·Î±×ÀÎ
¾ÆÀ̵ð
¾Ï   È£
ȸ¿ø°¡ÀÔ   ¾ÏÈ£ºÐ½Ç
¬á¬â¬à¬ã¬ä¬Ú¬ä¬å¬ä¬Ü¬Ú, ¬Õ¬à¬ã¬å¬Ô, ¬Ú¬ß¬Õ¬Ú¬Ó¬Ú¬Õ¬å¬Ñ¬Ý¬Ü¬Ú, ¬Ú¬ß¬ä¬Ú¬Þ http://youdosug.com - ¬á¬â¬à¬ã¬ä¬Ú¬ä¬å¬ä¬Ü¬Ú, ¬Õ¬à¬ã¬å¬Ô, ¬Ú¬ß¬Õ¬Ú¬Ó¬Ú¬Õ¬å¬Ñ¬Ý¬Ü¬Ú, ¬Ú¬ß¬ä¬Ú¬Þ
  Home
  ²ôÀû²ôÀû
  ¸®´ª½º
  ¼îÇθô
  °ÔÀÓ
  ¾Æ¹ÙŸ¼¥
  ¾Æ¹ÙŸ°ü¸®ÀÚ
  HTML ±³À° ¿¹Á¦1
  HTML ±³À° ¿¹Á¦2
  Å×½ºÆ®ÆäÀÌÁö


¸®´ª½º Tech °Ô½ÃÆÇ


ADMIN 2024. 04. 27.
 [º¸¾È] /tmp Æú´õ¸¦ ÀÌ¿ëÇÑ ÇØÅ· Â÷´Ü ¹æ¹ý
  ³¯Â¥: 2005.07.09. 14:20:03   Á¶È¸: 563
¿äÁò À¥ÇÁ·Î±×·¥ÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© /tmp Æú´õ¿¡ ÆÄÀÏÀ» ¿Ã¸° ÈÄ ÇØ´ç ÆÄÀÏÀ» ½ÇÇàÇÏ¿© ¼­¹ö¿¡ ºÎÇϸ¦ ÁÖ´Â °æ¿ì°¡ ¸¹´Ù.
ÀÌ°É ¸·´Â ¹æ¹ýÀº ¸ÕÀú 1777 ±ÇÇÑÀ¸·Î µÈ Æú´õ´Â °¡±ÞÀûÀÌ¸é ¾ø¾Ö´Â °ÍÀÌ ÁÁÀ¸¸ç ºÒ°¡ÇÇÇÒ °æ¿ì ÆÄƼ¼Ç¿¡ noexec ¸¦ Áà ½ÇÇà±ÇÇÑÀÌ ¾øµµ·Ï ÇÏ´Â °ÍÀÌ ÁÁ´Ù.

1. ¼­¹ö¿¡ 1777 ±ÇÇÑÀ¸·Î µÇ¾î ÀÖ´Â Æú´õ°¡ ¹¹°¡ ÀÖ´ÂÁö Á¶»çÇÑ´Ù.
# fine / -perm 1777 -print

2. º¸Åë /var/tmp ¿Í /tmp °¡ ÀÖÀ» °ÍÀÌ´Ù. ¿©±â¼­ /var/tmp ´Â /tmp ·Î ¸µÅ©¸¦ °É¾î Çϳª¸¸ °ü¸®ÇÏ¸é µÇµµ·Ï ÇÑ´Ù.

# rm -rf /var/tmp
# ln -s /tmp /var/tmp


3. /tmp ÆÄƼ¼Ç¿¡ ½ÇÇà±ÇÇÑÀ» ¾ø¾Ø´Ù.

(1) fstab ¼öÁ¤

# vi /etc/fstab

º¯°æ Àü)
/dev/sda10 /tmp ext3 defaults
none /dev/shm tmpfs defaults

º¯°æ ÈÄ)
/dev/sda10 /tmp ext3 defaults,noexec,nosuid
none /dev/shm tmpfs defaults,noexec,nosuid

(2) ¸®¸¶¿îÆ®
# mount -oremount /tmp
# mount -oremount /dev/shm

(3) Àû¿ë ¿©ºÎ È®ÀÎ
# mount

4. /tmp ÆÄƼ¼ÇÀÌ º°µµ·Î ³ª´²ÀÖÁö ¾Ê°í ÅëÀ¸·Î ÀâÇô ÀÖÀ» °æ¿ì ¾Æ·¡¿Í °°ÀÌ ÆÄƼ¼Ç º°µµ·Î Ãß°¡ ¼³Á¤

(1) ÆÄƼ¼Ç Ãß°¡ ¼³Á¤

# cd /dev
# dd if=/dev/zero of=tmpmount bs=1024 count=800000
# mke2fs -j /dev/tmpmount
-j ¿É¼ÇÀº ext3·Î »ý¼ºÇÑ´Ù´Â ÀǹÌ, »ý·«Çϸé ext2·Î »ý¼ºµÊ.
# mount -o loop,noexec,nosuid,rw /dev/tmpmount /tmp

(2) ¸®¸¶¿îÆ® ½Ã ¾Æ·¡¿Í °°Àº ¿¡·¯°¡ ³¯ °æ¿ì
[root@www root]# mount -o loop,noexec,nosuid,rw /dev/tmpmount /tmp
mount: Could not find any loop device, and, according to /proc/devices,
this kernel does not know about the loop device.
(If so, then recompile or `insmod loop.o'.)
ÀÌ °æ¿ì Ä¿³ÎÄÄÆÄÀÏ ½Ã
Block devices --->[*] Loopback device support ¿Í °°ÀÌ ¼±ÅÃÇØ ÁÖ¾î¾ß ÇÑ´Ù.
ÀϹÝÀûÀ¸·Î ²À ÀÌ ±â´ÉÀ» »ç¿ëÇÏÁö ¾ÊÀ¸½Ã´õ¶óµµ ¼±ÅÃÇØ ÁÖ´Â °ÍÀÌ ÁÁ´Ù.

5. noexecÀÇ ÇÑ°è
¹°·Ð À§¿Í °°ÀÌ ÇÑ´Ù°í Çؼ­ 100% /tmp ¿¡ ÆÄÀÏÀ» ¿Ã·ÁµÎ°í ½ÇÇàÇÏ´Â °ÍÀ» ¸·À» ¼ø ¾ø´Ù.
¾Æ·¡¿Í °°ÀÌ Á÷Á¢ ½ÇÇàÇÏÁö ¾Ê°í ÂüÁ¶ÇÏ¿© ½ÇÇàÇÒ °æ¿ì ÆÄƼ¼Ç¿¡ noexec¸¦ Áشٰí Çصµ ½ÇÇàÀÌ µÈ´Ù.
# /usr/bin/perl /tmp/test.cgi
# /bin/sh /tmp/test.sh
µû¶ó¼­ Áö¼ÓÀûÀÎ ¸ð´ÏÅ͸µÀÌ ÇÊ¿äÇÏ´Ù.

LIST  MODIFY DELETE WRITE REPLY 





Àüü±Û ¸ñ·Ï 2024. 04. 27.  Àüü±Û: 109  ¹æ¹®¼ö: 61764
77 [MySQL] mySqlDump ¿É¼Ç  2010.10.06.498
75 [À©µµ¿ì] À©µµ¿ì PC Á¾·á ¸í·É¾î  2010.06.29.557
74 µµ¸ÞÀÎ ÈÄÀÌÁî ¼­¹ö ¸®½ºÆ®  2010.06.11.522
73 [Tip] µµ¿ë¹æÁöÇØÁ¦ ÀÚ¹Ù½ºÅ©¸³Æ®  2010.05.12.488
72 [TIP] ÀÎŬ·çµåµÈ ÆÄÀÏ ¸ðµÎ º¸±â  2010.04.05.373
71 [MySQL] MySQL µ¥ÀÌÅÍŸÀÔÀÇ Å©±â  2010.01.05.411
70 ³» ÄÄÇ»ÅÍ ³×Æ®¿öÅ© Á¤º¸  2009.10.07.673
68 IP Address Subnet  2009.04.28.456
67 [TIP] ¾ÆÀÌÇÇ °É¾î¼­ ÇØ´ç ¾ÆÀÌÇÇ¿¡¼­¸¸ º¸ÀÌ°Ô ÇÏ±â  2009.03.18.358
66 [¸ÞÀÏ] imap Á¢¼Ó È®ÀÎ ¹æ¹ý  2009.03.02.365
64 [Tip] ¼­¹ö¿¡¼­ º¸´Â ½Ã°£°ú FTP Á¢¼Ó ½Ã º¸ÀÌ´Â ½Ã°£ÀÌ ´Ù¸¦ °æ¿ì  2008.06.25.364
63 [¾ÆÆÄÄ¡] ¾ÆÆÄÄ¡ °øÀ¯ ¸Þ¸ð¸® ¿À·ù  2007.03.31.399
62 ROOT DNS ã±â  2007.02.28.454
61 m07  2006.12.14.434
60 [Tip] °Ë»ö¿£ÁøÀÌ ±Ü¾î°¡´Â °Í ¸·±â  2006.05.22.330
59 [¾ÆÆÄÄ¡] ÅÚ·¹Æ÷Æ®·Î ±Ü¾î°¡´Â°Å ¸·±â  2006.05.22.396
58 [³×ÀÓ¼­¹ö] ³×ÀÓ¼­¹ö¸¦ ÀÌ¿ëÇÑ ´ëÇü»çÀÌÆ® ±¸ÃàÀ» À§ÇÑ ¼­¹öºÐ»ê  2006.03.14.538
57 alz ÷ºÎ Å×½ºÆ®  2006.03.07.458
56 [¸í·É¾î] find ¸í·É¾î À¯¿ëÇÑ »ç·Ê  2005.12.16.390
55 [FTP] proftpd Á¢¼Ó ½Ã ´À¸° °æ¿ì  2005.11.22.434
54 [qmail] qmail °ü·Ã ¸í·É¾î  2005.10.27.596
53 [¸®´ª½º] RPM ÆÐÅ°Áö ¸¸µé±â  2005.10.20.359
118 re: [¸®´ª½º] RPM ÆÐÅ°Áö ¸¸µé±â 2022.04.10.69
52 MySQL 4.1 Update From 4.0  2005.10.10.569
51 test  2005.09.21.1040
50 QmailScanner ½ºÆÔ¸ÞÀÏ ÇÊÅ͸µ Ãß°¡ ±ÔÄ¢  2005.09.07.455
49 [qmail] ÀÎÄÚµù¹®ÀÚ¿­ ¸¸µå´Â ¹æ¹ý  2005.08.30.350
48 [Àå¾Öó¸®] ERR Can't get lock. Mailbox in use ´ëó¹ý  2005.08.18.492
47 martian source IP from 0.0.0.0, on dev eth0  2005.08.11.910
46 [º¸¾È] /tmp Æú´õ¸¦ ÀÌ¿ëÇÑ ÇØÅ· Â÷´Ü ¹æ¹ý  2005.07.09.563
RELOAD WRITE
[1] 2 [3] [4] 





Copyright¨Ï 2002 RUBICON