AIX¿¡¼­ FTP¼­¹ö ±¸ÇöÇÏ´Â ¹æ¹ý
ÀÛ¼ºÀÚ °ü¸®ÀÚ ÀÛ¼º½Ã°£ 2004-06-29 11:05:58
 

AIX¿¡¼­ FTP¼­¹ö ±¸ÇöÇÏ´Â ¹æ¹ý
             
anonymous ftp¸¦ ÅëÇÏ¿© ¸ðµç »ç¿ëÀÚµéÀÌ ÆÄÀÏÀ» °øÀ¯ÇÏ¿© »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

¾Æ·¡ÀÇ ¸ñÂ÷¼øÀ¸·Î °­ÀÇ°¡ ÁøÇàµË´Ï´Ù.

------------------------------------------------------------

¥° ±âº»±¸Çö
¥± fileÀÇ owner³ª groupÀÇ À̸§À» º¸ÀÌ°Ô Çϱâ
¥² ftp½ÇÇà ·Î±× ³²±â±â
¥³ anonymous ftp »ç¿ë½Ã »ç¿ëÀÚ¿¡ µû¶ó µð·ºÅ丮 Á¢±ÙÀ» Á¦ÇÑÇϱâ

------------------------------------------------------------

[¥° ±âº»±¸Çö ]

1. ftp¶ó´Â groupÀ» »ý¼ºÇÕ´Ï´Ù.

#smitty mkgroup
Group Name : ftp

»ý¼º ÈÄ /etc/groupÀ» È®ÀÎÇÏ¿© group-id°¡ À¯ÀÏÇÏ°Ô ÁöÁ¤µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.

2. ftp¶ó´Â user¸¦ »ý¼ºÇÕ´Ï´Ù.

#smitty mkuser
User Name : ftp
Primary Group : ftp
Another user can SU to USER : false
HOME directory : /u/ftp (¿øÇÏ´Â °ÍÀ¸·Î)
User can LOGIN : false
User can LOGIN remotely : false

»ý¼º ÈÄ ´ÙÀ½À» È®ÀÎÇÕ´Ï´Ù.

/etc/passwd : 
passwordºÎºÐÀÌ '*' Àΰ¡, user-id°¡ À¯ÀÏÇÑ°¡, group-id°¡ ftp group-id Àΰ¡, 
Ȩµð·ºÅ丮 À§Ä¡

/etc/security/user :
login = false
su = false
rlogin = false
admin = false

3. ´ÙÀ½À» ½ÇÇàÇÕ´Ï´Ù.

#chmod 755 /u/ftp
#cd /u/ftp
#mkdir bin lib pub
#cp /usr/bin/ls bin/ls
#cp /lib/libc.a lib/libc.a
#chmod 555 bin
#chmod 555 lib
#chmod 777 pub

¿©±â¼­ pub´Â »ç¿ëÀÚµéÀÌ ÆÄÀÏÀ» ¿Ã¸®°Å³ª °¡Á®°¡´Â µð·ºÅ丮ÀÔ´Ï´Ù.

ÀÌÁ¦ »ç¿ëÀÚµéÀº ftp°èÁ¤À¸·Î ¾ÏÈ£ ¾øÀÌ ftpÁ¢±ÙÀ» ÇÒ ¼ö ÀÖ½À´Ï´Ù. ftp·Î µé¾î¿À¸é /u/ftp¸¦ ¡®/¡¯ ·Î ÀνÄÇϹǷΠ´Ù¸¥ µð·ºÅ丮´Â Á¢±ÙÇÏÁö ¸øÇÏ°í /u/ftp¿¡ ¼ÓÇÑ µð·ºÅ丮¿¡¸¸ Á¢±ÙÇÒ ¼ö ÀÖ½À´Ï´Ù. 

¾Æ¹«µµ ftp°èÁ¤À¸·Î rloginÀ̳ª telnet, su, rshÀ» ÇÒ ¼ö ¾ø½À´Ï´Ù. ¿ÀÁ÷ ftp¸¸ °¡´ÉÇÕ´Ï´Ù.

ftp¸¦ ÇÒ ¶§ user name¿¡ ftp ´ë½Å¿¡ anonymousµµ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÀÌ»óÀÇ ÀýÂ÷´Â /usr/lpp/tcpip/samples/anon.ftp¿¡ ½ºÅ©¸³Æ®È­µÇ¾î ÀÖÀ¸´Ï Âü°íÇϽñ⠹ٶø´Ï´Ù.

------------------------------------------------------------

[¥± fileÀÇ owner³ª groupÀÇ À̸§À» º¸ÀÌ°Ô Çϱâ]

1. /u/ftp/etc ¾Æ·¡¿¡ ´ÙÀ½°ú °°Àº ÇüÅ·Π¡°passwd¡± ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù.

ftp:*:302:1:anonymous ftp user:/u/ftp:/bin/false
root:*:0:0::/:/bin/false

¿©±â¿¡¼­ 302´Â ftpÀÇ useridÀÔ´Ï´Ù.

2. /u/ftp/etc ¾Æ·¡¿¡ ´ÙÀ½°ú °°Àº ÇüÅ·Π¡°group¡± ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù.

system:*:0: 
staff:*:1: 

3. ´ÙÀ½À» ½ÇÇàÇÕ´Ï´Ù.

#cd /u/ftp/etc
#chmod 400 * 

------------------------------------------------------------

[¥² ftsp½ÇÇà ·Î±×]

1. syslogd µ¥¸óÀ» ÀÌ¿ëÇϱâ
¨ç #smitty inetdconf

¨è "Change / Show Characteristics of an inetd Subserver"À» ¼±ÅÃÇÕ´Ï´Ù.

¨é ftp¸¦ ¼±ÅÃÇÕ´Ï´Ù.

¨ê ¡°Change the Service Program Command Line ARGUMENTS¡± Ç׸ñ¿¡ ftpd -l¸¦ ³Ö½À´Ï´Ù.

¨ë ¸¦ ÀÔ·ÂÇÕ´Ï´Ù.

¨ì /etc/syslog.conf ÆÄÀÏ¿¡ 

daemon.info /tmp/ftp.log

¸¦ ÷°¡ÇÕ´Ï´Ù.

¨í #touch /tmp/ftp.log

¨î #refresh -s syslogd

¸¦ ½ÇÇàÇÏ¿© º¯°æµÈ /etc/syslog.conf°¡ syslogd¿¡ Àû¿ëµÇµµ·Ï ÇÕ´Ï´Ù.

¨ï /tmp/ftp.log ÆÄÀÏ ³»¿ëÀ» È®ÀÎÇÕ´Ï´Ù.

*) ÀÏ¹Ý »ç¿ëÀÚÀÎ °æ¿ì ¾Æ·¡¿Í °°ÀÌ ·Î±×°¡ ³²½À´Ï´Ù. (ÀÔ·ÂÇÑ ¾ÏÈ£°¡ ³ªÅ¸³ªÁö ¾Ê½À´Ï´Ù.)
Mar 7 18:28:22 cali ftpd[11163]: FTP LOGIN FROM machine_name, user_name

*) Anonymous FTP »ç¿ëÀÚÀÎ °æ¿ì ¾Æ·¡¿Í °°Àº ·Î±×°¡ ³²½À´Ï´Ù. (¾ÏÈ£·Î¼­ ÀÔ·ÂÇÑ ¹®ÀÚ¿­ÀÌ ³ªÅ¸³³´Ï´Ù.)
Mar 7 18:29:41 cali ftpd[11169]: ANONYMOUS FTP LOGIN FROM machine_name,great

2. /var/adm/wtmp ÀÌ¿ëÇϱâ

#who -a /var/adm/wtmp 

À§ ¸í·ÉÀ» ½ÇÇàÇÏ¸é ´ÙÀ½°ú °°Àº ³»¿ëÀÌ ³ªÅ¸³³´Ï´Ù.

ftp x ftp12287 Mar 08 15:36 ? 12287 machine_name
. x ftp12287 Mar 08 15:37 ? 12287 

syslogd µ¥¸ó¿¡¼­ »ý¼ºµÈ ·Î±×ÆÄÀÏ¿¡¼­ º¸¿©ÁÖ´Â ³»¿ëº¸´Ù ÀûÀº Á¤º¸°¡ ÀÖÁö¸¸, Á¢¼Ó ½Ã°£, PID µîÀ» º¼ ¼ö ÀÖ´Â À¯¿ëÇÑ ÆÄÀÏÀÔ´Ï´Ù.

------------------------------------------------------------

[¥³anonymous ftp »ç¿ë ½Ã »ç¿ëÀÚ¿¡ µû¶ó µð·ºÅ丮 Á¢±ÙÀ» Á¦ÇÑÇϱâ]

AIX¿¡¼­ ftp ½Ã µð·ºÅ丮 Á¢±ÙÀÌ Á¦ÇѵǴ »ç¿ëÀÚ´Â "ftp"³ª ¡°anonymous" »ÓÀÔ´Ï´Ù.
±×·¯³ª ¾î¶² °æ¿ì ƯÁ¤ »ç¿ëÀÚ¿¡°Ô´Â ftp server Áß ÀϺθ¸ »ç¿ëÇϵµ·Ï ÇÒ ÇÊ¿ä°¡ ÀÖ½À´Ï´Ù.
ÀÌ·± °æ¿ì »ç¿ëÇÒ ¼ö ÀÖ´Â ftpd¿¡ Washington University at St.LouisÀÇ wuftpd°¡ ÀÖ½À´Ï´Ù. wuftpd¿¡¼­´Â anonymous »ç¿ëÀÚµéÀ» ºÐ·ùÇÏ¿© Á¦ÇÑÇÕ´Ï´Ù.
wuftpd´Â sharewareÀ̸ç http://www.hvu.nl/~koos/wu-ftpd-faq.html¿¡¼­ ´Ù¿î¹ÞÀ¸½Ç ¼ö ÀÖ½À´Ï´Ù.


¸ñ·Ï | ÀÔ·Â | ¼öÁ¤ | ´äº¯ | »èÁ¦