ȸ¿ø°¡ÀԡžÆÀ̵ð/ºñ¹øã±â
ȨÀ¸·Î


- var - log - secure ·Î±×¸¦ ÀÌ¿ëÇÑ IP Deny ÀÚµ¿ µî·Ï ½ºÅ©¸³Æ®
17³â Àü
ÀÌ ½ºÅ©¸³Æ®´Â ¸®´ª½º¿¡¼­ ±âº»ÀûÀ¸·Î Á¦°øÇÏ´Â ·Î±×¸¦ ÀÌ¿ëÇÏ¿© 10ºÐ °£°ÝÀ¸·Î ·Î±×¸¦ ÃßÃâÇÏ°í 20ȸ ÀÌ»ó Fail Password¸¦ ¹ß»ý½ÃŲ ¾ÆÀÌÇǸ¦ Tcp-Wrapper(/etc/hosts.deny)¿¡ µî·Ï½ÃÄÑ ´õÀÌ»ó ÇØÅ· ½Ãµµ¸¦ ¹æÁöÇÑ´Ù.


Caution : 10ºÐÀ̳»¿¡ ¶Õ¸®¸é ¾îÂîÇÒ ¼ö ¾øÀ½... =,.=;


ps. ½ºÅ©¸³Æ®ÀÇ Á¦ÀÛÀÇ Æí¸®¸¦ À§Çؼ­ Áߺ¹ µî·ÏÈ®ÀÎÀº ¾øÀ½... ^^;



±âº»È¯°æ : ¸®´ª½º, PHP Shell Script

ÀÛ¼º¾ð¾î : PHP



µ¿ÀÛ¿ø¸®

1. /var/log/secure ÆÄÀÏ¿¡¼­ 10ºÐ´ëÀÇ ·Î±×¸¦ ÃßÃâÇÑ´Ù.

  ¿¹ : ÇöÀç½Ã°£ÀÌ 18:25:00 À̶ó¸é ÃßÃâÇÏ´Â ½Ã°£Àº 18:10~19ºÐÀ» ÃßÃâÇÑ´Ù.

2. ¾ÆÀÌÇÇ º°·Î °¹¼ö¸¦ Åë°è³½´Ù.

3. ÇÑ ¾ÆÀÌÇÇ¿¡¼­ 20ȸ ÀÌ»ó sshd·Î ºñ¹Ð¹øÈ£°¡ Ʋ·È´Ù¸é /etc/hosts.deny¿¡ "ALL:¾ÆÀÌÇÇÁÖ¼Ò"ÀÇ  ÇüÅ·Πµî·ÏµÈ´Ù.

4. xinetd µ¥¸óÀ» Àç½ÃÀÛÇÑ´Ù.

5. µî·ÏÇÑ ¾ÆÀÌÇÇ ¸ñ·ÏÀ» ÁöÁ¤µÈ ¸ÞÀÏ ÁÖ¼Ò·Î ¹ß¼ÛÇÑ´Ù.



½ÇÇà¹æ¹ý

./secure_analysis.sh sshd



crontab µî·Ï½Ã

*/10 * * * * /°æ·Î¸í/secure_analysis.sh sshd



¼Ò½º

#!/usr/local/bin/php
<?
// °³¿ä
// secure log ¸¦ ºÐ¼®Çؼ­ sshd·Î ºÒ¹ýÀûÀÎ Á¢¼ÓÀ» ½ÃµµÇÏ´Â IP¸¦ /etc/hosts.deny¿¡ µî·ÏÇÏ´Â ÀÛ¾÷À» ÇÑ´Ù.

// Log Example : Jun  5 07:49:18 p1 sshd[1110]: Failed password for root from 211.114.190.196 port 52944 ssh2
// ÃßÃâ ¸í·É¾î : grep "Jun  7 09" secure | grep "sshd" | grep "Failed password" | awk -F "from" '{print $2}' | awk '{print $1}'

// ÁöÁ¤µÈ ÀԷ°ªÀ» ÀÔ·ÂÇÏÁö ¾ÊÀ¸¸é ½ÇÇàÇÏÁö ¾Ê´Â´Ù.

if($argc > 1)
{
$RECEIVE_EMAIL = "¼ö½Å ¸ÞÀÏÁÖ¼Ò";
$Hostname = trim(exec("hostname"));

$Date = date("Y-m-d H:i:s");

// 10ºÐÀü ºÐÀ» ±¸ÇÑ´Ù.
$TenAgo = substr(date("i",mktime (date("H"), date("i")-10, 0, date("m"), date("d"), date("Y"))),0,1);

if(!file_exists("/service/log_temp"))
{
   exec("mkdir -p /service/log_temp");
}

    if(!file_exists("/service/log_temp/secure_analysis.log"))
    {
        exec("touch /service/log_temp/secure_analysis.log");
    }

// ³¯Â¥¿¡ µû¶ó¼­ °Ë»ö¾îÀÇ °ø¹é󸮰¡ Ʋ¸° °ü°è·Î ... =,.=;
$DayLength = strlen(date("j"));

if($DayLength == 2)
{
  $now = date("M j H:");
}
else
{
  $now = date("M  j H:");
}

if($argv[1] == "sshd")
{
  exec("grep \"$now$TenAgo\" /var/log/secure | grep \"sshd\" | grep \"Failed password\" | awk -F \"from\" '{print \$2}' | awk '{print \$1}' > /service/log_temp/secure_log_".$argv[1]);
}

$Fail_IP_File = file("/service/log_temp/secure_log_".$argv[1]);

for($i=0; $i < count($Fail_IP_File); $i++)
{
  $Fail_IP_File[$i] = trim($Fail_IP_File[$i]);
}

$Fail_Statistics = array_count_values($Fail_IP_File);

exec("echo \"\" > /service/log_temp/DenyIP.list_".$argv[1]);

while (list ($Ip, $Count) = each ($Fail_Statistics))
{

// ¿©±âÀÇ 20À» Á¶Á¤ÇÏ¿© µî·ÏÀ» Á¶ÀýÇÒ ¼ö ÀÖ´Ù.
  if($Count > 20)
  {
   $Now_Time = date("Y³â m¿ù dÀÏ H½Ã iºÐ sÃÊ");
   exec("echo \"#Regist $Now_Time\" >> /etc/hosts.deny");
   exec("echo \"ALL : $Ip\" >> /etc/hosts.deny");
   $Restart_Xinetd = 1;
   exec("echo \"$Now_Time | $Ip | $Count ȸ\" >> /service/log_temp/DenyIP.list_".$argv[1]);
  }
  exec("echo \"$Date\t$Ip\t$Count\" >> /service/log_temp/secure_analysis.log");
}

if($Restart_Xinetd)
{
  exec("killall -HUP xinetd");
  exec("cat \"/service/log_temp/DenyIP.list_".$argv[1]."\" | mail -s \"$Hostname Deny IP List - $Date \" $RECEIVE_EMAIL");
}
}
else
{
echo("Missing Argument... Confirm Execute ...\n");
}
?>
ÃßõÃßõ : 341 Ãßõ ¸ñ·Ï
¹øÈ£ Á¦¸ñ
2,891
ÀÔ·Â Çʵ忡¼­ ƯÁ¤´Ü¾î(¿¹:#err)°¡ Æ÷ÇԵǾúÀ» ¶§ ½Ç½Ã°£ °¨Áö ¹× °æ°íâ ¶ç¿ì±â
2,890
µ¥ÀÌÅͺ£À̽º ÃÖÀûÈ­¿Í Äõ¸® È¿À²¼ºÀ» ³ôÀÌ °Ë»ö ¼º´ÉÀ» °³¼±ÇÏ´Â ¹æ¹ý
2,889
°£´ÜÇÑ °Ô½ÃÆÇ ¸¸µé±â
2,888
PHPÀÇ php.ini ÆÄÀÏ¿¡¼­ ¼³Á¤ÇÒ ¼ö ÀÖ´Â ÁÖ¿ä Ç׸ñµéÀ» Ä«Å×°í¸®º°·Î Á¤¸®
2,887
À¯Æ©ºê µ¿¿µ»óÀÇ ½æ³×ÀÏ À̹ÌÁö¸¦ üũÇÏ¿© À¯È¿ÇÑ ¿µ»óÀ̾ƴҶ§ ¿¬°áµÈ üũ¹Ú½º¸¦ ÀÚµ¿À¸·Î üũ
2,886
À̹ÌÁö URLÀÌ À¯È¿ÇÏÁö ¾ÊÀ» ¶§, ÇØ´ç À̹ÌÁö¿Í ¿¬°áµÈ üũ¹Ú½º¸¦ ÀÚµ¿À¸·Î üũ
2,885
HTTPS·Î Á¢¼ÓÇÑ »ç¿ëÀÚ¸¦ °­Á¦·Î HTTP·Î ¸®µð·º¼Ç ÇÏ·Á¸é
2,884
PHP¿¡¼­ MP3 ÆÄÀÏÀ» Á÷Á¢ ÀÐ°í ½ºÆ®¸®¹Ö Çϱâ
2,883
ÇöÀç ÆäÀÌÁö°¡ location.reload()¿¡ ÀÇÇØ »õ·Î°íħµÇ¾ú´ÂÁö
2,882
ÅؽºÆ® ÆÄÀÏÀ» Àаí, °¢ ÁÙÀÇ ³¡¿¡¼­ 6±ÛÀÚ¸¦ »èÁ¦ÇÑ ÈÄ, °á°ú¸¦ »õ·Î¿î ÆÄÀÏ¿¡ ÀúÀåÇÕ´Ï´Ù.
2,881
cURLÀ» »ç¿ëÇÏ¿© ¸®´ÙÀÌ·ºÆ®¸¦ µû¶ó°¡ ÃÖÁ¾ URL °¡Á®¿À±â
2,880
[PHP] $_SERVER ȯ°æº¯¼ö
2,879
10Áø¼ö <-> 16Áø¼ö º¯È¯±â PHP¼Ò½º
2,878
ÅؽºÆ®¿¡ Á÷Á¢ ±×¶óµ¥ÀÌ¼Ç »ö»óÀ» Àû¿ëÇÏ·Á¸é?
2,877
CSS¸¦ »ç¿ëÇÏ¿© ¿ä¼ÒÀÇ ³»¿ë¹°¿¡ µû¶ó width¸¦ Á¶Á¤ÇÏ´Â ¹æ¹ý
2,876
À¥¼­¹ö ip È®ÀÎ
2,875
À¥È£½ºÆÃÀÇ Àý´ë°æ·Î¸¦ È®ÀÎ
2,874
input ÀÔ·Â ÇÊµå ¾ÕµÚ °ø¹é ½Ç½Ã°£ Á¦°Å
2,873
Placeholder Æ÷Ä¿½º½Ã °¨Ãß±â
2,872
MySQL Áߺ¹µÈ µ¥ÀÌÅ͸¦ »èÁ¦
2,871
MySQL Áߺ¹ µ¥ÀÌÅÍ È®ÀÎ
2,870
sessionStorage.getItem ¿Í sessionStorage.setItem
2,869
Á¦ÀÌÄõ¸® ·£´ýÀ¸·Î ¹è°æ»ö º¯°æ
2,868
preg match¿¡ °üÇÑ Á¤±Ô½Ä
2,867
Stream an audio file with MediaPlayer ¿Àµð¿À ÆÄÀÏ ½ºÆ®¸®¹Ö Çϱâ
2,866
Audio Streaming PHP Code
2,865
PHP $ SERVER ȯ°æ º¯¼ö Á¤¸®
2,864
Vimeo (ºñ¸Þ¿À) API ¸¦ »ç¿ëÇÏ¿© Ç÷¹À̾î ÄÁÆ®·ÑÇϱâ
2,863
iframe »ç¿ë½Ã ÇÏ´Ü¿¡ ¹ß»ýÇÏ´Â °ø¹é Á¦°Å¹æ¹ý
2,862
¾ÆÀÌÇÁ·¹ÀÓ(iframe) Àüüȭ¸é °¡´ÉÇÏ°Ô Çϱâ
¸ñ·Ï
¹ÂÁ÷Æ®·ÎÆ® ºÎ»ê±¤¿ª½Ã ºÎ»êÁø±¸ °¡¾ßµ¿ ¤Ó °³ÀÎÁ¤º¸Ãë±Þ¹æħ
Copyright ¨Ï musictrot All rights reserved.