ãŸããã
çŽ9幎åãæåã®ç¡å¶éã®é¢çšãåžã«çŸãããšãïŒ500ã«ãŒãã«ã§128 kbit / sã®ãããªãã®ïŒãç§ã¯ããŸããŸãªåé¡ã解決ããããã«ã¢ããŒãã«èªåã®ããµãŒããŒãã眮ãããšã«ããŸããã æåã®ã¢ã€ãã¢ã®1ã€ã¯ãFreeBSD.orgãããžã§ã¯ãã®ãã©ãŒãäžããããšã§ããã ããã¯çŽ2幎éåããŸããã ããã«ãããã¯ããã£ãã«ã®æ¡å€§ããã³ãã®ä»ã®çç±ã«ãããæå³ããããŸããã§ããã
ããã«ããµãŒããŒã¯ç°ãªãæéã«ä»ã®ã¿ã¹ã¯ãåŒãåããŸããã
- ããŒã¿ãããã¥ã¡ã³ãããã£ã¹ããªãã¥ãŒã·ã§ã³ã®ããã¯ã¢ããã³ããŒã®ä¿åã
- ãã¬ã³ããããŠã³ããŒãããŠãã ããã
- DLNAããã³SMBãä»ããããŸããŸãªããã€ã¹ãžã®ãã¬ã³ãã®é
åžã
- ãããã€ããŒãžã®VPNã¯ã©ã€ã¢ã³ãïŒãµãŒããŒãMPDãä»ããŠ2ã€ã®PPTPæ¥ç¶ãç¶æããæéãããããŸãã-ããŒã«ã«ãã©ãã£ãã¯ãšäœéç¡å¶éæäœã®ããïŒ;
- VPNãµãŒããŒãšãªãã£ã¹ã²ãŒããŠã§ã€ãžã®æ¥ç¶ïŒåäœãããã£ãã«ïŒ;
- IPãã¬ãã©ããŒçšã®ã¢ã¹ã¿ãªã¹ã¯ãµãŒããŒïŒåŸã®å®¶ã«ã¯ãããããçš®é¡ã®SPA-3112ãã©ãžãªãã¥ãŒããªã©ããããŸããïŒã
- IPã«ã¡ã©ããããŒã¿ãåä¿¡ããMikrotikã¹ã¯ãªããã§ããã¯ã¢ããããªã»ããããããã®FTPãµãŒãã¹ã
- ç ãªã©
äžè¬çãªã¢ã€ãã¢-ããããã®ã«ã©ãã«ãªããŒããæã¡ããã®ãããªäœããå°ç¡ãã«ããããšãã匷ãé¡æãæã€ã³ã³ã¹ãã©ã¯ã¿ãŒã®æã®äžã äžè¬ã«ãããã¯nixã·ã¹ãã ãç¥ã£ãŠãããæããŠããã»ãšãã©ã®ã·ã¹ãã 管çè
ã«ãšã£ãŠäžè¬çãªç¶æ³ã§ãã
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã
æåã®4ã5幎éã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšããŠFreeBSDã䜿çšããŠããŸããã ããæç¹ã§ãä»äºãå€ããŠMicrosoftãã¯ãããžãŒã«æ²¡é ãå§ãããšããããŒã ãµãŒããŒã«å¯ŸåŠããæéã¯ãŸã£ãããããŸããã§ããã ç§ã¯ãŸããããŒãã¢ããã°ã¬ãŒãã«æéãè²»ããããšã«æ¬åœã«ç²ããŠããããšãèŠããŠããŸãã ä»ã®çç±ããã£ãã®ãããããŸããããæ£ç¢ºã«ã¯èŠããŠããŸããã ããããçµæã¯Debianãžã®ç§»åïŒåæ¥ïŒã§ããããµãŒããŒã¯é·ãé䜿çšãããŸããã§ããïŒäœ¿çšãããŸããããå€æŽã¯ãããŸããã§ãã-ããŸã«ããæŽæ°ãããŸããã§ããïŒã
ãããŠã€ãæè¿ã1æã®äŒæ¥ã«ãFreeBSD 11
ã§ãã 1ã€ã®åç¹åŸ©åž°ãè¡ãããŸãã-ãµãŒããŒãåã€ã³ã¹ããŒã«ãããŸãã-ãããŠããã®çç±ã¯ã
CBSDãããžã§ã¯ãã«å¯Ÿããç§ã®ç¥ãåããšè³è³ã§ãã
CBSDãããžã§ã¯ããæããçç±
ãããè¡ãã«ã¯ãçŽ5幎åã«FreeBSDãé¢ããçç±ãèŠããŠãããŠãã ãã-空ãæéã®äžè¶³ãå€ããã€ããªããã±ãŒãžã€ã³ã¹ããŒã«ã·ã¹ãã ïŒpkg_ *ïŒãããã³äžäŸ¿ãªJails管çã ç§ãFreeBSDããLinuxã«åãæ¿ããçç±ãæ£ç¢ºã«èšãã®ã¯é£ããã§ãã ããããç§ãä»ç¢ºä¿¡ããŠããããšã¯ããµãŒããŒäžã§CBSDãããžã§ã¯ããšFreeBSDã䜵çšããããšã§ãæçµçã«å©äŸ¿æ§ãšã»ãã¥ãªãã£ã®äž¡æ¹ãçµã¿åãããããšãã§ããããã«ãªããŸããã
éå»ã®ãã¹ãŠã®ã€ã³ã¹ããŒã«ã¯ããã¹ãŠã®åµã1ã€ã®ãã¹ã±ããã«å
¥ããŠãååã«åºã¥ããŠæ§æãããŠããŸãã 1ã€ã®ãµãŒãã¹ã䟵害ããããšãèªåçã«ãã¹ãŠã®ãµãŒãã¹ã䟵害ãããŸãã ãµãŒããŒã«CBSDãåºçŸãããããåãµãŒãã¹ãèªåã®ã»ã«ã«é
眮ããçžäºäœçšãå¶éããæãå¿
èŠãªæå°å€ã®ã¿ãæ®ããšããã«ãŒã«ãäœæããŸããã
ã ãã-ç§ã®çç±ïŒ
- ç°¡åãªã€ã³ã¹ããŒã«ïŒcbsdããã±ãŒãžãã€ã³ã¹ããŒã«ããæåã®ãŠã£ã¶ãŒããéå§ããäžè¬çãªè³ªåã«çããŸã-ããã¯2åã§ãïŒã
- æ°ããã»ã«ãäœæããé床ïŒZFSã®FSã«ããå°çšIPã¢ãã¬ã¹ãå²ãåœãŠãããã¯ã©ãŒã¿ãããã³pkgngãæ¢ã«åæåãããŠããæ°ããã»ã«ãååŸããåäžã®ã³ãã³ããå®äºããã®ã«1åããããŸãïŒ;
- ãµãŒããŒéã§ãã¹ãŠã®èšå®ã䜿çšããŠã»ã«ãç°¡åã«è»¢éã§ããŸãïŒããã¯éåžžã«äŸ¿å©ã§éèŠã§ã-çŸæç¹ã§ã¯ãFreeBSDããŒã¹ã®ãµãŒããŒã5å°ïŒèªå®
ã䞡芪ã矩çã®æ¯ãè·å Žã®ã«ããã«ïŒã«æ¢ã«ããã®ã§ãã»ã«ãäœæããŠèšå®ããã ãã§ãäžåºŠã ã-å°æ¥çã«ã¯ããšã¯ã¹ããŒã/ã€ã³ããŒããŸãã¯ã¯ããŒã³/移è¡ãä»ããŠã©ãã«ã§ã転éã§ããŸãã
- å®å
šæ§ãšå©äŸ¿æ§ã éåžžã匱ãäºææ§ã®ãã®ã ããã-ããã§ã¯ãçµåããããšãå¯èœã§ããããã§ãïŒ
- èªã¿åãå°çšã«ãŒãã·ã¹ãã ã§ã»ã«ãäœæã§ããŸãã ããã«ãããRootKit-toolsïŒåºæ¬ãŠãŒãã£ãªãã£ã眮ãæããïŒã®å®è£
ã1æ¡ã ãã»ã«ã«è€éã«ãªããŸãã
- ã»ã«ãšä»ã®ã»ã«ããã³ã€ã³ã¿ãŒããããšã®çžäºäœçšãå¶éããã ãã§ã-PBS / IPFWå¶åŸ¡ã¯CBSDã«çµ±åãããŠããŸãã
- æ°ããç°å¢ãç°¡åã«äœæã§ãããããããŒã¹ã·ã¹ãã ã«æ°ãããœãããŠã§ã¢ãé
眮ããèªæã¯ãããŸããïŒæ inessæ iness ...ïŒã
- ã»ã«ã¯ããšã¯ã¹ããŒã/ã€ã³ããŒãçšã«äºçŽãããŠããã ãã§ããã€ãŸããããé »ç¹ã«ã¹ã±ãžã¥ãŒã«ã©ããã«ã³ããŒãäœæã§ããŸãã
- ã»ã«ã®æŽæ°ã¯ç°¡åã§ãã¡ã€ã³ã·ã¹ãã ãã管çããŸãïŒäžçãæŽæ°ããã€ã³ã¹ããŒã«ããããœãããŠã§ã¢ãæŽæ°ããŸãïŒã SSHãµãŒãã¹ãäžããŠAnsibleãªã©ãèšå®ããå¿
èŠã¯ãããŸããã
- ã³ã³ãã³ãã»ãã¥ãªã㣠CBSDã«ã¯ãã³ã³ãã³ããšJailèªäœãããŸããŸãªå Žæã§ãã¹ãããæ©èœãçµã¿èŸŒãŸããŠããŸãã ãããŠãã»ã«ã®éå§æã«ãjailã®ã³ã³ãã³ããå«ããã£ã¬ã¯ããªããmount_nullfsãä»ããŠæå®ããããã£ã¬ã¯ããªã«ããŠã³ãããŸãã ãŸããèªã¿åã/æžã蟌ã¿ã¢ãŒãã§ã¯å¯èœã§ãããèªã¿åãå°çšã§ã¯å¯èœã§ãã ããã¯éåžžã«äŸ¿å©ã§ããããšãã°ãã»ã«ã®åæ¢ãããã¯ã¢ããïŒãšã¯ã¹ããŒãïŒãããã³ã»ã«ã®åèµ·åãè¡ãã¹ã¯ãªãããäœæã§ããããã§ãã ãã®çµæãã¢ãŒã«ã€ãã«ã¯ãœãããŠã§ã¢ãšèšå®ïŒ200ã300 MBã®å§çž®åœ¢åŒïŒã®ã¿ãå«ãŸããã³ã³ãã³ãã¯åå¥ã«ãšã¯ã¹ããŒããããŸããïŒããšãã°ã1 TBã®ãã¬ã³ãããããŸãïŒã OwnCloudã§ãåæ§ã§ãã SambaãµãŒããŒã ç
æåŸã«pkgng
pkgngã®äœæè
ã«æè¬ããŸãã ããã±ãŒãžïŒãã€ããªïŒç®¡çã®æ°ããè¿ä»£çãªã·ã¹ãã ã®éçºããªããã°ãCBSDãããžã§ã¯ãã¯çŸåšã»ã©äŸ¿å©ã§ã¯ãããŸããã
pkgngã®åºçŸã¯ããã»ãŒå®å
šã«ã/ usr / portsãæŸæ£ããçç±ã§ããã€ãŸããpkgngã®è¿œå ãšããŠåŠçããŸãã ç§ã¯æ¬¡ã®ååã䜿çšããŸãã
1. pkgã䜿çšããŠãã¹ãŠã®å¯èœãªãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããŸãã ææ°ã®ãã©ã³ãããæŽæ°ãååŸããŸãïŒ/etc/pkg/FreeBSD.confãã¡ã€ã«ãç·šéïŒã
2.ããã€ãã®ãœãããŠã§ã¢ãèªåã«åããªããã©ã°ã§pkgãªããžããªã«åéãããŠããããšãç解ããå ŽåïŒæã§ã¯ãªããCBSDãã¬ãŒã ã¯ãŒã¯ãä»ããŠ/ usr / portsãããŠã³ãããŸã-cbsd jset mode = quiet jname = dokuwiki mount_ports = "1"ïŒãå¿
èŠãªUSEãã©ã°ã䜿çšããŠããŒããããã®ãœãããŠã§ã¢ãåéããŸãã
3. pkg lockã䜿çšããŠãäžæã®ãªãã·ã§ã³ã§ã¢ã»ã³ãã«ããããã®ãœãããŠã§ã¢ã¯ãpkg upgradeãä»ããèªåæŽæ°ããéããããŸãã
çµæ-ä»»æã®æ°ã®ã»ã«ã§ã1ã€ã®ã¹ã¯ãªããã§99ïŒ
ã®ããã°ã©ã ãæŽæ°ã§ãã99ïŒ
ã®ç¢ºçã§ãµãŒãã¹ã®äœæ¥ãäžæããŸããã æ²ããããª-1ïŒ
ã¯åžžã«æ®ããŸãã ããã-ã»ã«ã®èªåããã¯ã¢ããããããŸãã 以åã«ã€ã³ã¹ããŒã«ãããããã±ãŒãžã®ãã£ãã·ã¥ãå«ããã£ã¬ã¯ããªããããŸãã ãããã£ãŠã2ã€ã®ããŒã«ããã¯ãªãã·ã§ã³ããããŸãïŒãã±ãããããŒã«ããã¯ããããã»ã«å
šäœãããŒã«ããã¯ããŸãïŒã æãåºãããŠãã ãã-1ã€ã®ã»ã«-1ã€ã®ãµãŒãã¹/ãµãŒãã¹ããããŸãã
CBSDã®ç 究äžã«æžãããã¹ã¯ãªãããšèšå®ã®äŸïŒ
ã»ã«å
ã®è匱ãªãœãããŠã§ã¢ã®ååšããã¹ãããŸããïŒïŒ/ bin / sh
echoãããŒã«ã«ã·ã¹ãã ã®ç¢ºèªã
pkgç£æ»-F
ãšã³ãŒ ""
echo "DokuWiki JAILã®ç¢ºèª"
/ usr / local / bin / cbsd jexec jname = dokuwiki pkg audit -F
ãšã³ãŒ ""
echoãOwnCloud JAILã®ç¢ºèªã
/ usr / local / bin / cbsd jexec jname = owncloud pkg audit -F
ãšã³ãŒ ""
echo "FTPããã¯ã¢ããJAILã®ç¢ºèª"
/ usr / local / bin / cbsd jexec jname = ftpbackup pkg audit -F
ãšã³ãŒ ""
echo "SAMBA JAILã®ç¢ºèª"
/ usr / local / bin / cbsd jexec jname = samba pkg audit âF
èµ·ååŸã®ã¹ã¯ãªããåºåïŒããŒã«ã«ã·ã¹ãã ã®ç¢ºèª
ææ°ã®vulnxmlãã¡ã€ã«
ã€ã³ã¹ããŒã«ãããããã±ãŒãžã«0åã®åé¡ãèŠã€ãããŸããã
DokuWiki JAILã®ç¢ºèª
ææ°ã®vulnxmlãã¡ã€ã«
ã€ã³ã¹ããŒã«ãããããã±ãŒãžã«0åã®åé¡ãèŠã€ãããŸããã
OwnCloud JAILã®ç¢ºèª
ææ°ã®vulnxmlãã¡ã€ã«
ã€ã³ã¹ããŒã«ãããããã±ãŒãžã«0åã®åé¡ãèŠã€ãããŸããã
FTPããã¯ã¢ããJAILã®ç¢ºèª
ææ°ã®vulnxmlãã¡ã€ã«
ã€ã³ã¹ããŒã«ãããããã±ãŒãžã«0åã®åé¡ãèŠã€ãããŸããã
SAMBA JAILã®ç¢ºèª
ææ°ã®vulnxmlãã¡ã€ã«
ã€ã³ã¹ããŒã«ãããããã±ãŒãžã«0åã®åé¡ãèŠã€ãããŸããã
æŽæ°å¯èœãªããã±ãŒãžããªã¹ãããŸããïŒïŒ/ bin / sh
echoãããŒã«ã«ã·ã¹ãã ã®ç¢ºèªã
pkg upgrade -n
ãšã³ãŒ ""
echo "DokuWiki JAILã®ç¢ºèª"
/ usr / local / bin / cbsd jexec jname = dokuwiki pkg upgrade -n
ãšã³ãŒ ""
echoãOwnCloud JAILã®ç¢ºèªã
/ usr / local / bin / cbsd jexec jname = owncloud pkg upgrade -n
ãšã³ãŒ ""
echo "FTPããã¯ã¢ããJAILã®ç¢ºèª"
/ usr / local / bin / cbsd jexec jname = ftpbackup pkg upgrade -n
ãšã³ãŒ ""
echo "SAMBA JAILã®ç¢ºèª"
/ usr / local / bin / cbsd jexec jname = samba pkg upgrade ân
åã®ã¹ã¯ãªããã®äž¡æ¹ãå®è¡ããã¹ã±ãžã¥ãŒã«ã«åŸã£ãŠã¡ãŒã«ã«éä¿¡ããŸããïŒïŒ/ bin / sh
å¯ã1
echoâ ToïŒvershinin.e@gmail.comâ> /root/Scripts/audit-pkg.mail
echoããµããžã§ã¯ãïŒMAINããã³JAILãããã·ã¹ãã ã§PKGãç£æ»ãã!!!ã>> /root/Scripts/audit-pkg.mail
echo "" >> /root/Scripts/audit-pkg.mail
echo "" >> /root/Scripts/audit-pkg.mail
å¯ã1
`/root/Scripts/pkg-audit-all-sys.sh >> / root / Scripts / audit-pkg.mail`
å¯ã1
`/root/Scripts/pkg-upgrade-all-sys.sh >> / root / Scripts / audit-pkg.mail`
å¯ã1
`cat /root/Scripts/audit-pkg.mail | / usr / local / bin / msmtp vershinin.e @ gmail.com`
å¯ã1
ã»ã«ãžã®ã¢ã¯ã»ã¹ããã³ã»ã«ããã®ã¢ã¯ã»ã¹ãå¶éããPFã«ãŒã«ïŒ######ååæèŠå######
###### DokuWiki #########
ïŒããã©ã«ãã®ãããã¯ã«ãŒã«
$ dokuwikiããanyãžã®ãããã¯
anyãã$ dokuwikiãžã®ãããã¯
ïŒANYããDokuwiki Apache HTTPã«æž¡ã
proto tcpãanyãã$ dokuwiki port 80ã«æž¡ããç¶æ
ãç¶æãã
###### FTPããã¯ã¢ãã######
ïŒããã©ã«ãã®ãããã¯ã«ãŒã«
$ ftpbackupããanyãžã®ãããã¯
anyãã$ ftpbackupãžã®ãããã¯
ïŒLANããFTPããŒãã«æž¡ãïŒ
proto tcpã$ mylansãã$ ftpbackupããŒã21ã«æž¡ããŸã
proto tcpã$ mylansãã$ ftpbackupããŒã{20000> <20100}ã«æž¡ããŸã
###### OwnCloud ########
ïŒããã©ã«ãã®ãããã¯ã«ãŒã«
$ owncloudããanyãžã®ãããã¯
anyãã$ owncloudãŸã§ãããã¯
ïŒLANããOwnCloud HTTPããŒãã«æž¡ã
proto tcpã$ mylansãã$ owncloudããŒã80ã«æž¡ããç¶æ
ãç¶æããŸã
ïŒWANããOwnCloud HTTPSããŒãã«æž¡ã
proto tcpãanyãã$ owncloudããŒã443ã«æž¡ããç¶æ
ãä¿æããŸã
###### JAILã®ãã¹ãŠã®ã«ãŒã«#######
$ mylansãã$ mylansã«proto icmpãæž¡ã
proto udpã$ mylansãã{$ dns_local $ dns_google}ããŒã53ç¶æ
ç¶æã«æž¡ã
proto tcpã$ mylansãã{$ pkg_mirror1 $ pkg_mirror2 $ pkg_mirror3 $ pkg_mirror4} keep stateã«æž¡ããŸã
æ¥ç¶ãããŠãããã¹ãŠã®ãµãŒããŒã®ãã¹ãŠã®ã»ã«ãšãã®ã¹ããŒã¿ã¹ã®ãªã¹ãã衚瀺ããã³ãã³ãã®äŸïŒcbsd jls alljails = 1 shownode = 1ïŒãšã€ãªã¢ã¹jallïŒ
圌女ã®çµè«ïŒ
ã»ã«ãå®æçã«ãšã¯ã¹ããŒãããããã®ã¹ã¯ãªããïŒïŒïŒ/ bin / sh
jailname = $ 1
CBSDPATH = / CBSD
JAILBACKUPTARGET = / data / JAILS
backupdate = `/ bin / date" +ïŒ
Y-ïŒ
m-ïŒ
d "`
jstatus = `/ usr / local / bin / cbsd jstatus $ jailname`
if [$ jstatus -ne "0"]; ãããã
/ usr / local / bin / cbsd jstop $ jailname
å¯ã15
fi
jstatus2 = `/ usr / local / bin / cbsd jstatus $ jailname`
if [$ jstatus2 -eq "0"]; ãããã
/ usr / local / bin / cbsd jexport jname = $ jailname compress = 0
å¯ã15
fi
if [-f $ CBSDPATH / export / $ jailname.img]; ãããã
cp $ CBSDPATH / export / $ jailname.img $ JAILBACKUPTARGET / $ jailname- $ backupdate.img
å¯ã5
fi
jstatus3 = `/ usr / local / bin / cbsd jstatus $ jailname`
if [$ jstatus3 -eq "0"]; ãããã
/ usr / local / bin / cbsd jstart $ jailname
å¯ã5
fi
jstatus4 = `/ usr / local / bin / cbsd jstatus $ jailname`
if [$ jstatus4 -ne "0"]; ãããã
echo "JAILã®ããã¯ã¢ãããæ£åžžã«çµäºããŸããïŒ ååæãåéããŸããïŒã
fi
èŠçŽïŒ
CBSDã¯éåžžã«èå³æ·±ããããžã§ã¯ãã§ããããããããããç¥ãããæ¢è£œã®æåãããœãªã¥ãŒã·ã§ã³ã®ããŒããã©ãªãªãã«
å«ããããšããå§ãããŸãã