̰ÍÀº ps ÇÁ·Î±×·¥À» »ç¿ëÇÒ ¶§ º¸¾È ȦÀ» ¿¾îÁÖ°Ô µÈ´Ù (CERT ±Ç°í¹® CA-95:09 ÂüÁ¶). ±×·¯¹Ç·Î ½ÃÀ۽à /tmp ¸¦ º¸È£ÇÑ´Ù. ¾Æ·¡ ³»¿ëÀ¸·Î /etc/init.d/tmpfix ¶ó´Â ÆÄÀÏÀ» »ý¼ºÇÑ´Ù:
#!/bin/sh
if [ -f /tmp ] ; then
/usr/ucb/chown sys.sys /tmp
/usr/ucb/chmod 1777 /tmp
fi
±×·± ÈÄ ´ÙÀ½ ¸µÅ©¸¦ »ý¼ºÇÏ°í ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÑ´Ù:
ln -s /etc/init.d/tmpfix /etc/rc3.d/S79tmpfix
- Solaris 1: restore ´Â SUID·Î µÇ¾î ÀÖÀ¸¸é º¸¾È ȦÀÌ ÀÖ´Ù. À̰ÍÀº º¸Åë ·çÆ®°¡ »ç¿ëÇϹǷÎ, SUID¸¦ ¾ø¾Öµµ ÀÛµ¿¿¡ ¹®Á¦°¡ ¾øÀ» °ÍÀÌ´Ù. chmod u-s
/usr/etc/restore
- ƯÁ¤ µð·ºÅ丮¿¡¼ ±â´ë¿Í ´Ù¸¥ »ç¿ëÀÚ°¡ ¼ÒÀ¯Çϰí ÀÖ´Â ÆÄÀÏ/µð·ºÅ丮µé¿¡ ÁÖÀǸ¦ ±â¿ïÀδÙ.
- ÆÄÀϽýºÅÛ ¸¶¿îÆÃ: ·ÎÄà µð½ºÅ©¿¡ ¸¶¿îÆ®ÇÑ´Ù°í ÇÏ´õ¶óµµ, ro (ÀбâÀü¿ë, read-only) ³ª nosuid ¿É¼ÇÀ» °¡Áö°í ÆÄÀϽýºÅÛÀ» ¸¶¿îÆ®ÇÒ °ÍÀ» °í·ÁÇÑ´Ù. ÀбâÀü¿ë ¿É¼ÇÀº °ÅÀÇ º¯ÇÏÁö ¾Ê´Â ÇÁ·Î±×·¥¿¡ À¯¿ëÇϰí, nosuid ¿É¼ÇÀº µ¥ÀÌŸ¸¦ Æ÷ÇÔÇÏ´Â µð½ºÅ© (±×·¯³ª SUID ½Ã½ºÅÛ ÇÁ·Î±×·¥Àº ¾ø´Â) ¿¡ À¯¿ëÇÏ´Ù. /usr Àº fstab ÀÌ ÀÐÇôÁö±â Àü¿¡ ½Ã½ºÅÛ¿¡¼ ÀÚµ¿À¸·Î ¸¶¿îÆ®ÇϹǷÎ, /usr ÀÌ ÀбâÀü¿ëÀ¸·Î ¸¶¿îÆ® µÇ·Á¸é Ãß°¡·Î remount ¿É¼ÇÀÌ ÇÊ¿äÇÏ´Ù.
- Àâ´ÙÇÑ ÆÄÀÏ »ç¿ëÇã°¡µéÀº Á» ¾ö°ÝÇÏ°Ô ÇØ¾ßÇÑ´Ù. ºÎ·Ï D¿¡ ÀÖ´Â ¿¹Á¦ ½ºÅ©¸³Æ®¸¦ ÂüÁ¶ÇÑ´Ù. ´ÙÀ½ ÆÄÀϵéÀÌ ¸í½ÃµÈ´ë·ÎÀÎÁö È®ÀÎÇÑ´Ù:
| /tmp /var/tmp |
1777 (sticky ºñÆ® ¼³Á¤) |
| /bin/chsh |
700 (Solaris 1) ·çÆ®¸¸ ½ÇÇà°¡´É. |
| /etc/utmp |
644 (Solaris 1) |
| /var/adm/utmp |
644 (Solaris 2) |
| /etc/sm /etc/sm.bak |
2755 (Solaris 1) |
| /etc/state /etc/mtab |
644 (Solaris 1) |
| /etc/motd /etc/syslog.pid |
644 |
| /usr/kvm/crash |
0755 (no GUID) |
| /vmunix |
644, Owner=root, Group=wheel (Solaris 1) |
| /etc /usr/etc /usr/ucb /usr/bin /tmp |
Owner=root (Solaris1). È®ÀÎÇÒ °Í: ÀϹÝÀûÀ¸·Î ÀÌ µð·ºÅ丮µéÀº bin ¿¡ ¼ÓÇÏ´ÂÁö. |
| /etc /sbin /tmp |
Owner=sys (Solaris 2) |
| /bin /usr/bin /usr/ucb |
Owner=bin (Solaris 2) |
ACL ÀÖ´Â ÆÄÀϽýºÅÛ:
AIX 4.x (¿©±â¼ ³íÀÇÇÏÁö ¾ÊÀ½) ¿Í Solaris 2.5 ´Â ¼¼ºÎ Á¢±ÙÅëÁ¦¸¦ À§ÇÑ ACLÀ» Á¦°øÇÑ´Ù ([unix5], ÆäÀÌÁö 1212 ÂüÁ¶).
Solaris 2.5: ±âº»ÀûÀ¸·Î »ç¿ëÀÚ ¹× ±×·ì ¸íºÎ°¡ ƯÁ¤ ÆÄÀÏÀ̳ª µð·ºÅ丮¸¦ À§ÇÑ »ç¿ëÇã°¡ ¸ñ·Ï (ACL) ¿¡ Ãß°¡µÉ ¼ö ÀÖ´Ù. ACL ¸¶½ºÅ©µµ Ãß°¡µÉ ¼ö Àִµ¥, ¼ÒÀ¯ÁÖ ¿ÜÀÇ ¸ðµç »ç¿ëÀÚ¿Í ±×·ìµé¿¡ ´ëÇØ Çã¿ëµÇ´Â ÃÖ´ë »ç¿ëÇã°¡¸¦ ¼³Á¤ÇÑ´Ù. µð·ºÅ丮 ·¹º§¿¡¼´Â, ¼ÒÀ¯ÀÚ, ±×·ì, ´Ù¸¥ÀÌ(other)¿¡ ´ëÇÑ µðÆúÆ® »ç¿ëÇã°¡¿Í ¸¶½ºÅ©¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ°í Æ¯Á¤ÇÑ »ç¿ëÀÚ¿Í ±×·ì¿¡ ´ëÇÑ µðÆúÆ®µµ ¼³Á¤ÇÒ ¼ö ÀÖ´Ù.
¿¹Á¦:
| getfacl MYFILE |
list ACL on MYFILE |
| ls -l MYFILE |
"Ư¼ö¹®ÀÚ" °¡ "+" À̸é, ACLÀ» »ç¿ëÁßÀÎ °ÍÀÌ´Ù |
| setfacl -s user::rwx,mask:r-x,user:bert:r-- MYFILE |
ACL Àº ÀÌ·¸°Ô ¼³Á¤µÈ´Ù: ¼ÒÀ¯ÁÖ´Â ¸ðµç ±ÇÇÑ, ³ª¸ÓÁö´Â ÃÖ´ë Àбâ & ½ÇÇà, »ç¿ëÀÚ "bert" ´Â Àбâ. |
¾ÈÀüÇÑ ½Ã½ºÅÛ ½Ãµ¿
°¡´ÉÇÑÇÑ EPROM ÆÐ½º¿öµå¸¦ »ç¿ëÇÑ´Ù (±×¸®°í Àá°ÜÁø ±Ý°í¾È¿¡ ½á¼ ³Ö¾îµÐ´Ù).
eprom secure=command [for Sun4]
eeprom secure-mode=command [for Sun4m,d,c]
- ´ÜÀÏ »ç¿ëÀÚ ¸ðµå´Â ·çÆ® ÆÐ½º¿öµå¸¦ ÀÔ·Â ÈÄ¿¡¸¸ °¡´ÉÇØ¾ß ÇÑ´Ù (Solaris 2.x ¿¡¼ µðÆúÆ®, Solaris 1.x : enable eeprom password).
- ÆÐ½º¿öµå¸¦ °¡Áö°í ÀÖ´Â ½Ãµ¿ ÆÄÀÏ: .tiprc ¿Í .netrc °°Àº ÆÐ½º¿öµå´Â ÆÐ½º¿öµå¸¦ Æ÷ÇÔÇϰí ÀÖÀ» ¼ö ÀÖ´Ù. À̵éÀº ¼ÒÀ¯ÁÖ¸¸ÀÌ Àб⠰¡´ÉÇØ¾ß ÇÑ´Ù! (chmod og-rwx FILE).
µî±ÞÀÌ»óÀÇ ½Ã½ºÅÛµéÀº ÆÄÀϾȿ¡ clear text ·Î ÆÐ½º¿öµå¸¦ Æ÷ÇÔÇÏ´Â °ÍÀº ÇÇÇØ¾ß ÇÑ´Ù.
- "dot" files: »ç¿ëÀÚÀÇ È¨ µð·ºÅ丮¿¡, Á¾Á¾ "." (dot) ·Î ½ÃÀ۵Ǵ ÆÄÀϵéÀÌ ¸¹ÀÌ ÀÖ´Â °æ¿ì°¡ ÀÖ´Ù. À̵éÀº ¾îÇø®ÄÉÀÌ¼Ç ¼³Á¤ ÆÄÀÏ¿¡¼ºÎÅÍ (e.g. .mailrc, .newsrc) ·Î±×ÀÎ ¼³Á¤¿¡±îÁö À̸¥´Ù(.profile, .login, .cshrc etc.). ÀÌ ÆÄÀϵ餷¤¤ ¼ÒÀ¯ÁÖ¸¸ ¾²±â °¡´ÉÇØ¾ß ÇÑ´Ù. ¶ÇÇÑ ¼ÒÀ¯ÁÖ¸¸ Àб⠰¡´ÉÇϰųª ±â²¯ÇØ¾ß ±×·ì±îÁö¸¸ ÀбⰡ °¡´ÉÇÑ °ÍÀÌ ÁÁ´Ù.
°´Ã¼ Àç»ç¿ë
°´Ã¼ Àç»ç¿ëÀ» ÅëÇÑ Á¤º¸ Àü¼Û ¹æÁö´Â ÁÖ·Î ´ÙÀ½ ¹æ¹ý¿¡ ÀÇÇØ:
- °¢ »ç¿ëÀÚ°¡ ½Ã½ºÅÛ¿¡ º°µµÀÇ ½Å¿ø(UID)À» °¡Áö°í ÀÖÀ½.
- umask °¡ °¢±â ¼³Á¤µÊ.
- ÆÄÀÏ »ç¿ëÇã°¡°¡ ¿Ã¹Ù¸£°Ô ¼³Á¤µÊ.
- ÀåÄ¡ Á¢±ÙÀÌ ÀûÀýÇÏ°Ô ÅëÁ¦µÊ (ÀϹÝÀûÀ¸·Î »ç¿ëÇã°¡¸¦ ÅëÇØ).
Solaris BSM
The Solaris BSM Àº »ç¿ëÀڵ鰣ÀÇ ÀåÄ¡ ÇÒ´ç°ú ÇØÁ¦¸¦ °¡´ÉÇÏ°Ô ÇÑ´Ù. ÀåÄ¡°¡ ÇØÁ¦µÇ¸é, À̵éÀº "û¼Ò°¡ µÇ¾î" ´ÙÀ½ »ç¿ëÀÚµéÀÌ ±×µé¿¡°Ô ¼ÓÇÏÁö ¾Ê´Â µ¥ÀÌŸ¿¡ Á¢±ÙÇÏ´Â °ÍÀ» ¹æÁöÇÑ´Ù. CD-ROM, 8mm Å×ÀÌÇÁ, QIC Å×ÀÌÇÁ µî°ú °°Àº Ç¥ÁØÀåÄ¡µé¿¡ ´ëÇÑ ÇØÁ¦ ·çƾµéÀÌ Ç¥ÁØÀ¸·Î Á¦°øµÈ´Ù.
ÀåÄ¡ ÇÒ´ç ±â´ÉÀ» »ç¿ëÇÏ·Á¸é BSM ÀÌ È°¼ºÈ µÇ¾î¾ß ÇÑ´Ù.
¾ÈÀüÇÑ µ¥ÀÌŸ ±³È¯ / Åë½Å
³×Æ®¿÷ Åë½Å »ó´ë¹æ ÀÎÁõ
NIS & NIS+ ¿¡ ´ëÇÑ Àý ÂüÁ¶.
½Å·ÚµÇ´Â È£½ºÆ®
.rhosts ³ª hosts.equiv ¸¦ ¼³Á¤Çϰí Berkley "r" ¸í·ÉµéÀ» (rlogin °°Àº) »ç¿ëÇÏ¿©, ¿ø°Ý ½Ã½ºÅÛ¿¡ ÆÐ½º¿öµå ¾øÀÌ ·Î±×ÀÎÀÌ °¡´ÉÇÏ´Ù. ÀÌ´Â ÆÐ½º¿öµå°¡ ³×Æ®¿÷À» (clear text·Î) µ¹¾Æ´Ù´ÏÁö ¾Ê´Â´Ù´Â ÀåÁ¡ °ú ÇϳªÀÇ È£½ºÆ®°¡ ´Ù¸¥ Çϳª¸¦ ¿ÏÀüÈ÷ ½Å·ÚÇÑ´Ù´Â ´ÜÁ¡ÀÌ ÀÖ´Ù. Çϳª°¡ ÇÔ¶ôµÇ¸é, ´Ù¸¥ Çϳªµµ ÇÔ¶ôµÉ °¡´É¼ºÀÌ ¸Å¿ì ¸¹´Ù.
- Telnet/rlogin ÀÇ ´ëü·Î¼ °í±Þ ÀÎÁõ°ú Àü ¼¼¼Ç ¾Ïȣȸ¦ Æ÷ÇÔÇÏ´Â ssh ¸¦ °í·ÁÇÑ´Ù.
- hosts.equiv´Â »ç¿ëÇÏÁö ¸»µµ·Ï ÇÑ´Ù. ³Ê¹« ÀϹÝÀûÀ̰í À§ÇèÇÏ´Ù.
- ÇÁ¸°ÅÍ Á¢±ÙÅëÁ¦¿¡ hosts.equiv º¸´Ù´Â hosts.lpdÀ» »ç¿ëÇÑ´Ù.
- /.rhosts ¸¦ »ç¿ëÇÏ´Â °æ¿ì, µ¿ÀÏÇÑ º¸¾È ºÐ·ù¸¦ °¡Áö°í °°Àº »ç¶÷ÀÌ °ü¸®ÇÏ´Â ½Ã½ºÅ۵鰣¿¡¸¸ »ç¿ëµÇ¾î¾ß ÇÑ´Ù. /.rhosts ³»¿ëÀÌ ¿Ã¹Ù¸¥Áö ÁÖ±âÀûÀ¸·Î È®ÀÎÇØ¾ß ÇÑ´Ù. »ç¿ëÇã°¡´Â 600 À̾î¾ß Çϰí, »ç¿ëÀÚ¿¡°Ô ¼ÓÇØ¾ß ÇÑ´Ù. Àý´ë "+" Ç׸ñÀº »ç¿ëÇÏÁö ¾Ê´Â´Ù.
- hosts.lpd °¡ »ç¿ëµÇ´Â °æ¿ì, »ç¿ëÇã°¡´Â 600 À̰í, ·çÆ®¿¡°Ô ¼ÓÇØ¾ß ÇÑ´Ù.
- ÁÖ±âÀûÀ¸·Î /.rhosts ¿Í hosts.equiv¸¦ °Ë»çÇϰí "ºÒ¼øÀÀ" »çÇ×À» º¸°í ¹× »èÁ¦Çϱâ À§ÇØ kill_baddies.pl Perl ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Ù (ºÎ·Ï D ÂüÁ¶).
.rhosts ¸¦ »ç¿ëÇÒ °æ¿ì, »ç¿ëÀÚÀ̸§ ¹× È£½ºÆ®¸¦ ¸ðµÎ °¡Áöµµ·Ï Ç׸ñÀ» Ãß°¡ÇÑ´Ù, e.g. ÇöÀç ½Ã½ºÅÛÀÌ sun_server ÀÇ »ç¿ëÀÚ freddie ¸¦ ½Å·ÚÇØ¾ß ÇÑ´Ù¸é, rhosts Ç׸ñÀº "sun_server freddie" ÀÌ µÇ¾î¾ß ÇÑ´Ù.
- .rhost ³ª hosts.equiv ¶Ç´Â hosts.lpd ¿¡ (ÀÌ ÆÄÀϵéÀº ÁÖ¼® ¹®ÀÚ°¡ ¾ø´Ù) "#" ³ª "!" ¸¦ Àý´ë »ç¿ëÇÏÁö ¾Ê´Â´Ù, À̸§ÀÌ "#" ÀΠȣ½ºÆ®ÀÇ Á¢±ÙÀ» Çã¿ëÇÏ°Ô µÈ´Ù.
°¡´ÉÇÑÇÑ tcp wrappers ¸¦ »ç¿ëÇÑ´Ù. »ó¼¼ÇÑ ³»¿ëÀº "·Î±×ÀÎ Á¢±ÙÅëÁ¦" Ç׸ñÀ» ÂüÁ¶ÇÑ´Ù.
- /.rhosts ¿Í /etc/hosts.equiv ÀÇ »ç¿ëÇã°¡¿Í º¯°æ³¯Â¥¸¦ °¨½ÃÇÑ´Ù. À̸¦ À§ÇØ ÀÚµ¿ÈµÈ ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÑ´Ù¸é °Å±â¼ »ç¿ëÇã°¡¿Í ¼ÒÀ¯±ÇÀ» ÀÚµ¿À¸·Î Àç¼³Á¤ÇØ¾ß ÇÑ´Ù.
- »ç¿ëÀÚÀÇ .rhosts ÆÄÀÏ ³»¿ëÀ» ÅëÁ¦ÇØ¾ß ÇÑ´Ù. À̸¦ À§Çؼ´Â, »ç¿ëÀÚ°¡ ÀÚ±âÀÇ .rhosts¸¦ º¯°æÇÒ ¼ö ÀÖ´Â ¹æ¹ýÀÌ ¾ø¾î¾ß ÇÑ´Ù. µÎ °¡Áö °¡´ÉÇÑ »çÇ×ÀÌ ÀÖ´Ù
1).rhosts ¸¦ ¼³Á¤ÇÏ¿©, »ç¿ëÀÚµéÀÌ Æ¯Á¤ ½Ã½ºÅ۵鿡 ½Å·ÚµÈ Á¢±ÙÀ» ÇÒ ¼ö ÀÖÁö¸¸ ´Ù¸¥ ½Ã½ºÅÛ¿¡´Â Á¢±ÙÇÒ ¼ö ¾ø°Ô ÇÑ´Ù.
2) ºó .rhosts ¸¦ ¼³Á¤ÇÏ¿© ½Å·Ú°ü°è(trust)°¡ Àý´ë »ç¿ëµÇÁö ¸øÇÏ°Ô ÇÑ´Ù.
°¢°¢¿¡ ´ëÇÑ ¹æ¹ýÀÌ ¿©±â ÀÖ´Ù (¸í·ÉÀº ·çÆ®·Î ½ÇÇàµÊ):
1. °¢ »ç¿ëÀÚ´Â $HOME ÀÚü°¡ ¾Æ´Ñ $HOME ¾Æ·¡ÀÇ ¼ºêµð·ºÅ丮 ($HOME/work) ¿¡¼ ÀÛ¾÷ÇÑ´Ù. »ç¿ëÀÚ´Â $HOME ¿¡ ¾²±â ±ÇÇÑÀÌ ¾øÀ¸¸ç °Å±â¿¡ ÀÖ´Â ¾î¶² ÆÄÀϵµ º¯°æÇÒ ¼ö ¾ø´Ù. ±×·¯³ª $HOME/work ¿¡ ÀÖ´Â ¸ðµç ÆÄÀÏÀº º¯°æÇÒ ¼ö ÀÖ´Ù.
chmod 111 ~$USER
mkdir ~$USER /work
touch ~$USER /.rhosts
chmod 640 ~$USER /.rhosts
chown root ~$USER /.rhosts
chmod 700 ~$USER /work
chown -R $USER ~$USER /work
2.
chmod 111 ~$USER
mkdir ~$USER /.rhosts ~$USER /work
chmod 0 ~$USER /.rhosts
chmod 700 ~$USER /work
chown -R $USER ~$USER /work
Ssh (Secure Shell)
Ssh ´Â ³×Æ®¿÷À» ÅëÇØ ´Ù¸¥ ÄÄÇ»ÅÍ¿¡ ·Î±×ÀÎÇϰí, ¿ø°Ý ½Ã½ºÅÛ¿¡¼ ¸í·ÉÀ» ½ÇÇàÇϰí ÇÑ ½Ã½ºÅÛ¿¡¼ ´Ù¸¥ ½Ã½ºÅÛÀ¸·Î ÆÄÀÏÀ» º¹»çÇϱâ À§ÇÑ ÇÁ·Î±×·¥ÀÌ´Ù.
X11 ¿¬°á°ú ÀÓÀÇ Æ÷Æ® ¿¬°áÀº ssh º¸¾È ä³ÎÀ» Åë°úÇÔÀ¸·Î½á ¾ÈÀüÇÏ°Ô º¸È£µÉ ¼ö ÀÖ´Ù. ±âº»ÀûÀ¸·Î, ssh ´Â ´Ù¸¥ °¡´É¼ºµéÀ» ¸¹ÀÌ °¡Áö´Â, Berkley "r" ¸í·É¾îµé :rsh, rlogin, rcp ±×¸®°í telnet¿¡ ´ëÇÑ ¾ÈÀüÇÑ ´ë¾ÈÀÌ´Ù. À̰ÍÀº ¹Ì±¹ ¹Û¿¡¼ °³¹ßµÇ¾ú±â ¶§¹®¿¡ º¥´õ¿¡ ÀÇÇØ ÀçÆÇ¸ÅµÇÁö ¾Ê´Â ÇÑ ¹Ì±¹ ¼öÃâ±ÔÁ¦¸¦ ¹ÞÁö ¾Ê´Â´Ù.
º¸´Ù ¿ÏÀüÇÑ ¼³¸íÀº ssh ÆäÀÌÁö¸¦ ÂüÁ¶ÇÑ´Ù.
³×Æ®¿÷ µ¥ÀÌŸ ±â¹Ð¼º
- telnet, rlogin, ftp °°Àº Ç¥ÁØ ·Î±×ÀÎ À¯Æ¿¸®Æ¼ µéÀº ³×Æ®¿÷À» ÅëÇØ ÆÐ½º¿öµå¸¦ clear text ·Î Àü¼ÛÇÑ´Ù. À̸¦ ÇÇÇϰí, ssh¸¦ »ç¿ëÇÑ´Ù.
¿öÅ©½ºÅ×ÀÌ¼Ç»ó¿¡ ³×Æ®¿÷ ½º´ÏÆÛ¸¦ Çã¿ëÇÏÁö ¸»°í, ÁÖ±âÀûÀ¸·Î promiscuous ¸ðµåÀÇ ³×Æ®¿÷ ÀÎÅÍÆäÀ̽º°¡ ÀÖ´ÂÁö °Ë»çÇÑ´Ù (ºÎ·Ï DÀÇ ¿¹Á¦ ½ºÅ©¸³Æ® kill_baddies.pl ÂüÁ¶)
³×Æ®¿÷ µ¥ÀÌŸ ¹«°á¼º
TCP/IP Àü¼Û ÇÁ·ÎÅäÄÝÀº ¾àÇÑ Ã¼Å©¼¶À» ¾²±â´Â ÇÏÁö¸¸ Àü¼ÛµÇ´Â µ¥ÀÌŸÀÇ ¹«°á¼ºÀ» °Ë»çÇÑ´Ù.
MD5 µµ±¸
MD5 ´Â (°ø°³ µµ¸ÞÀÎ) À¯Æ¿¸®Æ¼·Î RSA MD5 ¾Ë°í¸®µëÀ» »ç¿ëÇÏ¿© ÆÄÀÏ¿¡ ´ëÇÑ ÇØ½Ã¸¦ »ý¼ºÇÑ´Ù. À̰ÍÀº ÆÄÀÏ ¹«°á¼º °Ë»ç¿¡ »ç¿ëµÉ ¼ö Àִµ¥ (e.g. tripwire),
´õ¿í º¸ÆíÀûÀ¸·Î´Â ÀÎÅͳÝÀ¸·ÎºÎÅÍ ´Ù¿î¹ÞÀº ÆÐÄ¡ÀÇ ¹«°á¼º °Ë»ç³ª ¾ÈÀüÇÑ ¹®¼ Àü¼ÛÀÇ ±¸¼º¿ä¼Ò·Î ¾²ÀδÙ.
¶Ç´Ù¸¥ ¼±ÅÃÀ¸·Î ÆÄÀÏ¿¡ ¼¸íÇÏ¿© ºñÀΰ¡ º¯°æÀ» ŽÁöÇÒ ¼ö ÀÖ´Â PGP °¡ ÀÖ´Ù.
¼Û / ¼ö½Å ºÎÀÎ ¹æÁö
À¯´Ð½º¿¡¼ Á÷Á¢ Áö¿øµÇÁö ¾Ê´Â´Ù.
³×Æ®¿÷ Á¢±ÙÅëÁ¦
Inetd (Internet demons) - inetd.conf
- ÆÄÀÏÀÌ »ç¿ëÇã°¡ 600 À» °¡Áö¸ç ·çÆ®°¡ ¼ÒÀ¯Çϰí ÀÖµµ·Ï È®ÀÎÇÑ´Ù.
º¸´Ù ³ªÀº ·Î±ë°ú IP ±â¹Ý Á¢±ÙÅëÁ¦¸¦ À§ÇØ tcp_wrappers ¶Ç´Â FWTK netacl À» »ç¿ëÇÑ´Ù.
"·Î±×ÀÎ Á¢±ÙÅëÁ¦" ÀýÀ» ÂüÁ¶ÇÑ´Ù.
- walld ¸¦ º¯°æÇÏ¿© inetd.conf ¿¡¼ »ç¿ëÀÚ nobody ·Î ¿î¿µµÇ°Ô ÇÑ´Ù.
- ´ÙÀ½ ¼ºñ½º´Â Àý´ëÀûÀ¸·Î ÇÊ¿äÇÏÁö ¾Ê´Ù¸é »ç¿ëÇÏÁö ¸øÇÏ°Ô ÇÑ´Ù: rexd, rexecd, fingerd, systat, netstat, rusersd, sprayd, uucpd, tftpd.
- ftpd ¸¦ Á¦¿ÜÇÑ ¸ðµç ¼ºñ½º¸¦ »ç¿ëÇÏÁö ¸øÇÏ°Ô ÇÑ´Ù. (ƯÈ÷ tftpd, rexec, rexd, rusers, sprayd). ¿ø°Ý ·Î±×Àο¡ ssh ¸¦ »ç¿ëÇÑ´Ù.
- ÇÒ ¼ö ÀÖÀ¸¸é inetd ·Î±ëÀ» ÇÑ´Ù (Solaris¿¡¼ -t ¿É¼Ç).
- AIX: CERT ±Ç°í¹® CA-92 ÂüÁ¶:05.AIX.REXD.Daemon.vulnerability.
RPC (portmapper/rpcbind)
- °¡Àå ÃÖ½ÅÀÇ ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù.
- Solaris 1Àº CERT ±Ç°í¹® CA94:15 ÂüÁ¶.
- µî±Þ
½Ã½ºÅÛµéÀº Á¢±ÙÅëÁ¦¸¦ ÇÒ ¼ö ÀÖ´Â portmapper/rpcbind ¹öÀüÀ» »ç¿ëÇÒ ¼ö ÀÖ´Ù (Áï Wietsa Venema ÀÇ).
NFS
NFS ´Â À̱âÁ¾ ȯ°æ¿¡¼ ÆÄÀϽýºÅÛÀ» °øÀ¯ÇÏ´Â ¸Å¿ì À¯¿¬ÇÑ ¹æ¹ýÀÌ´Ù. ±×·¯³ª ¸î °¡Áö º¸¾È Ãë¾àÁ¡À» °¡Áö°í ÀÖÀ¸¸ç (ºó¹øÇÑ Ä§ÅõÁöÁ¡ÀÌ´Ù) Á¶½É½º·¯¿î ±¸¼ºÀÌ ÇÊ¿äÇÏ´Ù..
- NFS ¹öÀü 2´Â ´ëºÎºÐÀÇ º¥´õ°¡ Áö¿øÇÑ´Ù.
- 1995 ³â ÈĹݿ¡ Sun Àº NFS ¹öÀü 3À» Áö¿øÇÏ´Â Solaris 2.5¸¦ ¹ßÇ¥ÇÏ¿´´Âµ¥, ÀÌ´Â ´ÙÀ½°ú °°Àº °ÍµéÀ» Çã¿ëÇÑ´Ù:
- tcp (udp¿Í ´ë¸³ÇÏ´Â °ÍÀ¸·Î¼ÀÇ) ¿¬°á ÁöÇâÀû ÇÁ·ÎÅäÄÝ, ¹«°á¼º °³¼±À» ¼ö¹Ý (½ºÇªÇÎÀÌ ´õ ¾î·Á¿öÁü).
- ¼¹ö UFS ÆÄÀϽýºÅÛ¿¡¼ ACLÀÌ °¡´ÉÇÑ °æ¿ì º¸´Ù ¼¼¹ÐÇÑ Á¢±ÙÅëÁ¦¸¦ À§ÇÑ ACL (Á¢±ÙÅëÁ¦ ¸ñ·Ï).
NFS ¼¹ö
NFS ¼¹öÀÇ ¼³Á¤Àº /etc/dfs/dfstab (Solaris 2) ¿Í /etc/exports (Solaris 1) ¿¡¼ ÇÑ´Ù. ÀÌ ÆÄÀϵéÀ» º¯°æÇÑ ÈÄ, ´ÙÀ½°ú °°ÀÌ NFS¸¦ ¾÷µ¥ÀÌÆ®ÇÑ´Ù.
shareall (Solaris 2) ¶Ç´Â exportfs -ua; exportfs -a (Solaris 1).
- Àý´ë µð·ºÅ丮¸¦ ¸ðµÎ¿¡°Ô read/write export ÇÏÁö ¾Êµµ·Ï ÇÑ´Ù.
- ÇÊ¿äÇÑ °÷¿¡¸¸ µð·ºÅ丮¸¦ export ÇÏ°í °¡´ÉÇÑÇÑ readonly·Î ÇÑ´Ù.
- ·ÎÄÃÈ£½ºÆ®·Î´Â export ÇÏÁö ¸»°í export ¸ñ·ÏÀ» 256 ¹®ÀÚº¸´Ù Àû°Ô À¯ÁöÇÑ´Ù.
- ¸í¸íµÈ hosts/netgroups ·Î¸¸ export ÇÑ´Ù (access= ¿É¼ÇÀ¸·Î).
- ºÎÁÖÀÇ·Î ÀåÄ¡°¡ export µÇÁö ¾Êµµ·Ï -nodev ·Î export ÇÒ °ÍÀ» °í·ÁÇÑ´Ù.
- Netgroups: Solaris 2 ´Â /etc/netgroup À» »ç¿ëÇÏÁö ¾Ê°í, netgroup NIS/NIS+ Å×ÀÌºí¸¸ »ç¿ëÇÑ´Ù. »ç¿ëÀÚÀ̸§Àº /etc/netgroup (¶Ç´Â netgroup NIS/NIS+ table) ¿¡¼ ¾Æ¹« È¿·ÂÀÌ ¾øÀ¸¸ç, ÄÄÇ»ÅÍÀ̸§¸¸À» Æ÷ÇÔÇØ¾ß ÇÑ´Ù. ¿¹¸¦ µé¸é:
mail_clients (my_computer,,) (apollo,,) (dinky,,)
ÄÄÇ»ÅÍÀ̸§ÀÌ ¾øÀ¸¸é ¿ÍÀϵåÄ«µå·Î ½Å·ÚµÇ¾î, ¾î¶² ÄÄÇ»Å͵çÁö Á¢±ÙÇÒ ¼ö ÀÖ´Ù´Â °Í¿¡ À¯ÀÇÇÑ´Ù. Á¶½ÉÇϰí Å×½ºÆ®Çϱâ Çϱ⠹ٶõ´Ù!
root= ¿É¼ÇÀ» ½á¼ export ÇÏÁö ¸»µµ·Ï ÇÑ´Ù, À̰ÍÀº ¸¶¿îÆ®µÈ ÆÄÀϽýºÅÛ¿¡ ´ëÇØ Ŭ¶óÀÌ¾ðÆ® ½Ã½ºÅÛÀÇ ·çÆ® °èÁ¤ÀÌ ·çÆ® Á¢±ÙÀ» ÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù ( nobody Á¢±Ù ´ë½Å).
ÁÖÁöÀûÀ¸·Î ¸¶¿îÆ®µÈ µð·ºÅ丮 ¸ñ·ÏÀ» È®ÀÎÇÑ´Ù (showmount ¿Í nfsstat À» »ç¿ëÇÏ¿© [14]).
Export µÈ ¸ðµç ÆÄƼ¼Çµé¿¡ ´ëÇØ fsirand À» »ç¿ëÇÏ¿© inode ¹øÈ£¸¦ º¯Á¶(scramble) ÇÑ´Ù. À̸¦ À§Çؼ´Â ÆÄÀϽýºÅÛÀ» ³»·Á¾ß ÇϹǷÎ, ´ÜÀÏ»ç¿ëÀÚ ¸ðµå¿¡¼ ÇÏ´Â °ÍÀÌ °¡Àå °£ÆíÇÏ´Ù.
Ư±Ç (privileged) Æ÷Æ®·ÎºÎÅÍÀÇ ¿äû¸¸ ¹Þµµ·Ï ¼¹ö¸¦ ±¸¼ºÇÏ´Â °ÍÀ» °í·ÁÇØº»´Ù (PC¸¦ NFS Ŭ¶óÀÌ¾ðÆ®·Î »ç¿ëÁßÀÏ ¶§´Â À̰ÍÀº ¾Æ¹« ¼Ò¿ëÀÌ ¾ø´Ù). Solaris 2.x ¿¡¼, /etc/system ¿¡ ´ÙÀ½À» Ãß°¡ : set nfs:nfs_portmon = 1, SunOS ¿¡¼, /etc/rc.local ¿¡¼ rpc.mountd °¡ ½ÃÀÛµÈ ÈÄ ´ÙÀ½ ÁÙÀ» Ãß°¡: echo "nfs_portmon/W1" | adb -w /vmunix /dev/kmem .
- Solaris1: biod ÇÁ·Î¼¼½º´Â Ŭ¶óÀÌ¾ðÆ®¿¡¼¸¸ ½ÃÀÛÇϰí, nfsd´Â ¼¹ö¿¡¼¸¸ ½ÃÀÛÇÑ´Ù (/etc/rc.local ¿¡¼). Solaris 2 ¿¡¼´Â ÀÚµ¿À¸·Î ÀÌ°Ô µÈ´Ù (ÇÏÁö¸¸ º¸´Ù È®½ÇÈ÷ Çϱâ À§Çؼ´Â, mv /etc/rc3.d/S15nfs.server /etc/rc3.d/.S15nfs.server).
Solaris1: ½ÇÇàÁßÀÎ nfsd ¼ö¸¦ ÁÖ±âÀûÀ¸·Î È®ÀÎÇÑ´Ù (Æ®·ÎÀ̸ñ¸¶ À̸§À¸·Î ÈçÈ÷ ¾²ÀÓ). NFS ´Â Solaris 2 ¿¡¼´Â ¸ÖƼ¾²·¹µå·Î µ¿ÀÛÇϹǷÎ, ps -ef. ·Î ºÃÀ» ¶§ ÇϳªÀÇ ÇÁ·Î¼¼½º¸¸ÀÌ ÀÖ¾î¾ß ÇÑ´Ù.
PC NFS ¼¹ö
À¯´Ð½º·ÎºÎÅÍ NFS ÆÄƼ¼ÇÀ» ¸¶¿îÆ®ÇÏ´Â PCµéÀº ¼¹ö¿¡¼ ½ÇÇàµÇ´Â µ¥¸ó¿¡°Ô ÀÎÁõÀ» ¹Þ¾Æ¾ß ÇÑ´Ù: rpc.pcnfsd.
- ºÒÇàÈ÷µµ ÀÌ µ¥¸óÀº ÇÁ¸°ÅÍ ¿äûÀ» ó¸®Çϴµ¥ ÀÖ¾î Àΰ¡µÇÁö ¾ÊÀº »ç¿ëÀÚ°¡ ½Ã½ºÅÛ³»ÀÇ ¾î¶² µð·ºÅ丮µçÁö chmod¸¦ ÇÒ ¼ö ÀÖ°Ô Çϰí, system() È£Ãâ·Î ¾ÈÀüÇÏÁö ¸øÇÑ ÆÄ¶ó¹ÌÅ͸¦ Àü´ÞÇÔÀ¸·Î½á ´Ù¸¥ º¸¾ÈȦÀ» ¿©´Â ¹ö±×°¡ ÀÖ´Ù [15]. ¼öÁ¤µÈ ¹öÀüÀ» ftp.cert.org:/pub/tools/pcnfsd ¿¡¼ ´Ù¿î¹Þ°Å³ª Cert ±Ç°í¹® CA-96.08 ¿¡ ÀÖ´Â ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù. ¾î¶² º¥´õµéÀº ¼öÁ¤º»µµ Á¦°øÇÑ´Ù - ÀÚ¼¼ÇÑ ³»¿ëÀº ±Ç°í¹® ÂüÁ¶.
¹Î°¨ÇÑ µ¥ÀÌŸ¿¡ ´ëÇØ¼´Â PC-NFS¸¦ »ç¿ëÇÏÁö ¾Êµµ·Ï ÇÑ´Ù.
- /var/spool/pcnfs °¡ 755 ¸ðµå¸¦ °¡Áöµµ·Ï È®ÀÎÇÑ´Ù.
NFS Ŭ¶óÀ̾ðÆ®
NFS Ŭ¶óÀÌ¾ðÆ®µéÀº /etc/vfstab (Solaris 2), /etc/fstab (Solaris 1 & BSD), /etc/filesystems (AIX) ±×¸®°í /etc/checklist (HP) ¿¡¼ ±¸¼ºµÈ´Ù. ÀÌ ÆÄÀϵéÀ» º¯°æÇÑ ÈÄ, mountall (Solaris 2) ¶Ç´Â umount -a; mount -a (Solaris 1) ¸¦ ÅëÇØ NFS¸¦ ¾÷µ¥ÀÌÆ®ÇÑ´Ù.
- °¡´ÉÇÑÇÑ ÆÄƼ¼ÇµéÀ» nosuid ·Î ¸¶¿îÆ®ÇÑ´Ù.
¿öÅ©½ºÅ×À̼ǵéÀº NFS ¼¹ö°¡ µÇ¾î¼´Â ¾ÈµÈ´Ù. nfsd¸¦ »ç¿ë ¸øÇÏ°Ô ÇÑ´Ù. (Solaris 2 ¿¡¼´Â ÀÚµ¿, Solaris 1¿¡¼´Â /etc/rc.local).
- Solaris 2.5 À̻󿡼´Â, actimeo=0 ¿É¼ÇÀ» ½á¼ /var/mail À» ¸¶¿îÆ®ÇÏ¿© ÆÄÀÏ Àá±Ý ¹®Á¦¸¦ ÇÇÇÑ´Ù.
Secure NFS
Secure NFS ´Â ¾ÈÀüÇÑ ³×ÀÓ ¼ºñ½ºÀÇ ½ÇÇàÀ» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ´Â SunOS ¿¡¼ ½ÇÇà½Ã۱â´Â ¸Å¿ì ¾î·Æ´Ù´Â ¸»ÀÌ µÈ´Ù. Solaris 2¿¡¼´Â, NIS+ °¡ Á¦´ë·Î ½ÇÇàµÇ°í ÀÖÀ¸¸é, Secure NFS´Â ¼³Á¤ÇϱⰡ ½±´Ù.
- Read-write µð·ºÅ丮¿¡´Â °¡´ÉÇÑÇÑ Secure NFS¸¦ »ç¿ëÇÑ´Ù.
- È£½ºÆ®µé °£¿¡ ½Ã°£À» µ¿±âÈÇÑ´Ù (NTP, rdate ¶Ç´Â ´Ù¸¥ ºñ½ÁÇÑ µµ±¸¸¦ ÀÌ¿ëÇÏ¿©). ±×¸®°í³ª¼ time window °ªÀ» µðÆúÆ® °ªº¸´Ù ÁÙÀδÙ.
- .logout ÆÄÀÏ¿¡ keylogoutÀ» ³Ö´Â´Ù.
UUCP (UNIX to UNIX copy program)
UUCP °¡ ÇÊ¿äÇÏÁö ¾ÊÀ¸¸é »ç¿ë ºÒ°¡´ÉÇÏ°Ô ÇÑ´Ù. ÇÊ¿äÇϸé, [unix1] 193-219 ÆäÀÌÁö¿¡ Àִ´ë·Î ¼³Á¤ÇÑ´Ù.
UUCP ¸¦ »ç¿ë ¸øÇÏ°Ô ÇÏ·Á¸é:
Solaris 1: /etc/inetd.conf¿Í /etc/rc¿¡¼ in.uucpd¸¦ disable ÇÑ´Ù .
Solaris 2: /etc/inetd.conf¿¡¼ in.uucpd¸¦ disable ÇÑ´Ù. uucp crontab ¿¡ ÀÖ´Â ¸ðµç ¶óÀÎÀ» disable ÇÑ´Ù.
- ÇÊ¿äÇÏÁö ¾ÊÀ¸¸é /etc/inetd.conf¿¡¼ in.ftpdÀ» disable ÇÑ´Ù.
- º¸´Ù ³ªÀº ·Î±ë, Á¢±ÙÅëÁ¦ ¹× ±â´ÉÀ» À§ÇØ ¿þ½ºÅÏ ´ëÇÐÀÇ wu-ftpd »ç¿ëÀ» °í·ÁÇÑ´Ù. CERT ±Ç°í¹® CA-93:06, CA-94:07, CA-95:16 ¹× AA-97.03 ¿¡ µû¶ó (ÀÌÈÄ ±Ç°í¹®µµ È®ÀÎÇÒ °Í) °¡Àå ÃֽйöÀüÀ̳ª ÆÐÄ¡¸¦ ±¸ÇÑ´Ù.
- /etc/ftpusers¿¡ ½Ã½ºÅÛ °èÁ¤µéÀ» ³ª¿ÇÏ¿©, À̵éÀÌ ftp¿¡ »ç¿ëµÇÁö ¸øÇÏ°Ô ÇÑ´Ù.
- /etc/passwd¿¡ ºñÇ¥ÁØ ½©µéÀÌ ÀÖ´Ù¸é /etc/shells¸¦ ¾÷µ¥ÀÌÆ®ÇÑ´Ù.
tcp wrappers ¸¦ »ç¿ëÇÏ¿© IP ÁÖ¼Ò³ª È£½ºÆ®À̸§À» ±â¹ÝÀ¸·Î FTP¸¦ º¸È£ÇÑ´Ù ("·Î±×ÀÎ Á¢±ÙÅëÁ¦" Àýµµ ÂüÁ¶ÇÑ´Ù) .
- FTP ´Â /etc/ftpusers¸¦ ÅëÇØ ¶Ç´Â ´ÙÀ½ Æ®¸¯¿¡ ÀÇÇØ »ç¿ëÀÚº°·Î ¼±ÅÃÀûÀ¸·Î »ç¿ë°¡´ÉÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù: ÀÌ ½Ã½ºÅÛ¿¡ ftp Á¢±ÙÀ» ÇÏ¸é ¾ÈµÇ´Â »ç¿ëÀڵ鿡 ´ëÇØ, À̵éÀÇ °èÁ¤¿¡ ºñÇ¥ÁØ ½©À» ÁÖ°í (bash ³ª tcsh °°Àº) ÀÌ »õ·Î¿î ½©À» /etc/shells¿¡ ÀÔ·ÂÇÏÁö ¾Ê´Â´Ù. FTP Á¢±ÙÀÌ °ÅºÎµÉ °ÍÀÌ´Ù. ¹Ý´ë·Î, ºñÇ¥ÁØ ½©ÀÌ ÇÊ¿äÇÏ´Ù¸é, /etc/shells¿¡ ¹Ýµå½Ã ÀÖ¾î¾ß FTP°¡ ¿Ã¹Ù¸£°Ô µ¿À۵ȴÙ.
·Î±ëÀ» Ȱ¼ºÈÇÑ´Ù (Sun ¿¡¼´Â "-l" ¿É¼ÇÀ» Ãß°¡ÇÔÀ¸·Î½á).
À͸í (Anonymous) ftp
- Anon. ftp¸¦ À§Çؼ´Â ¸Å¿ì ½ÅÁßÇÑ ±¸¼ºÀÌ ÇÊ¿äÇÏ´Ù.
- º°µµÀÇ µð½ºÅ© ÆÄƼ¼Ç¿¡ Anonymous ¿µ¿ªÀ» µÎ°í nosuid·Î ¸¶¿îÆ®ÇÑ´Ù.
Solaris ¿¡¼´Â, Solaris 2.5 ÀÇ in.ftpd ¸Å´º¾ó(man) ÆäÀÌÁö¿¡ ÀÖ´Â Áö½Ã´ë·Î µû¸¥´Ù. 2.5 Àü¹öÀüÀÇ in.ftpd ¸Å´º¾ó ÆäÀÌÁö¿¡ ÀÖ´Â Áö½ÃµéÀº À߸øµÈ °ÍÀÓ¿¡ À¯ÀÇÇÑ´Ù.
- ¿þ½ºÅÏ ´ëÇÐ ftp ¼¹ö¸¦ »ç¿ëÇϰí ÀÖ´Ù¸é (wu-ftpd), CERT ±Ç°í¹® CA-93:06, CA-94:07, CA-95:16 ¹× AA-97.03 ¿¡ µû¶ó (ÀÌÈÄ ±Ç°í¹®µµ È®ÀÎÇÒ °Í) ÆÐÄ¡µÇ¾î¾ß ÇÑ´Ù. Ãß°¡µÈ ±â´ÉÀ¸·Î ÀÎÇØ Á¾Á¾ Anonymous ftp ·Î »ç¿ëµÇ°ï ÇÏÁö¸¸, Ãß°¡µÈ º¹À⼺Àº ¶ÇÇÑ º¸´Ù ¸¹Àº º¸¾ÈȦÀ» ¸¸µé¾î ³»±âµµ ÇÑ´Ù.
/etc/ftpaccess ±¸¼ºÆÄÀÏÀ» Ȱ¼ºÈÇÏ·Á¸é "-a" ¿É¼ÇÀ» »ç¿ëÇÑ´Ù.
- Solaris 2¸¦ À§ÇÑ °ßº» ±¸¼º ½ºÅ©¸³Æ®°¡ ºÎ·Ï D¿¡ ÀÖ´Ù.
- ¾÷·Îµå Çã¿ëÀ» ÇÇÇÑ´Ù. ÇÊ¿äÇÑ °æ¿ì, ¾÷·ÎµåµÈ ÆÄÀÏÀÇ ´Ù¿î·Îµå¸¦ Çã¿ëÇÏÁö ¸»°í, ¾÷·ÎµåµÈ ÆÄÀÏÀ̸§À» ¼û±â°í µ¤¾î¾²±â¸¦ Çã¿ëÇÏÁö ¾Ê´Â´Ù (¾È±×·¯¸é ºÒ¹ý ¼ÒÇÁÆ®¿þ¾î ÀúÀå¼Ò°¡ µÉ Áö ¸ð¸¥´Ù).
TFTP (Trivial File Transfer Protocol)
Tftp ´Â µð½ºÅ©¾ø´Â ºÎÆÃ, X Å͹̳Î, ¿ø°Ý ¼³Ä¡ (Jumpstart) µîµî¿¡ »ç¿ëµÈ´Ù. CERT ±Ç°í¹® CA-91:18, CA-91:19, CA-93:05 µµ ÂüÁ¶ÇÑ´Ù.
- ÇÊ¿äÇÏÁö ¾ÊÀ¸¸é /etc/inetd.conf¿¡¼ tftpd¸¦ Á¦°ÅÇÑ´Ù.
tcp wrappers ¸¦ ÅëÇØ ÀÌ ¼ºñ½º·ÎÀÇ Á¢±ÙÀ» Á¦ÇÑÇÑ´Ù.
- Solaris 1: Tftp Ȩ µð·ºÅ丮¸¦ ³ªÅ¸³»µµ·Ï ¹Ýµå½Ã -s /tftpboot ¿É¼ÇÀ¸·Î ½ÃÀÛµÇ°Ô ÇÑ´Ù, ±×·¯Áö ¾ÊÀ¸¸é ½Ã½ºÅÛ »óÀÇ ¾î¶² ÆÄÀÏÀ̵çÁö ³×Æ®¿÷ »óÀÇ ´Ù¸¥ ¸ðµç ½Ã½ºÅÛ¿¡ ÀÇÇØ ÀÐÇô/¾²¿©Áú ¼ö ÀÖ´Ù!! (Solaris 2 ¿¡¼´Â ÀÌ ¿É¼ÇÀÌ µðÆúÆ®ÀÌ´Ù).
tftp dgram udp wait nobody /secure/tcpd /usr/sbin/in.tftpd -s /tftpboot
- OSF/1 V3.2: Tftp Ȩ µð·ºÅ丮¸¦ ³ªÅ¸³»µµ·Ï ¹Ýµå½Ã -r /usr/users/bootfiles ¿É¼ÇÀ¸·Î ½ÃÀÛµÇ°Ô ÇÑ´Ù. "¾ÈÀüÇÑ(secure)" ¿É¼ÇÀº ¾øÁö¸¸ (Solaris -s ¿É¼Çó·³), ¸í·ÉÁÙ¿¡ µð·ºÅ丮¸¦ ³ª¿ÇÑÀ¸·Î½á get °ú put ¸í·É¾îÀÇ ¹üÀ§¸¦ Á¦ÇÑÇÒ ¼ö ÀÖ´Ù. µû¶ó¼:
- -d option ¿É¼ÇÀ» »ç¿ëÇÏ¿© syslog·ÎÀÇ ·Î±ëÀ» Ȱ¼ºÈÇÑ´Ù. µðÆúÆ® ·Î±ëÀº /var/adm/syslog.dated/DATE/daemon.log ·Î ¸Þ½ÃÁö¸¦ º¸³½´Ù. ¸ðµç ¿¡·¯µéÀÌ ´Ù ·Î±×¿¡ ¾²¿©Áö´Â °ÍÀº ¾Æ´ÏÁö¸¸, Àü¼ÛµÇ´Â ¸ðµç ÆÄÀϵéÀº ·Î±×µÈ´Ù.
- Tftpd °¡ Á¢±ÙÇÏ´Â µð·ºÅ丮¸¦ Á¦ÇÑÇÑ´Ù, tcp wrappers ¸¦ ¾²´Â inetd.conf Ç׸ñÀº ´ÙÀ½°ú °°À» °ÍÀÌ´Ù:
tftp dgram udp wait root /secure/tcpd /usr/sbin/tftpd -d -r /usr/users/bootfiles /usr/users/bootfiles
- /etc/tftptab¿¡ ÆÄÀÏÀ̸§À» Ãß°¡ÇÔÀ¸·Î½á Àü¼ÛµÉ ÆÄÀÏ À̸§À» Á¦ÇÑÇÒ ¼ö ÀÖ´Ù.
´ÙÀ̾ó¾÷ Á¢±ÙÅëÁ¦
Solaris: tt>/etc/dialups ¿Í /etc/d_passwd ¿¡¼ ´ÙÀ̾ó¾÷ ÆÐ½º¿öµå ¼³Á¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ [unix5], 1227 ÆäÀÌÁö ÂüÁ¶.
³×Æ®¿÷ ±¸¼º¿ä¼Ò
¶ó¿ìÆÃ
¶ó¿ìÅ͵鸸ÀÌ µ¥ÀÌŸ¸¦ ¶ó¿ìÆ®ÇØ¾ß ÇÑ´Ù, Áï ÄÄÇ»Å͵éÀº ¼ºê³Ýµé »çÀÌ¿¡ ¶ó¿ìÆÃÀ» ÇÏ¸é ¾ÈµÈ´Ù. À̰ÍÀº Á¤Àû(static) ¶ó¿ìÆÃÀ» »ç¿ëÇϰųª ¶ó¿ìÆÃ µ¥¸óÀ» "quiet mode" ¸ðµå·Î ½ÃÀÛÇÏ°Ô ÇÔÀ¸·Î½á È®½ÇÈ÷ ÇÒ ¼ö ÀÖ´Ù. ¸ðµç È£½ºÆ®¿¡¼ Á¤Àû ¶ó¿ìÆÃÀ» ±¸¼ºÇÒ °ÍÀ» ±ÇÀåÇÑ´Ù:
- Solaris 1.x ¿Í 2.1-4: in.routed¸¦ À§ÇØ /etc/defaultrouter ¸¦ »ý¼ºÇϰí, ¶ó¿ìÅÍ IP ÁÖ¼Ò¸¦ ³ÖÀº ÈÄ, ÀçºÎÆÃÇÑ´Ù. Sun¿¡¼´Â gated ¸¦ Á¦°øÇÏÁö ¾Ê´Â´Ù. Sun ÀÌ ÀÎÅÍÆäÀ̽º¸¦ µÎ°³ °¡Áö°í ÀÖÀ¸¸é,
- Solaris 2.5: /etc/notrouter ¸¦ »ý¼ºÇÏ¿© ¶ó¿ìÆÃ µ¥¸óÀÌ quiet mode¿¡¼ ½ÃÀÛÇϵµ·Ï ÇÑ´Ù.
- ´Ù¸¥ ¹öÀü: in.routed ´Â quite mode ¿¡¼ ½ÃÀ۵Ǿî¾ß ÇÑ´Ù (/etc/rc.local ³ª /etc/init.d/inetinit ¿¡¼ ¹Ýµå½Ã -q ¿É¼ÇÀ» °¡Áö°í ½ÃÀÛÇϵµ·Ï ÇÑ´Ù).
- AIX: TBD: gated ¿Í routed À» Áß´ÜÇÑ´Ù. /etc/gated.conf ¸¦ ÆíÁý?
- HP-UX: /etc/netlinkrc À» »ý¼ºÇÏ¿© ´ÙÀ½À» Ãß°¡ÇÑ ÈÄ, ÀçºÎÆÃÇÑ´Ù: (mode=1 ÀÌ ¸Â³ª?)
- /etc/route add default MY_ROUTER_ADDR mode
- OSF: ¶ó¿ìÆÃ µ¥¸óÀº /etc/rc.config ¿¡ ÀÖ´Â º¯¼öµé¿¡ ÀÇÇØ Á¦¾îµÈ´Ù:
ROUTER=NO, GATED=NO. µðÆúÆ® °ÔÀÌÆ®¿þÀÌ´Â /etc/routes ¿¡ ¼³Á¤µÈ´Ù.
º¹¼ö ÀÎÅÍÆäÀ̽º¸¦ °¡Áö´Â ½Ã½ºÅÛ¿¡¼ ¼Ò½º ¶ó¿ìÆÃ & IP Àü´Þ(forwarding)À» ºñȰ¼ºÈ ÇÑ´Ù:
- AIX, /etc/rc.net ¿¡ ´ÙÀ½À» Ãß°¡:
/usr/sbin/no -o ipfowarding=0
/usr/sbin/no -o ipsendredirects=0
/usr/sbin/no -o nonlocsrcroute=0
- Solaris 2: /etc/rc2.d/S69.inetÀ» ÆíÁý:
ndd -set /dev/ip ip_forwarding 0
ndd -set /dev/ip ip_ip_forward_src_routed 0
- Solaris 1:
echo "ip_forwarding/W 0" | adb -w /vmunix /dev/kmem
- ¶ó¿ìÆÃ µð¹ö±ë: tracerouteÀ» »ç¿ëÇϰųª µð¹ö±ë ¿É¼ÇÀ» ½á¼ ¶ó¿ìÆÃ µ¥¸óÀ» ½ÃÀÛÇÑ´Ù (e.g. in.routed -t).
SNMP
snmp¸¦ ÀÌ¿ëÇÏ¿© ³×Æ®¿÷À» °¨½ÃÇÏ´Â Áß¾Ó °ü¸®ÆÀÀÌ ¾ø´Ù¸é, »ç¿ëÇÒ ¼ö ¾ø°Ô ÇÑ´Ù. snmp ¸¦ »ç¿ëÇÏ·Á¸é:
- Á¶Á÷³»¿¡¼ snmp »ç¿ë¿¡ ´ëÇÑ Ç¥ÁØÀ» ¸¸µé°í ¸ðµç Ŭ¶óÀÌ¾ðÆ®µéÀ» ÀÌ¿¡ µû¶ó ¼³Ä¡ÇÑ´Ù.
Ŭ¶óÀÌ¾ðÆ®µé¿¡ ´ëÇØ ÀбâÀü¿ë Á¢±Ù¸¸ Çã¿ëÇÒ °ÍÀ» °í·ÁÇÑ´Ù. ¸í¸íµÈ ÄÄÇ»ÅÍ/IP ÁּҷκÎÅ͸¸ ¿äûÀ» ¹Þµµ·Ï ±¸¼ºÇÑ´Ù.
snmp Æ®·¦À̳ª °æ°í ¼³Á¤ ÇÏÁö ¸» °ÍÀ» °í·ÁÇÑ´Ù.
- ¸ð¸£´Â ÄÄÇ»ÅͷκÎÅÍ ¿äûÀÌ ¿ÔÀ» ¶§ °æ°í º¸³»´Â °ÍÀ» °í·ÁÇÑ´Ù.
- ¾î¶² À¯´Ð½º ¹öÀüµéÀº OS¿¡ snmp Ŭ¶óÀÌ¾ðÆ®¸¦ Æ÷ÇÔÇÏÁö ¾Ê°í ÀÖ¾î(e.g. Sun), Çϳª »çµçÁö (e.g. Sun Net manager) ±×³É Çϳª ´Þ¶ó°í Á¹¶ó¾ß ÇÑ´Ù (ÀÌ°Ô ³´Áö!). ¸ðµç º¥´õµéÀº V2 snmp Ŭ¶óÀÌ¾ðÆ®¸¦ °ø±ÞÇØ¾ß¸¸ ÇÑ´Ù - º¥´õ¿¡°Ô ¾ê±âÇ϶ó!
±âŸ: ARP, RARP, bootp, bootparams
ARP: Address Resolution Protocol Àº IP ÁÖ¼Ò¸¦ ÀÌ´õ³Ý (¶Ç´Â MAC - Media Access Control) ÁÖ¼Ò·Î º¯È¯ÇÏ´Â µ¥ »ç¿ëµÈ´Ù. µ¿ÀÏÇÑ ¼ºê³Ý¿¡ Àִ ȣ½ºÆ®µéÀÌ Åë½ÅÇÒ Çʿ䰡 ÀÖÀ» ¶§, ¼·Î »ó´ë¹æÀÇ MAC ÁÖ¼Ò¸¦ ¾Ë¾Æ¾ß ÇÑ´Ù. À̰͵éÀº ¼öµ¿ÀûÀ¸·Î ³×Æ®¿÷À» ÁöÄѺ¸°Å³ª, MAC ÁÖ¼Ò°¡ ÇÊ¿äÇÑ IP¸¦ Æ÷ÇÔÇÏ´Â arp ¿äûÀ» º¸³¿À¸·Î½á ¼öÁýµÈ´Ù.
RARP: Reverse ARP ´Â MAC ÁÖ¼Ò¸¦ IP ¹øÈ£·Î º¯È¯ÇÏ´Â µ¥ »ç¿ëµÈ´Ù. À̰ÍÀº ºÎÆÃ Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»Å͵éÀ» µ¿ÀûÀ¸·Î ±¸¼ºÇÏ´Â µ¥ »ç¿ëµÈ´Ù (Á¾Á¾ Jumpstart °°Àº ÀÚµ¿¼³Ä¡ µµÁß¿¡ »ç¿ëµÈ´Ù).
Bootp & bootparams: ÀÌ ÇÁ·ÎÅäÄݵéÀº Ŭ¶óÀÌ¾ðÆ®¿¡ ´ëÇÑ ÆÄ¶ó¹ÌÅÍ ¹è¿À» ¿ø°Ý ¼³Á¤ÇÏ´Â µ¥ »ç¿ëµÈ´Ù. Ŭ¶óÀÌ¾ðÆ®¿¡¼ ÇÊ¿äÇÑ ¼³Á¤ ºÐ·®À» ÁÙÀÌ·Á´Â »ý°¢ÀÌ´Ù. Jumpstart, Printers µî¿¡ ÀÇÇØ »ç¿ëµÈ´Ù.
À§ÀÇ ÇÁ·ÎÅäÄÝµé ¸ðµÎ´Â ¾î¶² º¸¾È Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù: À̵éÀº ·ÎÄà ³×Æ®¿÷¿¡¼ ÀÎÁõ ¾øÀÌ Á¤º¸¸¦ ¿ä±¸ÇÑ´Ù (½ÇÁ¦·Î ´©°¡ ÀÀ´äÇÏ´Â Áö¸¦ ¸ð¸¥´Ù).
°¡¿ë¼º
¹é¾÷ ¹× º¹¿ø
- ¹é¾÷ »öÀÎÀ» Á¾ÀÌ ¶Ç´Â »çÀÌÆ® ¹ÛÀÇ ÄÄÇ»ÅÍ¿¡ º¸°üÇÑ´Ù.
¸ðµç ¸Åü¸¦ °í·ÁÇÑ´Ù.
Å×ÀÌÇÁ¿¡ ¹é¾÷µÇ´Â µ¥ÀÌŸÀÇ ¾Ïȣȸ¦ °í·ÁÇÑ´Ù.
- ¹é¾÷ ¸Åü´Â Àá±ä ±Ý°í³ª Àá±ä ¹æ¿¡ º¸°üµÇ¾î¾ß ÇÑ´Ù.
¹é¾÷Àº ¾ÈÀüÇÑ ¹æ¹ý¿¡ ÀÇÇØ¼¸¸ ¼ö¼ÛµÇ¾î¾ß ÇÑ´Ù (Çö±Ý¼ö¼Ûó·³).
- ¹é¾÷ ¼ÒÇÁÆ®¿þ¾î°¡ ÀÖ´Â ¿©ºÐÀÇ ¿ÜºÎ ºÎÆ® µð½ºÅ©¸¦ Ç×»ó °¡Áö°í ÀÖÀ¸¸é ¸Å¿ì À¯¿ëÇÏ´Ù.
- Áß¿äÇÑ µð·ºÅ丮ÀÇ Á¤±âÀûÀÎ µð½ºÅ© ¹é¾÷Àº °ü¸®ÀÚ ½Ç¼ö·ÎºÎÅÍ »¡¸® º¹±¸ÇÏ´Â µ¥ À¯¿ëÇÏ´Ù. e.g. /var/nis ¹× /etc ¸¦ º°µµÀÇ ÄÄÇ»ÅÍ¿¡ ÀÖ´Â ÆÄÀÏ¿¡ tar ÇÑ´Ù.
°ßº» ¹é¾÷ Á¦Ç°
Legato Networker: ÀÌ Å¬¶óÀ̾ðÆ®/¼¹ö ¹é¾÷ ½Ã½ºÅÛÀº ¼¹ö·Î À¯´Ð½º ½Ã½ºÅÛÀÌ ÇÊ¿äÇϰí (e.g. Solaris, HP-UX..) UNIX, NT, OS/2, DOS¸¦ À§ÇÑ Å¬¶óÀÌ¾ðÆ®µéÀ» °¡Áø´Ù. À̰ÍÀº ¸¹Àº ÁêÅ©¹Ú½º¿Í ÇÔ²² µ¿ÀÛÇÏ¸ç »ó¼¼ÇÑ ¿Â¶óÀÎ »öÀÎÀ» À¯ÁöÇÑ´Ù. »ç¿ëÀÚµéÀº °ü¸®ÀÚ µµ¿ò ¾øÀÌ Àڽſ¡°Ô ¼ÓÇÏ´Â ÆÄÀϵéÀ» º¹¿øÇÒ ¼ö ÀÖ´Ù - ¿Ã¹Ù¸¥ Ä«¼¼Æ®¸¸ ÀÖÀ¸¸é. ÀúÀÚ´Â ÀÌ Á¦Ç°À» ½Ç¾÷¹«È¯°æ¿¡¼ Solaris 1, Solaris 2 ¸¦ »ç¿ëÇÏ¿© ½áº» ±àÁ¤ÀûÀÎ °æÇèÀÌ ÀÖÀ¸¸ç NT Ŭ¶óÀÌ¾ðÆ®·Î Å×½ºÆ® °æÇèÀÌ ÀÖ´Ù.
´ÜÁ¡: ºñ½Î´Ù. °Å´ëÇÑ ¿Â¶óÀÎ »öÀÎ. Å×ÀÌÇÁ°¡ ´ýÇÁ Çü½ÄÀÌ ¾Æ´Ï´Ù. ¾î¶² ÁêÅ©¹Ú½º µå¶óÀ̹öµéÀº ¹ö±×°¡ ÀÖ¾î ½Ã½ºÅÛ Áß´ÜÀ» ¾ß±âÇÒ ¼ö ÀÖ´Ù.
Amanda: ÀÌ °ø°³ µµ¸ÞÀÎ ¹é¾÷ À¯Æ¿¸®Æ¼´Â ¸¹Àº ¼¹öµéÀÇ ³×Æ®¿÷ Àü¹Ý¿¡ °ÉÄ£ ¹é¾÷À» À§ÇØ ¼³°èµÇ¾ú´Ù. À¯´Ð½º¿¡¼¸¸ µ¿ÀÛÇÑ´Ù. Amanda´Â Ç¥ÁØ À¯´Ð½º ´ýÇÁ ÀÇ È®ÀåÀÌ´Ù. ÁêÅ©¹Ú½º¸¦ Áö¿øÇÏ°í ¼º´ÉÀÌ ÁÁ´Ù. Amanda´Â Solaris 1 & 2 ¿¡¼ »ý»êµÈ´Ù. º¹¿øÇÏ´Â ÀÏÀÌ ¸Å¿ì µå¹® ´ë·®ÀÇ µ¥ÀÌŸ ¹é¾÷¿¡ ±Ç°íµÈ´Ù.
´ÜÁ¡: º¥´õ Áö¿øÀÌ ¾ø´Ù (À̸ÞÀÏ Åä·Ð ±×·ìÀº ÀÖÁö¸¸). GUI °¡ ¾ø¾î, ´õ¿í »ç¿ëÇϱⰡ ¾î·Æ´Ù. »ç¿ëÀÚ´Â ½º½º·Î ÆÄÀÏÀ» º¹¿øÇÒ ¼ö ¾ø´Ù.
°¡¿ë¼º °¨½Ã
¾î¶² ½Ã½ºÅÛÀÌ »ì¾Æ¼ µ¿ÀÛÁßÀÎÁö °ü¸®ÀÚ°¡ º¼ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â ¸î¸î À¯Æ¿¸®Æ¼µéÀÌ ÀÖ´Ù.
- Perfmeter ´Â (¸Å¿ì À¯¿ë) Ç¥ÁØ Sun ±×·¡ÇÈ À¯Æ¿¸®Æ¼·Î ·ÎÄÃÀ̳ª ¿ø°Ý È£½ºÆ®(µé)¿¡ ´ëÇÑ ´Ù¾çÇÑ Åë°è¸¦ ±×·¡ÇÈ ÇüÅ·Πº¸¿©ÁØ´Ù.
Perfmeter ´Â ÇÑ Äֿܼ¡¼ ´ë·« 10 ¼¹ö±îÁöÀÇ ´Ü¼øÇÑ ¸ð´ÏÅ͸µ¿¡ ƯÈ÷ ¾µ¸¸ÇÏ´Ù. 15Ãʳª ±× ÀÌ»óÀÇ Æú¸µ (polling) ½Ã°£À» ±ÇÀåÇÑ´Ù.
- uptime Àº Ç¥ÁØ À¯´Ð½º À¯Æ¿¸®Æ¼·Î, ´ÙÀ½°ú °°Àº Á¤º¸¸¦ Á¦°øÇÑ´Ù:
2:35pm up 21 day(s), 4:29, 16 users, load average: 0.09, 0.17, 0.23 0-4 Æò±ÕºÎÇÏ(load average) °¡ ÀϹÝÀûÀ̰í, 4-9 ´Â ³ôÀº °ÍÀ̸ç 10Àº ¹®Á¦¸¦ ³ªÅ¸³½´Ù.
ÀÚ¿ø ³²¿ë ¹æÁö
µð½ºÅ© ÇÒ´ç·®
ÇÒ´ç·® (Quotas)Àº ƯÁ¤ »ç¿ëÀÚ°¡ ƯÁ¤ µð½ºÅ© ÆÄƼ¼Ç¿¡¼ ¾ó¸¸ÅÀÇ °ø°£À» Â÷ÁöÇÒ ¼ö ÀÖ´ÂÁö¸¦ Á¦ÇÑÇÑ´Ù (Áï ¸î ¸Þ°¡¹ÙÀÌÆ® ¶Ç´Â inode °¹¼ö).
ÀÌ´Â, ƯÈ÷ ´ë±Ô¸ð ´ÙÁß »ç¿ëÀÚ ¼¹öµé¿¡¼, »ç¿ëÀÚµéÀÌ µð½ºÅ©¸¦ ²Ë ä¿ì°Å³ª °øÆòÇÑ ¸òº¸´Ù ´õ »ç¿ëÇÏÁö ¸øÇÏ°Ô ÇÏ´Â µ¥ ÇʼöÀûÀÌ´Ù. ÇÒ´ç·®Àº ¼º´É¿¡ ¿µÇâÀ» ÁÖ¸ç, µû¶ó¼ ¿¹¸¦ µé¸é /home °ú /var/mail ÆÄƼ¼Ç¿¡´Â ±ÇÀåµÇÁö¸¸, ·çÆ® ÆÄƼ¼Ç¿¡´Â ¾Æ´Ï´Ù.
- ÇÒ´ç·®Àº vfstab¿¡ rq¿É¼ÇÀ» Ãß°¡Çϰí quotas ÆÄÀÏÀ» »ç¿ëÇã°¡ 600À¸·Î ÆÄÀϽýºÅÛ¿¡ »ý¼º ÈÄ, quotaon -v -a ¸í·ÉÀ» ¹ßÇàÇÔÀ¸·Î½á ƯÁ¤ ÆÄÀϽýºÅÛ¿¡ ´ëÇØ ¼³Ä¡µÈ´Ù [16].
- ÇÒ´ç·®Àº quotaoff -v /usr ¸¦ ½á¼ ƯÁ¤ ÆÄÀϽýºÅÛ¿¡ ´ëÇØ ºñȰ¼ºÈÇÒ ¼ö ÀÖ´Ù.
- ´ç¿¬È÷ ÇÒ´ç·®Àº ¿©ÀüÈ÷ °¢ »ç¿ëÀÚ¿¡ ´ëÇØ »ý¼ºµÉ Çʿ䰡 ÀÖ´Ù. À̰ÍÀº edquota johnny ¸í·ÉÀ¸·Î »ç¿ëÀÚ ÇÒ´ç·®À» ÆíÁýÇϰųª, ±âÁ¸ »ç¿ëÀÚ ÇÒ´ç·®À» ÀÌ¿ëÇØ¼ »õ·Î¿î »ç¿ëÀÚ ÇÒ´ç·®À» »ý¼ºÇÔÀ¸·Î½á ´Þ¼ºÇÒ ¼ö ÀÖ´Ù: edquota -v johnny mathieu fabrice (ÇöÀç johnny°¡ »ç¿ëÁßÀÎ ÇÒ´ç·®À» Åä´ë·Î 2 ½Å±Ô ÇÒ´ç·® »ý¼º).
- ÇÒ´ç? È®ÀÎ (Solaris):
quota -v Johnny [Johnny ¿¡°Ô ºÎ¿©µÈ ÇÒ´ç·® ³ª¿]
quota -v 512 [Userid 512 ¿¡°Ô ºÎ¿©µÈ ÇÒ´ç·® ³ª¿]
repquota -va [¸ðµç ÆÄÀϽýºÅÛÀÇ ¸ðµç »ç¿ëÀÚ¿¡ ´ëÇÑ ÇÒ´ç·® º¸±â]
C-Shell
C-Shell (csh)Àº ¿ì¹ßÀûÀÎ ÀÚ¿ø ³²¿ë ¹æÁö¸¦ À§ÇÑ ¼ö´ÜÀ» ²Ï ¸¹ÀÌ Á¦°øÇÑ´Ù:
| C shell ±â´É |
¸í·É¾î |
| ÄÚ¾î ÆÄÀÏ¿¡ ³¶ºñµÇ´Â °ø°£ Á¦ÇÑ |
limit coredumpsize 0M |
| ½ºÅÃ, Èü, ÇÁ·Î¼¼½º´ç CPU ½Ã°£, ÃÖ´ë ÆÄÀÏÅ©±â ¹× °¡»ó¸Þ¸ð¸®µµ Á¦ÇÑ °¡´É. |
Use "limit" plus:
stacksize datasize cputime filesize memorysize |
| ±âÁ¸ ÆÄÀÏÀÌ ¿ì¹ßÀûÀ¸·Î ÆÄ±«µÇÁö ¾Êµµ·Ï Ãâ·Â ¹æÇâ Àüȯ(output redirection) Á¦ÇÑ. |
set noclobber |
| CTRL-d¸¦ ´·¯ ½Ç¼ö·Î C ½©À» Á¾·áÇÏ´Â °Í ¹æÁö. |
set ignoreeof |
| ÆÄÀÏ »èÁ¦½Ã »ç¿ëÀÚ¿¡°Ô ¹°¾î È®ÀÎ |
alias rm `rm -I \!*' |
µð½ºÅ©°¡ ²ËáÀ» °æ¿ì, ´ÙÀ½Àº ÇöÀç µð·ºÅ丮¿Í ¼ºêµð·ºÅ丮¿¡¼ 0.5MB (1000 ºí·Ï) º¸´Ù Å©°í »ý¼ºµÈ Áö 7ÀÏÀÌ ¾ÈµÈ ¸ðµç ÆÄÀÏ À» ³ª¿ÇÑ´Ù (Sun¿¡¼):
find . -xdev -mtime -7 -size +1000 -ls
´ÙÀ½Àº ¾îÇø®ÄÉÀ̼ÇÀ̳ª ¼ºñ½º°¡ ¿Ö ¿ÀÀÛµ¿ÇÏ´ÂÁö ã¾Æ³»´Â µ¥ À¯¿ëÇÏ´Ù:
| ¼³¸í |
Solaris 1 (SunOS 4) |
Solaris 2.x |
| ¾îÇø®ÄÉÀ̼ǿ¡ ÀÇÇÑ ½Ã½ºÅÛ È£Ãâ °¨½Ã |
ps -ax | grep <application name>
trace -p <pid> |
ps -ef | grep <application name>
truss -p -p <pid> |
| À§¿Í °°À½, verbose |
|
truss -f -p -v all <pid> |
| ÀÌ´õ³Ý ÀÎÅÍÆäÀ̽º le0 ¿¡¼ ÆÐŶ ÃßÀû |
etherfind le0 from myhost to \ myserver |
snoop -d le0 from host myhost \ to host myserver |
| À§¿Í °°À½, verbose summary |
|
snoop -d le0 -V from host \ myhost to host myserver |
º¯°æ/¸±¸®Áî °ü¸®
»ç¿ëÀÚ °øÁö
¿Â¶óÀÎ °øÁö
À¯´Ð½º´Â »ç¿ëÀÚ°£ Åë½ÅÀ» À§ÇÑ ÀÛÀº À¯Æ¿¸®Æ¼µéÀ» ¸¹ÀÌ Á¦°øÇÑ´Ù.
- Wall Àº ·Î±×¿ÂÇÑ ¸ðµç »ç¿ëÀڵ鿡°Ô ¸Þ½ÃÁö¸¦ º¸³¾ ¼ö ÀÖ°Ô ÇÑ´Ù.
- Talk ´Â µÎ ¸íÀÇ ¿Â¶óÀÎ »ç¿ëÀڵ鰣¿¡ ´ëÈ½Ä "äÆÃ" ¼¼¼ÇÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù.
- Email Àº "Áö±Ý º¸³»°í ³ªÁß¿¡ ÀдÂ" ¹æ½ÄÀÇ »ç¿ëÀÚ °øÁö¸¦ °¡´ÉÇÏ°Ô ÇÑ´Ù.
/etc/issue (Solaris 2.4 ÀÌ»ó)
ÀÌ ÆÄÀÏÀÇ ³»¿ëÀº login ÇÁ?ÇÁÆ®°¡ »ç¿ëÀÚ¿¡°Ô ÁÖ¾îÁö±â Àü¿¡ Ãâ·ÂµÈ´Ù. µû¶ó¼, À̸¦ Ȱ¿ëÇÏ¿© »ç¿ëÀڵ鿡°Ô ½Ã½ºÅÛÀÇ ºÐ·ù ·¹º§À» ¾Ë¸®µçÁö Ȥ½Ã ÀÖÀ» ¾Ç¿ë¿¡ ´ëÇÑ °á°ú¸¦ ¾Ë¸± ¼ö ÀÖ´Ù. E.g.
***************************************************************************
*** Àΰ¡µÈ »ç¿ëÀڵ鸸 ÀÌ ½Ã½ºÅÛ¿¡ ¿¬°áÇÒ ¼ö ÀÖ½À´Ï´Ù. *****
*** ½Ã½ºÅÛ º¸¾È Ä§ÇØ ½Ãµµ½Ã °í¹ßµÉ ¼ö ÀÖ½À´Ï´Ù. *****
***************************************************************************
- ssh ´Â ÇöÀç ÀÌ ÆÄÀÏÀ» ¹«½ÃÇÑ´Ù.
/etc/motd (Message of the Day)
/etc/motd ÀÇ ³»¿ëÀº ·Î±×ÀÎ ÇÏÀÚ¸¶ÀÚ »ç¿ëÀÚ¿¡°Ô º¸¿©Áø´Ù (xdm À̳ª ~/.hushlogin ¸¦ »ç¿ëÇÏÁö ¾Ê´Â ÇÑ). µû¶ó¼, À̸¦ ÀÌ¿ëÇÏ¿©:
- À¯Áöº¸¼ö¸¦ À§ÇÑ Áߴܽð£À» °øÁöÇÒ ¼ö ÀÖ´Ù.
- ½Ã½ºÅÛ º¯°æ»çÇ×, ½Å±Ô/Ãß°¡ ¾îÇø®ÄÉÀ̼ÇÀ» ¾Ë¸± ¼ö ÀÖ´Ù.
º¯°æ ·Î±×
¾î¶² ÆÄÀÏ/¼ºê½Ã½ºÅÛ¿¡ ¾ðÁ¦, ´©±¸¿¡ ÀÇÇØ ¾î¶² º¯°æÀÌ ÀÖ¾ú´ÂÁö¸¦ »ó¼¼ÇÏ°Ô ±â·ÏÇÑ ÆÄÀÏÀÌ °¢ ¼¹ö¿¡ º¸°üµÉ °ÍÀ» ±ÇÀåÇÑ´Ù. À̰ÍÀº ƯÈ÷ ÇѸí ÀÌ»óÀÇ °°Àº ½Ã½ºÅÛÀ» °í³ª¸®Çϰí ÀÖÀ» ¶§ Áß¿äÇÏ´Ù.
¿ø°Ý ¼³Ä¡ (UC)
TBD: Jumpstart (bootparams, ARP, root, package, patch servers), diskless booting, Solstice AutoClient
¿ø°Ý ÄܼÖ
´ëºÎºÐÀÇ À¯´Ð½º ÄֵܼéÀº (e.g. Suns) Á÷·ÄÆ÷Æ®¸¦ ÅëÇØ ¿ø°ÝÀ¸·Î °ü¸®µÉ ¼ö ÀÖ´Ù. À̰ÍÀº ¸Å¿ì À¯¿ëÇÑ ±â´ÉÀÌ´Ù.
- ¼¹öÀÇ ttya ¿Í ´Ù¸¥ ½Ã½ºÅÛ (¿öÅ©½ºÅ×À̼ÇÀ̶ó°í ºÎ¸£ÀÚ) ÀÇ (¿¹¸¦µé¾î) ttyb »çÀÌ¿¡ ³Î¸ðµ© ÄÉÀ̺íÀ» ¿¬°áÇÑ´Ù.
- ¼¹ö¸¦ Áß´ÜÇϰí, Űº¸µå & ½ºÅ©¸°À» Á¦°Å ÈÄ ÀçºÎÆÃÇÑ´Ù.
- ¿öÅ©½ºÅ×À̼ǿ¡¼, xterm À» ½ÃÀÛÇÏ¿© "cu -l ttyb -s 9600" À» ½ÇÇà ÇÑ ÈÄ, ¸î ¹ø ¸®ÅÏÀ» ´©¸¥´Ù. ·Î±×ÀÎ ÇÁ·ÒÇÁÆ®³ª ´Ù¸¥ ÄÜ¼Ö ¸Þ½ÃÁö°¡ º¸¿©¾ß ÇÑ´Ù. cu ´ë½Å tip À» /etc/remote ¿Í ÇÔ²² »ç¿ëÇÒ ¼öµµ ÀÖ´Ù.
- Sun ¿¡¼: ÀÌ ÄܼÖÀ» ÀÌ¿ëÇÏ¿© ¼¹ö¸¦ Á¤Áö½ÃŰ·Á¸é "~%b" À» Ä£´Ù, "STOP-A" ¿Í °°´Ù.
- ÄܼÖÀ» ±×¸¸µÎ·Á¸é, "~." À» Ä£´Ù. ¸ÕÀú Äֿܼ¡¼ ·Î±×¾Æ¿ôÇÏ´Â °ÍÀ» ÀØÁö ¾Ê´Â´Ù!
ÆÐÄ¡
- ½Å±Ô ½Ã½ºÅÛÀº °¡Àå ÃÖ½ÅÀÇ º¸¾È ÆÐÄ¡¿Í ÇÔ²² ¼³Ä¡µÇ¾î¾ß ÇÑ´Ù.
- º¥´õ ÆÐÄ¡ ¸®½ºÆ®¿Í CERT °°Àº À̸ÞÀÏ ¸®½ºÆ®¸¦ Á¤±âÀûÀ¸·Î È®ÀÎÇÏ¿© »õ·Î¿î º¸¾È °ü·Ã ÆÐÄ¡°¡ ÀÖ´ÂÁö ¾Ë¾Æº»´Ù (
¸ÅÁÖ).
FIRST, CERT ³ª CIACD ¿¡¼ °Á¶ÇÑ À§ÇèÇÑ ¹®Á¦µéÀº Áï½Ã Á¶Ä¡µÇ¾î¾ß ÇÑ´Ù.
- ÆÐÄ¡¸¦ ¾÷¹« ½Ã½ºÅÛ¿¡ ¼³Ä¡Çϱâ Àü¿¡ Å×½ºÆ®ÇÑ´Ù!
C ¶óÀ̺귯¸® ÆÐÄ¡
¾î¶² Ç÷§Æûµé¿¡¼´Â gets() ¶óÀ̺귯¸® ÇÔ¼ö°¡ Ãë¾àÁ¡À» °¡Áö°í ÀÖÀ» ¼ö ÀÖ´Ù. È®ÀÎÇϱâ À§ÇØ, ´ÙÀ½À» ÀÔ·ÂÇÑ´Ù:
yes | tr -d '\012' | dd bs=256 count=3 | telnet <host> 79
ÀÌ ¸í·ÉÀ¸·Î ÄÚ¾î ÆÄÀÏÀÌ ¸¸µé¾îÁö¸é, gets() °¡ ¾ÈÀüÇÏÁö ¸øÇÑ °ÍÀÌ¸ç µû¶ó¼ gets() ¸¦ È£ÃâÇÏ´Â ¸ðµç ÇÁ·Î±×·¥ÀÌ ¾ÈÀüÇÏÁö ¸øÇÒ ¼ö ÀÖ´Ù. ½Ã½ºÅÛ º¥´õ¿¡°Ô ¿¬¶ôÇÏ¿© ÆÐÄ¡¸¦ ¹Þ´Â´Ù.
À̰ÍÀº Solaris 1 & 2 ¿¡¼ Å×½ºÆ® ÇØºÃ´Âµ¥, ¹®Á¦°¡ ¾ø´Ù. TBD: OSF, AIX , Linux, IRIX & HP-UX??
HP º¸¾È ÆÐÄ¡
HP ÆÐÄ¡´Â À̸ÞÀÏ·Î ¹ÞÀ» ¼ö ÀÖ´Ù (ºÎ·Ï C ÂüÁ¶). HP´Â ´Ù¾çÇÑ Çϵå¿þ¾î& OS ¹öÀüµéÀ» ¸¹ÀÌ °¡Áö°í ÀÖ´Ù.
¿©±â HP-UX 10.01ÀÇ ¸î°¡Áö °ßº» ÆÐÄ¡°¡ ÀÖ´Ù:
PHCO_6595 S syslog(3)ÀÇ º¸¾È Ãë¾àÁ¡. ? HP-UX 10.10 ¿¡¼ ¼öÁ¤
IBM AIX º¸¾È ÆÐÄ¡ (PTF: Program Temporary Fixes)
ftp://ftp.auscert.org.au/pub/mirrors/software.watson.ibm.com/aix-patches
DEC º¸¾È ÆÐÄ¡
Ultrix: ÃÖÇÏ V4.4 ·Î ¾÷±×·¹À̵åÇϰí Security Enhancement kit ¸¦ Àû¿ëÇÑ´Ù.
OSF/1: ÃÖÇÏ V2.0 À¸·Î ¾÷±×·¹À̵åÇϰí Security Enhancement kit ¸¦ Àû¿ëÇÑ´Ù.
¸î¸î ÆÐÄ¡µéÀ» ±¸ÇÒ ¼ö ÀÖ´Â °÷:
ftp://ftp.auscert.org.au/pub/mirrors/ftp.service.digital.com/osf/
ftp://ftp.auscert.org.au/pub/mirrors/ftp.service.digital.com/osf/<v>/ssrt
ftp://ftp.service.digital.com/pub/osf/<v>/ssrt*
ftp://ftp.auscert.org.au/pub/mirrors/ftp.service.digital.com/ultrix /<v>/ssrt*
ftp://ftp.service.digital.com/pub/ultrix/<v>/ssrt*
<v> ´Â OS¹öÀü.
IRIX (Silicon Graphics) º¸¾È ÆÐÄ¡
IRIX ´Â ²Ï ¸¹Àº º¸¾È ȦÀ» °¡Áö°í ÀÖ¾ú´Âµ¥, ÁÖ·Î ½Ã½ºÅÛÀÌ »ç¿ëÀÚ¿¡°Ô Ä£¼÷ÇÏ°Ô ¼³°èµÇ°í º¸¾È¿¡ ´ëÇÑ °í·Á´Â °ÅÀÇÇÏÁö ¾Ê¾Ò±â ¶§¹®ÀÌ´Ù.
¼Ò½º´Â ºÎ·Ï C ÂüÁ¶.
ftp://ftp.auscert.org.au/pub/mirrors/ftp.uu.net/sgi/security.Z ÂüÁ¶
Sun º¸¾È ÆÐÄ¡
´ÙÀ½ ¸ñ·ÏÀº Sun ÆÐÄ¡µéÀÇ °ßº»À¸·Î, ¿©·¯ºÐ¿¡°Ô ½ÇÁ¦ ¹®Á¦µé¿¡ ´ëÇÑ ´À³¦À» ÁÖ±â À§ÇÑ °ÍÀÌ´Ù. °¢ ¸ñ·ÏÀÌ ¾ðÁ¦ °»½ÅµÇ¾ú´ÂÁö ¾Ë·ÁÁÖ´Â ³¯Â¥µéÀÌ ´Þ·ÁÀÖ´Ù. »ç½Ç ¿À·¡µÈ °ÅÁö¸¸, ÃֽŠÁ¤º¸·Î °»½ÅÇÒ °¡Ä¡°¡ ¾ø´Â °ÍÀÌ, sunsolve ¿¡¼ ÈξÀ ´õ ÁÁÀº ÀڷḦ Á¦°øÇÑ´Ù (4³âÀü¿¡ Çß´ø °Íº¸´Ù...:).
- Solaris 2 ¿¡¼, ¾î¶² ÆÐÄ¡°¡ ¼³Ä¡µÇ¾î ÀÖ´ÂÁö º¸·Á¸é, showrev -p ¸¦ »ç¿ëÇÑ´Ù, ¶Ç´Â:
installpatch -p | awk '{print $2}' | sort
- ÃÖ½ÅÀ¸·Î À¯ÁöÇϱâ À§ÇÑ °¡Àå ÁÁÀº ¹æ¹ýÀº Sun°ú ¼ºñ½º °è¾àÀ» ü°áÇÏ¿© sunsolve.sun.com ¿¡ ÀÖ´Â Sunsolve notification ¼¹ö¸¦ ÅëÇØ ½Å±Ô ÆÐÄ¡¿¡ ´ëÇØ ÀÚµ¿À¸·Î Å뺸 ¹Þ´Â °ÍÀÌ´Ù.
- ¶Ç´Ù¸¥ (¹«·á) À¯¿ëÇÑ µµ±¸´Â PatchDiag ÀÌ´Ù (sunsolve ¿¡¼ ±¸ÇÒ ¼ö ÀÖÀ½). À̸¦ °¡Àå ÃÖ½ÅÀÇ ÆÐÄ¡ Á¶È¸ ¸ñ·ÏÀ¸·Î ¼³Ä¡ÇÏ¿©, ½ÇÇàÇÏ¸é ´ç½ÅÀÇ ½Ã½ºÅÛ¿¡ ÇÊ¿äÇÑ ±ÇÀå(recommended), y2k, º¸¾È ÆÐÄ¡µéÀ» Á¤È®È÷ ¾Ë·ÁÁØ´Ù. ½Ã°£ÀÌ ÈξÀ Àý¾àµÈ´Ù.... °íÀ¯(appropriate) ÆÐÄ¡µµ °¡Á®¿ÀÁö ¾Ê´Â °ÍÀÌ ¾ÈŸ±õ´Ù!
Solaris 1.1 (SunOS 4.1.3, 16.11.95):
100103-12 SunOS 4.1.3;4.1.3_U1: set file permissions to more secure mode
100173-12 SunOS 4.1.3: NFS jumbo
100296-04 SunOS 4.0.3;4.1;4.1.1;4.1.2;4.1.3: netgroup exports to world
100377-22 SunOS 4.1.3: sendmail jumbo patch
100383-06 SunOS 4.0.3;4.1;4.1.1;4.1.2;4.1.3: rdist security and hard links enhancement,.
100424-01 SunOS 4.1.1: NFS fsirand security fix.
100448-03 OpenWindows 3.0: loadmodule is a security hole.
100482-07 SunOS 4.1;4.1.1;4.1.2;4.1.3: ypserv, ypxfrd, DNS fix.
100567-04 SunOS 4.1,4.1.1, 4.1.2, 4.1.3: mfree and icmp redirect security patch
100630-02 SunOS 4.1.1;4.1.2;4.1.3: SECURITY: methods to exploit login su
100631-01 SunOS 4.1.1;4.1.2;4.1.3: env variables can be used to exploit login.
101080-01 SunOS 4.1.1 4.1.2 4.1.3: security problem with expreserve
101200-03 SunOS 4.1.3: Breach of security using modload
100224-13 SunOS 4.1.1,4.1.2,4.1.3: /bin/mail jumbo patch
100257-06 SunOS 4.1.3c,4.1.3: ldd and ld.so incorrectly finds libXp.so
100272-07 SunOS 4.1.3: Security update for in.comsat.
100305-15 SunOS 4.1.1, 4.1.2, 4.1.3: lpr Jumbo Patch
100359-08 SunOS 4.1.1;4.1.2;4.1.3: streams jumbo patch
100444-74 OpenWindows 3.0: OpenWindows V3.0 Server Patch 3000-122
100452-72 OpenWindows 3.0: XView 3.0 Jumbo Patch
100478-01 OpenWindows 3.0: xlock crashes leaving system open
100507-06 SunOS 4.1.3: tmpfs jumbo patch
100593-03 SunOS 4.1.3: Security update for dump.
100630-02 SunOS 4.1.1, 4.1.2, 4.1.3: SECURITY: methods to exploit login/su
100631-01 SunOS 4.1 4.1.1 4.1.2 4.1.3: env variables can be used to exploit login
100726-28 SunOS 4.1.3: sun4m jumbo patch for kernel performance and memory bugs
100890-12 SunOS 4.1.3: domestic (US only) libc jumbo patch
100891-13 * SunOS 4.1.3: international libc jumbo patch
100909-03 SunOS 4.1.1;4.1.2;4.1.3: Security update for syslogd.
100988-04 SunOS 4.1.3: UFS File system and NFS locking Jumbo Patch.
101072-02 SunOS 4.1.1;4.1.2;4.1.3: Non-related data filled the last block tarfile
101080-01 SunOS 4.1.1 4.1.2 4.1.3: security problem with expreserve
101200-03 SunOS 4.1.3: Breach of security using modload
101480-01 SunOS 4.1.1;4.1.2;4.1.3: Security update for in.talkd.
101481-01 SunOS 4.1.3: Security update for shutdown.
101640-03 SunOS 4.1.3: in.ftpd logs password info when -d option is used.
102023-03 SunOS 4.1.3: Root access possible via forced passwd race condition
Solaris 2.0(Dec 1994):
101119-01 SunOS 5.0: fixes security hole in expreserve
100723-01 SunOS 5.0: installs create security hole
Solaris 2.1 (Dec 1994):
101352-03 SunOS 5.1 x86: security fixes for extraneous data, disk file problem
101089-01 SunOS 5.1: fixes security hole in expreserve
101707-01 SunOS 5.1 x86: mail uucleanup security fixes
Solaris 2.2 (Dec 1994):
101301-03 SunOS 5.2: security bug & tar fixes
101090-01 SunOS 5.2: fixes security hole in expreserve
101842-01 SunOS 5.2: sendmail jumbo patch - security
101268-01 SunOS 5.2: nispasswd puts questionable values in shadow fields
Solaris 2.3 (Dec 1994):
101235-01 SunOS 5.3: POINT PATCH: sendmail
101327-08 SunOS 5.3: security and miscellaneous tar fixes
101545-02 Tmpfs permissions TBD
101736-03 SunOS 5.3: nisplus patch
101739-07 SunOS 5.3: sendmail jumbo patch - security
101769-02 SunOS 5.3: nisupdkeys fixes
101889-03 OpenWindows 3.3: filemgr forked executable ff.core has a security hole.
102034-01 SunOS 5.3: portmapper security hole
102168-01 SunOS 5.3: nistbladm fix
102268-01 SunOS 5.3: nismkdir dumps core creating non-root masters
Solaris 2.4 x86 (May 1995):
101982-02 SunOS 5.4_x86: login & security fixes
102064-04 SunOS 5.4_x86: sendmail bug fixes
102106-01 SunOS 5.4_x86: nisd occasionally dies without core dumping
102293-02 OpenWindows 3.4_x86: security hole
102712-01 Tmpfs permissions
Solaris 2.4 SPARC (Nov. 17, 1995, tested):
101878-11 OpenWindows 3.4: Xview Jumbo
101945-34 SunOS 5.4: jumbo patch for kernel
101973-14 SunOS 5.4: fixes for libnsl and ypbind
102044-01 SunOS 5.4: bug in mouse code makes root attack possible.
102049-02 SunOS 5.4: linker fixes
102066-04 SunOS 5.4: sendmail bug fixes
102070-01 SunOS 5.4: Bugfix for rpcbind portmapper
102105-01 SunOS 5.4: nisd occasionally dies without core dumping
102216-02 SunOS 5.4: klmmod and rpcmod fixes
102218-03 SunOS 5.4: Libbsm fixes.
102273-01 SunOS 5.4: nisupdkeys -a does not deal properly with multi-homed systems
102277-02 SunOS 5.4: nss_nisplus.so.1 fixes
102292-01 OpenWindows 3.4: security hole
102303-05 SunOS 5.4: POINT PATCH: linker fixes
102319-01 SunOS 5.4: Sendmail point patch
102336-01 SunOS 5.4: NIS+ passwd aging fix.
102656-01 SunOS 5.4: /dev/qec should protect against being opened directly.
102680-03 SunOS 5.4: fixes for ufsdump and wall
102704-02 SunOS 5.4: jumbo patch for NIS commands
102711-01 SunOS 5.4: creation of /tmp/ps_data is security problem
102756-01 SunOS 5.4: expreserve still has security problem
102922-03 SunOS 5.4: Inetd fixes.
Solaris 2.5 SPARC (June 1996, tested):
103279-01 SunOS 5.5: nscd breaks password shadowing with NIS+
102832-01 OpenWindows 3.5: Xview Jumbo Patch
102835-01 OpenWindows 3.5: Filemgr Jumbo Patch
102837-01 OpenWindows 3.5: Calendar mgr doesn't display Fri March 1 in a leapyr
102839-01 OpenWindows 3.5: Mailtool attachments with subtype have wrong icon
102841-01 OpenWindows 3.5: OLGX (libolgx) Xsun memory leak with Caption widgets
102846-01 OpenWindows 3.5: Imagetool can't display pgm files properly
102850-01 OpenWindows 3.5: OLIT Jumbo Patch
102971-01 SunOS 5.5: vipw fix
102980-04 SunOS 5.5: sendmail fixes
102979-01 SunOS 5.5: memory leakage in be driver
102982-01 SunOS 5.5: csh fix
102984-01 SunOS 5.5: sd driver fix
103009-02 SunOS 5.5: ppp fixes
103017-04 SunOS 5.5: Jumbo point patch for SPARCstorage Array (SSA) 2.0
103026-01 SunOS 5.5: hme driver fixes
103048-02 SunOS 5.5: automountd fixes
103060-01 SunOS 5.5: nis_cachemgr fix
103066-01 SunOS 5.5: rpc.nisd hangs in write(2)
103093-02 SunOS 5.5: kernel patch
103135-01 SunOS 5.5: arch does not work correctly on non-SMI sparc systems
103136-01 SunOS 5.5: bugfix for renice
103162-01 SunOS 5.5: cp, mv and ln fix
103187-02 SunOS 5.5: libc fixes
103210-04 OpenWindows 3.5: Server (Xsun) Jumbo Patch
103226-03 SunOS 5.5: /kernel/sys/nfs and /kernel/fs/nfs fixes
103238-01 SunOS 5.5: Using sigprof and libaio will cause program to segfault
103242-02 SunOS 5.5: linker patch
103244-01 SunOS 5.5: ftp tests may cause system hang on Ultrasparc systems
103246-03 OpenWindows 3.5: patch for DPS and fonts
103251-02 OpenWindows 3.5: user cannot insert appointments into calendar
103276-01 SunOS 5.5: /bin/mail generates IOERR return code for quota exceeded
103282-02 OpenWindows 3.5: nohup cmdtool hangs up when parent dies
103285-01 SunOS 5.5: make and cpp fixes
103295-01 SunOS 5.5: fold loses data if files contain no newline
103300-02 OpenWindows 3.5: ff.core security patch
103301-02 OpenWindows 3.5: ff.core security patch
103318-01 SunOS 5.5: kernel/fs/fifofs and kernel/sys/pipe fixes
103325-01 SunOS 5.5: mount causes the system to panic Data fault
103381-01 OpenWindows 3.5: Patch for DGA client library FFB overlays
103468-01 SunOS 5.5: statd security problem
New Patches Released, but not yet tested by the author:
103226-06 SunOS 5.5: /kernel/sys/nfs, /kernel/fs/nfs & /kernel/misc/nfssrv fixes
103009-03 SunOS 5.5: ppp fixes
103076-03 Creator 2.5: FFB Patch
103526-01 SunOS 5.5: When fdc_sec_size is 128 or 256, it becomes an error
103241-01 SunOS 5.5: Undefined symbol in libc.so.1.9
103247-04 Solaris 2.5: admintool patch
103266-01 SunOS 5.5: nissetup default permissions for password table not secure
103454-01 OpenWindows 3.5: patch for Japanese input method in text of OLIT
103476-01 SunOS 5.5: bpp fixes
103477-01 SunOS 5.5: RPC: Unable to send/receive
103492-01 SunOS 5.5: autofs is not MT-safe
103505-01 OpenWindows 3.5: snapshot fails on FFB when default visual is overlay
103506-01 OpenWindows 3.5: Main window not redrawn correctly after unmapping
103516-01 SunOS 5.5: IPX/SPX and IPX Gateway hangs on heavy server load.
103661-01 SunOS 5.5: nisaddent fixes
103723-01 SunOS 5.5: cron fixes
Áߺ¹¼º (Redundancy)
°í°¡¿ë¼º ½Ã½ºÅÛ¿¡¼´Â RAID 5 ³ª ¹Ì·¯¸µÀÌ ±Ç°íµÈ´Ù. º°µµÀÇ (Áï ³»ÀåÀÌ ¾Æ´Ñ) RAID 5 »ç¿ëÀ» ±ÇÀåÇÑ´Ù. ÇÑ ¼¼Æ®¿¡¼ µÎ°³ÀÇ RAID 5 µð½ºÅ©¿¡ Àå¾Ö°¡ ¹ß»ýÇϸé, º¹±¸ ½Ã°£ÀÌ ¸Å¿ì ±æ¾îÁú ¼ö ÀÖ´Ù (¾Æ¸¶ 12-24½Ã°£) - µû¶ó¼ ¾Æ¸¶µµ ¾î¶² ½Ã½ºÅ۵鿡´Â ¹Ì·¯¸µÀÌ ´õ ³ªÀ» °ÍÀÌ´Ù.
µð½ºÅ© ¹Ì·¯¸µ / RAID: °ßº» Á¦Ç°
- Data General Clariion (1995 ³â 1¿ù) ¿ÜÀå RAID ½Ã½ºÅÛÀº NT, SunOS, Solaris, AIX, µîµî¿¡¼ µ¿ÀÛÇÑ´Ù. ÀúÀÚ´Â Solaris 2.4¿Í Sybase 4.9.2¸¦ °¡Áö°í »ç¿ëÇØºÃ´Âµ¥ ½Å·Ú¼º°ú ¼º´ÉÀÌ ÁÁ¾Ò´Ù.
- Sun SPARCstoragearray (1995³â 1¿ù) Àº Solaris ½Ã½ºÅÛ¿¡¼ ¾µ ¼ö ÀÖ´Â ¼Ö·ç¼ÇÀÌÁö¸¸, ¼º´ÉÀº Clarion ¸¸Å ÁÁÁö ¾Ê°í Sun ½Ã½ºÅÛ¿¡ Ư¼öÇÑ ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÇ¾î¾ß ÇÑ´Ù. µð½ºÅ© ÇÖ ½º¿ÍÇÎ (hot swapping)À» Çã¿ëÇÏÁö ¾Ê°í, ´Ù¸¥ ¾ÆÅ°ÅØÃÄ¿¡¼´Â µ¿ÀÛÇÏÁö ¾Ê´Â´Ù. ÇÏÁö¸¸ Èï¹Ì·Î¿î ¿É¼ÇµéÀÌ Àִµ¥, 3Km±îÁöÀÇ µà¾ó ±¤ ÀÎÅÍÆäÀ̽º, ±×·¡ÇÈ ¼³Á¤ ¼ÒÇÁÆ®¿þ¾î ±×¸®°í ±¦ÂúÀº °¡°Ý(¾î¶²¶§´Â!) µîÀÌ´Ù.
- Sun Disksuite Àº ¹Ì·¯¸µ/RAID 5 ¿¡´Â ºÎÁ·ÇÑ ¼ÒÇÁÆ®¿þ¾î ¼Ö·ç¼ÇÀ̰í, storage array¸¦ °ü¸®Çϴµ¥ ¾²ÀÏ ¼ö ÀÖ´Ù. V3.0 À» ¾÷¹«È¯°æ¿¡¼ Å×½ºÆ® ÇØºÃ´Âµ¥ ¸í·ÉÁÙ ÀÎÅÍÆäÀ̽º°¡ ¹«°Ì°í Á¶ÀâÇϱä ÇÏÁö¸¸ ¾ÈÁ¤ÀûÀÌ´Ù. V4.0 Àº ³ª»ÚÁö ¾ÊÀº ±×·¡ÇÈ ÀÎÅÍÆäÀ̽º¸¦ °¡Áö°í ÀÖ´Ù (ÇÊÀÚ´Â ½Å·ÚÇÏÁö ¾ÊÁö¸¸), ±×·¯³ª ¿©ÀüÈ÷ ¸í·ÉÁÙµµ ÇÊ¿äÇÏ´Ù. Disksuite Àº Sun¿¡¼¸¸ µ¹¾Æ°£´Ù.
- ÀÌ Ã¥ÀÇ Ã¹¹øÂ° ¹öÀü´ç½Ã·ÎºÎÅÍ RAID°¡ ¸¹ÀÌ Áøº¸ÇßÁö¸¸, ÇÊÀÚ´Â ¾ÆÁ÷µµ (¾î¶² ½Ã½ºÅÛ¿¡ ´ëÇØ¼´Â) ±×³É µÎ¹øÂ° (¿©ºÐ) µð½ºÅ©¸¦ °¡Áö°í, ¹ã¿¡ ¿Ã·Á¼, ù¹øÂ° µð½ºÅ©·ÎºÎÅÍ º¹»ç¹Þ°í, /etc/vfstab À» °íÄ¡°í, ºÎÆ® ºí·ÏÀ» ¼³Ä¡ÇÑ ÈÄ ³»¸®´Â °ÍÀ» ¼±È£ÇÑ´Ù. À̰ÍÀº ¹æÈº®¿¡ À¯¿ëÇϰí - ÇÊÀÚ°¡ Disksuite °°Àº RPC ¼ºñ½º¸¦ ¾²±â ²¨·ÁÇÏ´Â -, (Àå¾Ö½Ã) ó¸®Çϱ⠽±Áö¸¸ (±×³É µÎ¹øÂ° µð½ºÅ©·Î ºÎÆÃÇÏ¸é µÊ), 30ºÐÀÇ Áߴܽð£°ú 24½Ã°£±îÁöÀÇ µ¥ÀÌŸ ¼Õ½ÇÀ» ¼ö¿ë°¡´ÉÇØ¾ß ÇÑ´Ù. °Å´ëÇÑ µ¶¸³ µð½ºÅ©µµ ¿äÁò¿¡´Â Àú·ÅÇÏ´Ù. ´Ü¼øÇÑ °ÍÀÌ ¾Æ¸§´ä´Ù...
ÆÄÀÏ º¹Á¦ (rdist)
Rdist ´Â ½Ã½ºÅ۵鰣¿¡ ÆÄÀÏÀ» µ¿±âÈÇϰí Áß¿äÇÑ ÆÄÀϵéÀÌ º¯°æµÇÁö ¾ÊÀº °ÍÀ» È®ÀÎÇÏ´Â °£ÆíÇÑ ¹æ¹ýÀÌ´Ù. À̰ÍÀº Berkeley rsh ÇÁ·ÎÅäÄÝ·Î Åë½ÅÇϴµ¥, ÀÌ´Â °ð rshÀÇ °Á¡°ú ¾àÁ¡À» °¡Áö°í ÀÖ´Ù´Â ¶æÀÌ´Ù ("½Å·ÚµÇ´Â È£½ºÆ®" Àý ÂüÁ¶). ±×·¯³ª (V6.1.2 ¿¡¼) Àü¼ÛÀ» À§ÇØ SSH ¸¦ ¾µ ¼ö Àִµ¥, ±×·¯¸é Á¤¸» ¾ÈÀüÇØÁø´Ù. Ãßõ.
»ç¿ë:
- º¹¼öÀÇ ½Ã½ºÅÛµé »çÀÌ¿¡ ÆÄÀÏÀ» º¹Á¦, º¯°æµÇ´Â ÆÄÀϵ鸸 °»½Å. e.g. "¿ú ¹é¾÷".
- Áß¾ÓÀÇ ½Ã½ºÅÛ¿¡¼ Áß¿äÇÑ ÆÄÀϵéÀÇ º¯°æ»çÇ×À» °¨½ÃÇÑ´Ù. ¸¸¾à ¿¹¸¦ µé¾î, °ø°ÝÀÚ°¡ ¼¹ö¿¡ ÀÖ´Â DNS ±¸¼ºÆÄÀÏÀ» º¯°æÇߴµ¥, ÀÌ ÆÄÀÏÀÌ ¸ÅÀϹã rdist¿¡ ÀÇÇØ °¨½ÃµÈ´Ù¸é, rdist¿¡ ÀÇÇØ ¿Ã¹Ù¸¥ ¼³Á¤À¸·Î ÀÚµ¿ º¯°æµÇ°í °ü¸®ÀÚ´Â ÀÌ¿¡ ´ëÇØ Å뺸¸¦ ¹Þ´Â´Ù.
±Ç°í»çÇ×:
- °ø°³µµ¸ÞÀÎ ¹öÀüÀ» ¼³Ä¡ÇÑ´Ù (1996³â 6¿ù 6.1.2), (¿¹¸¦µé¸é) SunÀÇ ¹öÀüº¸´Ù ´õ ¸¹Àº ±â´ÉÀ» °¡Áö°í ÀÖ°í º¸¾È Ȧµµ ´õ Àû´Ù.
- SUID·Î ¸¸µéÁö ¾Ê´Â´Ù. °¡´ÉÇÑÇÑ ·çÆ®¸¸ »ç¿ëÇÑ´Ù.
- Àü¼ÛÇÁ·ÎÅäÄÝ·Î rsh ´ë½Å ssh »ç¿ëÀ» °í·ÁÇÑ´Ù (À̰ÍÀº º¸¾ÈÀ» ÈÎ-¾À °³¼±ÇÑ´Ù). Solaris2 ¿¡¼ Rdist 6.1.2 ¿Í ssh ´Â ¾ÆÁÖ Àß ÇÔ²² µ¿ÀÛÇÑ´Ù.
- rsh¸¦ »ç¿ëÇÑ´Ù¸é, Á¢±ÙÅëÁ¦ ¹× ·Î±ë Á¦°øÀ» À§ÇØ tcp wrappersÀÇ »ç¿ëÀ» °í·ÁÇÑ´Ù.
- Áß¾Ó¿¡ ÀÖ´Â rdist ½Ã½ºÅÛÀ» Àß º¸È£Çϰí, °¡´ÉÇÑÇÑ ÀÏ¹Ý »ç¿ëÀÚ °èÁ¤Àº Çã¿ëÇÏÁö ¾Ê´Â´Ù.
- »ç¿ëÀÚÀ̸§ (username) ¸»°í UID¿¡ ÀÇÇÑ µ¿±âȸ¦ ÇÑ´Ù - ƯÈ÷ À̱âÁ¾ ȯ°æ¿¡¼.
¿ÏÀüÇÑ ½Ã½ºÅÛ Áߺ¹¼º (Redundancy)
- IBMÀÇ HACMP (1995³â 11¿ù) ´Â AIX 4.1 ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ½Ã½ºÅÛ Áߺ¹¼ºÀ» Á¦°øÇÑ´Ù. ¾ÆÁ÷ Å×½ºÆ®´Â ¾ÈÇØºÃÁö¸¸, ¿©·¯°÷¿¡¼ ÃßõµÇ¾ú´Ù.
µÎ ½Ã½ºÅÛÀÌ RAID ¹Ú½º¿¡ µ¿½Ã¿¡ Á¢¼ÓÇϰí, ºñ»ó ´ë±â (hot standby) ½Ã½ºÅÛÀÇ ¸ð´ÏÅ͸µ ¼ÒÇÁÆ®¿þ¾î´Â ¸¶½ºÅÍ ¼¹ö¸¦ °è¼Ó °¨½ÃÇÏ´Ù°¡ ¸¶½ºÅͰ¡ ÀÀ´äÇÏÁö ¾ÊÀ¸¸é À̾î¹Þ´Â´Ù. ¸¶½ºÅÍÀÇ IP ÁÖ¼Ò´Â ´ë±â½Ã½ºÅÛ¿¡¼ »ç¿ëµÈ´Ù. ÃßÃø¿¡ ¸¶½ºÅÍ¿¡ ¿î¿µµÇ´Â ¼ÒÇÁÆ®¿þ¾îÀÇ È£½ºÆ® Id ±â¹Ý ¶óÀ̼¾½º°¡ ¹®Á¦ÀÏ °ÍÀÌ´Ù.
- Data General (1994) Àº ½Ã½ºÅÛ ·¹º§¿¡¼ Áߺ¹¼ºÀ» Á¦°øÇÏ´Â Clarion°ú ÇÔ²² »ç¿ëÇÏ´Â ¼ÒÇÁÆ®¿þ¾î¸¦ Á¦°øÇÑ´Ù. Å×½ºÆ®´Â ¾ÈÇØºÃ´Ù (²Ï ºñ½Î´Ù: ~$18k).
Àç³ º¹±¸
½ÇÇà±â·Ï ÆÄÀϽýºÅÛ (Journalling File Systems)
´ëºÎºÐÀÇ ¿äÁò À¯´Ð½º ½Ã½ºÅÛµéÀº (AIX4, Solaris 2.6...) ½ÇÇà±â·Ï(journalling) ÆÄÀϽýºÅÛÀ» Á¦°øÇÑ´Ù.
±âº»ÀûÀ¸·Î, ÆÄÀϽýºÅÛ¿¡ ´ëÇÑ º¯°æÀº ù¹øÂ°·Î ·Î±×¿¡, ±×´ÙÀ½¿£ µð½ºÅ©¿¡ ¾²¿©Áø´Ù. µð½ºÅ© ¾²±â°¡ ¼º°øÀûÀ¸·Î µÇ¸é, ·Î±×¿¡ ÀÖ´Â ³»¿ëµéÀº Á¦°ÅµÇ°Å³ª
"üũÆ÷ÀÎÆ®" µÇ¾îµµ µÈ´Ù. ÀÌ ÇÁ·Î¼¼½º´Â ½Ã½ºÅÛ Å©·¡½¬³ª Á¤Àü ÈÄÀÇ º¹±¸¸¦ °³¼±½ÃÄÑÁÖ°í µ¥ÀÌŸº£À̽º ¼¼°è¿¡¼´Â ¼ö³â°£ »ç¿ëµÇ¾î¿Ô´Ù. ½ÇÇà±â·ÏÀº ±×·¯³ª ¼º´É ÀúÇϸ¦ À¯¹ßÇÑ´Ù.
==> °¡¿ë¼ºÀÌ Áß¿äÇÏ°í µ¥ÀÌŸ°¡ ÀÚÁÖ ¾²ÀÌ´Â ÆÄÀϽýºÅÛ (e.g. /, /var and /home, ±×·¯³ª /usr ´Â ¸»°í) ¿¡ ´ëÇØ ½ÇÇà±â·ÏÀ» Ȱ¼ºÈÇÑ´Ù.
Å©·¡½¬ ´ýÇÁ
À¯´Ð½º ½Ã½ºÅÛÀÌ Å©·¡½¬µÇ¸é (" ÆÐ´Ð panic" À̶ó°íµµ ÇÔ), ÃßÈÄ ºÐ¼®À» À§ÇØ ¸Þ¸ð¸®ÀÇ Àüü ³»¿ëÀ» µð½ºÅ©¿¡ ¾µ °¡´É¼ºÀÌ ÀÖ´Ù. À¯´Ð½º ¼¹ö¿¡¼ ¼ÒÀ§ Å©·¡½¬ ´ýÇÁ¸¦ Ȱ¼ºÈ ÇÒ °ÍÀ» °·ÂÈ÷ ±Ç°íÇÑ´Ù. ÃæºÐÇÑ µð½ºÅ© °ø°£ÀÌ »ç¿ë°¡´ÉÇÑÁö¿¡ ÁÖÀǸ¦ ±â¿ï¿©¾ß ÇÑ´Ù (e.g. ¸Þ¸ð¸® 500MB ÀÎ ´ë¿ë·® db ¼¹ö¿¡¼, ½º¿Ò °ø°£¿¡ ´ýÇÁÇÒ ¼ö´Â ¾øÀ» °ÍÀÌ´Ù).
´ÙÀ½¿¡ ´ëÇÑ Man ÆäÀÌÁöµéµµ ÂüÁ¶ÇÑ´Ù: savecore, crash, adb, kadb .
- Solaris 1 ¿¡¼ ´ýÇÁ Ȱ¼ºÈ: ´ÙÀ½°ú °°ÀÌ /etc/rc.local ¿¡¼ ÁÖ¼®À» Áö¿î´Ù:
#
# Enable savecore (default is disabled)
#
mkdir -p /var/crash/¢¥hostname¢¥
echo -n 'checking for crash dump... '
intr savecore /var/crash/¢¥hostname¢¥
echo ''
- Solaris 2 ´ýÇÁ Ȱ¼ºÈ: ´ÙÀ½°ú °°ÀÌ /etc/init.d/sysetup ¿¡¼ ÁÖ¼®À» Áö¿î´Ù:
##
## Enable savecore (default is disabled)
##
if [ ! -d /var/crash/¢¥uname -n¢¥ ]
then mkdir -p /var/crash/¢¥uname -n¢¥
fi
echo 'checking for crash dump...\c '
savecore /var/crash/¢¥uname -n¢¥
echo ' '
- ´ýÇÁ·ÎÀÇ ºñÀΰ¡Á¢±ÙÀ» ¹æÁöÇϱâ À§ÇØ, À§ ÆÄÀϵ鿡 ´ÙÀ½ ÇàÀ» Ãß°¡ÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. ´ýÇÁ´Â Å©·¡½¬ ´ç½ÃÀÇ ¸Þ¸ð¸® µ¿°£¿¡ ÀÖ´Â ¸ðµç ¾îÇø®ÄÉÀ̼ÇÀ» Æ÷ÇÔÇϰí Àֱ⠶§¹®¿¡ ¸Å¿ì ±â¹Ð¼ºÀÌ ³ôÀº Á¤º¸¸¦ °¡Áú ¼ö ÀÖ´Ù.
chown -R root.staff /var/crash
chmod -R 600 /var/crash
- Å©·¡½¬ µð·ºÅ丮¿¡ minfree ¶ó´Â ÆÄÀÏÀÌ Á¸ÀçÇÒ °æ¿ì, ÀÌ ÆÄÀÏ¿¡ ÀÖ´Â ¼ýÀÚ´Â savecore°¡ ¼öÇàµÇ¾úÀ» ¶§ ÀÌ ÆÄÀϽýºÅÛ¿¡ ¸î ų·Î¹ÙÀÌÆ®ÀÇ °ø°£ÀÌ ºñ¾îÀÖ¾î¾ß ÇÏ´ÂÁö¸¦ ±ÔÁ¤ÇÑ´Ù.
- Ư¼ö ÀåÄ¡ (Áï ½º¿Ò¸»°í) ·ÎÀÇ ´ýÇÁµµ °¡´ÉÇÏ´Ù. Solaris 1¿¡¼, Ä¿³Î ±¸¼ºÆÄÀÏ¿¡ ´ÙÀ½ ÇàÀ» Ãß°¡Çϰí (device sd1b ¸¦ »ç¿ëÇÏ°í ½Í´Ù°í °¡Á¤) Ä¿³ÎÀ» À籸¼ºÇÑ´Ù (man config ÂüÁ¶):
config vmunix swap on sd1b
Solaris 2 ¿¡¼´Â, Á» ´õ º¹ÀâÇϰÔ, adb°¡ »ç¿ëµÇ¾î¾ß ÇÑ´Ù.
- Å©·¡½¬°¡ ¿©·¯¹ø ÀϾ °Í °°À¸¸é, ÀÌÀü ´ýÇÁµéÀ» ¾ÐÃàÇÑ´Ù. À̵éÀº ´ë°³ ¿ø·¡ Å©±âÀÇ °Ü¿ì 5%·Î ¾ÐÃàµÈ´Ù. Archive µÈ ´ýÇÁµµ ¸¶Âù°¡Áö´Ù.
- Å©·¡½¬ ´ýÇÁ´Â ¹Ýµå½Ã savecore·Î »ý¼ºµÈ ¾ÆÅ°ÅØÃÄ¿Í µ¿ÀÏÇÑ OS ¹öÀü¿¡¼ ºÐ¼®µÇ¾î¾ß ÇÑ´Ù .
Ãʱâ Å©·¡½¬ ´ýÇÁ ºÐ¼®
´ÙÀ½ ¸í·ÉÀº ÆÐ´ÐÀÌ ¹ß»ýÇϱâ Àü¿¡ ½Ã½ºÅÛ¿¡ ¹«½¼ÀÏÀÌ ÀÖ¾ú´ÂÁö ºÐ¼®ÇÏ´Â µ¥ »ç¿ëµÈ´Ù. À¯´Ð½º Å©·¡½¬ µð¹ö±ë¿¡ ´ëÇÑ ±¦ÂúÀº ±³º»À¸·Î [unix4] ÂüÁ¶.
| ¼³¸í |
Solaris 1 (SunOS 4) |
Solaris 2.x |
| ¾î¶² OSÀΰ¡? |
strings vmcore.0 | grep SunOS |
strings vmcore.0 | grep SunOS |
| ¾î¶² È£½ºÆ®Àΰ¡? |
strings vmcore.0 | grep machine |
strings vmcore.0 | grep machine |
| |
strings vmcore.0 | more |
strings vmcore.0 | more |
| ¾î¶² ÇÁ·Î¼¼½º°¡ ½ÇÇàÁßÀ̾ú³ª? |
ps -laxk vmunix.0 vmcore.0 |
crash »ç¿ë(¾Æ·¡ ÂüÁ¶) |
| ½Ã½ºÅÛ Å×ÀÌºí º¸±â |
pstat -T vmunix.0 vmcore.0 |
|
| ³×Æ®¿÷ Åë°è º¸±â |
netstat vmunix.0 vmcore.0 |
netstat -d unix.0 vmcore.0 |
| NFS Åë°è º¸±â |
nfsstat -n vmunix.0 vmcore.0 |
nfsstat -n unix.0 vmcore.0 |
| arp Å×ÀÌºí º¸±â |
arp -c vmunix.0 vmcore.0 |
arp -a unix.0 vmcore.0 |
| IPC º¸±â |
ipcs -a -N vmunix.0 -C vmcore.0 |
ipcs -a -N unix.0 -C vmcore.0 |
| |
| CRASH »ç¿ëÇϱâ: |
/etc/crash -d vmcore.0 -n vmunix.0 |
/usr/sbin/crash -d vmcore.0 -n vmunix.0 |
| crash µµ¿ò¸» |
> help |
> help |
| "p" ¸í·É¾î µµ¿ò¸» |
> help p |
> help p |
| ÇÁ·Î¼¼½º º¸±â |
> p -e |
> p -e |
| ÇÁ·Î¼¼½º »ó¼¼»çÇ× |
|
> p -l |
| crash »ó¼¼»çÇ× |
|
> status |
| crash Á¾·á |
> q |
> q |
| |
| ADB µð¹ö°Å »ç¿ëÇϱâ: |
adb -k vmunix.0 vmcore.0 |
adb -k unix.0 vmcore.0 |
| ÆÐ´Ð ¸Þ½ÃÁö°¡ ¹¹¿´³ª? |
*panicstr/s |
*panicstr/s |
| È£½ºÆ®À̸§ |
hostname/s |
$<utsname |
| OS ¹öÀü |
version/s |
$<utsname |
| µµ¸ÞÀÎ |
domainname/s |
srpc_domain/s |
| ½Ã½ºÅÛ |
sysname/s |
$<utsname |
| Á¦Á¶¾÷ü |
|
hw_provider/s |
| Å©·¡½¬ ½Ã°£/³¯Â¥ |
time/Y |
TIME/y |
| ºÎÆ® ½Ã°£/³¯Â¥ |
*boottime=Y |
*time-(lbolt%0t100)=Y |
| ½Ã½ºÅÛ ¸Þ½ÃÁö Ç¥½Ã |
msgbuf+10/s |
msgbuf+14s |
| ÃÖ±ÙÀÇ ¸Þ½ÃÁö ¹öÆÛ (ring) |
$<msgbuf |
$<msgbuf |
C ½ºÅà ¿ªÃßÀû
(Ç×»ó ¸ÂÁø ¾Ê´Ù!) |
$c |
$c |
| ½ºÅà ¿ªÃßÀû |
<sp$<stacktrace |
?? |
| ·çÆ® ÀåÄ¡´Â ¾î¶² °Í? |
|
rootfs$<bootobj |
| ½º¿Ò ÀåÄ¡´Â ¾î¶² °Í? |
|
swapfile$<bootobj
dumpfile$<bootobj |
| ·¹Áö½ºÅÍ º¸±â |
$cregs |
|
| IPC º¸±â |
ipcaccess/10i |
|
| adb Á¾·á |
CTRL-D or $q |
CTRL-D or $q |
| |
| Ä¿³Î ÇØÅ· (!#?) : |
adb -k /vmunix /dev/mem |
adb -k /dev/ksyms /dev/mem |
ADB ¸ÅÅ©·Î´Â /usr/lib/adb (Solaris 1) ³ª /usr/kvm/lib/adb (Solaris 2) ¿¡ º¸°üµÈ´Ù.
ÆÐ´Ð ¸Þ½ÃÁö¿¡ ´ëÇÑ ¸Þ¸ð:
- Memory address alignment ¶Ç´Â data fault ´Â ÀϹÝÀûÀ¸·Î À߸øµÈ Ä¿³Î Æ÷ÀÎÅ͸¦ ³ªÅ¸³½´Ù.
- Panic zero ´Â º¸Åë STOP-A ¸¦ °¡¸®Å²´Ù.
X À©µµ¿ì
See the X windows section in the "¾îÇø®ÄÉÀÌ¼Ç º¸¾È" ÀåÀÇ X À©µµ¿ì ÀýÀ» ÂüÁ¶ÇÑ´Ù.
üũ¸®½ºÆ®
ª°í ½Ç¿ëÀûÀΠüũ¸®½ºÆ® ¸î°¡Áö¸¦ ¼Ò°³ÇÑ´Ù.
[unix1] ¿¡µµ ÁÁÀº üũ¸®½ºÆ®µéÀÌ ÀÖ´Ù.
À¯´Ð½º °¨»ç üũ¸®½ºÆ®
½Ã½ºÅÛ ±¸¼º
°¨»çµÉ ½Ã½ºÅÛÀÇ ±¸¼ºÀ» ¹®¼ÈÇÑ´Ù:
¾ÆÅ°ÅØÃÄ (OS ¹öÀü), Çϵå¿þ¾î (CPU, ¸Þ¸ð¸®, µð½ºÅ©, ÁÖº¯ÀåÄ¡), ½Ã½ºÅÛ À̸§ & IP ÁÖ¼Ò, ½ÇÇàÁßÀÎ ÇÁ·Î¼¼½º ¸ñ·Ï, À߾˷ÁÁø ¼ºñ½ºµéÁß ½ÇÇàµÇÁö ¾Ê´Â °ÍÀÇ ¸ñ·Ï (°æÇè»ó), »ç¿ë°¡´ÉÇÑ rpc ¼ºñ½º ¸ñ·Ï°ú ³×Æ®¿÷ ÀÎÅÍÆäÀ̽º ¸ñ·Ï.
À§ »çÇ×À» ¾Ë±â À§ÇÑ À¯¿ëÇÑ ¸í·É¾îµé (Sun ¿¡¼):
uname -a, dmesg, format, showrev -p, ifconfig -a, ps -auwx or ps -ef, rpcinfo -p HOST, netstat -rn.
½Äº° & ÀÎÁõ
- ¸·ÇôÀÖÁö ¾ÊÀº °èÁ¤ ¸ñ·ÏÀ» ¸¸µé°í, ºó ÆÐ½º¿öµå¸¦ È®ÀÎÇϰųª ÆÐ½º¿öµå ÆÄÀÏ¿¡ ´ëÇØ crack À» µ¹¸°´Ù. µðÆúÆ® ÆÐ½º¿öµå¸¦ °¡Áö°í ÀÖ´Â °èÁ¤ÀÌ Àִ°¡?
½Ã½ºÅÛÀ» Á¶»çÇÏ¿© UID 0 À» °¡Áö°í Àְųª ÆÐ½º¿öµå°¡ ¾ø´Â °èÁ¤À» ã¾Æ³½´Ù:
awk -F: '{if ($3=="0") print $1}' /etc/passwd
awk -F: '{if ($2=="") print $1}' /etc/passwd ["logins -p" on Solaris]
- NIS: /var/yp/securenets °¡ Àִ°¡?
- NIS+: NIS+ °¡ NIS º¸´Ù ÈξÀ ³´´Ù. Passwd / shadow Å×ÀÌºí »ç¿ëÇã°¡´Â ±¦ÂúÀº°¡? ·¹º§ 2 º¸¾ÈÀ¸·Î ½ÇÇàµÇ°í Àִ°¡? ¸ðµç »ç¿ëÀÚµéÀÌ ¸ðµç ½Ã½ºÅÛ¿¡ Á¢±Ù °¡´ÉÇѰ¡ (nis_compat Ç׸ñ)? /var/nis ´Â Á¤±âÀûÀ¸·Î ¹é¾÷µÇ´Â°¡? º¹Á¦´Â?
- ÆÐ½º¿öµå ±ÔÄ¢ & ¼ö¸í,ÁÖ±â?
- °¢ °èÁ¤¿¡ ´ëÇÑ µðÆúÆ® ÆÄÀÏ »ý¼º ¸¶½ºÅ©. ½Ã½ºÅÛ µðÆúÆ®´Â (e.g. ftp ¿¡ ÀÇÇØ ¾÷·ÎµåµÇ´Â ÆÄÀÏ¿¡ ´ëÇÑ ¸¶½ºÅ©´Â)? ½Ã½ºÅÛ ½ÃÀÛ ÆÄÀϵ鿡´Â ¾ÈÀüÇÑ °ªµéÀÌ ¼³Á¤µÇ¾î Àִ°¡?
- Umask´Â e.g. 077 (±×·ìÀ̳ª ´Ù¸¥»ç¿ëÀÚ Á¢±Ù ¾øÀ½), 027 (±×·ì Àбâ, ´Ù¸¥»ç¿ëÀÚ Á¢±Ù¾øÀ½) ¶Ç´Â 022 (±×·ì & ´Ù¸¥»ç¿ëÀÚ Àбâ)? 002 °°Àº ´Ù¸¥ °ªµéÀº ¸Å¿ì ¼ö»óÇÏ´Ù.
Á¢±Ù ÅëÁ¦
- ¶ó¿ìÆÃ: ¾î¶² Á¾·ùÀÇ ¶ó¿ìÆÃÀÌ »ç¿ëµÇ´Â°¡? Á¤Àû, quiet modeÀÇ ¶ó¿ìÆÃ µ¥¸ó ¶Ç´Â ¿ÏÀüÇÑ ¶ó¿ìÆÃ? Å×À̺íÀ» °Ë»çÇÑ´Ù (netstat -rn).
- Inetd:
- ºÒÇÊ¿äÇÑ ¼ºñ½º´Â disable µÇ¾îÀÖ³ª?
- TCP wrappers?
- Inetd ·Î±ë (Solaris 2.4 ¿¡¼ inetd ¸í·ÉÇà¿¡ -t Ãß°¡) ?
- UUCP ´Â disable µÇ¾îÀÖ³ª?
- FTP: FTPD ·Î±ëÀÌ È°¼ºÈ µÇ¾îÀÖ³ª?
- /etc/shells °¡ Á¸ÀçÇϴ°¡? ¿£Æ®¸®´Â? (ÀÌ ½©À» °¡Áö´Â °èÁ¤Àº ftp¸¦ ¾µ ¼ö ÀÖ´Ù).
- Anonymous ftp °¡ ±¸¼ºµÇ¾î Àִ°¡? ¾ÈÀüÇϰÔ?
- /etc/ftpusers: ftp ¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Â(¾ø´Â) À¯È¿ °èÁ¤Àº ¹«¾ùÀΰ¡?
- TFTPD °¡ ÇÊ¿äÇÑ °æ¿ì, ¿Ã¹Ù¸£°Ô ±¸¼ºÇϰí (-s option), ¾Æ´Ï¸é disable ÇÑ´Ù.
- "r" ¸í·É¾î´Â ssh ·Î ´ëüµÇ¾ú´Â°¡?
- ·Î±×ÀÎ: ·çÆ® ·Î±×ÀÎÀº ÄַܼΠÁ¦ÇѵǾú´Â°¡ (/etc/ttytab ¶Ç´Â /etc/default/login)?
- BSD ½Ã½ºÅÛ¿¡¼ÀÇ SU: wheel ±×·ìÀ» »ç¿ëÇØ¼ root·Î su ÇÒ ¼ö ÀÖ´Â »ç¶÷ Á¦ÇÑ?
- NFS Ŭ¶óÀ̾ðÆ®: »ç¿ë°¡´ÉÇѰ¡? ÆÄÀϽýºÅÛµéÀº ¹ÏÀ»¸¸ÇÑ ½Ã½ºÅÛÀ¸·ÎºÎÅÍ ¸¶¿îÆ®µÇ´Â°¡? ¸¶¿îÆ®µÉ ¶§ SUID´Â disable µÇ´Â°¡?
- NFS ¼¹ö: »ç¿ë°¡´ÉÇѰ¡? rw, root ¿É¼Ç È®ÀÎ? ¾î¶² È£½ºÆ®µéÀÌ Á¢±ÙÇÒ ¼ö Àִ°¡? È£½ºÆ® ¸ñ·Ï¿¡ Àִ°¡? ¹ÏÀ»¸¸ÇѰ¡? Secure NFS ¸¦ »ç¿ëÇϴ°¡?
- X11: xauth ³ª xhosts °¡ »ç¿ëµÇ´Â°¡? "xhosts +" °¡ »ç¿ëµÇ´Â°¡? ´ÙÁß »ç¿ëÀÚ ½Ã½ºÅÛ¿¡¼ xhosts °¡ »ç¿ëµÇ´Â°¡?
- ½Å·ÚµÇ´Â È£½ºÆ® (´Ù¸¥ ¾î¶² ½Ã½ºÅÛµéÀÌ ÀÌ È£½ºÆ®¿¡ Á÷Á¢ Á¢¼ÓÇϴ°¡?): hosts.equiv, hosts.lpd, .rhosts, .shosts. ¾î¶² °èÁ¤µé¿¡ ´ëÇØ ¾î¶² È£½ºÆ®µéÀÌ Á¢±ÙÀÌ Çã¿ëµÇ´Â°¡? (¹«È¿ÇÑ) ÁÖ¼®À̳ª "+" °¡ »ç¿ëµÇ´Â°¡? °ø°Ý¿¡ ´ëÇÑ ÀúÇ×À» ´Ã¸®±â À§ÇØ tcp wrappers³ª ´Ù¸¥ ¸ÞÄ«´ÏÁòÀÌ »ç¿ëµÇ´Â°¡?
- EEPROM: ÆÐ½º¿öµå ÅëÁ¦? Solars1: ÄÜ¼Ö Á¢±ÙÀÌ °¡´ÉÇÏ´Ù¸é ÆÐ½º¿öµå¸¦ ÀüÇô ¸ô¶óµµ ½Ã½ºÅÛÀº ´ÜÀÏ »ç¿ëÀÚ ¸ðµå¿¡¼ ¿ÏÀüÈ÷ À籸¼ºµÉ ¼ö ÀÖ´Ù. ÆÐ½º¿öµå°¡ »ç¿ëµÈ´Ù¸é Á¾ÀÌ¿¡ ½á¼ ¾ÈÀüÇÑ Àå¼Ò¿¡ º¸°üµÇ¾î Àִ°¡?
- ¹°¸®Àû Á¢±Ù: ½Ã½ºÅÛÀÌ °³¹æµÈ Àå¼Ò¿¡ Àִ°¡ º¸È£±¸¿ª¿¡ Àִ°¡? µé¾î°¡°í ³ª°¡´Â »ç¶÷µéÀ» ÃßÀû°¨»çÇϴ°¡? ¸í¹éÇÑ Ãë¾àÁ¡ÀÌ Çϳª¶óµµ Àִ°¡?
- Cron/at: ¾î¶² »ç¿ëÀÚµéÀÌ ÀÌ ÇÁ·Î±×·¥µéÀ» »ç¿ëÇÒ ¼ö Àִ°¡ (cron.deny/at.deny)? cron ÆÄÀÏ »ç¿ëÇã°¡/¼ÒÀ¯±ÇÀº ¿Ã¹Ù¸¥°¡?
- PATH: ·çÆ®³ª ´Ù¸¥ °ü¸®ÀÚÀÇ ¸í·ÉÇà °æ·Î(path)¿¡ Á¡ (".") ÀÌ Àִ°¡? À̰ÍÀº Æ®·ÎÀ̸ñ¸¶¸¦ ½±°Ô ¸¸µç´Ù.
- ÆÄÀÏ »ç¿ëÇã°¡:
- »ç¿ëÀÚ "dot" ÆÄÀÏ.
- SUID ÆÄÀÏÀÇ ¸ñ·ÏÀ» ¸¸µç´Ù:
ncheck -s /dev/DISK_DEV_NAME (Solaris 2 ¸¸)
find / -type f \( -perm -004000 -o -perm 002000 \) -exec ls -alg {} \;
- »ç¿ëÀÚÀ̸§À̳ª ±×·ìÀÌ ¾ø´Â ÆÄÀÏÀ» ã´Â´Ù:
find / -nouser -o -nogroup -print
- ¸ðµç »ç¿ëÀÚ°¡ ¾²±â °¡´ÉÇÑ ÆÄÀÏ & µð·ºÅ丮ÀÇ ¸ñ·ÏÀ» ¸¸µç´Ù. µð·ºÅ丮¿¡ sticky ºñÆ®°¡ ¼³Á¤µÇ¾î Àִ°¡ (e.g. chmod 1777 /tmp)?
find / -type f -perm -22 -exec ls -l {} \;
find / -type d -perm -22 -exec ls -ld {} \;
- Àâ´ÙÇÑ ÆÄÀÏ »ç¿ëÇã°¡µéÀ» ¾ö°ÝÇÏ°Ô Á˾îÁØ´Ù. ´ÙÀ½ ÆÄÀϵéÀÌ ¸í½ÃµÈ´ë·Î µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù:
| /tmp /var/tmp |
1777 |
| /bin/chsh |
700 (Solaris 1) ·çÆ®¸¸ ½ÇÇà °¡´ÉÇÏ°Ô ÇÑ´Ù. |
| /etc/utmp |
644 (Solaris 1) |
| /var/adm/utmp |
644 (Solaris 2) |
| /etc/sm /etc/sm.bak |
2755 (Solaris 1) |
| /etc/state /etc/mtab |
644 (Solaris 1) |
| /etc/motd /etc/syslog.pid |
644 |
| /usr/kvm/crash |
0755 (no GUID) |
| /vmunix |
644, Owner=root, Group=wheel (Solaris 1) |
| /etc /usr/etc /usr/ucb /usr/bin /tmp |
Owner=root (Solaris1). È®Àοä¸Á: º¸Åë ÀÌ µð·ºÅ丮µéÀº bin ¿¡ ¼ÓÇÔ. |
| /etc /sbin /tmp |
Owner=sys (Solaris 2) |
| /bin /usr/bin /usr/ucb |
Owner=bin (Solaris 2) |
°¨»ç / ·Î±ë
- ¾î¶² ·Î±ëÀÌ ¼öÇàµÇ´Â°¡ (C2, Syslog, Sulog, loginlog, cron log, accounting, /etc/utmp, utmpx, wtmp, wtmpx, lastlog , SAR ·Î±×, NIS+ Æ®·£Àè¼Ç ·Î±×, ...).
- syslog ¸Þ½ÃÁöµéÀÌ Æ¯¼öÇÏ°Ô ±¸¼ºµÈ ¼¹ö·Î ÁýÁߵǴ°¡? ¸ðµç ¿ì¼±¼øÀ§/¼ºñ½º°¡ ·Î±×µÇ´Â°¡?
- ·Î±×ÆÄÀÏÀº º¸È£µÇ´Â°¡ (ÆÄÀÏ »ç¿ëÇã°¡)?
- À̵éÀº ÀÚµ¿ÀûÀ¸·Î °¡ÁöÄ¡±â (ºÒÇÊ¿äÇÑ »çÇ× Á¦°Å) / ¾ÐÃàµÇ´Â°¡? ¾ó¸¶³ª ÀÚÁÖ?
- À̵éÀº ÀÚµ¿ÀûÀ¸·Î ºÐ¼®µÇ°í (¾ó¸¶³ª ÀÚÁÖ, ¾îµð¿¡¼) °æ°í°¡ ¹ß»ýµÇ´Â°¡?
¿©·¯°¡Áö
- Sendmail: ¸ÞÀÏ ¼¹ö¸¦ Á¦¿ÜÇÑ ¸ðµç Ŭ¶óÀÌ¾ðÆ®¿¡¼ ³»·ÁÁ® Àִ°¡? ¸ÞÀϼ¹öµéÀº ÃÖ½ÅÀÇ sendmail ÆÐÄ¡·Î ¾÷µ¥ÀÌÆ® µÇ¾î Àִ°¡?
- ¸ðµç ±ÇÀå ÆÐÄ¡°¡ ¼³Ä¡µÇ¾î Àִ°¡ (ƯÈ÷ º¸¾È)?
- ¾î¶² º¸¾È °Ë»ç±âµç ÁÖ±âÀûÀ¸·Î ½ÇÇàµÇ´Â °ÍÀÌ Àִ°¡? (e.g. Satan, COPS, Tripwire, ESM, ASET, SecureMax...) ¾ó¸¶³ª ÀÚÁÖ? °á°ú´Â ¾îµð¿¡ Àִ°¡/
- etherfind/snoop Àº »èÁ¦µÇ¾ú°Å³ª / ·çÆ®¸¸ ½ÇÇà°¡´ÉÇѰ¡/?
- ÇöÀç ¿·ÁÀÖ´Â ³×Æ®¿÷ ¿¬°áÀ» º»´Ù (netstat -a), ÀÌ»óÇØ º¸ÀÌ´Â °ÍÀÌ Àִ°¡?
- DNS °¡ ¿î¿µµÇ°í Àִ°¡? Àû¾îµµ µÎ ´ëÀÇ ¼¹ö°¡ Àִ°¡? ¹ÏÀ»¸¸ÇѰ¡? DNS È£½ºÆ® À̸§ÀÌ Á¢±Ù ÅëÁ¦¿¡ ÀÌ¿ëµÇ´Â°¡?
¼ºñ½º °¡¿ë¼º / ½Å·Ú¼º
- ¹é¾÷ ¹× º¹¿ø Á¤Ã¥ / ¸ÞÄ«´ÏÁò / ÀýÂ÷?
- Áߺ¹¼º: RAID, ¹Ì·¯¸µ, º¹Á¦ (replicas), ºñ»ó´ë±â (hot standby) µîµî?
- /tmp °¡ ·çÆ®¿¡ Àִ°¡? Á¤±âÀûÀ¸·Î ºñ¿öÁö°Å³ª ºÎÆ®½Ã ºñ¿öÁö´Â°¡?
- /var ´Â ·çÆ®¿¡ Àִ°¡? ¸¸¾à ±×·¸´Ù¸é ¸ðµç ·Î±×µéÀÌ ÀÚµ¿ÀûÀ¸·Î °¡ÁöÄ¡±â µÇ¾î, ·çÆ® ÆÄÀϽýºÅÛÀÌ Àý´ë ²Ë Â÷Áö ¾Ê°Ô Çϴ°¡?
- "¼ºñ½º °ÅºÎ" °ø°ÝÀ» ¸·±â À§ÇÑ Æ¯º°ÇÑ ¹æÃ¥ÀÌ Àִ°¡? (e.g. TCP_SYN, ÆÄÀϽýºÅÛ ²ËÂü, »ç¿ëÀÚ ÇÒ´ç·®... µîÀ» °¨½Ã)
µµ±¸
Unischred ('93³â 4¿ù)
Unischred (from LAT) ´Â Çϵåµð½ºÅ©ÀÇ Á¤º¸¸¦ ¿ÏÀüÈ÷ »èÁ¦ÇÏ´Â À¯Æ¿¸®Æ¼ÀÌ´Ù. °¡°ÝÀº $229 Á¤µµÀÌ´Ù. Unischred Pro ´Â ´õ ¸¹Àº ±â´ÉÀ» °¡Áø µÎ¹øÂ° À¯Æ¿¸®Æ¼·Î (¹Ì ÀåºÎ DoD ½ÂÀÎ - ±º»ç Ç¥ÁØ ¸¸Á·) $829 Á¤µµ ÇÑ´Ù.
¿¬¶ôó:
Sales Europe - Simon Goodfellow, simon@sdirect.demon.co.uk
US - Gary Kremen, Los Alto Technologies, gary@lat.com
°¨½Ã µµ±¸
ÀÌ ÀýÀº ²Ï ¿À·¡µÆÀ¸¸ç, º¸´Ù ÃÖ±ÙÀÇ ¸®ºä´Â ¸ÞÄ«´ÏÁò Àå¿¡ ÀÖ´Ù.
OpenVision SecureMax 3.2 (1994³â 12¿ù)
ÀÌ »ó¿ë Á¦Ç°Àº, ¿ø·¡ VAX ¼¼°è¿¡¼ ¾²´Â °ÍÀε¥, ³×Æ®¿÷À» ÅëÇØ ¿©·¯ ´ëÀÇ ½Ã½ºÅÛÀ» °¨½ÃÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. Solaris 1.1 °ú Solaris 2.3, 2.4 ¿¡¼ »ç¿ë.
¿¬¶ôó: Openvision, Wiesbaden, Germany
ÀåÁ¡:
* ½Å·Ú¼º: ÀûÀº ¼öÀÇ ½Ã½ºÅÛ¿¡ ´ëÇØ ²Ï Àß µ¿ÀÛÇÑ´Ù (10 ´ë Á¤µµ).
* ¼öÁ¤ ½ºÅ©¸³Æ®µµ »ý¼ºÇÒ ¼ö ÀÖ´Ù.
* ¸í·ÉÇà°ú GUI ÀÎÅÍÆäÀ̽º.
´ÜÁ¡:
* Áö³ 2³â°£ ¹ßÀüÀÌ ¾ø¾ú´Ù.
* 10 Ŭ¶óÀÌ¾ðÆ®°¡ ³ÑÀ¸¸é ¾ÈÁ¤¼º ¹®Á¦°¡ ÀÖ´Ù.
* °èÃþÀû °ü¸®±¸Á¶°¡ ¾Æ´Ï´Ù (°¢ Ŭ¶óÀÌ¾ðÆ®°¡ ÇϳªÀÇ Äָܼ¸ °¡Áü).
* ÄܼÖÀÌ ²Ï ºñ½Î´Ù (´ë·« 4000.- CHF).
* ¿Ü±¹¾î »çÀüÀÌ ¾ø´Ù.
* ½ºÀ§½º¿¡ Áö¿ª»ç¹«¼Ò°¡ ¾ø´ë --;(°¡Àå °¡±î¿î °÷ÀÌ Wiesbaden, D).
* »õ·Î¿î OS ¹öÀü (e.g. Solaris 2.4 --;;) À» À§ÇÑ ÅÛÇø´ÀÌ ´Ê°Ô ³ª¿Â´Ù.
Raxco ESM 4.0 (1995³â 3¿ù)
ESMÀº »ó¿ëÁ¦Ç°À¸·Î, ÃßÈÄ ±â¾÷ Àü¹Ý¿¡ °ÉÄ£ À¯´Ð½º º¸¾È °ü¸®Àڷμ ¸¹Àº °¡´É¼ºÀ» º¸¿©ÁÖ°í ÀÖ´Ù. Solaris 2.4 ¿¡¼ Å×½ºÆ®ÇÏ¿´´Ù. ¾Ë·ÁÁø ¹®Á¦Á¡À» º¸¿ÏÇÏ´Â »õ·Î¿î ¹öÀüÀÌ 1995³â ¸»¿¡ ³ª¿Ã °Í °°¾Ò´Ü´Ù.
ÀåÁ¡:
* SecureMax º¸´Ù º¸¾È ¹®Á¦¸¦ ´õ ¸¹ÀÌ Å½ÁöÇÒ ¼ö ÀÖ´Ù.
* ¸Å¿ì À¯¿¬ÇÏ´Ù (°èÃþÀû ±¸Á¶, Á¤Ã¥ÀÌ »ç¾÷±¸Á¶¸¦ ¹Ý¿µÇÒ ¼ö ÀÖÀ½).
* GUI »ç¿ëÀÌ ½±´Ù.
* ºü¸£´Ù (only differences are reported between agent and console).
* ½ºÀ§½º¿¡ Áö¿ª»ç¹«¼Ò°¡ Àִٴ±º.
* ´Ù¾çÇÑ Ç÷§ÆûÀ» Áö¿øÇÑ´Ù.
* ÇöÀç ¹öÀüÀº ÀÏȸ¼º ½Ã½ºÅÛ °¨»ç ¼öÇà¿¡ Àû±Ø ÃßõµÈ´Ù.
´ÜÁ¡:
* ÀÚµ¿È°¡ ¾î·Æ´Ù - °ü¸®ÀÚÀÇ ½Ã°£ÀÌ ³Ê¹« ¸¹ÀÌ ¼ÒºñµÈ´Ù (»õ ¹öÀü 4.1¿¡¼´Â °³¼±µÇ¾î¾ß ÇÑ´Ù).
* Solaris 2 ¹öÀüÀº package Çü½ÄÀÌ ¾Æ´Ï´Ù.
* ¸í·ÉÇà ÀÎÅÍÆäÀ̽º°¡ ¾ø°í, Á¦°Å ½ºÅ©¸³Æ®µµ ¾ø°í, ¿Ü±¹¾î »çÀü ¹× ¸Å´º¾ó ÆäÀÌÁöµµ ¾ø´Ù.
* ¸Å¿ì ¿ø½ÃÀûÀÎ ½ºÄÉÁì·¯, ÆÄÀÌÇÁ·Î Ãâ·Â ºÒ°¡, ÆíÁý ºÒ°¡, º¸°í¼ À̸ÞÀÏ ºÒ°¡.
* ÀÏ´ÜÀÇ Å¬¶óÀÌ¾ðÆ®µé¿¡ ´ëÇÑ "¾÷µ¥ÀÌÆ®" ºÒ°¡´É.
* Ŭ¶óÀÌ¾ðÆ® ÀÚµ¿¼³Ä¡ ºÒ°¡´É.
* ÀÛ°í ºÒ¿ÏÀüÇÑ ¹®¼.
* Raxco ´Â ÇÒ ¼ö ÀÖ´Â °Íº¸´Ù ¸¹Àº °ÍÀ» ¾à¼ÓÇÑ´Ù!
¿¬¶ôó: www.raxco.com
Solaris 2: ASET
- Solaris 2.x ¿¡ Ç¥ÁØÀ¸·Î Æ÷ÇԵǾî ÀÖ´Â ASET (Automated Security Enhancement Tool) Àº ½Ã½ºÅÛ ÆÄÀϵ鿡 ´ëÇÑ º¯°æÀ» °¨½ÃÇÑ´Ù (man aset ÂüÁ¶).
ASET Àº ¿ø·¡ Solaris 1À» À§ÇÑ C2 kit ÀÇ ÀϺηΠ°³¹ßµÇ¾ú´Ù.
- GUI °¡ ¾ø¾î (¸í·ÉÇุ ÀÖÀ½), óÀ½¿£ »ç¿ëÇϱâ Èûµé´Ù.
- ±×·¯³ª, SecureMax³ª ESM ÀÌ ¾øÀ» ¶§´Â ÀÌÀÇ »ç¿ëÀ» ±ÇÀåÇÑ´Ù.
Áß¾Ó °ü¸® µµ±¸
À¯´Ð½º ½Ã½ºÅÛµéÀÇ À̱âÁ¾ ³×Æ®¿÷À» À§ÇÑ, µÎ°¡Áö Áß¿äÇÑ Áß¾Ó ÁýÁᫎ ±ÔÄ¢ ±â¹Ý (rule based) °ü¸® µµ±¸´Â Tivoli ¿Í CA-Unicenter ÀÌ´Ù. ÀúÀÚ´Â ¾Æ¹«°Íµµ ¾È½áºÃÁö¸¸, À̵éÀº Ãë¾àÁ¡ÀÌ ÀÖ´Â °É·Î ¾Ë·ÁÁ® ÀÖ´Ù (1994).
AIX ¿¡ ´ëÇØ, IBM Àº ±âº»ÀûÀÎ ½Ã½ºÅÛ °ü¸®¸¦ À§ÇÑ SMIT ¿Í ºÐ»ê(distributed) SMIT À» Á¦°øÇÑ´Ù. ±×·¯³ª, À̵éÀº ¸í·ÉÇà¿¡ ´ëÇÑ ¿ä±¸¸¦ Àذí ÀÖ´Ù. SMIT Àº ¾î¶² Á¶ÀÛÀ» ¼öÇàÇϱâ À§ÇØ ¾î¶² ¸í·É¾îµéÀ» ½ÇÇàÇÏ·Á°í ÇÏ´ÂÁö¸¦ º¸¿©Áֱ⠶§¹®¿¡ AIX¸¦ ¹è¿ì´Âµ¥ ÁÁ´Ù. SMIT ÀÇ curses based Å͹̳Π¹öÀüµµ ÀÖ´Ù (smitty ¶ó´Â). IBMÀÇ ÄªÂùÇÒ¸¸ÇÑ ³ë·ÂÀÌ´Ù!
ÀÏȸ¼º °¨»ç µµ±¸
Åë»óÀûÀÎ ½Ã½ºÅÛ °¨½Ã (º¸Åë ½Ã½ºÅÛ °ü¸®ÀÚ¿¡ ÀÇÇÑ) ¿¡ ´õÇÏ¿©, ÀÏȸ¼º ½Ã½ºÅÛ °¨»ç°¡ ¼öÇàµÇ¾î¾ß ÇÑ´Ù (e.g. Àϳ⿡ Çѹø). ÀÌ °¨»ç´Â µ¶ÀÚÀûÀÎ °¨»çÀÚ¿¡ ÀÇÇØ ¼öÇàµÇ¾î¾ß ÇÑ´Ù (°ü¸®ÀÚ°¡ ¾Æ´Ñ). ´ÙÀ½Àº ±×·¯ÇÑ °¨»ç µµ±¸ÀÇ °ßº»µéÀÌ´Ù.
Satan 1.1
Satan Àº ³×Æ®¿÷ »óÀÇ ¸¹Àº È£½ºÆ®µé¿¡ ´ëÇØ ³×Æ®¿÷ ¼ÒÇÁÆ®¿þ¾îÀÇ Ãë¾àÁ¡À» ½ºÄµÇÒ ¼ö ÀÖ°Ô ÇØÁÖ´Â °ø°³ µµ¸ÞÀÎ ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù (Perl °ú WWW ºê¶ó¿ìÀú ±â¹Ý).
¾Ë·ÁÁø ¸ðµç Ãë¾àÁ¡À» Å×½ºÆ®ÇÏ´Â °ÍÀº ¾Æ´ÏÁö¸¸, »ç¿ëÇϱ⠽±°í ¼ºê³Ý Àüü¿¡ Àִ ȣ½ºÆ®µéÀ» ½ºÄµÇÒ ¼ö ÀÖ´Ù. ³Ý½ºÄÉÀÌÇÁ¿Í °°Àº html ºê¶ó¿ìÀú ±â¹ÝÀÇ ±×·¡ÇÈ »ç¿ëÀÚ ÀÎÅÍÆäÀ̽º·Î »ç¿ë°ú È®ÀåÀÌ ½±´Ù. Links CERT ±Ç°í¹® µîÀ» ¿¬°áÇÏ¿© º¸¾È °ü¸®Àڵ鿡°Ô Èï¹Ì·Ó´Ù. Àû±Ø Ãßõ.
SatanÀº ´ÙÀ½ º¸¾È Ãë¾àÁ¡µéÀ» Å×½ºÆ®ÇÑ´Ù:
- NFS ÆÄÀϽýºÅÛµéÀÌ unprivileged ÇÁ·Î±×·¥¿¡, ÀÓÀÇÀÇ È£½ºÆ®¿¡, ¶Ç´Â portmapper¸¦ ÅëÇØ export µÇ¾î Àִ°¡?
- ÀÓÀÇÀÇ È£½ºÆ®·ÎºÎÅÍ NIS ÆÐ½º¿öµå ÆÄÀÏ Á¢±ÙÀ̳ª rexd ¶Ç´Â rsh Á¢±ÙÀÌ °¡´ÉÇѰ¡?
- tftp¸¦ ÅëÇÑ ÀÓÀÇÀÇ ÆÄÀÏ Á¢±ÙÀÌ °¡´ÉÇÑ´Ù?
- X ¼¹ö Á¢±ÙÅëÁ¦°¡ disable µÇ¾î Àִ°¡?
- ¾²±â °¡´ÉÇÑ anonymous ftp µð·ºÅ丮°¡ Àִ°¡?
- ¾ÈÀüÇÏÁö ¸øÇÑ sendmail À̳ª wu-ftpd ¹öÀüÀ» »ç¿ëÁßÀΰ¡?
±Ç°í»çÇ×:
- Àý´ë ½Ã½ºÅÛ °ü¸®ÀÚ¿Í ÇïÇÁµ¥½ºÅ©¿¡°Ô Å뺸 ¾øÀÌ ³×Æ®¿÷¿¡¼ Satan À» »ç¿ëÇÏÁö ¾Ê´Â´Ù.
- Satan Àº »ç¿ëÀÚ³ª ÀÏÂ÷ Áö¿øÀηÂÀÌ ÀϹÝÀûÀ¸·Î »ç¿ëÇÒ ¼ö À־ ¾ÈµÈ´Ù.
- Satan Àº ÀÎÅͳݻ󿡼 "Àß ¾Ë·ÁÁ®" Àֱ⠶§¹®¿¡, ÀÎÅͳݿ¡ ³ëÃâµÈ ¸ðµç ½Ã½ºÅÛµéÀº Á¤±âÀûÀ¸·Î ½ºÄµµÇ¾î¾ß ÇÑ´Ù.
- ³»ºÎÀÇ ¹Î°¨ÇÑ ½Ã½ºÅ۵鵵 º¸¾ÈÁ÷¿ø¿¡ ÀÇÇØ Á¤±âÀûÀ¸·Î ½ºÄµµÇ¾î¾ß ÇÑ´Ù.
- 1.0 Àº º¸¾È ¹ö±×°¡ ÀÖÀ¸´Ï »ç¿ëÇÏÁö ¾Êµµ·Ï ÇÑ´Ù. ´ë½Å V1.1À» »ç¿ëÇÑ´Ù.
- WWW ºê¶ó¿ìÀú¸¦ »ç¿ëÇÏ¿© Satan °ú ÀÎÅÍ³Ý ºê¶ó¿ì¡À» µ¿½Ã¿¡ ÇÏÁö ¾Ê´Â´Ù.
- ´©°¡ ´ç½ÅÀÇ ¼¹ö¸¦ ½ºÄ³´×ÇÏ´Â °æ¿ì Áï½Ã °ü¸®ÀÚ¿¡°Ô ÅëÁöÇÒ ¼ö ÀÖµµ·Ï "Satan detector" ¸¦ ¼³Ä¡ÇÑ´Ù!
ºÎ·Ï D¿¡ ÀÖ´Â ¿¹Á¦µéÀ» º»´Ù.
- Satan Àº È®ÀåÇϱ⠽±°Ô ¼³°èµÇ¾úÀ¸¸ç, ´Ù¸¥ ¾Ë·ÁÁø Ãë¾àÁ¡À» ´Ù·ç°í ´Ù¸¥ ¾ÆÅ°ÅØÃĵéÀ» ÀνÄÇÏ°í ¿î¿µÃ¼Á¦¸¦ ¹öÀü¿¡ µû¶ó ³ª¿Çϵµ·Ï È®ÀåÇϸé ÁÁÀ» °ÍÀÌ´Ù.
¹°·Ð, ±×·± ÀÏÀ» À§Çؼ´Â ¾î¶² ȸ»ç³ª ´ëÇÐÀÇ ÈÄ¿øÀ» ¹Þ¾Æ¾ß°ÚÁö¸¸, ±×·²¸¸ÇÑ °¡Ä¡°¡ ÀÖÀ» °ÍÀÌ´Ù.
Merlin
Merlin Àº Tiger, COPS, tripwire µîµî°ú °°Àº º¸¾È °Ë»ç µµ±¸¿¡ ¾²±â ±¦ÂúÀº HTML ÇÁ·ÐÆ® ¿£µåÀÌ´Ù.
ÀÌ Á¦Ç°µéÀ» óÀ½ »ç¿ëÇÒ ¶§´Â À¯¿ëÇÏÁö¸¸ (¹è¿ì°í ¾²±â ½±´Ù), À¯Æ¿¸®Æ¼ÀÇ »ó¼¼ ±¸¼ºÀ» ÇÒ ¼ö ¾ø´Ù.
ISS (Internet Security Scanner): 1995³â 12¿ù
Internet Security Scanner ´Â "Satan °°Àº" ³×Æ®¿÷ ½ºÄ³³ÊÀÌ´Ù. °ø°³ µµ¸ÞÀΰú »ó¿ë ¹öÀüÀÌ ÀÖ´Ù. ÇÊÀÚ´Â °ø°³µµ¸ÞÀÎÀ» ÄÄÆÄÀÏÇÒ ¼ö°¡ ¾ø¾ú°í, »ó¿ë¹öÀüÀº ²Ï ºñ½Î¸ç ($4000.- Àåºñ 100 °³ °Ë»çÇϴµ¥) Æò°¡ÆÇÀº ÇϳªÀÇ ½Ã½ºÅÛ¿¡¼¸¸ µ¿ÀÛÇÑ´Ù. SunOS4.x, Solaris 2.3, HP-UX ¹× AIX 3.2 ¿¡ ´ëÇÑ Áö¿øÀÌ Á¦ÇÑÀûÀÌ´Ù.
TAMU tiger (1995³â 12¿ù)
ÅØ»ç½º ´ëÇÐÀÇ Tiger ½ºÅ©¸³Æ®´Â, ½Ã½ºÅÛÀ» ½ºÄµÇÏ¿© °¡´ÉÇÑ º¸¾È ¹®Á¦Á¡µéÀ» º¸°íÇÑ´Ù. ÀÌ À¯Æ¿¸®Æ¼´Â ¾ÆÁÖ »ó¼¼ÇÑ ºÎºÐ±îÁö °¡´ÉÇÏÁö¸¸, ³Ê¹« »ó¼¼Çؼ ÀÚµ¿ÈÇÏ·Á¸é ¾öû³ ³ë·ÂÀÌ ÇÊ¿äÇØ, "ÀϹÝÀûÀ¸·Î" ±ú²ýÇÑ ½Ã½ºÅÛ¿¡¼´Â °á°ú¹°ÀÌ ¾ø´Ù. ¾ÆÁ÷±îÁö Å×½ºÆ®µÈ ¾î¶² »ó¿ëÁ¦Ç°µéº¸´Ùµµ ¸¹Àº ȦµéÀ» ã¾Æ³½´Ù. ±³Á¤ ½ºÅ©¸³Æ®´Â »ý¼ºµÇÁö ¾ÊÀ¸¸ç, µû¶ó¼ ¹®Á¦ÀÇ ±³Á¤Àº ¼öÀÛ¾÷À¸·Î ÇØ¾ßÇÏ°í ½Ã°£ÀÌ ¸¹ÀÌ °É¸°´Ù. Solaris 1.x ¿Í 2.x ´Â Àß Áö¿øµÇÁö¸¸, AIX , OSF ¹× HP-UX. ¿¡¼ ¾ó¸¶³ª Àß µ¿ÀÛÇÏ´ÂÁö´Â ¹ÌÁö¼ö´Ù.
- ±Ç°í: SecureMax ³ª ESM °°Àº »ó¿ë À¯Æ¿¸®Æ¼°¡ ¾øÀ» ¶§ °¨»çµµ±¸·Î »ç¿ëÇÑ´Ù.
Ç¥ÁØ À¯Æ¿¸®Æ¼
| last |
¸¶Áö¸· ·Î±×ÀÎ/½Ã½ºÅÛÁ¾·á¸¦ º¸¿©ÁÜ. |
| showmount -e |
NFS exported µð·ºÅ丮 È®ÀÎ |
| showmount -a |
¾î¶² NFS exported µð·ºÅ丮¸¦ ´©°¡ ¸¶¿îÆ®Çϰí ÀÖ´ÂÁö º¸¿©ÁÜ. |
| netstat -r |
¶ó¿ìÆÃ Å×À̺í È®ÀÎ. |
| nfsstat -s |
³ôÀº NFS ¿¡·¯ Ä«¿îÆ®¸¦ È®ÀÎ (À§Á¶µÈ ÆÐŶÀÏ ¼ö ÀÖÀ½). |
| vmstat 5 5 |
°¡»ó ¸Þ¸ð¸® Åë°è¸¦ 5Ãʸ¶´Ù È®ÀÎ. -s ¿É¼ÇÀº ¿ä¾à. |
| pstat -s |
(Solaris 1.x): VM Åë°è. |
| pstat -T |
(Solaris 1.x): »ç¿ëµÈ/³²¾ÆÀÖ´Â Ä¿³Î Å×À̺íÀ» º¸¿©ÁÜ. |
| swap -l |
(Solaris 2.x): ½º¿Ò ÆÄÀÏ & VM Åë°è ³ª¿. |
| iostat 5 5 |
I/O Åë°è. |
| tunefs -m 5 DEVICE |
ÆÄÀϽýºÅÛ Æ¯¼º minfree ¼öÁ¤ (¼º´É ÃÖÀûȸ¦ À§ÇØ ³²°Ü µÐ °ø°£, º¸Åë 10%). ¸ÕÀú FS ¸¦ ³»·Á¾ß(unmount) ÇÔ . |
| snoop |
(Solaris 2.x): ³×Æ®¿÷ Æ®·¡ÇÈ °¨½Ã. º¸¾ÈÁ÷¿ø¸¸ »ç¿ë! |
| etherfind |
(Solaris 1.x): ³×Æ®¿÷ Æ®·¡ÇÈ °¨½Ã. º¸¾ÈÁ÷¿ø¸¸ »ç¿ë! |
| ifconfig -a |
(Sun): ³×Æ®¿÷ ÀåÄ¡ ±¸¼ºÀ» Ç¥½Ã. e.g. le0 °¡ promiscuous ¸ðµå·Î µÇ¾î ÀÖ´ÂÁö È®ÀÎ. |
| sar |
(Solaris 2.x): Á¤±âÀûÀÎ ¼º´É Åë°è ¼öÁý. CPU: -u ¿É¼Ç. ÆäÀÌ¡: -g ¿É¼ÇÀº page-out ±×¸®°í -p ¿É¼ÇÀº page-in Åë°è.
½º¿ÍÇÎ: ¹°¸®ÀûÀ¸·Î 512 ¹ÙÀÌÆ® ºí·ÏÀÇ °³¼ö¸¦ º¸°í ½º¿ÒµÈ ¸Þ¸ð¸® -r ¿É¼Ç »ç¿ë. |
À¯´Ð½º º¸¾È µµ±¸ - °ø°³µµ¸ÞÀÎ
´ëºÎºÐÀÇ À¯´Ð½º º¸¾Èµµ±¸µéÀº °ø°³µµ¸ÞÀο¡ ÀÖ´Ù. ´õ »ó¼¼ÇÑ »çÇ׵鿡 °ü½ÉÀÖ´Â »ç¶÷µéÀº Åë»óÀûÀÎ °Ë»ö¿£ÁøÀ¸·Î ´õÀÌ»ó ãÀ» ¼ö ¾ø´Â °æ¿ì ÀúÀÛÀÚ¿¡°Ô ¿¬¶ôÇÒ ¼ö ÀÖ´Ù.
Perl
- Perl Àº sh,csh,sed,awk,tr ÀÇ ±â´ÉÀ» ÅëÇÕÇÏ°í Æ¯Á¤ Ç¥ÁØ ¶óÀ̺귯¸® CÇÔ¼ö¿¡ ´ëÇÑ Á÷Á¢ Á¢±ÙÀ» Á¦°øÇÑ´Ù (e.g. ¼ÒÄÏ È£Ãâ, IPC, ÆÐ½º¿öµå & È£½ºÆ® Å×À̺í Á¶ÀÛ...). ÇöÀç ¹öÀüÀº 5. Perl Àº ƯÁ¤ º¸¾È ±â´ÉÀ» ±¸ÇöÇÏ´Â ½ºÅ©¸³Æ®¸¦ ÀÛ¼ºÇÏ´Â µ¥ ¾²ÀÏ ¼ö ÀÖ´Ù, e.g. Satan ½ºÄµ¿¡ ´ëÇØ ½Ã½ºÅÛÀ» °¨½Ã, ½Ã½ºÅÛÀÇ .rhosts, hosts.equiv ÆÄÀÏ °¨½Ã ¹× Á¤Ã¥¿¡ À§¹ÝµÇ´Â °Í »èÁ¦.
- °¡´ÉÇÑÇÑ PerlÀ» Ç¥ÁØ ½ºÅ©¸³Æ® ¾ð¾î·Î »ç¿ëÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. Perl Àº ´ëºÎºÐÀÇ À¯´Ð½º ½Ã½ºÅÛ°ú VMS, NT, OS2 µîµî¿¡¼ µ¿ÀÛÇÑ´Ù.
¿©·¯°¡Áö ±¦ÂúÀº °Íµé (Á» ¿À·¡µÈ....)
- Top Àº Ȱ¼º ÇÁ·Î¼¼½ºµé, ¸Þ¸ð¸® »ç¿ëµîÀ» °¨½ÃÇÏ´Â À¯Æ¿¸®Æ¼ÀÌ´Ù. Ãßõ.
- Contool: Àº Sun¿ë ÀбâÀü¿ë ÄַܼÎ, ¼Ò¸® °æº¸¿Í Ãß°¡ ·Î±ëÀ» Á¦°øÇÑ´Ù. syslog ÄÜ¼Ö ½Ã½ºÅÛ¿¡ À¯¿ëÇÏ´Ù.Ãßõ.
- Nfswatch: Solaris 1&2 ¿¡¼, NFS °¡ ½Ç½Ã°£À¸·Î °¨½ÃµÉ ¼ö ÀÖ´Ù. Solaris2¿¡¼ Ãßõ.
- Ofiles ¿Í lsof (Ãßõ) Àº ¿·ÁÀÖ´Â ¸ðµç ÆÄÀϵé, ÀåÄ¡ ¹× ¼ºñ½ºµéÀ» º¸¿©ÁØ´Ù.
- monitor_processes.pl Àº ÀúÀÚ°¡ ¸¸µç ½ºÅ©¸³Æ®·Î ƯÁ¤ÇÑ ÇÁ·Î¼¼½º°¡ ½ÇÇàÁßÀÎÁö¸¦ º¸±â À§ÇÑ °ÍÀÌÀÚ.
¼¹ö¿¡¼ (cronÀ» ÅëÇØ) »ç¿ëµÇ¾î Áß¿äÇÑ µ¥¸óµéÀÌ ¸ðµÎ µ¿ÀÛÁßÀÎÁö È®ÀÎÇÒ ¼ö ÀÖ´Ù.
- monitor_socket.pl (ÀúÀÚ°¡ ÀÛ¼º) Àº Satan À̳ª Sybase °°Àº °ÍÀ¸·ÎºÎÅÍÀÇ ¼ÒÄÏ ¿¬°áÀ» °¨½ÃÇÑ´Ù.
À̰ÍÀº (µ¥¸óÀ¸·Î¼) ·ÎÄà TCP ¼ÒÄÏÀ» listen ÇÏ¿© (¸í·ÉÇà¿¡¼ Á¦°øµÈ ¸ñ·ÏÀ» ÅëÇØ, ¶Ç´Â Sybase µðÆúÆ® 2025 & 2026) $user ¿¡°Ô ¿¬°á »ó¼¼»çÇ×À» À̸ÞÀÏ·Î º¸³½´Ù.
¿¬°áÀÌ Sybase·ÎºÎÅÍ ¿À´Â °Í °°À¸¸é, Sybase ¿¬°á µ¥ÀÌŸ¸¦ ÀÐÀ» ¼ö ÀÖ´Â ÇüÅ·ΠÃâ·ÂÇÑ´Ù. Solaris 1.1, 2.3, 2.4 ¿¡¼ Å×½ºÆ® µÊ.
- Proctool Àº ÇÁ·Î¼¼½ºµéÀ» °¨½ÃÇϰí (Sun¿¡¼), °æ°í¸¦ ¼³Á¤ÇÏ´Â µîµîÀÇ ÀÏÀ» ÇÏ´Â ±×·¡ÇÈ À¯Æ¿¸®Æ¼ÀÌ´Ù.
- Top Àº ÇÁ·Î¼¼½º¸¦ °¨½ÃÇÏ´Â µ¥ ÀÛ°í ¶Ù¾î³ ¸í·ÉÇà À¯Æ¿¸®Æ¼ÀÌ´Ù. Ãßõ.
- Swatch´Â ·Î±×ÆÄÀÏÀ» °¨½ÃÇϰí, ¸ÂÃß¾îÁø ±ÔÄ¢¿¡ µû¶ó Á¶Ä¡¸¦ ÃëÇÑ´Ù (e.g. °ü¸®ÀÚ¿¡°Ô À̸ÞÀÏ ¹ß½Å). Perl·Î ÀÛ¼ºµÊ. Highly customisable.
- Sudo ´Â º¸Åë ·çÆ®°¡ ¼öÇàÇÏ´Â ¾î¶² ÀÛ¾÷µéÀ» ÅëÁ¦µÈ ¹æ½ÄÀ¸·Î À§ÀÓÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.
- Shadow ´Â Solaris 1 ¿¡¼ shadow ÆÐ½º¿öµå ÆÄÀÏ »ç¿ëÀ» °¡´ÉÇÏ°Ô ÇØ º¸¾ÈÀ» Áõ´ë½ÃŲ´Ù.
- Tripwire: Gene Kim °ú Gene Spafford °¡ ¸¸µé¾úÀ¸¸ç, ftp://cert.org/pub/tools/tripwire¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Ù.
½Ã½ºÅÛ¿¡¼ ¾î¶² ÆÄÀÏÀÌ¶óµµ º¯°æµÇ¾ú´ÂÁö È®ÀÎÇÏ´Â µ¥ »ç¿ëµÈ´Ù. ¸Å¿ì Æ÷°ýÀûÀÌ°í ¸¹Àº Ç÷§Æûµé¿¡¼ µ¿ÀÛÇÑ´Ù. Tripwire ´Â ÆÄÀÏ ¼¸íÀ» »ý¼ºÇϱâ À§ÇØ ´Ù¾çÇÑ ´ëÁßÀû ÇØ½¬ ÇÔ¼ö¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Ù(e.g. MD2, MD5, SHS ...). Ãßõ.
- wrapper.c: À̰ÍÀº SUID wrapper ÇÁ·Î±×·¥À¸·Î SUID Á¢±ÙÀÌ ÇÊ¿äÇÑ ½ºÅ©¸³Æ®¿¡ »ç¿ëÇϱâ À§ÇÑ °ÍÀÌ´Ù.
- Ypx ´Â NIS µ¥ÀÌŸº£À̽º¿¡¼ º¸¾È ȦÀ» °Ë»çÇÏ´Â °ø°³µµ¸ÞÀÎ À¯Æ¿¸®Æ¼ÀÌ´Ù.
- smrsh: sendmail À̽´¸¦ À§ÇÑ °ÍÀ¸·Î, "¾îÇø®ÄÉÀÌ¼Ç º¸¾È" ÀåÀÇ "sendmail" ÀýÀ» ÂüÁ¶ÇÑ´Ù.
- COPS Àº tripwire ¿Í ºñ½ÁÇÏÁö¸¸, °èÁ¤, ÀåÄ¡ ¹× Çʼö ÆÄÀϵ鵵 °Ë»çÇÑ´Ù.
- anlpasswd: ¼øÇâÀû(proactive) ÆÐ½º¿öµå °Ë»ç±â·Î, »ç¿ëÀÚ°¡ ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÒ ¶§ ÀÏ·ÃÀÇ °Ë»ç¸¦ ÇÏ¿© Å×½ºÆ®¸¦ Åë°úÇÏÁö ¸øÇÏ´Â ÆÐ½º¿öµå´Â °ÅºÎÇÑ´Ù.
Shadow ÆÐ½º¿öµå ½Ã½ºÅÛ°ú ÇÔ²² µ¿ÀÛÇϵµ·Ï ¼³°èµÇ¾ú´Ù.
ftp://ftp.auscert.org.au/pub/mirror/info.mcs.anl.gov/* ÂüÁ¶.
- Crack: Àº À̵û±Ý¾¿ ÆÐ½º¿öµå ÆÄÀÏÀÇ °µµ¸¦ °Ë»çÇÏ´Â µ¥ ÁÁ´Ù.
ftp.auscert.org.au/pub/cert/tools/crack ÂüÁ¶.
- cpm: ³×Æ®¿÷ ÀÎÅÍÆäÀ̽º°¡ promiscuous ¸ðµå·Î µ¿À۵ǰí ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.
- rscan ¿©·¯°¡Áö ÀϹÝÀûÀÎ IRIX-specific º¸¾È ¹ö±×¿Í ¹®Á¦µé¿¡ ´ëÇØ °Ë»ç. ¿©±â¿¡ ÀÖ´Ù:
ftp.auscert.org.au/pub/mirrors/ftp.vis.colostate.edu/rscan/*
- ftp ¿¡ ´ëÇÑ ¼Ò½ºµéÀº ftp.uu.net:/packages/bsd-sources ¿¡¼ ãÀ» ¼ö ÀÖ´Ù.
- XNTP ¶Ç´Â NTP ´Â ³×Æ®¿÷ ½Ã°£ ÇÁ·ÎÅäÄÝ (Network Time Protocol) À¯Æ¿¸®Æ¼·Î, ½Ã½ºÅÛµéÀÇ ³×Æ®¿÷ÀÌ ´ë´ÜÇÑ Á¤È®¼ºÀ¸·Î ½Ã°£À» Áöų ¼ö ÀÖ°Ô ÇØÁØ´Ù.
Secure NFS ³ª ½Ã°£ ±â¹ÝÀÇ ÀÎÁõ (SecurID °°Àº) ¿¡ À¯¿ëÇÏ´Ù. Solaris 2.6 ÀÌ»ó¿¡ Æ÷ÇԵǾî ÀÖ´Ùftp.udel.edu/pub/ntp/.
- ´Ù¸¥ °Íµé : xtr, sush, shadow, securelib.
[11] ÆÐ½º¿öµå°¡ ½Ã½ºÅ۵鰣¿¡ µ¿±âȵǸé, °¡Àå Ãë¾àÇÑ ½Ã½ºÅÛÀÌ º¸¾È ·¹º§À» °áÁ¤Áþ´Â´Ù.
[12] "Avalon Security Research" ´Â ÀÌ È¦°ú ÇÔ²² À̸¦ ÀÌ¿ëÇÒ ¼ö ÀÖ´Â ½ºÅ©¸³Æ® ("slammer") ¸¦ ÀÎÅͳݿ¡ °ø°³ÇÏ¿´´Ù.('95³â 11¿ù).
[13] ÀúÀÚ¿¡°Ô ÀÚµ¿ÀûÀ¸·Î /etc/.rootkey ¸¦ ¹ß»ý½Ãų ¼ö ÀÖ´Â ½ºÅ©¸³Æ®°¡ ÀÖ´Ù.
[14] À̸¦ À§Çؼ´Â ½ºÅ©¸³Æ®°¡ ÇÊ¿äÇÏ´Ù, Ç¥ÁØ À¯Æ¿¸®Æ¼°¡ ¾ø´Ù.
[15] "Avalon Security Research" ´Â ÀÌ È¦°ú ÇÔ²² À̸¦ ÀÌ¿ëÇÒ ¼ö ÀÖ´Â ½ºÅ©¸³Æ® ("slugger") ¸¦ ÀÎÅͳݿ¡ °ø°³ÇÏ¿´´Ù.('95³â 11¿ù).
[16] ¿¡Á¦ ¸í·É¾îµéÀº Solaris 2.4 ¿ëÀÌ´Ù.
Previous Next
Top Detailed TOC
IT Security Cookbook, 15 July, 2000