ºô¸ô»P¸ê°T¦w¥þ
½Òµ{»¡©ú¡G
- ³Ìªñ§ó·s®É¶¡¡G 2010/07/26 14:30
- ¥»½Òµ{¨Ï¥Î±Ð§÷¬°¡G¡yLinux ¨t²Î¦w¥þ¨¾Å@»P«Ø¸m¡z¡AùÖ®p¥Xª©ªÀ¡F
- ¥»½Òµ{¨Ï¥Î±Ð§÷¬°¡G¡y¸ê°T¦w¥þ·§½×»P¹ê°È¡z¡AùÖ®p¥Xª©ªÀ¡F
- ¨C¶g³£¦³¥i¯à·|¦³¤W¾÷¹ê§@¡Anµ¥¦Ñ®vÀˬd§¹²¦¤~¯à°÷¤U½Ò¡I§_«h´N¤£ºâ¦³¨Ó¤W½Ò¡I
²Ä¤@¶g¡GWindows ªº¤@¯ë«OÅ@¡G
- ¸ê°T¦w¥þªº¥Øªº¦bºûÅ@¸ê°Tªº¡G«O±K©Ê¡B§¹¾ã©Ê¡B¥i¥Î©Ê¤TºØ¡F
- ¯}Ãa¸ê¦wªº¥Dn«Â¯Ù¡G
- ¹F¨ì¤J«I (access) ªº¥Øªº¡G¥¼¸g±ÂÅvªº¨Ï¥Î¥L¤H¸ê·½¡A¹F¨ì¯}Ãa¸ê°Tªº«O±K©Ê¡F
- ¹F¨ì«§ï (modification) ªº¥Øªº¡GÀH·Nקï¥L¤H¸ê°T¦Ó¯}Ãa¬Y¨Ç¨Æ¹ê¡A¯}Ãa¸ê®Æªº§¹¾ã©Ê¡F
- ¹F¨ì©Úµ´ªA°Èªº¥Øªº¡G¤zÂZ¥L¤Hªº¥¿±`¨Ï¥Î¥\¯à¡A¯}Ãa¸ê°Tªº¥i¥Î©Ê¡C
- ¤@¯ë§ðÀ»¡G
- §ðÀ»³qÃö±K»y¡G´N¬O±K½X¯}¸Ñ (password-cracking)¡A¥i¯à¨Ï¥Î (1)ºô¸ôºÊ¬Ý©Î (2)¦r¨å§ðÀ»¡F
- §Q¥Î«áªù¡G§Q¥Îµ{¦¡ªºº|¬}¶i¥X¨t²Î©Îºô¸ô¡C¥i¯à¨Ï¥Îì¥ý³nÅéºûÅ@ªÌªº«áªù
(¥æ³f®É§Ñ°OÃö³¬)¡A©ÎªÌ¬O¥Ñ§ðÀ»ªÌ´Ó¤J¤ì°¨µ{¦¡¶}±Ò«áªù¡C
- ÄdºI»P°°¸Ë¡G§Q¥Î¤¤¶¡ÄdºI«Ê¥]¡A¨Ã°°¸Ë¦¨¬°¹ï¤è¦Óµ¹¤©¿ù»~¸ê°T¡C
- ³nÅé®zÂIªº§Q¥Î¡G¤£¤@©w¬O³nÅ骺¿ù»~¡A¥i¯à¬OÂǥѬY¨Ç³nÅ骺¥\¯à©ÎªÌ¬O¦X¨Ö¼ÆºØ¥\¯à¡A¨Ó¹F¨ì§ðÀ»ªº¥Øªº¡C
¨Ò¦p SQL injection ¡A¥¨¶°¯f¬r¡B¹q¤l¶l¥óªºªþÀɧ¨±a¥\¯à¡B¹q¤l¶l¥óªº³q°T¿ýµo«H¥\¯àµ¥¡C
- ´c·Nµ{¦¡ªººØÃþ¡G
- ¯f¬r¡G±H©~©ó¨ä¥Lµ{¦¡ªº¤p³nÅé¡A¥Øªº¬°¡G·P¬Vµ¹¨ä¥L¹q¸£¤ÎÅý¨ü®`¹q¸£¤£¯à¥¿±`¹B§@¡C±`¨£·P¬V³~®|¡G
¥iÄ⦡´CÅé (USB³Ì±`¨£)¡B¹q¤l¶l¥ó¡B¥¿±`³nÅ骺¤À¨É®É³Q¯}¸Ñ (¤£ÀH·N¤U¸ü°Ú¡I)
- įÂΡGįÂÎ¥i¥H¦Û¤v¦s¦b¤£»Ý±H©~©ó¨ä¥Lµ{¦¡¡AįÂÎ¥i¥H¦Û¤v½Æ»s¦Û¤v¦Ó¦bºô¸ô¤W¤j¶q¶Ç¼½¡C
įÂγq±`·|³y¦¨°O¾ÐÅé¡BÀW¼eªºº¡¸ü¨Ï¥Î¡A¨Ï±o¹q¸£»Pºô¸ô§Î¦¨Ãþ¦ü©Úµ´ªA°Èªºª¬ºA
- ¤ì°¨¡Gµ{¦¡¬O³z¹L¨Ï¥ÎªÌªº¿ù»~§PÂ_¦Ó¤U¸ü¦w¸Ë¡C
- Å޿謵¼u¡G¦b¬Y¨Ç±ø¥ó¤U·|³Q±Ò°Êªº§ðÀ»¡A¨Ò¦p¤Q¤T¸¹¬P´Á¤©Î¥|¤ë¤@¸¹·M¤H¸`±Ò°Êªº´c·N³nÅé¡C
- ´c·N¦æ°Ê½X¡G¨Ò¦pºô¶¦øªA¾¹Y¦³®zÂI¡A®£©È·|³Q´c·Nµ{¦¡½X§ðÀ»¾ÉP¨t²Î¥X²{°ÝÃD(¬õ¦âĵ§ÙįÂιï IIS ªº¼vÅT)
- °lÂÜ cookies ¡G§ä´M¨Ï¥ÎªÌ¹q¸£¤ºªº cookie ÂÇ¥H§ä¨ì¦³¥Îªº¸ê°T
- §ðÀ»¤u¨ã¡G¥]¬A«áªùµ{¦¡¡BÁä½L°¼¿ý©Î¿Ã¹õÂ^¨ú¡BÂsÄý¾¹´O¤Jµ{¦¡¡B§ðÀ»¤u¨ã¥] (rootkits)
- ºô¸ô³¨³½¡G°°¸Ë¦Xªkªº¦øªA¾¹
- «ç»ò¨¾¤î´c·Nµ{¦¡¡G
- įÂλP¯f¬r¨Ï¥Î¨¾¬r³nÅé¨Ó©è¾×¡F
- ¤ì°¨«h»Ýn¨Ï¥ÎªÌ¦³¸û¨Îªº¹q¸£ºô¸ô¾Þ§@¦æ¬°¡C
- ©è¾×§ðÀ»¤u¨ã¡G(1)¸É¤B³nÅé (2)«DºÞ²zûÅvµn¤J¨t²Î (3)ÀH®É§ó·s©Ò¦³¨¾¬r¡B¨¾¤ì°¨³nÅé
- ºô¸ô§ðÀ»ªº¤âªk¡G
- °»¹î¡G°e¥X°»´ú«Ê¥]¨Ó¦¬¶°§A¥D¾÷¤W±ªº¸ê°T (¥]¬A WWW ªº³nÅ骩¥»µ¥)
- ´ú¸Õ¡G¨Ì¾Ú³o¨Ç¦^À³ªº¸ê°T¡A¨Ó¤ÀªR¥i¯à¥i¥H§ðÀ»ªº³nÅé
- «I¤J¡G¶}©l¹Á¸Õ¦UºØ³nÅé§ðÀ»¡A³Ì²×¯à°÷´x´¤§Aªº¨¾¤õÀð©Î´Ó¤J¤ì°¨
- ±±¨î¡G¦w´¡«áªùµ{¦¡¡A«Ø¥ß¤@Ó±±¨î¤J¤f
- §Q¥Î¡G§Q¥Î©p¥D¾÷¤W±ªº¦UºØ¸ê·½ (¤×¨ä¬Oºô¸ôÀW¼e)
- Âà¾Ô¡G·í§@¸õªO§ðÀ»§O¤H (»ø«Í¹q¸£)
- ³Ì±`¨Ï¥Îªº³nÅé¡GÂsÄý¾¹ªº¬ÛÃö¥\¯à¤ÀªR¡G
- ActiveX ¡G Microsoft ªº IE ÂsÄý¾¹ªº ActiveX ºô¸ô§Þ³N¡A¤¹³\ IE ¨Ï¥ÎÀ³¥Îµ{¦¡ªº³¡¤À¥\¯à¡A
¥Ñ©ó¤¹³\ÃB¥~µ{¦¡ªº¹B§@¡AY¥¼¯à¾A·íªºq©w³W«h¡A¥i¯àµo¥Í¸ûÄY«ªº¸ê¦w°ÝÃD¡C
- Java ¬ÛÃöµ{¦¡¡G ¤@ºØ¸ó¥¥xªºµ{¦¡»y¨¥¡A¥i¥Î¨Ó«Ø¸m°ÊºAºô¶ªºµ{¦¡»y¨¥¡C¥Ø«eÂsÄý¾¹«Ü¦h³£¦³¤ä´© Java
ªºÀô¹Ò¥\¯à¡C¦ý»Ýnª`·N Java µ{¦¡ªº¦w¥þ©Ê¡F
- Active Content ©Î Plug-ins¡GÁ|¨Ò¨Ó»¡¡A Flash player ´N¬O¤@ºØ plugin ªºÃB¥~³nÅé¡C
- Javascript¡G ¤£¥²½sĶ§Y¥i¦bÂsÄý¾¹¤W±¹B§@ªºµ{¦¡»y¨¥¡A±`¥Î¨Ó¦s¨ú¥»¦aºÝªº¬ÛÃö¹q¸£¸ê·½¡F
- VBScript¡GÃþ¦ü Javascript ¡A¦ý¥u¾A¥Î©ó IE ¦Ó¤w¡C
- Cookies¡G Cookies ì¥ý³]p¥u¦³«Ø¸m¥Lªººô¯¸¤~¯à¦s¨ú¡A¦ý¥Ø«e«Ü®e©ö³Q¯}¸Ñ¡C
¥Dn¬O¦b¥Î¤áºÝ¹q¸£©ñ¸m¨Ï¥ÎªÌ¬ÛÃöªº¸ê®Æ¡A¥i¯à¥]¬Aµn¤Jªº±b¸¹»P±K½Xµ¥¡C
- ±j¤ÆÓ¤H¹q¸£ Windows ¨t²Î¡G
- ±j¤Æ Windows §@·~¨t²Î¥»¨¡G
- ³z¹L Windows Live Update ¥h§ó·s¡I
- ³z¹L¤u§@ºÞ²zû¥hºÊ¬Ý CPU, RAM, ºÏºÐ¾÷ªº¹B§@
- ³z¹L¨Æ¥óÀ˵ø¾¹¥hÆ[¹î¨t²Î¹B§@ªº¸ê®Æ
- ±j¤Æºô¸ô¦w¥þ¡G
- ºô¸ô¨ó©w»P NetBEUI¡GNetBIOS ©Î³\¥i¥HÃö³¬¡I½Ð¦Û¦æÀˬd¦³µL±Ò°Ê port 139 ¡H
- ³z¹L netstat »PºÞ²z¤¶±¥h±±¨î¬ÛÃöªºªA°È¥\¯à¡C
- ±j¤ÆÀ³¥Îµ{¦¡¡G
- ³Æ¥÷ Windows ªº«n¸ê®Æ¡G§Q¥Î Cwrsync ªº¶W±j³Æ¥÷¥\¯à («ö³o¸Ì¤U¸ü)
- ÂsÄý¾¹¥\¯àªº«·sq©w¡G
- ¦b IE ¤W±¨îq¡G(1)ºô»Úºô¸ô¦w¥þ©Ê«·s½Õ¾ã¬°¤¤/°ª¦w¥þ©Ê¡F (2)±N±X¤s»P¬ÛÃöªººô¯¸¥[¤J«H¥ôºô¯¸¡F
(3)±N cookies ³B²z¬°¡yÂмg¦Û°Ê cookie ³B²z¡A¨Ã©ó¡y²Ä¤@¤è cookies, ²Ä¤T¤è cookies ¡z¿ï¾Ü¡y´£¥Ü¡z¥\¯à¡F
(4)¦b¤u¨ã/ºô»Úºô¸ô¿ï¶µ/¶i¶¥¤¤¡A½Õ¾ã¦h´CÅ骺¨¾Å@¾÷¨î¡A¨ú®ø¼½©ñÁnµ»P¼v¹³¥\¯à¡C
- ¦b Firefox ¤W±¨îq¡G(1)¤Ä¿ï¡y¦bºô¯¸¸Õ¹Ï¦w¸Ëªþ¥[¤¸¥ó®É³qª¾§Ú¡z (2)«Øij¨ú®ø Java µ{¦¡¿ï¶µ¡F
(3)¦b¡y²M²zÁô¨p¸ê®Æ¡z¤¤¡A¶}±Ò¿ï¶µ¡A¥i²¾°£±Ó·Pªº¸ê°T¡C
²Ä¤G¡B¤T¶g¡G¥D¾÷ªº¦w¥þ¨¾Å@¤Jªù (½Ò¥»²Ä¤@¡B¤G³¹¤º®e)
- ¶i¦æ¦w¥þ©Ê¬ÛÃö¤è®×ªº«Ø¥ß¡A§ÚÌ»Ýn¦Ò¶qªº¶µ¥Ø¥Dn¦³¡G
- Àô¹Ò¤¤þ¨Ç¸ê²£¬O»Ýn³Q¶i¦æ«OÅ@ªº¡F
- »Ýn³Q«OÅ@ªº¸ê²£¤¤¡Aþ¨Ç¨ã³Æ¦w¥þ©Êªº·ÀI¡H
- ³o¨Ç¦w¥þ·ÀI¬O§_³y¦¨§A¹B¦æªºÀô¹Ò¤W¤§¦w¥þ¨Æ¥óªº¨Ó·½¡H
- ·sªº¤è®×©Îקï²{¦³ªº¦w¥þ¤è®×®É¡A¬O§_¦³¬ÛÃöªº¦¨¥»¦Ò¶q©Î©Ò»Ýn¿Å¶qªº¨ä¥L«D¦w¥þ¦]¯À¦s¦b¡H
- ¸ê²£¤¤¯S©w¶µ¥Øªº«OÅ@¥Dn¤À¬°¡G(1)«O±K©Ê¸ê®Æ¨Ò¦p¤@¨Ç°Ó·~§Þ³N»P (2)¥i¥Î©Ê¸ê®Æ¨Ò¦p¹q¤l¶l¥óªA°È
- ¸ê²£ªº·ÀI¥Dn¦³¡G(1)¦ÛµM¨a®`ªºµo¥Í (2)¸ê²£ÀݥΪº·ÀI (3)¥Î¤á¥»¨ªº¿ù»~ (4)µê°²ªº°T®§¸ê°T
(5)¤õ¨a»P¤ô¨aªºµo¥Í¡C
- ³q°T¤ÀªRªk¡G
- ¸ê®Æ«Ê¥]¥H¦óºØ¶Ç¿é¨ó©w¦bºô¸ô¤Wªº¥D¾÷¶¡¹B§@¡H
- ¹ï©ó¨CӨϥΪ̨ӻ¡¡Aþ¨Ç¸ê·½¬O¥i¦s¨úªº¡Hþ¨Ç¬O³Q¨îªº¡H
- þ¨Ç¸ê·½¤@©w±o¦b¨CÓ¤u§@°Ï°ì¤¤³Q¶i¦æ¨ú±oªº¡H
- þ¨Ç¸ê°T¥i¥H´£¨Ñµ¹¥~³¡¨Ï¥ÎªÌ¨Ó¦s¨ú¡H¥i³z¹L¦óºØ¤è¦¡¨Ó¨ú±o¡H
- ¤½¥q¤º³¡´£¨Ñ¤Fþ¨Ç¥~³¡ªº¸ê·½¦s¨ú¡H
- ¨Ï¥ÎªÌ¨Ï¥Î¸ê·½®É»Ýn¥I¶O¶Ü¡H
- ¬O§_¦³¥~³¡ªA°Èªº´£¨ÑªÌ¡A³o¨Ç´£¨ÑªÌ·|²o¯A¨ìþ¨Ç½d³ò¡H
- ¦w¥þ¨î¬O§_·|¼vÅT¨ì즳¨Ï¥ÎªÌªº¾Þ§@²ßºD¡H
- ±`¨£ªº§ðÀ»¤âªk¡G
- ¦s¨ú¦¡§ðÀ»¡G¿s±´ (¤H¦×·j¯Á)¡BÅÑÅ¥ (CSMA/CD¥\¯à)¡BÄdºI (Ãþ¦üºÊÅ¥¡A¦ý¬O±j¨îÄdºI°T®§)
- «§ï¦¡§ðÀ»¡GÅܧó (º¶)»P§R°£ (µn¿ýÀÉ)
- ªýÂ_¦¡ªA°È§ðÀ»¡G³æ¤@¨Ó·½¤è¦¡¡B¤À´²¦¡ªýÂ_¦¡ªA°È§ðÀ»¡I
- ±`¨£ªººô¸ô¦w¥þ«Â¯Ù¡G
- Àb«È»P©Ç«È (hack, cracker)
- ±ÂÅvªº¤º³¡¤Hû
- Hactivists¡G ¬D¾Ô¯à§_§ðÀ»¬Y¤@¥Ø¼Ð¦Ó¤J«I©Î§ðÀ»
- Script Kiddies¡G¤òÀY¤p¤l¡I
- ¤TºØ´U¤l¡G
- ¥Õ´UÀb«È (white hat hacker)¡G §ä¥X°ÝÃD§ðÀ»¦Û§Ú¡F
- ¶Â´UÀb«È (black hat hacker)¡G §Q¥Î¯}¸Ñµ{¦¡¨Ó°w¹ï¬Y¨Ç¯S©w¥Ø¼Ð¶i¦æ§ðÀ»¡A¨ú±o¦Û¤v·Qn¨ú±oªº§Q¯q
- ¦Ç´UÀb«È (grey hat hacker) ¡G »P¥Õ´UÀb«È¦³Ãþ¦üªº§Þ³N¡A¦ý¥Î¨Ó¯}¸Ñ§O¤Hªº¨t²Î¡A¦ý¤£¨£±o·|¥hÅѨú¤H®aªº¾÷±K¸ê®Æ¡C
- «Ø¸m¦øªA¾¹®É©Ò»Ýn¦Ò¶qªº¬ÛÃö¦]¯À¡G
- ¦øªA¾¹¥D¾÷Ãþ«¬ªº¬D¿ï¡G¤ä´©¦h¥Î¤á¦s¨ú¡H¤ä´©°ªt¸üºô¸ô¦s¨ú¡H¤ä´©¥i¥Î©ÊµwÅé¬[ºc¡H¥i½T«O¸ê®Æ§¹¾ã©Ê¡H
- §@·~¨t²Î¬D¿ï¡G¨Ï¥Î³Ì·sªº Linux ¡A¥B¨Ï¥Î¥ø·~ª©·|¤ñ¸û¦n¡A¬°¦ó¡H
- ¨aÃø´_쪺¤è®×³]p¡GªA°Èªº°ª¥i¥Î©Ê (³Æ´©»P±µºÞ¨t²Î)
- ®e¿ù¯¸ªº¨Ï¥Î¡G·Ç³Æ¥t¤@¥x¥i¥Îªº¬Û¦P¾÷«¬µwÅé³Æ¥Î
- ¹q¤O«OÅ@¡G¥]¬A¤£Â_¹q¨t²Î (on-line, off-line)¡B¹q·½¬ðªi«OÅ@µ¥«OÅ@§AªºµwÅé³]³Æ
- ºÏºÐªº®e¿ù¾÷¨î¡G¥]¬A¨Ï¥ÎºÏºÐ°}¦C (RAID)
- ¥D¾÷ªº¦w¥þ¨¾Å@¨BÆJ¡G
- ¥D¾÷¦s¨úªº¹êÅé¦w¥þ¡G ¦aÂI (¾÷©Ð)¡B¶i¥XºÞ¨î³æ¡BÀô¹ÒºûÅ@ (·Å«×/Àã«×/¹q¤O±±¨îµ¥)¡B§@·~¨t²Î¬G»Ù±Æ°£
- BIOS ¨¾Å@¡G ³]©w BIOS ±K½X¡A¦p¦óÅý BIOS ±K½X¥¢®Ä¡H
- Linux ªº¿ï³æ«OÅ@ (grub)
- Àɮרt²Îªº¦w¥þ°t¸m¡G ¥]¬A¤À³Îªº¸ê®Æ»P°Ñ¼Æ¡A¥H¤ÎÅvªº·§©Àµ¥¡A«ÂI¥]¬A¤À³Î (fdisk)¡B±¾¸ü (mount)¡B
Åv (rwx, ¨Ï¥Î chown, chgrp, chmod µ¥«ü¥O)¡B¯S®í³æ¤@¥Î¤áÅv (ACL)µ¥
- ªA°Èªº·s¼W»P²¾°£¡G ¥i³z¹L rpm ¥H¤Î yum ½u¤W³B²z¾÷¨î¨Ó¹B§@
-
- ¥»¶g²ßÃD»P¹ê§@¡G
- »¡©ú RAID 0, RAID 1, RAID 5 ªº®e¶q¡B®Ä¯à¡B®e¿ùµ¥¾÷¨î
- ¦b§Aªº Linux ¤W±·s«Ø¤@Ó Software RAID ¡Aµ¥¯Å¬° 5 ¡A¨Ï¥Î 3 Ó partition ºc¦¨¡A¥B«O¯d¤@Ó spare-disk
- ¨Ï¥Î fdisk -l Æ[¹î§Aªº¨t²ÎºÏºÐ¤À³Îªí¡F
- ¨Ï¥Î fdisk /dev/sda ¶}©l¶i¦æ¤À³Î¡A¨CÓ¤À³Î¨Ï¥Î 1000MB ¡F
- ¨Ï¥Î partprobe ©Î reboot ¾ã²z¦n§Aªº¤À³Îªí
- ¨Ï¥Î mdadm --create /dev/md0 --level=5 --raid-devices=3 --spare-devices=1 /dev/sda... «Ø¸m /dev/md0
- ¨Ï¥Î mdadm --detail /dev/md0 Æ[¹îºÏºÐ°}¦C
- ¨Ï¥Î /etc/mdadm.conf «Ø¸m§Aªº³]©wÀÉ
- ¨Ï¥Î mkfs -t ext3 /dev/md0 ®æ¦¡¤Æ§AªººÏºÐ°}¦C
- ½s¿è vim /etc/fstab ±N /dev/md0 ±¾¸ü¦b§Aªº /raid ¥Ø¿ý¤¤ (¦¹¥Ø¿ý½Ð¦Û¦æ«Ø¥ß)
- ¨Ï¥Î mount -a ¨Ã·f°t df ´ú¸Õ±¾¸ü»PÆ[¹î
- ¼ÒÀÀ§Aªº¬YÓ partition µo¥Í¿ù»~¡A¨ÃÆ[¹î¿ù»~±¡ªp¡A¥B¼ö©Þ´¡¦³°ÝÃDªººÏºÐ
- ¨Ï¥Î mdadm --detail /dev/md0 Æ[¹îºÏºÐ°}¦C¡A¨Ã¼ÒÀÀ¬YӺϺеo¥Í¿ù»~¡A°²³]¬° /dev/sdaX
- ¨Ï¥Î mdadm --fail /dev/md0 /dev/sdaX ¡A¦A¨Ï¥Î mdadm --detail /dev/md0 Æ[¹î¿ù»~µo¥Í
- ¨Ï¥Î mdadm --remove /dev/md0 /dev/sdaX ¨ú¥X¿ù»~ªººÏºÐ¡A¦AÆ[¹î /dev/md0
- ¨Ï¥Î mdadm --add /dev/md0 /dev/sdaX ¦A´¡¤J·sªººÏºÐ¡A¨ÃÆ[¹î /dev/md0
- ¦b§AÌ®aªº¹q¸£¥D¾÷¤W±¡A§ä¨ì BIOS ±K½X³]©w¶µ¥Ø¨Ã¹Á¸Õ³]©w±K½X¦b¤WÀY
- Àɮרt²Îªº¦w¥þ©Ê¡G¦p¦ó«Ø¸m±MÃD¤p²Õªº¦@¨É¥Ø¿ý
- §Q¥Î useradd / groupadd µ¥«ü¥O¡A«Ø¥ß dicgroup ¸s²Õ¡A¥H¤Î¦b¦¹¸s²Õ¤ºªº dicuser1, dicuser2, dicuser3
- «Ø¥ß¦@¨Éªº /srv/dicgroup ¸s²Õ¡Aª`·NÅv¥\¯à
- ±N /etc/shadow ½Æ»s¨ì /srv/dicgroup ¡A¥B»ÝnÅý dicgroup ªº¤HÌ¥i¥H¶i¦æŪ¼g°Ê§@
- Àɮרt²Îªº¯S®íÅv³]©w¡G ACL (Access Crontrol List) ¥\¯à
- ¥Î¹w³]È«Ø¥ß dicteacher ±b¸¹
- ¤Wz±b¸¹¦b /srv/dicgroup ¤º¶È¯àŪ¨ú¡A¤£¥i¼g¤J»Pקï
- Æ[¹î§A¥Ø«e¨t²Î¤W±ªºªA°È¸ê®Æ¡G
- ¦³¨S¦³¦w¸Ë httpd ³o¤äµ{¦¡¡H
- ³o¤äµ{¦¡¹w³]¦³¨S¦³¶}¾÷±Ò°Ê¡H
- ¦p¦ó¥ß§Y±Ò°Ê¡H
- ¦p¦óÆ[¹î³q°T°ð¤f¡H
- ¦p¦óÆ[¹îµ{§Ç (PID) ¡H
- §R°£±¼¤£»ÝnªºªA°È§a¡I¨Ì¾Ú¦Ñ®v¦b¥Õª©¤W±ªº³]©wÈ¡A±N§AªºªA°È¶i¦æ³B²z¡C
²Ä¥|¶g¡G¥[±Kºtºâ»P¾ÌÃҨϥΠ(½Ò¥»²Ä¤T³¹¤º®e)
- ¥[±K»P¸Ñ±K¡G
- ¥[±K¡G³z¹L½ÆÂøªº¨ç¼Æ¥H¤Î/©Î¯S§Oªºª÷Æ_¡A±N©ú¤å°T®§Âন±K¤å¶Ã½Xªº¤@Ó¹Lµ{¡F
- ¸Ñ±K¡G»P¥[±K¹Lµ{¬Û¤Ï¡A³z¹L½ÆÂøªº¨ç¼Æ»P¸Ñ±Kª÷Æ_±N±K¤å¶Ã½XÂন¥i¨Ñ¬d¾\ªº©ú¤å°T®§¡C
- ¹ïºÙ¦¡ª÷Æ_ºtºâªk¡G
- §Q¥Î¦P¤@§âª÷Æ_¶i¦æ¥[±K»P¸Ñ±Kªº§@·~¡F
- ¥Ñ©ó¥u¦³¤@§âª÷Æ_¡A¦pªGª÷Æ_¿ò¥¢¡A®e©ö³y¦¨¦w¥þ©Êªº°ÝÃD¡F
- ±`¨£ªº¾÷¨î¦³¡GDES, Triple DES, Skipjack, IDEA, RC5, Blowfish, AESµ¥¡C
- «D¹ïºÙ¦¡ª÷Æ_¨t²Î¡G
- ³q°TÂù¤è³£¦³¤@¹ïª÷Æ_¡A¤À§O¬°¦øªA¾¹´£¨Ñªº¤½Æ_(public key)¥H¤Î¥Î¤áºÝ¹q¸£¹Bºâ¥Xªº¨pÆ_(private key)¡F
- ¤@¯ë¨Ó»¡¡A¤½Æ_¥Î¦b¥[±K¾÷¨î¡A¦Ó¨pÆ_«h¬O¥Î¦b¸Ñ±K¤è±¡F
- ¨pÆ_³q±`¬O¥Î¤áºÝ¦Û¦æ¹Bºâ¥X¨Óªº¡A©Ò¥H쥻´N¬O¦³«O±Kªºª¬ºA¡F
- ±`¨£ªº¾÷¨î¡GDiffie-Hellman, RSA
- Âø´êºtºâªk (hash algorithm)
- ±N¥ô·Nªø«×ªº¸ê®ÆÂন©T©wªø«×ªº¿é¥X¡A³oÓ¿é¥X¦r¦ê«K¬OÂà´«¦r¦êªºÂø´êÈ¡F
- ³q±`¬O¤@ºØ³æ¦Vªººtºâ¤è¦¡¡AµLªk°f¦V¸ÑªR¡F
- ±`¨£ªº¹Bºâ¾÷¨î¦³¡GMD5, SHA1, RipeMD-160 µ¥µ¥
- ¨Ï¥ÎªÌªº±K½X«OÅ@¡G
- Linux ¥Î /etc/passwd, /etc/shadow ¦s©ñ¨Ï¥ÎªÌ¸ê®Æ¡F
- ¥i¨Ï¥Î finger Àˬd¨Ï¥ÎªÌªº°Ñ¼Æ¡F
- ¥i¨Ï¥Î chage -l Æ[¹î¨Ï¥ÎªÌªº±K½X°Ñ¼Æ¡C
- ¾ÌÃÒªº¨Ï¥Î¡G
- ¾ÌÃÒªº¨Ï¥Î¥Dn¦³¥|¤j³¡¤À¤¸¥ó²Õ¦¨¡G¾ÌÃÒºÞ²z¤¤¤ß¡Bµù¥UºÞ²z¤¤¤ß¡B«D¹ïºÙ©Ê¥[±Kºtºâªk(RSA)¡B¼Æ¦ì¾ÌÃÒ¡F
- ¥Ø«eÂsÄý¾¹§¡¤w¤º«Ø https ªº¾ÌÃÒ¬d¸ß»P°O¿ý¥\¯à¡C
- ¦w¥þ³s½u¾÷¨î¡G
- ³z¹L ssh ±b¸¹@¥D¾÷IP ³s½u¨ì»·ºÝ¥D¾÷¤W¡F
- ³z¹L scp -r ÀÉ®× ±b¸¹@¥D¾÷IP:/»·ºÝ¥D¾÷/¥Ø¿ý §Y¥i¶i¦æ¤W¶Ç¡F
- ³z¹L rsync -av -e ssh ÀÉ®× ±b¸¹@¥D¾÷IP:/»·ºÝ¥D¾÷/¥Ø¿ý §Y¥i¶i¦æ¤W¶Ç/¤U¸üªº¬M®g¸ê®Æ¡F
- ³z¹L sftp ±b¸¹@¥D¾÷IP §Y¥i¨Ï¥ÎÃþ¦ü FTP ªºÀɮ׶ǿé¥\¯à¡C¥ç¥i¨Ï¥Î gftp ¨Ó³B²z¡C
- ¦pªG¤½Æ_°O¿ý¥¢®Ä¡A¥iקï ~/.ssh/known_hosts ¤ºªº°O¿ý¸ê®Æ¡F
- ¥i³z¹L¦¨¹ïªºª÷Æ_¨t²Î¶i¦æ§K±K½Xªºµn¤Jª¬ºA¡C
- ¥»¶g²ßÃD»P¹ê§@¡G
- ³z¹L mkpasswd ¥H¤Î md5sum ÀË´ú§Aªº¨t²Î«ü¯¾¸ê®Æ¡F
- ³z¹L ssh ªº¦¨¹ïª÷Æ_¾÷¨î¡A«Ø¥ß§K±K½Xªº¥iµn¤J¥\¯à¡G
- ¦b¥Î¤áºÝ«Ø¥ß¦¨¹ïªºª÷Æ_¡G ssh-keygen¡F
- ¦b¨Ï¥ÎªÌªº ~/.ssh/ ¤º¡A±N .pub ªº¤½Æ_¤W¶Ç¨ì¦øªA¾¹¤W¡A¨Ã¥B§ó¦W¡F
- ³s½u¦Ü¦øªA¾¹¤W¡A±N¸ÓÀÉ®×Âà¦s¦¨¬° ~/.ssh/authorized_keys ¡F
- .ssh/ ¥²¶·¬O 700¡A¦Ó authorized_keys ¥²¶·n¬O 644 ¡C
- §Q¥Î rsync °t¦X ssh ³s½u³q¹D¡A±N§A¥D¾÷¤W±ªº¸ê®Æ¬M®g¨ì 192.168.42.41 ¨º³¡¥D¾÷¥h¡C¨Ã½Ð¯d·N¡G
- §A±on¨Ï¥Î siteXX (XX ¥Nªí§Aªº¥D¾÷¸¹½X) §@¬°±b¸¹¡Aµn¤J¨ì¸Ó¾÷¾¹¤¤¡F
- ¨Ï¥Î siteXX ±b¸¹®É¡A¤£»Ýn¥Î¨ì±K½X (siteXX ªº±K½X»P±b¸¹¬Û¦P)¡F
- ±N§Aªº /etc ½Æ»s¨ì»·ºÝ¥D¾÷ªº ~siteXX/backup/etc ¥h¡F
- ¨C¶g¤éâ±á 1:15 ¶i¦æ¦¹¶µ§@·~¡C
²Ä¤¶g¡G¨¾¤õÀð«Ø¸m»P¦w¸Ë (½Ò¥»²Ä¥|¡B¤¡B¤»¡B¤C¡B¤K³¹¤º®e)
- Æ[¹î°ð¤fªº«ü¥O¡G netstat ¡A±`¥Î¿ï¶µ¦³¡G
- -l ¡GÅã¥ÜºÊÅ¥°ð¤f¡F
- -p ¡GÅã¥Ü PID »P progra
- -t ¡GÅã¥Ü TCP «Ê¥]Ãþ«¬ªº³s½u
- -u ¡GÅã¥Ü UDP «Ê¥]Ãþ«¬ªº³s½u
- -a ¡GÅã¥Ü©Ò¦³³s½u¸ê®Æ¡A²z½×¤W¤£À³»P -l ¦P®ÉÀ³¥Î
- °ð¤f±½ºË«ü¥O¡G nmap ¡A²©ö¨Ï¥Î¤è¦¡¡G¡ynmap localhsot¡z«á±¥[¤W IP ©Î¥D¾÷¦WºÙ´N¬O¤F¡I
- -sS ¡G¨Ï¥Î TCP sync ±½ºË¡A¦ý¤£°õ¦æ§¹¾ãªº TCP ¤T¦V¥æ´¤¡A¶È°õ¦æ ACK-SYN ¦Ó¤w¡F
- -sT ¡G§Q¥Î TCP ¤T¦V¥æ´¤¥h±½ºË TCP °ð¤f¡F
- -sA ¡G³z¹L ACK Stealth ±½ºË¡A¦C¥X±½ºË¹ï¶Hªº¨¾¤õÀð°t¸mª¬ºA¡A¤£¦C¥X TCP °ð¤f
- -sW ¡GTCP Window ±½ºË¡AÃþ¦ü TCP ACK¡A¦ý·|¦C¥X TCP °ð¤f¡F
- -sU ¡GUDP ±½ºË¡F
- -sN ¡GTCP Null ±½ºË¡A³z¹L TCP µLºX¼Ð«Ê¥]¨Ó®æ¦¡¨Ó±½ºË¡F
- -sF ¡GTCP Fin ±½ºË¡F
- -sI ¡GIdle ±½ºË¡A¥Dn±½ºË´¿¸g³Q¤J«I§ðÀ»©ÎªÌ¬O³Q¥Î¨Ó°µ¬°¸õªOªº»ø«Í¥D¾÷
- -sP ¡G³z¹L icmp «Ê¥]®æ¦¡¨Ó±½ºË¦Ó¤w¡A¥i§PÂ_¸Ó¥D¾÷¬O§_¨ã¦³ ICMP ªº¦^À³¥\¯à¡C
- °ò¥»ªº¨¾¤õÀðÃþ«¬¡G
- «Ê¥]¹LÂo¦¡¡G Netfilter (iptables)¡F
- ¨Ì¾Úµ{¦¡¶i¦æ¹LÂo¡G TCP Wrappers
- TCP Wrappers ªº¨¾¤õÀð¾÷¨î¡G
- ³z¹L /etc/hosts.allow ¤Î /etc/hosts.deny ¶i¦æ©è¾×¡F
- ²©ö»yªk¬°¡G¡y program : IP ¥D¾÷¦WºÙ IP/netmask ¡z
- ¥ý¤ÀªR¸Ó³nÅ骺µ{¦¡¦³¨S¦³¤ä´© TCP Wrappers ¤~¯à°÷¨Ï¥Î
- ¥un¬O Xinetd ºÞ²z³£¡A³£¦³¤ä´©¡A¨ä¥Lªº´N±on³z¹L¡y ldd program ¡z¨Ó§PÂ_ (libwrap)
- «Ê¥]¹LÂo¦¡ªº¨¾¤õÀð³q±`¥i¥HºÞ²zªº¸ê®Æ¦³¡G
- OSI ²Ä¤G¼h (¸ê®ÆÃìµ²)¡G MAC (ºô¥d¥d¸¹)
- OSI ²Ä¤T¼h (ºô¸ô¼h)¡G IP, ICMP (Ãþ§O 0 »P 8 n¯S§O°O¾Ð)
- OSI ²Ä¥|¼h (¶Ç¿é¼h)¡G TCP, UDP, port, ¯S®íºX¼Ð (syn, ack...)
- iptables ªº³W«hÆ[¹î¡Giptables-save
- iptables ¤¤¡A°w¹ï¥»¾÷©Ò»Ýn³q¹Lªº±`¨£Ãì (ÄÝ©ó filter ªí®æ)
- INPUT (³Ì±`¥Î¨ÓºÞ¨îªº¤@¶µ)
- OUTPUT
- FORWARD
- iptables ªº°ò¥»»yªk - ²M°£³W«h¡G
- iptables -F (-t nat)¡G²M°£³W«h
- iptables -X (-t nat)¡G²M°£¦ÛqªºÃìµ²
- iptables -Z (-t nat)¡G²M°£²Îp¸ê®Æ
- iptables ªº°ò¥»»yªk - q©w¬Fµ¦¡G
- iptables -P {INPUT|OUTPUT|FORWARD} {ACCEPT|DROP|REJECT}
- iptables ªº°ò¥»»yªk - ³Ì°ò¦»yªk²¤¶¡G
- iptables [-A INPUT] [-i lo,eth0] [-s IP/netmask] [-d IP/netmask] [[-p tcp,udp]
[--dport °ð¤f] [--sport °ð¤f]] [[-p icmp] [--icmp-type ¸¹½X]] [-j ACCEPT,DROP,REJECT,LOG]
- iptables ªº°ò¥»»yªk - «nªº¼Ò²Õ¡G
- iptables -A INPUT -m state --state ESTABLISHED,RELATED
- iptalbes -A INPUT -m mac --mac-source aa:bb:cc:dd:ee:ff
- §Q¥Îµ{¦¡±±¨î§@¬°¨¾¤õÀð¡A¥H¥N²z¦øªA¾¹ proxy ¬°¨Ò¡G
- ¥N²z¦øªA¾¹ªºì²z¡G¥N²z¥Î¤áºÝ¨ì Internet ¥h®»¨ú¸ê®Æ¨Ó¦^À³¡F
- ¥Ñ©ó¦^À³«e·|¥ý¼g¤@¥÷³Æ¥÷¨ìµwºÐ§Ö¨ú¡A¤U¤@ÓŪ¨ú¬Û¦P¸ê®Æªº¥Î¤á¡A¥iª½±µ³z¹L proxy ªº§Ö¨ú¸ê®Æ±o¨ì¡F
- ¬°À³¥Îµ{¦¡¼h¯Åªº¨¾¤õÀð¥\¯à¡C
- ¦b Linux ©³¤U¡A¥i³z¹L squid ³oÓµ{¦¡¨Óµ¹¤©³B²z
- squid.conf ªº¥Dn³]©wÈ¡G
- http_port 3128
- cache_mem 16
- cache_dir
- visible_hostname
- acl name src IP/netmask
- acl name dst IP/netmask
- acl name dstdomain ¥D¾÷¦W
- http_access [allow|deny] name
- Ãö©ó NAT (Network Address Translation, NAT) ¡G
- NAT §Þ³N©ÎºÙ¬° IP ±»½ª (ºô¸ô±»½ª)¡A¬O¤@ºØ¥Î¨Ó¨ú¥N¨Ó·½©Î¬O¥Ø¼Ð¦ì§}ªº§Þ³N¡A¥i¥H±N IP ªíÀYªº IP/port ¶i¦æ°°¸Ë¡C
±`¥Î©ó¶È¦³¤@Ó¹ï¥~ IP (public IP) ¦ý«o¦³¦h¥x¹q¸£ªºÀô¹Ò (·Q¹³¤@¤U±Ð«Ç´N¬O°Õ)
- NAT ¨Ì¾Úק諸¨Ó·½©Î¥Øªº¡A¦Ó¤À¬° SNAT (source NAT, קï¨Ó·½) ¥H¤Î DNAT (Destination, קï¥Øªº¦a)¡C
- IP ¤À¨É¾¹ªº¥\¯à (SNAT)¡G
- ±Ò°Ê®Ö¤ß¸ô¥ÑÂ໼¯à¤O¡G vim /etc/sysctl.conf, ¤º³¡ªº ip_forward ³]©w¬° 1¡F
- ¹ê»Ú±Ò°Ên sysctl -p ¡A¥B¬d¾\ /proc/sys/net/ipv4/ip_forward ¬O§_¬° 1 ©O¡H
- ³Ì²×¦A³z¹L iptables ªº IP °°¸Ë¯à¤O¡G
- iptables -t nat -A POSTROUTING -o eth0 -s ºô°ì/¤lºô¸ô¾B¸n -j MASQUERADE
- ±N server ¬[³]¦b¨¾¤õÀ𤧤º¡A´N¬O DNAT Åo¡I
- ¤@³¡¥D¾÷ IP ¬° 192.168.42.41¡A¾Ö¦³ port 80 ªº http ¥\¯à¡F
- ·í¥ô¦ó¤H³s½u¨ì§Aªº port 8080 ®É¡A§A±N¥L¾É¦V¸Ó¥D¾÷ªº port 80 ¡G
- iptables -t nat -A PREROUTING -p tcp -d 192.168.42.xx --dport 8080 -j DNAT
--to-destination 192.168.42.41:80
- ¥»¶g²ßÃD»P¹ê§@¡G
- Æ[¹î¸ô¥Ñªí¡A§ä¨ì¸ô¥Ñ¾¹¡A¨ÃÀË´ú¤@¤U¡A¸Ó¸ô¥Ñ¾¹¦³±Ò°Ê¤°»ò TCP »P UDP ªº°ð¤f¡H
- dovecot ¬°¦¬«H¥\¯àªº³nÅé¡A°²³]§Ṳ́µ¤Ñ·Qn±Ò°Ê pop3 ³oºØ¦¬«H¾÷¨î¡G
- Àˬd¦³µL¦w¸Ë dovecot ¡AYµL¦w¸Ë½Ð¦w¸Ë¥L¡F
- ½s¿è /etc/dovecot.conf ¡A§ä´M protocol ¡A½Ð±Ò°Ê pop3 ¾÷¨î§Y¥i¡F
- ±Ò°Ê dovecot ¡A¨Ã¥B·|¶}¾÷·|¦Û°Ê±Ò°Ê
- Æ[¹î pop3 ªº°ð¤f¦³¨S¦³±Ò°Ê¡F
- Àˬd dovecot ¦³¨S¦³¤ä´© TCP Wrappers ¡H
- ²{¦bnÅý 172.25.0.0/16 ¨S¦³¿ìªk¨Ï¥Î POP3 ¡A¸Ó¦p¦ó³B²z¡H
- ¨Ì¾Ú©³¤U¦æ¬°¡A»s§@§Aªº¨¾¤õÀð¸}¥»¡A¨Ã±N¨¾¤õÀð¸}¥»Âмg¦Ü¥¿½Tªº³W«h¨îqÀɤ¤
- ²M°£©Ò¦³³W«h
- INPUT ¬° DROP ¨ä¾l¬° ACCEPT
- lo ¬°«H¥ô¸Ë¸m
- ¨Ó¦Û eth0 ¥B¬° 192.168.42.0/24 ªº«Ê¥]¡A§¡¬O«H¥ôºô°ì
- ¥un¬O¦Û¤vµo¥Xªº¦^À³«Ê¥]¡A³q³q¤©¥H±µ¨ü
- ¨Ó¦Û 172.16.0.0/16 ªº¨Ó·½¡A§¡¥i¨Ï¥Î§Aªº POP3 ªA°È¡F
- ¨Ó¦Û 172.17.0.0/16 ªº¨Ó·½¡A§¡¥i¨Ï¥Î§Aªº SSH ¥\¯à¡F
- §Aªº http ¦³¹ï¥þ¥@¬É¶}©ñ¡F
- §Aªº FTP ¥u¹ï 172.18.0.0/16 ªº¨Ó·½¶}©ñªA°È
- °õ¦æ¸}¥»¡AÆ[¹î¤§¡AY¨S¦³°ÝÃD¡A½ÐÂмg¨ì¥¿½Tªº³W«hÀɤ¤
- ³]©w¥N²z¦øªA¾¹ squid
- ¦w¸Ë¦n squid ¨Ã¥B±Ò°Ê squid ¡A¥B³]©w¬°¨C¦¸¶}¾÷§¡±Ò°Ê
- ³]©w squid ªº±Ò°Ê°ð¤f¬° 8080
- ³]©w cache_dir ¹w³]Èקï¤@¤U¡A°²³]¨Ï¥Î¤F 500MB ªº®e¶q¡F
- Åý 192.168.42.0/24 ¥H¤Î 192.168.1.0/24 §¡¥i¨Ï¥Î§Aªº proxy
- Åý§Aªº¥Î¤á¤£¥i¥H¨Ï¥Î www.bing.com ³oÓºô°ì
- Åý§Aªº¥Î¤á¤£¥i¥H¨Ï¥Î .sexy.com ³oÓºô°ì
- ³]©w¥Î¤áºÝÂsÄý¾¹¡A«ü©w³oÓ proxy ¡A¨Ã¥B¶i¦æ´ú¸Õ
- Àˬdµn¿ýÀÉ¡A¬Ý¬Ý¬O§_¦³¥¿½Tªºµ¹¤©°O¿ý¸ê®Æ¡H
- ¹ê§@ squid ªº¨¥÷»{ÃÒ¡I¤£»Ýn¥[¤J IP ºô¬qªº«H¥ôÈ¡Aª½±µµ¹¤©±b¸¹/±K½X§Y¥i¨Ï¥Î§Aªº Proxy ¡C
- ¦b squid.conf ¤º¥[¤J¦p¤Uªº°Ñ¼Æ¡G
- ±K½X©Ò¦bÀɮסGauth_param digest program /usr/lib/squid/digest_pw_auth /etc/squid/proxy_passwd
- ±Ò°Êµ{§Ç¼Æ¶q¡Gauth_param digest children 5
- Åã¥Ü¦bµøµ¡¦r¡Gauth_param digest realm This is squid web proxy
- ²MªÅ¼È¦s®É¶¡¡Gauth_param digest nonce_garbage_interval 5 minutes
- ÅçÃÒ¦^À³®É¶¡¡Gauth_param digest nonce_max_duration 30 minutes
- ³Ì¦h¹Á¸Õ¦¸¼Æ¡Gauth_param digest nonce_max_count 50
- ¤¹³\ÅçÃÒacl ¡Gacl allowed_users proxy_auth REQUIRED
- ¤¹³\ÅçÃÒ³q¹L¡Ghttp_access allow allowed_users
- ±N /etc/squid/proxy_passwd ¤º¥[¤J±b¸¹±K½Xªº¬ÛÃö¸ê°T¡A¨Ò¦p¡G
- ³Ì«á±on«·s±Ò°Ê /etc/init.d/squid restart
- ³Ì²×¦A´ú¸Õ¬Ý¬Ý¡A±Ò°Ê§AªºÂsÄý¾¹³]©w¸Õ¬Ý¬Ý¡C(§A¥i¯àÁÙ±on±N¦Û¤vªº Intranet IP ¨ú®ø¦b
squid.conf ¤º¤~¦æ¡I)
²Ä¤»¶g¡G¤J«I°»´ú¨t²Î (½Ò¥»²Ä¤E³¹)
- ¤J«I°»´ú (Intrusion Detection) ¡A³z¹L¤@¨Ç¥D¾÷°O¿ýªºÃÒ¾Ú¨Ó¬dÅç¬O§_³Q§ðÀ»ªº±¡¹Ò
- ºô¸ôºÊ±±¨t²Î¡G tcpdump ¯Â¤å¦r¤¶±
- ºô¸ôºÊ±±¨t²Î¡G³z¹L ntop ³nÅé¥\¯à
- ³Ì²³æ¤è«Kªº¤J«I°»´úÀË´ú¨t²Î¡G rootkit hunter
- »s§@¨t²Îªº«ü¯¾½X¡G Tripwire ³nÅé
²Ä¤C¶g¡G«nªA°Èªº¸ê®Æ¥[±K¥\¯à
- ftp ªº chroot ¥\¯à¡G
- ftp Âର ftps ªº¥\¯à¡G(http://www.brennan.id.au/14-FTP_Server.html)
- «Ø¥ß SSL ªº¾ÌÃÒÀÉ¡G
#cd /etc/pki/tls/certs
# make vsftpd.pem
- קï vsftpd.conf ªº¤º®e¡G
ssl_enable=YES
allow_anon_ssl=NO
force_local_data_ssl=NO
force_local_logins_ssl=YES
ssl_tlsv1=YES
ssl_sslv2=NO
ssl_sslv3=NO
rsa_cert_file=/etc/pki/tls/certs/vsftpd.pem
- apache ªº SSL ¥\¯à
- apache ªº«n¸ê®Æ»{ÃÒ¥\¯à (.htaccess)
- ftp / apache ªº¨Ï¥ÎªÌ±b¸¹ºÏºÐ°tÃB (quota) ¥\¯à
²Ä¤K¶g¡G´Á¥½¦ÒÃDÁ`¾ã²z
- §A¨t²Îªº SELinux ½Ð±N¥L½Õ¾ã¦¨ Permissive ªº¼Ò¦¡¡F
- §Ú·QnÅý§Aªº¨t²Î§ó¥[¦w¥þ¡A©Ò¥H³nÅ骺§ó·s¬O«Ü«nªº¡C½Ð¨Ì§Ç¶i¦æ¡G
- ¥ýקï yum ³]©wÀÉ¡AÅý§A«e©¹ http://ftp.ksu.edu.tw/ ¨ú±o os ¤Î updates ³o¨âÓ repository
- ½Ð¶i¦æ¥þ¨t²Îªº§ó·s¡A¥B¦b§ó·s§¹²¦«á¡A¨Ï¥Î·sªº®Ö¤ß¶}¾÷¡F
- ³]©w¨C¤Ñªºâ±á 3:10 ¶i¦æ¤@¦¸¥þ¨t²Î§ó·s¡C
- §Ú·QÅý¨t²Î¨ã¦³°ò¥»ªº¨¾¤õÀð¡A¦]¦¹½Ð¨Ì¾Ú¦p¤Uªº³W«h¶¶§Ç¡A³]©w¦n§Aªº¨¾¤õÀð³W«h¡G
¬Fµ¦µ¹¤©¤è±¡G
- ²M°£©Ò¦³³W«h (¥]¬A filter »P nat ªí®æ)
- INPUT ¬° DROP ¨ä¾l¬° ACCEPT
³W«h¶¶§Ç¤è±¡G
- lo ¬°«H¥ô¸Ë¸m
- ¨Ó¦Û eth0 ¥B¬° 192.168.42.0/24 ªº«Ê¥]¡A§¡¬O«H¥ôºô°ì
- ¥un¬O¦Û¤vµo¥Xªº¦^À³«Ê¥]¡A³q³q¤©¥H±µ¨ü
- ©ñ¦æ©Ò¦³ªº icmp «Ê¥]
- ¨Ó¦Û 172.16.0.0/16 ªº¨Ó·½¡A§¡¥i¨Ï¥Î§Aªº POP3 ªA°È¡F
- ¨Ó¦Û 172.17.0.0/16 ªº¨Ó·½¡A§¡¥i¨Ï¥Î§Aªº SSH ¥\¯à¡F
- §Aªº http ¦³¹ï¥þ¥@¬É¶}©ñ¡F
- §Aªº FTP ¹ï¥þ¥@¬É¶}©ñ
°õ¦æ¸}¥»¡AÆ[¹î¤§¡AY¨S¦³°ÝÃD¡A½ÐÂмg¨ì¥¿½Tªº³W«hÀɤ¤
- «Ø¥ß¤@Ó Software RAID ¡A©Ò»Ýnªº°Ñ¼Æ¦p¤U¡G
- ½T»{ /dev/sda8 ¥H«eªº partition ¥²¶·n«O¯d¡A©³¤U·s¼W /dev/sda9 ¥H«á¤À³Î¼Ñ
- ¦@¦³ 5 Ó¬Û¦P®e¶qªº¸Ë¸m¡A¨CӸ˸m 1.2GB (partition ªº¤j¤p)¡F
- ¥|Ó¤@²Õ«Ø¸m¦¨¬°¤@Ó level 5 ªº³nÅéºÏºÐ°}¦C¡A¥BÃB¥~§t¦³¤@Ó spare disk ¡A©Ò¥HÁ`¦@ªá¶O 5 Ӹ˸m¤§·N¡F
- ³oӺϺа}¦C³Q®æ¦¡¤Æ¦¨¬° ext3 ªºÀɮרt²Î¡F
- ³oÓ·sªººÏºÐ°}¦C³Q±¾¸ü¨ì /home ³oӥؿý¤U¡A¥B¥[¤J acl ±±¨î°Ñ¼Æ¡F
- ³oÓ·sªºÀɮרt²Î¦b¨C¦¸¶}¾÷«á³£·|¦Û°Ê±¾¸ü (/etc/fstab)
- ±b¸¹«Ø¸m¡A§Ú»Ýnªº±b¸¹¦p¤U¡A½Ð¨Ì§ÇÀ°§Ú«Ø¥ß¥L¡G
- «Ø¥ß¤@Ó¸s²Õ¡A¦WºÙ¬° examgroup
- «Ø¥ß¤TÓ±b¸¹¡A³o¤TÓ±b¸¹ªº¦³¥[¤J examgroup ¸s²Õ¡A¤TÓ±b¸¹¦WºÙ¬°¡G examuser1, examuser2, examuser3
- ³o¤TÓ±b¸¹ªº±K½X§¡¬° password
- ³o¤TÓ±b¸¹ªº¦@¨É¥Ø¿ý³]©w¦b /home/examdir/ ¤¤¡A½Ð¦Û¦æ³B²z¥¿½TªºÅv³á¡I
- ±b¸¹«Ø¸m¡A§Ú»Ýnªº¯S®í±b¸¹»P¥\¯à¦p¤U¡G
- «Ø¥ß¤@Ó¿W¥ßªº±b¸¹¡A¦WºÙ¬° examcheck¡A±K½X¬° password ¡A¤£ÄÝ©ó examgroup ¸s²Õ¡F
- ³oÓ±b¸¹n¯à°÷¶i¤J»P¹î¬Ý /home/examdir/ (»Ý¦³ r,x Åv)¡C
- ±b¸¹±±ºÞ¡A§Ú»Ýn±N©Ò¦³±b¸¹ªººÏºÐ°tÃB³]p¦¨¬°¦p¤U¼Ò¼Ë¡G
- ¥Dn±±¨î /home ³oÓ filesystem ªººÏºÐ°tÃB (½Ð³B²z /etc/fstab µ¥°Ê§@)
- examuser1, examuser2, examuser3 ªººÏºÐ°tÃB¡AºÞ¨îªº¬O®e¶q¡A¥B soft ¬° 100MB ¡Ahard ¬° 200MB
- examcheck ªººÏºÐ°tÃB«h¬° soft 50MB, hard 100MB
- ²§¦a³Æ´©¡A§A»Ýnªº¬O rsync ³oÓ«ü¥O¡A¥B§A¦³¤@Ó±b¸¹¦WºÙ¬° guestXX ¦b 192.168.42.42 ¨º³¡¥D¾÷¤W¡AµM«á¡G
- §A»Ýn¥i¥H¦Û°Êªº¨Ï¥Î ssh ¥H guestXX ±b¸¹µn¤J¸Ó¨t²Î¡A¤£»Ýn±K½X
- §A»Ýn±N§Aªº /home, /etc ³Æ¥÷¨ì 192.168.42.41:/home/guestXX/backup/ ·í¤¤ (³z¹L rsync)
- §A»Ýn¨C¤Ñâ±á 5:10am ¶i¦æ¤Wz°Ê§@¡C
- §A»Ýn±Ò°Ê¥N²z¦øªA¾¹¡A±Ò°Êªº«ÂI¦p¤U¡G
- §A»Ýn±Ò°Ê proxy °ð¤f¬° 3128
- ³o³¡ proxy ¥i¥H´£¨Ñ 192.168.42.0/24 ¨Ó¨Ï¥Î¥N²z¦øªA¾¹ªº¥\¯à¡C
- ¨t²Î°»´ú¥\¯à¡G§A»Ýn¨C¤Ñ 3:30am ¶i¦æ rootkit hunter ªº¦Û°Ê°»´ú¥\¯à³á¡I(¤£¥Î¶i¦æ)
- examuser1 µ¥¤H§¡¥i¨Ï¥Î ftp ¡A¦ý¨CӥΤ᳣¹w³]³QÂê¦í¦b®a¥Ø¿ý¤º (chroot)
- ·í¦³¤H¨Ï¥Î http://§AªºIP/secure/ ®É¡A¿Ã¹õ·|¥X²{»Ýn¿é¤J±b¸¹±K½Xªº¸ê°T¡A¥B¥un¿é¤J±b¸¹¬° exam ¡A±K½X¬° password ¡A
¥L´N·|¬Ý¨ì¿Ã¹õ¥X²{¡G¡y You can access this directory ¡zªº¦r¼Ë¤F¡I