>> Delete Reply from No. 46068 article
No. RE: [질문]tcp_wrapper로는 부족합니까?

등록 2002-04-02 12:59:00 By localhost     조회 1
이름 ngine    

		: 안녕하세요..누가 침입한 흔적이 있어서요.
:
: tcp_wrapper로 IP를 모두 막아놓고 제가 사용하는 하나의 IP만 열어놓았는데
: 어제 193.230.234.111 에서 접속을 하고 계정을 만들어 놓았더군요.
: tcp_wrapper에서 설정을 했다하더라도 허용되지않은 호스트가 접속할수 있는
: 지 궁굼합니다.
:
: # hosts.deny    This file describes the names of the hosts which are
: #               *not* allowed to use the local INET services, as ecided
: #               by the '/usr/sbin/tcpd' server.
: #
: # The portmap line is redundant, but it is left to remind you that
: # the new secure portmap uses hosts.deny and hosts.allow.  In articular
: # you should know that NFS uses portmap!
: in.telnetd: ALL: twist ( /etc/hosts.denyck Y Y %a %c %d %h %n %p %s %
: u ) &
: in.ftpd:    ALL: twist ( /etc/hosts.denyck Y Y %a %c %d %h %n %p %s %
: u ) &
: ipop3d:     ALL: twist ( /etc/hosts.denyck Y Y %a %c %d %h %n %p %s %
: u ) &
:
:
: # hosts.allow   This file describes the names of the hosts which are
: #               allowed to use the local INET services, as decided
: #               by the '/usr/sbin/tcpd' server.
: #
: in.telnetd: 127.0.0.1 192.168.1.2 203.222.0.216
: in.ftpd:    127.0.0.1 192.168.1.2 203.222.0.216
: ipop3d:     127.0.0.1 192.168.1.2 203.222.0.216
:
: 설정은 위화같이 해 놓았습니다. 당연히 위에서 허용한 IP외에서는 접속이
: 불가합니다.
: 어케 telnet으로 들어왔을까요? 조언부탁합니다.
 텔넷은 문제가 많다고 하네요..
ssh 보안쉘을 사용하시는게 좋다고 하네요.
ssh 설치는 oops.org 정균님 강좌나
와우리눅스
http://wowlinux.com/download/specialview.html?db=special&id=69&view=1 강좌 참조 하시구요..
 /etc/inetd.conf에서 텔넷포트 주석처리하시구요..
# /etc/rc.d/init.d/inet restart 해주셔서 텔넷을 막아주세요...--24시간 윈엠프 음악방송 http://www.no
1muse.com http://no1muse.com/listen.pls
[관리자] 패스워드를 입력 하십시오. 답장이 존재하면 함께 삭제됩니다.[ 목록 | 이전 ]
패스워드:    

Copyleft 1999-2026 by JSBoard Open Project
Theme Designed by IDOO All right reserved