wA@As峹аѦo

bФFy¦zBysu port number zByɯŮMzAAӷdzƭnW Internet FܡHIpGuOQnW Internet hsA۵MSDApGOQn Internet }AȡA̦n٬O{Ѥ@Uw|n@ǡCHM]sFA port ]FAٻݭn{ѤwڡHIIMաI]Oڭ̪D|QsM|}HΪ_ (DoS)ҧxZڡIboӳ`̭Aڭ̷|yLФ@ǰ¦@[AרOtκ޲zӭnƱoI

1. ʥ]suiJDy{
@@1.1 ʥ]iJDy{
@@1.2 D@O@Gv]wBMsBSELinux
2. DӳvWGACL ϥ
@@2.1 O ACL H
@@2.2 pҰ ACLH
@@2.3 ACL ]wޥG getfacl , setfacl
3. @DZ`kPDO@觋
4. QJI᪺״_u@
@@4.1 ޤHB~ޥP
@@4.2 JI_u@
5. I^U
6. ҫm
7. ѦҸ
8. w糧媺ijGhttp://phorum.vbird.org/viewtopic.php?p=114062

ʥ]suiJDy{
bo@Aڭ̭nQתOAӦۤ@ӺWsunDQiJڭ̪DɡA oӺʥ]biJDڨoƪӬy{OpHAѤFӬy{A A~|o{GӨtξާ@򥻷OpnI ӧA]~|AѭnpO@ADwoIܤֻA̻@@@C


ʥ]iJDy{
b¦`ڭ̽ͨLثe[cDnO TCP/IP DA ӵjsuOVA𫟺SH TCP ʥ]NC t~Aھ Server/Client suVP TCP/IP Aڭ̷|Dإߤ@iasuݭn@ Socket Pair UA Y諸ӷPؼФ IP P port oAHϳsuݥiHQs۹諸γnWC

Wͨ쪺odzOݩ¦Abo̧ڭ̭nͪOAno TCP ʥ]QiJ Linux DWA Mϥ port ҹnӦstΪɮרtθ귽ɡAٱongLdOH |ҨӻApGA Linux D} WWW port 80 AȡA port 80 OѤ@ӦW٬ httpd {ұҰʪAoӵ{]wɬ httpd.conf A Client suniJA Linux D WWW ɡA |gL򶥬qOH򥻤WA|gLpUϪXӶqG

ʥ]iJy{
Ϥ@Bʥ]iJy{

  1. ʥ]LoGIP Filtering Net Filter
    niJ Linux ʥ]|qL Linux ֤ߪw]ANO٬ IP Filter Net Filter NNA ²檺ANO iptables oӳnҴѪ\Ciptables o Linux w]niHwʥ] IP, port, MAC, HγsuAp SYN, ACK ƶiRA HLow諸ʥ]OI|ҨӻApG IP aaa.bbb.ccc.ddd OӴcNӷA ANiHzL iptables רӦ۸ IP ʥ]suAHF򥻪D\C oڭ̷|bU@`JAѡC

  2. ĤGhGTCP Wrappers
    qL IP Filter Aʥ]|}l Super daemons TCP_Wrappers AӬOOH IFNO /etc/hosts.allow P /etc/hosts.deny ]wɥ\oC oӥ\]Ow TCP Header iARAP˧AiH]w@ǾөY IP Port Anӷݪʥ]QγqLF

  3. A (daemon) \G
    eoӰʧ@򥻤WO Linux w]\AӳoĤTӨBJNOݩn\FC |ҨӻAAiHb httpd.conf oӳ]wɤWdY IP ӷϥ httpd oӪAȨӨoDơA Yϸ IP qLehLoALµLkoD귽In`NOA pG httpd o{ӴNDܡA client ݱNiQ httpd n骺|}ӤJIDAӤݭnoD root KXI]A np߳oDZҰʦbںWnI ҥHe@ɯŮMOܭnI

  4. ϥΥDɮרtθ귽G
    Q@QAAϥss WWW D̥DnتOHMNOŪD WWW ưաI WWW ƬOԣHNOɮװڡI^_^IҥHA̲׺ʥ]OnVDnDɮרtΪưաC ڭ̳o̰]Anϥ httpd o{ӨotΪɮ׸ơA httpd w]OѤ@ӨtαbW٬ httpd ӱҰʪAҥHGAƪvMNOn httpd o{iHŪ~ڡIpGAeT]w OK A̲v]w~A ϥΪ̨µLksAƪC
boǨBJ~Aڭ̪ Linux Hάn鳣iٷ|䴩nɰO\A FOv{AHK޲z̦bӪ~d߻PJIA}nRnɪߺDO@wnإߪA רO /var/log/messages P /var/log/secure oǭɮסI MUjDn Linux distribution jhXAXL̦ۤvnɤRMAҦp CentOS logwatch ALӮMäoAXҦ distributions AҥHզۤvgF@ logfile.sh shell scriptAziHbU}Uӵ{G
nFAھڳoǬy{AAıoڭ̥iHpO@ۤvDOH


D@O@G v]wBMsBSELinux
b¦g̭eXڭ̽ͨܦhɮv譱`NƶA ؿ̭nO w (igJ)vAܩɮרӻA r (iŪ) ]OD`nIӥѫe@p`Ϥ@ڭ̤]DAȨNOѥDɮ׸귽 client ݨӬd\NOFC

ھڳo˪kAAiHDApGAYǤQnQŪƦbDWܡA NӸƪv]wQYǺAŪpA NF̰¦O@FCҥHzɮvnڡIܭnIOܡH


  • vn
    ``bWҪɭԷ|}ApGAunUF@ӫOAAtδNonswˤFI NOGychmod -R 777 /zAoӫOiOyצMIzIOH]tΤWӴNܦhݭnQO@ơA Ҧp /etc/shadow H /etc/passwd AרO shadow KXɮסCMYO[KLơA LOѤFA{b PC t׹bӧ֤FAӺWSӦhɤO}ѱKXnA pGA /etc/shadow QoAKKIAKXNy}FzCU@A}YǺAȪܡA ҦpisunJ ssh Aȩ mail AȡAHiHϥΧADӵnJA Ϊ̬OQΧADӦADWLϥΪ̪HAIɤjFI

    A̡AܦhBͦbDW``wإv drwxrwxrwx ؿӴѨϥΪ̤WǸơA obOܦMIIpGϥΪ̪\OܡALiHbnp httpd ϥΤWA ӫإߤ@ǦMI script bA drwxrwxrwx ؿApGAp߶iJӥؿA Sp߰FӴcNϥΪ̩ҫإߪ script A߱z㤤СI

    t~ApGAOǮզѮvAFPPǥvq_AA|ƱPǭ̩ҤWǪƤ|QLPǩѨC AӦpivWdHpGªǥͳqqWǨ@ؿAåBSwSvɡA YǦPǪƥi|QѨPƻsAGOAiƷ|QYǴcNPǩҧRI iN·ФFIҥHAv]wuܭnաI

    ӰFDzΪv~AƹWثe Linux 䴩@غ٬ ACL B~v觋A ]䴩jƦw SELinux AoӤpFڭ̷|b᭱~򤶲СC


  • Y檺KXnʡG
    ܦhϥΪ̬FKOСAѬOtκ޲zGyޡIڪKXiiH²@IڡH ӳ·ЪڳOIzpGzOӥitκ޲zAAӦp^H pGAj}KAӥiOwLaI|ҨӻApGA mail server WYӨϥΪ̱b alex nFAL email address N|OGy alex@your.host.name zA oӨϥΪ̥ѩϥβߺD}ALNL mail address db Internet WAҥHܦhHDo addressC

    DNDA|F_ܡHIF_ܡIpGaåALQn alex HA LNbLHnWWADAM᰽Jb alex åBJKX alex A pGAu alex oӨϥΪ̫إߦPWKXAIt(ХxyoA)Io alex ûLHFI

    o٦noIpGA}񻷺ݳsunJAȡAaåNiHQ alex oӱbPKXӵnJADA pGASnvWܡAzI㳡DƳQIi@FI ҥHAzKXnܡHڥi{I


  • MsnʡG
    ܦhBͥѩ峹YAi|ª Linux distribution ӧ@[xA |ҨӻAϥ Red Hat 9 Ӭ[BͷQ٬O֪CpGAuQªӶi[]A ӥBٹ Internet }AȪܡAADN|b@ѪɶQyj[zI OH]Mn鳣Oi঳|}ApGASɬ}.....

    ǪBͻ{GyڪKX]wY@IAӴNnFaHzuܡHڭ@@@Ϥ@y{A ĤTӨBJO_ϥΨ httpd oӵ{\FAU@oӵ{DH |ҨӻAžǶBʹgbL|쪺Q|S@pj[S׸ɺ|} Linux tΡA QΪNO httpd oӳn骺|}AӤJIL{SO@HWI ӥBL쪺iO root voIOߪI ӥBLSJKXAϥΪJI{hO Internet WoC

    bWYoӨҤlOnӪBͪ\OAӬOnjaAM׸ɪnʡI no}ѵ{޹DbӦhFApGAb̵uɶoM󪺧sܡA ܤָӯ}ѵ{AtδN|ͮġIAD۵MN|wǡC ӳoӰDbҦ@~tΤWOsbI Windows tΤ]OCӤ륲nXL̪M{׸ɡA _h@˷|QΤJIڡIL Linux M|}׸ɭn֦hFI


  • SELinux
    b̷s Linux 2.6 ֤ߤWҵoi distributions ثew]|Ұʤ@ӦW SELinux ֤߼ҲաA o SELinux nb}J֤߮ɴNonJAoӪNOԣNNH SELinux O Security Enhanced Linux (w[j Linux) YgA LäO@Ө𪺳nAӬO@ӡywɮרtv@ӳW@ӼҲzC

    DzΪ Linux vOTب (owner, group, others) HΤTv (r, w, x)A ƹWAoTبTvզXõLkĪ޲zҦtΤW daemon sƮɩһݭn欰C ]awKoiXoӥiHӳWɮv\઺ SELinux FC

    ѩ SELinux DnOiɮרtΪӳv]wAҥHQnϥ SELinux tmɡA ݭn Linux ɮרtΥHΰ¦@~tηnܲMA_hN|ϱoܦhAȵLkTҥΨtθ귽A ɭPADܦhAȵLkstθơI]Aڭ̭𫎆IJ Linux [BͨӻA ijA SELinux AT~ Linux ܲ`A Aӹհtm SELinux oӦ쪺NNI

    ]NOApGAS SELinux ܡAANonw SELinux iɮvB~tmA _hAAȴNi|`ҰʡIp SELinux OHAiHo˰G
    1.  /etc/selinux/config e 
    [root@linux ~]# vi /etc/selinux/config
    # NU]wȧ令oˡG
    SELINUX=disabled
    
    2. ק} grub ]w
    [root@linux ~]# vi /boot/grub/menu.lst
    .....ٲ.....
        kernel /boot/vmlinuz-2.6.9 ro root=/dev/hda1 rhgb selinux=0
    .....ٲ.....
    
    3. s}
    [root@linux ~]# sync; reboot
    
    ] SELinux nb}ɭԸJAP˪An]ns}~I ]ApGAϥΪOz distributions w]wˡAXG SELinux Ow]ҰʪI AiH̾ڤWzXӨBJN SELinux As}YiCpG SELinux 쪺ܡA UsiHѦҬݬݡG

  • DӳvWGACL ϥ
    be@p`ڭ̴ Linux tΪvOܭnADzΪvȦTبBTvӤwA tX chmod, umask, chown, chgrp OӶiϥΪ̻Psլv]wCpGniv]wɡA ҦpYӥؿn}񵹬YӯSwϥΪ̨ӨϥήɡADzΪ owner,group,others vkiNLkFC L٦nAڭ̦ ACL oӪNiHϥΡIoN쪺AUڭ̴Nӽͤ@͡G


    O ACLH
    ACL O Access Control List YgADnتObѶDzΪ owner,group,others read,write,execute v~ӳv]wCACL iHw@ϥΪ̡A @ɮשΥؿӶi r,w,x vWdAݭnSvϥΪpD`UC

    ѩ ACL ODzΪ Unix-like @~tvB~䴩ءA]nϥ ACL nɮרtΪ䴩~C ثejɮרtγ䴩 ACL \A]A ReiserFS, EXT2/EXT3, JFS, XFS C b SuSE oӪAw]OҰ ACL ALb CentOS hw]SҰ ACLC ҥH@Unϥ ACL \ɡAAnҰʧAt filesystem 䴩~I

    ACL DniHwǤ譱ӱvOHLDniHwXӶءG
    nFAAӬݬݦpAɮרtΥiH䴩 ACL aI


    pҰ ACL
    nAɮרtΤ䴩 ACL D`²IpnA /home 䴩 ACL ܡAiHo˰G
    [root@linux ~]# mount -o remount,acl /home
    [root@linux ~]# mount | grep /home
    /dev/hda5 on /home type ext3 (rw,acl)
    
    ݨ쨺ӥX{ ACL FaINFpGSX{o@AAɮרtάOLk䴩 ACL A U@`m߱ziNLରOF㨺pGQn@}NAɮרtΤ䴩 ACL OH Iק /etc/fstab NFINL令UҼˡG
    [root@linux ~]# vi /etc/fstab
    /dev/hda5  /home   ext3   defaults,acl   1 2
    
    [J@qSr骺ơAU}N䴩 ACL FI²aI ^_^


    ACL ]wޥG getfacl, setfacl
    nFAA filesystem Ұ ACL 䴩AUӸӦp]wP[ ACL OH ²AQγoӫONiHFG
    ڭ̨@@@ setfacl pϥΧaI
    [root@linux ~]# setfacl [-mxdb] ]w
    ѼơG
    -m  G]w@ ACL WdF
    -x  G@ ACL WdF
    -b  G ACL WdF
    -d  G]ww] ACL WdAȯwؿϥΡC
    
    ̱`ΪNO -m ѼưաIΨөwq@ ACL ]wWdC ACL Ӧp]wOH PϥΪ̡BsջPw]v]wkIPALA򥻤WUoT²]wkG
    1. wϥΪ
    ]wȪWdG u:[ϥΪ̱bC]:[rwx]
    Ҧpw dmtsai oӨϥΪ̨ӳWdv rx AhG
    [root@linux ~]# setfacl -m u:dmtsai:rx somefilename
    
    2. wsըӳ]w
    ]wȪWdG g:[sզW]:[rwx]
    Ҧpw users oӸsըӳWdv rw AhG
    [root@linux ~]# setfacl -m g:users:rw somefilename
    
    3. ww]vӳWdA umask \
    ]wȪWdG m:[rwx]
    Ҧp]w]v rwxAhG
    [root@linux ~]# setfacl -m m:rwx somefilename
    
    AѤFW]w觋A{bڭ̨ӹھާ@@UaI]G
    bDzΪ Linux ɮvAnFWz\ɡAAon jordan P tip oӨϥΪ̥[J users Ӹsդ~AO jordan OƱiHbӥؿu@AҥHLn֦ w vA tip oȯŪAҥHL֦ w vIzIp@ӡANLkWzNƶFI ɧڭ̥unzL ACL ӳWw tip/jordan oӨϥΪ̨ӳ]wLvoIӬy{iHOo˪G
    1. إ߸ӥؿóWnvG
    [root@linux ~]# mkdir /home/project
    [root@linux ~]# chown eric:users /home/project
    [root@linux ~]# chmod 770 /home/project
    [root@linux ~]# ls -ld /home/project
    drwxrwx---  2 eric users 4096 Sep  5 15:54 /home/project/
    # @IwgNݭnؿWnFIϥΪ/sջPvOKFF
    
    2. إ jordan ϥv(ݭn w)G
    [root@linux ~]# cd /home
    [root@linux home]# setfacl -m u:jordan:rwx project
    
    [root@linux home]# getfacl project
    # file: project    <==eTuOXoɦWDz Linux v
    # owner: eric
    # group: users
    user::rwx          <==`NݡAoOwyw]ϥΪ̡zv]wF
    user:jordan:rwx    <==oOw jordan v]w
    group::rwx         <==oOwyw]sաzv]w
    mask::rwx          <==oNhOw]ݩʰաI
    other::---
    # WoӿX@ 8 ڭ̷|bUԲӻI
    
    [root@linux home]# ls -ld project
    drwxrwx---+ 2 eric users 4096 Sep  5 15:54 project
    # ݬݡIhF@ + лxI
    
    getfacl OiHΨӨoYɦW ACL ưաIܩX@ 8 ƧAnoˬݡG
    nFA{b jordan oBͷLiJ /home/project AߨN|֦ rwx vFI Ӥݭn[J users oӸsթOIuOܤKaIӦnFI t~AAp󪾹DYɦW㦳B~ ACL vOHiHѦҤW̲תXGA |o{ /home/project oӥؿvسMOX{y drwxrwx---+ zOI ӦhXӪy + zNOܸɦWB~ ACL ذաI UӦpBz tip OHP˨ϥ ACL ӱG
    3. ]w tip oӨϥΪ̪vơG 
    [root@linux home]# setfacl -m u:tip:rx project
    [root@linux home]# getfacl project
    # file: project
    # owner: eric
    # group: users
    user::rwx
    user:tip:r-x   <==@IhXӪNNաI
    user:jordan:rwx
    group::rwx
    mask::rwx
    other::---
    
    p@ӡA tip oϥΪ̫hȯiJӥؿhŪӤwAӵLkigJʧ@OI O_ܤKڡIF ACL ثAzNiHNAtΤݭnϥΨSv]wؿiӳ]wA AtܪXzAwڡI


  • ACL mask
    Mo˴N]wn@ ACL ءALAٻݭnAѨb ACL mask ҥNNqI bWӤpרҷAڭ̨èSh]wo maskAmask ݭnPϥΪ̪vi޿B (AND) A ~OĪvo(effective permission)I

    |ҨӻApGAıoAؿnҦHȮɶȯŪgJɡAiHN ACL mask ]w rx YiA LHNݭnAB~]wFIݬݩUoӨҤlG
    [root@linux ~]# cd /home
    [root@linux home]# setfacl -m m:rx project
    [root@linux home]# getfacl project
    # file: project
    # owner: eric
    # group: users
    user::rwx
    user:tip:r-x
    user:jordan:rwx        #effective:r-x
    group::rwx             #effective:r-x
    mask::r-x
    other::---
    
    WXO getfacl XGAèS[uڡI ^_^I 쥻 jordan 㦳yrwxzvA mask Ȧyr-xzḀh y̳v~|ͮġAN٬v (effective permission) ozI ҥHAjordan hȷ| rx vӤwڡIo˹ mask ΪkAFܡH

  • @DZ`kPDO@觋
    ڭ̥Ϥ@AѨƶǰe쥻ɩһݭngLXDuA {bzӤMڭ̱``b¦g̭@ͨ]wTviHO@zDFaH 򰣤Feͨ쪺D򥻫O@~A q`HaOpA Linux DOHUڭ̴Nӽͤ@ͧaI AѤ@UHaOpAAڭ̤~kQp󨾿mAzOaHI


  • obTqKXG
    ѩܦhHwΦۤvWrӧ@bTA]boOܮeI |ҨӻApGABͱNA email address p߬|XhAҦpG dmtsai@your.host.name ˦A HaN|DA@DAW٬ your.host.nameABboDW|@ӨϥΪ̱bA bW٬ dmtsai AoaåAQάYǯSnҦp nmap ӶiAD port scan AKKILNiH}lzLADҰʪn\ӲqAoӱbKXFI

    t~ApGA``[ADnɡAA]|o{pGADҰ Mail server AȮɡA AnɴN|``X{ǩdzåեH@ǩ_Ǫ`bbչϲqAKXA |ҨӻGadmin, administrator, webmaster .... bAըѨApHHC pGADuobAӥBob٨S}nKXWANeyСzI IuO·СIҥHڭ̱`AtαbdU൹KXAeQqKXI

    oزqKX觋O̦JIҦ@FA̪DAbAΪ̬OiHqXӧAtΦDZbA ʪNuOKXӤwA ]L|yܧVOzhqAKXAɡAAKXWpGnܡAܮeNQFI D]ܮeQj[ڡIҥHA}nKX]mߺDOܭnC

    Loا觋OɡA]ثeܦhn鳣KXJƪA pGsJTKX٤ন\nJAӦsuN|Q_uI ҥHAoا觋q֡Aثeٷ|ݨNOFIo]O cracker |ϥΪ觋@C ڭ̭npO@OH򥻤觋Oo˪G
    • ָTn|GҦpnN Email Address HNG Internet WYF
    • إ߸Y檺KX]wWhG]A /etc/shadow, /etc/login.defs ɮת]wA ijziHѦ¦g b޲z@ӳWdAϥΪ̱KXܧɶA pGDíwB|[JYDZbɡA]iHҼ{ϥ chattr ӭb (/etc/passwd, /etc/shadow) F
    • v]wGѩo觋|oAYӨϥΪ̱bnJvA ҥHpGAtv]woyܡA̤]ȯo@ϥΪ̪vӤwA Dˮ`աIҥHAv]wOnF

  • QΨtΪ{|}yDʡzG
    Ϥ@̭ĤTӨBJAڭ̪DpGAD}AȮɡA NҰʬYӺnIڭ̤]Dѩni༶g觋DAiಣͤ@Ƿ|Q cracker åΪε{XAӳoǯε{Xѩ󲣥ͰDjpA bug (ΡAi|ytΪíwη) P Security (wDA{Xg觋|ɭPtΪϥvQcN̩Ҵx) DC

    {DQAYǸ cracker |ռg@ǰwoӺ|}{XA åBNoӵ{Xm cracker `hWAǥHPۤvy\Oz..... nOAoص{XyOܮeQozC hyլլLl(xyASƷFN)zooǵ{XALi|Qnyդ@ճoӧ{¤OzA ҥHNӡygz@fApGAKrAΪ̷ѬPyǮaA˷ɡA iN|Qpߪ......

    oاҦOثe̱`A]̥un{NiHiFA yӥBѧ}loAtΪ root vݭnqKXA ݭnANߨJI\zAҥHyլլLlz̷̳RNOoөNNFC oӪNॻOayAD{|}zӧAҥHApGADHɫObYɧsqA Ϊ̬Ojݭn{ANiH׹LoӰDC]AAӭno˰G
    • ݭnAȡG} port V֡AiHQJI޹DV֡A @DtdAȶV¡AVeXDICݬݫeͨ쪺 Linux suf @aI
    • HɫOsGoӨSI@wni檺IѦҫe@ ɯŮMC
    • ݭnn\G|ҨӻA᭱|쪺ݵnJA SSH iH root ѻݵnJAMIƱMnLڡI^_^

  • QΪu{@FG
    u{ (Social Engineering) ²ANOzLHPHʨӹFyJIzتI @_@IHPHʥiHJIADHbIVAܡHMOC

    bxW|AO`ݨYǤH|Hyh|BBpRQ~zWqӴF}ѦʩmA ѦʩmǥXfU̪ǥicҶܡHu{]OkCbjq̭A γ\Ai|o˪qܡGyڬOHƳgzAڪbMnJFH Aڬݤ@ݡAHܪڥtؤ@ӱbAڧiDAڭnKXO....zCpGA@ɤdLbKXܡA ADiNo˳QjF

    u{FkhOA]AϥΡynߪ email qzByĵiHzByzA bbOnFAbKXAhQγ觋ӴFAbYǴcNWJAbKXA ܰQաInp󨾽dOH
    • l̡ܹͪGn@۫HAAnHߪVWeA n@ɤ߷WNFpI
    • nHNzSb/KXTG̦nnHNb Internet WgoǸơA uܦMII]b Internet WAAûDùe۪O֡H

  • Qε{\઺yQʡzG
    ԣHFDʧ~A٦ҿתQʧHSڡAytzIp@QʧOH NonѡycNz_FCpGAwWHNsܡA򦳪ɭԥi|sW@ǼsiܦhA Ϊ̬O@uXAoǺٷ|ܦnߪyѧAܦhnΪn۰ʤUPwˡz\A pGӺOAҫHAҦp Red Hat, CentOS, Windows xܡA٦nA pGO@ӧA]MLOFAAO_nPNUw˸ӳnH

    pGA``b`N@ǺMBzsDɡA`|o{ Windows s (IE) DA ɫhOs (Firefox, Netscap, IE...) |X{DCA||ıo_ǰڡA ys]|DHzoO]ܦhs|Dʪ WWW DҴѪU{\A Ϊ̬O۰ʦw˨Ӧ۹DnAs٥iѩ{oͦwDA WWW soHǰecN{XADӰAKKIСI

    AS|QڡAڷFs˪cNHܡI`O|DzʤߤjNɭ԰ڡI pGAѤpߦ@ email A̭iDAAȦbDA ƱAsWYӺhݬݧAbO_bDCAA||hH pGѦӺYYbѤjSӫ~AA||hIIBH Oi઺ڡILAo]NܮeQFC

    p󨾳ưڡHMإߨ}nߺḒnFG
    • HɧsDWҦMGpGAsOSDA ǻcN{XɡAAsN|A۵MwhڡI
    • pƳn骺\G|ҨӻAAHn餣nDʪUɮסA AsbwˬYdznɡAnqLAT{~wˡAo˴NeJA@Ǥp·СF
    • ns줣DG곾{oӤ~I ]ܦhɭԧڭ̳ google bjMDѨMDڡAAp󪾹DO_OFHH ҥHAeI٬OܭnInHSsWcNN|DڡI

  • įΩΤ차 rootkitG
    rootkit NOiHo root v@su (kit)ANpPeDʧ{|}k@ˡA rootkit Dn]OzLD{|}CLA rootkit ]|zLu{ϥΪ̤UBw rootkit nA G cracker oH²檺j[DڡI

    rootkit FiHzLWzkӶiJI~Arootkit ٷ|˩Ϊ̬OiۧڽƻsA |ҨӻAܦh rootkit NOįΩΪ̬O차ҵ{Cįη|AD@oeʥ]V~A G|AWeQYAҦp 2001-2003 ~ Nimda, Code Red Fܩ차{ (Trojan Horse) h|ADi}ҫ (}@ port cracker DʪJI)AGNO....j[Bj[Bj[I

    rootkit ꮼnlܪA]ܦhɭԥL|Dʪhקt[OA ]A ls, top, netstat, ps, who, w, last, find AAݤYǦD{A p@ӡAA Linux DNܮeQOOFIMIIp󨾳ƩOH

  • DoS k ( Denial of Service )
    o½Ķy_zAoاk]ܭnRAӥBkܦhA̱`N SYN Flood kFIٰOoڭ̦b¦̭쪺ADF@ӱa SYN TCP ʥ]AN|ҥιnD port ӵݳsuAåBoeX^ʥ] (a SYN/ACK XЪ TCP ʥ])Aõ Client ݪA^C

    nFAboӨBJڭ̨ӷQ@QApG cient ݦboeX SYN ʥ]AoNӦ Server ݪT{ʥ]Az Server ݴN|@ŵAӥB Client ݥiHzLn\AbuuɶoeXo˪ SYN ʥ]Az Server N|_oeT{ʥ]AåB}Ҥjq port bŵID port ҥΧA.....tδNFI

    iȪOAq`D@褣|u@IL|zL Internet WͥD (wgOADoSo{D) oʥAADbuɶNߨ豾IC o DoS kyɥۭѵIzqA LOJIztΡAӬOnztαIOI ̱`QΨӧ@_AȪAȴNO WWW FA] WWW q`o Internet }AȡC

    oاk]OBzA]nNontή֤ߦ䴩۰ʩ DoS A nzNonۦ漶gnӧP_IuO·аڡӰDzD`jA åByoo֤HzA_hӤ|Q DoS աI ^_^


  • LG
    W쪺O`kAO٦@ǰ񪺧kաA Lǧkݭn޳NǡAҦp IP FCLiHFADiӫʥ]ӷOӦ۫HA ӥBzLʥ]ǰeAѧ@򪺥DʵoeXT{ʥ]Pu@OC p@ӡAADiN|~Pӫʥ]T꦳^AӥBOӦۤDC

    Lڭ̪DںOѪAӨCDbC@Ӯɬq ACK T{XۦPA ҥHoӤ觋nFiHnJA|·СAҥHAӮeoͦbڭ̳oǤpDWաI LA٬Oon`N@UG
    • ]wWhGQ Linux تn iptables إ߸AiHd欰F
    • ֤ߥ\GoAzntή֤ߦܲ`JAѡA ~k]wnA֤ߺ\C
    • nɻPtκʱGAiHzLRnɨAѨtΪpA t~]iHzL MRTG ʱn ӧYAѨtάO_`AoǤu@OܦnVOVI

  • D@pyG
    nAtΧwASyTTzOSkFIڭ̤]@jA y@[]٭nnz[I]y@HoDɤѡzAP˪DzGy@HХIzA nHADSԣnơAQJIγQӤJ차]SYA ]ڭ̪Aq`|鷺ӷDWdePApGADbqA Op߳QJIܡAQqAO_N|SbMIҷFH

    t~AbįΫܡyoFz~NAڭ̤]|o{unϰ̭@DСA ӰϰN|LkϥκFA]WewgQįζzI pGo{LѨSkHFALkH]ëDAIA ӬO]HYӤHqFįΡAӨDįΪ]uO]ӨϥΪ̤pߥhݤF@UⱡA Aıo|ӭu@_ݦⱡ٬O fire ӤHH

    ҥHڡAD@٬OܭnInpݤFIѴXӤVjaҬݬݧaG
    1. إߧnJKXWhF
    2. Dv]wF
    3. ]w۰ʤɯŻP׸ɮM|}BβMIMF
    4. bCtΪAȪ]wAjƦw]wءF
    5. Q iptables, TCP_Wrappers jƺF
    6. QΥDʱnp MRTG P logwatch ӤRDpPnɡF

  • QJI᪺״_u@
    pGADQJIܡAӧA]ѩAѨDʱݭnAҥHb̵uɶo{@ƥA ӦpwoӳQJIDӭ״_HpGAn״_ܡAAoӺޤHٻݭnB~ޯH Uڭ̴Nӽͤ@͡C


    ޤHB~ޥP
    qe@p`RAz|o{ٯuO֪ALݭn@~tΦ@w{תxA {ǪB@ (process) PvAhݭnAѡI_hN·ФFIF@~tΪ򥻷~A ̺ٻݭnԣSޥOHMݭnڡI@Ḏ`oͰDpA Oѡy~ΩҲͪzAҥHڡAAuަnDӤwOySkDzաI UNӽͽͧAٻݭnԣޥOH

  • AѤOݭnO@eG
    ڪѧoA٭nDOݭnO@rHISANOpIѭڭ̪DDJIkA AѡAunHbzDeAƳi|o͡I]ApGzD۷nA СynHaIzziHѦҤ@UiJ|byi઺ȡz̭nѨ@qƪxסI ^_^""
    • wGNaI
    • nG٥]ṱnƩOI
  • w«( Black hats )JIG
    oiO}AO«ȧrIoO]쥻b赓qvAaHO¦UlA ҥHeH̴Nٺ̬ Black hats աIbwo譱̮ɡAFYިnJ~A ٻݭnSO쥻zDHINڭ̤pӻAnHnBʹNHKLաI LnwKXOLbۦPnOAzNLIHaΥLKXnJzDAï}azDA iNovFIpGOj~ܡAuϥκɡA]nŪOI ^_^

  • DҦwơG
    SnAFhߡA٬OhߡIJӪRnɡA``Wݬݳ̷swqiAoO̰¦I ٥]tFḨ֪tקsDMI]AV֧szMANV֥iH«ȪJII

  • WhqwG
    o·Ф@ǰաI]zݭn_մզAաIHǫΤƪw]wI 򻡩OHnoOApGzWhqwoӦhɭԡA @Ӹƫʥ]NngLVhd~৹㪺qLAHiJDIKKI oiO۷OɶI|yDįणISOdNo@IOI

  • Yɺ@zDG
    N軡AzݭnHɺ@zDA]A𤣬O@g]wNΦbALFI ]AAYKA]||}IoǺ|}]AWh]w}BQθsJI޳NB Qαz³n骺AȺ|}IҥHAݭnYɺ@zDrIo譱FR log files ~A]iHǥѧYɰӶioӤu@IҦp PortSentry NOZ@MnOI

  • }nШ|Vmҵ{G
    OҦHOqAרM{bTzOMܦh||JqèrI oӮɭԡAnoOAڭ̹󤺳q`SӦhWdApGLΤqhaƫH ɭ٬OLߪҥHAݭnSOШ|Vmҵ{rIo]OqݭnުD]@I

  • ƥpeG
    ѦAHi׺֧rIHDɭԷ|ja_Bڭ̤]DɭԷ|Mwбh ҥHAƥpeO۷nI~AjSH|LDO 100% waI pGAtγQJIAyƪlɡAAnp_ADڡHI@Ө}n޲zHA LɵL卖|i歫nƪƥIܭnڡI o@аѦҤ@U¦Dz߽g Linux DƥeaI ѫ򪺻ݳsuA SSH `]|@ӫܴΪ rsync uAziH@@I

  • JI_u@
    ҿסyʱK@zڡAHOA`|Ҽ{gpAU@zDN]oy@zɭPQJIFA ӫHѤWAڭ̪Dy차zOYA]L|bztΤU}ӫ(Back door)̥iHnJzDAӥBٷ|«z Linux W{Az䤣Ӥ차{IH

    ܦhBͳߺDyϥunN root KX^ӴNnFz o˪[IAƹWAˤ@D٬OQ~MIڡIҥHA U@zDQJIFA̦nk٬OyswLinux z|bI

    Ӧp󭫷sw˩OHܦhBͤ@AawˡAo@AaQJI㬰OH]LSyOаVzڡII Uڭ̴Nӽͤ@͡A@QJIDӦp״_nH
    1. ߧYްuG

      JMo{QJIFAĤ@ƱNO\I\²檺@k۵MNOޱuFI ƹWAu̥Dn\ణFO@ۤv~A٥iHO@P쪺LDC򻡩OH|ӳ̪ (2003/08) ofefrnFAL|PVP줧LDIҥHAްuA ݪ̥ߧYNLkiJz Linux DAӥBz٥iHO@줺LDڡI

    2. RnɸTAjMi઺JI~|G

      QJIAMOunsw˴NnAٻݭnB~R yڪDo@|QJIAOpJIHzA pGzXDIA򤣦z Linux \OߨWjFAD]|VӶVwI ӦpGzDpXQJIi~|A򭫷sw˫AU٬OiQHP˪kJIڡI ·ЪաInFAӦpXJI~|OH

      • RnGCŪ cracker q`ȬOQΤunӤJIztΡAҥHڭ̥iHǥѤR@ǥDnnɨӧX𫍧 IP HΥi঳D|}CiHR /var/log/messages, /var/log/secure ٦Q last OӧXWnJ̪TC

      • ˬdD}񪺪AGܦh Linux ϥΪ̱``oۤvtΤW}Fh֪AȡHڭ̻LA CӪAȳ|}Ϊ̬OӱҥΪWjΪ̬Oի\AҥHAXztΤWAȡA åBˬd@UCӪAȬO_|}AΪ̬Ob]wWFʥAM@Ӥ@ӪzaI

      • d Internet WwqG zLwqAѤ@U̷s|}TAwzDNbWI

    3. nƳƥG

      DQJIAoD۷YAOH]DW۷nưڡI pGDWSnơA򪽱sw˴NnFIҥHAQJIAˬdFJI~|A AӴNOnƥnƤFCnFAݭӰDAOynzH who, ps, ls OOnƶܡH٬O httpd.conf ]wɬOnơHSΪ̬O /etc/passwd, /etc/shadow ~OnơH

      I򥻤WAnӬOyD Linux tΤW즳zAҦp /etc/passwd, /etc/shadow, WWW , /home ̭ϥΪ̭nɮ׵Aܩ /etc/*, /usr/, /var ؿUơANoݭnƥFC `NGnƥ@ binary ɡA] Linux tΦw˧᥻ӴNoɮסA~A oɮפ]ܦiywgQ«LFzAƥoǸơAϦӳyUt٬ObI

    4. sswˡG

      ƥFơAAӴNOsw Linux tΤFCӦbowˤA z̦nܾAXzۤvwˮMYiAnM󳣵LwˤWhڡIMII

    5. M󪺺|}׸ɡG

      OoڡAsw˧AХߧYsztήMA_h٬O|QJIաIwbLbҤUN Internet W|}׸ɮMUUӡAMN_ӡAM᮳ۤvw˧tΤWAmount CD LsAsAåB]wFAPɶiU@BJy βݭnAzAڤ~NuWDdWI ]Twbw˧AsW Internet hsM󪺳oqɶA||SJI....

    6. βݭnAȡG

      oӭnʤݭnAFaHIҥζV֪AȡAtηMiHQJIiʴNCC

    7. Ʀ^_P_Aȳ]wG

      ƥƭn򪺽ƻs^ӨtΡAPɱNtΪAȦAs}AЪ`NA oǪAȪ]w̦nAT{@UAקK@Ǥ]wѼƦbYI

    8. sW InternetG

      Ҧu@i檺thFA~N讳uWӧaI_DB@FI
    gLo@sꪺʧ@AzDӷ|_bҡA٤౼HߡA ̦n٬OѦҨ𪺳]wAåBh譱Ѧ Internet W@ǦѤ⪺gAnzDiHw@ǡI

    I^U

    ҫm

    ѦҸ

    2002/08/12GĤ@I
    2003/08/23GssƻPW[I^UBҫm
    2006/08/31GNª峹ʨBC
    2006/09/06GW[ SELinux ²满AW[ ACL ءI