>> Edit article
이름
제목
패스워드
INET 슈퍼 서버로 접근 제어하기 ...기본적인 설정은 다음에 있습니다. /etc/inetd.conf [alex99@chongnux /etc]$ cat inetd.conf ## inetd.conf This file describes the services that will be available# through the INETD TCP/IP super server. To re-configure# the running INETD process, edit this file, then send the# INETD process a SIGHUP signal.## 각 라인은 공백으로 구분되며 7개의 필드로 구성되어 있습니다. # <service_name> <sock_type> <proto> <flags> <user> <server_path> <args>service_name sock_type proto flags user server_path args service /etc/services 파일에서처럼 설정과 관계된 서비스이다. socket_type 이 필드는 해당 엔트리다 관계된다고 간주할 소켓의 타입을 기술한다. 가능한 값은 stream, dgram, raw, rdw 또는 seqpacket이다. 이것은 자연 히 약간 기술적인데, 첫째가는 규칙으로 거의 모든 tcp 기반의 서비스는 stream을 사용하고 거의 모든 udp 기반의 서비스는 dgram을 사용한다. 다른 값을 사용하는것은 매우 특별한 형태의 서버일때 뿐이다. proto 이 엔트리에 유효하다고 간주되는 프로토콜. 이것은 /etc/services 파일 의 적절한 엔트리와 매치되야 하며 전형적으로 tcp 또는 udp 중의 하나 이다.Sun RPC(Remote Procedure Call)기반의 서버는 rpc/tcp 또는 rpc/udp를 사용한다. flags 이 필드를 위한 세팅에는 두가지 값밖에 없다. 프로그램을 실행한뒤 소 켓을 놓아주어 다음의 커넥션 요청에 대해 새로운것을 시작하게 하는냐, 아니면 기다리며 다른 서버가 이미 동작한다고 가정하여 다음 터넥션을 다루게 할것이냐하는 두가지이다. 또 이것을 다루는 것은 약간 애매하지 만, tcp 서버는 이 엔트리를 nowait으로 설정하고 udp 서버는 이것을 wait으로 설정하는것이 첫째가는 룰이다. 이것에 예외가 있음을 주의하 고 그러므로 확실하지 않을경우 예제 가이드를 참고하라. user 네트워크 데몬이 시작할때 /etc/passwd의 어느 계정이 이 데몬의 소유자 가 될것인가를 기술해준다. 이것은 보안문제에 대해 보안장치를 원할때 유용하다. 이 엔트리의 유저를 nobody로 함으로써 네트워크 서버의 보안 이 깨졌을때 피해를 최소화 할수있다. 그러나 이 필드는 전형적으로 root로 설정되는데 많은 서버가 적절히 동작하기 위해서 root의 권한을 요구하기 때문이다. server_path 이 엔트리에 대해 실행할 실제 서버 프로그램의 경로이다. server_args 이 필드는 라인의 나머지 부분을 이루며 선택적이다. 이 필드는 서버 데몬 프로그램이 실행될때 프로그램에 넘겨주고싶은 커맨드 라인 변수를 넣어주는 부분이다. ## These are standard services.#ftp stream tcp nowait root /usr/sbin/tcpd in.ftpd -l -atelnet stream tcp nowait root /usr/sbin/tcpd in.telnetdgopher stream tcp nowait root /usr/sbin/tcpd gn# Shell, login, exec and talk are BSD protocols.#shell stream tcp nowait root /usr/sbin/tcpd in.rshdlogin stream tcp nowait root /usr/sbin/tcpd in.rlogind;exec stream tcp nowait root /usr/sbin/tcpd in.rexecdtalk dgram udp wait root /usr/sbin/tcpd in.talkdntalk dgram udp wait root /usr/sbin/tcpd in.ntalkddtalk stream tcp waut nobody /usr/sbin/tcpd in.dtalkd# Pop and imap mail services et al#pop-2 stream tcp nowait root /usr/sbin/tcpd ipop2dpop-3 stream tcp nowait root /usr/sbin/tcpd ipop3dimap stream tcp nowait root /usr/sbin/tcpd imapd# The Internet UUCP service.#uucp stream tcp nowait uucp /usr/sbin/tcpd /usr/lib/uucp/uucico -l# cfinger is for GNU finger, which is currently not in use in RHS Linux#finger stream tcp nowait root /usr/sbin/tcpd in.fingerdcfinger stream tcp nowait root /usr/sbin/tcpd in.cfingerdsystat stream tcp nowait guest /usr/sbin/tcpd /bin/ps -auwwxnetstat stream tcp nowait guest /usr/sbin/tcpd /bin/netstat -f inet# Time service is used for clock syncronization.#time stream tcp nowait nobody /usr/sbin/tcpd in.timedtime dgram udp wait nobody /usr/sbin/tcpd in.timed# Authentication#auth stream tcp nowait nobody /usr/sbin/in.identd in.identd -l -e -o **********************************************************************위의 설정은 red5.2의 디폴트 설정이다. 여기서 자신이 막고 싶은 데몬이 있다면 앞에 ;을 붙여주기만 하면된다. 일반적이 해커들의 공격대상인 BSD프로토콜을 막아주는 것이 보안에 도움이 된다. ********************************************************************** [ BSD 란 ?] -- 1977 ----> 최근의 버전은: 4.4 BSD (1993)Berkeley System Distribution<operating system> (BSD) A family of Unix versions for the DEC VAX and PDP-11, developed by Bill Joy and others at the University of California at Berkeley. BSD Unix incorporates paged virtual memory, TCP/IP networking enhancements, and many other features. <운영 시스템> 유닉스 계보의 한 버전으로서 DEC, VAX ,PDP -11 을 캘리포니아 버클리 대학의 Bill joy 와 그의 연구원들에 의해 향상된 유닉스 버전이다. BSD 유닉스는 가상 페이지 메모리와 TCP/IP 네트윜과 많은 다른 것들을 통합했다.여담: 리눅스는 대개 BSD방식으로 구현을 했다. 그렇다고 System V.3 의 방식을 전혀 사용 하지 않았다는 말은 아니다. ㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠ설정이 끝난 후에 해야 할일 .. /etc/rc.d/inet stop --> 멈추고 /etc/rc.d/inet start --> 다시 시작하고 ㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠ슈퍼데몬이 관리 하는 서버의 이름은 파일 서두에 in. 이라는 이름을가진다..[alex99@chongnux sbin]$ ls in.*in.comsat* in.identd* in.rlogind* in.telnetd* in.wuftpd@in.fingerd* in.ntalkd* in.rshd* in.tftpd*in.ftpd* in.rexecd* in.talkd@ in.timed* 여기서 막아 두어야 할 것은 rlogin,rsh,rexec 정도이다. 해커들이 들쑤시는 곳이 이 부분인 듯....??ㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠ***서비스 제어 tcpd ---> in.telnetd 제어 하기 (접근 제한을 두는 것은 보안의 필수 이다.)[alex99@chongnux /etc]$ ls ho*host.conf hosts hosts.allow hosts.deny 위의 파일중 hosts.allow hosts.deny 은 in.telnetd를 제어한다. hosts.deny 파일에 in.telnetd : ALL 하게 되면 모든 호스트의 접근을 막아준다.hosts.allow 파일에 in.telnetd : 접근 허락 IP를 적어줌...ㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠ 이상 .. 행복하세요.... ㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠㅠ [참고] 리눅스 NET-3-HOWTO, Linux Networking. 역자 : 조용준, 알짜 레드햇 5.2 이 만용 저 기타 사전ㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛㅛ
Copyleft
1999-2026 by
JSBoard Open Project
Theme Designed by
IDOO
All right reserved