ååã ãµãŒããŒãéžæããæ¹æ³ãšããµãŒããŒãèªåã®æã§ãªãã£ã¹ã«ã€ã³ã¹ããŒã«ããæ¹æ³ã«ã€ããŠèª¬æããŸãã ã
次ã®ã¹ããã-ã¢ããªã±ãŒã·ã§ã³ãWebãµãŒãã¹ãããã³ããŒã¿ããŒã¹ãæäœããITã€ã³ãã©ã¹ãã©ã¯ãã£ã確ç«ãã-ãå®è¡ããŸãã ããã¯ç°¡åãªäœæ¥ã§ã¯ãããŸããããé©åãªä¿è·ããªããã°ãã€ã³ãã©ã¹ãã©ã¯ãã£å šäœãå±éºã«ãããããŸãã
ä»åã¯ããµãŒããŒã®äœ¿çšãéå§ããåã«ãšãã¹ãåºæ¬çãªã»ãã¥ãªãã£å¯Ÿçã«ã€ããŠèª¬æããŸãã
SSHããŒ
ãã®æè¡ã¯ããã¹ã¯ãŒãèªèšŒã®ä»£æ¿ãšããŠèªèšŒã«äœ¿çšãããæå·ããŒã®ãã¢ã«åºã¥ããŠããŸãã ãã°ã€ã³ã·ã¹ãã ã¯ãèªèšŒåã«äœæãããç§å¯éµãšå ¬ééµã䜿çšããŸãã ç§å¯ããŒã¯ä¿¡é Œã§ãããŠãŒã¶ãŒã«ãã£ãŠç§å¯ã«ãããŸãããå ¬éããŒã¯æ¥ç¶ããå¿ èŠãããä»»æã®SHHãµãŒããŒããé åžã§ããŸãã
SSHããŒã«ããèªèšŒãæ§æããã«ã¯ããŠãŒã¶ãŒã®å ¬éããŒããµãŒããŒäžã®ç¹å¥ãªãã£ã¬ã¯ããªã«é 眮ããå¿ èŠããããŸãã ãŠãŒã¶ãŒããµãŒããŒã«æ¥ç¶ãããšãSSHã«æ¥ç¶èŠæ±ã衚瀺ãããŸãã 次ã«ãå ¬éããŒã䜿çšããŠãã³ãŒã«ãäœæããã³éä¿¡ããŸãã åŒã³åºã-ãµãŒããŒã«ã¢ã¯ã»ã¹ããããã«é©åãªå¿çãå¿ èŠãšããæå·åãããã¡ãã»ãŒãžã ç§å¯éµã®ææè ã®ã¿ãã¡ãã»ãŒãžã«æ£ããè¿ä¿¡ã§ããŸãã ã€ãŸãã圌ã ãããã£ã¬ã³ãžãåãå ¥ããé©åãªå¿çãäœæã§ããŸãã å ¬ééµã¯ã¡ãã»ãŒãžã®æå·åã«äœ¿çšãããŸãããåãã¡ãã»ãŒãžã埩å·åããããšã¯ã§ããŸããã
ã³ãŒã«ãšã¢ã³ãµãŒã¯ãŠãŒã¶ãŒã«æ°ä»ãããã«ééããŸãã éåžžã¯ã/ .ssh /ã«æå·åããã圢åŒã§ä¿åãããŠããç§å¯ããŒãããéããSSHã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒã«æ£ããå¿çãéä¿¡ã§ããŸãã
SSHããŒã¯ã©ã®ããã«ã»ãã¥ãªãã£ãåäžãããŸããïŒ
SSHã§ã¯ãããããçš®é¡ã®èªèšŒãå®å šã«æå·åãããŸãã ãã ãããã¹ã¯ãŒãããŒã¹ã®èªèšŒãæå¹ã«ãªã£ãŠããå Žåãæ»æè ã¯ãµãŒããŒããŒã¿ã«å°éã§ããŸãã ææ°ã®ã³ã³ãã¥ãŒãã£ã³ã°ãã¯ãŒã®å©ããåããŠããããã³ã°ã®è©Šã¿ãèªååããæ£ãããã¹ã¯ãŒããèŠã€ãããŸã§çµã¿åãããŠçµã¿åãããŠå ¥åããããšã«ããããµãŒããŒã«ã¢ã¯ã»ã¹ã§ããŸãã
SSHããŒã§èªèšŒãèšå®ããããšã«ããããã¹ã¯ãŒããå¿ããããšãã§ããŸãã ããŒã¯ãã¹ã¯ãŒããããã¯ããã«å€ãã®ããŒã¿ããããæã£ãŠãããããã¯ã©ãã«ãŒãååŸããªããã°ãªããªãçµã¿åããã®æ°ãéåžžã«å€ããªããŸãã å€ãã®SSHããŒã¢ã«ãŽãªãºã ã¯ãäžèŽããã®ã«æéããããããããšããçç±ã ãã§ãçŸä»£ã®ã³ã³ãã¥ãŒãã£ã³ã°ãã¯ãããžãŒã§ã¯è§£èªã§ããªããšèããããŠããŸãã
SSHã®å®è£ ã¯ã©ããããé£ããã§ããïŒ
SSHããŒã®èšå®ã¯éåžžã«ç°¡åã§ãã å€ãã®å ŽåãLinuxããã³UnixãµãŒããŒç°å¢ã«ãªã¢ãŒãã§ãã°ã€ã³ããæ¹æ³ãšããŠäœ¿çšãããŸãã ã³ã³ãã¥ãŒã¿ãŒã§ããŒãã¢ãçæãããããæ°åã§å ¬éããŒããµãŒããŒã«è»¢éã§ããŸãã
ããŒãèšå®ããããã®åºæ¬çãªæé ã¯æ¬¡ã®ãšããã§ãã
1.ã³ã³ãã¥ãŒã¿ãŒã§ããŒãã¢ãçæããã«ã¯ã次ã®ã³ãã³ããå ¥åããå¿ èŠããããŸãã
ssh-keygen -t rsa
2.ããŒçæã³ãã³ããå ¥åããããããšãã°ããã¡ã€ã«ã®ä¿åå ŽæãéžæããããŒãã¬ãŒãºãªã©ãããã€ãã®è³ªåã«çããå¿ èŠããããŸãã äžè¬çã«ãçµæã¯æ¬¡ã®ããã«ãªããŸãã
ssh-keygen -t rsa Generating public/private rsa key pair. Enter file in which to save the key (/home/demo/.ssh/id_rsa): Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /home/demo/.ssh/id_rsa. Your public key has been saved in /home/demo/.ssh/id_rsa.pub. The key fingerprint is: 4a:dd:0a:c6:35:4e:3f:ed:27:38:8c:74:44:4d:93:67 demo@a The key's randomart image is: +--[ RSA 2048]----+ | .oo. | | . oE | | + . o | | . = = . | | = S = . | | o + = + | | . o + o . | | . o | | | +----------------------------+
3.éµãå ¥æãããã䜿çšããä»®æ³ãµãŒããŒã«å ¬ééµãé 眮ããŸãã ããã«é¡äŒŒããäœããåŸãŸãïŒ
The authenticity of host '12.34.56.78 (12.34.56.78)' can't be established. RSA key fingerprint is b1:2d:33:67:ce:35:4d:5f:f3:a8:cd:c0:c4:48:86:12. Are you sure you want to continue connecting (yes/no)? yes Warning: Permanently added '12.34.56.78' (RSA) to the list of known hosts. user@12.34.56.78's password: Now try logging into the machine, with "ssh 'user@12.34.56.78'", and check in: ~/.ssh/authorized_keys
ãµãŒããŒã§ãŸã èªèšŒãã¹ã¯ãŒããå¿ èŠã ãšæãå Žåã¯ããã¹ã¯ãŒãã®è©Šè¡åæ°ãå¶éããFail2banãªã©ã®ãœãªã¥ãŒã·ã§ã³ãã芧ãã ããã
ãã¡ã€ã¢ãŠã©ãŒã«
ãã¡ã€ã¢ãŠã©ãŒã«ã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ãããããã¯ãŒã¯ã¢ã¯ã»ã¹ãå¶åŸ¡ãããœãããŠã§ã¢ãŸãã¯ãã¡ãŒã ãŠã§ã¢ã§ãã ããã¯ãäŸå€ãé€ããéããŠããåããŒããžã®ã¢ã¯ã»ã¹ããããã¯ãŸãã¯å¶éããããšãæå³ããŸãã
äžè¬çãªãµãŒããŒã§ã¯ãå€ãã®ãã¡ã€ã¢ãŠã©ãŒã«ã³ã³ããŒãã³ããããã©ã«ãã§èµ·åãããŸãã ãããã¯ã°ã«ãŒãã«åããããšãã§ããŸãïŒ
-ã€ã³ã¿ãŒãããäžã§èª°ã§ãæ¥ç¶ã§ãããªãŒãã³ãµãŒãã¹ã¯ãå€ãã®å Žåå¿åã§ãã è¯ãäŸã¯ããµã€ããžã®ã¢ã¯ã»ã¹ãèš±å¯ããWebãµãŒããŒã§ãã
-ç¹å®ã®å ŽæãŸãã¯èš±å¯ããããŠãŒã¶ãŒã®ã¿ãå©çšã§ãããã©ã€ããŒããµãŒãã¹ã äŸã¯ããµã€ããŸãã¯ããŒã¿ããŒã¹ã®ã³ã³ãããŒã«ããã«ã§ãã
-å€éšãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãªãã§ããµãŒããŒèªäœã®å éšã§å©çšå¯èœãªå éšãµãŒãã¹ã ããšãã°ãããŒã«ã«æ¥ç¶ã®ã¿ãåãå ¥ããããŒã¿ããŒã¹ã
ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšãããšãäžèšã®ã«ããŽãªã«åŸã£ãŠãœãããŠã§ã¢ãšããŒã¿ãžã®ã¢ã¯ã»ã¹ãå¶éãããŸãã ã¯ããŒãºããµãŒãã¹ã¯ããŸããŸãªæ¹æ³ã§æ§æã§ããã»ãã¥ãªãã£ãæ§ç¯ããæè»æ§ãæäŸããŸãã æªäœ¿çšã®ããŒãã«ã€ããŠã¯ãã»ãšãã©ã®æ§æã§ããããã³ã°ãæ§æã§ããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã¯ã©ã®ããã«ã»ãã¥ãªãã£ãé«ããŸããïŒ
ãã¡ã€ã¢ãŠã©ãŒã«ã¯ããµãŒããŒæ§æã®äžå¯æ¬ ãªéšåã§ãã ãœãããŠã§ã¢ã«å éšã»ãã¥ãªãã£æ©èœãããå Žåã§ãããã¡ã€ã¢ãŠã©ãŒã«ã¯è¿œå ã®ã»ãã¥ãªãã£å±€ãæäŸããŸãã
æ éã«æ§æããããã¡ã€ã¢ãŠã©ãŒã«ã¯ããã¹ãŠãžã®ã¢ã¯ã»ã¹ããããã¯ããŸãããããªãèªèº«ã¯äŸå€ãã¹ããŒããŸããã ãã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠæ»æãããè匱ãªã³ã³ããŒãã³ãã¯ããµãŒããŒã®æ»æ察象é åãæžãããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ãå®è£ ããã®ã¯ã©ããããé£ããã§ããïŒ
LAMPãµãŒããŒã§ã¯å€ãã®ãã¡ã€ã¢ãŠã©ãŒã«ãå©çšå¯èœã§ãã äžè¬ã«ããã¡ã€ã¢ãŠã©ãŒã«ã®ã€ã³ã¹ããŒã«ã¯æ°åã§å®äºãã2ã€ã®ã±ãŒã¹ã§å¿ èŠã«ãªããŸãããµãŒããŒã®åæã»ããã¢ããäžãšãæ¢ã«å®è¡äžã®ãµãŒããŒã®ç¹å®ã®ãµãŒãã¹ãå€æŽããå Žåã§ãã
ãã®èšäºã§ã¯ç¹å®ã®ãã¡ã€ã¢ãŠã©ãŒã«ãæšå¥šããŸãããããã¯å¥ã®è°è«ã®ãããã¯ã§ãã
VPNããã³ãã©ã€ããŒããããã¯ãŒã¯
VPNïŒä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ïŒã¯ããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãšçŸåšã®æ¥ç¶ã®éã«å®å šãªæ¥ç¶ãäœæããæ¹æ³ã§ãã ã»ãã¥ãªãã£ã§ä¿è·ãããããŒã«ã«ãšãªã¢ãããã¯ãŒã¯ã䜿çšããŠãããããªæ¹æ³ã§ããµãŒããŒã§ã®äœæ¥ãæ§æã§ããŸãã
VPNã¯ã©ã®ããã«ã»ãã¥ãªãã£ãåäžãããŸããïŒ
ãã©ã€ããŒããããã¯ãŒã¯ãšãããªãã¯ãããã¯ãŒã¯ã®ã©ã¡ãããéžæããå Žåã¯ãåžžã«æåã®ãªãã·ã§ã³ããå§ãããŸãã åæã«ãããŒã¿ã»ã³ã¿ãŒã®ãŠãŒã¶ãŒã¯1ã€ã®ãããã¯ãŒã¯ã§æ¥ç¶ãããŠããããšãèŠããŠããå¿ èŠããããŸãããµãŒããŒéã®å®å šãªéä¿¡ã®ããã«è¿œå ã®å¯Ÿçãè¬ããããšã§ããªã¹ã¯ãæ倧éã«æé€ããå¿ èŠããããŸãã
VPNã䜿çšããããšã¯ãåºæ¬çã«ããµãŒããŒã ããèŠãããšãã§ãããã©ã€ããŒããããã¯ãŒã¯ãäœæããæ¹æ³ã§ãã éä¿¡ã¯å®å šã«ãã©ã€ããŒãã§å®å šã§ãã ããã«ãVPNãåã ã®ã¢ããªã±ãŒã·ã§ã³ãšãµãŒãã¹çšã«æ§æããŠããããã®ãã©ãã£ãã¯ãä»®æ³ã€ã³ã¿ãŒãã§ã€ã¹ãééããããã«ããããšãã§ããŸãã ãããã£ãŠãã¯ã©ã€ã¢ã³ãåŽã®ã¿ã«ãããªãã¯ã¢ã¯ã»ã¹ãèš±å¯ããVPNãããµãŒããŒã®äœæ¥ã®å éšéšåãé ãããšã«ããã瀟å ã®ããã»ã¹ãä¿è·ããããšãã§ããŸãã
VPNã®å®è£ ã¯ã©ããããé£ããã§ããïŒ
ãµãŒãã¹ãšããŠã®ããŒã¿ã»ã³ã¿ãŒã®ãã©ã€ããŒããããã¯ãŒã¯-ããã¯ç°¡åã§ãã è€éãã¯ããµãŒããŒããã®ã€ã³ã¿ãŒãã§ã€ã¹ããã¡ã€ã¢ãŠã©ãŒã«ãããã³äœ¿çšããã¢ããªã±ãŒã·ã§ã³ã®ãã©ã¡ãŒã¿ãŒã«ãã£ãŠã®ã¿å¶éãããŸãã ããŒã¿ã»ã³ã¿ãŒã¯ãããªãã ãã§ã¯ãªããè€æ°ã®ãµãŒããŒãæ¥ç¶ãã倧èŠæš¡ãªãã©ã€ããŒããããã¯ãŒã¯ã䜿çšããããšã«æ³šæããŠãã ããã
VPNã«é¢ããŠã¯ãåæã»ããã¢ããã¯ããå°ãè€éã§ãããã»ãšãã©ã®å Žåãã»ãã¥ãªãã£ã®åäžã¯æè³ã®äŸ¡å€ããããŸãã åVPNãµãŒããŒã¯ãå®å šãªæ¥ç¶ã«å¿ èŠãªå ±æããŒã¿ãšã»ãã¥ãªãã£æ§æã䜿çšããŠã€ã³ã¹ããŒã«ããã³æ§æããå¿ èŠããããŸãã VPNãéå§ããããVPNãã³ãã«ã䜿çšããããã«ãœãããŠã§ã¢ãæ§æããå¿ èŠããããŸãã
PKIããã³SSL / TLSæå·å
å ¬éããŒåºç€ïŒPKIïŒ-å人ãèå¥ããéä¿¡ããŒã¿ãæå·åããããã®èšŒææžãäœæã管çãæ€èšŒããããã«èšèšãããã·ã¹ãã ã®ã»ããã èªèšŒåŸãæå·åãããéä¿¡ã«ã䜿çšã§ããŸãã
SSLã¯ã©ã®ããã«ã»ãã¥ãªãã£ã匷åããŸããïŒ
ãµãŒããŒçšã®èšŒææžãšèšŒææžç®¡çã»ã³ã¿ãŒãäœæãããšããµãŒããŒã€ã³ãã©ã¹ãã©ã¯ãã£å ã®å šå¡ããã©ãã£ãã¯ãæå·åããä»ã®ãŠãŒã¶ãŒã®IDãã§ãã¯ã䜿çšã§ããŸãã PKIã¯ãæ»æè ãã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ãµãŒããŒã®åäœãã·ãã¥ã¬ãŒãããŠãã©ãã£ãã¯ãååããããã¡ãã»ãŒãžãåœè£ ãããããéã«ãäžéè æ»æãé²ãã®ã«åœ¹ç«ã¡ãŸãã
åãµãŒããŒã¯ããã¹ãŠã®åå è ãå ¬ééµãšç§å¯éµã®ãã¢ãäœæããèªèšŒå±ãéããŠèªèšŒãããããã«æ§æã§ããŸãã CAã¯ãçžäºã®ä¿¡é ŒåºŠã¯äœããCAã®ä¿¡é ŒåºŠãé«ããã¹ãŠã®åå è ã«å ¬ééµãé åžã§ããŸãã å ¬ééµããã®ææè ã«å±ããŠããããšã確èªã§ããã®ã¯ãåŸè ã®ã¿ã§ãã
TLS / SSLæå·åããµããŒãããã¢ããªã±ãŒã·ã§ã³ãšãããã³ã«ã䜿çšããå Žåãããã¯VPNã³ã¹ãïŒSSLã䜿çšããããšãå€ãïŒãåæžããæ¹æ³ã§ãã
SSLã®å®è£ ã¯ã©ã®ãããé£ããã§ããïŒ
蚌ææ©é¢ãšãã®ä»ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ããã¢ããã«ã¯ãå€ãã®åæåªåãå¿ èŠã§ãã ããã«ã蚌ææžç®¡çã¯è¿œå ã®ç®¡çè² æ ã§ããå¿ èŠã«å¿ããŠãæ°ãã蚌ææžãäœæãã眲åãã倱å¹ãããå¿ èŠããããŸãã
å€ãã®ãŠãŒã¶ãŒã«ãšã£ãŠãæ¬æ Œçãªå ¬éããŒã€ã³ãã©ã¹ãã©ã¯ãã£ã®å°å ¥ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ãå€§å¹ ã«å¢å ããå Žåã«ã®ã¿æå³ããããŸãã VPNãä»ããæ¥ç¶ã¯ãäŒæ¥ãPKIããã³è¿œå ã®ç®¡çæè³ãäžå¯æ¬ ãšãªããã€ã³ãã«éãããŸã§ããµãŒããŒä¿è·ã®åªããæ段ãšãªããŸãã
ç£æ»ãµãŒãã¹
ãããŸã§ããµãŒããŒã®ã»ãã¥ãªãã£ãåäžããããã¯ãããžãŒã«ã€ããŠèª¬æããŠããŸããã ãã ããã»ãã¥ãªãã£ã®ã»ãšãã©ã¯ã·ã¹ãã ã®åæã«ãããŸãã å©çšå¯èœãªæ»æ察象é åãšããããã¯ããå¿ èŠã®ããã·ã¹ãã ã³ã³ããŒãã³ããç解ãããšãæé«ã®é²åŸ¡çµæãåŸãããŸãã
ç£æ»ã¯ããµãŒããŒã€ã³ãã©ã¹ãã©ã¯ãã£ã§å®è¡ãããŠãããµãŒãã¹ã瀺ãããã»ã¹ã§ãã å€ãã®å Žåããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ãæ¢å®ã§èµ·åæã«ç¹å®ã®ã³ã³ããŒãã³ããèªã¿èŸŒãã§å®è¡ããããã«æ§æãããŠããŸãã
ç£æ»ã¯ãã·ã¹ãã ã䜿çšããããŒããåãå ¥ãããããããã³ã«ãåæããã®ã«åœ¹ç«ã¡ãŸãã ãã®æ å ±ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã®æ§æã«åœ¹ç«ã€å ŽåããããŸãã
ç£æ»ã¯ã»ãã¥ãªãã£ãã©ã®ããã«åäžãããŸããïŒ
ãµãŒããŒã¯ãå éšç®çããã³å€éšããŒã¿ã®åŠçã®ããã«å€ãã®ããã»ã¹ãå®è¡ããŸãã åããã»ã¹ã¯ããµãŒããŒã«å¯Ÿããæ»æã®æœåšçãªè åšã§ãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä»çµã¿ãç解ããããåæãéå§ããŸãã åããã»ã¹ã«ã¯ããã€ãã®ãã¹ãåé¡ããããŸãã
-èš±å¯ãªããµãŒãã¹ãéå§ããå¿ èŠããããŸããïŒ
-ã€ã³ã¿ãŒãã§ãŒã¹ã§ãµãŒãã¹ãèµ·åãããŠããŸããïŒ 1ã€ã®IPã«é¢é£ä»ããå¿ èŠããããŸããïŒ
-ãã®ããã»ã¹ãééãããã©ãã£ãã¯ãèš±å¯ããå Žåããã¡ã€ã¢ãŠã©ãŒã«ã¯æ£ããæ§æãããŠããŸããïŒ
-ãã¡ã€ã¢ãŠã©ãŒã«ã¯ç¹å®ã®ããã»ã¹ããã®äžèŠãªãã©ãã£ãã¯ãééãããŸããïŒ
-åãµãŒãã¹ã«è匱æ§ãããå Žåã«ã»ãã¥ãªãã£éç¥ãåä¿¡ããæ¹æ³ã¯ãããŸããïŒ
ãã®ã¿ã€ãã®ç£æ»ã¯ãæ°ãããµãŒããŒãã»ããã¢ããããããã®å¿ é ã®ãã©ã¯ãã£ã¹ã§ãã
ç£æ»ã®å®æœã¯ã©ããããé£ããã§ããïŒ
åºæ¬çãªç£æ»ã¯éåžžã«ç°¡åã§ãã netstatã³ãã³ãã䜿çšããŠãåã€ã³ã¿ãŒãã§ã€ã¹ã§ãªãã¹ã³ããŠãããµãŒãã¹ã確èªã§ããŸãã ããã°ã©ã åãããã»ã¹IDïŒPIDïŒãTCPããã³UDPãã©ãã£ãã¯ããªãã¹ã³ããããã®ã¢ãã¬ã¹ã瀺ãç°¡åãªäŸïŒ
sudo netstat -plunt
次ã®ãããªãã®ãåŸãããŸãã
Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 887/sshd tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 919/nginx tcp6 0 0 :::22 :::* LISTEN 887/sshd tcp6 0 0 :::80 :::* LISTEN 919/nginx
ããããããŒã«ã«ã¢ãã¬ã¹ãããã³PID /ããã°ã©ã åã®åã«æ³šæããŠãã ããã 0.0.0.0ãããã«ãªã¹ããããŠããå ŽåããµãŒãã¹ã¯ãã¹ãŠã®ã€ã³ã¿ãŒãã§ãŒã¹ã§æ¥ç¶ãåãå ¥ããŸãã
ãã¡ã€ã«ç£æ»ããã³äŸµå ¥æ€ç¥ã·ã¹ãã
ãã¡ã€ã«ç£æ»ã¯ãçŸåšã®ã·ã¹ãã ã®ç¶æ ããã·ã¹ãã ãè¯å¥œãªç¶æ ã«ãããšãã«ãã¡ã€ã«ã¬ã³ãŒãããã³ã·ã¹ãã ã®ç¹æ§ãšæ¯èŒããããã»ã¹ã§ãã ãã®ã¡ãœããã¯ãèš±å¯ãå¿ èŠãªå€æŽãæ€åºããããã«äœ¿çšãããŸãã
äŸµå ¥æ€ç¥ã·ã¹ãã ïŒIDSïŒã¯ãã·ã¹ãã ãŸãã¯ãããã¯ãŒã¯ã®äžæ£è¡çºãç£èŠãããœãããŠã§ã¢ã§ãã å€ãã®ãã¹ãã£ã³ã°IDSã¯ãã·ã¹ãã ã®å€æŽããã§ãã¯ããæ¹æ³ãšããŠãã¡ã€ã«ç£æ»ã䜿çšããŸãã
ãã¡ã€ã«ç£æ»ã¯ã»ãã¥ãªãã£ãã©ã®ããã«æ¹åããŸããïŒ
äžèšã®äŸã®ãµãŒããŒä¿å®ç£æ»ã®ããã«ãããã¯ã»ãã¥ãªãã£ã匷åããéåžžã«äŸ¿å©ãªæ¹æ³ã§ãã ãããã¯ãŒã¯ç®¡çè ã¯å®æçã«ãã¡ã€ã«ãç£æ»ã§ããŸãããIDSã䜿çšããŠèªåçã«ç£æ»ããããšãã§ããŸãã
ãã¡ã€ã«ç£æ»ã¯ããŠãŒã¶ãŒãããã»ã¹ã«ãã£ãŠãã¡ã€ã«ã·ã¹ãã ãå€æŽãããªãããã«ããããã®æ°å°ãªãæ¹æ³ã®1ã€ã§ãã å€ãã®çç±ãããã¯ã©ãã«ãŒã¯ãµãŒããŒãé·æé䜿çšããããã«æ°ä»ãããã«è¡ãããããŸãã ãããã³ã°ãããããŒãžã§ã³ã®ãã¡ã€ã«ã眮ãæããããšãã§ããŸãã ãã¡ã€ã«ç£æ»ãå®æœãããšãã©ã®ãã¡ã€ã«ãå€æŽãããããããããŸããããã«ããããµãŒããŒç°å¢ã®æŽåæ§ã確èªã§ããŸãã
ãã¡ã€ã«ç£æ»ãå®è£ ããã®ã¯ã©ããããé£ããã§ããïŒ
IDSã®å®è£ ãŸãã¯ãã¡ã€ã«ã®æ€èšŒã¯å°é£ãªå ŽåããããŸãã åæã»ããã¢ããã«ã¯ããµãŒããŒã§è¡ã£ããã¹ãŠã®éæšæºã®å€æŽãšé€å€ãããã¹ãŠã®ãã¹ã®èª¬æãå«ãŸããŠããŸãã
ç£æ»ã«ãããæ¥ã ã®ãµãŒããŒç®¡çã«æéãããããŸãã ããã«ãããæŽæ°ãéå§ããåãšã€ã³ã¹ããŒã«ããåŸããœãããŠã§ã¢ããŒãžã§ã³ã®å€æŽããã£ããããããã«ã·ã¹ãã ãå確èªããå¿ èŠããããããæŽæ°ããã»ã¹ãè€éã«ãªããŸãã ããã«ãæ»æè ãç£æ»ããã¥ã¡ã³ããå€æŽã§ããªãããã«ãååã«ä¿è·ãããå Žæã«ã¬ããŒããã¢ããããŒãããå¿ èŠããããŸãã
äžæ¹ã§ã¯ãç£æ»ã¯ç®¡çäžã®è² æ ã§ãããä»æ¹ã§ã¯ãå€æŽããããŒã¿ãä¿è·ããããã®ä¿¡é Œã§ããæ¹æ³ã§ãã
åé¢ã©ã³ã¿ã€ã
å°çšã®ã¹ããŒã¹ã§ã·ã¹ãã ã³ã³ããŒãã³ããèµ·åããæ¹æ³ã
ãµã³ãããã¯ã¹ã䜿çšãããšãåå¥ã®ã¢ããªã±ãŒã·ã§ã³ã³ã³ããŒãã³ããåå¥ã®ãµãŒããŒã«åé¢ã§ããŸãã åé¢ã¬ãã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã·ã¹ãã èŠä»¶ãšã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ã¢ããªã±ãŒã·ã§ã³ã®å Žæã«å€§ããäŸåããŸãã
åé¢ãããã©ã³ã¿ã€ã ã¯ã©ã®ããã«ã»ãã¥ãªãã£ãæ¹åããŸããïŒ
ããã»ã¹ãåå¥ã®ã©ã³ã¿ã€ã ã«åå²ããããšã«ãããæœåšçãªè åšãè¿ éã«éé¢ããèœåãåäžããŸãã è¹äœã®ééãä¿æããŠè¹ãdrããã®ãé²ãè¹ã®åºç»ã®ããã«ããµãŒããŒã€ã³ãã©ã¹ãã©ã¯ãã£ã®åé¢ãããã³ã³ããŒãã³ãã¯ãã·ã¹ãã ã®ä»ã®éšåãžã®æ»æè ã®ã¢ã¯ã»ã¹ãé®æããã®ã«åœ¹ç«ã¡ãŸãã
éé¢ãããç°å¢ãå®è£ ããã®ã¯ã©ããããé£ããã§ããïŒ
éžæããã·ã§ã«ã®ã¿ã€ãã«ãã£ãŠã¯ãæç±ã¯ç°¡åãªæé ã«ãªãå ŽåããããŸãã ã³ã³ããŒãã³ããã³ã³ããã«æ¢±å ããããšã§ãããã«åªããæç±æ§èœãå®çŸã§ããŸãã
åéšåã«chrootç°å¢ãèšå®ãããšãããçšåºŠã®åé¢ãåŸãããŸãããå®å šã§ã¯ãããŸããã æé©ãªãªãã·ã§ã³ã¯ãã³ã³ããŒãã³ããå°çšã®ãã·ã³ã«è»¢éããããšã§ããããã¯ã¯ããã«ç°¡åã§ãããã³ã¹ããããããŸãã
çµè«ãšããŠ
äžèšã®æè¡ãšå¯Ÿçã¯ããµãŒããŒãä¿è·ããããã«è¡ãããšãã§ããæ©èœåŒ·åã®ã»ãã®äžéšã§ãã ãã®ãããªä¿è·æ¹æ³ã®å°å ¥ã¯éåžžã«éèŠã§ãããåŸ æ©æéãé·ããªãã»ã©ã»ãã¥ãªãã£æ©èœã®å¹æãäœäžãããããæ©ããã°æ©ãã»ã©è¯ãããšã«æ³šæããããšãéèŠã§ãã
ãã®èšäºã§ã¯ãçè«çãªèŠ³ç¹ãããµãŒããŒã®ã»ãã¥ãªãã£åé¡ãæ€èšããŸãã éæ¥å»ããã®è¿œå ã楜ãã¿ã«ããŠããŸãã 䟿å©ãªããã¥ã¢ã«ãäžç·ã«äœããŸãããïŒ
ç·Žç¿ã§ã©ã®ãããªä¿è·æ段ã䜿çšããŠããŸããããŸããªãããããå¹æçã§ãããšèããã®ã§ããïŒ