โ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃ
ftp๋Š” ์ข€ ๊นŒ๋‹ค๋กญ๋‹ค. VMware NAT ๋ฐฉ์‹์ด ์•„๋‹Œ ๋ธŒ๋ฆฌ์ง€ ๋ฐฉ์‹์„ ์ด์šฉํ•ด์„œ ํ•˜๋Š” ๋ฐฉ๋ฒ•์ด ์žˆ๋‹ค.
๋Œ€์ฒด๋กœ ์ง‘์ง‘๋งˆ๋‹ค ๊ณต์œ ๊ธฐ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ๊ธฐ ๋•Œ๋ฌธ์— ๊ณต์œ ๊ธฐ์—์„œ ์ง์ ‘ ๋ฐ›์•„์„œ ํฌ์›Œ๋”ฉ์‹œํ‚ค๋Š” ๋ฐฉ๋ฒ•์„
์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ๋‹ค. ๋ชฐ๋ก  ์ด๋ ‡๊ฒŒ ํ•œ๋‹ค๊ณ  ํ•˜์ง€๋งŒ ์ด ๋ฐฉ์‹๋„ ์„ค์ •ํ•˜๊ธฐ๊ฐ€ ์‰ฝ์ง€๊ฐ€ ์•Š๋‹ค.
์ด ๋ธŒ๋ฆฌ์ง€ ์ ‘์† ๋ฐฉ์‹์˜ ์žฅ์ ์€ ํŒจ์‹œ๋ธŒ ๋ชจ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  ์ง์ ‘ ์ ‘์†ํ•ด์„œ ์‚ฌ์šฉํ•˜๊ธฐ ๋•Œ๋ฌธ์— ํŽธํ•˜๋‹ค๋Š” ๊ฒƒ์ด๋‹ค.
โ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃ
[root@nsโ™ฅBunnyComโ™ฅ~]# rpm -qa | grep vsftp
[root@nsโ™ฅBunnyComโ™ฅ~]# yum install vsftp
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/vsftpd/vsftpd.conf
### anonymous_enable=YES (default = YES). anonymous ์‚ฌ์šฉ์ž์˜ ์ ‘์† ํ—ˆ์šฉ ์—ฌ๋ถ€
anonymous_enable=YES
### local_enable=YES (default = NO). ๋กœ์ปฌ ๊ณ„์ • ์‚ฌ์šฉ์ž์˜ ์ ‘์† ํ—ˆ์šฉ ์—ฌ๋ถ€
local_enable=YES
### write_enable=YES (defualt = NO). write ๋ช…๋ น์–ด ํ—ˆ์šฉ ์—ฌ๋ถ€
write_enable=YES
### local_umask=022 (default = 077). ๋กœ์ปฌ ๊ณ„์ • ์‚ฌ์šฉ์ž์šฉ umask
local_umask=022
### anon_upload_enable=YES (default = NO). anonymous ์‚ฌ์šฉ์ž๊ฐ€ ํŒŒ์ผ์„ ์—…๋กœ๋“œ ํ• ์ˆ˜ ์žˆ๋Š”์ง€ ์—ฌ๋ถ€ ํ—ˆ์šฉ์‹œ ์—…๋กœ๋“œ ํ• ์ˆ˜์žˆ๋Š” ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ์ƒ์„ฑํ•ด ์ฃผ์–ด์•ผ ํ•œ๋‹ค.
anon_upload_enable=YES
### anon_mkdir_write_enable=YES (default = NO). anonymous ์‚ฌ์šฉ์ž์˜ ๋””๋ ‰ํ† ๋ฆฌ ์ƒ์„ฑ ํ—ˆ์šฉ ์—ฌ๋ถ€
anon_mkdir_write_enable=YES
## ์ƒˆ๋กœ์šด ๋””๋ ‰ํ† ๋ฆฌ์— ๋“ค์–ด๊ฐ”์„ ๋•Œ ๋ฟŒ๋ ค์ค„ ํ™˜๊ฒฝ ๋ฉ”์‹œ์ง€๋ฅผ ์ €์žฅํ•œ ํŒŒ์ผ๋ช…
dirmessage_enable=YES
# Activate logging of uploads/downloads.
xferlog_enable=YES
### connect_from_port_20=YES Standalone ์ผ๋•Œ ํฌํŠธ ๋ณ€๊ฒฝ์„ ์›ํ•  ๊ฒฝ์šฐ ์„ค์ •.
connect_from_port_20=YES
### listen_port=2121 ๊ธฐ๋ณธ ํฌํŠธ์™ธ ๋‹ค๋ฅธ ํฌํŠธ๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค. vsftpd ์„œ๋ฒ„๋ฅผ ์žฌ์‹คํ–‰ํ•œ๋‹ค.
listen_port=1999
### chown_upload=YES ์ต๋ช…์œ ์ €๊ฐ€ ์—…๋กœ๋“œํ•œ ํŒŒ์ผ์˜ ์†Œ์œ ๊ถŒ์„ ์ž๋™๋ณ€๊ฒฝ.
#chown_uploads=YES
### chwon_username=acsecret ์†Œ์œ ๊ถŒ์„ ๋ณ€๊ฒฝํ•˜๊ธฐ ์›ํ•˜๋Š” ์œ ์ €๋ช…์œผ๋กœ ๊ธฐ์ž…
#chown_username=whoever
### xferlog ํ‘œ์ค€ ํฌ๋งท์€ ๋กœ๊ทธ์ธ, ๋””๋ ‰ํ† ๋ฆฌ ์ƒ์„ฑ๋“ฑ์˜ ๋กœ๊ทธ๋ฅผ ๋‚จ๊ธฐ์ง€ ์•Š์ง€๋งŒ
### vsftpd ์Šคํƒ€์ผ ๋กœ๊ทธ๋Š” ์ด๋ฅผ ํฌํ•จํ•œ ๋ณด๋‹ค ์ƒ์„ธํ•œ ๋กœ๊ทธ๋ฅผ ๋‚จ๊ธด๋‹ค
### xferlog_file=/var/log/vsftpd.log ํŒŒ์ผ ์ „์†ก ๋กœ๊ทธ ํŒŒ์ผ๋ช…
xferlog_file=/var/log/vsftpd.log
### xferlog_enable=YES (default=YES). ํŒŒ์ผ ์ „์†ก ๋กœ๊ทธ๋ฅผ ๋‚จ๊ธธ ๊ฒƒ์ธ์ง€ ์—ฌ๋ถ€
xferlog_enable=YES
### xferlog_std_format=YES (defalut=YES). xferlog ํ‘œ์ค€ ํฌ๋งท์œผ๋กœ ๋กœ๊ทธ๋ฅผ ๋‚จ๊ธธ์ง€ ์—ฌ๋ถ€
xferlog_std_format=YES
### idle_session_timeout=600 (default=300์ดˆ). ํด๋ผ์ด์–ธํŠธ์—์„œ ์•„๋ฌด๋Ÿฐ ๋ช…๋ น์ด ์—†์„๊ฒฝ์šฐ ์„ธ์…˜์„ ๋๋‚ผ ๋•Œ๊นŒ์ง€์˜ ๋Œ€๊ธฐ์‹œ๊ฐ„.
idle_session_timeout=900
### data_connection_timeout=120 (default=60์ดˆ). data connection ์„ ๋Š์„ ๋Œ€๊ธฐ ์‹œ๊ฐ„.
data_connection_timeout=200
### no_priv_user=ftp ์ต๋ช…(anonymous) ๋กœ๊ทธ์ธ์‹œ, ์•จ๋ฆฌ์–ด์‹ฑ๋  ์œ ์ €๋ช… ๊ธฐ์ž….
#nopriv_user=ftpsecure
### session_support=YES wtmp ์— ๋กœ๊ทธ ๋‚จ๊ธฐ๊ธฐ (YES ๋กœ ํ•ด์•ผ๋งŒ last ๋ช…๋ น์–ด๋กœ ์ ‘์† ์—ฌ๋ถ€ ํ™•์ธ ๊ฐ€๋Šฅ)
#session_support=YES
#async_abor_enable=YES
### ascii_upload_enable=YES ASCII ํŒŒ์ผ ์—…๋กœ๋“œ ๊ฐ€๋Šฅ.
#ascii_upload_enable=YES
### ascii_download_enable=YES ASCII ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ๊ฐ€๋Šฅ
#ascii_download_enable=YES
### FTP ์„œ๋ฒ„ ์ ‘์†ํ•  ๋•Œ ๋กœ๊ธด ๋ฉ”์‹œ์ง€ (default=๋ฒ„์ „๋ฒˆํ˜ธ). ํ•œ๊ธ€ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
ftpd_banner=^^ Mnetwork.co.kr FTP Server service ^^.
### deny_email_enable=YES ์ต๋ช… ์ ‘์†์‹œ ํŒจ์Šค์›Œ๋“œ์— ์ผ๋ฐ˜ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋ฅผ ๊ฑฐ๋ถ€ ์—ฌ๋ถ€
#deny_email_enable=YES
### (vsftpd.banned_emails์— ์ง€์ •๋œ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋งŒ ํ—ˆ์šฉ)
#banned_email_file=/etc/vsftpd.banned_emails
### chroot_local_user=YES (default=NO). ์ ‘์†์‹œ ๋กœ์ปฌ ์‚ฌ์šฉ์ž์˜ ํ™ˆ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ /๋กœ ๋ณ€๊ฒฝ ์‚ฌ์šฉ์ž์˜ ํ™ˆ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ๋ฒ—์–ด๋‚˜์ง€ ๋ชปํ•˜๋„๋ก
### ์ œํ•œํ•˜๊ธฐ ์œ„ํ•œ ์„ค์ •. ์ œํ•œ์ด ํ•„์š”ํ•  ๊ฒฝ์šฐ YES ๋กœ ๋ฐ”๊พผ ํ›„ ์ œํ•œํ•  ์‚ฌ์šฉ์ž ID ๋ฅผ chroot_list_file= ์— ์„ค์ •ํ•œ ํŒŒ์ผ์— ์ง€์ •ํ•œ๋‹ค
chroot_local_user=YES
#chroot_list_enable=YES
# (default follows)
#### ์ฃผ์˜ํ•  ๊ฒƒ์€ chroot_local_user=YES ์™€ chroot_list_enable=YES ๋ฅผ ํ•จ๊ป˜ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ  /etc/vsftpd.chroot_list์— ํฌํ•จ๋œ ์‚ฌ์šฉ์ž ID ๋งŒ
#### ์ œํ•œ์—†์ด ํ™ˆ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ๋ฒ—์–ด๋‚  ์ˆ˜ ์žˆ๋‹ค. (๋ฐ˜๋Œ€๋กœ ์ž‘์šฉ)
#chroot_list_file=/etc/vsftpd.chroot_list
### ls_recurse_enable=YES ๋””๋ ‰ํ† ๋ฆฌ ๋‚ด์šฉ ์ถœ๋ ฅ์‹œ ์บ์‰ฌ ์‚ฌ์šฉ์—ฌ๋ถ€.
ls_recurse_enable=YES
### pam_service_name=vsftpd ==> PAM ํŒŒ์ผ๋ช…์„ ์ง€์ • (์„ค์น˜ํ•  ๋•Œ /etc/pam.d/vsftpd ๋ช…์œผ๋กœ ๋ณต์‚ฌํ•จ)
pam_service_name=vsftpd
### userlist_enable=YES /etc/vsftpd.user_list ์— ์žˆ๋Š” ์‚ฌ์šฉ์ž์— ๋Œ€ํ•ด ์ ‘๊ทผ์„ ํ—ˆ๊ฐ€ ์„ค์ •.
userlist_enable=YES
## listen=YES Standalone ์œผ๋กœ ์šด์˜ํ•  ๋•Œ listen=YES
listen=YES
tcp_wrappers=YES
# ํŒจ์‹œ๋ธŒ ํ˜•ํƒœ
## [NO : ์‚ฌ์šฉํ•˜์ง€ ์•Š์Œ] [YES : ์‚ฌ์šฉ]
pasv_enable=YES
pasv_promiscuous=YES
### ๊ฐ€์ƒ ํฌํŠธ ๋ฒˆํ˜ธ ์ง€์ •
pasv_min_port=40001
pasv_max_port=40002
##### ========= ๊ฐ€์ƒ์œ ์ € ==========
guest_enable=YES
### guest_username=virftp ==> ๊ฐ€์ƒ ์œ ์ €์˜ ์‹ค์ œ ํ• ๋‹น ๊ณ„์ •
guest_username=virftp
#### user_sub_token=$USER ==> ์„œ๋กœ ๋‹ค๋ฅธ ํ™ˆ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ๋ถ€์—ฌํ•˜๊ธฐ ์œ„ํ•ด ์…‹ํŒ…
user_sub_token=$USER
local_root=/home/ftp2
### virftp_use_local_privs=YES ์„ค์ •ํ•˜์ง€ ์•Š์œผ๋ฉด ๊ธฐ๋ณธ ์ ์œผ๋กœ anonymous ์˜ ๊ถŒํ•œ์„ ๊ฐ€์ง€๊ณ   ํ™”์ผ์„ ์ƒ์„ฑํ•˜์ง€ ๋ชปํ•œ๋‹ค.
virftp_use_local_privs=YES
### ์ ‘์†์ž - xinetd ๋ฅผ ํ†ตํ•˜์ง€ ์•Š๊ณ  standalone์œผ๋กœ ๋™์ž‘ํ•  ๋•Œ๋งŒ ์‚ฌ์šฉ ๊ฐ€๋Šฅ)
### max_clients=100 ์ตœ๋Œ€ ์ ‘์†์ž ์ˆ˜
max_clients=15
### max_per_ip=3 IP ๋‹น ์ ‘์† ์ˆ˜
max_per_ip=2
### ์ „์†ก์†๋„ ์ œํ•œ (0์€ ์ œํ•œ์—†์Œ, ๋‹จ์œ„๋Š” ์ดˆ๋‹น bytes)
### anon_max_rate=10000, trans_chunk_size=0 ๋กœ ์„ค์ •ํ•˜์—ฌ chunk size ๋ฅผ vsftpd ๊ฐ€ ํŒ๋‹จํ•˜๋„๋ก ํ•œ๋‹ค.
### local_max_rate=200000 ๊ณ„์ • ์‚ฌ์šฉ์ž์˜ ์ „์†ก๋Ÿ‰ ์ œํ•œ
local_max_rate=200000
### anon_max_rate=100000 anonymous ์‚ฌ์šฉ์ž์˜ ์ „์†ก์†๋„ ์ œํ•œ
anon_max_rate=100000
### trans_chunk_size=0 ์ง€์ •ํ•œ byte ๋‹จ์œ„๋กœ ๋‚˜๋ˆ ์„œ ์ „์†ก ์ €์žฅํ•œ๋‹ค. 0์€ vsftpd ๊ฐ€ ์•Œ์•„์„œ ํŒ๋‹จํ•œ๋‹ค.  v1.1.3 ์ด์ƒ์—์„œ trans_chunk_size ์˜ต์…˜์ด ์žˆ๋‹ค.
trans_chunk_size=0
[root@nsโ™ฅBunnyComโ™ฅ~]# service vsftpd restart
[root@nsโ™ฅBunnyComโ™ฅ~]# nmap -sS -O -v 192.168.40.4 | grep ftp
21/tcp   open  ftp     vsftpd 2.0.5
ftp.xxxxxxxxxx.xx.kr   A       192.168.40.4
[root@nsโ™ฅBunnyComโ™ฅ~]# setsebool -P ftp_home_dir=1
[root@nsโ™ฅBunnyComโ™ฅ~]# ftp 192.168.40.4
KERBEROS_V4 rejected as an authentication type
Name (192.168.40.4:root): bunny
331 Please specify the password.
Password: xxxxxxxxxxxxxxxxxxx
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files. => ์ ‘์†ํ™•์ธ
ftp> ls -al
227 Entering Passive Mode (192,168,40,4,156,65)
150 Here comes the directory listing.
-rwx------    1 500      500          5670 Feb 25 06:23 IPTables_powerSecurity_script.sh
-rw-r--r--    1 500      500           843 Feb 26 02:01 sulinux-download-sct.sh
226 Directory send OK.
ftp> quit  => ์ข…๋ฃŒ๋ช…๋ น์ด๋‹ค.
์ด๋Ÿฐ์‹์œผ๋กœ ์„ค์ •ํ•˜๊ณ  ํ…Œ์ŠคํŠธ ๊นŒ์ง€ ์™„๋ฃŒํ•˜๋ฉด ๋ชจ๋“  ๊ตฌ์ถ•์€ ๋๋‚œ๋‹ค.

 

 

 

[root@nsโ™ฅBunnyComโ™ฅ~]# mv /etc/sysctl.conf /etc/sysctl_backup.conf
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/sysctl.conf
########## ์ปค๋„์˜ต์…˜ ํŠœ๋‹๊ฐ’๋“ค  ################
net.ipv4.icmp_echo_ignore_all = 0
net.ipv4.icmp_echo_ignore_broadcasts = 1
net.ipv4.icmp_ignore_bogus_error_responses = 1
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 180
net.ipv4.tcp_timestamps = 0
net.ipv4.tcp_syncookies = 1
net.ipv4.tcp_max_syn_backlog = 1280
net.ipv4.tcp_sack = 0
net.ipv4.tcp_window_scaling = 0
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.ip_local_port_range = 32768 61000
net.ipv4.ip_forward = 0
vm.bdflush = 100 1200 128 512 15 5000 500 1884 2
vm.buffermem = 80 10 60
kernel.sysrq = 1
##์„ ํƒ์‚ฌํ•ญ
#net.ipv4.icmp_echo_ignore_all = 0
#fs.file-max = 32768
###  RAM 256M :8192
##### ======================= ์˜ต์…˜ ์„ค๋ช… ================================#####
#net.ipv4.icmp_echo_ignore_all = 1   ์‘๋‹ต ๋ง‰๊ธฐ
#net.ipv4.icmp_echo_ignore_all = 0   ์‘๋‹ต ํ•˜๊ธฐ
#net.ipv4.icmp_echo_ignore_broadcasts = 1   Broadcast๋กœ ์˜ค๋Š” ํ•‘ ์ฐจ๋‹จํ•˜๊ธฐ
#net.ipv4.conf.all.accept_source_route = 0  IP ์†Œ์Šค ๋ผ์šฐํŒ… ๋ง‰๊ธฐ
#net.ipv4.tcp_max_syn_backlog=1024  backlog ๋Š˜๋ฆฌ๊ธฐ ์กฐ์ • ๊ฐ’
#net.ipv4.tcp_syncookies = 1  syncookie ๊ธฐ๋Šฅ ํŒ๋ณ„
#net.ipv4.conf.all.send_redirects= 0
#net.ipv4.conf.all.accept_redirects= 0   ICMP redirect๋ฅผ ๋ง‰๋Š”๋‹ค
#net.ipv4.icmp_ignore_bogus_error_responses = 1   bad icmp ํŒจํ‚ท ์ฐจ๋‹จ
#net.ipv4.conf.all.rp_filter = 1  IP ์Šคํ‘ธํ•‘ ๋ฐฉ์ง€ํ•˜๊ธฐ
#net.ipv4.conf.all.log_martians = 1  IP ์Šคํ‘ธํ•‘๋œ ํŒจํ‚ท ๋กœ๊ทธ์— ๊ธฐ๋กํ•˜๊ธฐ
#/etc/host.conf ํŒŒ์ผ์— nospoof ์˜ต์…˜์„ ์ฃผ์–ด IP ์Šคํ‘ธํ•‘ ๋ฐฉ์ง€๋ฅผ ์œ„ํ•œ ์„ค์ •์„ ์ถ”๊ฐ€ multi on + nospoof on
#net.ipv4.tcp_fin_timeout = 30   ์—ฐ๊ฒฐ์ข…๋ฃŒ์‹œ๊ฐ„์„ ์ค„์ธ๋‹ค
#net.ipv4.tcp_keepalive_time = 1800   keepalive ์‹œ๊ฐ„ ์ค„์ด๊ธฐ
#net.ipv4.ip_local_port_range = 32768 61000  ์—ด์ˆ˜ ์žˆ๋Š” ํฌํŠธ ๋Š˜๋ฆฌ๊ธฐ
======================================================================================
[root@nsโ™ฅBunnyComโ™ฅ~]# sysctl -w  => ์‹œ์Šคํ…œ ์„ค์ • ์ €์žฅ
[root@nsโ™ฅBunnyComโ™ฅ~]# sysctl -a  => ์‹œ์Šคํ…œ ์„ค์ • ๊ฐ’ ์ถœ๋ ฅ

 

 

 

[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/issue  => ๋‚ด๋ถ€ ์ ‘์†์‹œ ๋ณด์—ฌ์ค„ ๊ณต์ง€ ๋ฉ”์‹œ์ง€ ์„ค์ •
=============================================================
โ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅ
โ™ฅBunny Server main  System ^^; โ™ฅโ™ฅโ™ฅ
โ™ฅ๋ชจ๋‘ ๋งŒ๋‚˜์„œ ๋ฐ˜๊ฐ€์›Œ์š”~~~       โ™ฅโ™ฅโ™ฅ
โ™ฅ์ฆ๊ฒ๊ณ  ๋ณด๋žŒ์žˆ๋Š” ํ•˜๋ฃจ๊ฐ€ ๋˜์„ธ์š”^^ โ™ฅโ™ฅ
โ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅโ™ฅ
SULinux release 2.0
Kernel \r on an \m
=============================================================
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/issue.net  => ์™ธ๋ถ€์—์„œ ์ ‘์†์‹œ ๋ณด์—ฌ์ค„ ๊ณต์ง€ ๋ฉ”์‹œ์ง€ ์„ค์ •
=================================================================
โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…
โ˜…โ˜…โ˜…โ˜… Bunny Server Power System ^^;      โ˜…โ˜…โ˜…โ˜…
โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…
โ˜…โ˜…โ˜…โ˜…  ๋ชจ๋‘ ๋งŒ๋‚˜์„œ ๋ฐ˜๊ฐ€์›Œ์š”~~~         โ˜…โ˜…โ˜…โ˜…โ˜…
โ˜…โ˜… ๊ด€๋ฆฌ์ž: Bunny <
bunny@bunny.linux.ne.ke>  โ˜…โ˜…โ˜…
โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…
SULinux release 2.0
Kernel \r on an \m
====================================================================
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/motd => ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ณด์—ฌ์ค„ ์ธ์‚ฌ๋ง์ด๋‚˜ ๊ธฐํƒ€ ์•ˆ๋‚ด์‚ฌํ•ญ์„ ์ง€์ •ํ•œ๋‹ค.
=====================================================================
โ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃ
โ–ฃโ–ฃโ–ฃ   ์—ฌ๋Ÿฌ๋ถ„ ์•ˆ๋…•ํ•˜์„ธ์š” ^^                                  โ–ฃโ–ฃโ–ฃ
โ–ฃโ–ฃโ–ฃ   ์ด๋ฒˆ ์„œ๋ฒ„ ๊ณต์ง€์˜ˆ์—ฌ ์„œ๋ฒ„์—์„œ ์ด์ƒํ•œ ํ–‰๋™ ํ•˜์ง€ ๋งˆ์„ธ์š”^^ โ–ฃโ–ฃโ–ฃ
โ–ฃโ–ฃโ–ฃ   ๋‚˜์•ˆํ…Œ ๊ฑธ๋ฆฌ๋ฉด ์‚ญ์ œ ํ• ๊บผ์˜ˆ์—ฌ ...                       โ–ฃโ–ฃโ–ฃ
โ–ฃโ–ฃโ–ฃ   ์ข‹์€ ์‹œ๊ฐ„ ๋˜์‹œ๊ณ ์š”                              โ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃ
โ–ฃโ–ฃโ–ฃ   ๊ฒŒ์‹œํŒ์—ํŽธ ์‚ฌํ•ญ ์žˆ์œผ์‹œ๋ฉด ๋ฉ”์„ธ์ง€ ๋‚จ๊ฒจ์ฃผ์„ธ์—ฌ^^    โ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃ
โ–ฃโ–ฃโ–ฃ   good bye~~~~^^                                  โ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃ
โ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃโ–ฃ

 

 

 

sendmail SMTP ์„œ๋ฒ„ ๊ตฌ์ถ• ์„ค์ •
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/xinetd.d/imap

 disable = no  => ์‚ฌ์šฉ์‹œ์ž‘

[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/xinetd.d/ipop3

 disable = no  => ์‚ฌ์šฉ์‹œ์ž‘

[root@nsโ™ฅBunnyComโ™ฅ~]# cat /etc/services | grep imap  => ์„ค์ • ํ™•์ธ
imap            143/tcp         imap2           # Interim Mail Access Proto v2
imap            143/udp         imap2
[root@nsโ™ฅBunnyComโ™ฅ~]# cat /etc/services | grep smtp => ์„ค์ • ํ™•์ธ
smtp            25/tcp          mail
smtp            25/udp          mail
[root@nsโ™ฅBunnyComโ™ฅ~]# cat /etc/services | grep pop3  => ์„ค์ • ํ™•์ธ
pop3            110/tcp         pop-3           # POP version 3
pop3            110/udp         pop-3
[root@nsโ™ฅBunnyComโ™ฅ~]# service xinetd restart => ์„œ๋น„์Šค ์žฌ ์‹œ์ž‘
[root@nsโ™ฅBunnyComโ™ฅ~]# telnet localhost imap => * OK .. ์„ค์ •์ด ๋‚˜์˜ค๋ฉด ์„ฑ๊ณต
[root@nsโ™ฅBunnyComโ™ฅ~]# telnet localhost 25   => * OK .. ์„ค์ •์ด ๋‚˜์˜ค๋ฉด ์„ฑ๊ณต
[root@nsโ™ฅBunnyComโ™ฅ~]# telnet localhost 110 => * OK .. ์„ค์ •์ด ๋‚˜์˜ค๋ฉด ์„ฑ๊ณต
์ƒŒ๋“œ๋ฉ”์ผ ํ™˜๊ฒฝ ์„ค์ • ํ•˜๊ธฐ
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/mail/sendmail.mc

 dnl # DAEMON_OPTIONS(`Port=smtp,Addr=127.0.0.1, Name=MTA')dnl => ์ฃผ์„์ฒ˜๋ฆฌ
DAEMON_OPTIONS(`Port=smtp, Name=MTA')dnl => ์ „์ฒด์ ์œผ๋กœ ํ—ˆ์šฉํ•œ๋‹ค๋ฉด ์ฃผ์„ ํ’€๊ณ  ์ด์ฒ˜๋Ÿผ ์„ค์ •
LOCAL_DOMAIN(`localhost.localdomain')dnl => ๋กœ์ปฌ ๋„๋ฉ”์ธ ์„ค์ •
dnl MASQUERADE_AS(`mydomain.com')dnl => ์ €์ •๋œ ์ž์‹ ์˜ ๋„๋ฉ”์ธ์œผ๋กœ ์„ค์ •
MASQUERADE_AS(`xxxxxxxxx.pe.kr')dnl
FEATURE(masquerade_envelope)dnl

์ €์žฅํ•˜๊ณ  ๋น ์ ธ๋‚˜์˜จ๋‹ค.
SMTP ์ธ์ฆ (SMTP AUTH)์„ ์‚ฌ์šฉํ•˜๋„๋ก ์„ค์ •
์ธํ„ฐ๋„ท์„ ๊ฒฝ์œ ํ•  ๊ฒฝ์šฐ, SMTPs(SMTP over SSL)์„ ์ด์šฉํ•ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๋‹ค์Œ ์„ค์ •์„ ํ•ด์•ผ ํ•œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/mail/sendmail.mc

 ๋‹ค์Œ ๊ตฌ๋ฌธ์ด ์ฃผ์„์ฒ˜๋ฆฌ ๋˜์–ด ์žˆ์„ ๊ฒƒ์ด๋‹ค. ์•„๋ž˜์ฒ˜๋Ÿผ ์ฃผ์„์„ ์ œ๊ฑฐ ํ•œ๋‹ค.
TRUST_AUTH_MECH(`EXTERNAL DIGEST-MD5 CRAM-MD5 LOGIN PLAIN')dnl
define(`confAUTH_MECHANISMS', `EXTERNAL GSSAPI DIGEST-MD5 CRAM-MD5 LOGIN PLAIN')dnl

์ €์žฅํ•˜๊ณ  ๋น ์ ธ๋‚˜์˜จ๋‹ค.
๋‹ค์Œ์— SMTP์ธ์ฆ ๊ด€๋ฆฌ ๋ฐ๋ชฌ์ธ saslauthd๋ฅผ ์‹คํ–‰์‹œํ‚จ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# service saslauthd start
saslauthd (์„)๋ฅผ ์‹œ์ž‘ ์ค‘:                                  [  OK  ]
[root@nsโ™ฅBunnyComโ™ฅ~]# chkconfig saslauthd on  => ์ž๋™ ์‹คํ–‰ ์„ค์ •
์ด์ œ sendmail.cf ํŒŒ์ผ์„ ์ƒ์„ฑํ•ด ์ค€๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# m4 /etc/mail/sendmail.mc > /etc/mail/sendmail.cf
[root@nsโ™ฅBunnyComโ™ฅ~]# service sendmail restart => ๋ฉ”์ผ์„œ๋ฒ„ ์žฌ ์‹คํ–‰
[root@nsโ™ฅBunnyComโ™ฅ~]# system-config-securitylevel => ๋ฐฉํ™”๋ฒฝ ์„ค์ •์—์„œ SMTP ํฌํ† ๋ฅผ ์—ด์–ด์ค€๋‹ค.
๊ทธ๋ž˜์•ผ๋งŒ ์„œ๋กœ ํ†ต์‹ ํ•˜๋ฉด์„œ ์ฃผ๊ณ  ๋ฐ›์„์ˆ˜ ์žˆ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# nmap -sS -O -v 192.168.40.4 => ํฌํŠธ ํ™•์ธ
25/tcp   open  smtp    Sendmail 8.13.8/8.13.8
110/tcp  open  pop3    UW Imap pop3d 2007d.104
143/tcp  open  imap    UW imapd 2007d.404 
=> ์ด์ฒ˜๋Ÿผ 3๊ฐ€์ง€ ํฌํŠธ๊ฐ€ ์—ด์–ด์ ธ์•ผ ํ•œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# mail
lifebunny99@gmail.com => ๋ฉ”์ผ์ด ์ „๋‹ฌ๋˜๋Š”์ง€ ํ…Œ์ŠคํŠธ ํ•ด ๋ณธ๋‹ค.

 

์‚ฌ์‹ค ๊ณต์œ ๊ธฐ ์ƒํƒœ์—์„œ ์„œ๋ฒ„ ์šด์˜์‹œ ๋ฐฉํ™”๋ฒฝ์„ ๋‚ด๋ถ€ ์‹œ์Šคํ…œ์—์„œ ๊ตฌ์ฒด์ ์œผ๋กœ ์„ค์ •์„ ํ•  ํ•„์š”๋Š” ์—†๋‹ค.

์™œ๋ƒํ•˜๋ฉด ๊ณต์œ ๊ธฐ ์ž์ฒด๊ฐ€ ๋ฐฉํ™”๋ฒฝ ๊ธฐ๋Šฅ์„ ๋‹ด๊ณ  ์žˆ๊ณ  ์„ค์ •์—์„œ ํฌ์›Œ๋”ฉ ๊ธฐ๋Šฅ์„ ์ด์šฉํ•ด์„œ ์ง€์ •๋œ ํฌํŠธ ์™ธ์—๋Š” ์ ‘๊ทผ์ด

๋ถˆ๊ฐ€๋Šฅํ•˜๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค. ๋‹ค๋งŒ ์ด ๋ฐฉํ™”๋ฒฝ ์‚ฌ์Šฌ์€ ๊ฐœ์ธ ๊ณต์œ ๊ธฐ๊ฐ€ ์•„๋‹Œ ์‹ค์žฌ๋กœ ๊ณ ์ •IP์ƒํƒœ์—์„œ ์ง์ ‘ ๋„คํŠธ์›Œํฌ์— ๋ฌผ๋ ค์žˆ๋Š” ์„œ๋ฒ„ ์ปดํ“จํ„ฐ์—์„œ๋งŒ ํ•ด ์ฃผ๋ฉด ์ข‹์„ ๊ฒƒ์ด๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด ๋ณด์•ˆ์ ์œผ๋กœ ํ•ดํ‚น์„ ๋‹นํ•  ํ™•๋ฅ ์ด ๋†’์•„์ง„๋‹ค.

 

root@nsโ™ฅBunnyโ™ฅ/shellroot]# vi iptables_powerSecurity_script.sh

echo "###################################################################"

echo "#################### ์‹œ์Šคํ…œ ๋ฐฉํ™”๋ฒฝ ์ •์ฑ… ๋ณด์•ˆ ์„ค์ • #################"

echo "#################### ์ž‘์„ฑ์ž : ํ•˜ ํƒœ ์šฉ <bunny>    #################"

echo "#################### http://bunnyblog.tistory.com #################"

echo "#################### E-Mail : bunny@apptree.pe.kr ################"

echo "###################################################################"

IPTABLES="/sbin/iptables"

IP_ADDR=`grep "IPADDR=" /etc/sysconfig/network-scripts/ifcfg-Auto_eth0 | awk -F'=' '{ print $2 }'`

. /etc/init.d/functions

case "$1" in

start|restart)

             echo "$1ing next_firewall :"

             ;;

         stop)

             echo "$1ping next_firewall :"

             $IPTABLES -F

             $IPTABLES -X

             $IPTABLES -P INPUT ACCEPT

             $IPTABLES -P FORWARD ACCEPT

             $IPTABLES -P OUTPUT ACCEPT

             exit

             ;;

            *)

             echo $"Usage: $0 {start|restart|stop}"

             exit

             ;;

esac

echo "================== ๋ฃฐ์…‹ ์ดˆ๊ธฐํ™” ====================="

$IPTABLES -F

echo "==================  ๊ธฐ๋ณธ์ •์ฑ… ์„ค์ • ======================"

$IPTABLES -P INPUT DROP

$IPTABLES -P FORWARD DROP

$IPTABLES -P OUTPUT ACCEPT

echo "================== Loopback ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ ================="

$IPTABLES -A INPUT -i lo -j ACCEPT

echo "==================  ์ž๊ธฐ์ž์‹ ์„ ์†Œ์Šค๋กœ ํ•˜๋Š” ํŠธ๋ž˜ํ”ฝ ์ฐจ๋‹จ  =================="

$IPTABLES -A INPUT -i eth0 -s $IP_ADDR -j DROP

$IPTABLES -A INPUT -i eth0 -s 127.0.0.0/8 -j DROP

echo "================== ์ƒํƒœ์ถ”์  ์„ค์ • ======================="

$IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

$IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

$IPTABLES -A INPUT -p tcp ! --syn -m state --state NEW -j DROP

$IPTABLES -A INPUT -p all -m state --state INVALID -j DROP

echo "================== ๋น„์ •์ƒ์  tcp-flags ์ฐจ๋‹จ ==================="

$IPTABLES -A INPUT -p tcp --tcp-flags ACK,FIN FIN -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL NONE -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL PSH,FIN -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL URG,PSH,FIN -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,ACK,FIN -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,FIN,PSH -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,FIN,RST -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,FIN,RST,PSH -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,FIN,ACK,RST -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,ACK,FIN,RST,PSH -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags FIN,RST FIN,RST -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ACK,PSH PSH -j DROP

$IPTABLES -A INPUT -p tcp --tcp-flags ACK,URG URG -j DROP

echo "================== ftp servive ========================"

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 20 -m state --state NEW -j ACCEPT

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 21 -m state --state NEW -j ACCEPT

echo "================== ssh servive ========================"

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 22 -m state --state NEW -j ACCEPT

echo "================== telnet servive ======================"

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 23 -m state --state NEW -j ACCEPT

echo "================== smtp servive  ======================="

#$IPTABLES -A INPUT -p tcp --sport 1024: --dport 25 -m state --state NEW -j ACCEPT

echo "================== domainserver servive ====================="

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 53 -m state --state NEW -j ACCEPT

$IPTABLES -A INPUT -p udp --sport 1024: --dport 53 -m state --state NEW -j ACCEPT

echo "================== http servive ====================="

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 80 -m state --state NEW -j ACCEPT

echo "================== OpenVPN service ==================="

$IPTABLES -A INPUT -p udp --sport 1024: --dport 1194 -m state --state NEW -j ACCEPT

echo "================== pop3 servive ====================="

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 110 -m state --state NEW -j ACCEPT

echo "================== identd servive ==================="

$IPTABLES -A INPUT -p tcp --syn --dport 113 -j REJECT --reject-with tcp-reset

echo "================== imap servive =================="

#$IPTABLES -A INPUT -p tcp --sport 1024: --dport 143 -m state --state NEW -j ACCEPT

echo "================== snmp servive =================="

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 161 -m state --state NEW -j ACCEPT

$IPTABLES -A INPUT -p udp --sport 1024: --dport 161 -m state --state NEW -j ACCEPT

$IPTABLES -A INPUT -p udp --sport 1024: --dport 199 -m state --state NEW -j ACCEPT

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 199 -m state --state NEW -j ACCEPT

echo "================== https servive ================="

#$IPTABLES -A INPUT -p tcp --sport 1024: --dport 443 -m state --state NEW -j ACCEPT

echo "================== rsync servive ================="

#$IPTABLES -A INPUT -p tcp --sport 1024: --dport 873 -m state --state NEW -j ACCEPT

echo "================== mysql servive ================="

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 3306 -m state --state NEW -j ACCEPT

echo "================== http servive 3000 =================="

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 3000 -m state --state NEW -j ACCEPT

echo "================== servive luxe =================="

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 39789 -m state --state NEW -j ACCEPT

$IPTABLES -A INPUT -p tcp --sport 1024: --dport 36785 -m state --state NEW -j ACCEPT

$IPTABLES -A INPUT -p icmp --icmp-type echo-request -j ACCEPT

[root@nsโ™ฅBunnyโ™ฅ/shellroot]# sh iptables_powerSecurity_script.sh

[root@nsโ™ฅBunnyโ™ฅ/shellroot]# iptables โ€“L รจ ๋ฐฉํ™”๋ฒฝ ์ •์ฑ…์„ ํ™•์ธํ•œ๋‹ค.

[root@nsโ™ฅBunnyโ™ฅ/shellroot]# iptables โ€“F รจ ๋ฐฉํ™”๋ฒฝ ์ •์ฑ…์„ ์ดˆ๊ธฐํ™” ํ•œ๋‹ค.

<์ฐธ๊ณ  ๋‚ด์šฉ>

iptables ๋ณด์•ˆ ์‚ฌ์Šฌ ์˜ต์…˜

-A(--append) : ์ •์ฑ…์•ˆ์— ๊ทœ์น™์„ ๋ง๋ถ™์ธ๋‹ค. -D(--delete) : ํ•œ๊ฐœ๋˜๋Š” ๊ทธ์ด์ƒ์˜ ์„ ํƒ๋œ ๊ทœ์น™์„ ์ง€์šด๋‹ค

-R(--replace) :์„ ํƒ๋œ ๊ทœ์น™์„ ์ƒˆ๋กœ์šด ๊ทœ์น™์œผ๋กœ ๋Œ€์ฒดํ•œ๋‹ค. -I(--insert) : ์ •์ฑ…์†์— ์ƒˆ๋กœ์šด ๊ทœ์น™์„ ๋„ฃ๋Š”๋‹ค.

-P(--policy) : ๊ธฐ๋ณธ ์ •์ฑ…์„ ๋ณ€๊ฒฝํ•œ๋‹ค  -N(--new-chain) : ์ƒˆ๋กœ์šด ์ •์ฑ…์ˆ˜๋ฆฝํ•œ๋‹ค

-X(--delete-chain) : ์ •์˜๋˜์ง€ ์•Š์€ ๊ทœ์น™์€ ์ง€์šด๋‹ค.  -L(--list) : ๊ฐ ์ •์ฑ…์„ ๋‚˜์—ดํ•œ๋‹ค.

0-F(--flush) : ๋ชจ๋“ ์ •์ฑ…์„ ์ง€์šด๋‹ค  -Z(--zero) ์ •์ฑ…์•ˆ์—์žˆ๋Š” ๋ชจ๋“  ๊ทœ์น™๋“ค์˜ ํŒจํ‚ท์ด๋‚˜ ์นด์šดํ„ฐ์˜ ๋ฐ”์ดํŠธ๊ฐ’์„ 0์œผ๋กœ

์ดˆ๊ธฐํ™”ํ•œ๋‹ค.

์ถ”๊ฐ€์˜ต์…˜  รจ ACCEPT <๋‹น์—ฐํžˆ ๋ฐ›์•„๋“ค์ธ๋‹ค๋Š” ๋œป์ด๊ณ >   REJECT

โ€“ DENY <๊ฑฐ๋ถ€ํ•œ๋‹ค๋Š” ๋œป์ธ๋ฐ REJECT๋Š” ์นœ์ ˆํ•˜๊ฒŒ '๊ฑฐ๋ถ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค>

DENY <๋ถˆ์นœ์ ˆํ•˜๊ฒŒ ์•„๋ฌด๋Ÿฐ ์‘๋‹ต์ด ์—†๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•œ๋‹ค>

์„ธ๋ถ€ ์˜ต์…˜  รจ -p(--protocol) ์ด ๊ทœ์น™์˜ protocol  -s(--source)  ๋ฐœ์‹ ์ง€ ์ฃผ์†Œ  -sport(--source-port)

 ๋ฐœ์‹ ์ง€ port(๋ชจ๋“ ์ฃผ์†Œ์— ๋Œ€ํ•ด์„œ) 

-d(--destination) ๋„์ฐฉ์ง€ ์ฃผ์†Œ  -dport(--destination-port) ๋„์ฐฉ์ง€ port(๋ชจ๋“  ์ฃผ์†Œ์— ๋Œ€ํ•ด์„œ) -icmp-type 

ICMP type์„ ๋‚˜ํƒ€๋‚ธ๋‹ค -j(--jump)  ํŒจํ‚ท์„ ์ ํ”„์‹œํ‚จ๋‹ค. -i(--interface) ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ง€์ •ํ•ด์ค€๋‹ค.

======================================================================================

iptables -s 211.238.165.111 -j DROP   รจ ๋ง‰๊ธฐ

iptables -A INPUT -s 211.238.165.111 -p tcp --destination-port telnet -j DROP รจ Service ์ฐจ๋‹จํ•˜๊ธฐ

iptables -A INPUT -p tcp --destination-port telnet -i ppp0 -j DROP  รจ ์„ ํƒ์ ์ธ ์ฐจ๋‹จ

iptables -A INPUT -i ppp0 -p tcp --syn -j DROP  รจ SYN Packets ๋ง‰๊ธฐ

iptables -A INPUT -i ppp0 -p tcp --syn --destination-port ! 80 -j DROP รจ SYN Packets web ๋ง‰๊ธฐ

iptables -P FORWARD ACCEPT  รจ Chain ์ •์ฑ…

=============================================================================================================

 

 

 

[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/ssh/sshd_config

 #### ์ง€์ •๋œ ํฌํŠธ๋กœ ์ ‘์†์‹œ ์‚ฌ์šฉ๊ฐ€๋Šฅ #####
Port 22
###### ํ”„๋กœํ†จ์ฝœ ๋ฐฉ์‹์„ ๊ฒฐ์ • ํ•œ๋‹ค. #######
Protocol 2,1
# Protocol 1
###### ํ•ด๋‹น ์ธ์ฆํ‚ค์˜ ์„ค์ •์„ ๊ด€๋ฆฌ #######
# HostKey for protocol version 1
HostKey /etc/ssh/ssh_host_key
# HostKeys for protocol version 2
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key
#LoginGraceTime 2m
##### No<ROOT์ ‘์†๋ถˆ๊ฐ€> Yes<ROOT์ ‘์†ํ—ˆ๊ฐ€> #####
PermitRootLogin yes
UsePrivilegeSeparation yes
UsePAM yes

[root@nsโ™ฅBunnyComโ™ฅ~]# service sshd restart
[root@nsโ™ฅBunnyComโ™ฅ~]# su - bunny
[bunny@nsโ™ฅBunnyโ™ฅ~]# ssh-keygen  => ์ธ์ฆํ‚ค ์„ค์ •
[bunny@nsโ™ฅBunnyโ™ฅ~]# ssh -l root xxxxxxxxxxx.pe.kr
The authenticity of host 'xxxxxxxxx.pe.kr (xxx.xxx.xxx.xxx)' can't be established.
RSA key fingerprint is 89:1a:xx:ad:04:xx:d2:bb:xx:95:13:62:f9:dx:x0:f2.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'xxxxxxxxx.pe.kr (xxx.xxx.xxx.xxx)' (RSA) to the list of known hosts.
Address xxx.xxx.xxx.xxx maps to ns.xxxxxxxxxx.pe.kr, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
root@xxxxxxxxx.pe.kr's password:
Last login: Mon Mar  2 16:12:38 2015 from 210.10.xx.xx

 

๋„๋ฉ”์ธ์„œ๋ฒ„ ๊ตฌ์ถ• ์‹œ ์ค‘์š”ํ•œ ์ ์ด ์žˆ๋‹ค.
ํ•ญ์ƒ ๋„ค์ž„์„œ๋ฒ„๋ฅผ ์ •ํ™•ํžˆ ์„ค์ •ํ•ด์•ผ ํ•œ๋‹ค๋Š” ์ ์ด๋‹ค. ๊ณ ์ •IP์ƒํƒœ์—์„œ๋Š” ์ƒ๊ด€์ด ์—†๋Š”๋ฐ
๋ฌธ์ œ๋Š” ๊ณต์œ ๊ธฐ๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ๊ฐ€ ๋ฌธ์ œ๊ฐ€ ๋œ๋‹ค๋Š” ์ ์ด๋‹ค.
๋‹ค์‹œ ๋งํ•˜๋ฉด ๋„๋ฉ”์ธ ๊ฐ€์ž… ์‹œ ๋„ค์ž„์„œ๋ฒ„๊ฐ€ 211.238.100.5๋ผ๊ณ  ๊ฐ€์ •ํ•  ๋•Œ
๊ณต์œ ๊ธฐ์˜ ์‹ค์ œ IP๊ฐ€ 211.238.100.5๋กœ ๋˜์–ด ์žˆ์–ด์•ผ ํ•œ๋‹ค๋Š” ์ ์ด๋‹ค.
๊ทธ ์กฐ๊ฑดํ•˜์— ๋‚ด๋ถ€ ์ปดํ“จํ„ฐ์˜ IP๊ฐ€ 192.168.10.5๋ผ๊ณ  ๊ฐ€์ •ํ•  ๋•Œ ๋‚ด๋ถ€์„œ๋ฒ„ ์ปดํ“จํ„ฐ์— ๋„๋ฉ”์ธ์„œ๋ฒ„๋ฅผ ์„ค์น˜ ์‹œ
๋„ค์ž„์„œ๋ฒ„์— 211.238.100.5๋ผ๋Š” ์‹ค์žฌ๊ณต์œ ๊ธฐ IP๋ฅผ ์ ์–ด์ฃผ์–ด์•ผ ํ•œ๋‹ค.
๊ทธ๋ž˜์•ผ๋งŒ ํฌํŠธ ํฌ์›Œ๋”ฉ ์„ค์ • ์‹œ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๋‚ด ๋„๋ฉ”์ธ์„ ์งˆ์˜ ํ•  ๋•Œ ๋„ค์ž„์„œ๋ฒ„์ธ 211.238.100.5์˜ ๊ณต์œ ๊ธฐ๊ฐ€
๋‚ด๋ถ€ ์„œ๋ฒ„์ปดํ“จํ„ฐ์ธ 192.168.10.5์— ํฌ์›Œ๋”ฉํ•ด์„œ ์‘๋‹ตํ•œ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค.
์ด์ ์„ ๋ถ„๋ช…ํžˆ ์•Œ๊ณ  ์žˆ์–ด์•ผ๋งŒ ํ˜ผ๋™ํ•˜์ง€ ์•Š๋Š”๋‹ค.
๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๋‚ด๊ฐ€ ํ• ๋ ค๊ณ  ํ•˜๋Š”๊ฒƒ์€ vmware ๊ฐ€์ƒ OS์ƒํƒœ์—์„œ ๋„๋ฉ”์ธ์„œ๋ฒ„๊ฐ€ ์‘๋‹ตํ• ์ˆ˜ ์žˆ๋„๋ก ํ•ด์•ผ ํ•œ๋‹ค๋Š” ์ ์ด๋‹ค.
์ฆ‰ 4๋‹จ๊ณ„ ๋„คํŠธ์›Œํฌ ๊ณต์œ  ์„ค์ •์„ ํ•ด์•ผ ํ•œ๋‹ค๋Š” ์ ์ด๋‹ค.
(1) ๊ณต์œ ๊ธฐ NAT์„ค์ • => ์ž‘์—…์ปด์˜ ๊ณ ๊ธ‰๋ฐฉํ™”๋ฒฝ์—์„œ ์˜คํ”ˆํฌํŠธ์„ค์ • => vm์›จ์–ด NAT์„ค์ • => ๊ฐ€์ƒ Linux ์„œ๋น„์ŠคํฌํŠธ ์„ค์ •

 
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/named.conf 

 //      listen-on port 53 { 127.0.0.1; }; => ์ฃผ์„์ฒ˜๋ฆฌํ•ด์•ผ ํฌํŠธ๊ฐ€ ์—ด๋ฆฐ๋‹ค.
//      allow-query     { localhost; };
        allow-query     { localhost; 192.168.40.0/24; }; => ์ถ”๊ฐ€
        allow-transfer { localhost; 192.168.40.0/24; }; => ์ถ”๊ฐ€
        allow-query-cache { localhost; };
 include "/etc/named.rfc1912.zones"; => ์ด๋ถ€๋ถ„ ์„ค์ •

[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/named.rfc1912.zones

 

 ### ๋‹ค์Œ ๋‚ด์šฉ์„ ์ถ”๊ฐ€
zone "com111.pe.kr" IN {
        type master;
        file "com111.server";
        allow-update { none; };
};
zone "40.168.192.in-addr.arpa" IN {
        type master;
        file "192.168.40.db";
        allow-update { none; };
};

[root@nsโ™ฅBunnyComโ™ฅ~]# cd /var/named/chroot/var/named/
[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# vi livesystem.server

 $TTL    86400
@               IN SOA  com111.pe.kr. root.com111.pe.kr. (
                                        42              ; serial (d. adams)
                                        3H              ; refresh
                                        15M             ; retry
                                        1W              ; expiry
                                        1D )            ; minimum
                IN NS           @
                IN A            127.0.0.1
                IN AAAA         ::1
        IN      NS      com111.pe.kr.
        IN      A       192.168.40.4
        IN      MX      10      com111.pe.kr.
ns      IN      A       192.168.40.4
mail    IN      A       192.168.40.4
ftp     IN      A       192.168.40.4
www     IN      A       192.168.40.4
mp3     IN      A       192.168.40.4
blog    IN      A       192.168.40.4

[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# vi 192.168.40.db

 $TTL    86400
@               IN SOA  com111.pe.kr.       com111.pe.kr.  (
                                        42              ; serial (d. adams)
                                        3H              ; refresh
                                        15M             ; retry
                                        1W              ; expiry
                                        1D )            ; minimum
        IN      NS      localhost.
        IN      NS      com111.pe.kr.
        IN      A       192.168.40.4
4       IN      PTR     com111.pe.kr.

[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# named-checkconf /etc/named.conf
[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# named-checkzone com111.pe.kr com111.server
[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# named-checkzone com111.pe.kr 192.168.40.db
[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# service named start
named๋ฅผ ์‹œ์ž‘ ์ค‘:                                           [  OK  ]
[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# chkconfig named on  => ๋ถ€ํŒ…์‹œ ์‹œ์ž‘ ์„ค์ •
[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# ps aux | grep named
named    11935  0.0  0.3  88684  4080 ?        Ssl  16:53   0:00 /usr/sbin/named -u named -t /var/named/chroot
[root@nsโ™ฅBunnyComโ™ฅ/var/named/chroot/var/named]# nslookup com111.pe.kr
Server:         162.252.53.132
Address:        162.252.53.132#53
Name:   com111.pe.kr
Address: 192.168.40.4     => ์‘๋‹ตํ™•์ธ

์œ ์ € ์‚ฌ์šฉ์ž ์ถ”๊ฐ€ ๋ฐ ๊ธฐํƒ€ ์„ค์ •
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/login.defs => ์œ ์ €์˜ ์ „๋ฐ˜์ ์ธ ์„ค์ •์กฐ์ •

 MAIL_DIR        /var/spool/mail   ==> ๋ฉ”์ผ ๊ฒฝ๋กœ ๋ณ€๊ฒฝ
PASS_MAX_DAYS   99999   ==> ํŒจ์Šค์›Œ๋“œ์˜ ๋ณ€๊ฒฝ์—†์ด ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ๋Œ€์ผ์ž.
PASS_MIN_DAYS   0     ==> ํŒจ์Šค์›Œ๋“œ์˜ ๋ณ€๊ฒฝ์—†์ด ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์†Œ์ผ์ž
PASS_WARN_AGE   7  ==>  ๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณ€๊ฒฝ ๊ฒฝ๊ณ  ๋ฉ”์„ธ์ง€ ๋ณด๋‚ด๋Š” ๊ธฐ๊ฐ„(์œ ํšจ๊ธฐ๊ฐ„์œผ๋กœ๋ถ€ํ„ฐ x์ผ)
PASS_MIN_LEN    5   ==> PASS_MIN_LEN    8  ์ •๋„๋กœ ์ˆ˜์ •
UID_MIN     500       ==> ์‚ฌ์šฉ์ž๋ฅผ ์ถ”๊ฐ€ํ•  ๋•Œ UID์˜ ์ตœ์†Œ๊ฐ’  ๋ฒ”์œ„๋ฅผ ์„ค์ •
UID_MAX    60000   ==> ์‚ฌ์šฉ์ž๋ฅผ ์ถ”๊ฐ€ํ•  ๋•Œ UID์˜ ์ตœ๋Œ€๊ฐ’์˜ ๋ฒ”์œ„๋ฅผ ์„ค์ •
GID_MIN     500        ==> ์‚ฌ์šฉ์ž๋ฅผ ์ถ”๊ฐ€ํ•  ๋•Œ GID์˜ ์ตœ์†Œ๊ฐ’  ๋ฒ”์œ„๋ฅผ ์„ค์ •
GID_MAX    60000    ==> ์‚ฌ์šฉ์ž๋ฅผ ์ถ”๊ฐ€ํ•  ๋•Œ GID์˜ ์ตœ๋Œ€๊ฐ’์˜ ๋ฒ”์œ„๋ฅผ ์„ค์ •
CREATE_HOME yes   ==>  ํ™ˆ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ์ž๋™์œผ๋กœ ์ƒ์„ฑํ•  ๊ฒƒ์ธ๊ฐ€์˜ ์—ฌ๋ถ€
UMASK  077  ==> ์‚ฌ์šฉ์ž ๋””๋ ‰ํ† ๋ฆฌ ์ƒ์„ฑ์‹œ UMASK ๊ฐ’์„ ์„ค์ •ํ•œ๋‹ค. 076  : 701๋กœ ์ƒ์„ฑ๋œ๋‹ค.
SULOG_FILE   /var/log/test_log   ==> sulog ํŒŒ์ผ์„ /var/log ๋””๋ ‰ํ† ๋ฆฌ ๋ฐ‘์— test_log ๋ž€ ํŒŒ์ผ๋ช…์œผ๋กœ ๋‚จ๊ธธ ๊ฒƒ
SU_WHEEL_ONLY  yes ==> su ๋ช…๋ น์€ wheel ๊ทธ๋ฃน์— ์†ํ•˜๋Š” ์‚ฌ์šฉ์ž๋งŒ์ด ์‹คํ–‰์‹œํ‚ฌ ์ˆ˜ ์žˆ๋„๋ก ํ•  ๊ฒƒ
SYSLOG_SU_ENAB es  ==> # ํ•˜๊ธฐ๋กœ ํ•œ ํŒŒ์ผ์—๋„ ๋™์‹œ์— ๋‚จ๊ธธ ๊ฒƒ

[root@nsโ™ฅBunnyComโ™ฅ~]# authconfig --updateall  => ๋ชจ๋“  ์„ค์ • ํŒŒ์ผ์„ ์—…๋ฐ์ดํŠธ
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/security/limits.conf  => ์‚ฌ์šฉ์ž ๋ฆฌ์†Œ์Šค ์„ค์ •ํŒŒ์ผ

@user           hard    core            0
@user           hard    nproc           20
@user           hard    rss             5000
# ์ฝ”์–ดํ™”์ผ ์ƒ์„ฑํ•˜์ง€ ์•Š๊ณ  , ํ”„๋กœ์„ธ์Šค์ˆ˜ 20 , ์‚ฌ์šฉ์ž ํ•œ ์‚ฌ๋žŒ๋‹น ๋ฉ”๋ชจ๋ฆฌ ์‚ฌ์šฉ์„ 5๋ฉ”๊ฐ€๋กœ ์ œํ•œ

[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/pam.d/login

 session required        pam_limits.so => ์ถ”๊ฐ€

[root@nsโ™ฅBunnyComโ™ฅ~]# adduser bunny  => ์‚ฌ์šฉ์ž ์œ ์ € ์ถ”๊ฐ€
[root@nsโ™ฅBunnyComโ™ฅ~]# passwd bunny  => ์‚ฌ์šฉ์ž ํŒจ์Šค์›Œ๋“œ ์„ค์ •
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/default/useradd

# useradd defaults file
GROUP=100
### ๊ธฐ๋ณธ ์œ ์ € ๋””๋ ‰ํ† ๋ฆฌ ###
HOME=/home
INACTIVE=-1
EXPIRE=
### ๊ธฐ๋ณธ ์‚ฌ์šฉํ•˜๋Š” shell ์ง€์ • ####
SHELL=/bin/bash
### ์…ˆํ”Œ ๋””๋ ‰ํ† ๋ฆฌ ์ง€์ • ####
SKEL=/etc/skel
CREATE_MAIL_SPOOL=yes

[root@nsโ™ฅBunnyComโ™ฅ~]# mkdir -m 755 /etc/skel/www  => ์‚ฌ์šฉ์ž web์„œ๋น„์Šค ๋””๋ ‰ํ† ๋ฆฌ ์„ค์ •
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/skel/www/index.html

โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…
โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…    ๋ฒ„๋‹ˆ ๊ณ„์ • ์‚ฌ์šฉ์ž ํ…Œ์ŠคํŠธ ํ์ด์ง€   โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…
โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…    ํ™ˆ ํ์ด์ง€๊ฐ€ ๋ณด์ด์‹œ๋‚˜์š” ~~~^^     โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…
โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…โ˜…

[bunny@nsโ™ฅBunnyโ™ฅ~]# vi .bash_profile

# User specific environment and startup programs
################# ์‹œ์Šคํ…œ ์ฝ˜์†” DIR ์นผ๋ผ ์„ค์ • #######################
eval `dircolors /etc/DIR_COLORS -b`
export LS_COLORS="di=01;31":"fi=01;37":"ex=01;32":"ln=01;36":"so=01;31"
######################  ์‹œ์Šคํ…œ ํ”„๋กฌํ”„ํŠธ ํ™˜๊ฒฝ ์„ค์ •  ############################
PS1="\[\033[0;41m\][\u@\hโ™ฅBunnyโ™ฅ\w]#\[\033[0;00m\] "
# PS1="\[\033[0;44m\][\u@\hโ™ฅSunnyโ™ฅ\w]#\[\033[0;00m\] "
#### ์‹œ๊ฐ„ ํƒ€์ž„ ์•„์›ƒ #####
# TMOUT=600
export LANG=ko_KR

์œ ์ €์™€ ๊ทธ๋ฃน ํŒจ์Šค์›Œ๋“œ ๊ด€๋ฆฌ ๋ช…๋ น์–ด

 /home]# cat /etc/default/useradd => ์œ ์ € ์ƒ์„ฑ์‹œ ํ™˜๊ฒฝ์ •๋ณด ํŒŒ์ผ
HOME=/home  => /home/users ์—์„œ ์ƒ์„ฑ ๊ฐ€๋Šฅ     GROUP=100  => ์†ํ•  ๊ทธ๋ฃน ์ƒ์„ฑ ์ง€์ •
/home]# ls -al /etc/skel/  => ๊ณ„์ • ์ƒ์„ฑ์‹œ ์ฐธ์กฐ ๋””๋ ‰ํ† ๋ฆฌ
ํ•„์š”ํ•œ ํŒŒ์ผ => www<์‚ฌ์šฉ์ž webroot> index.htm<๊ธฐ๋ณธwebํ…Œ์ŠคํŠธํŒŒ์ผ> .bash_profile <์‚ฌ์šฉ์ž ์ •๋ณด์‹œ์Šคํ…œํŒŒ์ผ>
/]# cat /etc/passwd  => ํŒจ์Šค์›Œ๋“œ ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ๋Š” ํŒŒ์ผ
/]# cat /etc/shadow => ์ƒˆ๋„์šฐ ํŒจ์Šค์›Œ๋“œ ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ๋Š” ํŒŒ์ผ
/]# cat /etc/gshadow  => ๊ทธ๋ฃน ์ •๋ณด์™€ ๊ทธ๋ฃน ํŒจ์Šค์›Œ๋“œ ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ๋Š” ํŒŒ์ผ
/home]# adduser bunny
-c : ์‚ฌ์šฉ์ž์ •๋ณด์ž…๋ ฅ -d : ํ™ˆ๋””๋ ‰ํ† ๋ฆฌ์ง€์ • -e : ๊ณ„์ •์œ ํšจ๊ธฐ๊ฐ„์„ค์ • -f : ๋น„ํ™œ์„ฑ๊ธฐ๊ฐ„<์ž๋™๋งŒ๋ฃŒ> -g : ๊ธฐ๋ณธ๊ทธ๋ฃน
?G : ๋‹ค์ค‘๊ทธ๋ฃน -s: ๊ธฐ๋ณธ์‰ด๋ณ€๊ฒฝ
/home]# adduser -G bunny<๋‹ค์ค‘๊ทธ๋ฃน> -d /home/users/bunny<ํ™ˆ ์ง€์ •> -s /bin/sh<๊ธฐ๋ณธshell> bunny
/home]# id bunny
uid=512(bunny) gid=513(bunny) groups=513(bunny,512(bunny)  => ๋ณ€๊ฒฝ ๋‚ด์šฉ์„ ํ™•์ธ
/home/users]# userdel bunny  => ์‚ฌ์šฉ์ž ๊ณ„์ •์„ ์‚ญ์ œ
/home/users]# userdel -r bunny  => -r์€ ํ•ด๋‹น ๊ณ„์ • ๋””๋ ‰ํ† ๋ฆฌ ๊นŒ์ง€ ์‚ญ์ œ
/home/users]# groupadd admin  => ์ƒˆ๋กœ์šด ๊ทธ๋ฃน ์ƒ์„ฑ
-g : ๊ทธ๋ฃนID์ง€์ •ํ•ด์„œ ์ƒ์„ฑ    -r : ๊ทธ๋ฃนID 500์ดํ•˜ ๊ฐ’์œผ๋กœ ์ž๋™์ƒ์„ฑ  

-f : ์‹œ์Šคํ…œ๊ทธ๋ฃน์— ์กด์žฌํ•  ๊ฒฝ์šฐ ์—๋Ÿฌ ์ถœ๋ ฅ ์—†์ด ์ข…๋ฃŒ
/home/users]# groupadd -g 655 admin
/]# groups bunny  => ์†ํ•œ ๊ทธ๋ฃน์„ ์กฐํšŒ
/home/users]# cat /etc/group | grep admin  => admin:x:655:
/chroot]# chsh bunny<์•„์ด๋””> => New shell [/bin/bash]: /bin/tcsh <์‚ฌ์šฉํ•˜๋Š” SHELL ๋ณ€๊ฒฝ>
/chroot]# chage -l bunny => ์‚ฌ์šฉ์ž์˜ ๊ณ„์ •ํ™œ์„ฑํ™” ์ •์ฑ… ํ™•์ธ
/home/users]# groupdel admin =>  ์ง€์ • ๊ทธ๋ฃน์„ ์‚ญ์ œํ•œ๋‹ค.
/]# gpasswd bunny  => ๊ทธ๋ฃน ํŒจ์Šค์›Œ๋“œ๋ฅผ ์ง€์ •ํ•œ๋‹ค.
์‚ฌ์šฉ๋ฒ•: [-r|-R] ๊ทธ๋ฃน [-a ์‚ฌ์šฉ์ž] ๊ทธ๋ฃน [-d ์‚ฌ์šฉ์ž] ๊ทธ๋ฃน [-A ์‚ฌ์šฉ์ž,...] [-M ์‚ฌ์šฉ์ž,...] ๊ทธ๋ฃน
/]# groupmod  -n admin bunny => ์ง€์ • ๊ทธ๋ฃน์„ ๋ณ€๊ฒฝํ•œ๋‹ค.
[n ๋ณ€๊ฒฝ๋ ๋ฃน๋ช… / g ๊ทธ๋ฃน์˜๊ณ ์œ ID] ๊ทธ๋ฃธ๋ช…
~]# usermod  => ์œ ์ € ์„ค์ • ์ •๋ณด ๋ณ€๊ฒฝ
-c : ์‚ฌ์šฉ์ž์ •๋ณด์ž…๋ ฅ -d : ํ™ˆ๋””๋ ‰ํ† ๋ฆฌ์ง€์ • -e : ๊ณ„์ •์œ ํšจ๊ธฐ๊ฐ„์„ค์ • -f : ๋น„ํ™œ์„ฑ๊ธฐ๊ฐ„<์ž๋™๋งŒ๋ฃŒ>
-g : ๊ธฐ๋ณธ๊ทธ๋ฃน -G : ๋‹ค์ค‘๊ทธ๋ฃน -s: ๊ธฐ๋ณธ์‰ด๋ณ€๊ฒฝ
~]# chage -l bunny  => ์‚ฌ์šฉ์ž ์œ ํšจ ์ •๋ณด ์กฐํšŒ
~]# chage -M 25 -E 2006/04/18 bunny => ์‚ฌ์šฉ์œ ํšจ๊ธฐ๊ฐ„ ๋ณ€๊ฒฝ
-l<์œ ํšจ๊ธฐ๊ฐ„ ์กฐํšŒ> -m<์ƒˆ๋กœ์šด ํŒจ์Šค์›Œ๋“œ ์ตœ์†Œ๋ณ€๊ฒฝ์ผ์ˆ˜> -M<์œ ํšจํŒจ์Šค์›Œ๋“œ ์ตœ๋Œ€์ผ์ˆ˜> -W<ํŒจ์Šค์›Œ๋“œ ๋ณ€๊ฒฝ์ผ์ˆ˜>
-E<์œ ํšจ๊ธฐ๊ฐ„ ์„ค์ •>
/etc]# passwd bunny  => ์ผ๋ฐ˜ ์œ ์ €์˜ ํŒจ์Šค์›Œ๋“œ ๋ณ€๊ฒฝ
etc]# passwd -S bunny  => -S๋Š” ์œ ์ €์˜ ํŒจ์Šค์›Œ๋“œ ์ƒํƒœ ์กฐํšŒ
~]# passwd -l bunny  => ์ผ์‹œ lock ๊ฑธ์–ด์„œ ์‚ฌ์šฉ ์ •์ง€
~]# passwd -u bunny  => ์ผ์‹œ lock ๊ฑธ์–ด๋‘” ์‚ฌ์šฉ ์„ค์ •์„ ํ‘ผ๋‹ค.
~]# passwd -d bunny  =>  ์‚ฌ์šฉ์ž์˜ ํŒจ์Šค์›Œ๋“œ๋ฅผ ๋‹ค์‹œ ์ดˆ๊ธฐํ™” ์„ค์ • <๋กœ๊ธด ์—†์ด ์ ‘์†>
~]# gpasswd bunny  => ๊ทธ๋ฃน ํŒจ์Šค์›Œ๋“œ๋ฅผ ์„ค์ •ํ•œ๋‹ค.
/]# chfn bunny  => ์‚ฌ์šฉ์ž์˜ ์ •๋ณด๋ฅผ ์ˆ˜์ •ํ•˜๊ณ  ํŽธ์ง‘ํ•œ๋‹ค.
/chroot]# chown bunny<์†Œ์œ ์ž>.root<์†Œ์œ ๊ทธ๋ฃน> system_install_OS.sh
/chroot]# chown -R bunny.root Server_Change_Configure => -R<์žฌ๊ท€์ >
/chroot]# chmod -R 700 Server_Change_Configure/  => -R <์žฌ๊ท€์ > ํผ๋ฏธ์…˜ ์ ์šฉ ๋ณ€๊ฒฝ
/chroot]# chmod -R 1700 Server_Change_Configure  => <1-2-4> ์Šˆํผํ‚ค ํผ๋ฏธ์…˜ ์ ์šฉ
~]# chattr -R<์„œ๋ธŒ> +iA<+ ์ถ”๊ฐ€ - ์ œ๊ฑฐ> proftpd-1.2.8-1kr.i686.rpm => ํŠน์ˆ˜ ๋ชจ๋“œ๋กœ ์ ์šฉ

 

 

[root@nsโ™ฅBunnyComโ™ฅ~]# clock  => ์„œ๋ฒ„์‹œ๊ฐ„ ์กฐํšŒ
2015๋…„ 03์›” 06์ผ (๊ธˆ) ์˜คํ›„ 02์‹œ 07๋ถ„ 19์ดˆ  -0.627682 seconds
[root@nsโ™ฅBunnyComโ™ฅ~]# hwclock => ํ•˜๋“œ์›จ์–ด ์‹œ๊ฐ„ ์กฐํšŒ
2015๋…„ 03์›” 06์ผ (๊ธˆ) ์˜คํ›„ 02์‹œ 11๋ถ„ 18์ดˆ  -0.628150 seconds
[root@nsโ™ฅBunnyComโ™ฅ~]# rdate -s time.bora.net => ์„œ๋ฒ„์‹œ๊ฐ„ ๋™๊ธฐํ™”
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/rc.d/rc.local

 ###### System Time Update #####
rdate -s time.bora.net
clock --show

=> ์ด๋ ‡๊ฒŒ ํ•˜๋ฉด ์ž๋™์œผ๋กœ ๋ถ€ํŒ…์‹œ ๋งˆ๋‹ค ์‹œ์Šคํ…œ ์‹œ๊ฐ„์„ ๋งˆ์ถ”์–ด์„œ ๋ณด์—ฌ์ค€๋‹ค.

 

์‹œ๊ฐ„ ๋™๊ธฐํ™” ์„œ๋ฒ„ ์„ค์ • ํ•˜๊ธฐ
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/ntp.conf

#server 0.centos.pool.ntp.org
#server 1.centos.pool.ntp.org
#server 2.centos.pool.ntp.org
server time.kriss.re.kr => ์„œ๋ฒ„ ์ถ”๊ฐ€
server time2.kriss.re.kr => ์„œ๋ฒ„ ์ถ”๊ฐ€
server ntp1.cs.pusan.ac.kr
server ntp2.cs.pusan.ac.kr

=> ์ €์žฅํ•˜๊ณ  ๋ฐ๋ชฌ์„ ์žฌ ์‹œ์ž‘ํ•ด ์ค€๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# service ntpd restart
[root@nsโ™ฅBunnyComโ™ฅ~]# ps aux | grep ntpd
ntp       4422  0.0  1.7  44396 15792 ?        SLs  14:22   0:00 ntpd -u ntp:ntp -p /var/run/ntpd.pid -g
[root@nsโ™ฅBunnyComโ™ฅ~]# chkconfig ntpd on
[root@nsโ™ฅBunnyComโ™ฅ~]# ntpq -p
     remote           refid      st t when poll reach   delay   offset  jitter
==============================================================================
 210.98.16.100   .INIT.          16 u    -   64    0    0.000    0.000   0.000
 210.98.16.101   210.98.16.100    2 u   47   64    3    3.021  745.812   2.337
 ntp1.sjtel.net  192.168.18.10    2 u   43   64    3    5.727  -255.57   3.325
 ntp2.sjtel.net  192.168.18.10    2 u   42   64    3    5.776  -258.50   2.988
 LOCAL(0)        .LOCL.          10 l   48   64    3    0.000    0.000   0.001
 => ํ˜„์žฌ ํ˜„ํ™ฉ์„ ํŒŒ์•…ํ• ์ˆ˜ ์žˆ๋‹ค.

์‹œ์Šคํ…œ ์—…๊ทธ๋ ˆ์ด๋“œ ๋ฐ ๋ฌด๊ฒฐ์„ฑ ์œ ์ง€ <YUM>
์—ฌ๊ธฐ์„œ ๋งค์šฐ ์ค‘์š”ํ•˜๋‹ค. ์—…๋ฐ์ดํŠธ ํ• ๋•Œ ์ค‘์š”ํ•œ์ ์ด ๋„คํŠธ์›Œํฌ DNS์„ค์ •๊ณผ ํ˜ธ์ŠคํŠธ ์„ค์ •์ด ์žฌ๋Œ€๋กœ ์ด๋ฃจ์–ด์ ธ์•ผ
์—๋Ÿฌ ์—†์ด ์ง„ํ–‰์„ ํ•œ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค. ๋˜ ํ•œ๊ฐ€์ง€๊ฐ€ ์—…๋กœ๋“œ ๋ฏธ๋Ÿฌ ์‹ธ์ดํŠธ ๊ฒฝ๋กœ๊ฐ€ ์ •ํ™•ํ•˜๊ฒŒ ์„ค์ •๋˜์–ด ์žˆ์–ด์•ผ ํ•œ๋‹ค.
๋งŒ์•ฝ ์—๋Ÿฌ๊ฐ€ ๋‚œ๋‹ค๋ฉด ์ˆ˜๋™์œผ๋กœ ํŒŒ์ผ์„ ์—ด์–ด์„œ ์ˆ˜์ •ํ•ด์•ผ ํ•œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/yum.repos.d/SUL-Base.repo

 [base]
name=SULinux-$releasever - Base
mirrorlist=http://www.sulinux.net/mirrorlist/?release=$releasever&arch=$basearch&repo=os
gpgcheck=1
gpgkey=ftp://ftp.sulinux.net/SULinux/RPM-GPG-KEY-SUL2
[update]
name=SULinux-$releasever - Update
mirrorlist=http://www.sulinux.net/mirrorlist/?release=$releasever&arch=$basearch&repo=updates
gpgcheck=1
gpgkey=ftp://ftp.sulinux.net/SULinux/RPM-GPG-KEY-SUL2
[extras]
name=SULinux-$releasever - Extras
mirrorlist=http://www.sulinux.net/mirrorlist/?release=$releasever&arch=$basearch&repo=extras
gpgcheck=1
gpgkey=ftp://ftp.sulinux.net/SULinux/RPM-GPG-KEY-SUL2

[root@nsโ™ฅBunnyComโ™ฅ/etc/init.d]# ./yum-updatesd start
[root@nsโ™ฅBunnyComโ™ฅ~]# yum -y update  => ์ž๋™ ์—…๋ฐ์ดํƒ€ ์‹œ์ž‘
[root@nsโ™ฅBunnyComโ™ฅ~]# yum -y clean all  => ๋ชจ๋“  ์บ์‹œ ์‚ญ์ œ

 

 < ๋ช…๋ น ์‚ฌ์šฉ๋ฒ• >
#yum -y<์„ค์น˜์‹œ๋ฌด์กฐ๊ฑดok> install<์„ค์น˜> php<ํŒฉํ‚ค์ง€>
#yum -y remove<์ œ๊ฑฐ> bind
#yum -y update <์ž๋™ ์ตœ์‹  ์—…๊ทธ๋ ˆ์ด๋“œ>
#yum -y upgrade <์ž๋™ ์—…๊ทธ๋ ˆ์ด๋“œ ํ• ๋•Œ ์ง์ ‘ ์†Œ์Šค ๋ฐ›์œผ๋ฉด์„œ ์„ค์น˜>
#yum list php <์„ค์น˜ ๋ฆฌ์ŠคํŠธ ์ถœ๋ ฅ>
#yum info php <์„ค์น˜ ํŒฉํ‚ค์ง€ ์ •๋ณด ์ถœ๋ ฅ>
#yum search apache <ํŒฉํ‚ค์ง€ ๋””๋น„์—์„œ ์›ํ•˜๋Š” ํŒฉํ‚ค์ง€๋ฅผ ์ฐฟ์„๋•Œ>
#yum -y clean <์บ์‹œ ์ €์žฅ ๋ชฉ๋ก์„ ์ดˆ๊ธฐํ™” ์‹œํ‚จ๋‹ค.>
#yum check-update 
#yum -y grouperase  <๊ทธ๋ฃนํŒฉํ‚ค์ง€์— ์†ํ•œ ๋ชจ๋‘๋ฅผ ์ง€์šด๋‹ค.>
#yum -y groupinstall  <๊ทธ๋ฃนํŒฉํ‚ค์ง€์— ์†ํ•œ ๋ชจ๋‘๋ฅผ ์„ค์น˜ํ•œ๋‹ค.>
#yum -y groupupdate  <๊ทธ๋ฃนํŒฉํ‚ค์ง€์— ์†ํ•œ ๋ชจ๋‘๋ฅผ ์—…๊ทธ๋ ˆ์ด๋“œ ํ•œ๋‹ค.>

 

 

vmware์—์„œ ์„œ๋ฒ„๋ฅผ ์šด์˜ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋งŽ์€ ์ œ์•ฝ์ด ๋”ฐ๋ฅด๊ณ  ๋งŽ์€ ๋ถ€๋ถ„์„ ์„ค์ •ํ•ด ์ฃผ์–ด์•ผ ํ•œ๋‹ค.
๊ทธ์ค‘์— ํ•˜๋‚˜๊ฐ€ wmware network NAT๋ถ€๋ถ„ํ•˜๊ณ  ์›๋„์šฐ7์˜ ๋ฐฉํ™”๋ฒฝ ๋ถ€๋ถ„์ด๋‹ค.
์ด ๋ถ€๋ถ„์„ ์ •ํ™•ํ•˜๊ฒŒ ์ดํ•ดํ•˜์ง€ ๋ชปํ•˜๋ฉด ์ „์ฒด ์ž‘์—…์ด ํ˜ผ๋ž€์— ๋น ์ง„๋‹ค.
๊ทธ๋ฆฌ๊ณ  wmware ๋„คํŠธ์›Œํฌ์˜ ๋™์  IP๋ถ€๋ถ„๋„ ๋ณธ์ธ์ด ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋งŒํผ๋งŒ ์„ค์ •ํ•ด ๋‘๋Š”๊ฒŒ ์ข‹๋‹ค.
๊ฐ€์ƒ OS๋Š” ์ง€๊ธˆ ์„ค์ •ํ•ด์ค€ ๋‚ด์šฉ์„ ๋ฐ›๊ณ ๋‚˜์„œ ๊ณ ์ •IP์ฒ˜๋Ÿผ ์‚ฌ์šฉํ• ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ค€๋‹ค.

 

[root@nsโ™ฅBunnyComโ™ฅ~]# netconfig => ์ž๋™์œผ๋กœ ๋„คํŠธ์›Œํฌ๋ฅผ ์„ค์ •ํ•ด ์ฃผ๋Š” ์„ค์ •๋„๊ตฌ์ด๋‹ค.
๋ชฐ๋ก  ์ˆ˜๋™์œผ๋กœ ifconfig ๋ช…๋ น์–ด๋‚˜ route ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•ด์„œ ์„ค์ •ํ•˜๋Š” ๋ฐฉ๋ฒ•๋„ ์žˆ์ง€๋งŒ
์–ด๋–ป๊ฒŒ ์„ค์ •์„ ํ•˜๋˜ ํŽธํ•œ๋ฐฉ๋ฒ•์œผ๋กœ ์„ค์ •ํ•˜๋ฉด ๋œ๋‹ค.
x ์ด๋ฆ„               eth0________________ x
x ์žฅ์น˜               eth0________________ x
x Use DHCP           [ ]                  x
x Static IP          192.168.40.4________ x
x Netmask            255.255.255.0_______ x
x Default gateway IP 192.168.40.2________ x
=> ์œ„ ๋ฐฉ์‹๋Œ€๋กœ ์„ค์ •ํ•ด ์ฃผ๋Š”๊ฒŒ ๊ณ ์ • IP ๋ฐฉ์‹์ด๋‹ค.
์ €์žฅํ•ด ์ฃผ๊ณ  ๋น ์ ธ ๋‚˜์˜จ๋‹ค.
๋‹ค์Œ์— ์„ค์ •ํ•  ๋ถ€๋ถ„์€ HOSTNAME๋ฅผ ์ •ํ•ด ์ฃผ์–ด์•ผ ํ•œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/sysconfig/network

NETWORKING_IPV6=no
HOSTNAME=ns.xxxxxxxxxxxx.pe.kr => ์—ฌ๊ธฐ์„œ ์ž์‹ ์˜ ํ˜ธ์ŠคํŠธ๋„ค์ž„๋ช…์„ ์ ์–ด์ฃผ๋ฉด ๋œ๋‹ค.
NETWORKING=yes

์ด์ œ ํ˜ธ์ŠคํŠธ ํŒŒ์ผ์„ ํŽธ์ง‘ํ•œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/hosts

 <ํ˜ธ์ŠคํŠธIP>      <ํ˜ธ์ŠคํŠธ๋„๋ฉ”์ธ๋ช…>       <ํ˜ธ์ŠคํŠธ๋ช…>
192.168.40.4    ns.xxxxxxxxxxxxx.pe.kr      ns
192.168.40.4    se.xxxxxxxxxxxx.co.kr       se
192.168.40.4    bunny.xxxxxxxxxxx.pe.kr     bunny

์ด๋Ÿฐ์‹์œผ๋กœ ์ž์‹ ์ด ์›ํ•˜๋Š” ๋‚ด์šฉ์„ ์ž‘์„ฑํ•ด ์ฃผ๋ฉด ๋œ๋‹ค.
๊ฐ€์žฅ ์ค‘์š”ํ•œ ๋„ค์ž„์„œ๋ฒ„๋ฅผ ์„ค์ •ํ•ด ์ค€๋‹ค.
์™œ ์ค‘์š”ํ•˜๋ƒ ํ•˜๋ฉด yum ์—…๋ฐ์ดํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜๊ณ ์ž ํ• ๋•Œ ๋Œ€๋ถ€๋ถ„์˜ ์—๋Ÿฌ๊ฐ€ ์ด๋ถ€๋ถ„์„ ์žฌ๋Œ€๋กœ ์„ค์ •ํ•˜์ง€ ๋ชปํ•ด์„œ
๋ฐœ์ƒํ•˜๊ธฐ ๋•Œ๋ฌธ์ด๊ณ  ๋ฟ๋งŒ์•„๋‹ˆ๋ผ. ์™ธ๋ถ€์„œ๋ฒ„์— ์ ‘์†ํ• ๋•Œ๋„ ์ด๋ถ€๋ถ„์„ ์ฝ๊ณ  ๋‚œ ๋‹ค์Œ์— ์ธ์ฆ์„ ์‹œ์ผœ์ค€๋‹ค๊ณ 
๋‚˜๋Š” ์•Œ๊ฒŒ ๋˜์—ˆ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/resolv.conf 

 ### ํ•œ๊ตญ ํ†ต์‹  DNS ์„œ๋ฒ„
nameserver 168.126.63.1
nameserver 168.126.63.2
### SK ๋ธŒ๋žœ๋“œ DNS ์„œ๋ฒ„
nameserver 219.250.36.130
nameserver 210.220.163.82
### kr.dnsever ์„œ๋น„์Šค ์„œ๋ฒ„ 1์ฐจ
nameserver      162.252.53.132
### kr.dnsever ์„œ๋น„์Šค ์„œ๋ฒ„ 2์ฐจ
nameserver      162.252.53.170
### ๊ตฌ๊ธ€ ๋„ค์ž„์„œ๋ฒ„
#nameserver     8.8.8.8
### vm์›จ์–ด ๊ฐ€์ƒ IP์ฃผ์†Œ
nameserver      192.168.40.4
### vm์›จ์–ด ๊ฐ€์ƒ ๊ฒŒ์ดํŠธ์›จ์ด ์ฃผ์†Œ
nameserver      192.168.40.2
### ๊ณต์œ ๊ธฐ ํ• ๋‹น ์ž‘์—… ์ปดํ“จํ„ฐ ์‹ค์ œ IP
nameserver      192.168.0.2
search  localdomain
domain  xxxxxxxxxxxx.pe.kr

=> ์—ฌ๊ธฐ์„œ ์ค‘์š”ํ•œ๊ฒŒ ํ•œ๊ตญํ†ต์‹  DNS์„œ๋ฒ„ํ•˜๊ณ  SK๋ธŒ๋žœ๋“œ์„œ๋ฒ„์ด๋‹ค. ์ด ์–‘๋Œ€ ์„œ๋ฒ„๋งŒ ์žฌ๋Œ€๋กœ ์„ค์ •ํ•ด๋„
ํŠน๋ณ„ํ•œ ๋ฌธ์ œ๋Š” ๋ฐœ์ƒํ•˜์ง€ ์•Š๋Š”๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# service network restart
์ด๋ ‡๊ฒŒ ์žฌ ์‹œ์ž‘ํ•ด ์ค€๋‹ค.
๋‹ค์Œ์— ํ•‘ ๋ช…๋ น์œผ๋กœ ์‘๋‹ต์ด ์žฌ๋Œ€๋กœ ์ด๋ฃจ์–ด ์ง€๋Š”์ง€ ํ™•์ธํ•œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# ping -c 3 ns.xxxxxxxxxxxxx.pe.kr
PING ns.xxxxxxxxxxxx.pe.kr (192.168.40.4) 56(84) bytes of data.
64 bytes from ns.xxxxxxxxxxxx.pe.kr (192.168.40.4): icmp_seq=1 ttl=64 time=18.5 ms
64 bytes from ns.xxxxxxxxxxxx.pe.kr (192.168.40.4): icmp_seq=2 ttl=64 time=0.065 ms
=> ์ด๋ ‡๊ฒŒ ์‹œ์Šคํ…œ์ด ์‘๋‹ตํ•ด์•ผ๋งŒ ํ•œ๋‹ค. ๋งŒ์•ฝ ์—๋Ÿฌ๊ฐ€ ๋‚œ๋‹ค๋ฉด ์œ„์— ์–ด๋Š๋ถ€๋ถ„์— ๋ณธ์ธ์ด ์„ค์ •์„
์ž˜๋ชปํ–ˆ๋‹ค๋Š” ์˜๋ฏธ์ด๋‹ค. ์žฌ ๊ฒ€ํ† ํ•ด ๋ณด๊ธฐ ๋ฐ”๋ž€๋‹ค.

 

root์˜ ์ถ”๊ฐ€์ ์ธ ํ™˜๊ฒฝ ์„ค์ •์„ ํ•ด ๋‘”๋‹ค.
์†”์งํžˆ TELNET ์ฝ˜์†” ๋ชจ๋“œ ์ƒํƒœ์—์„œ ๋””ํดํŠธ๋กœ ์ž‘์—…์„ ํ•˜๋‹ค๋ณด๋ฉด ์ง€๋ฃจํ•˜๊ณ  ํ™”๋ฉด ์‹ธ์ด์ฆˆ๋„ ์ž˜ ๋งž์ง€ ์•Š์•„์„œ
์ข€ ์งœ์ฆ์ด ๋‚ ๋•Œ๊ฐ€ ์žˆ๋‹ค. ์ผ๋‹จ ํ™”๋ฉด ์นผ๋ผํ•˜๊ณ  ํ™”๋ฉด ์‹ธ์ด์ฆˆ ๋ถ€๋ถ„๋ฅผ ๋ณ€๊ฒฝํ•ด์•ผ ํ•œ๋‹ค.
์ž์ฃผ ์‚ฌ์šฉํ•˜๋Š” ๋ช…๋ น์–ด๋Š” alias๋ฅผ ์ด์šฉํ•ด์„œ ๋‹จ์ถ• ์‹œ์ผœ์„œ ์‚ฌ์šฉํ•ด๋„ ์ข‹์„ ๊ฒƒ์ด๋‹ค.
vi edit ํ™˜๊ฒฝ์— ๋Œ€ํ•œ ์„ค์ •๋„ ๋ฏธ๋ฆฌ ํ•ด ๋‘”๋‹ค.

1. root ํ™˜๊ฒฝ ์„ค์ •
[root@nsโ™ฅBunnyComโ™ฅ~]# vi .bash_profile 

 ############## ์‹œ์Šคํ…œ ์ฝ˜์†” DIR ์นผ๋ผ ์„ค์ • ##################
eval `dircolors /etc/DIR_COLORS -b`
export LS_COLORS="di=01;31":"fi=01;37":"ex=01;32":"ln=01;36":"so=01;33"
###############  ์‹œ์Šคํ…œ ํ”„๋กฌํ”„ํŠธ ํ™˜๊ฒฝ ์„ค์ •  ################
PS1="\[\033[0;44m\][\u@\hโ™ฅBunnyComโ™ฅ\w]#\[\033[0;00m\] "
#### ์‹œ๊ฐ„ ํƒ€์ž„ ์•„์›ƒ #####
TMOUT=800
PATH=$PATH:$HOME/bin  ## sulinux์˜ ์„œ๋ฒ„๊ด€๋ฆฌ์‹คํ–‰ํŒŒ์ผ์ด ์žˆ๋Š” ๊ณณ์ด๋‹ค.
#### ์ถ”๊ฐ€๋กœ ์œ ์ € ๋กœ์ปฌ์— ์žˆ๋Š” ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์˜ ์‹คํ–‰ํŒŒ์ผ์„ ์—ฐ๊ฒฐํ•ด์„œ ์‚ฌ์šฉํ•˜๊ณ ์ž ํ• ๋•Œ
##### ์„ค์ • ํ•œ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๋’ค์— ์ถ”๊ฐ€ ํ•  PATH ์žˆ์„๋•Œ : => ์ด ํ‘œ์‹œ๋กœ ๊ตฌ๋ถ„ํ•œ๋‹ค.
PATH=$PATH:$HOME/bin:/usr/local/bin:/usr/local/sbin:/chroot/shell

[root@nsโ™ฅBunnyComโ™ฅ~]# source .bash_profile
[root@nsโ™ฅBunnyComโ™ฅ~]# set | grep PATH => ์ด๊ฑธ๋กœ ๋‚ด์—ญ์„ ํ™•์ธํ• ์ˆ˜ ์žˆ๋‹ค.
PATH=/usr/kerberos/sbin:/usr/kerberos/bin:/usr/lib64/ccache:/usr/local/sbin:/usr/local/bin:/usr/local/sbin:/chroot/shell
๋‹ค๋ฅธ ์‚ฌ์šฉ์ž๊ฐ€ ํ•จ๋ถ€๋กœ ๋ฃจํŠธํŒŒ์ผ์„ ์‹คํ–‰ํ•˜๊ฑฐ๋‚˜ ๋ณ€์กฐํ•˜๋Š”๊ฑธ ๋ฐฉ์ง€ ํ•˜๊ธฐ ์œ„ํ•ด ํผ๋ฏธ์…˜๊ณผ ์†Œ์œ ๊ถŒํ•œ์„ ๊ฑธ์–ด๋‘”๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# chmod 700 /root ; chown -R root:root /root
์„ค์น˜์‹œ ์„ค์น˜ํ–ˆ๋˜ ํŒŒ์ผ์— ๋Œ€ํ•œ ์ •๋ณด๋‚˜ ๋กœ๊ทธ์ •๋ณด๋ฅผ  ์‚ญ์ œํ•œ๋‹ค.
์†”์งํžˆ ์ด๊ฑธ ์ง€์šด๋‹ค๊ณ  ํ•ด๋„ yum์œผ๋กœ ์—…๋ฐ์ดํŠธ ํ•˜๋ฉด ๋˜ ์ƒ๊ธด๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# rm -fr install.log install.log.syslog
2. SElinux ๋ณด์•ˆ ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉ์„ ์ •์ง€ํ•œ๋‹ค. ์™œ๋ƒํ•˜๋ฉด ๋Œ€ํ˜• ์„œ๋ฒ„๋ฅผ ์šด์˜ํ•œ๋‹ค๋ฉด ์ƒ๊ด€ ์—†์ง€๋งŒ
๊ตฌ์ง€ ์ด๊ฑธ ์‚ฌ์šฉํ•˜๋ฉด์„œ ๊นŒ์ง€ ์‹ ๊ฒฝ์จ์•ผ ํ•  ํ•„์š”์„ฑ์ด ์žˆ๋Š”๊ฐ€ ํ•˜๋Š” ์ƒ๊ฐ์ด ๋“ ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/selinux/config

 SELINUX= disabled <3๊ฐ€์ง€ ๋ชจ๋“œ๊ฐ€ ์žˆ๋‹ค. Enforcing + permissive + disabled >
=> ์‚ฌ์šฉ์ •์ง€๋Š” SELINUX= disabled ์ด๊ณ  ์‚ฌ์šฉํ•œ๋‹ค๋ฉด Enforcing์œผ๋กœ ๋ฐ”๊พธ๋ฉด ๋œ๋‹ค.
SELINUXTYPE=targeted

[root@nsโ™ฅBunnyComโ™ฅ~]# getsebool -a  <selinux ๋ณด์•ˆ ์ •์ฑ… ์ถœ๋ ฅ>
[root@nsโ™ฅBunnyComโ™ฅ~]# setsebool -P ftp_home_dir 0 => ๋ถˆ๊ฐ€
[root@nsโ™ฅBunnyComโ™ฅ~]# setsebool -P ftp_home_dir 1 => ํ—ˆ๊ฐ€
[root@nsโ™ฅBunnyComโ™ฅ~]# setenforce 0 <0์ด๋ฉด ์ •์ง€์ด๊ณ  1์ด๋ฉด ์‚ฌ์šฉ๊ฐ€๋™์ด๋‹ค.>
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/grub.conf
selinux=0 => ์ถ”๊ฐ€์‹œํ‚ด
[root@nsโ™ฅBunnyComโ™ฅ~]# restorecon -rv /home
[root@nsโ™ฅBunnyComโ™ฅ~]# setsebool -P httpd_can_network_connect_db on => ๊ฐ€๋™์‹œ์—๋งŒ ์ด ๋ช…๋ น์€ ํ†ตํ•œ๋‹ค.
3. Vi ์—๋””ํ„ฐ์— ๋Œ€ํ•œ ๋‚˜๋งŒ์˜ ํ™˜๊ฒฝ ์„ค์ •
[root@nsโ™ฅBunnyComโ™ฅ~]# rm -fr /bin/view
[root@nsโ™ฅBunnyComโ™ฅ~]# rm -fr /bin/vi
[root@nsโ™ฅBunnyComโ™ฅ~]# ln -s /usr/bin/vim /bin/vi

[root@nsโ™ฅBunnyComโ™ฅ~]# vi .vimrc

set ruler
syntax on
colorscheme evening
set title

====================================================================
์˜ต์…˜ ์„ค๋ช…
=====================================================================
set nocompatible " Vim ๋””ํดํŠธ ๊ธฐ๋Šฅ๋“ค์„ ์‚ฌ์šฉํ•จ
set backspace=2 " ์‚ฝ์ž… ๋ชจ๋“œ์—์„œ ๋ฐฑ์ŠคํŽ˜์ด์Šค๋ฅผ ๊ณ„์† ํ—ˆ์šฉ
set autoindent " ์ž๋™ ๋“ค์—ฌ์“ฐ๊ธฐ
set cindent " C ์–ธ์–ด ์ž๋™ ๋“ค์—ฌ์“ฐ๊ธฐ
set smartindent " ์—ญ์‹œ ์ž๋™ ๋“ค์—ฌ์“ฐ๊ธฐ
set textwidth=76 " 76๋ฒˆ์งธ ์นธ์„ ๋„˜์–ด๊ฐ€๋ฉด ์ž๋™์œผ๋กœ ์ค„ ๋ฐ”๊ฟˆ
set nowrapscan " ์ฐพ๊ธฐ์—์„œ ํŒŒ์ผ์˜ ๋งจ ๋์— ์ด๋ฅด๋ฉด ๊ณ„์†ํ•˜์—ฌ ์ฐพ์ง€ ์•Š์Œ
set nobackup " ๋ฐฑ์—…ํŒŒ์ผ์„ ๋งŒ๋“ค์ง€ ์•Š์Œ
set novisualbell " ๋น„์ฃผ์–ผ๋ฒจ ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Œ
set nojoinspaces " J ๋ช…๋ น์–ด๋กœ ์ค„์„ ๋ถ™์ผ ๋•Œ ๋งˆ์นจํ‘œ ๋’ค์— ํ•œ์นธ๋งŒ ๋”
set ruler " ์ƒํƒœํ‘œ์‹œ์ค„์— ์ปค์„œ ์œ„์น˜๋ฅผ ๋ณด์—ฌ์คŒ
set tabstop=4 " ๊ฐ„๊ฒฉ
set shiftwidth=4 " ์ž๋™ ๋“ค์—ฌ์“ฐ๊ธฐ ๊ฐ„๊ฒฉ
set keywordprg=edic " K๋ฅผ ๋ˆŒ๋ €์„ ๋•Œ ์‹คํ–‰ํ•  ๋ช…๋ น์–ด
set showcmd " (๋ถ€๋ถ„์ ์ธ) ๋ช…๋ น์–ด๋ฅผ ์ƒํƒœ๋ผ์ธ์— ๋ณด์—ฌ์คŒ
set showmatch " ๋งค์น˜๋˜๋Š” ๊ด„ํ˜ธ์˜ ๋ฐ˜๋Œ€์ชฝ์„ ๋ณด์—ฌ์คŒ
set ignorecase " ์ฐพ๊ธฐ์—์„œ ๋Œ€/์†Œ๋ฌธ์ž๋ฅผ ๊ตฌ๋ณ„ํ•˜์ง€ ์•Š์Œ
set incsearch " ์ ์ง„์ ์œผ๋กœ ์ฐพ๊ธฐ
set autowrite " :next ๋‚˜ :make ๊ฐ™์€ ๋ช…๋ น๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ์ž๋™์œผ๋กœ ์ €์žฅ
set title " ํƒ€์ดํ‹€๋ฐ”์— ํ˜„์žฌ ํŽธ์ง‘์ค‘์ธ ํŒŒ์ผ์„ ํ‘œ์‹œ 2005-04-14 09:17:46
========================================================================
4. alias๋ฅผ ์ด์šฉํ•œ ๋‹จ์ถ• ๋ช…๋ น์–ด ์„ค์ •
alias๋Š” ๊ธด ๋ช…๋ น๊ตฌ๋ฌธ์ด๋‚˜ ์ž์ฃผ ์‚ฌ์šฉํ•˜๋Š” ๋ช…๋ น์–ด๋ฅผ ๋ณ„๋ช…์„ ์ง€์–ด์„œ ๋‹จ์ถ•์‹œ์ผœ์„œ ์‚ฌ์šฉํ•˜๋Š” ๋ช…๋ น์–ด์ด๋‹ค.
์œ ์ €์ž์‹ ๋งŒ ์„ค์ •ํ• ๋•Œ๋Š” .bashrc์— ์„ค์ •ํ•˜๋ฉด ๋˜๊ณ  ๋ชจ๋“  ์œ ์ € ์ „์ฒด์— ๋Œ€ํ•œ ์„ค์ •์„ ํ•˜๊ณ ์ž ํ•  ๋•Œ๋Š”
/etc/profile์— ์„ค์ •ํ•œ๋‹ค.
ํ˜„์žฌ ์„ค์ •๋˜์–ด ์žˆ๋Š” alias ๊ฐ’์„ ๋ณผ๋•Œ๋Š” ์•„๋ž˜์ฒ˜๋Ÿผ ํ•˜๋ฉด ์ถœ๋ ฅ๋œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# alias
[root@nsโ™ฅBunnyComโ™ฅ~]# vi .bashrc

 alias lsd='ls -l | grep "^d"'     # ls ์˜ ๊ฒฐ๊ณผ์—์„œ ๋””๋ ‰ํ† ๋ฆฌ๋งŒ ์ถœ๋ ฅ
alias ll='ls -al' ; alias rm='rm -i' ; alias cp='cp -i' ; alias mv='mv -i'
alias rm='rm -i' ; alias nmap='nmap -A -sS -O -v -F' ; alias du='du -ha'

[root@nsโ™ฅBunnyComโ™ฅ~]# source .bashrc
๋งŒ์•ฝ ์—˜๋ฆฌ์–ด์Šค๋ฅผ ํ•ด์ œํ•˜๊ณ ์ž ํ• ๋•Œ๋Š” ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# unalias cp   => ํŠน์ • ์—˜๋ฆฌ์–ด์Šค๋งŒ ํ•ด์ œ.
[root@nsโ™ฅBunnyComโ™ฅ~]# unalias -a   => ์ „์ฒด ์—˜๋ฆฌ์–ด์Šค๋ฅผ ๋ชจ๋‘ ํ•ด์ œ.
5. ์ฝ˜์†” ํ•ด์ƒ๋„ ์กฐ์ ˆํ•˜๊ธฐ
- ๋ชฐ๋ก  vmware ์ž์ฒด์ ์œผ๋กœ ์ง€์›ํ•˜๋Š” ๋“œ๋ผ์ด๋ฒ„๋ฅผ ์„ค์น˜ํ•˜๋ฉด ํ•ด์ƒ๋„๋ฅผ ์กฐ์ ˆํ• ์ˆ˜ ์žˆ์ง€๋งŒ ๊ฐ€์ƒOS๊ฐ€ ์•„๋‹Œ
์‹ค์ œ ์„œ๋ฒ„์ปดํ“จํ„ฐ์—์„œ ํ•ด์ƒ๋„๋ฅผ ์ˆ˜๋™์œผ๋กœ ๋งˆ์ถ”์–ด์•ผ ํ•  ๋•Œ๊ฐ€ ์žˆ๋‹ค. ๋Œ€๋ถ€๋ถ„์˜ ์„œ๋ฒ„๋Š” GUI ๋ชจ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์ง€
์•Š๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ๊ณ  ๋ณด์•ˆ์ ์œผ๋กœ ์‹ ๊ฒฝ์„ ์จ์•ผ ๋˜๊ธฐ ๋•Œ๋ฌธ์— ๊ทธ๋งŒํผ ์†์ด ๋งŽ์ด ๊ฐ„๋‹ค.
๊ทธ๋Ÿฌ๋ฏ€๋กœ ์ฝ˜์†”์—์„œ ๋งŽ์€ ์ž‘์—…์„ ํ•˜๋Š”๊ฒŒ ์‚ฌ์‹ค์ด๋‹ค. ์ž‘์—…ํ•˜๊ธฐ ํŽธํ•œ ์กฐ๊ฑด์„ ๋งŒ๋“ค์–ด์•ผ ํ•˜๋Š” ๋ถ€๋ถ„๋„ ์žˆ๊ธฐ ๋•Œ๋ฌธ์—
ํ•ด์ƒ๋„๋ฅผ ์กฐ์ ˆํ•˜๋Š” ๋ฐฉ๋ฒ•๋„ ์•Œ์•„ ๋‘˜ ํ•„์š”์„ฑ์ด ์žˆ๋‹ค๊ณ  ๋ณธ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# vi /etc/grub.conf

 ### vga=0x343 => ์ด ์˜ต์…˜์„ ๋„ฃ์–ด์ค€๋‹ค. ์ด๊ฑด 1280*960์˜ 32๋น„ํŠธ๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค๋Š” ์˜๋ฏธ์ด๋‹ค.
### vga=ask => ํ•ด์ƒ๋„ ๋ฉ”๋‰ด์—์„œ ์„ ํƒํ•ด์„œ ์‚ฌ์šฉํ•˜๊ณ ์ž ํ• ๋•Œ ์“ฐ๋Š” ์˜ต์…˜์ด๋‹ค.
title SULinux (2.6.18-400.1.1.el5)
        root (hd0,0)
        kernel /vmlinuz-2.6.18-400.1.1.el5 ro root=LABEL=/ rhgb quiet vga=0x343
        initrd /initrd-2.6.18-400.1.1.el5.img
title SULinux (2.6.18-400.1.1.el5xen)
        root (hd0,0)
        kernel /xen.gz-2.6.18-400.1.1.el5 vga=gfx-1024x768x16
        module /vmlinuz-2.6.18-400.1.1.el5xen ro root=LABEL=/ rhgb quiet vga=ask
        module /initrd-2.6.18-400.1.1.el5xen.img

์ด๋ ‡๊ฒŒ ์ˆ˜์ •ํ•˜๊ณ  ์žฌ๋ถ€ํŒ…ํ•ด์„œ ๋ณด๋ฉด ํ™•์ธํ• ์ˆ˜ ์žˆ๋‹ค.
๊ทธ๋ฆฌ๊ณ  ๋ถ€ํŒ…ํ•ด์„œ ์ฝ˜์†”์—์„œ ์‹ธ์ด์ฆˆ๋ฅผ ํ™•์ธํ•ด์„œ ๋ณด๋ฉด ์•Œ์ˆ˜ ์žˆ์„ ๊ฒƒ์ด๋‹ค.

 

 


์ผ๋‹จ ๋ฆฌ๋ˆ…์Šค์„œ๋ฒ„๋ฅผ ์„ค์น˜ํ•˜๊ธฐ ์ „์— VMWare์˜ ๋„คํŠธ์›Œํฌ ์„ค์ • ๋ฐ NAT ์„ค์ •์„ ์™„๋ฃŒํ•ด์•ผ ํ•œ๋‹ค.
๊ทธ๋ฆฌ๊ณ  vmware์˜ ๋“œ๋ผ์ด๋ฒ„๋ฐ OS ๊ด€๋ฆฌ ์„œ๋ฒ„ ๋„๊ตฌ๋ฅผ ์„ค์น˜ํ•ด์•ผ ํ•œ๋‹ค.
์ € ์ „์šฉ ๋„๊ตฌ๋ฅผ ์„ค์น˜ํ•˜์ง€ ์•Š์œผ๋ฉด ์‚ฌ์šฉํ•˜๊ธฐ๊ฐ€ ์•„์ฃผ ์งœ์ฆ๋‚œ๋‹ค.
์ž‘์—…์ด๋‚˜ ๋ณต์‚ฌ ์ž‘์—…์„ ํ•˜๋Š” ๊ฒฝ์šฐ์— ์žฌ๋Œ€๋กœ ์ด๋ฃจ์–ด์ง€์ง€ ์•Š๋Š” ๋ถ€๋ถ„์ด ์žˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.
1. VMWare์˜ ๋„คํŠธ์›Œํฌ ์„ค์ •๋ถ€๋ถ„์€ ๋‚ด๊ฐ€ ์ž‘์„ฑํ•œ ๋‹ค์Œ ๋ฉ”๋‰ด์–ผ์„ ์ฐธ๊ณ ํ•œ๋‹ค.
http://bunnyblog.tistory.com/296
2. NAT ํฌ์›Œ๋”ฉ ์„ค์ •์€ ๋‚ด๊ฐ€ ์ž‘์„ฑํ•œ ๋‹ค์Œ ๋ฉ”๋‰ด์–ผ์„ ์ฐธ๊ณ  ํ•œ๋‹ค.
http://bunnyblog.tistory.com/353
3.๋””๋ฐ”์ด์Šค ๋“œ๋ผ์ด๋ฒ„ ๋„๊ตฌ ์„ค์น˜ํ•˜๊ธฐ
์ผ๋‹จ vm์›จ์–ด์—์„œ [๋ฉ”๋‰ด => VM => Cancel VMware Tools Installation ์ด๋ผ๋Š” ๋ฉ”๋‰ด๋ฅผ ํด๋ฆญํ•ด์„œ ํ•ด๋‹น ์šด์˜์ฒด์ œ์˜
๋“œ๋ผ์ด๋ฒ„์”จ๋””๋ฅผ ์‚ฝ์ž…ํ•ด ์ค๋‹ˆ๋‹ค.
Sulinux ์ฝ˜์†”์—์„œ ํ•ด๋‹น ์”จ๋”” ์ด๋ฏธ์ง€๋ฅผ ๋งˆ์šดํ‹ด ์‹œ์ผœ์•ผ ํ•ฉ๋‹ˆ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ/media]# mkdir isocd
[root@nsโ™ฅBunnyComโ™ฅ/media]# mount /dev/hdc -t iso9660 -r isocd/
[root@nsโ™ฅBunnyComโ™ฅ/media]# cd isocd/
[root@nsโ™ฅBunnyComโ™ฅ/media/isocd]# mkdir /root/vmtools
[root@nsโ™ฅBunnyComโ™ฅ/media/isocd]# cp -ab * /root/vmtools/
[root@nsโ™ฅBunnyComโ™ฅ/media/isocd]# cd /root/vmtools/
[root@nsโ™ฅBunnyComโ™ฅ~/vmtools]# tar xvfz VMwareTools-9.6.0-1294478.tar.gz
[root@nsโ™ฅBunnyComโ™ฅ~/vmtools]# cd vmware-tools-distrib/
[root@nsโ™ฅBunnyComโ™ฅ~/vmtools/vmware-tools-distrib]# ./vmware-install.pl => ์ธ์Šคํ†จ ์‹คํ–‰ํŒŒ์ผ
=> ์ด๋ถ€๋ถ„์€ ์ƒ๋žตํ•œ๋‹ค. ์„ค์น˜๊ฒฝ๋กœ๋‚˜ ๋ชจ๋ฅ ์‚ฝ์ž…๋ชจ๋“œ ๋ถ€๋ถ„ ๊ทธ๋ฆฌ๊ณ  ๊ทธ๋ž˜ํ”ฝ ํ•ด์ƒ๋„ ๋ถ€๋ถ„์— ๋Œ€ํ•ด์„œ
๋ฌผ์–ด๋ณด๋Š”๋ฐ ๋‚˜๋จธ์ง€๋Š” ๋””ํดํŠธ๋กœ ํ•ด ์ฃผ๋ฉด ๋˜๊ณ  ํ•ด์ƒ๋„ ๋ถ€๋ถ„์ด ๋งˆ์ง€๋ง‰๋ถ€๋ถ„์—์„œ ๋ฌผ์–ด๋ณด๊ฒŒ๋œ๋‹ค.
์—ฌ๊ธฐ์„œ ์ž์‹ ์ด ์›ํ•˜๋Š” ํ•ด์ƒ๋„ ๋ฒˆํ˜ธ๋ฅผ ์น™๊ณ  ์—”ํ„ฐ ํ•˜๋ฉด ๋ชจ๋“  ์„ช์น˜๋Š” ๋๋‚œ๋‹ค.
์ผ๋‹จ ์„ค์น˜๊ฐ€ ๋๋‚˜๋ฉด ์žฌ๋ถ€ํŒ…์„ ํ•ด์ค€๋‹ค.
๋ถ€ํŒ…ํ• ๋•Œ ์„œ๋ฒ„ ๋ฆฌ์ŠคํŠธ๋ฅผ ๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์„œ๋ฒ„๋ฐ๋ชฌ์ด ์žˆ์„ ๊ฒƒ์ด๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# ls -al /etc/init.d/vm*
-rwxr-xr-x 1 root root 39800  3์›”  5 16:52 /etc/init.d/vmware-tools
-rwxr-xr-x 1 root root 15208  3์›”  5 16:52 /etc/init.d/vmware-tools-thinprint
=> vmware-tools ์ด ํŒŒ์ผ์ด ๊ด€๋ฆฌ๋ฐ๋ชฌ์ด๋‹ค. ์ด ๋ฐ๋ชฌ์€ ๋ถ€ํŒ…์‹œ ์ž๋™์œผ๋กœ ์‹คํ–‰๋˜๊ธฐ ๋•Œ๋ฌธ์— ํŠน๋ณ„์ด
์‚ฌ์šฉ์ž๊ฐ€ ์ˆ˜๋™์œผ๋กœ ์‹œ์ž‘์„ ํ•ด ์ฃผ๋Š” ๊ฒฝ์šฐ๋Š” ์—†์„๊ฒƒ ๊ฐ™๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# service vmware-tools restart => ์ˆ˜๋™์œผ๋กœ ์žฌ ์‹œ์ž‘
๋งŒ์•ฝ vmware tools๋ฅผ ์‚ญ์ œํ•˜๊ณ ์ž ํ• ๋•Œ๋Š” ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์น˜๋ฉด ์ž๋™ ์‚ญ์ œ๋œ๋‹ค.
[root@nsโ™ฅBunnyComโ™ฅ~]# vmware-uninstall-tools.pl
[root@nsโ™ฅBunnyComโ™ฅ~]# vmware-config-tools.pl  => ์ด ๋ช…๋ น์€ ํ™˜๊ฒฝ์„ค์ •์„ ๋‹ค์‹œ ํ• ๋•Œ ์‚ฌ์šฉํ•œ๋‹ค.
์ด์ •๋„๋งŒ ์•Œ์•„๋„ vmware ๋„๊ตฌ๋ฅผ ์ œ์–ดํ•˜๋Š”๋ฐ๋Š” ๋ฌธ์ œ๊ฐ€ ์—†์„ ๊ฒƒ์ด๋‹ค.
์ง€๊ธˆ๊นŒ์ง€ ์ด์•ผ๊ธฐ ํ•œ ์ด 3๊ฐ€์ง€๊ฐ€ ๋ชจ๋‘ ์„ค์ •์ด ๋˜์–ด์•ผ๋งŒ ์„œ๋ฒ„์šด์˜๋ฅผ ํ• ์ˆ˜ ์žˆ๋‹ค.
๋‹จ์ˆœ์ด vmware ๊ฐ€์ƒ OS๋ฅผ ์„ค์น˜ํ•˜๋Š”๊ฒŒ ์ค‘์š”ํ•œ๊ฒŒ ์•„๋‹ˆ๋‹ค. ์–ผ๋งˆ๋งŒํผ ํšจ์œจ์„ฑ์„ ๊ฐ€์ง€๊ณ 
๊ทน๋Œ€ํ™” ํ•ด์„œ ์‚ฌ์šฉํ• ์ˆ˜ ์žˆ๋Š๋ƒ๊ฐ€ ์ค‘์š”ํ•œ ๊ฒƒ์ด๋‹ค.

 

vmware๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด์„œ ์ฐธ ์ƒ๊ฐํ•˜์ง€๋„ ๋ชปํ–ˆ๋˜ ๋‚œ๊ด€์— ๋ด‰์ฐฉํ–ˆ๋‹ค.
sulinux๋ฅผ ์„ค์น˜ํ•˜๋ฉด์„œ ์–ธ์–ด ์ถœ๋ ฅ ์ธ์ฝ”๋”ฉ ๋ฌธ์ œ ๋•Œ๋ฌธ์— ํ•œ์ฐธ ์ƒ๊ฐ์„ ํ–ˆ๋‹ค.
๋ชฐ๋ก  ๊ธฐ๋ณธ์œผ๋กœ ์„ค์ •๋˜์–ด ์žˆ๋Š” UTF-8๋ฅผ ์‚ฌ์šฉํ•ด๋„ ๋˜์ง€๋งŒ ๋‚ด๊ฐ€ ์‚ฌ์šฉํ•˜๋ฉด์„œ ์•„์ง๋„ ํ˜ธํ™˜์„ฑ์ด ๋˜์ง€ ์•Š๋Š”
๋ถˆํŽธํ•จ์„ ๋Š๋ผ๊ฒŒ ๋˜์—ˆ๋‹ค. ssh๋กœ ์ ‘์†ํ•ด์„œ ๋ณด๋ฉด ํ™”๋ฉด์ด ๊นจ์ง€๊ณ  ๋ถ„๋ช…ํžˆ vi์—์„œ ์ž‘์„ฑ์„ ํ–ˆ๋Š”๋ฐ
๋‹ค๋ฅธ ๋ฆฌ๋ˆ…์Šค ์„œ๋ฒ„์—์„œ ๋ถˆ๋Ÿฌ์™€์„œ ๋ณด๋ฉด ์ „๋ถ€ ๊นจ์ ธ์„œ ๋ณด์ธ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค.
๋ฐฉ๋ฒ•์€ ๊ธฐ์กด์— ์‚ฌ์šฉํ•˜๋˜ eucKR์ธ์ฝ”๋”ฉ์ด๋‚˜ KO_Kr๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•๋ฐ–์— ์—†์—ˆ๋‹ค.
๊ฐ€์žฅ ํฐ ๊ฑธ๋ฆผ๋Œ์ด mc๋ผ๋Š” ํ”„๋กœ๊ทธ๋žจ์„ ์‚ฌ์šฉํ• ๋•Œ๊ฐ€ ํฐ ๋ฌธ์ œ ์˜€๋‹ค. sulinux์—์„œ ์ œ๊ณตํ•˜๋Š” ๋ชจ๋“  ํŒฉํ‚ค์ง€๋Š”
utf8๊ธฐ๋ฐ˜์œผ๋กœ ์ž‘์„ฑํ•œ๊ฑฐ ๊ฐ™๋‹ค. -_-;;

1. UTF-8 ์„ค์ •
yum -y install kde-i18n-Korean
yum -y install fonts-korean
fc-cache => ์–ธ์–ด์บ์‹œ๋ฐ ๋“ฑ๋ก ๋กœ๋“œ
vi /etc/sysconfig/i18n

 

ANG="ko_KR.UTF-8"
##LANG="ko_KR.UTF-8"
SUPPORTED="en_US.iso885915:en_US:en:ko_KR.eucKR:ko_KR:ko:UTF-8"
SYSFONT="latarcyrheb-sun16"
SYSFONTACM="latarcyrheb-sun16"

 

source /etc/sysconfig/i18n
export LANG="ko_KR.UTF-8"
export LC_ALL="ko_KR.UTF-8"
locale

2. eucKR ์„ค์ • <์ฃผ๋กœ ๋‚ด๊ฐ€ ๋งŽ์ด ์‚ฌ์šฉ>
# set | grep LANG => ์„ค์ •๋‚ด์—ญ ํ™•์ธ
LANG=ko_KR.UTF-8
# unset LANG => ํ˜„์žฌ ์–ธ์–ด์„ค์ •์„ ํ•ด์žฌํ•œ๋‹ค.
# LANG=C => ๋””ํดํŠธ ์–ธ์–ด ์ž๋™ ์„ค์ •
# locale -a | grep ko => ์‚ฌ์šฉ๊ฐ€๋Šฅํ•œ ํ•œ๊ตญ์–ด ๋‚ด์—ญ ํ™•์ธ
vi /etc/sysconfig/i18n

 

ANG="ko_KR.eucKR"
SUPPORTED="en_US.iso885915:en_US:en:ko_KR.eucKR:ko_KR:ko:UTF-8"
SYSFONT="lat0-sun16"
SYSFONTACM="iso15"

 

source /etc/sysconfig/i18n
export LANG="ko_KR.eucKR"
export LC_ALL="ko_KR.eucKR"
locale | grep LANG

3. .bash_profile ํ•˜๊ณ  rc.local์— ์ž๋™์‹คํ–‰ ๋“ฑ๋กํ•˜๊ธฐ

##### ์›”๋ž˜ ๋””ํดํŠธ ํ•œ๊ธ€์–ธ์–ด #######
#export LANG="ko_KR.UTF-8"
#export export LC_ALL="ko_KR.UTF-8"
##### ์ „์šฉ ์‹œ์Šคํ…œ ์–ธ์–ด๋กœ ์‚ฌ์šฉ์„ค์ • #######
export LANG="ko_KR.eucKR"
export LC_ALL="ko_KR.eucKR"

 

[root@nsโ™ฅBunnyโ™ฅ/home/bunny/www]# yum -y install mod_ssl

[root@nsโ™ฅBunnyโ™ฅ/etc/httpd/conf.d]# vi ssl.conf

LoadModule ssl_module modules/mod_ssl.so

Listen 443

<VirtualHost _default_:443>

DocumentRoot "/var/www/html"

ServerName www.xxxxxxxxxxxx.pe.kr:443

ErrorLog logs/ssl_error_log

TransferLog logs/ssl_access_log

SSLCertificateFile /etc/pki/tls/certs/localhost.crt

SSLCertificateKeyFile /etc/pki/tls/private/localhost.key

[root@nsโ™ฅBunnyโ™ฅ/etc/httpd/conf.d]# service httpd restart

[root@nsโ™ฅBunnyโ™ฅ/home/webroot]# nmap -sS -O -v -F localhost | grep 443
Discovered open port 443/tcp on 127.0.0.1
443/tcp  open  https  ==> ํฌํŠธ ํ™•์ธ

[root@nsโ™ฅBunnyโ™ฅ/home/webroot]# httpd -S
VirtualHost configuration:
wildcard NameVirtualHosts and _default_ servers:
_default_:443          www.xxxxxxxxx.pe.kr (/etc/httpd/conf.d/ssl.conf:74) ==> ํ™•์ธ

https://xxxxxxxxxx.pe.kr/  ==> ํ์ด์ง€ ๋ณด์•ˆ ์ธ์ฆ์„œ ์ถœ๋ ฅ ํ™•์ธ

 

 

[root@nsโ™ฅBunnyโ™ฅ~]# vi /etc/httpd/conf/httpd.conf

LoadModule userdir_module modules/mod_userdir.so

<IfModule mod_userdir.c>

UserDir www  ==> ๊ณ„์ •์˜ web๋ฃจํŠธ ์„ค์ • <๋ณดํ†ต์€ public_html>

<Directory /home/*/www>

    AllowOverride All

    Options MultiViews Indexes SymLinksIfOwnerMatch IncludesNoExec ExecCGI

    <Limit GET POST OPTIONS>

        Order allow,deny

        Allow from all

    </Limit>

    <LimitExcept GET POST OPTIONS>

        Order deny,allow

        Deny from all

    </LimitExcept>

</Directory>

DirectoryIndex index.html index.html.var index.htm INDEX.HTML index.cgi

[root@nsโ™ฅBunnyโ™ฅ~]# service httpd restart

[root@nsโ™ฅBunnyโ™ฅ~]# su - bunny

[bunny@ns ~]$ mkdir www

[bunny@ns ~]$ chmod 711 /home/bunny

[bunny@ns ~]$ chmod 755 /home/bunny/www

[bunny@ns ~]$ cd www

[bunny@ns www]$ vi index.cgi

#!/usr/local/bin/perl

print "Content-type: text/html\n\n";

print "<html>\n<body>\n";

print "<div style=\"width: 100%; font-size: 40px; font-weight: bold; text-align: center;\">\n";

print "User Test Page ( /home/bunny/www )";

print "\n</div>\n";

print "</body>\n</html>\n";

[bunny@ns www]$ chmod 705 index.cgi

๋งŒ์•ฝ ์™ธ๋ถ€์—์„œ ํ์ด์ง€๊ฐ€ ์—ด๋ฆฌ์ง€ ์•Š์„๊ฒฝ์šฐ Selinux์˜ ๋ณด์•ˆ ์„ค์ •์„ 0์œผ๋กœ ํ•ด์žฌ ํ•œ๋‹ค.

[root@nsโ™ฅBunnyโ™ฅ/etc/httpd/conf]# setenforce 0

๊ทธ ๋‹ค์Œ์— ๊ณ„์ • ํ™ˆ ํ์ด์ง€๋กœ ์ ‘์†ํ•ด์„œ ํ™•์ธํ•ด ๋ณธ๋‹ค. ํ์ด์ง€๊ฐ€ ์—ด๋ฆฌ๋Š”์ง€!

http://xxxxxxxxxxx.pe.kr/~bunny 

 

 

+ Recent posts