Bugun tashar jiragen ruwa (cikin Turanci tashar tashar jirgin ruwa) Tabbas aiki ne da yakamata dukkanmu masu kula da sabobin su sani sosai, anan nayi bayani dalla-dalla menene wannan kuma yadda za'a aiwatar da saita shi š
A yanzu haka wadanda muke sarrafa sabar suna da damar SSH zuwa wannan sabar, wasu mun canza tsoho tashar jiragen ruwa na SSH kuma baya amfani da tashar jiragen ruwa 22 wasu kuma kawai suna barin shi kamar haka (wani abu da ba a ba da shawara ba), duk da haka sabar ta ba da damar samun damar SSH ta wasu tashar jiragen ruwa kuma wannan ya riga ya zama 'yanayin rauni'.
con Knocking tashar jirgin ruwa zamu iya cimma wadannan:
1. Ba a kunna damar SSH ta kowace tashar jiragen ruwa. Idan muna da SSH da aka saita don tashar 9191 (misali) wannan tashar (9191) za'a rufe ta ga kowa.
2. Idan wani yana son samun damar sabar ta hanyar SSH, a bayyane yake, ba za su iya ba, tunda tashar tashar 9191 a rufe take ... amma, idan muka yi amfani da 'sihiri' ko haÉakar Éoye, za a buÉe wannan tashar, misali:
1. Na buga zuwa tashar jiragen ruwa 7000 na saba
2. Na sake yin wata waya don shigar da 8000 na sabar
3. Na sake yin wata waya don tashar 9000 na sabar
4. Sabar tana gano cewa wani yayi hadadden sirrin (tabo tashar jiragen ruwa 7000, 8000 da 9000 a wannan tsari) kuma zai bude tashar 9191 don SSH ya nemi shiga (zai bude shi ne kawai don IP din da akayi hada shi lambar tashar mai gamsarwa).
5. Yanzu don rufe SSH kawai nakan buga tashar 3500
6. Zan sake yin wata waya don tashar jirgin ruwa ta 4500
7. Kuma a Ęarshe wani waya zuwa tashar 5500
8. Yin wannan wani haÉin haÉin sirri wanda uwar garken ya gano zai sake rufe tashar 9191 kuma.
A wasu kalmomin, bayyana wannan har ma da sauĘin ...
con Knocking tashar jirgin ruwa uwar garkenmu na iya samun takamaiman mashigai, amma idan sabar ta gano hakan daga X IP an yi haÉin tashar tashar jiragen ruwa daidai (sanyi da aka riga aka bayyana a cikin fayil Éin sanyi) zai aiwatar da wasu umarni akan kanta a bayyane (umurnin Har ila yau an bayyana a cikin fayil Éin daidaitawa).
Shin ba a fahimta ba? š
Yadda ake girka daemon don Port Knocking?
Ina yin shi tare da kunshin kokd, wanda zai bamu damar ta hanya mai sauki, mai sauqi da sauri don aiwatarwa da daidaitawa Knocking tashar jirgin ruwa.
Sanya kunshin: knockd
Yadda ake tsara Knocking Port da knockd?
Da zarar an girka sai mu ci gaba don daidaita shi, saboda wannan za mu gyara (azaman tushen) fayil Éin /etc/knockd.conf:
nano /etc/knockd.conf
Kamar yadda kake gani a cikin wannan fayil Éin tuni akwai tsoho sanyi:
Bayyana saitunan tsoho abu ne mai sauki.
- Na farko, UseSyslog yana nufin cewa don yin rikodin aiki (log) za mu yi amfani da shi / var / log / syslog.
- Na biyu, a cikin sashe [bude SSH] A nan ne bayyanannun umarnin buÉe SSH za su tafi, da farko muna da jerin tashoshin jiragen ruwa (haÉakar sirrin) waÉanda aka saita ta tsohuwa (tashar jiragen ruwa 7000, tashar jiragen ruwa 8000 kuma a Ęarshe tashar 9000). Babu shakka za'a iya canza tashoshin jiragen ruwa (a gaskiya ina ba da shawarar hakan) haka kuma ba lallai ne su zama 3 ba, suna iya zama Ęasa ko Ęasa da hakan, ya dogara da ku.
- Na uku, seq_timeout = 5 yana nufin lokacin jira don asirin haÉin tashar jirgin ruwa da zai faru. Ta hanyar tsoho an saita shi daĘiĘa 5, wannan yana nufin cewa da zarar mun fara aiwatar da ĘwanĘwasa tashar jiragen ruwa (ma'ana, lokacin da muka buga zuwa tashar 7000) muna da matsakaicin 5 seconds don gama daidai jerin, idan sakan 5 ya wuce kuma mu basu gama buga tashar jirgin ruwa ba to kawai zai zama kamar dai jerin ba su da inganci.
- Bedroom, umurnin ba ya buĘatar bayani mai yawa. Wannan zai zama kawai umarnin da sabar zata aiwatar lokacin da ta gano haÉin da aka bayyana a sama. Umurnin da aka saita ta tsohuwa, abin da yake yi shi ne bude tashar jiragen ruwa 22 (canza wannan tashar don tashar SSH Éin ku) kawai ga IP Éin da ya yi madaidaicin haÉin tashar jiragen ruwa.
- Na Biyar, tcpflags = syn Ta wannan layin ne muke tantance nau'in fakiti wanda sabar zata gane tana da inganci ga tashar buga lamba.
Sannan akwai sashin da zai rufe SSH, cewa tsoffin daidaito ba komai bane face jerin jerin tashoshin jiragen sama da ke sama amma a akasin hakan.
Anan akwai daidaitawa tare da wasu gyare-gyare:
Yadda ake farawa daemon knockd?
Don fara shi dole ne mu fara gyara (azaman tushen) fayil Éin / sauransu / tsoho / bugawa:
nano /etc/default/knockd
A can za mu canza layin lamba 12 wanda ke cewa: Ā«START_KNOCKD = 0Ā»Kuma canza 0 zuwa 1, zamu sami:Ā«START_KNOCKD = 1Ā«
Da zarar an gama wannan yanzu kawai zamu fara shi:
service knockd start
Kuma voila, an saita shi kuma yana aiki.
Knocking Port da buga ĘwanĘwasa da gudu!
Kamar yadda kake gani a tsarin daidaitawar da ta gabata, idan aka yi ĘwanĘwasa tashar jiragen ruwa zuwa tashar 1000, sannan zuwa 2000 kuma a Ęarshe zuwa 3000 sai tashar 2222 (my SSH) za ta buÉe, da kyau a nan kuma wata kwamfutar da ke aiwatar da ĘwanĘwasa tashar:
Da zarar na danna [Shigar] akan Knock No.1, akan No.2 kuma a Ęarshe akan No.3 tashar zata buÉe, ga log Éin:
Kamar yadda kake gani, yayin buga tashar 1000, mataki na 1 an yi rijista, sannan 2000 zata kasance mataki na 2 kuma a karshe 3 tare da 3000, lokacin yin wannan umarnin da na ayyana a cikin .conf ana aiwatar dashi kuma hakane.
Sannan rufe tashar jirgin kawai zai iya buga 9000, 8000 kuma a karshe 7000, ga log Éin:
Kuma da kyau anan bayanin amfani ya Ęare š
Kamar yadda kake gani, Knocking na Port yana da ban sha'awa da amfani, saboda duk da cewa bawai kawai muke so mu bude tashar jirgin ruwa ba bayan wani hadadden tashoshin jiragen ruwa, umarni ko umarnin da sabar zai aiwatar zai iya bambanta, ma'ana ... maimakon bude tashar jirgin ruwa zamu iya shelanta kashe wani tsari, dakatar da aiki kamar apache ko MySQL, da sauransu ... iyaka shine tunanin ku.
Da kyau kuma ya zuwa yanzu labarinā¦ Ni ba masani bane a cikin wannan lamarin amma ina so in sanar da ku wannan aikin mai ban sha'awa.
Gaisuwa š
Kyakkyawan labari, abin birgewa ne kuma ban san akwai shi ba ... zai yi kyau idan kuka ci gaba da fitar da labarai don sabbin abubuwan sysadmin kuma hakan š
Gaisuwa da godiya ^ _ ^
Na gode da sharhi.
Ee ... shine kenan tare da abubuwanda suke kan DNS na Fico, bana son a bar ni a baya LOL !!!
Ba abu mai tsanani ba ne. Watanni da yawa da suka gabata naji wani abu game da Port Knocking kuma nan da nan ya dauke hankalina, amma tunda nayi tunanin zai kasance mai sarkakiya a lokacin ban yanke shawarar shiga ba, jiya kawai nayi bitar wasu kunshin daga repo na gano kwankwasa da yanke shawarar gwadawa, kuma ga koyawa.
A koyaushe ina son sanya labaran fasaha, wasu na iya zama ba su da ban sha'awa ammaā¦ Ina fata wasu suna š
gaisuwa
Barka dai, Na san cewa wannan labarin ya kasance na dan wani lokaci amma ina Ęaddamar da buĘata don ganin ko wani zai iya warware min.
Gaskiyar ita ce na aiwatar da buga tashar jirgin ruwa zuwa ga rasberi don ĘoĘarin inganta tsaro lokacin da na haÉa ta da ita daga wajen hanyar sadarwar gida. Don wannan don aiki dole ne in buÉe kewayon tashar jiragen ruwa akan 7000-9990 na'ura mai ba da hanya tsakanin hanyoyin sadarwa da ke jagorantar na'ura. Shin yana da lafiya buÉe waÉannan tashoshin jiragen ruwa a kan na'ura mai ba da hanya tsakanin hanyoyin sadarwa ko, akasin haka, yayin ĘoĘarin samun Ęarin tsaro, ina yin akasin haka?
Gaisuwa da godiya.
Mai girma, Na kasance sysadmin shekaru kuma ban san shi ba.
Tambaya Éaya ... yaya kuke yin "ĘwanĘwasawa"?
Kuna bugawa kan waÉancan tashar jiragen ruwa? Me telnet yake amsa muku? Ko akwai wasu umarnin "bugawa"?
Kyakkyawan sanyi shine labarin. Mai ban mamaki. Na gode sosai
Na yi gwajin tare da telnet kuma komai yayi aiki na al'ajabi ... amma, abin al'ajabi, akwai umarnin 'bugawa', yi a mutum buga don haka zaka iya gani š
Telenet baya amsa min da gaske kwata-kwata, kayan magana tare da manufofin DROP sun sa baya amsawa kwata-kwata kuma telnet din yana nan yana jiran wasu martani (wanda ba zai taba zuwa ba), amma dan wasan da ake bugawa zai gane bugun koda kuwa babu wanda ya amsa shi š
Na gode kwarai da bayaninka, abin farin ciki ne sanin cewa har yanzu rubutuna suna son ^ _ ^
Ara zuwa WaÉanda Aka fi so! : D!
Gracias!
Godiya š
Ahh tsaro, wannan jin daÉin lokacin da muka amintar da pc don yin ruwa, sannan kwanaki / makonni daga baya muna ĘoĘari haÉi daga wani wuri mai nisa ba za mu iya samun damar ba saboda Firewall yana cikin yanayin "ba wanda zai iya kowa", ana kiran wannan zama a waje da castle dangane da sysadmins. š
Wannan shine dalilin da ya sa wannan post Éin yana da amfani, tare da buga ĘwanĘwasa zaka iya samun dama daga ko ina wanda zai iya aika fakiti zuwa ga hanyar sadarwarka ta gida, kuma maharan sun rasa sha'awa idan suka ga cewa tashar tashar ssh a rufe take, bana tsammanin zasu buga Ęarfi don buÉe tashar jiragen ruwa.
Kai, labarin yana da kyau.
Abu daya: Shin yana aiki don haÉi daga wajen cibiyar sadarwar gida?
Na faÉi haka ne saboda ina da na'ura mai ba da hanya tsakanin hanyoyin sadarwa tare da mashigai waÉanda aka rufe ba tare da wanda ya dace da ssh wanda aka miĘa shi zuwa sabar ba.
Ina tsammanin cewa don yin aiki daga wajen cibiyar sadarwar gida, zai zama dole a buÉe mashigai na na'ura mai ba da hanya tsakanin hanyoyin sadarwa daidai da Port Knocking kuma a tura su zuwa sabar ita ma.
Mmm ...
Ban san yadda lafiya za ayi wannan ba.
Me kuke tunani?
Ba ni da tabbaci sosai, ban yi gwajin ba amma ina tsammanin eh, ya kamata ku buÉe tashoshi a kan na'ura mai ba da hanya tsakanin hanyoyin sadarwa in ba haka ba ba za ku iya buga uwar garken ba.
Yi gwajin ba tare da buÉe tashoshi a kan na'ura mai ba da hanya tsakanin hanyoyin sadarwa ba, idan ba ya aiki a gare ku abin kunya ne, saboda na yarda da ku, ba kyau a buÉe waÉannan tashar jiragen ruwa a kan na'ura mai ba da hanya tsakanin hanyoyin sadarwa.
Tabbas, dole ne mu buÉe tashoshin jiragen ruwa mu tura su zuwa kwamfutar da muke kira.
Tausayi.
Babban godiya sosai! Yanzu haka na fara karatun aikin yanar gizo kuma waÉannan koyarwar suna da kyau a gare ni! godiya don Éaukar lokaci don raba ilimin
Na koyi abubuwa da yawa a cikin shekaru tare da Ęungiyar Linux ta duniya ... na foran shekaru na so in ba da gudummawa ma, wannan shine ainihin dalilin da yasa na rubuta š
Na gode sosai, ba ku san yadda yake taimaka min ba, na kusan kafa sabar kuma wannan yana da kyau a gare ni.
gaisuwa
Abinda muke kenan, don taimakawa š
Labari mai kyau! Ba ni da masaniya game da wannan kuma yana taimaka min sosai (Ina amfani da RackSpace da ke amfani da KVM, don haka ya dace da ni kamar safar hannu!). Ara wa fi so.
Godiya ga yin tsokaci š
Kamar yadda aka saba DesdeLinux nos trae excelentes post con tutoriales que son realmente utiles para poner en acciĆ³n, gracias por compartir!! š
Na gode da bayaninka š
Haka ne, koyaushe muna ĘoĘari mu gamsar da Ęishirwar ilimin da masu karatun mu ke da shi š
Abin sha'awa, Ban san zaÉi ba.
Tsallake kai tsaye don kitso laburaren sara na.
Gracias!
Jin daÉi a gare ni š
gaisuwa
Gaisuwa KZKG ^ Gaara !!! Kin matse. Babban labarin don kiyaye sabobin. Babu @% * & ^ ra'ayin cewa akwai irin wannan abu. Zan gwada shi. na gode
wannan yana da kyauā¦. ^ - ^
Barka dai, zaku iya bayanin yadda ake girka shi a cikin CentOS 5.x?
Na sauke rpm:
http://pkgs.repoforge.org/knock/knock-0.5-3.el5.rf.x86_64.rpm
An girka:
rpm -i knock-0.5-3.el5.rf.x86_64.rpm
Sanya fayil Éin sanyi tare da daĘiĘa 15 na lokaci da tashar jiragen ruwa da nake amfani da su don haÉawa ta ssh zuwa vps dina
Aljanin ya fara:
/ usr / sbin / bugawa & &
Na buga da komai kuma tashar bata rufewa, ta hanyar bude tashar tana bude, amma baya rufewa.
Shin ina yin wani abu ba daidai ba?
Mmmm, buĘatun telnet zuwa waÉannan tashar jiragen ruwa za a iya koya daga manajan cibiyar sadarwarmu ta gida, ko kuma daga mai ba da sabis Éinmu, a'a? Zai iya toshe mutane daga waje amma ba su ba, don haka idan suna son kunna tasharmu za su iya yi saboda ganin buĘatun da muke yi, mmm bari mu ce ya kare amma ba 100%
Zai iya zama, amma banyi tsammanin zasuyi tunanin cewa wasu layukan waya suna aiwatar da aikin X ba. Sai dai idan sun ga cewa ana bin hanyoyin telnet iri Éaya.
Labari mai ban sha'awa, Ina da tambaya. Ina tsammanin akwai kuskure a cikin hoton fayil Éin sanyi, saboda idan ka bincika da kyau, a duka layukan umarnin kuna amfani da ACCEPT a cikin Iptables. Ina ganin daya yakamata ya Yarda wani kuma ya zama RASHI.
In ba haka ba, kyakkyawan shiri. Na gode sosai da kuka ba da lokaci don bayyana iliminku ga wasu.
gaisuwa