|
AIX¿¡¼ FTP¼¹ö ±¸ÇöÇÏ´Â ¹æ¹ý
anonymous ftp¸¦ ÅëÇÏ¿© ¸ðµç »ç¿ëÀÚµéÀÌ ÆÄÀÏÀ» °øÀ¯ÇÏ¿© »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
¾Æ·¡ÀÇ ¸ñÂ÷¼øÀ¸·Î °ÀÇ°¡ ÁøÇàµË´Ï´Ù.
------------------------------------------------------------
¥° ±âº»±¸Çö
¥± fileÀÇ owner³ª groupÀÇ À̸§À» º¸ÀÌ°Ô Çϱâ
¥² ftp½ÇÇà ·Î±× ³²±â±â
¥³ anonymous ftp »ç¿ë½Ã »ç¿ëÀÚ¿¡ µû¶ó µð·ºÅ丮 Á¢±ÙÀ» Á¦ÇÑÇϱâ
------------------------------------------------------------
[¥° ±âº»±¸Çö ]
1. ftp¶ó´Â groupÀ» »ý¼ºÇÕ´Ï´Ù.
#smitty mkgroup
Group Name : ftp
»ý¼º ÈÄ /etc/groupÀ» È®ÀÎÇÏ¿© group-id°¡ À¯ÀÏÇÏ°Ô ÁöÁ¤µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.
2. ftp¶ó´Â user¸¦ »ý¼ºÇÕ´Ï´Ù.
#smitty mkuser
User Name : ftp
Primary Group : ftp
Another user can SU to USER : false
HOME directory : /u/ftp (¿øÇÏ´Â °ÍÀ¸·Î)
User can LOGIN : false
User can LOGIN remotely : false
»ý¼º ÈÄ ´ÙÀ½À» È®ÀÎÇÕ´Ï´Ù.
/etc/passwd :
passwordºÎºÐÀÌ '*' Àΰ¡, user-id°¡ À¯ÀÏÇÑ°¡, group-id°¡ ftp group-id Àΰ¡,
Ȩµð·ºÅ丮 À§Ä¡
/etc/security/user :
login = false
su = false
rlogin = false
admin = false
3. ´ÙÀ½À» ½ÇÇàÇÕ´Ï´Ù.
#chmod 755 /u/ftp
#cd /u/ftp
#mkdir bin lib pub
#cp /usr/bin/ls bin/ls
#cp /lib/libc.a lib/libc.a
#chmod 555 bin
#chmod 555 lib
#chmod 777 pub
¿©±â¼ pub´Â »ç¿ëÀÚµéÀÌ ÆÄÀÏÀ» ¿Ã¸®°Å³ª °¡Á®°¡´Â µð·ºÅ丮ÀÔ´Ï´Ù.
ÀÌÁ¦ »ç¿ëÀÚµéÀº ftp°èÁ¤À¸·Î ¾ÏÈ£ ¾øÀÌ ftpÁ¢±ÙÀ» ÇÒ ¼ö ÀÖ½À´Ï´Ù. ftp·Î µé¾î¿À¸é /u/ftp¸¦ ¡®/¡¯ ·Î ÀνÄÇϹǷΠ´Ù¸¥ µð·ºÅ丮´Â Á¢±ÙÇÏÁö ¸øÇÏ°í /u/ftp¿¡ ¼ÓÇÑ µð·ºÅ丮¿¡¸¸ Á¢±ÙÇÒ ¼ö ÀÖ½À´Ï´Ù.
¾Æ¹«µµ ftp°èÁ¤À¸·Î rloginÀ̳ª telnet, su, rshÀ» ÇÒ ¼ö ¾ø½À´Ï´Ù. ¿ÀÁ÷ ftp¸¸ °¡´ÉÇÕ´Ï´Ù.
ftp¸¦ ÇÒ ¶§ user name¿¡ ftp ´ë½Å¿¡ anonymousµµ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ»óÀÇ ÀýÂ÷´Â /usr/lpp/tcpip/samples/anon.ftp¿¡ ½ºÅ©¸³Æ®ÈµÇ¾î ÀÖÀ¸´Ï Âü°íÇϽñ⠹ٶø´Ï´Ù.
------------------------------------------------------------
[¥± fileÀÇ owner³ª groupÀÇ À̸§À» º¸ÀÌ°Ô Çϱâ]
1. /u/ftp/etc ¾Æ·¡¿¡ ´ÙÀ½°ú °°Àº ÇüÅ·Π¡°passwd¡± ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù.
ftp:*:302:1:anonymous ftp user:/u/ftp:/bin/false
root:*:0:0::/:/bin/false
¿©±â¿¡¼ 302´Â ftpÀÇ useridÀÔ´Ï´Ù.
2. /u/ftp/etc ¾Æ·¡¿¡ ´ÙÀ½°ú °°Àº ÇüÅ·Π¡°group¡± ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù.
system:*:0:
staff:*:1:
3. ´ÙÀ½À» ½ÇÇàÇÕ´Ï´Ù.
#cd /u/ftp/etc
#chmod 400 *
------------------------------------------------------------
[¥² ftsp½ÇÇà ·Î±×]
1. syslogd µ¥¸óÀ» ÀÌ¿ëÇϱâ
¨ç #smitty inetdconf
¨è "Change / Show Characteristics of an inetd Subserver"À» ¼±ÅÃÇÕ´Ï´Ù.
¨é ftp¸¦ ¼±ÅÃÇÕ´Ï´Ù.
¨ê ¡°Change the Service Program Command Line ARGUMENTS¡± Ç׸ñ¿¡ ftpd -l¸¦ ³Ö½À´Ï´Ù.
¨ë ¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
¨ì /etc/syslog.conf ÆÄÀÏ¿¡
daemon.info /tmp/ftp.log
¸¦ ÷°¡ÇÕ´Ï´Ù.
¨í #touch /tmp/ftp.log
¨î #refresh -s syslogd
¸¦ ½ÇÇàÇÏ¿© º¯°æµÈ /etc/syslog.conf°¡ syslogd¿¡ Àû¿ëµÇµµ·Ï ÇÕ´Ï´Ù.
¨ï /tmp/ftp.log ÆÄÀÏ ³»¿ëÀ» È®ÀÎÇÕ´Ï´Ù.
*) ÀÏ¹Ý »ç¿ëÀÚÀÎ °æ¿ì ¾Æ·¡¿Í °°ÀÌ ·Î±×°¡ ³²½À´Ï´Ù. (ÀÔ·ÂÇÑ ¾ÏÈ£°¡ ³ªÅ¸³ªÁö ¾Ê½À´Ï´Ù.)
Mar 7 18:28:22 cali ftpd[11163]: FTP LOGIN FROM machine_name, user_name
*) Anonymous FTP »ç¿ëÀÚÀÎ °æ¿ì ¾Æ·¡¿Í °°Àº ·Î±×°¡ ³²½À´Ï´Ù. (¾ÏÈ£·Î¼ ÀÔ·ÂÇÑ ¹®ÀÚ¿ÀÌ ³ªÅ¸³³´Ï´Ù.)
Mar 7 18:29:41 cali ftpd[11169]: ANONYMOUS FTP LOGIN FROM machine_name,great
2. /var/adm/wtmp ÀÌ¿ëÇϱâ
#who -a /var/adm/wtmp
À§ ¸í·ÉÀ» ½ÇÇàÇÏ¸é ´ÙÀ½°ú °°Àº ³»¿ëÀÌ ³ªÅ¸³³´Ï´Ù.
ftp x ftp12287 Mar 08 15:36 ? 12287 machine_name
. x ftp12287 Mar 08 15:37 ? 12287
syslogd µ¥¸ó¿¡¼ »ý¼ºµÈ ·Î±×ÆÄÀÏ¿¡¼ º¸¿©ÁÖ´Â ³»¿ëº¸´Ù ÀûÀº Á¤º¸°¡ ÀÖÁö¸¸, Á¢¼Ó ½Ã°£, PID µîÀ» º¼ ¼ö ÀÖ´Â À¯¿ëÇÑ ÆÄÀÏÀÔ´Ï´Ù.
------------------------------------------------------------
[¥³anonymous ftp »ç¿ë ½Ã »ç¿ëÀÚ¿¡ µû¶ó µð·ºÅ丮 Á¢±ÙÀ» Á¦ÇÑÇϱâ]
AIX¿¡¼ ftp ½Ã µð·ºÅ丮 Á¢±ÙÀÌ Á¦ÇѵǴ »ç¿ëÀÚ´Â "ftp"³ª ¡°anonymous" »ÓÀÔ´Ï´Ù.
±×·¯³ª ¾î¶² °æ¿ì ƯÁ¤ »ç¿ëÀÚ¿¡°Ô´Â ftp server Áß ÀϺθ¸ »ç¿ëÇϵµ·Ï ÇÒ ÇÊ¿ä°¡ ÀÖ½À´Ï´Ù.
ÀÌ·± °æ¿ì »ç¿ëÇÒ ¼ö ÀÖ´Â ftpd¿¡ Washington University at St.LouisÀÇ wuftpd°¡ ÀÖ½À´Ï´Ù. wuftpd¿¡¼´Â anonymous »ç¿ëÀÚµéÀ» ºÐ·ùÇÏ¿© Á¦ÇÑÇÕ´Ï´Ù.
wuftpd´Â sharewareÀ̸ç http://www.hvu.nl/~koos/wu-ftpd-faq.html¿¡¼ ´Ù¿î¹ÞÀ¸½Ç ¼ö ÀÖ½À´Ï´Ù.
|