RSS2.0 SiteMap °õºþ
Á°¤Ø   Ìá¤ë   ¼¡¤Ø

Æü¾ï²½¤¹¤ë¥¢¥¿¥Ã¥¯

¡üimapd¤Ø¤Î¥¢¥¿¥Ã¥¯

2·î11Æü¤Îͼ¹ïº¢¡¢imapd¤òÁÀ¤Ã¤¿¥¢¥¿¥Ã¥¯¤¬´Ñ¬¤µ¤ì¤¿¤È¤¤¤¦¥á¡¼¥ë¤¬linux-security-jp¥á¡¼¥ê¥ó¥°¥ê¥¹¥È¤Ëή¤ì¤Þ¤·¤¿¡£Êó¹ð¤µ¤ì¤¿Êý¤Ï¡¢ÂнèºÑ¤ß¤Î¥Ð¡¼¥¸¥ç¥ó¤Îimapd¤ò»È¤Ã¤Æ¤ª¤é¤ì¤¿¤Î¤Ç¡¢¤ï¤¶¤È¥¢¥¯¥»¥¹¤òǧ¤á¤ëÀßÄê¤Ë¤·¤Æ¤ß¤¿¤½¤¦¤Ç¤¹¡£ ¤¹¤ë¤È¡¢¿ô»þ´Ö¸å¤ËºÆÅÙ¥¢¥¿¥Ã¥¯¤¬¤¢¤ê¡¢º£Å٤ϼºݤËimapd¥µ¡¼¥Ð¤Ë¥í¥°¥¤¥ó¤ò»î¤ß¤¿µ­Ï¿¤¬¥í¥°¤Ë»Ä¤µ¤ì¤Þ¤·¤¿¡£

¡ÚÃí¡Û¥Û¥¹¥È̾¡¢Áê¼ê¦¤ÎIP¥¢¥É¥ì¥¹¤Ï½ñ¤­´¹¤¨¤Æ¤¢¤ê¤Þ¤¹

Feb 11 21:23:38 hostname imapd[32508]: Login failure user=^P^P^P^P^P^(ά)P^^
P^P^P^P host=[12.34.56.78]
Feb 11 21:23:39 hostname imapd[32508]: Missing command before authentication
host=[12.34.56.78]
Feb 11 21:23:41 hostname imapd[32508]: Connection reset by peer, while
reading line user=^P^P^P^P^P^(ά)^P^P^P^P^P host=[12.34.56.78]

¥æ¡¼¥¶Ì¾¤È¤·¤Æ¤­¤ï¤á¤ÆÄ¹¤¤Ê¸»úÎó¤òÁ÷¤ê¹þ¤ß¡¢¥µ¡¼¥Ð¦¤Î¥Ð¥Ã¥Õ¥¡¥ª¡¼¥Ð¥Õ¥í¡¼¤òÁÀ¤Ã¤¿¥¢¥¿¥Ã¥¯¤À¤È¤¤¤¦¤³¤È¤¬ÆÉ¤ß¼è¤ì¤Þ¤¹¡£¤½¤·¤Æ¡¢¥¢¥¿¥Ã¥«¡¼¤Ïid¥³¥Þ¥ó¥É¤ÇÀ®¸ù¤·¤¿¤«¤É¤¦¤«³Îǧ¤·¤è¤¦¤È¤·¤¿¤½¤¦¤Ç¤¹¡£¤³¤ÎÊó¹ð¤ËÂФ·¤Æ¡¢¿ô¿Í¤ÎÊý¤«¤é¡Ö¤¦¤Á¤Ë¤âÍ褿¤è¡×¤È¤¤¤¦¥Õ¥©¥í¡¼¤¬¤¢¤ê¤Þ¤·¤¿¡£

¤µ¤é¤Ë¡¢¥¢¥¿¥Ã¥«¡¼Â¦¤Î¥Û¥¹¥È¤Ë´Ø¤¹¤ë¾ðÊó¤â¤¤¤¯¤Ä¤«½¸¤Þ¤ê¤Þ¤·¤¿¡£¤³¤Î¥¢¥¿¥Ã¥¯¤ÎÆÃħ¤Ï¡¢

* ¥É¥á¥¤¥ó̾¤«¤é¥á¥­¥·¥³¤ÎÂç³ØÆâ¤Î¥Û¥¹¥È¤ÈÁÛÁü¤Ç¤­¡¢telnet¤Ø¤Î¥¢¥¯¥»¥¹À©¸Â¤Ï¹Ô¤Ã¤Æ¤¤¤Ê¤¤¤è¤¦¤À¡£¥×¥í¥ó¥×¥È¤«¤éLinux¥Þ¥·¥ó¤ÈȽÌÀ¡£ * 3²ó¥¢¥¿¥Ã¥¯¤ò¼õ¤±¤¿Êý¤Î¥í¥°¤Ë¤è¤ë¤È¡¢¥¢¥¿¥Ã¥¯´Ö³Ö¤ÏÌó2»þ´ÖȾ¡£¥¹¥¯¥ê¥×¥È¤ò»È¤Ã¤¿¼«Æ°±¿Å¾¤Ë¤Ê¤Ã¤Æ¤¤¤ë²ÄǽÀ­¤â¹Í¤¨¤é¤ì¤ë¡£ * ¾¤Î¾õ¶·¤â¹Íθ¤¹¤ë¤È¡¢¥¢¥¿¥Ã¥«¡¼¤Ï¼ÂºÝ¤Ë¤ÏÊ̤ΤȤ³¤í¤Ë¤¤¤Æ¡¢¤³¤Î¥Û¥¹¥È¤òƧ¤ßÂæ¤Ë¤·¤Æ¤¤¤ë²ÄǽÀ­¤â¹Í¤¨¤é¤ì¤½¤¦¡£

¤Ê¤É¤È¤Ê¤ê¤½¤¦¤Ç¤¹¡£whois¤ÇÄ´¤Ù¤¿´ÉÍý¼Ô¤Ë³Îǧ¥á¡¼¥ë¤òÁ÷¤Ã¤¿¤½¤¦¤Ç¤¹¤¬¡¢¤½¤Î·ëËö¤Ï¤Þ¤À¤ï¤«¤Ã¤Æ¤¤¤Þ¤»¤ó¡£

¡üphf¤Î°­ÍÑ

imapd¤Ø¤Î¥¢¥¿¥Ã¥¯¤Î¿ôÆü¸å¡¢»ä¤Î²ñ¼Ò¤Ç´ÉÍý¤ò¼õÂ÷¤·¤Æ¤¤¤ë¥µ¡¼¥Ð¤ËÂФ·¤Æ¡¢phf¥¹¥¯¥ê¥×¥È¤ò°­ÍѤ·¤¿¥¢¥¿¥Ã¥¯¤¬¤¢¤ê¤Þ¤·¤¿¡£¤½¤Î¤È¤­¤Î¥í¥°¤ò¼¨¤·¤Þ¤¹¡£

dialup107-5-8.foo.com - - [14/Feb/1998:03:33:12 +0900] "GET /cgi-bin/phf?
Qalias=x%0a/bin/cat%20/etc/passwd HTTP/1.1" 404 -

phf ¤Î°­ÍѤˤĤ¤¤Æ¤Ï¡¢°ÊÁ°¤Ë¤â½ñ¤­¤Þ¤·¤¿¡£Êó¹ð¤µ¤ì¤Æ¤«¤é»þ´Ö¤¬·Ð²á¤·¤Æ¤¤¤ë¤Ë¤â¤«¤«¤ï¤é¤º¡¢ÁêÊѤï¤é¤º·«¤êÊÖ¤µ¤ì¤Æ¤¤¤ë¤è¤¦¤Ç¤¹¡£ºÇ¶á¤Î³Æ¼ï¥Ð¥¤¥Ê¥ê¥Ñ¥Ã¥±¡¼¥¸¤Ë¤Ïphf¥¹¥¯¥ê¥×¥È¤ÏÆþ¤Ã¤Æ¤¤¤Ê¤¤¤è¤¦¤Ç¤¹¤¬¡¢1¡¢2ǯÁ°¤ËWWW¥µ¡¼¥Ð¤òΩ¤Á¾å¤²¤¿Êý¤Ï¡¢/cgi-bin/¤ËÁêÅö¤¹¤ë¥Ç¥£¥ì¥¯¥È¥ê¤ò³Îǧ¤·¤Þ¤·¤ç¤¦¡£

¤³¤Î¥¢¥¿¥Ã¥¯¤¬¤Ê¤«¤Ê¤«¸º¤é¤Ê¤¤Íýͳ¤Ï¡¢ÆÃÊÌ¤Ê¥×¥í¥°¥é¥à¤òÍѰդ·¤Ê¤¯¤Æ¤â¥¢¥¿¥Ã¥¯¤Ç¤­¤ë¤³¤È¡¢¥Ñ¥¹¥ï¡¼¥É¥Õ¥¡¥¤¥ë¤ò¥·¥ã¥É¥¦²½¤·¤Æ¤¤¤Ê¤¤¥µ¥¤¥È¤À¤È¡¢¤¿¤À¤Á¤Ë¡ÖÌòΩ¤Ä¡×¾ðÊ󤬯þ¼ê¤Ç¤­¤ë¤³¤È¡¢¤Ê¤É¤Ê¤Î¤Ç¤·¤ç¤¦¡£

¡ütelnetd¤Ø¤Î¥¢¥¿¥Ã¥¯

¤³¤Î¸¶¹Æ¤ò½ñ¤¯¿ôÆüÁ°¡¢»ä¤Î²ñ¼Ò¤¬´ÉÍý¤·¤Æ¤¤¤ë¥µ¡¼¥Ð¿ôÂæ¤ËƱ°ì¥µ¥¤¥È¤«¤ételnetd¤Ø¤Î¥¢¥¿¥Ã¥¯¤¬¤¢¤ê¤Þ¤·¤¿¡£¥¢¥¯¥»¥¹¸µ¤Ï¤ä¤Ï¤ê³¤³°¡¢ºÇ½é¤Î¥¢¥¿¥Ã¥¯¤ÈºÇ¸å¤Î¥¢¥¿¥Ã¥¯¤Î´Ö¤ËÌó2»þ´Ö¤Î¤º¤ì¤¬¤¢¤ê¤Þ¤·¤¿¡£

¤³¤ì¤é¤Î¥µ¡¼¥Ð¤Ç¤Ïtelnet¤Ë¤è¤ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¦¤«¤é¤Î¥¢¥¯¥»¥¹¤ò¶Ø»ß¡¢¤Þ¤¿¤Ï¸·¤·¤¯À©¸Â¤·¤Æ¤¤¤Þ¤·¤¿¤Î¤Ç¡¢tcp wrapper¤¬¥¢¥¯¥»¥¹¤ò¸¡½Ð¤·¤Æ¥á¡¼¥ë¤ÇÃΤ餻¤Æ¤¯¤ì¤¿¤Î¤Ç¤¹¡£

¤³¤Î¥¢¥¿¥Ã¥¯¤ÎÂоݤȤʤä¿¥µ¡¼¥Ð¤Î1Âæ¤Ï¡¢2½µ´Ö¤Û¤ÉÁ°¤Ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤ËÀܳ¤·¤¿¤Ð¤«¤ê¡£¥á¡¼¥ë¥µ¡¼¥Ð¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¤¬¡¢WWW¥µ¡¼¥Ð¤Ê¤ÉÀ¤´Ö¤ËÃΤé¤ì¤ë¤è¤¦¤Ê¥µ¡¼¥Ðµ¡Ç½¤Ï»ý¤¿¤»¤Æ¤¤¤Þ¤»¤ó¡£¤½¤ì¤Ë¤â¤«¤«¤ï¤é¤º¥¢¥¿¥Ã¥¯¤ò¼õ¤±¤ë¤È¤¤¤¦¤³¤È¤Ï¡¢¡ÖŨ¡×¤Î¾ðÊó¼ý½¸ÎϤ¬¹â¤¤¤³¤È¤ò¼¨¤·¤Æ¤¤¤ë¤è¤¦¤Êµ¤¤¬¤·¤Þ¤¹¡£

¡üpossible SYN flood

»ä¤Î²ñ¼Ò¤Î¥µ¡¼¥Ð¤¬possible SYN flood¤È¤¤¤¦¥á¥Ã¥»¡¼¥¸¤ò¿ôÆüÁ°¤Ë½Ð¤·¤Þ¤·¤¿¡£¼Â¤Ï¤³¤ì¤¬2²óÌܤÀ¤Ã¤¿¤Î¤Ç¡¢JPCERT/CC¤ÎÊý¤ò¸ò¤¨¤Æ¥¢¥¯¥»¥¹¸µ¤Î¥µ¥¤¥È´ÉÍý¼Ô¤È¥á¡¼¥ë¤Ç¸¡Æ¤¤ò¹Ô¤¤¤Þ¤·¤¿¡£·ëÏÀ¤«¤éÀè¤Ë½ñ¤­¤Þ¤¹¤¬¡¢¤³¤Î·ï¤Ï°Õ¿ÞŪ¤Ê¥¢¥¿¥Ã¥¯¤Ç¤Ï¤Ê¤¯¡¢¶öȯŪ¤ÊÍ×°ø¤¬½Å¤Ê¤Ã¤¿¡Ö¸íÊó¡×¤À¤í¤¦¤È¤¤¤¦·ëÏÀ¤ËÍî¤ÁÃ夭¤Þ¤·¤¿¡£

Mar 16 12:28:54 myserv kernel: Warning: possible SYN flood from 123.45.67.89 
on 98.76.54.32:22926. Sending cookies.

¤Ê¤¼¤³¤¦È½ÃǤ·¤¿¤«¡¢½ç¤òÄɤäÆÀâÌÀ¤·¤Þ¤·¤ç¤¦¡£SYN flood¤Ï¡¢É¸Åª¥µ¡¼¥Ð¤ò¥µ¡¼¥Ó¥¹ÉÔǽ¤Ë´Ù¤ì¤ë¥¢¥¿¥Ã¥¯¤Î¤Ò¤È¤Ä¤Ç¤¹¡£TCP¤Ç¤ÎÄÌ¿®¤Ï¡¢¥¯¥é¥¤¥¢¥ó¥È¤¬¡Ö¥µ¡¼¥Ó¥¹¤ò¼õ¤±¤¿¤¤¡×¤È¤¤¤¦¥Ñ¥±¥Ã¥È¤ò¥µ¡¼¥Ð¤ËÁ÷¤ë¤³¤È¤«¤é»Ï¤Þ¤ê¤Þ¤¹¡£¤³¤Î¥Ñ¥±¥Ã¥È¤ÏSYN¥Õ¥é¥°¤ò1¤Ë¤·¤¿ÆÃÊ̤ʥѥ±¥Ã¥È(SYN¥Ñ¥±¥Ã¥È)¤Ç¤¹¡£

SYN¥Ñ¥±¥Ã¥È¤ò¼õ¤±¼è¤Ã¤¿¥µ¡¼¥Ð¤Ï¡¢Àܳ¤Ë±þ¤¸¤ë¾ì¹ç¤ÏSYN¥Õ¥é¥°¤ÈƱ»þ¤ËACK¥Õ¥é¥°¤òΩ¤Æ¤¿¥Ñ¥±¥Ã¥È(SYN-ACK¥Ñ¥±¥Ã¥È)¤òÊÖ¤·¤Þ¤¹¡£¤½¤·¤ÆÆ±»þ¤ËÀܳ¤òÂÔ¤Á¼õ¤±¤ëÂÎÀ©¤ËÆþ¤ê¤Þ¤¹¡£

Àµ¾ï¤Ê¥¯¥é¥¤¥¢¥ó¥È¤Ï¡¢¤³¤³¤ÇACK¥Õ¥é¥°¤òΩ¤Æ¤¿¥Ñ¥±¥Ã¥È¤òºÆÅÙÁ÷¤ê¤Þ¤¹¡£¤³¤³¤ÇTCP¤Ç¤ÎÄÌ¿®Ï©(¥³¥Í¥¯¥·¥ç¥ó)¤¬³ÎΩ¤¹¤ë¤ï¤±¤Ç¤¹¡£¤³¤Î²áÄø¤ò3¥¦¥§¥¤¥³¥ß¥å¥Ë¥±¡¼¥·¥ç¥ó¤È¸Æ¤Ó¤Þ¤¹¡£

SYN flood¥¢¥¿¥Ã¥¯¤Ï¡¢ºÇ½é¤ÎSYN¥Ñ¥±¥Ã¥È¤òÁ÷¤Ã¤¿¸å¤Ç¡¢Ê֤äƤ­¤¿SYN-ACK¥Ñ¥±¥Ã¥È¤ò̵»ë¤·¤Þ¤¹¡£Ã±¤Ë̵»ë¤¹¤ë¤À¤±¤Ç¤Ê¤¯¡¢¥¢¥¿¥Ã¥«¨¡¤ÏSYN¥Õ¥é¥°¤òΩ¤Æ¤¿¥Ñ¥±¥Ã¥È¤ò¥µ¡¼¥Ð¤Ë̵¿ô¤ËÁ÷¤êÉÕ¤±¤Þ¤¹¡£

¥µ¡¼¥Ð¤Î»ñ¸»¤âÍ­¸Â¤Ç¤¹¤«¤é¡¢¤­¤ï¤á¤ÆÂ¿¿ô¤ÎSYN¥Ñ¥±¥Ã¥È¤òÁ÷¤êÉÕ¤±¤é¤ì¤¿¤é¡¢¿·¤¿¤Ê¥ê¥¯¥¨¥¹¥È¤Ë±þ¤¸¤ë;͵¤¬¤Ê¤¯¤Ê¤Ã¤Æ¤·¤Þ¤¤¤Þ¤¹¡£¤Ä¤Þ¤ê¡¢¥µ¡¼¥Ðµ¡Ç½¤¬Æ¯¤«¤Ê¤¯¤Ê¤Ã¤Æ¤·¤Þ¤¦¤Î¤Ç¤¹¡£

SYN flood¥¢¥¿¥Ã¥¯¤òËɤ°¤Ë¤Ï¡¢¥³¥Í¥¯¥·¥ç¥ó¤¬³ÎΩ¤·¤Æ¤¤¤Ê¤¤¥µ¡¼¥Ó¥¹Í×µá¤ÎÁí¿ô¤òÀ©¸Â¤¹¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£Linux¤Ï¥»¥­¥å¥ê¥Æ¥£¤ËÉÒ´¶¤ËÂбþ¤·¤Æ¤¤¤ëOS¤Ç¤¹¤«¤é¡¢ÅöÁ³ºÇ¶á¤Î¥«¡¼¥Í¥ë¤ÏSYN flood¥¢¥¿¥Ã¥¯¤Ø¤ÎÂкö¤¬²Äǽ¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£

¡üJPCERT/CC¤ª¤è¤Ó¥¢¥¯¥»¥¹¸µ¤Ø¤ÎÏ¢Íí

¤³¤Î·ï¤Ç¤Ï¡¢Æ±°ì¥Û¥¹¥È¤«¤é¤Îµ¿¤ï¤·¤¤¥á¥Ã¥»¡¼¥¸¤¬2²óȯÀ¸¤·¤¿¤¿¤á¡¢JPCERT/CC¤ËÏ¢Íí¤·¡¢Æ±»þ¤Ë¥¢¥¯¥»¥¹¸µ¤Ë¤âÌ䤤¹ç¤ï¤»¤Þ¤·¤¿¡£

¡Öµ¿¤ï¤·¤¤¡×¤È»×¤ï¤ì¤ë¾ì¹ç¤Ç¤â¡¢·è¤·¤ÆÁê¼ê¤ò²Ã³²¼Ô¤È·è¤á¤Ä¤±¤ë¤è¤¦¤Êɽ¸½¤ÏÈò¤±¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£¥¢¥É¥ì¥¹¤Î´Ö°ã¤¤¤Ê¤Éñ½ã¥ß¥¹¡¢¤³¤Ã¤Á¤Î´ª°ã¤¤¤Ê¤É¤Î²ÄǽÀ­¤â¤¢¤ë¤«¤é¤Ç¤¹¡£¤µ¤é¤Ë¡¢Ê̤Υ¢¥¿¥Ã¥«¡¼¤ËƧ¤ßÂæ¤Ë¤µ¤ì¤Æ¤¤¤ë²ÄǽÀ­¤â¤¢¤ê¤Þ¤¹¡£

µæÌÀ¤òÄ̤¸¤Æ¸ß¤¤¤Î¥»¥­¥å¥ê¥Æ¥£¥ì¥Ù¥ë¤ò¹â¤á¤¿¤¤¤È¤¤¤¦µ¤»ý¤Á¤Ç¡¢»ö¼Â¤òÀµ³Î¤Ë½Ò¤Ù¡¢¶¨ÎϤò¤ª´ê¤¤¤¹¤ë¤Î¤¬¤¤¤¤¤Ç¤·¤ç¤¦¡£JPCERT/CC¤ÎÊý¤Î¥á¡¼¥ë¤Ï¤è¤¯Îý¤ê¾å¤²¤é¤ì¤Æ¤¤¤Æ¡¢·Ù²ü¿´¤äȿȯ¤ò°ú¤­µ¯¤³¤µ¤Ê¤¤¤è¤¦¤ÊÇÛθ¤ËËþ¤Á¤Æ¤¤¤Þ¤·¤¿¡£

¥¢¥¯¥»¥¹¸µ¤Î´ÉÍý¼Ô¤ÎÊý¤Ï¡¢³ºÅöÆü»þÁ°¸å¤Î¥í¥°¤òÄ´¤Ù¡¢³°Éô¤«¤é¤Î¿¯Æþ¤Î²ÄǽÀ­¤â´Þ¤á¤¿¸¡¾Ú¤ò¹Ô¤Ã¤Æ¤¯¤À¤µ¤¤¤Þ¤·¤¿¡£¤½¤·¤Æ¡¢Æ§¤ßÂæ¤Ë»È¤ï¤ì¤¿²ÄǽÀ­¤¬¤Ê¤¤¤È»×¤ï¤ì¤ë¤³¤È¡¢¥á¥Ã¥»¡¼¥¸¤¬½Ð¤¿¤È¤­¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤¤¤¿¥æ¡¼¥¶¤ò¸Ä¿Í¥ì¥Ù¥ë¤Þ¤ÇÆÃÄê¤Ç¤­¡¢°Õ¿ÞŪ¤Ê¥¢¥¿¥Ã¥¯¤Ï¤Ê¤«¤Ã¤¿¤È»×¤ï¤ì¤ë¤³¤È¤Ê¤É¤ò¤ªÃΤ餻¤¤¤¿¤À¤­¤Þ¤·¤¿¡£

¤½¤ì¤Ç¤Ï¡¢¤É¤¦¤·¤Æ¤³¤Îpossible SYN flood¤È¤¤¤¦¥á¥Ã¥»¡¼¥¸¤¬½Ð¤¿¤Î¤Ç¤·¤ç¤¦¤«¡£¤½¤ì¤òÆÍ¤­»ß¤á¤Ê¤¤¤ÈÉ԰¤¬»Ä¤ê¤Þ¤¹¡£

¡ü¥µ¡¼¥Ð¤¬Àܳ¤ò¼õ¤±ÉÕ¤±¤ë¤·¤¯¤ß

TCP ¤ò°·¤¦¥µ¡¼¥Ð¤Ï¡¢ÆÃÄêÈÖ¹æ¤Î¥Ý¡¼¥È¤ò³«¤¤¤Æ¥¯¥é¥¤¥¢¥ó¥È¤«¤é¤ÎÀܳÍ×µá¤ò¼õ¤±ÉÕ¤±¤Þ¤¹¡£¥Ý¡¼¥È¤ò³«¤¯¤È¤­¡¢listen(2)¥·¥¹¥Æ¥à¥³¡¼¥ë¤¬»È¤ï¤ì¤Þ¤¹¡£man¥Ú¡¼¥¸¤ò¸«¤ë¤È¤ï¤«¤ê¤Þ¤¹¤¬¡¢listen(2)¤Ë¤Ï¥Ý¡¼¥ÈÈÖ¹æ(Àµ³Î¤Ë¤Ï¥½¥±¥Ã¥È¥Ç¥£¥¹¥¯¥ê¥×¥¿)¤È¡Ö¥Ð¥Ã¥¯¥í¥°¡×¤ò»ØÄꤷ¤Þ¤¹¡£

¡Ö¥Ð¥Ã¥¯¥í¥°¡×¤Ï¡¢¤³¤Î¥Ý¡¼¥È¤¬¼õ¤±ÉÕ¤±¤é¤ì¤ëÀܳÍ×µá¤Î¿ô¤Î¾å¸Â¤Ç¤¹¡£¥Ð¡¼¥¸¥ç¥ó2.0.x¤Î¥«¡¼¥Í¥ë¤Ç¤Ï¡¢SYN flood¥¢¥¿¥Ã¥¯Âкö¤Ë¤³¤ÎÃͤò»È¤Ã¤Æ¤¤¤Þ¤¹¡£¥«¡¼¥Í¥ëÄê¿ôSOMAXCONN (¥Ç¥Õ¥©¥ë¥ÈÃͤÏ128)¤Þ¤¿¤Ï¡Ö¥Ð¥Ã¥¯¥í¥°¡×Ãͤµ¤¤Êý¡¢¤Þ¤¿¤ÏºÇ¾®ÃÍ5¤òmax_ack_backlog¤È¤·¤Þ¤¹¡£

ÀܳÂÔ¤Á¤Î¥Ð¥Ã¥¯¥í¥°(ack_backlog)¤Î¿ô¤Ï¡¢SYN-ACK¥Ñ¥±¥Ã¥È¤òÁ÷¤Ã¤¿»þÅÀ¤Ç1¤ÄÁý¤¨¡¢¥³¥Í¥¯¥·¥ç¥ó¤¬³ÎΩ¤·¤¿»þÅÀ¤Ç¤³¤ì¤ò1¤Ä¸º¤ê¤Þ¤¹¡£

ack_backlog¤ÎÃͤ¬max_ack_backlog¤òͤ¨¤ë¤È¡¢possible SYN flood·Ù¹ð¥á¥Ã¥»¡¼¥¸¤¬½Ð¤ë¤ï¤±¤Ç¤¹¡£

¡ü22926È֥ݡ¼¥È¤ÎÆæ

possible SYN flood·Ù¹ð¥á¥Ã¥»¡¼¥¸¤¬½Ð¤ë¥á¥«¥Ë¥º¥à¤Ï¤ï¤«¤ê¤Þ¤·¤¿¡£¤Ç¤â¡¢¥¢¥¿¥Ã¥¯¤Ç¤Ï¤Ê¤¤¤Î¤Ë¥á¥Ã¥»¡¼¥¸¤¬½Ð¤ë¥±¡¼¥¹¤È¤Ï²¿¤Ê¤Î¤Ç¤·¤ç¤¦¤«¡£

¤½¤³¤Ç¥í¥°¤ò¤â¤¦°ìÅÙÄ´¤Ù¤Þ¤·¤¿¡£¥¢¥¯¥»¥¹¸µ¤Ï»ä¤Î¥µ¡¼¥Ð¤Î22926È֥ݡ¼¥È¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤¤¤Þ¤¹¡£¤³¤ì¤ÏÀèÊý¤Î¥í¥°¤Ç¤â³Îǧ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£

¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤Ç»È¤ï¤ì¤ë¥µ¡¼¥Ó¥¹¤Ï¡¢Ä̾ï1023Èְʲ¼¤Î¥Ý¡¼¥È¤ò»È¤Ã¤Æ¤¤¤Þ¤¹¡£22926È֥ݡ¼¥È¤È¤¤¤¦¤Î¤Ï¡¢¤Á¤ç¤Ã¤È¤ª¤«¤·¤¤¤è¤¦¤Êµ¤¤¬¤·¤Þ¤¹¡£

¤â¤¦°ìÅÙ¥í¥°¥Õ¥¡¥¤¥ëÁ´ÂΤòÄ´¤Ù¤Æ¤ß¤Þ¤·¤¿¡£Á°¸å¤Î¥í¥°¹Ô¤«¤é¡¢¥¢¥¯¥»¥¹¸µ¤Î¥æ¡¼¥¶¤ÏFTP¤Ç¥Õ¥¡¥¤¥ë¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¤¤¤¿¤³¤È¤¬È½ÌÀ¤·¤Þ¤·¤¿¡£¤³¤ì¤Ç22926ÈÖ¤ÎÆæ¤¬¤ï¤«¤ê¤Þ¤·¤¿¡£

FTP¤Ç¤Ï¥»¥Ã¥·¥ç¥ó¤ÎÀ©¸æ¤Î¤¿¤á¤Î¥³¥Í¥¯¥·¥ç¥ó¤È¤ÏÊ̤ˡ¢¥Ç¡¼¥¿Å¾Á÷¤Î¤¿¤á¤Î¤â¤¦¤Ò¤È¤Ä¤Î¥³¥Í¥¯¥·¥ç¥ó¤¬»È¤ï¤ì¤Þ¤¹¡£ºÇ½é¤Î¥³¥Í¥¯¥·¥ç¥ó¤Ë¤Ï21È֥ݡ¼¥È¤¬»È¤ï¤ì¤Þ¤¹¤¬¡¢¥Ç¡¼¥¿Å¾Á÷¤Î¥³¥Í¥¯¥·¥ç¥ó¤òºî¤ê½Ð¤¹¤Î¤Ë2¤È¤ª¤ê¤ÎÊýË¡¤¬¤¢¤ê¤Þ¤¹¡£¤³¤³¤Ç22926È֥ݡ¼¥È¤¬Åо줹¤ë¤Î¤Ï¡¢¥Ñ¥Ã¥·¥Ö¥â¡¼¥É¤È¸Æ¤Ð¤ì¤ëÊýË¡¤Ç¤¹¡£

¥Ñ¥Ã¥·¥Ö¥â¡¼¥É¤Ç¤Ï¡¢¥µ¡¼¥Ð¤¬¶õ¤¤¤Æ¤¤¤ë¥Ý¡¼¥È¤òÁª¤ó¤Ç³«¤­¡¢¥Ý¡¼¥ÈÈÖ¹æ¤ò¥¯¥é¥¤¥¢¥ó¥È¤ËÄÌÃΤ·¤Þ¤¹¡£¶õ¤¤¤Æ¤¤¤ë¥Ý¡¼¥È¤È¤¤¤¦¤³¤È¤Ç¡¢¤³¤Î¥»¥Ã¥·¥ç¥ó¤Ç¤Ï 22926ÈÖ¤¬»È¤ï¤ì¤¿¤ï¤±¤Ç¤¹¡£¥¯¥é¥¤¥¢¥ó¥È¤Ï¤³¤Î¥Ý¡¼¥È¤ËÂΤ·¤Æ¥³¥Í¥¯¥·¥ç¥ó¤òÄ¥¤ê¡¢¥Ç¡¼¥¿Å¾Á÷¤¬¹Ô¤ï¤ì¤Þ¤¹¡£

»ä¤Î¥µ¡¼¥Ð¤¬»È¤Ã¤Æ¤¤¤ëwu-ftpd¤Î¥½¡¼¥¹¤òÄ´¤Ù¤Æ¤ß¤ë¤È¡¢¥Ñ¥Ã¥·¥Ö¥â¡¼¥É¤Ç¤Îlisten()¤Ç¤Ï¡¢¥Ð¥Ã¥¯¥í¥°Ãͤ¬1¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£¤¹¤Ç¤Ë³ÎΩ¤·¤Æ¤¤¤ë¥»¥Ã¥·¥ç¥ó¤ÎÁê¼ê¤Ë¤À¤±Ä󼨤¹¤ë°ì»þŪ¤Ê¥Ý¡¼¥È¤Ç¤¹¤Î¤Ç¡¢1¤È¤¤¤¦Ãͤϼ«Á³¤Ç¤¹¡£

¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤Ç¤Ï¡¢º®»¨¤Ë¤è¤Ã¤Æ¥Ñ¥±¥Ã¥È¤¬¼Î¤Æ¤é¤ì¤¿¤êÂçÉý¤ËÃٱ䤷¤ÆÆÏ¤¯¤³¤È¤¬¤¢¤ê¤Þ¤¹¡£¥µ¡¼¥Ð¤¬Á÷¤Ã¤¿SYN-ACK¤ò¥¯¥é¥¤¥¢¥ó¥È¤¬¼õ¤±¼è¤ì¤º¡¢¥¯¥é¥¤¥¢¥ó¥È¤¬ºÆÅÙSYN¥Ñ¥±¥Ã¥È¤òÁ÷¤Ã¤Æ¤·¤Þ¤¦²ÄǽÀ­¤ÏÈÝÄê¤Ç¤­¤Þ¤»¤ó¡£

º£²ó¤Ï¥¯¥é¥¤¥¢¥ó¥È¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¸¡Æ¤¤Ï¤Ç¤­¤Þ¤»¤ó¤Ç¤·¤¿¡£¤·¤«¤·¡¢²óÀþ»ö¾ð¤Î°­²½¤Ê¤É¤Ê¤ó¤é¤«¤Î°ì»þŪ¤ÊÍ×°ø¤Ë¤è¤Ã¤Æ¡¢ack_backlogÃͤ¬Â礭¤¯¤Ê¤Ã¤Æ¤·¤Þ¤¤possible SYN flood·Ù¹ð¥á¥Ã¥»¡¼¥¸¤¬½Ð¤¿¤È²ò¼á¤¹¤ë¤Î¤¬ÂÅÅö¤À¤È»×¤¤¤Þ¤¹¡£

¡ü¶µ·±

ÉÔÀµ¥¢¥¯¥»¥¹¤ò»×¤ï¤»¤ë¥í¥°¥á¥Ã¥»¡¼¥¸¤¬½Ð¤¿¾ì¹ç¤Ç¤â¡¢¤½¤Î¿¤¯¤ÏÁê¼ê¤Îñ½ã¥ß¥¹¤Ç¤¢¤Ã¤¿¤ê¡¢¶öȯŪ¤ÊÍ×°ø¤¬½Å¤Ê¤ê¹ç¤Ã¤¿·ë²Ì¤Î¥á¥Ã¥»¡¼¥¸¤Ç¤¢¤Ã¤¿¤ê¤·¤Þ¤¹¡£

possible SYN flood¹Ô¤À¤±¤Ç¤Ê¤¯Á°¸å¤Î¥í¥°¥á¥Ã¥»¡¼¥¸¤ò¿µ½Å¤Ë¸¡Æ¤¤·¡¢¤µ¤é¤Ë22926È֤Ȥ¤¤¦¥Ý¡¼¥ÈÈÖ¹æ¤Î°ÕÌ£¤ËÁ᤯µ¤ÉÕ¤¤¤Æ¤¤¤¿¤é¡¢¥¢¥¯¥»¥¹¸µ´ÉÍý¼Ô¤Ê¤É¤Î¼ê¤òÈѤ碌¤º¤Ë¾å¤Î·ëÏÀ¤ËÅþã¤Ç¤­¤¿¤Î¤Ç¤Ï¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£¤Þ¤À¤Þ¤À½¤¹Ô¤¬É¬ÍפǤ¹¡£

¡ÚLinux Japan Vol.8 ·ÇºÜµ­»ö¤ò²ÃÉ®½¤Àµ¡Û

Á°¤Ø   Ìá¤ë   ¼¡¤Ø

²áµîµ­»ö¤Î¥¢¡¼¥«¥¤¥Ö

´ØÏ¢¥ê¥ó¥¯

¡÷La Mail¥À¥¦¥ó¥í¡¼¥É
¥¢¥é¥á¡¼¥ë|@La Mail

¤ªÃΤ餻

´ØÀ¾¥ª¡¼¥×¥ó¥½¡¼¥¹2011/¥³¥ß¥å¥Ë¥Æ¥£Âç·èÀï¤Ë½ÐŸ

2011.11.10  ¾ÜºÙ¤Ï¤³¤Á¤é

[¥×¥ì¥¹¥ê¥ê¡¼¥¹] ¥µ¡¼¥É¥¦¥§¥¢¤ÈLINBIT ¤¬¹ñÆâÁíÂåÍýŹ·ÀÌó¤òÄù·ë

2011.10.04  ¾ÜºÙ¤Ï¤³¤Á¤é

DRBD¥¯¥é¥¹¥¿¥¹¥¿¥Ã¥¯¥µ¥Ý¡¼¥ÈÅù ÎÁ¶âÂηÏÊѹ¹¤Î¤ªÃΤ餻

2011.09.28  ¾ÜºÙ¤Ï¤³¤Á¤é

Lotus Knows Expo2011 ½ÐŸ¤Î¤´°ÆÆâ

2011.09.10  ¾ÜºÙ¤Ï¤³¤Á¤é

¹ñÆâ³°¤ÎÊ£¿ô¥Ç¡¼¥¿¥»¥ó¥¿¤òÍøÍѤ·¤¿¥Ç¥£¥¶¥¹¥¿¥ê¥«¥Ð¥ê¥µ¡¼¥Ó¥¹Ä󶡤Τ´°ÆÆâ

2011.09.08  ¾ÜºÙ¤Ï¤³¤Á¤é