|
|
|
¸®´ª½ºÆÁ Go Unix Power Tools Online Book
Go Bash Guide
|
|
Read No. 154 article |
2002-05-11 05:19:13 |
|
|
|
|
|
|
http://mse.korea.ac.kr/~mse/board1/cgi-bin/CrazyWWWBoardLE.cgi?
mode=read&num=24&db=5&backdepth=1
¦£¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¤
¦¢ ¢º ¹ø È£ : 121/177 ¢º µî·ÏÀÚ : LAWWAL ¦¢
¦¢ ¢º µî·ÏÀÏ : 99³â 01¿ù 19ÀÏ 14:32 ¦¢
¦¢ ¢º Á¦ ¸ñ : [TIP] ÇØÅ·À» ¸·¾Æº¾½Ã´Ù. ¦¢
¦¦¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¡¦¥
¾îÁ¦ Á¦ ¼¹ö¿¡ ÇØÅ·ÈçÀûÀÌ ¹ß°ßµÇ¾î ¿ÜºÎ·ÎºÎÅÍÀÇ ¸ðµç ÅÚ·¿ µîÀÇ Á¢¼ÓÀ»
¸·¾Ò´ä´Ï´Ù.
ÇÏÁö¸¸ ¸·´Â°ÍÀ¸·Î´Â Á÷¼ºÀÌ Ç®¸®Áö ¾Ê¾Æ °£´ÜÇÑ ½ºÅ©¸³Æ®À» Á¦ÀÛÇϱ⿡ À̸£·¶ÁÒ.
³»¿ëÀÎ Áï½¼, ¿ÜºÎ¿¡¼ Á¢±ÙÀ» ½ÃµµÇÒ °æ¿ì ƯÁ¤ ¼ºñ½º (telnet, ftp, imap,
finger µî)¸¦ ¿øÃÊÀûÀ¸·Î ¸·´Â ´ë½Å¿¡ Á¢¼Ó½ÃµµÀÚÀÇ Á¢¼ÓÁ¤º¸¸¦ ȸ鿡 º¸¿©ÁÖ°í
(ÀÏÁ¾ÀÇ °æ°í ³»Áö ¾È³»¸ñÀûÀÌ µÇ°ÚÁÒ) ¿î¿µÀÚ¿¡°Õ ¸ÞÀÏ·Î ¼¼ºÎ ³»¿ªÀÌ ¹ß¼ÛµÇµµ·Ï
ÇÏ¿´½À´Ï´Ù.
ÀÌ°ÍÀº tcp_wrapper¿¡ ÀÇÇØ ¼ºñ½º¸¦ Á¦ÇÑÇÏ´Â °ÍÀ¸·Î¼µµ ÀÌ¹Ì º¸¾ÈÀÇ È¿°ú°¡
ÀÖÁö¸¸, ÀϹÝÀûÀ¸·Î ÇØŷŸ°ÙÀ» Á¤ÇÏ¸é ¿©·¯ ¼ºñ½º¸¦ µÚÁö´Ù ±¸¸ÛÀÌ ÀÖ´Â ºÎºÐÀ»
ÆÄ°íµå´Â ÇØÄ¿µéÀÇ ½À¼ºÀ» °í·ÁÇغ¼ ¶§ Çã¿ëµÇÁö ¾Ê´Â ¼ºñ½º¿¡ ÇѹøÀ̶óµµ
Á¢±ÙÀ» ½ÃµµÇÑ °æ¿ì ½Ã°£, ½Ãµµ ¼ºñ½º, ½Ãµµ ¼¹ö ip ¶Ç´Â µµ¸ÞÀÎ, ½Ãµµ ¼¹öÀÇ
finger Á¤º¸ µîÀ» ¿î¿µÀÚ¿¡°Ô ¾Ë·Á »çÀü¿¡ °æ°èÇÒ ¼ö ÀÖµµ·ÏÇϴµ¥ ¸ñÀûÀÌ ÀÖ½À´Ï´Ù.
(¿À´Ã ÀÌ ½ºÅ©¸³Æ®¸¦ Â¥¸é¼ Á¦ ¼¹öÀÇ ·Î±×ÆÄÀÏÀ» ºÐ¼®Çغ¸´Ï±î ÅÚ·¿À¸·Î Á¢±ÙÀ»
½ÃµµÇغ¸°í, ftp, pop, imap, finger µîÀ» Â÷·Ê·Î Á¢±ÙÇغ¸´Â ÇüÅ°¡ ´õ·¯ ´«¿¡
¶ç´õ±º¿ä. ÀÌ´Â ¼¹öÀÇ ±¸¸ÛÀ» ã±â À§Çؼ°ÚÁÒ. --;)
·¹µåÇÞ°ú °°Àº ¹èÆ÷º»¿¡¼´Â tcp_wrapper¸¦ ÀÌ¿ëÇØ inet ½´ÆÛ¼¹ö¸¦ ÅëÇÏ´Â
°¢Á¾ ¼ºñ½º¿¡ ´ëÇØ Á¢±ÙÁ¦ÇÑÀ» µÑ¼ö ÀÖ½À´Ï´Ù.
½Ä»óÇÑ°¨ÀÌ ¾øÁø ¾ÊÁö¸¸ Á¦°¡ ÀÛ¼ºÇÑ ½ºÅ©¸³Æ®À» ÀÌ¿ëÇϱâ À§Çؼ´Â À̺κÐÀÌ
¼±ÇàµÇ¾î¾ß Çϱ⠶§¹®¿¡ °£·«ÇÏ°Ô³ª¸¶ ¼³¸íÇÏ°Ú½À´Ï´Ù.
/etc/hosts.allow <- Á¢¼ÓÀ» Çã¿ëÇÒ Á¶°ÇÀ» ÁöÁ¤ÇÏ´Â ÆÄÀÏ
/etc/hosts.deny <- Á¢¼ÓÀ» °ÅºÎÇÒ Á¶°ÇÀ» ÁöÁ¤ÇÏ´Â ÆÄÀÏ
/etc/hosts.allow
in.telnetd: LOCAL 210.100.100.1
À§ ³»¿ëÀº ÅÚ·¿ Á¢¼Ó¿¡ ÀÖ¾î local°ú 210.100.100.1¸¸À» Çã¿ëÇÑ´Ù´Â °ÍÀÌÁÒ.
/etc/hosts.deny
in.telnetd: ALL:
À§ ³»¿ëÀº ÅÚ·¿ Á¢¼Ó¿¡ ÀÖ¾î ¸ðµç ¼¹ö·ÎºÎÅÍÀÇ Á¢¼ÓÀ» °ÅºÎÇÑ´Ù´Â °ÍÀÌÁÒ.
ÇÏÁö¸¸ À§¿Í °°Àº °æ¿ì hosts.allow°¡ ¿ì¼±Çϱ⠶§¹®¿¡ local, 210.100.100.1 Àº
Á¢¼ÓÀÌ Çã¿ëµÇ°í ±× ¿Ü¿¡´Â ¸ðµÎ °ÅÀýÇÑ´Ù´Â °ÍÀ¸·Î Çؼ®ÇÒ ¼ö ÀÖ°Ú½À´Ï´Ù.
(½ÇÀº Àúµµ ¿¹ÀüºÎÅÍ À§ ³»¿ëÀº ¾Ë°í ÀÖ¾úÁö¸¸ ¿À´Ã óÀ½ Àû¿ëÇѰŶó Ȥ½Ã Ʋ¸±
¼öµµ ÀÖ°ÚÁö¸¸, Àú´Â À§¿Í °°ÀÌ Çߴµ¥ ¿øÇϴ´ë·Î ÀÛµ¿ÇÏ°í ÀÖÁÒ. ^^)
ÀÚ¼¼ÇÑ °ÍÀº man hosts.allow Çغ¸½Ã¸é µË´Ï´Ù.
hosts.deny¿¡´Â hosts.allow¿¡ ¾ø´Â ÇÑ°¡Áö Ư¼öÇÑ ¿É¼ÇÀÌ Àִµ¥,
ÀÌ´Â Á¢¼ÓÀ» °ÅÀýÇÔ°ú µ¿½Ã¿¡ ƯÁ¤ ¸í·ÉÀ» ½ÇÇàÇϵµ·Ï ÁöÁ¤ÇÒ ¼ö ÀÖ´Ù´Â °ÍÀÔ´Ï´Ù.
(ÇöÀç Á¦°¡ ¼³¸íÇÏ°í ÀÖ´Â ¹öÀüÀº ¾ËÂ¥ 5.2 »ðÀÔºÐÀÎ tcp_wrappers-7.6-5ÀÔ´Ï´Ù.
±× ÀÌÀü ¹öÀüÀº Àß ¸ð¸£°Ú½À´Ï´Ù. ½áº¸Áö ¾Ê¾Æ¼... --;)
¶Ç ¸í·É ½ÇÇà ¹æ¹ýµµ ¾à°£ ƯÀÌÇÏ´ä´Ï´Ù.
¾Æ¹«Æ° Á¦ /etc/hosts.deny ÆÄÀÏÀ» º¸¿©µå¸®ÁÒ.(½ÇÁ¦¿Í´Â ¾à°£ Â÷ÀÌ°¡ ÀÖ´ä´Ï´Ù ^^)
------------------------- start
#¼ºñ½º: °ÅºÎÁÖ¼Ò: ½©¸í·É
in.telnetd: ALL: twist ( /etc/hosts.denyck Y Y %a %c %d %h %n %p %s %u ) &
ipop3d: ALL: twist ( /etc/hosts.denyck Y Y %a %c %d %h %n %p %s %u ) &
------------------------- end
¼³¸íÇÏÀÚ¸é ¸ðµç Á¢¼ÓÀ»(À§¿¡¼ ¼³¸íÇßµíÀÌ hosts.allow¿¡¼ ÁöÁ¤ÇÑ°ÍÀ» Á¦¿ÜÇÑ)
°ÅºÎÇϸç, °ÅºÎ½Ã /etc/hosts.denyck ¶ó´Â ½ºÅ©¸³Æ®À» ½ÇÇàÇ϶ó´Â °Ì´Ï´Ù.
±× ¿ìÃø¿¡ Y Y %a %c %d %h %n %p %s %u ¶ó°í µÇ¾î ÀÖ´Â ºÎºÐÀº ½ÇÇàµÉ
½ºÅ©¸³Æ®¿¡ ÀÎÀÚ¸¦ Àü´ÞÇÏ´Â °Í(argument)À¸·Î¼, ÀÌ °ªÀº °ÅºÎ½Ã¿¡ Á¢¼Ó½ÃµµÀÚÀÇ
Á¤º¸¸¦ tcp_wrapper°¡ ½ÀµæÇÑ °ÍÀε¥ À̸¦ ±×´ë·Î ½ºÅ©¸³Æ®·Î Àü´ÞÇϱâ À§ÇØ
¼ø¼´ë·Î ÀÎÀÚ°ªÀ¸·Î ³ª¿ÇÑ °ÍÀÔ´Ï´Ù.
¼ø¼´ë·Î º¸¸é, Á¦ÀÏ ¾ÕÀÇ Y´Â Á¢¼Ó°ÅºÎ¿¡ ´ëÇÑ ¾Æ·¡¿Í °°Àº ¸Þ¼¼Áö¸¦ ȸ鿡
³ªÅ¸³»ÁÖ´Â °ÍÀ¸·Î¼ °æ°íÀÇ Àǹ̰¡ ³»Æ÷µÇ¾î ÀÖ´Ù°í º¼ ¼ö ÀÖ½À´Ï´Ù.
´Ù¸¥ ¾È³»¸Þ¼¼Áö µîÀ» Ãß°¡ÇÏ°í ½Í°Å³ª ÀϺΠÇ׸ñÀ» Áö¿ì°í ½ÍÀ» ¶§µµ Á¦°øµÇ´Â
½ºÅ©¸³Æ®¸¦ ¾à°£ º¯ÇüÇϴ°ÍÀ¸·Î °¡´ÉÇÕ´Ï´Ù.
¸¸¾à ¾Æ·¡ ¸Þ¼¼Áö¸¦ º¸ÀÌÁö ¾ÊÀ¸·Á¸é NÀ̶ó°í ÀÔ·ÂÇؾßÇÕ´Ï´Ù.
[abcdef@open ~]$ telnet bom.sarang.net
Trying 210.126.148.20...
Connected to bom.sarang.net.
Escape character is '^]'.
===================================
Á¢¼ÓÀÌ Çã¿ëµÇÁö ¾Ê½À´Ï´Ù.
===================================
Access Time : Tue Jan 19 04:08:52 KST 1999
Client host address : 210.126.123.123
Client information : 210.126.123.123
Client host name(or IP) : 210.126.123.123
Client host name : unknown
Client user name : unknown
Connection closed by foreign host.
[abcdef@open ~]$
µÎ¹ø° Y´Â »ó¼¼ÇÑ Á¢¼Ó½Ãµµ ³»¿ëÀ» ¿î¿µÀÚ¿¡°Ô ¸ÞÀÏ·Î Àü´ÞÇÒ°ÍÀÎÁö¸¦ ÁöÁ¤ÇÏ´Â
ÀÎÀڷμ Y·Î ÁöÁ¤ÇÒ °æ¿ì ¸ÞÀÏ·Î ¾Æ·¡¿Í °°ÀÌ Àü´ÞµË´Ï´Ù.
Date: Tue, 19 Jan 1999 04:08:53 +0900 (KST)
From: root
To: root at bom.sarang.net
Subject: tcp_wrapper report [in.telnetd]
===============================
Á¢¼Ó °ÅºÎÀÚ »ó¼¼Á¤º¸
===============================
Access Time : Tue Jan 19 04:08:52 KST 1999
Access client host address : 210.126.123.123
Access client information : 210.126.123.123
The daemon process name : in.telnetd
Access client host name(or IP) : 210.126.123.123
Access client host name : unknown
The daemon process id : 7373
Server information : in.telnetd@210.126.148.20
Access client user name : unknown
--------------------------------------------------------------------------
Access client finger information
--------------------------------------------------------------------------
[210.126.148.110]
--------------------------------------------------------------------------
³ª¸ÓÁö ÀÎÀÚ %a %c %d %h %n %p %s %u Àº man hosts.allow ÆäÀÌÁöÀÇ EXPANSIONS
ºÎºÐ¿¡ ±â·ÏµÇ¾î ÀÖ´Â ³»¿ëÀÔ´Ï´Ù.
ÁÖÀÇÇÒ Á¡Àº ¾Æ·¡ ½ÇÇàµÉ ½ºÅ©¸³Æ®¿¡¼ ¼ø¼´ë·Î ÀÎÀÚ¸¦ º¼·¯¼ È°¿ëÇϹǷÎ
ÀÎÀÚµéÀÇ ³ª¿¼ø¼¸¦ ¹Ù²Ù°Å³ª ÀϺΠÀÎÀÚ¸¦ »©¹ö¸®°Ô µÇ¸é ¿ÀÀÛµ¿À» ÀÏÀ¸Å³ ¼ö
ÀÖ´Ù´Â °Ì´Ï´Ù.
¸¶Áö¸·À¸·Î Á¢±Ù °ÅºÎ½Ã hosts.deny·Î ºÎÅÍ ÀÎÀÚ¸¦ ³Ñ°Ü¹Þ¾Æ ½ÇÇàµÉ
/etc/hosts.denyck ½ºÅ©¸³Æ®ÀÔ´Ï´Ù.
------------------------- start
#!/bin/sh
################################ º¯¼öÁ¤ÀǺι®
# ¸ÞÀÏ ¼ö½ÅÀÚ
mailto=root
# ȸéÃâ·Â ¿©ºÎ, ¸ÞÀÏÀü¼Û ¿©ºÎ
dsp=${1}; msg=${2}
# Á¢¼ÓÀÚ Á¤º¸ µî
a=${3}; c=${4}; d=${5}; h=${6}; n=${7}; p=${8}; s=${9}; u=${10}
# ÇöÀç ½Ã°£
time=`date`
# Á¢¼Ó½ÃµµÀÚ ¼Ò¼Ó ¼¹öÀÇ finger Á¤º¸
finger=`/usr/bin/finger -l @$h 2> /dev/null`
################################ ȸé Ãâ·ÂºÎ¹®
if [ "$dsp" = Y ]
then
/bin/echo "
===================================\n\
Á¢¼ÓÀÌ Çã¿ëµÇÁö ¾Ê½À´Ï´Ù. \n\
===================================\n\
\n\
Access Time : $time\n\
Client host address : $a\n\
Client information : $c\n\
Client host name(or IP) : $h\n\
Client host name : $n\n\
Client user name : $u\n\n"
fi
################################ ¸ÞÀÏ ¼Û½ÅºÎ¹®
if [ "$msg" = Y ]
then
/bin/echo "
===============================\n\
Á¢¼Ó °ÅºÎÀÚ »ó¼¼Á¤º¸ \n\
===============================\n\
\n\
Access Time : $time\n\
Access client host address : $a\n\
Access client information : $c\n\
The daemon process name : $d\n\
Access client host name(or IP) : $h\n\
Access client host name : $n\n\
The daemon process id : $p\n\
Server information : $s\n\
Access client user name : $u\n\
\n\
--------------------------------------------------------------------------\n\
Access client finger information \n\
--------------------------------------------------------------------------\n\
$finger\n\
--------------------------------------------------------------------------\n\
\n\n" | \
/bin/mail -s "tcp_wrapper report [$d]" $mailto
fi
------------------------- end
|
|
Page Loading [ 0.04 Sec ]
SQL Time [ 0 Sec ]
|
|
|