BACKRUSH  À¯´Ð½º¸í·É  ´ÙÀ½  ÀÚ·á½Ç  Ascii Table   ¿ø°ÝÁ¢¼Ó  ´Þ·Â,½Ã°£   ÇÁ·Î¼¼½º   ½©
ÁöÇÏö³ë¼±   RFC¹®¼­   SUN FAQ   SUN FAQ1   C¸Þ´º¾ó   PHP¸Þ´º¾ó   ³Ê±¸¸®   ¾Æ½ºÅ°¿ùµå ¾ÆÀÌÇǼ­Ä¡

±Û¾´ÀÌ: wrapper Tcp_Wrapper È°¿ë Á¶È¸¼ö: 7637


TCP_wrapper

Network service(finger, frp, telnet, rlogin, rsh, exec, tftp, talk µî)¿¡ ´ëÇÑ ¿ä±¸¸¦¸ð´ÏÅ͸µ ¹× ÇÊÅ͸µÇÏ¿© log file(service¸¦ ¿äûÇÑ client name°ú service nameÀ» ±â·Ï)À» ¸¸µé¸ç ¸î°¡Áö ºÎ°¡ÀûÀÎ º¸¾È üũ¸¦ ÇÏ´Â º¸¾È °­È­ µµ±¸ÀÌ´Ù. Tcpwrapper´Â Å©±âµµ ÀÛÀ» »Ó´õ·¯ system¿¡ Á¸ÀçÇÏ´Â software³ª configuration file¸¦¹Ù²Ü ÇÊ¿ä°¡ ¾øÀ¸¸ç client¿Í server application »çÀÌÀÇ ½ÇÁúÀûÀÎ communication¿¡ ´ëÇØ ºÎÇϸ¦ ÁÖÁö ¾Ê´Â´Ù. TCP_wrapper´Â ³×Æ®¿÷ ÆÐŶÀ¸·ÎºÎÅÍ ¾ò¾îÁö´Â ¼Ò½º ¾îµå·¹½º Á¤º¸¸¦ ¹ÙÅÁÀ¸·Î access control, host name spoofing, host address spoofing, client username lookups, language extensions, multiple ftp/gopher/www archives on one host, banner messages, sequence number guessing µîÀÇ ±â´ÉÀ» ¼öÇàÇÑ´Ù.

1) ¾îµð¼­ °¡Á®¿À³ª

´ÙÀ½¿¡¼­ anonymous FTP¸¦ ÀÌ¿ëÇÏ¿© ±¸ÇÒ ¼ö ÀÖ´Ù.

ftp//:ftp.cert-kr.or.kr/pub/tools/tcp_wrapper/tcp_wrappers_7.4.tar.Z

2) Tcp wrapperÀÇ ÀÛµ¿

´ëºÎºÐÀÇ TCP/IP applicationÀº client-server ¸ðµ¨À» ±â¹ÝÀ¸·Î ÇÑ´Ù. ¿¹¸¦ µé¸é »ç¿ëÀÚ°¡ telnet¸¦ ÀÌ¿ëÇÏ¿© ´Ù¸¥ È£½ºÆ®¿¡ ¿¬°áÇÏ¸é ±× target È£½ºÆ®¿¡´Â in.telnetdÀ̶ó´Â ÇÁ·Î¼¼¼­°¡ ±¸µ¿µÇ¾î »ç¿ëÀÚ¿¡°Ô login process¸¦ ¿¬°áÇØ ÁØ´Ù. ÀÌ·¯ÇÑ ¹æ½ÄÀº º¸Åë inetd process¸¦ ÀÌ¿ëÇÏ¿© ±¸µ¿µÇ´Âµ¥ inetd´Â inetd.conf¿¡ Á¤ÀǵǾî ÀÖ´Â ¿©·¯°¡Áö network connectionÀ» ±â´Ù¸®´Ù°¡ ¾î¶² service°¡ ¿¬°áµÇ¸é inetd´Â Àû´çÇÑ server program¸¦ ±¸µ¿½ÃŲ´Ù.(À§ÀÇ °æ¿ì telnetÀÌ µé¾î¿À¸é inetd´Â in.telnetd¸¦ ±¸µ¿ÇÏ°Ô µÈ´Ù. ¹°·Ð ÀÌ°ÍÀº inetd.conf¿¡ Á¤ÀÇ µÇ¾î ÀÖ´Ù´Â °¡Á¤ÇÏ¿¡¼­ ÀÌ´Ù.) ±×ÈÄ inted´Â ´Ù¸¥ ¿¬°áÀ» ±â´Ù¸®°Ô µÈ´Ù.

ÀÌ·± ¹æ½ÄÀº telnet¿¡ ´ëÇÑ log fileÀ» ¸¸µé¾î ÁÖÁö ¾ÊÀ¸¹Ç·Î crackerÀÇ Ä§ÀÔÀ» ¹ß°ßÇϱ⠾î·Æ´Ù. ±×·¯³ª Tcp wrapper¸¦ »ç¿ëÇϸé in.telnetd¸¦ ±¸µ¿Çϱâ Àü¿¡ tcpd¶ó´Â µ¥¸ó¸¦ ±¸µ¿½ÃÄÑ telnet¿¡ ´ëÇÑ log fileÀ» ±â·ÏÇÑ ÈÄ in.telnetd¸¦ ±¸µ¿½ÃŲ´Ù. ÀÌ·¯ÇÑ ¹æ½ÄÀ» cracker°¡ ½Ã½ºÅÛ¿¡ µé¾î ¿À±â À§ÇØ ÀÚÁÖ »ç¿ëÇÏ´Â finger, rsh, tftpµî¿¡ »ç¿ëÇϸé crackerµµ ¸ð¸£°Ô ±×ÀÇ trace¸¦ ³²°Ü ³õÀ» ¼ö ÀÖ´Ù.

wrapper ÇÁ·Î±×·¥Àº Ŭ¶óÀ̾ðÆ®ÀÇ À¯Àú(ÇÁ·Î¼¼¼­)³ª ¼­¹ö ¾îÇø®ÄÉÀ̼ǰú ¾î¶²ÇÑ »óÈ£ÀÛ¿ëµµ °®Áö ¾Ê´Â´Ù. ÀÌ°ÍÀÇ ÁÖ¿äÇÑ µÎ°¡Áö ÀÌÁ¡Àº 1)¿¡Çø®ÄÉÀ̼ǿ¡µ¶¸³ÀûÀ̸ç, 2) ¿ÜºÎ¿¡ ºñ°¡½ÃÀû(ÀÎÁõµÈ ÃÖ¼ÒÀÇ À¯Àú¿Ü¿¡) ÀÌ´Ù´Â °ÍÀÌ´Ù. wrapperÀÇ ´Ù¸¥ Áß¿äÇÑ ÀÌÁ¡Àº Ŭ¶óÀ̾ðÆ®¿Í ¼­¹ö»çÀÌ¿¡ Ãʱâ Á¢¼Ó¶§¸¸ ÀÛµ¿À» ÇÏ°í ¿¬°áµÈ ÈÄ¿¡´Â »ç¶óÁø´Ù´Â °ÍÀÌ´Ù.

wrapper ÇÁ·Î±×·¥Àº ·Î±ë Á¤º¸¸¦ syslogd¿¡ º¸³»¸ç, º¸Åë /etc/syslog.conf ÆÄÀÏÀÇ ÄÁÇDZԷ¹À̼ǿ¡ ÀÇÇؼ­ wrapper ·Î±×Á¤º¸ÀÇ À§Ä¡°¡ °áÁ¤µÈ´Ù. µðÆúÆ®·Î wrapper ·Î±×´Â sendmail µ¥¸óÀÇ ·Î±×¸¦ Ãë±ÞÇÏ´Â °°Àº Àå¼Ò¿¡ À§Ä¡ÇÑ´Ù. Makefile°ú syslog.conf ÆÄÀÏÀ» ¼öÁ¤ÇÔÀ¸·Î½á À§Ä¡¸¦ º¯°æÇÒ ¼ö ÀÖ´Ù.

3) Tcp wrapperÀÇ ±â´É

LOG FILE

À§¿¡¼­ ¾ð±ÞÇÑ °Íó·³ Tcp wrapper(Áï tctd)´Â telnet, finger, ftp, rexec, rsh, rlogin, tftp, talk, comsat µî¿¡ ´ëÇÑ log fileÀ» ¸¸µé¾î ÁØ´Ù. Default´Â sendmail daemon¿¡ ´ëÇÑ logÁ¤º¸°¡ ±â·ÏµÇ´Â °÷(/var/log/syslog)¿¡ ±â·ÏµÈ´Ù. ¸¸¾à ¹Ù²Ù°í ½ÍÀ¸¸é syslog.conf¸¦ ¼öÁ¤ÇÏ¸é µÈ´Ù.

Access Control

-DHOSTS_ACCESSÀÇ ¿É¼ÇÀ¸·Î ÄÄÆÄÀÏ µÉ¶§, wrapper ÇÁ·Î±×·¥Àº °£´ÜÇÑ ÇüÅÂÀÇaccess control¸¦ Áö¿øÇÑ´Ù. ¿¢¼¼½º´Â ¸Å È£½ºÆ®, ¸Å ¼­ºñ½º ¶Ç´Â ±×µéÀÇ Á¶ÇÕµé·Î ÄÁÆ®·ÑµÉ ¼ö ÀÖ´Ù.

Access controlÀÇ /etc/hosts.allow°ú /etc/hosts.deny¶ó´Â È­Àϵ鿡 ÀÇÇØÁ¶Á¤µÈ´Ù.

/etc/hosts.allow

in.ftpd: kiscc.cert-kr.or.kr localhost
UNKNOWN : /usr/ucb/finger @%h | /ust/ucb/mail jhkim &
in.rlogind: kiscc.cert-kr.or.kr localhost
UNKNOWN : /usr/ucb/finger @%h | /ust/ucb/mail jhkim &

À§¿¡¼­ º¸¸é ftp ³ª rlogin´Â kiscc.cert-kr.or.kr¿¡¼­ ¿À´Â °ÍÀº Çã¶ôµÈ´Ù. ±×¸®°í È£½ºÆ®ÀÇ À̸§À̳ª address¸¦ ¸ð¸£´Â °÷¿¡¼­ ¿À´Â °æ¿ì¿¡´Â ±× È£½ºÆ®¿¡ ´ëÇÑfingerÀÇ °á°ú¸¦ jhkim¿¡°Ô mail¸¦ º¸³»°Ô ÇÑ´Ù. µû¶ó¼­ ¸¸¾à cracker°¡ µé¾î¿À·Á ÇÒ ¶§ trace°¡ ³²°Ô µÈ´Ù.

/etc/hosts.deny

in.telnetd, in.rlogind, in.ftpd: ALL EXCEPT 134.75

À§¿Í °°ÀÌ /etc/hosts.deny¶ó´Â È­ÀÏÀ» ¸¸µé¾î ÁÖ¸é telnet, rlogin, ftp¿¡ ´ëÇÑ ¼­ºñ½º´Â 134.75.*.*¿¡¼­ ¿À´Â °Í¸¸ Á¦¿ÜÇÏ°í´Â ¸ðµÎ denyµÈ´Ù.

Host name spoofing

RSH¿Í RLOGIN °°Àº ³×Æ®¿÷ ¿¡Çø®ÄÉÀ̼ǿ¡¼­, Ŭ¶óÀ̾ðÆ® È£½ºÆ® À̸§Àº

4) Tcp wrapperÀÇ ¼³Ä¡

Easy Installation

¿©±â¼­´Â inetd.conf¸¦ º¯°æ½ÃÅ°Áö ¾Ê°í ¼³Ä¡ÇÏ´Â ¹æ¹ýÀ» ¼³¸íÇÑ´Ù.

ÀÏ´Ü README, MakefileÀ» ÀÐ¾î º» ÈÄ settingÇÑ´Ù.
Makefile¸¦ OS¿¡ ¸Â°Ô ȯ°æÀ» ¼³Á¤»ç°Ô µÇ¾î ÀÖÀ¸¹Ç·Î Àß È®ÀÎÇÑ ÈÄ installÀ» ÇØ¾ß ÇÑ´Ù.
¸ÕÀú ½ÇÁ¦ daemon¸¦ ¾î´À µð·ºÅ丮¿¡ µÑÁö¸¦ °áÁ¤ÇÑ ÈÄ MakefileÀÇ REAL DAEMON DIR¿¡ Àû´Â´Ù.
#Ultrix 4.x SunOS 4.x ConvexOS 10.x
REAL_DEAMON_DIR=/usr/etc/real_daemon

¿©·¯°¡Áö option¸¦ ¼±ÅÃÇÑ´Ù. ¿¹¸¦ µé¾î Access control¸¦ installÇÏ°í ½ÃÇÇÁö ¾ÊÀ¸¸é MakefleÀÇ DHOSTS ACCESS¸¦ comment½ÃÅ°¸éµÈ´Ù. ±×·¯³ª À¢¸¸ÇÏ¸é ±×³É MakefileÀ» ±×³É ³ö´©´Â °ÍÀÌ ÁÁ´Ù. ÀÚ¼¼ÇÑ °ÍÀº README, Makefile¸¦ Àо´Ù.
ÀÌÁ¦ make¸¦ ÇÑ´Ù. ÀÚ½ÅÀÇ OS¸¦ ÁöÁ¤ÇØ ÁØ´Ù.
% make sunos40

ÀÌ·¸°Ô ÇÏ¸é ¸î°³ÀÇ ½ÇÇà °¡´ÉÇÑ ÇÁ·Î±×·¥ÀÌ »ý±â°Ô µÈ´Ù. ±×Áß ¿ì¸®°¡ »ç¿ëÇÒ °ÍÀº tcpdÀÌ´Ù. ¸ÕÀú ÀÚ½ÅÀÌ ¼³Á¤ÇÑ REAL DAEMON DIRÀ» ¸¸µçÈÄ ±× µð·ºÅ丮¿¡ ½ÇÁ¦ µ¥¸óÀ» À̵¿½ÃŲ ÈÄ tcpd¸¦ ¿øÇÏ´Â daemonÀ̸§À¸·Î copyÇÑ´Ù.
% mkdir /usr/etc/real_daemon
% mv /usr/etc/in.telnetd /ust/etc/real_daemon
% cp tcpd /usr/etc/in.telnetd

ÀÌ¿Í °°ÀÌ ´Ù¸¥ daemonµéµµ moveÇÏ¸é µÈ´Ù.

Advanced installation

À§ÀÇ Easy installationÀÇ make±îÁö ÇÑ´Ù.
ÀÚ½ÅÀÌ ¼³Á¤ÇÑ REAL DAEMON DIR¸¦ ¸¸µç ÈÄ ±× µð·ºÅ丮¿¡ ½ÇÁ¦ µ¥¸óÀ» move½ÃŲ´Ù. ±× ÈÄ¿¡´Â inetd.conf¸¦ ¹Ù²Ù¾î¾ß ÇÑ´Ù. ¿¹¸¦ µé¾î
shell stream tcp nowait root /usr/etc/in.rshd in.rshd
login stream tcp nowait root /usr/etc/in.rlogind in.rlogind
exec stream tcp nowait root /usr/etc/in.rexecd in.rexecd
cosmat stream udp wait root /usr/etc/in.cosmat in.cosmat
talk stream udp wait root /usr/etc/in.talkd in.talkd



ÀÇ °æ¿ì¸¦ ´ÙÀ½°ú °°ÀÌ ¹Ù²Ù¾î ÁÖ¸é µÈ´Ù.

shell stream tcp nowait root /usr/etc/tcpd in.rshd
login stream tcp nowait root /usr/etc/tcpd in.rlogind
exec stream tcp nowait root /usr/etc/tcpd in.rexecd
cosmat stream udp wait root /usr/etc/tcpd in.cosmat
talk stream udp wait root /usr/etc/tcpd in.talkd

kill -HUP inetd-process-number ¸í·ÉÀ» ½ÇÇà½ÃŲ´Ù.
Access controlÀ» ½ÇÇàÇÏ°í ½ÍÀ¸¸é À§ÀÇ Access control¸¦ ÂüÁ¶ÇÑ´Ù.

°ü·Ã±Û : ¾øÀ½ ±Û¾´½Ã°£ : 2002/11/17 20:39 from 61.82.164.84

  (»ì·ÈÀ½)¸®´ª½ºº¸¾È±³Àç-1005 ¸ñ·Ïº¸±â »õ±Û ¾²±â Áö¿ì±â ÀÀ´ä±Û ¾²±â ±Û ¼öÁ¤ tripwire È°¿ë  
BACKRUSH  À¯´Ð½º¸í·É  ´ÙÀ½  ÀÚ·á½Ç  Ascii Table   ¿ø°ÝÁ¢¼Ó  ´Þ·Â,½Ã°£   ÇÁ·Î¼¼½º   ½©
ÁöÇÏö³ë¼±   RFC¹®¼­   SUN FAQ   SUN FAQ1   C¸Þ´º¾ó   PHP¸Þ´º¾ó   ³Ê±¸¸®   ¾Æ½ºÅ°¿ùµå ¾ÆÀÌÇǼ­Ä¡