๐ŸŒ‡โ”‚System_Study/๐Ÿ”โ”‚Etc..

๊ธฐ๋Šฅ๊ฒฝ๊ธฐ๋Œ€ํšŒ - 1

Jastes 2023. 3. 4. 13:31

 

ํ•ด๋‹น ๋‚ด์šฉ์„ ์‹ค์Šต ํ›„ ์ •๋ฆฌํ•˜๊ธฐ ๐Ÿ“™

๊ธฐ์ดˆ(์ง€๋ฐฉ๋Œ€ํšŒ ๋‚ด์šฉ).pdf
1.01MB

1. SSH ์ ‘์† ์‹œ ๋ฉ”์‹œ์ง€ ์ถœ๋ ฅ ์„ค์ •

/etc/ssh/sshd_config ํŒŒ์ผ๋กœ ๋“ค์–ด๊ฐ„ ํ›„ ํŒŒ์ผ์—์„œ 22๋ฒˆ ํฌํŠธ๊ฐ€ ์—ด๋ ค์žˆ๋Š”์ง€ ํ™•์ธํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.
์ฐธ๊ณ ๋กœ /etc(์‹คํ–‰ํŒŒ์ผ)/ssh(ํฌํŠธ)/sshd_config(daemon์œผ๋กœ ๋ฐฑ๊ทธ๋ผ์šด๋“œ ์„ค์ •ํŒŒ์ผ)๋กœ์จ
์œ„์™€ ๊ฐ™์ด ์ƒ๊ฐํ•˜์‹œ๋ฉด ์‰ฝ๊ฒŒ ์œ„์น˜๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ฃผ์„ ์ œ๊ฑฐํ•œ ๋ชจ์Šต

์•„ ๊ทผ๋ฐ ์šฐ๋ถ„ํˆฌ๊ฐ€ ๊ฐ€์žฅ ๋ฒ”์šฉ์ ์ด๊ณ , ๋Œ€์ค‘์ ์ด๋‹ˆ ๊ฑฐ๊ธฐ์„œ ํ•˜๋Š”๊ฒŒ ์ข‹๊ฒ ๋„ค์š”
๊ทธ๋ฆฌ๊ณ  ํ•ด๋‹น ๋ชจ๋“ˆ์ธ ssh์™€ net-tools๋Š” ์„ค์น˜ํ•ด์ฃผ์„ธ์š”(์•ต๊ฐ„ํ•ด์„  ์žˆ์„๊ฑฐ์˜ˆ์š”)


2. SSH ์ ‘์† ์‹œ ๋ฉ”์‹œ์ง€ ์ถœ๋ ฅ ์„ค์ •

 

How to Fix SSH Failed Permission Denied (publickey,gssapi-keyex,gssapi-with-mic)

The SSH Permission Denied (publickey,gssapi-keyex,gssapi-with-mic) appears on SSH login. This tutorial features the steps to fix the error.

phoenixnap.com

 

 

๋ฆฌ๋ˆ…์Šค SSH ์ ‘์† ๋ฐฉ๋ฒ• (SSH ํ”„๋กœํ† ์ฝœ ์—ฐ๊ฒฐ ํ—ˆ์šฉ ์„ค์ •ํ•˜๊ธฐ) - JooTC

๋ฆฌ๋ˆ…์Šค SSH ์ ‘์† ๋ฆฌ๋ˆ…์Šค ์„œ๋ฒ„์— ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•ด ์ง์ ‘ ๋กœ์ปฌ PC์—์„œ ํ„ฐ๋ฏธ๋„์ด๋‚˜ ๊ทธ๋ž˜ํ”ฝ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ํ™œ์šฉํ•˜์—ฌ ์ž‘์—…์„ ์ง„ํ–‰ํ•˜๊ฑฐ๋‚˜, ์›๊ฒฉ์ง€์—์„œ ํ˜ธ์ŠคํŠธ ์ ‘์†์„ ์œ„ํ•œ ํ”„ํ† ๋กœ์ฝœ์„ ์‚ฌ์šฉํ•œ ์—ฐ๊ฒฐ์ด ์žˆ์Šต

jootc.com

SSH์™€ ๊ด€๋ จ๋œ ๋ชจ๋“ˆ์„ ์„ค์น˜ํ•ด๋„ ์•ˆ๋˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์ข…์ข… ์žˆ๋Š”๋ฐ ์œ„ ๋งํฌ๋ฅผ ์ ‘์†ํ•˜์—ฌ
ํ•ด๊ฒฐํ•ด๋ณด์„ธ์š”(์ €๋Š” ๋‹ค๋ฅธ ๋ฌธ์ œ๋กœ ์ด์ƒ์ด ์žˆ์—ˆ๋Š”๋ฐ sudo passwd๋กœ ํ™˜๊ฒฝ์ธ์ž๋ฅผ ๋„ฃ์–ด์•ผ ๋จ)

์œ„ ๊ทธ๋ฆผ์˜ ์ฐจ์ด์ ์€ ๋ฐฐ๋„ˆ์— ๋ฌธ๊ตฌ๋ฅผ ๋„ฃ์—ˆ๋ƒ ์•ˆ ๋„ฃ์—ˆ๋ƒ ์ฐจ์ด์ธ๋ฐ
์ด์ฒ˜๋Ÿผ SSH์— ์›๊ฒฉ์ ‘์†(์ €ํฌ๋Š” ํ‘œ์‹œ๋ฅผ ์œ„ํ•ด ๋กœ์ปฌ๋กœ)๋กœ ๋“ค์–ด์™”์„ ๋•Œ ๋‚˜์˜ค๋Š” ๋ฌธ๊ตฌ๊ฐ€ Banner๋ผ๊ณ  ํ•ฉ๋‹ˆ๋‹ค.
๊ทธ๋Ÿผ ํ•œ๋ฒˆ ๋ฉ”์‹œ์ง€๋ฅผ ์ถ”๊ฐ€ํ•ด๋ด…์‹œ๋‹ค.

๋จผ์ € /etc/ssh/sshd_config์˜ ๊ฒฝ๋กœ์— ๋“ค์–ด๊ฐ€์„œ Banner์˜ ์ฃผ์„์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
์—ฌ๊ธฐ์„œ Banner๊ฐ€ none์œผ๋กœ ๋˜์–ด ์žˆ๋‹ค๋ฉด(๋ฒ„์ „ ์—…๋ฐ์ดํŠธ๋กœ ์•ˆ๋˜๋Š” ๊ฑฐ ๊ฐ™์œผ๋‹ˆ๊นŒ)
apt install -y openssh-server ์„ ํ•˜์‹œ๋Š” ๊ฒƒ๋„ ๋‚˜์˜์ง„ ์•Š์•„์š”(ํ•ด๋„ ์ „ ๋ณ€ํ™”๊ฐ€ ์—†๊ธด ํ•˜๋˜๋ฐ)

๊ทธ๋Ÿฌ๋ฉด ํ•ด๋‹น ์ฃผ์„์— /etc/issue.nat(ํŒŒ์ผ์„ ์›ํ•˜๋Š” ํ˜•ํƒœ๋กœ ์ถœ๋ ฅํ•ด์คŒ)์„ ์ถ”๊ฐ€ํ•˜๊ณ 
ํ•ด๋‹น ๊ฒฝ๋กœ๋กœ ๊ฐ€์„œ ์›ํ•˜๋Š” ๋ฌธ๊ตฌ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

๊ทธ๋ฆฌ๊ณ  service ssh(d) restart or systemctl restart ssh๋ฅผ ํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.
๋” ์ž์„ธํžˆ๋Š” ์ถ”ํ›„ ๋” ์•Œ์•„๋ด…์‹œ๋‹ค.


3. ๋น„๋ฐ€๋ฒˆํ˜ธ ์ •์ฑ… ์„ค์ •

์ผ๋‹จ ๋ฆฌ๋ˆ…์Šค ์ž์ฒด๊ฐ€ ์ง€ํ–ฅํ•˜๋Š” ๋ถ€๋ถ„ ์ค‘ ํ•˜๋‚˜๋Š” ๋‹ค์ค‘ ์‚ฌ์šฉ์ž์ด๋‹ค. ๊ทธ๋Ÿฌ๊ธฐ์— ๋น„๋ฒˆ ์ •์ฑ… ์„ค์ • ์•Œ์•„๋ณด์ž

์ผ๋‹จ ์œ ์ €๋ฅผ ์ƒ์„ฑํ•ด์ค€๋‹ค(root ๊ถŒํ•œ์ด ์žˆ์–ด์•ผ ์ƒ์„ฑ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค)
๊ทธ ํ›„ ๋น„๋ฒˆ ์ •์ฑ… ์„ค์ • ํ›„ ํ™•์ธํ•ด๋ด…์‹œ๋‹ค.


/etc/login.defs

login์˜ default ๊ธฐ๋ณธ ๋น„๋ฒˆ ํ•ญ๋ชฉ์„ ์ง€์ •ํ•˜๋Š” ํŒŒ์ผ
  • PASS_MAX_DAYS
    : ๋น„๋ฒˆ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ๋Œ€ ์ผ์‹œ
  • PASS_MIN_DAYS
    : ๋น„๋ฒˆ ๋ฐ”๊พธ๋Š” ์‚ฌ์ด์˜ ์ตœ์†Œ ์ผ์‹œ
  • PASS_MIN_LEN
    : ๋น„๋ฒˆ ์ตœ์†Œ ๊ธธ์ด
  • PASS_WARN_AGE
    : ๋น„๋ฒˆ ๋งŒ๋ฃŒ ์ „ ๊ฒฝ๊ณ ํ•˜๋Š” ์ผ์‹œ


etc/pam.d/command-password

login.defs์˜ ํŒŒ์ผ์—์„  ์„ค์ •ํ•  ์ˆ˜ ์—†์—ˆ๋˜ ์„ธ๋ถ€๋‚ด์šฉ
etc/pam.d/command-* ๋ถ€๋ถ„์—์„œ ์˜์–ด ํ•ด์„ ๊ทธ๋Œ€๋กœ ์„ค์ • ๊ฐ€๋Šฅ

์œ„์™€ ๊ฐ™์ด ์„ค์ •์„ ํ•˜์…จ๋‹ค๋ฉด ๋‚˜๊ฐ€์…”์„œ ๋น„๋ฒˆ ์„ค์ • ํ™˜๊ฒฝ์„ ํ™•์ธํ•˜์‹ ๋‹ค๋ฉด..

์œ„์™€ ๊ฐ™์ด ์„ค์ •์ด ๋œ ๋ชจ์Šต์„ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
์ฐธ๊ณ ๋กœ ์‹คํ–‰์ด ์•ˆ๋œ๋‹ค๋ฉด ์•„๋ก€ ๋ชจ๋“ˆ์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์•„์ฃผ์„ธ์š”

์œ„์™€ ๊ฐ™์ด ํŒจํ‚ค์ง€๋ฅผ ๋‹ค์šด๋กœ๋“œ๋ฅผ ๋ฐ›์•„์•ผ ์ •์ฑ… ์„ค์ •์ด ๊ฐ€๋Šฅํ•˜๋‹ค๊ณ  ํ–ˆ๋Š”๋ฐ
์ €๋Š” ์•ˆํ•ด๋„ ๋˜๋”๋ผ๊ณ ์š”. ๋ฒ„์ „์— ๋”ฐ๋ผ ์„ฑ๊ณต์˜ ์ ‘๊ทผ ๋ฐฉ์‹์ด ๋‹ฌ๋ผ์ง€๋‚˜๋ด์š”


์•Œ๋œฐ์‹ ์žก

/var/log/apache2 diretory permission

์ œ Ubuntu์—์„  apache2๊ฐ€ ์ด์Šˆ๊ฐ€ ์žˆ๋Š”๊ฑฐ ๊ฐ™๋„ค์š”

๋‘˜์˜ ์ ‘๊ทผ ๊ถŒํ•œ์„ ๋‹ค๋ฅด๊ฒŒ ํ•˜์—ฌ ์ ‘๊ทผํ•˜๋ฉด..(user&root)
์œ„์™€ ๊ฐ™์ด apache2์˜ ๊ตฌ์„ฑ ์š”์†Œ์˜ ํŒŒ์ผ์ด user์™€ group์ด ๋‹ฌ๋ผ์ง„ ๋ชจ์Šต์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๊ทธ๋Ÿผ www-data๊ฐ€ ๋Œ€์ฒด ๋ญ˜๊นŒ์š”?


www-data๋ž€?

 

www-data not exists in centos, what is the replacement? · Issue #73 · GeoNode/documentation

There are many times the www-data is mentioned in the document, but it does not exist in the centos. So many commands in the document are not able to invoked in centos.

github.com

์œ„์—์„œ ์–ด๋Š์ •๋„ ์„ค๋ช…ํ•˜๊ณ  ์žˆ์œผ๋‚˜ ๊ฐ„๋žตํ•˜๊ฒŒ ์ •๋ฆฌํ•˜์ž๋ฉด..
์šฐ๋ถ„ํˆฌ์— ๊ธฐ๋ณธ์ ์œผ๋กœ ์กด์žฌํ•˜๋Š” User๋กœ์จ, ์‹ค์ œ /etc/passwd ํŒŒ์ผ์—์„œ ํ™•์ธํ•˜๋ฉด ์กด์žฌํ•ฉ๋‹ˆ๋‹ค.

์†”์งํžˆ www-data๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  ํŒŒ์ผ ๊ถŒํ•œ์„ root๋กœ ํ•ด๋„ ์‹คํ–‰์—๋Š” ์ง€์žฅ X
๊ทธ๋Ÿผ ์™œ www-data๋กœ ๊ณ„์ •์„ ๋ณ€๊ฒฝํ•œ ์ƒํƒœ๋ฅผ ์ง€ํ–ฅํ•˜๋ฉฐ ์™œ ๋งŒ๋“ค์–ด์กŒ์„๊นŒ์š”?
๋‹ค ์“ฐ์ž„์ด ์žˆ๊ฒ ์ฃ ?


apache2๋Š” ์›น ์„œ๋น„์Šค๋ฅผ ๊ตฌ๋™ํ•  ๋•Œ ์‚ฌ์šฉํ•˜๋ฏ€๋กœ WAS(Node.js, Nginx, Django)์™€ ๊ฐ™์€ ์„œ๋ฒ„์—
๊ตฌ๋™ํ–ˆ๋‹ค๊ณ  ํ•ด๋„ ๋ฌด๋ฐฉํ•ฉ๋‹ˆ๋‹ค(๊ธฐ๋Šฅ์ด ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค) ๊ทธ๋Ÿฌ๊ธฐ์— ๊ณต๊ฒฉ ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•œ๋‹ค๋ฉด
์˜ˆ๋ฅผ ๋“ค๋ฉด Zero-day → RCE ๊ณต๊ฒฉ์œผ๋กœ ์ด์–ด์ง„๋‹ค๋ฉด root๊ถŒํ•œ์ด๋ผ๋ฉด ํ”ผํ•ด ↑

๊ทธ๋Ÿฌ๊ธฐ์— www-data๋ผ๋Š” ์†Œ์œ ์ฃผ ๊ถŒํ•œ์ด ๋งŒ๋“ค์–ด์ง„๊ฒƒ์ด๋ฉฐ ํ•ด๋‹น ๊ถŒํ•œ์œผ๋กœ๋งŒ apache2๊ฐ€ ๊ตฌ๋™
๊ทธ๋Ÿฌ๊ธฐ์— hacker๊ฐ€ Exploit๋ฅผ ํ•ด๋„ ํ•ด๋‹น ๊ถŒํ•œ์œผ๋ก  ํ•œ์ •์ ์œผ๋กœ ๋™์ž‘๋˜๊ฒ ์ฃ 
๊ฒฐ๊ตญ ๋ณด์•ˆ์ƒ์˜ ์ด์œ ๋กœ ์กด์žฌํ•ฉ๋‹ˆ๋‹ค(๋ฏธ๋Ÿฌ์‚ฌ์ดํŠธ๋Š”..?, ๋ฐฉํ™”๋ฒฝ์˜ ์กด์žฌ ์ด์œ ๊ฐ€ ์œ ์‚ฌํ•˜์ฃ )

ํ•ด๋‹น ๋ช…๋ น์–ด๋Š” ๊ธฐ์ดˆ๋ผ์„œ ์ •๋ฆฌ ์•ˆํ• ๋ ค๊ณ  ํ–ˆ๋Š”๋ฐ ํ˜น์‹œ ๋ชฐ๋ผ์„œ.. ๊ทธ๋Œ€๋กœ ์˜ฌ๋ ค๋ด…๋‹ˆ๋‹ค ใ… 
chmod๋Š” ์ต์ˆ™ํ•˜์‹ค๊ฑฐ๊ณ  chown(er)๋ผ๋Š” ์˜๋ฏธ๋กœ ์†Œ์œ ์ž ๋ณ€๊ฒฝ์ž…๋‹ˆ๋‹ค.
์‰˜ ์Šคํฌ๋ฆฝํŠธ์—์„œ๋„ ์ค‘์š”ํ•œ -R์ด ํ•ต์‹ฌ์ด๋ผ๋Š” ์ !!


4. apache2 ํŒŒ์ผ ์—…๋กœ๋“œ ๊ถŒํ•œ ์„ค์ •

/var/www(default front)/apache2/uploads์— ์•„๋ฌด ํŒŒ์ผ์ด๋‚˜ ๋งŒ๋“ญ์‹œ๋‹ค.
touch a.txt๋ฅผ ์‹คํ–‰ํ•˜๊ณ  Index of /uploads ๋กœ ํ–ฅํ•˜๋Š” ๊ฒฝ๋กœ๋ฅผ ํ™•์ธํ•œ๋‹ค๋ฉด..

 

Ubuntu Apache2 DefaultRuntimeDir must be a valid directory, absolute or relative to ServerRoot

I have a web server running Ubuntu 17.04 that I am attempting to set up with Apache. Everything ran great until I decided to host two websites on a single machine through virtualHosts. Now apache r...

askubuntu.com

๊ทผ๋ฐ.. ์ €๋Š” apache2์˜ ํŒŒ์ผ ๊ฒฝ๋กœ๊ฐ€ ์•„๋ฌด๋ฆฌํ•ด๋„ ๋™์ž‘์€ ๋˜์ง€๋งŒ ๊ฒฝ๋กœ์— ์—†๊ธฐ์—.. ๋‚œ๊ฐํ•˜๋„ค

localhost/upload๋ฅผ ๋“ค์–ด๊ฐˆ๋•Œ ์™ผ์ชฝ์„ ์˜ค๋ฅธ์ชฝ์œผ๋กœ ๋ณด์ด๊ฒŒ ๋งŒ๋“ค์–ด์•ผํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋ฉด..

/etc/apache2/apache2.conf

granted → denied ๋กœ ๋ณ€๊ฒฝํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.
์—ฌ๊ธฐ์„œ <Directory /var/www>์˜ ์˜๋ฏธ๋Š” /var/www ๋””๋ ‰ํ† ๋ฆฌ์— ๋Œ€ํ•œ ๊ถŒํ•œ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค.

  • Require all granted : ๋ฌด์กฐ๊ฑด ํ—ˆ์šฉ
  • Require all denied : ๋ฌด์กฐ๊ฑด ๊ธˆ์ง€
  • Require ip 192.168 11 : ํŠน์ • IP๋งŒ ์ ‘๊ทผ ํ—ˆ์šฉ(Ex. 192.168๊ณผ 11๋กœ ์‹œ์ž‘๋˜๋Š” ๋Œ€์—ญ๋Œ€๋งŒ ํ—ˆ์šฉ)

5. sudo ํŠน์ • ๋ช…๋ น ์ œํ•œ

sudoers ํŒŒ์ผ์ด๋ž€?

root๋Š” ์„œ๋ฒ„์˜ ๋ชจ๋“  ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•˜์ง€๋งŒ, ์ผ๋ฐ˜ ์œ ์ €๋Š” ๋ชจ๋“  ์ž‘์—…์„ ํ•  ์ˆ˜ ์—†๊ฒŒ ๊ถŒํ•œ์„ ์ œํ•œํ•ฉ๋‹ˆ๋‹ค.
๊ทผ๋ฐ ์„œ๋ฒ„๋ฅผ ์šด์šฉํ•˜๋ฉด ์ผ๋ฐ˜ ์œ ์ €๋ฅผ ์ƒ์„ฑํ•  ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์ด ์ƒ๊น๋‹ˆ๋‹ค.

๊ทธ๋Ÿฐ๋ฐ ๋งŒ์•ฝ ์ผ๋ฐ˜ ์œ ์ €๊ฐ€ ๊ด€๋ฆฌ์ž๋งŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๋ช…๋ น์„ ์‹คํ–‰ํ•œ๋‹ค๋ฉด..
(๊ด€๋ฆฌ์ž ๊ณ„์ •์ด ์žˆ์–ด์•ผํ•˜๊ณ  ๊ถŒํ•œ ๋ถ€์—ฌํ•ด ๋ชจ๋“  ๋ช…๋ น์–ด๋ฅผ ๋ถ€์—ฌ ์ฆ‰, SetUID๊ฐ™์€ ๊ฒฝ์šฐ๋ฅผ ์ตœ์†Œํ™” ใ„ฑ)

sudoers ํŒŒ์ผ์€ ์ผ๋ฐ˜ ์œ ์ €๊ฐ€ ๊ด€๋ฆฌ์ž๋งŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๋ช…๋ น์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•˜๊ฑฐ๋‚˜ ์ œํ•œ์ด ๊ฐ€๋Šฅ

/etc/sudoers ํŒŒ์ผ์— ๋Œ€ํ•˜์—ฌ ๊ทธ๋Ÿผ ์•Œ์•„๋ด…์‹œ๋‹ค.

sudoers ํŒŒ์ผ์€ ๊ธฐ๋ณธ์ ์œผ๋กœ r(์ฝ๊ธฐ ๊ถŒํ•œ)๋งŒ ์กด์žฌํ•˜๊ธฐ ๋•Œ๋ฌธ์— ํŒŒ์ผ ์ˆ˜์ • X

์œ„์™€ ๊ฐ™์ด chmod +w /etc/sudoers ํŒŒ์ผ์˜ ์“ฐ๊ธฐ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค.
ํฌ๊ฒŒ ๋‘๊ฐ€์ง€ ๋ฐฉ๋ฒ•์œผ๋กœ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ฒซ๋ฒˆ์งธ๋Š” chmod๋กœ ํŒŒ์ผ ๊ถŒํ•œ ๋ณ€๊ฒฝ ํ›„ ์ˆ˜์ •ํ•˜๋Š” ๊ฒƒ์ด๊ณ ,
๋‘๋ฒˆ์งธ๋Š” visudo ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ํŒŒ์ผ์„ ์ˆ˜์ •ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.
ํŠนํžˆ visudo๋Š” ์ข€ ์ƒ์†Œํ•˜๋„ค์š”

update-alternatives --config editor๋กœ visudo๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ nano๋ผ์„œ
์ž์‹ ์ด ๋ณ€ํ•œ ์—๋””ํ„ฐ๋กœ ๋ฐ”๊พธ๋ฉด ๋ฉ๋‹ˆ๋‹ค.(์ €๋Š” vim์ด ํŽธํ•ด์„œ)
๊ทธํ›„ ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ด๋ด…์‹œ๋‹ค.

/etc/sudoers

Cmnd_Alias SHUTDOWN=/sbin/... ๋ผ๋Š” ์œ„์— ์ด๋ฏธ์ง€๋Œ€๋กœ ๋„ฃ๋Š”๋‹ค.
์—ฌ๊ธฐ์„  /sbin/ ๋””๋ ‰ํ† ๋ฆฌ์— ์žˆ๋Š” ๋ช…๋ น์–ด๋“ค์„ ํ—ˆ์šฉ X ๋ผ๋Š” ์˜๋ฏธ์ด๋‹ค.

๊ทธ๋ฆฌ๊ณ  %sudo ๊ฐ€ ์žˆ๋Š” ๋ผ์ธ์—์„œ !SHUTDOWN์„ ํ†ตํ•ด ํ•ด๋‹น์— ์žˆ๋Š” ๋ชจ๋“  ๊ฒƒ์„ False ์ฒ˜๋ฆฌ๋ฅผ ํ•ฉ๋‹ˆ๋‹ค.

์œ„์—๋ฅผ ํ™•์ธํ•˜๋ฉด sudo update๋Š” ์ž˜ ์‹คํ–‰๋˜์ง€๋งŒ, reboot&halt ๋“ฑ SHUTDOWN์œผ๋กœ ์ง€์ •ํ•œ
๋ช…๋ น์–ด๋Š” ์‹คํ–‰์ด ์•ˆ๋˜๋Š” ๋ชจ์Šต์ž…๋‹ˆ๋‹ค.


6. ๋ฐฑ์—… ์Šคํฌ๋ฆฝํŠธ ์ž‘์„ฑ

์„œ๋ฒ„ ๊ด€๋ฆฌ ์‹œ์—๋Š” ๋ฐฑ์—…์ด ์ค‘์š”ํ•˜๊ณ  ์…ธ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํ™œ์šฉํ•˜๋ฉด ๋ฐฑ์—…์„ ํšจ์œจ์ ์œผ๋กœ ํ•˜๋ฏ€๋กœ
ํ•œ๋ฒˆ ๋ฐฐ์šธ ๊น€์— ๊ณต๋ถ€ํ•ด๋ด…์‹œ๋‹ค.

ํ•ด๋‹น ์œ ์ € ๊ณ„์ •์— backup ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ๋งŒ๋“ค๊ณ  ํ•ด๋‹น ํŒŒ์ผ์—
/var/log/* ํŒŒ์ผ๊ณผ /etc/* ํŒŒ์ผ์„ .tar.gz ํŒŒ์ผ๋กœ ์••์ถ•ํ•ด ๋ฐฑ์—…ํ•˜๋Š” ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ•ด๋ด…์‹œ๋‹ค.

์•Œ๋“ค์‹ ์žก - ์••์ถ• ํ˜•์‹์„ ์•Œ์•„๋ด…์‹œ๋‹ค.
 ์••์ถ• ํฌ๋ฉง์˜ ํ™•์žฅ์ž๋Š” .zip .tar .gz(gzip) .7z ๋“ฑ ๋ฌด์ง€ ๋งŽ์Šต๋‹ˆ๋‹ค.
์—ฌ๊ธฐ์„  .tar.gz ์ค‘์ ์œผ๋กœ ์•Œ์•„๋ด…์‹œ๋‹ค.

 .tar ๋Š” ์—ฌ๋ŸฌํŒŒ์ผ์„ ๋ฌถ๋Š” ๋ฐฉ๋ฒ•์ด๊ณ  .gz๋Š” ๋ฌถ์€ ํŒŒ์ผ์„ ์ž‘๊ฒŒ ์••์ถ•
๊ทธ๋Ÿฌ๊ธฐ์— ๋‘๊ฐœ๋ฅผ ๋™์‹œ์— ์‚ฌ์šฉํ•˜์—ฌ ์ž์› ์ ˆ์•ฝ ๋ฐ ํšจ์œจ์„ฑ์„ ๋Š˜๋ฆผ

> tar ๋ช…๋ น์–ด ์˜ต์…˜

๋ฐฑ์—… ์Šคํฌ๋ฆฝํŠธ ์ž‘์„ฑ

์œ„์™€ ๊ฐ™์ด ๋ฐฑ์—… ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
์ฐธ๊ณ ๋กœ Shell_Script๋Š” C์–ธ์–ด์™€ ๋ฆฌ๋ˆ…์Šค ๋ช…๋ น์–ด์™€ ๋น„์Šทํ•˜๋ฏ€๋กœ ์ง๊ด€์ ์œผ๋กœ ๋ณด์ผ ๊ฒ๋‹ˆ๋‹ค.
๋‹ค๋งŒ ๋ฌธ๋ฒ• ํ™œ์šฉ ๋ถ€๋ถ„์—์„œ ์ต์ˆ™ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์„ ๋“ฏ ์‹ถ๋„ค์š”(์ €๋„ ์•ฝ๊ฐ„ ๊ทธ๋ž˜์š” ใ… )


Tip. ์„œ๋ฒ„ ๊ด€๋ฆฌ

์„œ๋ฒ„๋ฅผ ๊ด€๋ฆฌํ•˜๋ฉด ์ž๋™ํ™”์— ๋Œ€ํ•˜์—ฌ ๋งŽ์€ ๋ถ€๋ถ„์„ ๊ณ ๋ฏผํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.
ํŠนํžˆ ๋ฐฑ์—… ์Šคํฌ๋ฆฝํŠธ๋Š” ์ž๋™ํ™”๋ฅผ ์œ„ํ•ด ๋งŒ๋“ค์—ˆ์ง€๋งŒ ๋‹จ์ ๋„ ๋ช…ํ™•ํ•˜๊ฒŒ ๋ณด์ž…๋‹ˆ๋‹ค.
๋งค๋ฒˆ ๋ฐฑ์—…์„ ํ•˜๊ธฐ ์œ„ํ•ด์„  backup.sh ํŒŒ์ผ์„ ์‹คํ–‰ํ•ด์•ผํ•˜๋‹ˆ๊นŒ์š”

๊ทธ๋Ÿฌ๊ธฐ์— Cron์ด๋ผ๋Š” ์ž๋™ํ™”๋ฅผ ์œ„ํ•œ ๋„๊ตฌ๋ฅผ ์†Œ๊ฐœํ•ฉ๋‹ˆ๋‹ค.
Crontab(Windows์˜ ์Šค์ผ€์ฅด๋Ÿฌ ๊ฐ™์€ ๊ณ„๋…) ์•Œ๋žŒ ๊ฐ™์€ ๊ณ„๋…์ž…๋‹ˆ๋‹ค.
์ด Crontab์„ ์ด์šฉํ•˜์—ฌ backup Script์˜ ๋™์ž‘์˜ ๋‹จ์ ์„ ํ•ด๊ฒฐํ•ฉ์‹œ๋‹ค.

 

crontab ๋ช…๋ น

์šฉ๋„ cron ์ž‘์—…์„ ์ œ์ถœ, ํŽธ์ง‘, ๋‚˜์—ด ๋˜๋Š” ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค. ๊ตฌ๋ฌธ crontab [ -e [UserName] | -l [UserName] | -r [UserName] | -v [UserName] | File ] ์„ค๋ช… crontab ๋ช…๋ น์€ cron ์ž‘์—…์„ ์ œ์ถœ, ํŽธ์ง‘, ๋‚˜์—ด ๋˜๋Š” ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค. cron ์ž‘์—…

www.ibm.com

์ƒ์„ธํ•œ ๋‚ด์šฉ์€ ์œ„์— ๋งํฌ๋ฅผ ํ†ตํ•ด ํ•™์Šต ํ›„ ํ™€์šฉํ•˜์‹œ๊ธธ ๋ฐ”๋ž๋‹ˆ๋‹ค.
๊ทธ๋Ÿผ Crontab + Shell Script๋ฅผ ํ†ตํ•ด ํŠน์ • ์ฃผ๊ธฐ๋งˆ๋‹ค ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰
์ฆ‰, ์ž๋™ ๋ฐฑ์—…๋„ ๊ฐ€๋Šฅํ•˜๋‹ค๋Š” ์ ์ด ๋ณด์ด๊ฒ ์ฃ ?


7. SSH ์ธ์ฆ ์ตœ๋Œ€ ํšŸ์ˆ˜ ์ œํ•œ

SSH ์ธ์ฆ ์ตœ๋Œ€ ํšŸ์ˆ˜ ์ œํ•œ๊ณผ ๋ฉ”์‹œ์ง€ ๋„์šฐ๊ธฐ ํ•ด๋ด…์‹œ๋‹ค.

/ect/ssh/sshd_conf

ํ•ด๋‹น ๊ฒฝ๋กœ์—์„œ ํŽธ์ง‘์„ MaxAuthTries ์ฃผ์„์„ ํ•ด์ œํ•œ ํ›„ ์ง€์ •ํ•˜๋ฉด..

์ €๋Š” SSH ์„ค์ •์—์„œ ๋ญ” ๋ฌธ์ œ ์ƒ๊ฒจ์„œ ์•ˆ๋ฌ๋Š”๋ฐ
์‹ค์ œ๋กœ๋Š” Too many auth.. failures ๋จธ๋ผ๋จธ๋ผ ๋‚˜์˜ต๋‹ˆ๋‹ค.

์ด๊ฑด ์ง„์งœ ๊ฐ„๋‹จํ•œ ๋ฌธ์ œ๋„ค์—ฌ;;


Vi ํŽธ์ง‘๊ธฐ ์ž๋™ํ™” ํ•ด๊ฒฐ์ฑ…

sed๋ผ๋Š” ํ‚ค์›Œ๋“œ๊ฐ€ ํ•ต์‹ฌ์ž…๋‹ˆ๋‹ค.
sed๋ฅผ ์ด์šฉํ•œ ๋ช…๋ น์„ ์ ๊ณ  ์‰˜ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•˜๋ฉด ์ €์ ˆ๋กœ ํŒŒ์ผ์ด ์ˆ˜์ •๋ฉ๋‹ˆ๋‹ค.

sed๋ž€?
์ˆ˜์ •, ์น˜ํ™˜, ์‚ญ์ œ, ๊ธ€ ์ถ”๊ฐ€ ๋“ฑ ํŽธ์ง‘๊ธฐ์— ์‚ฌ์šฉํ•  ์›ฌ๋งŒํ•œ ๊ธฐ๋Šฅ ์‚ฌ์šฉ๊ฐ€๋Šฅ

๊ทธ๋ฆฌ๊ณ  ๋ช…๋ น์–ด๋กœ ์“ธ ์ˆ˜ ์žˆ๋‹ค๋ฉด ์‰˜ ์Šคํฌ๋ฆฝํŠธ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๋œป์ด ๋ฉ๋‹ˆ๋‹ค!!


-s : ์น˜ํ™˜

Ex) sed 's/AAAAA/BBBBB/' ./Hello.txt

์œ„์™€ ๊ฐ™์ด ์ž…๋ ฅํ•˜๋ฉด AAA..๊ฐ€ BBB..๋กœ ๋ฐ”๋€Œ์–ด ์ถœ๋ ฅ๋˜์ง€๋งŒ,
ํŒŒ์ผ์€ ๋ณ€๊ฒฝ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.


-i : ์ž…๋ ฅ

Ex) sed -i 's/AAAAA/BBBBB/' ./Hello.txt

์œ„ ํ‚ค์›Œ๋“œ์— -i๋ฅผ ์‚ฝ์ž…ํ–ˆ์„ ๋ฟ์ธ๋ฐ, ํŒŒ์ผ ๋‚ด์šฉ๋„ ๋ณ€๊ฒฝ๋œ ๋ชจ์Šต


sed์˜ ์žฅ์ ?

  • ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ์ผ๊ด„์ ์œผ๋กœ ์ˆ˜์ •&์ž‘์„ฑ ๊ฐ€๋Šฅ
    - awk, grep ๋ช…๋ น์–ด ๋“ฑ๊ณผ ์—ฐ๋™ ๊ฐ€๋Šฅ
  • regex์™€ ๊ฐ™์€ ์ •๊ทœ ํ‘œํ˜„์‹์œผ๋กœ ์ •๋ฐ€ํ•˜๊ณ  ์„ธ๋งํ•œ ์ž‘์—… ๊ฐ€๋Šฅ
  • ๋‹ค์–‘ํ•œ ํŒŒ์ผ์„ ์ˆ˜์ •ํ•˜๋Š” ๊ฒƒ์„ ์ž๋™ํ™” ํ•  ๋•Œ ์ •๋ง ์œ ์šฉ
 

[๋ฆฌ๋ˆ…์Šค/์œ ๋‹‰์Šค] ์œ ์šฉ ๋ช…๋ น์–ด sed๋ฅผ ์‚ดํŽด๋ณด์ž! sed ๋ช…๋ น์–ด ์‚ฌ์šฉ๋ฒ•๊ณผ ์˜ˆ์‹œ, ํŒจํ„ด ์ŠคํŽ˜์ด์Šค์™€ ํ™€๋“œ ์Šค

[๋ฆฌ๋ˆ…์Šค ์œ ๋‹‰์Šค ์™„์ „์ •๋ณต ๋ชฉ์ฐจ] ์•ˆ๋…•ํ•˜์„ธ์š”. ์ฃผ์ธ์žฅ ์–‘ํ–„์ฐŒ์ž…๋‹ˆ๋‹ค. ์˜ค๋Š˜์€ sed ๋ช…๋ น์–ด์— ๋Œ€ํ•ด ์‚ดํŽด๋ณด๋ ค๊ณ  ํ•ด์š”. SED ๋ช…๋ น์–ด ์•Œ๊ธฐ, SED๋Š” ๋ฌด์Šจ ๋ช…๋ น์–ด์•ผ? viํŽธ์ง‘๊ธฐ ์•„์‹œ์ฃต~ sed ๋ช…๋ น์–ด๋„ viํŽธ์ง‘๊ธฐ์ฒ˜๋Ÿผ

jhnyang.tistory.com

๋”์šฑ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์•„๋ก€ ๋งํฌ์—์„œ ์ฐธ๊ณ  ๋ฐ”๋ž๋‹ˆ๋‹ค.
์ €๋„ ๊ณต๋ถ€ํ•  ๋•Œ ๋„์›€์ด ๋งŽ์ด ๋œ ์ž๋ฃŒ์ž…๋‹ˆ๋‹ค.


์ฐธ๊ณ  ์ž๋ฃŒ

 

[CentOS] ํŒจ์Šค์›Œ๋“œ ์ •์ฑ… ์„ค์ •

1. ํŒจ์Šค์›Œ๋“œ ์ •์ฑ… ํ™•์ธ [root@localhost ~]# chage -l root Last password change : never Password expires : never Password inactive : never Account expires : never Minimum number of days between password change : 0 Maximum number of days between passwo

tistory.latch.co.kr

๋”๋ณด๊ธฐ

์ฐธ๊ณ  ์ด๋ฏธ์ง€