ãã ããå®å šãªITã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§ç¯ããããã«å€é¡ã®è²»çšããããå¿ èŠã¯ãããŸãã ã ããšãã°ãLinuxã·ã¹ãã ã«ã¯ä¿è·ã¡ã«ããºã ãçµã¿èŸŒãŸããŠãããé©åã«æ§æãããŠããã°ãOSããã³ãããã¯ãŒã¯ã«å¯Ÿããæãäžè¬çãªã¿ã€ãã®æ»æãåæ ã§ããŸãã
ãã®èšäºã§ã¯ãITã€ã³ãã©ã¹ãã©ã¯ãã£ããããã³ã°ããŠæ å ±ãå±éºã«ãããå¯èœæ§ãæžããããã€ãã®åºæ¬çãªãã³ããèŠãŠãããŸãã æçš¿ã®äŸã¯LinuxããŒã¹ã®ã·ã¹ãã çšã«æäŸãããŠããŸããã説æãããŠãããã©ââã¯ãã£ã¹ã®äžéšã¯ä»ã®OSã«ãé©çšã§ããŸãã
/ Flickr / cezary borysiuk / PD
1.ææ°ã®ã»ãã¥ãªãã£æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ããŸã
ãã®ç¹ã¯éåžžã«æçœã§ãããã¢ããªã±ãŒã·ã§ã³ã®å®æçãªæŽæ°ã®éèŠæ§ã¯ä»¥åã«æžãããŠããŸãããæ®å¿µãªãããããã¯ãŸã é¢é£æ§ã倱ããªãã OpenSSL- Heartbleed ïŒCVE-2014-0160ïŒã®è匱æ§ç¶æ³ãã芧ãã ããã
æ»æè ããµãŒããŒã®ç§å¯éµãæœåºããããã䜿çšããŠéä¿¡ããããã©ãã£ãã¯ã埩å·åã§ããããã«ããŸãã 2014幎ã«ãšã©ãŒæ å ±ãå ¬éãããæç¹ã§ãè匱ãªãµã€ãã®æ°ã¯åèš50äžã§ããããåæã«Googleã®éçºè BodoMöllerãšAdam Langleyã¯è匱æ§ãä¿®æ£ããããããæºåããŸãã ã ãã ããå šå¡ãã¢ããããŒããã€ã³ã¹ããŒã«ããããã§ã¯ãªããShodanã«ãããš ãHeartbleedã¯20äžè¿ãã®Webãµã€ãã®åœ±é¿ãåããŠããŸãã
ã·ã¹ãã ãææ°ã®ç¶æ ã«ä¿ã€ããã«ãOSã®èªåæŽæ°ã»ãã¥ãªãã£ãèšå®ããããšããå§ãããŸãã ã»ãšãã©ã®ãã³ããŒã¯ãããããèªåçã«ã€ã³ã¹ããŒã«ããããŒã«ãæäŸããŠããŸãã ããšãã°ãDebianã«ã¯ç¡äººã¢ããã°ã¬ãŒããŠãŒãã£ãªãã£ããããRed Hat ããŒã¹ã®ã·ã¹ãã ã«ã¯AutoUpdatesããããŸãã Yum-cronã¯CentOSã§ã dnf-automaticã¯Fedoraã§å©çšã§ããŸãã
ããã±ãŒãžãããŒãžã£ãŒã䜿çšããŠã¢ããã°ã¬ãŒãããããšãã§ããŸãã ããšãã°ã Debianã®å Žå ïŒ
apt-get update && apt-get upgrade
ãããã®èªåã€ã³ã¹ããŒã«ã«ã¯æ¬ ç¹ããããŸããããšãã°ãæŽæ°ã«ããã·ã¹ãã ãã¯ã©ãã·ã¥ããå ŽåããããŸãã ãããã£ãŠãéçšç°å¢ã«æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ããåã«ããµã³ãããã¯ã¹å ã®ãœãããŠã§ã¢ã®äºåãã¹ããå®æœãã䟡å€ããããŸãã
ãµãŒãã¹ããã¯ã®éçºè ã¯ããœãããŠã§ã¢è£œåãã·ã¹ãã ã«æœåšçã«å±éºãªå€æŽãå ããªãããã«ããŸãããã¢ããªã±ãŒã·ã§ã³ãšãµãŒãã¹ã®å¯èœãªçµã¿åããããã¹ãŠãã¹ãããããšã¯ã§ããŸããã ããšãã°ãæè¿ãªãªãŒã¹ãããWindows 10çšã®ãããKB4041676ã¯ãäžéšã®ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒãç¡éã®åèµ·åãµã€ã¯ã«ã«éãããæ»ã®ãã«ãŒã¹ã¯ãªãŒã³ããçæããŸããã
åæã«ãã¢ããã°ã¬ãŒãåŸã®ã·ã¹ãã ã®äžéšã¯ãé¢é£ãããã¹ãŠã®ããã»ã¹ãåèµ·åããããŸã§ãäŸç¶ãšããŠãšã¯ã¹ããã€ãã«å¯ŸããŠè匱ã§ãã ããšãã°ã2014幎ã«OpenSSLã¯ãæ»æè ãDDoSæ»æãè¡ãããšãå¯èœã«ããããã€ãã®è匱æ§ãçºèŠããŸãã ã DebianããŒãžã§ã³1.0.1e-2 + deb7u10ã§ã¯éããããŠããŸããããããããæå¹ã«ããã«ã¯ãOpenSSLã«é¢é£ãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ãåèµ·åããå¿ èŠããããŸããã åèµ·åãå¿ èŠãªããã°ã©ã ãæ€çŽ¢ããããã«ãã³ãã¥ããã£ã¯checkrestartããã³needs- restarting ãŠãŒãã£ãªãã£ã éçºã ãŸãã ã
2.ã»ãã¥ãªãã£æ¡åŒµæ©èœãæå¹ã«ããŸã
çŸä»£ã®ã·ã¹ãã ã§ã¯ãããŸããŸãªãŠãŒã¶ãŒãææããå€æ°ã®ããŒã¢ã³ãšããã°ã©ã ãå転ããŠããŸãã ãã©ã³ã¿ãªãŒãšåŒã°ããåŸæ¥ã®Unixã¢ãã«ïŒDAC-ä»»æã¢ã¯ã»ã¹å¶åŸ¡ïŒã¯ãã¢ã¯ã»ã¹æš©ãå²ãåœãŠããšãã«ããŠãŒã¶ãŒããŠãŒã¶ãŒã°ã«ãŒããããã³ã¢ããªã±ãŒã·ã§ã³ç®¡çããã»ã¹ãè€éã«ããä»ã®3ã€ã®ãã©ã¡ãŒã¿ãŒã§åäœããŸãã
ã»ãã¥ãªãã£ããªã·ãŒãèšå®ããããã®ããå€ãã®ãªãã·ã§ã³ã管çè ã«æäŸããããã«ãMACïŒå¿ é ã¢ã¯ã»ã¹å¶åŸ¡ïŒã¢ãã«ãã€ãŸã匷å¶ã¢ã¯ã»ã¹å¶åŸ¡ã«åºã¥ããŠã»ãã¥ãªãã£æ¡åŒµæ©èœãéçºãããŸããã ãããã¯åŸæ¥ã®ã¢ãã«ãè£å®ãããã¹ãŠã®ããã»ã¹ã®ã»ãã¥ãªãã£ããªã·ãŒã確ç«ããæ©äŒãæäŸããŸãã ããšãã°ãæå®ãããããŒãã§ãªãã¹ã³ããããã«WebãµãŒããŒãã泚æãããããæå®ããããã£ã¬ã¯ããªããã®ã¿ãã¡ã€ã«ãèªã¿åããããã«ããŸãã
ã»ãã¥ãªãã£ã¢ããªã±ãŒã·ã§ã³ã®äžã§ã¯ã SELinuxãAppArmorãGrSecurityïŒä»ã«ããããŸã ïŒãåºå¥ã§ããŸããããããã«é·æãšçæããããŸãã 次ã«ãSELinuxã®æ©èœãç°¡åã«æ€èšŒããŸããããã¯æãå®å šã§ïŒãã®ã¢ããªã±ãŒã·ã§ã³ã¯æ¿åºã·ã¹ãã ã§äœ¿çšããããã«äœæãããïŒãnixCraft Vivek Giteã®ã·ã¹ãã 管çè ããã³äœæè ãšããŠãæã匷åãªã¢ã¯ã»ã¹å¶åŸ¡ã¡ã«ããºã ãåããŠããŸãã
3ã€ã®åäœã¢ãŒãããããŸãã 匷å¶ã¯ã確ç«ãããã»ãã¥ãªãã£ããªã·ãŒã«éåããã¢ã¯ã·ã§ã³ããããã¯ããããã©ã«ãã¢ãŒãã§ãã 2çªç®ã®ã¢ãŒãïŒèš±å¯ïŒã¯ããã°å ã®ãã¹ãŠã®éåããã£ããã£ããŸããããããããããã¯ããŸããã 3çªç®ã®ç¶æ -ç¡å¹-ã¯ãã·ã¹ãã ãç¡å¹ã§ããããšãæå³ããŸãã
次ã®ã³ãã³ããèšè¿°ãããšãèšå®ãããŠããã¢ãŒãã確èªã§ããŸãã
$ /usr/sbin/getenforce
SELinuxãæå¹ã«ããã«ã¯ã次ã®ããã«å ¥åããŸã ïŒFedoraã®å ŽåïŒïŒ
rpm -qa | grep selinux rpm -q policycoreutils rpm -qa | grep setroubleshoot #
ãã®ãŠãŒãã£ãªãã£ã¯ãããã€ãã®ã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ãæäŸããŸãã
- Type Enforcement ïŒTEïŒïŒãã©ã€ããªã¢ã¯ã»ã¹å¶åŸ¡ã¡ã«ããºã ã æè»ã§ããæéãããããŸãã ãã¹ãŠã®ãªããžã§ã¯ããšãµããžã§ã¯ãã«ã¯èå¥åãä»ããŠããããããã䜿çšããŠã«ãŒã«ãšããªã·ãŒãå²ãåœãŠãããšãã§ããŸãã
- 圹å²ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ ïŒRBACïŒïŒã·ã¹ãã ã«ã¯ã1ã€ä»¥äžã®ãã¡ã€ã³ã¿ã€ãã«é¢é£ä»ãããã圹å²ãå²ãåœãŠãããŸãã ãããã®ãã£ãŒãã¯ããã§èŠã€ããããšãã§ããŸã ã
- ãã«ãã¬ãã«ã»ãã¥ãªã㣠ïŒMLSïŒïŒãã¹ãŠã®ã·ã¹ãã ãªããžã§ã¯ãã¯ç¹å®ã®ã¬ãã«ã®ã¢ã¯ã»ã¹ãåãåãããã®æ©èœãå¶éããŸãã ãã®ã¬ãã«ã§ã¯ããµãŒãã¹ã¯æ å ±ã®èªã¿åããšæžã蟌ã¿ãè¡ãããšãã§ããäžã®ã¬ãã«ã§ã¯æžã蟌ã¿ã®ã¿ãäžã®ã¬ãã«ã§ã¯èªã¿åãã®ã¿ãå¯èœã§ãã ã»ãã¥ãªãã£ã¬ãã«ã®å³ãããã«ãããŸã ã
SELinuxãã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããç¶æ³ã®äŸãšããŠãæ§æãšã©ãŒãçºçããå ŽåããããŸãã DNSãµãŒããŒã¯ããµãŒããŒéã§ããŒã¿ãè€è£œãããšãã«ããŸãŒã³è»¢éãšåŒã°ãããã®ãå®è¡ããããšããããããŸãã æ»æè ã¯ãã®æé ã䜿çšããŠã誀ã£ãæ å ±ããµãŒããŒã«ãããŒããã£ã¹ãã§ããŸãã Fedoraã§BINDã䜿çšããå Žåã管çè ãæ å ±ã®äº€æãèš±å¯ãããµãŒããŒã®ç¯å²ãå¶éãå¿ããŠããSELinuxããªã·ãŒã¯ã¬ããªã±ãŒã·ã§ã³äžã®ãŸãŒã³ãã¡ã€ã«ã®å€æŽãé²ããŸãã
SELinuxã§ã¯ãããã»ã¹ãä»ã®ããã»ã¹ã§äœ¿çšããããã¡ã€ã«ã«ã¢ã¯ã»ã¹ããã®ããããã¯ããããšãã§ããŸãã ããšãã°ãæ»æè ã¯SambaãµãŒããŒãå±éºã«ãããããšã¯ã§ããããããä»ããŠä»ã®ã·ã¹ãã ïŒMySQLããŒã¿ããŒã¹ãªã©ïŒã®ãã¡ã€ã«ãå€æŽããŸãã
SELinuxãä¿è·ãããã®ä»ã®ãŠãŒã¶ãŒã±ãŒã¹ã¯ã ããããå ¥æã§ããŸã ã Debian 㧠SELinuxãã»ããã¢ããããããã®è©³çŽ°ãªã¬ã€ããšãFedoraã®ã¬ã€ããããã«ãããŸã ã
3.ã¢ã¯ã»ã¹æš©ãèšå®ãããã¹ã¯ãŒãããªã·ãŒãèšå®ãã
ãã®ç¹ãéåžžã«æçœã§ãããéèŠã§ã¯ãªããªããŸããã 2015幎ã«2000人ã®ãªãã£ã¹ã¯ãŒã«ãŒã察象ã«ã€ã³ã¿ãŒã¡ãã£ã¢ãå®æœãã調æ»ã«ãããšãåçè ã®93ïŒ ãå°ãªããšã1床ã¯æ å ±ã»ãã¥ãªãã£èŠä»¶ãç¡èŠããããšãèªããŸããã åæã«ãITæ¥çã®åŸæ¥å¡ã®67ïŒ ããããŸããŸãªã¢ã«ãŠã³ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããååãšå ±æããŠãããšçããŠããŸãã
è匱ã§äžè¬çãªãã¹ã¯ãŒãã¯ãäŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãææãã®å¯èœæ§ãé«ããäžé©åã«èšå®ãããã¢ã¯ã»ã¹æš©ã¯çµç¹ã®ã·ã¹ãã ã®æãç©ŽãéããŸãã ãããã£ãŠããµãŒããŒã«ç®¡çè ïŒã«ãŒãïŒãšããŠæ¥ç¶ããããšã¯ãå§ãããŸãã ã æ°ãããŠãŒã¶ãŒãäœæããæš©éãå¶éããŠãã®ã¢ã«ãŠã³ããæäœããsudoã䜿çšããŠç®¡çããããšããå§ãããŸãã
Stack Exchangeã®å± äœè ãææããŠããããã«ããã®ã¢ãããŒãã¯æ»æè ã®ç掻ãå°é£ã«ããŸãã ããã«ãŒã¯ãSSHïŒssh root @ $ IPïŒãä»ããŠæ¥ç¶èŠæ±ãéä¿¡ãããããã䜿çšããæšæºã®çµã¿åããïŒãrootããŸãã¯ãpassword123ããæãäžè¬çã§ãïŒãŸãã¯ãã«ãŒããã©ãŒã¹ã䜿çšããŠãã¹ã¯ãŒããéžæã§ããŸãã ã«ãŒãã¢ã¯ã»ã¹ãååŸã§ããå Žåãã·ã¹ãã å šäœã§ãç¡å¶éã®é»åããååŸããŸãã
ããããrootãSSHçµç±ã§æ¥ç¶ã§ããªãå Žåããããã¯æåã«ãŠãŒã¶ãŒåãæšæž¬ããå¿ èŠãããããããã³ã°æé ãé£ãããªããŸãã
Debianããã³Ubuntuã§æ°ãããŠãŒã¶ãŒãäœæããã«ã¯ãã³ã³ãœãŒã«ã§æ¬¡ã®ã³ãã³ããå ¥åããŸãã
adduser administrator
管çè ãã£ãŒã«ãã¯ä»»æã«å€æŽã§ããŸãã 次ã«ããã¹ã¯ãŒããç»é²ãããŸãã ãã¹ã¯ãŒãããã§ã¯ ã8ã10æåã®é·ãã§ãç°ãªãã¬ãžã¹ã¿ãæ°åãç¹æ®æåã䜿çšãããã¹ã¯ãŒããäœæããããšããå§ãããŸãã Coding Horrorããã°ã®èè ã§ãããStack Overflowããã³Stack Exchangeãã©ãããã©ãŒã ã®å ±åèšç«è ã§ãããžã§ãã¢ããŠããã¯ã10æå以äžã®ãã¹ã¯ãŒãã䜿çšãããšã æã人æ°ã®ãããªã¹ãã«è¡šç€ºãããå¯èœæ§ã80ïŒ æžå°ããããšã«æ³šç®ããŠããŸãã
ã¯ããè€éã§é·ããã¹ã¯ãŒããäœæããå¿ èŠãããããšã¯ããç¥ãããŠããŸãããå®éã«ã¯ã誰ãããã®èŠåã«åŸãããã§ã¯ãããŸããã SplashDataããŒã ã¯ã2016幎ã«ãçµ±åããããäŒæ¥åŸæ¥å¡ã®ã¢ã«ãŠã³ããã500äžãè¶ ãããã¹ã¯ãŒããåæããŸãã ã ç 究è ã¯ãã»ãšãã©ã®ãã¹ã¯ãŒãã¯å®å šã«å®å šã§ã¯ãªããšçµè«ä»ããŸããã ãã¹ã¯ãŒãã123456ããæãäžè¬çã«ãªããããã¹ããã»ããå šäœã®4ïŒ ã®ã¢ã«ãŠã³ãã§äœ¿çšãããŸããã ã»ãŒåãå²åã§å ¥åããããã¹ã¯ãŒããpasswordãã
ãŸããåéšã®ä»ã®ãŠãŒã¶ãŒã®æ¿èªã®ããã«ããŒã¿ãåŠçãã䟡å€ããããŸãã è匱ãªãã¹ã¯ãŒãã¯ã John the ripperãŠãŒãã£ãªãã£ã䜿çšããŠæ€åºã§ããŸãã ã·ã¹ãã ã«ããã¹ã¯ãŒãã®ãªãããŠãŒã¶ãŒãããªãããšã確èªããã«ã¯ããã®ã³ãã³ãã圹ç«ã¡ãŸãã
awk -F: '($2 == "") {print}' /etc/shadow
ãã¹ã¯ãŒãã®äœæãå¿ é æé ã«ãããã¹ã¯ãŒãã®æå¹æéãèšå®ããã«ã¯ãpam_cracklib.soãã¡ã€ã«ã®èšå®ãå€æŽããŸãã
chage -M 60 -m 7 -W 7 UserName
pam_unix.soã®å€ããã¹ã¯ãŒãã®åå©çšãé²ãããã°ã€ã³è©Šè¡åæ°ã«å¶éãèšå®ããŸãã
è€æ°ã®ã¢ããªã±ãŒã·ã§ã³ãããããããããããŸããŸãªéèŠãªæ å ±ã«ã¢ã¯ã»ã¹ã§ããå Žåãå¥ã ã®ã¢ã«ãŠã³ãããããããèµ·åããŠãããã¢ããªã±ãŒã·ã§ã³ããå¥ã®ã¢ããªã±ãŒã·ã§ã³ã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ããããã¯ãã䟡å€ããããŸãã
ã¢ããªã±ãŒã·ã§ã³ã«ã¡ãŒã«ãµãŒãã¹ãåã蟌ãããã®APIãéçºããŠããMailgunãææããŠããããã«ããã®ã¢ãããŒãã®ç®æšã¯ãããã«ãŒããŸã ã·ã¹ãã ã«äŸµå ¥ã§ããå Žåã«ããã«ãŒã®ããªãã·ã§ã³ãã®æ°ãæžããããšã§ãã ã¢ããªã±ãŒã·ã§ã³ã®ã¢ã¯ã·ã§ã³ã®ãªã¹ããå¿ èŠæå°éã«å¶éãããŠããå Žåãæ»æè ã¯ãããšãã°ã¢ã¯ã»ã¹æš©ãäžããŠé倧ãªæ害ãäžããããšãã§ããŸããã
é©åãªãŠãŒã¶ãŒã®ããäžã§éå§ãããããã«ããµãŒãã¹ãããã¢ãããŸãã ãããè¡ãã«ã¯2ã€ã®æ¹æ³ããããŸãã 1ã€ç®ã¯ãOSã¹ã¯ãªããïŒ initãŸãã¯systemd ïŒã䜿çšããŠã¢ããªã±ãŒã·ã§ã³ãèµ·å/åæ¢ããç£èŠããŒã«ïŒ monit ïŒã䜿çšããŠã¯ã©ãã·ã¥ããå Žåã«åèµ·åããããšã§ãã 2çªç®ã®ã¢ãããŒãã¯ãã¢ããªã±ãŒã·ã§ã³ãç¬èªã«ç®¡çããããã»ã¹å¶åŸ¡ã·ã¹ãã ïŒ Supervisord ã s6 ã daemontools ïŒã䜿çšããããšã§ãã
/ Flickr / reynermedia / CC
4.ãã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ãšäŸå€ãæ§æãã
æè¿ã systemdãããŒãžã£ãŒã«è匱æ§ïŒ CVE-2017-15908 ïŒãçºèŠãããDDoSæ»æãå¯èœã«ãªããŸããã è匱ãªã·ã¹ãã ãããã«ãŒã«ãã£ãŠå¶åŸ¡ãããŠããDNSãµãŒããŒã«DNSã¯ãšãªãéä¿¡ãããšãsystemdãç¡éã«ãŒãã«å ¥ãã100ïŒ ã®CPUè² è·ãåŒãèµ·ããç¹å¥ãªã¯ãšãªãè¿ããŸããã
ãã®ã¿ã€ãã®æ»æããä¿è·ãã1ã€ã®æ¹æ³ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãæ§æããããšã§ããå ·äœçã«ã¯ããã®å Žåããã¡ã€ã¢ãŠã©ãŒã«ã¯RFC 4034ã®ã»ã¯ã·ã§ã³4ã§èª¬æãããŠãããªãœãŒã¹ã¬ã³ãŒããå«ãæœåšçã«æªæã®ãããã±ããããããã¯ããããã«æ瀺ãããŸã ã
äžè¬ã«ãå€éšã¢ã¯ã»ã¹çšã«å°æ°ã®ãµãŒãã¹ã®ã¿ãéããšããé£çµ¡å ãã®æ°ãæžãããã®çµæãã·ã¹ãã ã«äŸµå ¥ããå¯èœæ§ãäœããªããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãèšå®ãããšããMailgunããŒã ã¯æ¬¡ã®ååã«åŸãããšãæšå¥šããŸã ã
- æ°ããã«ãŒã«ãèšå®ããåã«ãæ¢åã®ã«ãŒã«ãåé€ããŸãã
- ããã©ã«ãã§ã¯ãçä¿¡ãã©ãã£ãã¯ãåŠçããã«ã¯ ãDROPãã©ã¡ãŒã¿ãŒãèšå®ããŸãïŒç¢ºç«ãããã«ãŒã«ãæºãããªããã©ãã£ãã¯ã¯ã¹ããããããŸããïŒã ãã®åŸãå€éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãåŸã ã«ãéããããšãã§ããŸãã
- ã€ã³ã¿ãŒãããå¶åŸ¡ã¡ãã»ãŒãžãããã³ã«ïŒICMPïŒãã©ãã£ãã¯ãå®å šã«å¶éããªãã§ãã ããã ã«ãŒã¿ãŒãšãã¹ãã¯ããã䜿çšããŠããµãŒãã¹ã®å¯çšæ§ããã±ãããµã€ãºãªã©ã«é¢ããéèŠãªæ å ±ãéä¿¡ããŸããStackExchangeã§è¿°ã¹ãããã«ãICMPã¯å¶éã§ããŸããããããã®çŠæ¢ã®åœ¢åŒã¯äŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãã£ãŠç°ãªããŸãã
- IPv6ã䜿çšããŠããªãå Žåããã®ãã©ãã£ãã¯ãå¶éããŸãã
ããããã¹ãŠã®æšå¥šäºé ãå®è£ ããããã«ãMailgunã¯æ§æçšã®ç¬èªã®ã¹ã¯ãªãããäœæããŸãã ã ãã¡ãã§èŠã€ããããšãã§ããŸãã
5. SSHçµç±ã§å®å šã«æ¥ç¶ãã
ãŸããä¿¡é Œã§ããSSHããŒãçæããŸãã ããã¯ãssh-keygenã䜿çšããŠå®è¡ã§ããŸãã
ssh-keygen -t rsa -b 4096 -C foo@example.com
ãã®åŸãããŒã䟵害ãããå Žåã«ããŒãä¿è·ãããã¹ãã¬ãŒãºãå ¥åããå¿ èŠããããŸãã SSHæ¥ç¶ãæŽçããã«ã¯ããŸãšããªæšæºæ§æã®OpenSSHã䜿çšã§ããŸãã OpenSSHãã©ã¡ãŒã¿ã«é¢ãã詳现æ å ±ã¯ãMozillaã®ããã¥ã¢ã«ãŸãã¯CentOS wikiããŒãžã«ãããŸã ã
ç§ãã¡ã®åŽã§ã¯ãæå·ããŒã®ãã¢ã䜿çšããŠSSHçµç±ã§ã¢ã¯ã»ã¹ããããšããå§ãããŸãã 2çªç®ã®ããŒã¯ããã«ãŒããã©ãŒã¹ã«ãããããã³ã°ãå€§å¹ ã«è€éã«ããŸãã åè¿°ã®ããã«ããã¹ã¯ãŒããé·ãã»ã©ä¿¡é Œæ§ãé«ããªããSSHããŒã®é·ãã¯ãããšãã°2048ãããã«ãªããŸãã
ãããè¡ãã«ã¯ãæ°ããããŒãäœæããå ¬éããŒããµãŒããŒã«ã¢ããããŒãããŸãã ããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒãã次ã®ããã«å ¥åããŸãã
ssh-copy-id admin@1.1.1.1
adminãããŒã®ææè ã®ååã«ã1.1.1.1ããµãŒããŒã®IPã¢ãã¬ã¹ã«çœ®ãæããŸãã æ¥ç¶ã確èªããã«ã¯ãåæ¥ç¶ããå¿ èŠããããŸãã
ãã¹ã¯ãŒããå ¥åããããã®SSHæ¥ç¶ãå®å šã«ç¡å¹ã«ããŠãå šå¡ãããŒã䜿çšã§ããããã«ããããšãã§ããŸãã 次ã«ã/ etc / ssh / sshd_configãã¡ã€ã«ã®PasswordAuthentificationãã©ã¡ãŒã¿ãŒã®å€ãnoãšããŒã¯ããå¿ èŠããããŸãã
UbuntuïŒãŸãã¯DebianïŒã§ã¯ã次ã®ããã«ãªããŸãã
nano /etc/ssh/sshd_config ... PasswordAuthentication no
è¿œå ã®æ¥ç¶ã»ãã¥ãªãã£ã¯2FAïŒ äºèŠçŽ èªèšŒ ïŒã䜿çšããŠå®çŸã§ããããšã«æ³šæããŠãã ããã
6.æå·åã䜿çšãã
äŸµå ¥è ããã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããã«ã¯ãæå·åã䜿çšããå¿ èŠããããŸãã å人æ å ±ããã³è³æ Œæ å ±ãæå·åããã«ä¿åããªãã§ãã ããã ãã¹ã¯ãŒããGitHubã®ãã©ã€ããŒããªããžããªã«ããå Žåã§ãã ãã®ãããGitHubã䟵害ãããå Žåã«ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããŸããããã¯ãæšå¹Žäžå¹Žã§æ¢ã«çºçããŠããŸãã æ»æè ã¯ãä»ã®ãµãŒãã¹ããããã³ã°ããçµæãšããŠã³ã³ãã€ã«ããããã¹ã¯ãŒããšé»åã¡ãŒã«ã¢ãã¬ã¹ã®ãªã¹ãã䜿çšããŠãããã€ãã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã䟵害ããäŒæ¥æ å ±ã«ã¢ã¯ã»ã¹ããŸããã
æå·åçšã®ããŒã«ãŸãã¯ã©ã€ãã©ãªãéžæããå ŽåãMailgunããŒã ãšStack Exchangeã®å± äœè ã¯ã次ã®ã«ãŒã«ã«åŸãããšããå§ãããŸãã
- ææ°ã®å¯Ÿç§°æå·ã䜿çšããŸããæãäžè¬çãªãªãã·ã§ã³ã¯ AESãšSalsa20ïŒNaClïŒã§ãã
- MAC ïŒã¡ãã»ãŒãžèªèšŒã³ãŒãïŒã䜿çšããŠãããŒã¿ãœãŒã¹ã®æŽåæ§ãšèªèšŒãå¶åŸ¡ããŸãã é©åãªãªãã·ã§ã³ã¯ã HMAC-SHA-512ãŸãã¯Poly1305ã§ãã
- ããŒãšã¿ã€ã ã³ãŒããçæããããã®é«å質ãªã©ã³ããã€ã¶ãŒã«æ³šæããŠãã ããã ããšãã°ã / dev / urandom ã
- ããŒã«ããã¹ãã¬ãŒãºã§æ©èœããå Žåã¯ã KDFã䜿çšããŠããããšã確èªããŠãã ããã
察å¿ããã¹ã¬ããã®Stack Exchangeã§ããŠãŒã¶ãŒã¯æå·åã·ã¹ãã ãäœæããããã®å€ãã®ããŒã«ïŒentlibãBouncy Castleãªã© ïŒãæäŸããŸãã æ¬åœã«å¿ èŠãªå Žåã¯ãç¬èªã®ãŠãŒãã£ãªãã£ãäœæã§ããŸããã RedditãšQuoraã®äœæ°ã¯ããã®ã¢ãããŒãã¯ãããã³ã°ã®ãªã¹ã¯ãé«ããã ãã ãšèšããŸãã Stack Exchangeã§è¿°ã¹ãããã«ãã»ãšãã©ã®å Žåãèªå®¶è£œã®æå·ã¯ ã ããªã¢ã«ãã¡ããã£ãã¯æå·ããã³çœ®ææå·ã 解èªããããã®ããã«ãŒããŒã«ã«ããæ»æã«ã»ãšãã©èããŸããã
ããã«ãæå·åã·ã¹ãã ã®æäœãéå§ããåã«ãããã€ãã®ãœãŒã¹ãæäŸããŠããŸãã 1ã€ç®ã¯Crypto101ã³ãŒã¹ã§ãã¹ã¿ãŒãã¢ããåãã®ã»ãã¥ãªãã£ãã¬ãŒãã³ã°äŒç€Ÿã§ããããªã³ã·ãã«ã®ãã£ã¬ã¯ã¿ãŒã§ããLaurens Van HoutvenãæããŠããŸãã 2çªç®ã®ãªãœãŒã¹ã§ããmatasanoæå·ãã£ã¬ã³ãžã«ã¯ãå®éã®æå·ã«å¯Ÿããæ»æã瀺ã48ã®æŒç¿ãå«ãŸããŠããŸãã èè ã¯ããã®ãããã¯ã«é¢ããæ¬ãèªãããããæå·ã®åçãç 究ããããã®ããå¹æçãªæ¹æ³ã§ãããšäž»åŒµããŠããŸãã
7.ããã¯ã¢ãããå®æçã«äœæããŠç¢ºèªãã
ããã¯ã¢ããã®åé¡ã¯ãäžèšã®ãããã¯ã®äžè¬çãªããŒãããå°ãå€ããŠããŸãããã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ã確ä¿ããããã«ãéèŠã§ãã ç¹°ãè¿ãã«ãªããŸããããã®ãããã¯ã¯å€ãã®è³æã§ãåã¿ç ãããŠããŸãããã倧äŒæ¥ã§ããééããç¯ããŠãããããç¹°ãè¿ãå¿ èŠããããšèããŠããŸãã
æè¿ã®äŸããããªã©ã³ãã®ã·ã¹ãã 管çè ã«ããGitLabãŠãŒã¶ãŒã®ãããžã§ã¯ãã®ããã¥ã¡ã³ããšã³ãŒããå€æŽããèŠæ±ã䌎ãããŒã¿ããŒã¹ã®äžéšã®åé€ã ãã®åŸãå瀟ã¯ãå®è£ ããã5ã€ã®ããã¯ã¢ããã¹ãã¬ãŒãžã·ã¹ãã ã®ããããæ å ±ã®åŸ©å ã«åœ¹ç«ããªãã£ããšææããŸããã
ãããã£ãŠãããã¯ã¢ãããäœæããããžãã¹ã®èŠä»¶ãèæ ®ããŠãå¯èœãªéãé »ç¹ã«æºåã確èªããããšã¯åœç¶ã®ããšã§ãã ããšãã°ãWebã¢ããªã±ãŒã·ã§ã³éçºäŒç€Ÿã§ããNeon Rainã®ãšã³ãžãã¢ã¯ãé±ã«1åãã¡ã€ã«ãããã¯ã¢ããããæ¯æ©ããŒã¿ããŒã¹ãããã¯ã¢ããããŸãã Cloud Academiesã§ããŒã¿ããŒã¹ã®æ¯æ¥ã®ããã¯ã¢ããã³ããŒãäœæããŸã ã ããšãã°ãChalvington Groupã®ããã¯ã¢ããã®ãã§ãã¯ã«é¢ããŠã¯ãå埩ã®å¯èœæ§ãæ¯æè©äŸ¡ãããŸãã
äžè¬ã«ã1æ¥ã«1åããã¯ã¢ããããã®ãéåžžã®æ¹æ³ã§ãã äž»ãªããšã¯ãããã¯ã¢ããã䜿çšããŠãµãŒããŒãžã®ã¢ã¯ã»ã¹ãå¶éããããšã§ããåŒãç¶ãã¢ã¯ã»ã¹ããã¢ã«ãŠã³ãã®å Žåãã¡ã€ã³ã€ã³ãã©ã¹ãã©ã¯ãã£ã§äœ¿çšããããã®ãšã¯ç°ãªãæ¿èªã¡ã«ããºã ã䜿çšãã䟡å€ããããŸãã
ç¬èªã®ããã¯ã¢ããã€ã³ãã©ã¹ãã©ã¯ãã£ãç·šæããããªãå Žåã¯ãããã¯ã¢ããã³ããŒã®ä¿åãæ åœãããµãŒãããŒãã£ãã³ããŒã«ãã®ã¿ã¹ã¯ã転éããããšããå§ãããŸãã ããšãã°ã1cloudã§ã¯ã1æ¥ã«1åããã¯ã¢ããããã¯ã©ã€ã¢ã³ãã¯ã³ããŒã«å¿ èŠãªã¹ãã¬ãŒãžæéïŒ7ã14ã21ããŸãã¯28æ¥ïŒãéžæããŸãã
äžèšã®ããŒã«ãšèšå®ã¯ãã·ã¹ãã ãä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã ã¯ããããããçš®é¡ã®æ»æããITã€ã³ãã©ã¹ãã©ã¯ãã£ã100ïŒ ä¿è·ããããšã¯ç©ççã«äžå¯èœã§ãããã¯ã©ãã«ãŒã®å¯¿åœãè€éã«ããæœåšçãªãšã¯ã¹ããã€ãã®æ°ãå¶éããããšã¯å¯èœã§ãã 泚æã泚æãããã³æ³šæãæãã°ãéèŠãªæ±ºå®ãäžããä¿è·å¯Ÿçãè¬ããã®ã«å¿ èŠãªæéãåŸãããšãã§ããŸãã
äŒæ¥ããã°1cloudã®ãããã¯ã«é¢ãã3ã€ã®è³æïŒ