ããŒã¿æŒããã«é¢ããæ
å ±ã
ãã¥ãŒã¹ã«æ¬¡ç¬¬ã«ç»å Žããå€§äŒæ¥ã¯ã»ãã¥ãªãã£ã®åŒ·åã«èšå€§ãªéãè²»ãããŠããŸãã IDCã®ã³ã³ãµã«ãã£ã³ã°çµç¹ã
ææããŠããããã«ã2020幎ãŸã§ã«ãITã»ãã¥ãªãã£ãžã®äžççãªæ¯åºã¯1,000åãã«ãè¶
ããŸãã
ãã ããå®å
šãªITã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§ç¯ããããã«å€é¡ã®è²»çš
ããããå¿
èŠ
ã¯ãããŸãã ã ããšãã°ãLinuxã·ã¹ãã ã«
ã¯ä¿è·ã¡ã«ããºã
ãçµã¿èŸŒãŸããŠãããé©åã«æ§æãããŠããã°ãOSããã³ãããã¯ãŒã¯ã«å¯Ÿããæãäžè¬çãªã¿ã€ãã®æ»æãåæ ã§ããŸãã
ãã®èšäºã§ã¯ãITã€ã³ãã©ã¹ãã©ã¯ãã£ããããã³ã°ããŠæ
å ±ãå±éºã«ãããå¯èœæ§ãæžããããã€ãã®åºæ¬çãªãã³ããèŠãŠãããŸãã æçš¿ã®äŸã¯LinuxããŒã¹ã®ã·ã¹ãã çšã«æäŸãããŠããŸããã説æãããŠãããã©ââã¯ãã£ã¹ã®äžéšã¯ä»ã®OSã«ãé©çšã§ããŸãã
/ Flickr / cezary borysiuk / PD1.ææ°ã®ã»ãã¥ãªãã£æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ããŸã
ãã®ç¹ã¯éåžžã«æçœã§ãããã¢ããªã±ãŒã·ã§ã³ã®å®æçãªæŽæ°ã®éèŠæ§ã¯ä»¥åã«æžãããŠããŸãããæ®å¿µãªãããããã¯ãŸã é¢é£æ§ã倱ããªãã OpenSSL-
Heartbleed ïŒCVE-2014-0160ïŒã®è匱æ§ç¶æ³ãã芧ãã ããã
æ»æè
ããµãŒããŒã®ç§å¯éµãæœåºããããã䜿çšããŠéä¿¡ããããã©ãã£ãã¯ã埩å·åã§ããããã«ããŸãã 2014幎ã«ãšã©ãŒæ
å ±ãå
¬éãããæç¹ã§ãè匱ãªãµã€ãã®æ°ã¯åèš50äžã§ããããåæã«Googleã®éçºè
BodoMöllerãšAdam Langleyã¯è匱æ§ãä¿®æ£
ãããããã
æºåããŸãã ã ãã ããå
šå¡ãã¢ããããŒããã€ã³ã¹ããŒã«ããããã§ã¯ãªããShodanã«ãã
ãš ãHeartbleedã¯20äžè¿ãã®Webãµã€ãã®åœ±é¿ãåããŠããŸãã
ã·ã¹ãã ãææ°ã®ç¶æ
ã«ä¿ã€ããã«ãOSã®
èªåæŽæ°ã»ãã¥ãªãã£ãèšå®ããããšããå§ãããŸãã ã»ãšãã©ã®ãã³ããŒã¯ãããããèªåçã«ã€ã³ã¹ããŒã«ããããŒã«ãæäŸããŠããŸãã ããšãã°ãDebianã«ã¯
ç¡äººã¢ããã°ã¬ãŒããŠãŒãã£ãªãã£ããããRed Hat
ããŒã¹ã®ã·ã¹ãã ã«ã¯
AutoUpdatesããããŸãã
Yum-cronã¯CentOSã§ã
dnf-automaticã¯Fedoraã§å©çšã§ããŸãã
ããã±ãŒãžãããŒãžã£ãŒã䜿çšããŠã¢ããã°ã¬ãŒãããããšãã§ããŸãã ããšãã°ã
Debianã®å Žå ïŒ
apt-get update && apt-get upgrade
ãããã®èªåã€ã³ã¹ããŒã«ã«ã¯æ¬ ç¹ããããŸããããšãã°ãæŽæ°ã«ããã·ã¹ãã ãã¯ã©ãã·ã¥ããå ŽåããããŸãã ãããã£ãŠãéçšç°å¢ã«æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ããåã«ããµã³ãããã¯ã¹å
ã®ãœãããŠã§ã¢ã®äºåãã¹ãã
宿œãã䟡å€
ããããŸãã
ãµãŒãã¹ããã¯ã®éçºè
ã¯ããœãããŠã§ã¢è£œåãã·ã¹ãã ã«æœåšçã«å±éºãªå€æŽãå ããªãããã«ããŸãããã¢ããªã±ãŒã·ã§ã³ãšãµãŒãã¹ã®å¯èœãªçµã¿åããããã¹ãŠãã¹ãããããšã¯ã§ããŸããã ããšãã°ãæè¿
ãªãªãŒã¹ãããWindows 10çšã®ãããKB4041676ã¯ãäžéšã®ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒãç¡éã®åèµ·åãµã€ã¯ã«ã«éãããæ»ã®ãã«ãŒã¹ã¯ãªãŒã³ããçæããŸããã
åæã«ãã¢ããã°ã¬ãŒãåŸã®ã·ã¹ãã ã®äžéšã¯ãé¢é£ãããã¹ãŠã®ããã»ã¹ãåèµ·åããããŸã§ãäŸç¶ãšããŠãšã¯ã¹ããã€ãã«å¯ŸããŠè匱ã§ãã ããšãã°ã2014幎ã«OpenSSLã¯ãæ»æè
ãDDoSæ»æãè¡ãããšãå¯èœã«ããããã€ãã®è匱æ§ã
çºèŠããŸãã ã DebianããŒãžã§ã³1.0.1e-2 + deb7u10ã§ã¯
éããããŠããŸããããããããæå¹ã«ããã«ã¯ãOpenSSLã«é¢é£ãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ãåèµ·åããå¿
èŠããããŸããã åèµ·åãå¿
èŠãªããã°ã©ã ãæ€çŽ¢ããããã«ãã³ãã¥ããã£ã¯
checkrestartããã³
needs- restarting ãŠãŒãã£ãªãã£ã éçºã ãŸãã ã
2.ã»ãã¥ãªãã£æ¡åŒµæ©èœãæå¹ã«ããŸã
çŸä»£ã®ã·ã¹ãã ã§ã¯ãããŸããŸãªãŠãŒã¶ãŒãææãã倿°ã®ããŒã¢ã³ãšããã°ã©ã ãå転ããŠããŸãã ãã©ã³ã¿ãªãŒãšåŒã°ããåŸæ¥ã®Unixã¢ãã«ïŒDAC-ä»»æã¢ã¯ã»ã¹å¶åŸ¡ïŒã¯ãã¢ã¯ã»ã¹æš©ãå²ãåœãŠããšãã«ããŠãŒã¶ãŒããŠãŒã¶ãŒã°ã«ãŒããããã³ã¢ããªã±ãŒã·ã§ã³ç®¡çããã»ã¹ãè€éã«ããä»ã®3ã€ã®ãã©ã¡ãŒã¿ãŒã§
åäœããŸãã
ã»ãã¥ãªãã£ããªã·ãŒãèšå®ããããã®ããå€ãã®ãªãã·ã§ã³ã管çè
ã«æäŸããããã«ãMACïŒå¿
é ã¢ã¯ã»ã¹å¶åŸ¡ïŒã¢ãã«ãã€ãŸã匷å¶ã¢ã¯ã»ã¹å¶åŸ¡ã«åºã¥ããŠ
ã»ãã¥ãªãã£æ¡åŒµæ©èœãéçºãããŸããã ãããã¯åŸæ¥ã®ã¢ãã«ãè£å®ãããã¹ãŠã®ããã»ã¹ã®ã»ãã¥ãªãã£ããªã·ãŒã確ç«ããæ©äŒãæäŸããŸãã ããšãã°ãæå®ãããããŒãã§ãªãã¹ã³ããããã«WebãµãŒããŒããæ³šæãããããæå®ããããã£ã¬ã¯ããªããã®ã¿ãã¡ã€ã«ãèªã¿åããããã«ããŸãã
ã»ãã¥ãªãã£ã¢ããªã±ãŒã·ã§ã³ã®äžã§ã¯
ã SELinuxãAppArmorãGrSecurityïŒä»ã«ããã
ãŸã ïŒã
åºå¥ã§ããŸããããããã«é·æãšçæããããŸãã æ¬¡ã«ãSELinuxã®æ©èœãç°¡åã«æ€èšŒããŸããããã¯æãå®å
šã§ïŒãã®ã¢ããªã±ãŒã·ã§ã³
ã¯æ¿åºã·ã¹ãã ã§äœ¿çšãããã
ã«äœæãããïŒãnixCraft Vivek Giteã®ã·ã¹ãã 管çè
ããã³äœæè
ãšããŠãæã匷åãªã¢ã¯ã»ã¹å¶åŸ¡ã¡ã«ããºã ãåããŠããŸãã
3ã€ã®åäœã¢ãŒãããããŸãã 匷å¶ã¯ã確ç«ãããã»ãã¥ãªãã£ããªã·ãŒã«éåããã¢ã¯ã·ã§ã³ããããã¯ããããã©ã«ãã¢ãŒãã§ãã 2çªç®ã®ã¢ãŒãïŒèš±å¯ïŒã¯ããã°å
ã®ãã¹ãŠã®éåããã£ããã£ããŸããããããããããã¯ããŸããã 3çªç®ã®ç¶æ
-ç¡å¹-ã¯ãã·ã¹ãã ãç¡å¹ã§ããããšãæå³ããŸãã
次ã®ã³ãã³ããèšè¿°ãããšãèšå®ãããŠããã¢ãŒãã確èªã§ããŸãã
$ /usr/sbin/getenforce
SELinuxãæå¹ã«ããã«ã¯ã次ã®ããã«
å
¥åããŸã ïŒFedoraã®å ŽåïŒïŒ
rpm -qa | grep selinux rpm -q policycoreutils rpm -qa | grep setroubleshoot
ãã®ãŠãŒãã£ãªãã£ã¯ãããã€ãã®ã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ãæäŸããŸãã
- Type Enforcement ïŒTEïŒïŒãã©ã€ããªã¢ã¯ã»ã¹å¶åŸ¡ã¡ã«ããºã ã æè»ã§ããæéãããããŸãã ãã¹ãŠã®ãªããžã§ã¯ããšãµããžã§ã¯ãã«ã¯èå¥åãä»ããŠããããããã䜿çšããŠã«ãŒã«ãšããªã·ãŒãå²ãåœãŠãããšãã§ããŸãã
- 圹å²ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ ïŒRBACïŒïŒã·ã¹ãã ã«ã¯ã1ã€ä»¥äžã®ãã¡ã€ã³ã¿ã€ãã«é¢é£ä»ãããã圹å²ãå²ãåœãŠãããŸãã ãããã®ãã£ãŒãã¯ããã§èŠã€ããããšãã§ããŸã ã
- ãã«ãã¬ãã«ã»ãã¥ãªã㣠ïŒMLSïŒïŒãã¹ãŠã®ã·ã¹ãã ãªããžã§ã¯ãã¯ç¹å®ã®ã¬ãã«ã®ã¢ã¯ã»ã¹ãåãåãããã®æ©èœãå¶éããŸãã ãã®ã¬ãã«ã§ã¯ããµãŒãã¹ã¯æ
å ±ã®èªã¿åããšæžã蟌ã¿ãè¡ãããšãã§ããäžã®ã¬ãã«ã§ã¯æžã蟌ã¿ã®ã¿ãäžã®ã¬ãã«ã§ã¯èªã¿åãã®ã¿ãå¯èœã§ãã ã»ãã¥ãªãã£ã¬ãã«ã®å³ãããã«ãããŸã ã
SELinuxãã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããç¶æ³ã®äŸãšããŠãæ§æãšã©ãŒãçºçããå Žåã
ãããŸãã DNSãµãŒããŒã¯ããµãŒããŒéã§ããŒã¿ãè€è£œãããšãã«ããŸãŒã³è»¢éãšåŒã°ãããã®ãå®è¡ããããšããããããŸãã æ»æè
ã¯ãã®æé ã䜿çšããŠã誀ã£ãæ
å ±ããµãŒããŒã«ãããŒããã£ã¹ãã§ããŸãã Fedoraã§BINDã䜿çšããå Žåã管çè
ãæ
å ±ã®äº€æãèš±å¯ãããµãŒããŒã®ç¯å²ãå¶éãå¿ããŠããSELinuxããªã·ãŒã¯ã¬ããªã±ãŒã·ã§ã³äžã®ãŸãŒã³ãã¡ã€ã«ã®å€æŽãé²ããŸãã
SELinuxã§ã¯ãããã»ã¹ãä»ã®ããã»ã¹ã§äœ¿çšããããã¡ã€ã«ã«ã¢ã¯ã»ã¹ããã®ããããã¯ããããšãã§ããŸãã ããšãã°ãæ»æè
ã¯SambaãµãŒããŒãå±éºã«ãããããšã¯ã§ããããããä»ããŠä»ã®ã·ã¹ãã ïŒMySQLããŒã¿ããŒã¹ãªã©ïŒã®ãã¡ã€ã«ã倿ŽããŸãã
SELinuxãä¿è·ãããã®ä»ã®ãŠãŒã¶ãŒã±ãŒã¹ã¯ã
ããããå
¥æã§ã
ãŸã ã Debian
ã§ SELinuxãã»ããã¢ããããããã®è©³çްãªã¬ã€ããšãFedoraã®ã¬ã€ãã
ããã«ãããŸã ã
3.ã¢ã¯ã»ã¹æš©ãèšå®ãããã¹ã¯ãŒãããªã·ãŒãèšå®ãã
ãã®ç¹ãéåžžã«æçœã§ãããéèŠã§ã¯ãªããªããŸããã 2015幎ã«2000人ã®ãªãã£ã¹ã¯ãŒã«ãŒã察象ã«ã€ã³ã¿ãŒã¡ãã£ã¢ã宿œ
ãã調æ»ã«ãã
ãšãåçè
ã®93ïŒ
ãå°ãªããšã1åºŠã¯æ
å ±ã»ãã¥ãªãã£èŠä»¶ãç¡èŠããããšãèªããŸããã åæã«ãITæ¥çã®åŸæ¥å¡ã®67ïŒ
ããããŸããŸãªã¢ã«ãŠã³ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããååãšå
±æããŠãããšçããŠããŸãã
è匱ã§äžè¬çãªãã¹ã¯ãŒãã¯ãäŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãææãã®å¯èœæ§ãé«ããäžé©åã«èšå®ãããã¢ã¯ã»ã¹æš©ã¯çµç¹ã®ã·ã¹ãã ã®æã穎ãéããŸãã ãããã£ãŠããµãŒããŒã«ç®¡çè
ïŒã«ãŒãïŒãšããŠæ¥ç¶ãã
ããšã¯ãå§ãããŸãã ã æ°ãããŠãŒã¶ãŒãäœæããæš©éãå¶éããŠãã®ã¢ã«ãŠã³ããæäœããsudoã䜿çšããŠç®¡çããããšããå§ãããŸãã
Stack Exchangeã®
å±
äœè
ãææããŠããããã«ããã®ã¢ãããŒãã¯æ»æè
ã®ç掻ãå°é£ã«ããŸãã ããã«ãŒã¯ãSSHïŒssh root @ $ IPïŒãä»ããŠæ¥ç¶èŠæ±ãéä¿¡ãããããã䜿çšããæšæºã®çµã¿åããïŒãrootããŸãã¯ãpassword123ãã
æãäžè¬çã§ãïŒãŸãã¯
ãã«ãŒããã©ãŒã¹ã䜿çšããŠãã¹ã¯ãŒããéžæã§ããŸãã ã«ãŒãã¢ã¯ã»ã¹ãååŸã§ããå Žåãã·ã¹ãã å
šäœã§ãç¡å¶éã®é»åããååŸããŸãã
ããããrootãSSHçµç±ã§æ¥ç¶ã§ããªãå Žåããããã¯æåã«ãŠãŒã¶ãŒåãæšæž¬ããå¿
èŠãããããããã³ã°æé ãé£ãããªããŸãã
Debianããã³Ubuntuã§æ°ãããŠãŒã¶ãŒãäœæããã«ã¯ãã³ã³ãœãŒã«ã§æ¬¡ã®ã³ãã³ããå
¥åããŸãã
adduser administrator
管çè
ãã£ãŒã«ãã¯ä»»æã«å€æŽã§ããŸãã æ¬¡ã«ããã¹ã¯ãŒããç»é²ãããŸãã ãã¹ã¯ãŒãããã§
㯠ã8ã10æåã®é·ãã§ãç°ãªãã¬ãžã¹ã¿ãæ°åãç¹æ®æåã䜿çšãããã¹ã¯ãŒããäœæããããšã
ãå§ãããŸãã Coding Horrorããã°ã®èè
ã§ãããStack Overflowããã³Stack Exchangeãã©ãããã©ãŒã ã®å
±åèšç«è
ã§ãããžã§ãã¢ããŠããã¯ã10æå以äžã®ãã¹ã¯ãŒãã䜿çšãããšã
æã人æ°ã®ãããªã¹ãã«è¡šç€º
ãããå¯èœæ§ã80ïŒ
æžå°ããããšã«æ³šç®ããŠããŸãã
ã¯ããè€éã§é·ããã¹ã¯ãŒããäœæããå¿
èŠãããããšã¯ããç¥ãããŠããŸãããå®éã«ã¯ã誰ãããã®èŠåã«åŸãããã§ã¯ãããŸããã SplashDataããŒã ã¯ã2016幎ã«ãçµ±åããããäŒæ¥åŸæ¥å¡ã®ã¢ã«ãŠã³ããã500äžãè¶
ãããã¹ã¯ãŒãã
åæããŸãã ã ç ç©¶è
ã¯ãã»ãšãã©ã®ãã¹ã¯ãŒãã¯å®å
šã«å®å
šã§ã¯ãªããšçµè«ä»ããŸããã ãã¹ã¯ãŒãã123456ããæãäžè¬çã«ãªããããã¹ããã»ããå
šäœã®4ïŒ
ã®ã¢ã«ãŠã³ãã§äœ¿çšãããŸããã ã»ãŒåãå²åã§å
¥åããããã¹ã¯ãŒããpasswordãã
ãŸããåéšã®ä»ã®ãŠãŒã¶ãŒã®æ¿èªã®ããã«ããŒã¿ãåŠçãã䟡å€ããããŸãã è匱ãªãã¹ã¯ãŒãã¯ã
John the ripperãŠãŒãã£ãªãã£ã䜿çšããŠæ€åºã§ããŸãã ã·ã¹ãã ã«ããã¹ã¯ãŒãã®ãªãããŠãŒã¶ãŒãããªãããšã確èªããã«ã¯ããã®ã³ãã³ãã圹ç«ã¡ãŸãã
awk -F: '($2 == "") {print}' /etc/shadow
ãã¹ã¯ãŒãã®äœæãå¿
é æé ã«ãããã¹ã¯ãŒãã®æå¹æéãèšå®ããã«ã¯ãpam_cracklib.soãã¡ã€ã«ã®èšå®ã倿ŽããŸãã
chage -M 60 -m 7 -W 7 UserName
pam_unix.soã®å€ããã¹ã¯ãŒãã®åå©çšãé²ãããã°ã€ã³è©Šè¡åæ°ã«å¶éãèšå®ããŸãã
è€æ°ã®ã¢ããªã±ãŒã·ã§ã³ãããããããããããŸããŸãªéèŠãªæ
å ±ã«ã¢ã¯ã»ã¹ã§ããå Žåãå¥ã
ã®ã¢ã«ãŠã³ãããããããèµ·åããŠãããã¢ããªã±ãŒã·ã§ã³ããå¥ã®ã¢ããªã±ãŒã·ã§ã³ã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ããããã¯ãã䟡å€ããããŸãã
ã¢ããªã±ãŒã·ã§ã³ã«ã¡ãŒã«ãµãŒãã¹ãåã蟌ãããã®APIãéçºããŠããMailgunã
ææããŠããããã«ããã®ã¢ãããŒãã®ç®æšã¯ãããã«ãŒããŸã ã·ã¹ãã ã«äŸµå
¥ã§ããå Žåã«ããã«ãŒã®ããªãã·ã§ã³ãã®æ°ãæžããããšã§ãã ã¢ããªã±ãŒã·ã§ã³ã®ã¢ã¯ã·ã§ã³ã®ãªã¹ããå¿
èŠæå°éã«å¶éãããŠããå Žåãæ»æè
ã¯ãããšãã°ã¢ã¯ã»ã¹æš©ãäžããŠéå€§ãªæå®³ãäžããããšãã§ããŸããã
é©åãªãŠãŒã¶ãŒã®ããäžã§éå§ãããããã«ããµãŒãã¹ãããã¢ãããŸãã ãããè¡ãã«ã¯2ã€ã®æ¹æ³ããããŸãã 1ã€ç®ã¯ãOSã¹ã¯ãªããïŒ
initãŸãã¯
systemd ïŒã䜿çšããŠã¢ããªã±ãŒã·ã§ã³ãèµ·å/忢ããç£èŠããŒã«ïŒ
monit ïŒã䜿çšããŠã¯ã©ãã·ã¥ããå Žåã«åèµ·åããããšã§ãã 2çªç®ã®ã¢ãããŒãã¯ãã¢ããªã±ãŒã·ã§ã³ãç¬èªã«ç®¡çããããã»ã¹å¶åŸ¡ã·ã¹ãã ïŒ
Supervisord ã
s6 ã
daemontools ïŒã䜿çšããããšã§ãã
/ Flickr / reynermedia / CC4.ãã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ãšäŸå€ãæ§æãã
æè¿ã
systemdãããŒãžã£ãŒã«è匱æ§ïŒ
CVE-2017-15908 ïŒãçºèŠãããDDoSæ»æãå¯èœã«ãªããŸããã è匱ãªã·ã¹ãã ãããã«ãŒã«ãã£ãŠå¶åŸ¡ãããŠããDNSãµãŒããŒã«DNSã¯ãšãªã
éä¿¡ãããšãsystemdãç¡éã«ãŒãã«å
¥ãã100ïŒ
ã®CPUè² è·ãåŒãèµ·ããç¹å¥ãªã¯ãšãªãè¿ããŸããã
ãã®ã¿ã€ãã®æ»æããä¿è·ãã1ã€ã®æ¹æ³ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãæ§æããããšã§ããå
·äœçã«ã¯ããã®å Žåããã¡ã€ã¢ãŠã©ãŒã«ã¯
RFC 4034ã®ã»ã¯ã·ã§ã³4ã§èª¬æãããŠãããªãœãŒã¹ã¬ã³ãŒããå«ãæœåšçã«æªæã®ãããã±ããããããã¯ããããã«æç€ºãã
ãŸã ã
äžè¬ã«ãå€éšã¢ã¯ã»ã¹çšã«å°æ°ã®ãµãŒãã¹ã®ã¿ãéããšããé£çµ¡å
ãã®æ°ãæžãããã®çµæãã·ã¹ãã ã«äŸµå
¥ããå¯èœæ§ãäœããªããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãèšå®ãããšããMailgunããŒã ã¯
次ã®ååã«
åŸãããšãæšå¥šã
ãŸã ã
- æ°ããã«ãŒã«ãèšå®ããåã«ãæ¢åã®ã«ãŒã«ãåé€ããŸãã
- ããã©ã«ãã§ã¯ãçä¿¡ãã©ãã£ãã¯ãåŠçããã«ã¯ ãDROPãã©ã¡ãŒã¿ãŒãèšå®ããŸãïŒç¢ºç«ãããã«ãŒã«ãæºãããªããã©ãã£ãã¯ã¯ã¹ããããããŸããïŒã ãã®åŸãå€éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãåŸã
ã«ãéããããšãã§ããŸãã
- ã€ã³ã¿ãŒãããå¶åŸ¡ã¡ãã»ãŒãžãããã³ã«ïŒICMPïŒãã©ãã£ãã¯ãå®å
šã«å¶éããªãã§ãã ããã ã«ãŒã¿ãŒãšãã¹ãã¯ããã䜿çšããŠããµãŒãã¹ã®å¯çšæ§ããã±ãããµã€ãºãªã©ã«é¢ããéèŠãªæ
å ±ãéä¿¡ããŸããStackExchangeã§è¿°ã¹ãããã«ãICMPã¯å¶éã§ããŸããããããã®çŠæ¢ã®åœ¢åŒã¯äŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãã£ãŠç°ãªããŸãã
- IPv6ã䜿çšããŠããªãå Žåããã®ãã©ãã£ãã¯ãå¶éããŸãã
ããããã¹ãŠã®æšå¥šäºé
ãå®è£
ããããã«ãMailgunã¯æ§æçšã®ç¬èªã®ã¹ã¯ãªãããäœæã
ãŸãã ã
ãã¡ãã§èŠã€ããããšãã§ããŸãã
5. SSHçµç±ã§å®å
šã«æ¥ç¶ãã
ãŸããä¿¡é Œã§ããSSHããŒãçæããŸãã ããã¯ãssh-keygenã䜿çšããŠå®è¡ã§ããŸãã
ssh-keygen -t rsa -b 4096 -C foo@example.com
ãã®åŸãããŒã䟵害ãããå Žåã«ããŒãä¿è·ãããã¹ãã¬ãŒãºãå
¥åããå¿
èŠããããŸãã SSHæ¥ç¶ãæŽçããã«ã¯ããŸãšããªæšæºæ§æã®OpenSSHã䜿çšã§ããŸãã OpenSSHãã©ã¡ãŒã¿ã«é¢ãã詳现æ
å ±ã¯ãMozillaã®
ããã¥ã¢ã«ãŸãã¯CentOS
wikiããŒãžã«ãããŸã ã
ç§ãã¡ã®åŽã§ã¯ãæå·ããŒã®ãã¢ã䜿çšããŠSSHçµç±ã§ã¢ã¯ã»ã¹ããããšã
ãå§ãããŸãã 2çªç®ã®ããŒã¯ããã«ãŒããã©ãŒã¹ã«ãããããã³ã°ã倧å¹
ã«è€éã«ããŸãã åè¿°ã®ããã«ããã¹ã¯ãŒããé·ãã»ã©ä¿¡é Œæ§ãé«ããªããSSHããŒã®é·ãã¯ãããšãã°2048ãããã«ãªããŸãã
ãããè¡ãã«ã¯ãæ°ããããŒãäœæããå
¬éããŒããµãŒããŒã«ã¢ããããŒãããŸãã ããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒããæ¬¡ã®ããã«å
¥åããŸãã
ssh-copy-id admin@1.1.1.1
adminãããŒã®ææè
ã®ååã«ã1.1.1.1ããµãŒããŒã®IPã¢ãã¬ã¹ã«çœ®ãæããŸãã æ¥ç¶ã確èªããã«ã¯ã忥ç¶ããå¿
èŠããããŸãã
ãã¹ã¯ãŒããå
¥åããããã®SSHæ¥ç¶ãå®å
šã«ç¡å¹ã«ããŠãå
šå¡ãããŒã䜿çšã§ããããã«ããããšãã§ããŸãã æ¬¡ã«ã/ etc / ssh / sshd_configãã¡ã€ã«ã®PasswordAuthentificationãã©ã¡ãŒã¿ãŒã®å€ãnoãšããŒã¯ããå¿
èŠããããŸãã
UbuntuïŒãŸãã¯DebianïŒã§ã¯ã次ã®ããã«ãªããŸãã
nano /etc/ssh/sshd_config ... PasswordAuthentication no
远å ã®æ¥ç¶ã»ãã¥ãªãã£ã¯2FAïŒ
äºèŠçŽ èªèšŒ ïŒã䜿çšããŠå®çŸã§ããããšã«æ³šæããŠãã ããã
6.æå·åã䜿çšãã
䟵å
¥è
ããã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããã«ã¯ãæå·åã䜿çšããå¿
èŠããããŸãã å人æ
å ±ããã³è³æ Œæ
å ±ãæå·åããã«ä¿åããªãã§ãã ããã ãã¹ã¯ãŒããGitHubã®ãã©ã€ããŒããªããžããªã«ããå Žåã§ãã ãã®ãããGitHubã䟵害ãããå Žåã«ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããŸããããã¯ãæšå¹Žäžå¹Žã§æ¢ã«
çºçããŠããŸãã æ»æè
ã¯ãä»ã®ãµãŒãã¹ããããã³ã°ããçµæãšããŠã³ã³ãã€ã«ããããã¹ã¯ãŒããšé»åã¡ãŒã«ã¢ãã¬ã¹ã®ãªã¹ãã䜿çšããŠãããã€ãã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã䟵害ããäŒæ¥æ
å ±ã«ã¢ã¯ã»ã¹ããŸããã
æå·åçšã®ããŒã«ãŸãã¯ã©ã€ãã©ãªãéžæããå Žå
ãMailgunããŒã ãšStack Exchangeã®å±
äœè
ã¯ã次ã®ã«ãŒã«ã«åŸãããšããå§ãããŸãã
- ææ°ã®å¯Ÿç§°æå·ã䜿çšããŸããæãäžè¬çãªãªãã·ã§ã³ã¯ AESãšSalsa20ïŒNaClïŒã§ãã
- MAC ïŒã¡ãã»ãŒãžèªèšŒã³ãŒãïŒã䜿çšããŠãããŒã¿ãœãŒã¹ã®æŽåæ§ãšèªèšŒãå¶åŸ¡ããŸãã é©åãªãªãã·ã§ã³ã¯ã HMAC-SHA-512ãŸãã¯Poly1305ã§ãã
- ããŒãšã¿ã€ã ã³ãŒããçæããããã®é«å質ãªã©ã³ããã€ã¶ãŒã«æ³šæããŠãã ããã ããšãã°ã / dev / urandom ã
- ããŒã«ããã¹ãã¬ãŒãºã§æ©èœããå Žåã¯ã KDFã䜿çšããŠããããšã確èªããŠãã ããã
察å¿ããã¹ã¬ããã®Stack Exchangeã§ããŠãŒã¶ãŒ
ã¯æå·åã·ã¹ãã ãäœæ
ããããã®å€ãã®ããŒã«ïŒentlibã
Bouncy Castleãªã© ïŒãæäŸããŸãã æ¬åœã«å¿
èŠãªå Žåã¯ãç¬èªã®ãŠãŒãã£ãªãã£ãäœæã§ããŸããã
Redditãš
Quoraã®äœæ°ã¯ããã®ã¢ãããŒãã¯ãããã³ã°ã®ãªã¹ã¯ãé«ããã ãã ãšèšããŸãã Stack Exchangeã§
è¿°ã¹ãããã«ãã»ãšãã©ã®å Žåãèªå®¶è£œã®
æå·ã¯ ã
ããªã¢ã«ãã¡ããã£ãã¯æå·ããã³
眮ææå·ã è§£èªããããã®ããã«ãŒããŒã«ã«ããæ»æã«ã»ãšãã©èããŸããã
ããã«ãæå·åã·ã¹ãã ã®æäœãéå§ããåã«ãããã€ãã®ãœãŒã¹ãæäŸããŠããŸãã 1ã€ç®ã¯
Crypto101ã³ãŒã¹ã§ãã¹ã¿ãŒãã¢ããåãã®ã»ãã¥ãªãã£ãã¬ãŒãã³ã°äŒç€Ÿã§ããããªã³ã·ãã«ã®ãã£ã¬ã¯ã¿ãŒã§ããLaurens Van HoutvenãæããŠããŸãã 2çªç®ã®ãªãœãŒã¹ã§
ããmatasanoæå·ãã£ã¬ã³ãžã«ã¯ãå®éã®æå·ã«å¯Ÿããæ»æã瀺ã48ã®æŒç¿ãå«ãŸããŠããŸãã èè
ã¯ããã®ãããã¯ã«é¢ããæ¬ãèªãããããæå·ã®åçãç ç©¶ããããã®ãã广çãªæ¹æ³ã§ãããšäž»åŒµããŠããŸãã
7.ããã¯ã¢ããã宿çã«äœæããŠç¢ºèªãã
ããã¯ã¢ããã®åé¡ã¯ãäžèšã®ãããã¯ã®äžè¬çãªããŒãããå°ãå€ããŠããŸãããã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ã確ä¿ããããã«ãéèŠã§ãã ç¹°ãè¿ãã«ãªããŸããããã®ãããã¯ã¯å€ãã®è³æã§ãåã¿ç ãããŠããŸããããå€§äŒæ¥ã§ããééããç¯ããŠãããããç¹°ãè¿ãå¿
èŠããããšèããŠããŸãã
æè¿ã®
äŸããããªã©ã³ãã®ã·ã¹ãã 管çè
ã«ããGitLabãŠãŒã¶ãŒã®ãããžã§ã¯ãã®ããã¥ã¡ã³ããšã³ãŒãã倿ŽããèŠæ±ã䌎ãããŒã¿ããŒã¹ã®äžéšã®åé€ã ãã®åŸãå瀟ã¯ãå®è£
ããã5ã€ã®ããã¯ã¢ããã¹ãã¬ãŒãžã·ã¹ãã ã®ããããæ
å ±ã®åŸ©å
ã«åœ¹ç«ããªãã£ããšææããŸããã
ãããã£ãŠãããã¯ã¢ãããäœæããããžãã¹ã®èŠä»¶ãèæ
®ããŠãå¯èœãªéãé »ç¹ã«æºåã確èªããããšã¯åœç¶ã®ããšã§ãã ããšãã°ãWebã¢ããªã±ãŒã·ã§ã³éçºäŒç€Ÿã§ããNeon Rainã®ãšã³ãžãã¢ã¯ãé±ã«1åãã¡ã€ã«ãããã¯ã¢ããããæ¯æ©ããŒã¿ããŒã¹ãããã¯ã¢ããããŸãã Cloud Academiesã§ããŒã¿ããŒã¹ã®æ¯æ¥ã®ããã¯ã¢ããã³ããŒã
äœæããŸã ã ããšãã°ãChalvington Groupã®ããã¯ã¢ããã®ãã§ãã¯ã«é¢ããŠã¯ãå埩ã®å¯èœæ§ãæ¯æ
è©äŸ¡ãããŸãã
äžè¬ã«ã1æ¥ã«1åããã¯ã¢ããããã®ã
éåžžã®æ¹æ³ã§ãã äž»ãªããšã¯ãããã¯ã¢ããã䜿çšããŠãµãŒããŒãžã®ã¢ã¯ã»ã¹ãå¶éããããšã§ããåŒãç¶ãã¢ã¯ã»ã¹ããã¢ã«ãŠã³ãã®å Žåãã¡ã€ã³ã€ã³ãã©ã¹ãã©ã¯ãã£ã§äœ¿çšããããã®ãšã¯ç°ãªãæ¿èªã¡ã«ããºã ã䜿çšãã䟡å€ããããŸãã
ç¬èªã®ããã¯ã¢ããã€ã³ãã©ã¹ãã©ã¯ãã£ãç·šæããããªãå Žåã¯ãããã¯ã¢ããã³ããŒã®ä¿åãæ
åœãããµãŒãããŒãã£ãã³ããŒã«ãã®ã¿ã¹ã¯ã転éããããšããå§ãããŸãã ããšãã°ã1cloudã§ã¯ã1æ¥ã«1åããã¯ã¢ããããã¯ã©ã€ã¢ã³ãã¯ã³ããŒã«å¿
èŠãªã¹ãã¬ãŒãžæéïŒ7ã14ã21ããŸãã¯28æ¥ïŒãéžæããŸãã
äžèšã®ããŒã«ãšèšå®ã¯ãã·ã¹ãã ãä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã ã¯ããããããçš®é¡ã®æ»æããITã€ã³ãã©ã¹ãã©ã¯ãã£ã100ïŒ
ä¿è·ããããšã¯ç©ççã«äžå¯èœã§ãããã¯ã©ãã«ãŒã®å¯¿åœãè€éã«ããæœåšçãªãšã¯ã¹ããã€ãã®æ°ãå¶éããããšã¯å¯èœã§ãã æ³šæã泚æãããã³æ³šæãæãã°ãéèŠãªæ±ºå®ãäžããä¿è·å¯Ÿçãè¬ããã®ã«å¿
èŠãªæéãåŸãããšãã§ããŸãã
äŒæ¥ããã°1cloudã®ãããã¯ã«é¢ãã3ã€ã®è³æïŒ