お客様システムにおけるセキュリティ施策

Similar documents
DNS DNS(Domain Name System) named(bind), tinydns(djbdns), MicrosoftDNS(Windows), etc 3 2 (1) ( ) IP IP DNS 4

DNSを「きちんと」設定しよう

DNS (BIND, djbdns) JPNIC・JPCERT/CC Security Seminar 2005

MUA (Mail User Agent) MTA (Mail Transfer Agent) DNS (Domain Name System) DNS MUA MTA MTA MUA MB mailbox MB

Logitec NAS シリーズ ソフトウェアマニュアル


Logitec NAS シリーズ ソフトウェアマニュアル

Mac OS X Server メールサービスの管理(バージョン 10.3 以降用)

日本語ドメイン名運用ガイド

untitled

¥Í¥Ã¥È¥ï¡¼¥¯¥×¥í¥°¥é¥ß¥ó¥°ÆÃÏÀ

2

1 Linux UNIX-PC LAN. UNIX. LAN. UNIX. 1.1 UNIX LAN. 1.2 Linux PC Linux. 1.3 studenta odd kumabari studentb even kumabari studentc odd kumabari student

TCP/IP Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.3 Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.4 2

5. sendmail.cf

untitled

e164.arpa DNSSEC Version JPRS JPRS e164.arpa DNSSEC DNSSEC DNS DNSSEC (DNSSEC ) DNSSEC DNSSEC DNS ( ) % # (root)

IW2002-B5 1 Internet Week ( ) 9:30 12:30 ( ) Copyright 2002 All Rights Reserved, by Seiji Kumagai ADSL FTTH 24 IP LAN

AirMac ネットワーク構成の手引き


Logitec NAS シリーズ ソフトウェアマニュアル

TCP TCP TCP fin TCP NULL UDP ICMP Unreachable finger phf nph-test-cgi php ftp 18 1

FileMaker Server Getting Started Guide

1. 2. ( ) Secure Secure Shell ssh 5. (xinetd TCP wrappers) 6. (IPsec) 7. Firewall 2

BIND 9 BIND 9 IPv6 BIND 9 view lwres

AirMac ネットワーク for Windows

SRT/RTX/RT設定例集

FileMaker Server Getting Started Guide

2004 SYN/ACK SYN Flood G01P014-6

PDF

untitled

LHD-LAN_E_G_PDF.}.j...A...p65

FileMaker Server Getting Started Guide

2011 I/ 2 1

2 1: OSI OSI,,,,,,,,, 4 TCP/IP TCP/IP, TCP, IP 2,, IP, IP. IP, ICMP, TCP, UDP, TELNET, FTP, HTTP TCP IP

設定例集_Rev.8.03, Rev.9.00, Rev.10.01対応

A/B WWW MTA/MSP sendmail POP/IMAP apache WWW 1 1 sendmail uw imap apache WWW host host subnet1: /24 IF1: router & server mail and

shibasaki(印刷用)

untitled

Macintosh HD:Users:ks91:Documents:lect:nm2002s:nm2002s03.dvi

2008, 2009 TOSHIBA TEC CORPORATION All rights reserved

( )

Mac OS X Server QuickTime Streaming Server 5.0 の管理(バージョン 10.3 以降用)

Microsoft Word - 08平成23年度広報_内藤.docx

Win XP SP3 Japanese Ed. NCP IPSec client Hub L3 SW SRX100 Policy base VPN fe-0/0/0 vlan.0 Win 2003 SVR /

shio_ PDF

2/11 ANNEX HATS HATS

目次

<834E C F D E657073>

Teradici Corporation # Canada Way, Burnaby, BC V5G 4X8 Canada p f Teradici Corporation Teradi

Doctor Web Pacific Dr.Web Mail Security Suite Mail Security Suite Sendmail Postfix qmail MTA(Mail Transfer Agent) SMTP Proxy MTA MTA OS 1 /

untitled

UCE DOS ( )

UsersGuide_INR-HG5497c_.doc

Dec , IS p. 1/60

guide.PDF

Lync Server 2010 Lync Server Topology Builder BIG-IP LTM Topology Builder IP Lync 2010 BIG IP BIG-IP VE Virtual Edition BIG-IP SSL/TLS BIG-IP Edge Web

IP 2.2 (IP ) IP 2.3 DNS IP IP DNS DNS 3 (PC) PC PC PC Linux(ubuntu) PC TA 2

橡C16.PDF

Copyright 2006 Mitsui Bussan Secure Directions, Inc. All Rights Reserved. 3 Copyright 2006 Mitsui Bussan Secure Directions, Inc. All Rights Reserved.

Si-R30取扱説明書

はじめに

WIDE 1

FileMaker Server 16 インストールおよび構成ガイド

main.dvi

ヤマハ ルーター ファイアウォール機能~説明資料~

LHD-LAN ...[.U.[.Y.}.j...A.. V05.p65

Packet Tracer: 拡張 ACL の設定 : シナリオ 1 トポロジ アドレステーブル R1 デバイスインターフェイス IP アドレスサブネットマスクデフォルトゲートウェイ G0/ N/A G0/

FileMaker Server 9 Getting Started Guide

untitled

wp_integrating_AD_10.9_16JAN2014

IP Windows Word Excel Web Web Word Excel XHTML CSS Web Windows Word Excel Web XHTML CSS

worm hoihoi

Testing XML Performance

perimeter gateway

2 BIG-IP 800 LTM v HF2 V LTM L L L IP GUI VLAN.

Si-R30コマンドリファレンス

第1回 ネットワークとは

Mac OS X Server Windows NTからの移行

のコピー

ファーストステップガイド1.2.doc

雲の中のWebアプリケーション監視術!~いまなら間に合うクラウド時代の性能監視入門~

Microsoft Windows, Windows CE, Microsoft Corporation Citrix ICA Citrix Presentation Server Citrix Systems, Inc IBM IBM Corporation

i TCP/IP NIC Intel 3com NIC TCP/IP *1 20 IPv4 IPv6 IPv6 TCP/IP TCP/IP *1 3

Epson Print Admin

第3回_416.ppt

アライドテレシス ディストリビューション・スイッチ AT-x600シリーズで実現するMicrosoft® NAP

"CAS を利用した Single Sign On 環境の構築"

caff と mail-transport-agent - 第156回 2017年10月度 東京エリアDebian勉強会

Configuring_01

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

wp_integrating_active_directory_ml

dvi

ヤマハ ルーター ファイアウォール機能~説明資料~

"CAS を利用した Single Sign On 環境の構築"

内閣官房情報セキュリティセンター(NISC)

RouteMagic Controller RMC-MP200 / MP Version

FUJITSU Network Si-R Si-R Gシリーズ Webユーザーズガイド


_‚Ofl¼

Transcription:

UNIX IT fujitsu.com

1. UNIX 2. 3. 4. 2

1. UNIX

UNIX U1 BIND Domain Name System U2 Web Server U3 Authentication U4 Version Control Systems U5 Mail Transport Service U6 Simple Network Management Protocol U7 Open Secure Sockets Layer (SSL) U8 Misconfiguration of Enterprise Services NIS/NFS U9 Databases U10 Kernel SANS(http://www.sans.org/top20/) 4

JPCERT IPA 1999 2000 2001 2002 2003 2004 843 2375 3403 1435 3457 5811 IPA 200x 2000 2001 2002 2003 2004 106 1253 1 329 212 356 813 5

WebApplication Cross Site Scripting(XSS) OS /SQL ssh Brute Force (?) 6

( ) 7

2.

DNS 9

DNS # dig @dns.example.org example.org axfr ; <<>> DiG 9.2.2 <<>> @dns.example.org axfr... ;; XFR size: 10 records # dig @dns.example.org version.bind chaos txt ;; ANSWER SECTION Vesion.bind. 0 CH TXT 9.2.1 10

BIND named.conf options { version unknown ; fetch-glue no; # BIND 8 }; zone EXTERNAL { allow-transfer { SLAVE1; SLAVE2; } match-client { any; } recursion no; }; zone INTERNAL { allow-transfer { none; } match-client { 192.168.0.1/24; } recursion yes; }; 11

# dig @dns.example.org example.org axfr ; <<>> DiG 9.2.2 <<>> @dns.example.org axfr... ;; Transfer failed. # dig @dns.example.org version.bind chaos txt ;; ANSWER SECTION Vesion.bind. 0 CH TXT unknown 12

Web HTTP TRACE WebApplication 13

HTTP TRACE (Apache) HTTP TRACE XSS Basci (US-CERT VU#867593) httpd.conf RewriteEngine on RewriteCond %{REQUEST_METHOD} ^TRACE RewriteRule.* - [F] https VirtualHost mod_rewrite 14

HTTP TRACE (Apache) TRACE # telnet www.example.org 80 TRACE / HTTP/1.1 Host: www.example.org < > HTTP/1.1 200 OK ( ) 200: HTTP TRACE ( ) 400: 403,404: HTTP TRACE ( ) 15

(Apache) OS httpd.conf ServerToken ProductOnly ServerSignature Off # telnet www.example.org 80 HEAD / HTTP/1.0 < > HTTP/1.1 200 OK Data: Sat, 21 Aug 2004 04:12:03 GMT Server: Apache( ) Apache 16

Directory Index Web /backup /test backup.zip *.bak /manual/ index.html.* 17

Web 443/tcp stunnel(http://www.stunnel.org/) OpenSSL(http://openssl.org/) openssl s_client -connect <IP Address>:<Port> - state nikto(http://www.cirt.net/) N-Stealth(http://www.nstalker.com/nstealth) 18

WebApplication hidden 19

expn / vrfy 20

expn / vrfy ID( ) ID (ssh ) # telnet mail.example.com 25 220 mail.example.com ESMTP Sendmail 8.XX.XX HELO test.example.com 250 test.example.com Hello... EXPN fuji 550 5.1.1 fuji... User unknown EXPN toru 250 2.1.5 toru@mail.example.com 21

expn / vrfy (sendmail / Postfix) sendmail.cf(sendmail) # privacy flags O PrivacyOptions=authwarnings,noexpn,novrfy sendmail.mc(sendmail) define( confprivacy_flags, authwarnings,noexpn,novrfy ) goaway main.cf(postfix) disable_vrfy_command = yes qmail 22

expn / vrfy # telnet mail.example.com 25 220 mail.example.com ESMTP unknow HELO test.exaple.com 250 test.example.com Hello... EXPN fuji 502 5.7.0 Sorry, we do not allow this option VRFY toru 252 2.5.2 Cannot VRFY user; try RCPT to attempt delivery (or try finger) 23

SMTP SMTP E-mail # telnet mail.example.org 25 220 mail.example.org ESMTP unknown MAIL FROM: spam@spam.com 250 2.1.0 spam@spam.com RCPT TO: spam@ahoo.com 250 2.1.5 spam@ahoo.com DATA 24

# telnet mail.example.org 25 220 mail.example.org ESMTP unknown MAIL FROM: spam@spam.com 250 2.1.0 spam@spam.com RCPT TO: spam@ahoo.com 550 5.7.1 Unable to relay for spam@ahoo.com InterScan VirusWall for UNIX sendmail InterScan ORDB(http://www.ordb.org/) 25

(sendmail) sendmail.mc (sendmail) define( confsmtp_login_msg, unknown )dnl define('confreceived_header','$?sfrom $s $.$?_($?s$ from $.$_) $.$?{auth_type}(authenticated) $.by $j (unknown)$?r with $r$. id $i$?u for $u; $ ; $.$b')dnl (Postfix) smtp_banner = $myhostname ESMTP unknown 26

Brute Force SNMP HTTP Proxy 27

Brute Force ID/Password Brute Force (RSA ) sshd_conf RSAAuthentication yes RhostsAuthentication no RhostsRSAAuthentication no PasswordAuthentication no PerimetRootLogin no PerimetEmptyPassword no AllowUsers user1, user2,... 28

SNMP public private SNMP ADMsnmp(http://adm.freelsd.net/ADM/) snmpwalk(http://net-snmp.sourceforge.net/) 29

HTTP (SPAM ) # telnet proxy.example.com 80 CONNECT mail.example.org:25 HTTP/1.0 < > HTTP/1.0 200 Connection established 220 mail.exaple.org ESMTP ( ) 200: HTTP TRACE ( ) 403, 405: CONNECT ( ) 30

HTTP Proxy FireWall ForwardingProxy squid.conf acl office src 192.168.1.0/255.255.255.0 http_access allow office pxytest(http://www.unicom.com/sw/pxytest/) 31

inetd (echo finger ) netstat nmap RPC(NIS NFS ) rpcinfo -p <IP > R X-Window NIS+ LDAP 32

cc(gcc) wget OS setuid setgid iptable TCP wrapper FireWall chroot 33

34

3.

OS OS 36

DAT ( ) Logwatch swatch ( ) analog / MRTG 37

( ) FireWall Accept FireWall-1 Short Log ntp FireWall UDP 38

chkrootkit(http://www.chkrootkit.org/) tripwire(http://www.tripwire.co.jp/) Nessus(http://www.nessus.org/) QualysGurad(http://segroup.fujitsu.com/secure/ service/attacktest-express/index.html) 39

/ 40

4.

( ) 42

http://www.npa.go.jp/cyber/soudan.htm ( ) 43

JPCERT/CC http://www.jpcert.or.jp/form/ info@jpcert.or.jp FAX 03-3518-2177 (IPA) ISEC http://www.ipa.go.jp/security/todoke/ crack@jpa.go.jp TEL 03-5978-7509 FAX 03-5978-7518 44

HDD ( HDD ) 45

LAN ( ) 46

47

48