LinuxSoft


README (rkdat - rookit detector for Linux)

ÆüËܸìÈǥɥ­¥å¥á¥ó¥È¤Ë¤Ä¤¤¤Æ

¡¡ÆüËܸìÈǤΥɥ­¥å¥á¥ó¥È¸ø³«¤Ë¤Ä¤¤¤Æ¤ÏÇ°¤Î¤¿¤áºî¼Ô¤µ¤ó¤ËÌ䤤¹ç¤ï¤»Ãæ¤Ç¤¹¡£ÀèÊý¤Î²óÅú¤ä¥é¥¤¥»¥ó¥¹¤Ë¤è¤Ã¤Æ¤Ï¥É¥­¥å¥á¥ó¥È¤ÏÈó¸ø³«¤Ë¤Ê¤ë¾ì¹ç¤â¤¢¤ê¤Þ¤¹¡£

¡¡¥É¥­¥å¥á¥ó¥È¤ÎÆâÍƤϽÐÍè¤ë¤À¤±¥ª¥ê¥¸¥Ê¥ë±Ñ¸ì¤ËÃé¼Â¤ËËÝÌõ¤¹¤ë¤è¤¦¤ËÅؤá¤Þ¤¹¤¬¡¢ÆüËܸì¤È¤·¤ÆÉÔŬÀÚ¤ÊÉôʬ¤ÏÆüËܸì¤È¤·¤ÆÆɤߤ䤹¤¤¤è¤¦¤ËÃÖ¤­´¹¤¨¤Æ¤¤¤ë¾ì¹ç¤â¤¢¤ê¤Þ¤¹¡£¤Ê¤ª¡¢ÌÈÀÕ»ö¹à¤È¤·¤Æ¡¢ÆüËܸìÈǤòÍøÍѼԤ¬ÍøÍѤ¹¤ë¤Ë¤¢¤¿¤ê¡¢¤¤¤«¤Ê¤ë¾ì¹ç¤âÌõ¼Ô¤Ï¤½¤ÎÀÕ¤ò¤òÄɤ¤¤Þ¤»¤ó¡Ê¡¢¤È½ñ¤¯¤Î¤¬°ìÈÌŪ¤Ç¤¹¤Î¤Ç¡¢»ä¤â½ñ¤«¤»¤Æ¤¯¤À¤µ¤¤¡£¡£¡Ë¡£

¥ª¥ê¥¸¥Ê¥ëÃøºî¸¢É½µ­

rkdet rootkit detector

Andrew Daviel <andrew@vancouver-webpages.com>
February 2000
Revised March 2001

Tiny Abstract - Í×Ìó

¡¡¥×¥í¥°¥é¥à¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢¥¯¥é¥Ã¥«¡¼¤Î¥·¥¹¥Æ¥àÇ˲õ³èÆ°¤ò¸¡½Ð¤·¤Þ¤¹¡£

Abstract - ³µÍ×

¡¡¤³¤Î¥Ç¡¼¥â¥ó(rkdet)¤Ï Rootkit*1 ¤ä¥Ñ¥±¥Ã¥È¥¹¥Ë¥Õ¥¡¡Ê¥Ñ¥±¥Ã¥È¥­¥ã¥×¥Á¥ã¡Ë¤ò°Õ¿Þ¤¹¤ë¹Ô°Ù¤òºÙ¤¯¤¹¤ë¤³¤È¤òÌÜŪ¤È¤·¤¿¤â¤Î¤Ç¤¹¡£¥Ç¡¼¥â¥ó¼«ÂΤÏ̵³²¤ÇÈó¾ï¤Ë¾®¤µ¤ÊÆ°ºî¤Ç²ÔƯ¤Ç¤­¤ë¤è¤¦À߷פµ¤ì¤Æ¤¤¤Þ¤¹¡£¤â¤·°Û¾ï¤ò¸¡½Ð¤¹¤ë¤È¡¢¥í¥°¥Õ¥¡¥¤¥ë¤òźÉÕ¤·¤¿¥á¡¼¥ë¤òÁ÷¿®¤·¡¢Ä¾¤Á¤Ë¥Í¥Ã¥È¥ï¡¼¥¯¤â¤·¤¯¤Ï¥·¥¹¥Æ¥à¤òÄä»ß¤µ¤»¤Þ¤¹¡£µ¡Ç½¤È¤·¤ÆÄ̾ï¤Î¥Þ¥ë¥Á¥æ¡¼¥¶¥·¥¹¥Æ¥à¤ÇºÇ¾®¸Â¤Ç²ÔƯ¤¹¤ë¤è¤¦¤ËÀ߷פµ¤ì¤Æ¤ª¤ê¡¢Linux ¥«¡¼¥Í¥ë¤ÎÊѹ¹¤ä¥·¥¹¥Æ¥à¤ÎÊѹ¹¤òɬÍפȤ·¤Þ¤»¤ó¡£

License - ¥é¥¤¥»¥ó¥¹

¡¡rkdet ¤Ï¥Õ¥ê¡¼¥¦¥§¥¢¤Ç¤¹¡£rkdet ¤Ï David A. Curry ¤Ë¤è¤Ã¤ÆºîÀ®¤µ¤ì¤Þ¤·¤¿¡£
¡¡¤â¤·¥½¥Õ¥È¥¦¥§¥¢¤Î¼ïÊ̤òÄêµÁ¤¹¤ë¤Î¤Ç¤¢¤ì¤Ð¥Ñ¥Ö¥ê¥Ã¥¯¡¦¥É¥á¥¤¥ó*2¤Ç¤¹¡£

Background - ³«È¯¤Ë»ê¤ëÇØ·Ê

¡¡¿¯Æþ¼Ô¤Ï¤¢¤ê¤È¤¢¤é¤æ¤ë¼êÃʤòÍѤ¤¤Æ¤¢¤Ê¤¿¤¬±¿ÍѤ·¤Æ¤¤¤ë¥·¥¹¥Æ¥à¤Ø¤Î¿¯Æþ¤ò»î¤ß¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡£¿¯ÆþÊýË¡¤È¤·¤Æ¤Ï¸¢¸Â¤Î¤¢¤ë¥æ¡¼¥¶¤Î¥Ñ¥¹¥ï¡¼¥É¤òÅð¤à¤«¤âÃΤì¤Þ¤»¤ó¤·¡¢¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Î¥Ñ¥±¥Ã¥ÈÅðÄ°¡Ê¥¹¥Ë¥Ã¥Õ¥¡¡Ë¤Ë¤è¤Ã¤Æ¥Ñ¥¹¥ï¡¼¥É¾ðÊó¤òÆþ¼ê¤¹¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡£¤¢¤ë¤¤¤Ï¡¢¥·¥¹¥Æ¥à¾å¤ÇÆ°ºî¤¹¤ë¥Ç¡¼¥â¥ó¤ËÂФ·¤Æ¥Ð¥Ã¥Õ¥¡¡¦¥ª¡¼¥Ð¥é¥ó¤È¤¤¤Ã¤¿¥»¥­¥å¥ê¥Æ¥£¥Û¡¼¥ë¤Ø¤Î¹¶·â¤ò»î¤ß¤ë¤«¤âÃΤì¤Ê¤¤¤Î¤Ç¤¹¡£¤â¤·¿¯Æþ¼Ô¤Ë¥¢¥¯¥»¥¹¤µ¤ì¤Æ¤·¤Þ¤¦¤È¡¢¥¯¥é¥Ã¥«¡¼*3¤Ë¤è¤Ã¤Æ Eggdrop ¤È¤¤¤Ã¤¿ IRC ¥í¥Ü¥Ã¥È¤òÆ°ºî¤µ¤»¤ë¤À¤±¤Î°Ù¤Ë CPU ¤ò¾ÃÈñ¤µ¤»¤¿¤ê¡¢¤¤¤í¤ó¤Ê¼êÃʤǥѥ¹¥ï¡¼¥É¾ðÊó¤òÆþ¼ê¤¹¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡Ê¤¿¤È¤¨¥·¥¹¥Æ¥à¤Î¥Ñ¥¹¥ï¡¼¥É¤¬¥·¥ã¥É¥¦²½¤µ¤ì¤Æ¤¤¤Æ¤â¤Ç¤¹¡Ë¡£¤¢¤ë¤¤¤Ï½ã¿è¤Ë¥¯¥é¥Ã¥­¥ó¥°Íѥġ¼¥ë¤ò¤äÅð¤ó¤À¥Ç¡¼¥¿¤òÊݸ¤·¤Æ¤¤¤¯¤À¤±¤«¤â¤·¤ì¤Þ¤»¤ó¡£¤È¤Ï¤¤¤Ã¤Æ¤â¡¢¥¯¥é¥Ã¥«¡¼¤¬¿¯Æþ·ÁÀפò¾Ãµî¤·¤¿¤ê°­¼Á¤Ê¥×¥í¥°¥é¥à¤ò¼Â¹Ô¤¹¤ë¤è¤¦¤Ë¤Ê¤ë¤Þ¤Ç¤Ï¡¢¤¤¤¯¤Ä¤â¤Î¥¹¥Æ¥Ã¥×¤òƧ¤Þ¤Ê¤¯¤Æ¤Ï¤¤¤±¤Þ¤»¤ó¡£¤Þ¤º¡¢¥·¥¹¥Æ¥à¤ò¾è¤Ã¼è¤ë°Ù¤Ë¤Ï root ¥æ¡¼¥¶¸¢¸Â¤¬É¬ÍפǤ¹¡£¤½¤Î¤¿¤á¤Ë¤Ï setuid ¤µ¤ì¤¿ mount¡¢cron¡¢¤¢¤ë¤¤¤Ï¥²¡¼¥à¥×¥í¥°¥é¥à¤Ê¤É¤ËÂФ¹¤ë¹¶·âÍÑ¤Î¥×¥í¥°¥é¥à¤òÍѤ¤¤Þ¤¹¡£¤½¤Î¸å¡¢Â¿¤¯¤Î¥¯¥é¥Ã¥«¡¼Ã£¤Ï°ìÈÌŪ¤Ë½ÅÍפʥ·¥¹¥Æ¥à¥¢¥«¥¦¥ó¥È¤ò̵¸ú¤Ë¤·¤¿¤ê¡¢¿¯Æþ»þ¤Î¥í¥°µ­Ï¿¤òºï½ü¤·¤è¤¦¤È¤·¤Þ¤¹¡£¤³¤ì¤é¤ËÍѤ¤¤ë¥·¥¹¥Æ¥àÇ˲õ¡¦±£Êåġ¼¥ë¤¬°ìÈÌ¤Ë "Rootkit"(¥ë¡¼¥È¥­¥Ã¥È)¤È¸Æ¤Ð¤ì¤Æ¤¤¤ë¤â¤Î¤Ç¤¹¡£Åµ·¿Åª¤Ê¤â¤Î¤Ï "ps" ¤ä "netstat" ¥³¥Þ¥ó¥É¤ò²þã⤷¡¢¥¯¥é¥Ã¥«¡¼¤¬ÍѤ¤¤ë¥×¥í¥°¥é¥à¤äÀܳ¸µ¤Î IP ¥¢¥É¥ì¥¹¤ò±£¤¹Æ¯¤­¤ò»ý¤Á¤Þ¤¹¡£¤³¤ì¤é¥·¥¹¥Æ¥à¥³¥Þ¥ó¥É¤ËÂФ·¤Æ´Æ»ë¤ò¤·¤Ä¤Å¤±¤ì¤Ð¡¢¿¯Æþ»þ¤Ë¿¯Æþ¤ò¸¡¤¹¤ë¤³¤È¤¬½ÐÍè¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡£

¡¡¤â¤¦£±¤Äŵ·¿Åª¤Ê¤â¤Î¤Ï¥Ñ¥±¥Ã¥È¡¦¥¹¥Ë¥Õ¥¡¤ò¥·¥¹¥Æ¥à¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤³¤È¤Ç¤¹¡£¿¯Æþ¤·¤¿¥Þ¥·¥ó¤ÎÃÖ¤«¤ì¤Æ¤¤¤ëƱ°ì¥Í¥Ã¥È¥ï¡¼¥¯Æâ¤Ë¤¢¤ë¥Þ¥·¥ó¤Ø¤Î telnet ¤ä ftp ¤Î¥æ¡¼¥¶Ì¾¤È¥Ñ¥¹¥ï¡¼¥É¾ðÊó¤ò¼èÆÀ¤¹¤ë¤³¤È¤Ç¤¹¡£Æ±ÍÍ¤Ë IMAP ¤ä POP3 ¤È¤¤¤Ã¤¿¥á¡¼¥ë¤ä Windows ¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤Î¥í¥°¥¤¥ó¾ðÊó¤â¼èÆÀ¤µ¤ì¤Æ¤·¤Þ¤¦¤Ç¤·¤ç¤¦¡£¤â¤·¡¢¤³¤Î¤è¤¦¤ÊÅðÄ°³èÆ°¤ò´Æ»ë¤¹¤ë¤³¤È¤¬¤Ç¤­¤ì¤Ð¡Ê¥Í¥Ã¥È¥ï¡¼¥¯¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤Î¾õÂÖ¤¬ promiscuous*3 ¥â¡¼¥É¤Ë¤Ê¤ì¤Ð¡¢¿¯Æþ¤µ¤ì¤¿²ÄǽÀ­¤¬¹â¤¤¤ÈȽÃǤǤ­¤ë¤Ç¤·¤ç¤¦¡Ê¤·¤«¤·¤Ê¤¬¤é¡¢¥¯¥é¥Ã¥«¡¼¤Ï¥Í¥Ã¥È¥ï¡¼¥¯¤Î¥â¡¼¥É¤òÊѹ¹¤»¤º¡¢¤¿¤À¿¯Æþ¤·¤¿¥Þ¥·¥ó¤Î¾ðÊó¤ò´Æ»ë¤·¤Ä¤Å¤±¤ë¤À¤±¤«¤â¤·¤ì¤Þ¤»¤ó¡Ë¡£

Description - ¥½¥Õ¥È¥¦¥§¥¢¤Î²òÀâ

¡¡¤³¤Î¥×¥í¥°¥é¥à¤Ï rootkit ¤Ë¤è¤Ã¤Æ²þã⤵¤ì¤ë¤³¤È¤¬Â¿¤¤°ìÈÌŪ¤Ê¥×¥í¥°¥é¥à¤Î¥Á¥§¥Ã¥¯¥µ¥à¤ò¸¡ºº¤ò¤¹¤ë¤â¤Î¤Ç¤¹¡£¸¡ººÂоݤȤʤë¥Õ¥¡¥¤¥ë¤Ï¥³¥ó¥Ñ¥¤¥ë»þ¤Ë»ØÄꤷ¤Þ¤¹*4¡£¥Õ¥¡¥¤¥ë¥ê¥¹¥È¤Ï¥·¥¹¥Æ¥à¥³¥Þ¥ó¥É¤ä³Æ¼ï¤Î¥á¥Ã¥»¡¼¥¸¤È¶¦¥Ð¥¤¥Ê¥ê¡¦¥³¡¼¥É¤È¤·¤Æ¤Ë¥³¥ó¥Ñ¥¤¥ë¤µ¤ì¤ë¤Î¤Ç¡¢ÍøÍÑ»þ¤Ë¤Ï²òÆɤ·¤Å¤é¤¤¾õÂ֤ˤʤäƤ¤¤Þ¤¹¡£ÉÔÌÀÎƲ½¥¢¥ë¥´¥ê¥º¥à¤Ïº³ºÙ¤Ç¤¹¤¬¡¢¥³¥ó¥Ñ¥¤¥ë¤µ¤ì¤¿¥×¥í¥°¥é¥à¤Ï³°Éô¥×¥í¥°¥é¥à¤ä¥é¥¤¥Ö¥é¥ê¤ò°ìÀÚɬÍפȤ·¤Þ¤»¤ó¡£

¡¡¥×¥í¥°¥é¥à¤Ë¤Ë¤ÏǤ°Õ¤ÎÀ°¿ô¤ò°ú¿ô¤È¤·¤Þ¤¹¡£¤â¤·ÊѤʰú¿ô¡ÊÎ㤨¤Ð¥Ó¥Ã¥È 0 ¤¬¥»¥Ã¥È¤µ¤ì¤ë¾ì¹ç¡Ë¤¬¤¢¤ì¤Ð¡¢¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹ "ech0" ¤¬ promiscus *5 ¾õÂ֡ʥѥ±¥Ã¥È¼ý½¸Ãæ¡Ë¤Ç¤Ê¤¤¤«Ä´¤Ù¤Þ¤¹¡£¤â¤·¥Ó¥Ã¥È 1 ¤¬¥¯¥ê¥¢¤µ¤ì¤ë¤È¡¢¥×¥í¥°¥é¥à¤Ï¥Í¥Ã¥È¥ï¡¼¥¯¤Î route ¾ðÊó¤òºï½ü¤¹¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£¤â¤·¥Ó¥Ã¥È 1 ¤¬¥»¥Ã¥È¤µ¤ì¤ë¤È¡¢¥×¥í¥°¥é¥à¤Ï eth0 ¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ò̵¸ú¤Ë¤·¤Þ¤¹¡£¥·¥¹¥Æ¥à¤¬Ê£¿ô¤Î¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤òÈ÷¤¨¤Æ¤¤¤ë¾ì¹ç¤Ë¤Ï¡¢"xstrings.txt" ¤Ë´Þ¤Þ¤ì¤ë¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤Î¾ðÊó¤ò¤òÊѹ¹¤¹¤ë¤«¡¢¥×¥í¥°¥é¥à¤¬Ê£¿ô¤Î¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ËÂбþ¤Ç¤­¤ë¤è¤¦¤Ë¤·¤Ê¤±¤ì¤Ð¤¤¤±¤Ê¤¤¤Ç¤·¤ç¤¦¡£¥³¥Þ¥ó¥É¤Ï¤É¤Î¤è¤¦¤Ë¤Ç¤âÊѹ¹¤Ç¤­¤Þ¤¹¡£Î㤨¤Ð "init 1" ¤Ç¥·¥ó¥°¥ë¡¦¥æ¡¼¥¶¡¦¥â¡¼¥É¤Ë°Ü¹Ô¤µ¤»¤¿¤ê "shutdown -h now" ¤Ë¤è¤ê¨»þ¥·¥ã¥Ã¥È¥À¥¦¥ó¤ò¤µ¤»¤¿¤ê¡¢¤¢¤ë¤¤¤Ï "panic.sh" ¤Î¤è¤¦¤Ê¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤µ¤»¤ë¤³¤È¤â½ÐÍè¤Þ¤¹¡Êpanic.sh ¤Ï¥½¡¼¥¹¥³¡¼¥É¤Î¥¢¡¼¥«¥¤¥Ö¤Ë´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡Ë¡£

Enhanced Security - ¥»¥­¥å¥ê¥Æ¥£¤Î³ÈÄ¥

¡¡¥»¥­¥å¥ê¥Æ¥£¤Ë¤Ä¤¤¤Æ"¤¢¤¤¤Þ¤¤¤Ê¾õÂÖ"¤È¤¤¤¦¤Î¤Ï¿¿¤Î°ÕÌ£¤Ç°ÂÁ´¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¤¬¡¢Á´¤¯¤Ê¤Ë¤â¤·¤Ê¤¤¤è¤ê¤Ï¤Þ¤·¤Ç¤¹¡£LIDS ¤È¤¤¤Ã¤¿¥«¡¼¥Í¥ë³ÈÄ¥¥â¥¸¥å¡¼¥ë¤òÍѤ¤¤º¤Ë¿¯Æþ¼Ô¤¬ÀßÃÖ¤·¤¿±£¤ì¤¿¥×¥í¥°¥é¥à¤ò¸¡½Ð¤¹¤ë¤³¤È¤ÏÆñ¤·¤¤¤Ç¤¹¡£¤Ç¤¹¤¬¡¢Ã±½ã¤Ë rkdet ¤¬±£¤µ¤ì¤¿¤«¤É¤¦¤«¤Ï "ps ax|grep rkdet" ¤ä "locate rkdat" ¤¢¤ë¤¤¤Ï "find /proc -name exe -exec grep -l md5sum {} \;" ¤È¤¤¤Ã¤¿ÊýË¡¤ÇÄ´¤Ù¤ë¤³¤È¤Ï½ÐÍè¤ë¤Î¤Ç¤¹¡£¥·¥¹¥Æ¥àËɱҤΤ¿¤á¤Ë¤Ï¡¢¤³¤Î¥É¥­¥å¥á¥ó¥È¤ä¥¤¥ó¥¹¥È¡¼¥ë»þ¤Ë»ÈÍѤ·¤¿¥Õ¥¡¥¤¥ë·²¤ò¥¤¥ó¥¹¥È¡¼¥ë¸å¤Ïºï½ü¤µ¤ì¤¿¤Û¤¦¤¬Îɤ¤¤Ç¤·¤ç¤¦¡£¤½¤ì¤«¤é¡¢¥¤¥ó¥¹¥È¡¼¥ë»þ¤Î̾Á°¤âÊѤ¨¤¿Êý¤¬Îɤ¤¤«¤â¤·¤ì¤Þ¤»¤ó¡Ê makefile Ãæ¤ÎÊÑ¿ô "ME" ¤Ï¥³¥ó¥Ñ¥¤¥ë»þ¤ËÀ¸À®¤¹¤ë¼Â¹Ô¥Õ¥¡¥¤¥ë̾¤Ç¤¹¡£¤³¤ÎÉôʬ¤Ï RPC .spec ¥Õ¥¡¥¤¥ë¤Î "name" ¤ËÁêÅö¤·¤Þ¤¹¡£Ç¤°Õ¤Î̾Á°¤Ç¥³¥ó¥Ñ¥¤¥ë¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡Ë¡£xstrings.txt ¤Ç¤Ï·Ù¹ð¥á¥Ã¥»¡¼¥¸¤ä¥³¥Þ¥ó¥É¤Î¥ê¥¹¥È¡¢É½¼¨¥á¥Ã¥»¡¼¥¸¤ÎÄ´À°¤¬²Äǽ¤Ç¤¹¡£¤Þ¤¿¡¢xstrings.txt ¤Ë´Þ¤Þ¤ì¤ë2¤Ä¤á¤ÎÈÖ¹æ¤Ï XPAT ¤È rkdet.c¡Ê¤È mkfil.pl¡Ë¤ÇÄêµÁ¤µ¤ì¤Æ¤¤¤ë°Û¤Ê¤Ã¤¿¥Ñ¥¿¡¼¥ó¤Ç¥³¥ó¥Ñ¥¤¥ë¤¹¤ë»þ¤ËÍѤ¤¤Þ¤¹¡£¥³¥ó¥Ñ¥¤¥ë¤Ë¤è¤Ã¤ÆºîÀ®¤µ¤ì¤¿¼Â¹Ô¥Õ¥¡¥¤¥ë¤Ï¡¢ÀßÄê»þ¤Î¾õ¶·¤Ë¤ª¤¤¤Æ°Û¤Ê¤Ã¤¿Ä¹¤µ¤ä¥Á¥§¥Ã¥¯¥µ¥à¤ò»ý¤Ä¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£ÉÔÀµ¥¢¥¯¥»¥¹¼Ô¤¬²òÀϤò»î¤ß¤è¤¦¤È¤·¤Æ¤â¥Ñ¥¿¡¼¥ó¥Þ¥Ã¥Á¤È¤¤¤Ã¤¿¼êË¡¤Ç¤Ï²òÀϤµ¤»¤Þ¤»¤ó¡£

¡¡¤³¤Î¥×¥í¥°¥é¥à¤ò²þÎɤ¹¤ë¤³¤È¤Ç softdog.o ¤È¤¤¤Ã¤¿´Æ»ë¥â¥¸¥å¡¼¥ë¤È¤·¤Æ¡¢°Û¾ï¸¡½Ð»þ¤Ë¥ê¥Ö¡¼¥È¤ò¹Ô¤¦¤è¤¦¤Ë¤¹¤ë¤³¤È¤â½ÐÍè¤ë¤Ç¤·¤ç¤¦¡£¹Í¤¨²á¤®¤«¤â¤·¤ì¤Þ¤»¤ó¤¬¡¢´Æ»ë¥â¥¸¥å¡¼¥ë¤Ë¤è¤Ã¤Æ cookie ¤ä¥Á¥ã¥ì¥ó¥¸¥Ñ¥¹¥ï¡¼¥É¡¢¤½¤·¤Æ LIDS ¤È¤¤¤Ã¤¿¥Ñ¥Ã¥±¡¼¥¸¤Î¥í¥Ã¥¯¤Þ¤Ç½ÐÍè¤ë¤è¤¦¤Ë¤Ê¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡£LIDS ¤Ï /proc/ ¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤«¤é¥×¥í¥°¥é¥à¾ðÊó¤ò¸«¤¨¤Ê¤¯¤µ¤»¤ë¤³¤È¤Ë¤â»È¤ï¤ì¤ë¤«¤é¤Ç¤¹¡£

Other Security Systems - ¤½¤Î¾¤Î¥»¥­¥å¥ê¥Æ¥£¡¦¥·¥¹¥Æ¥à

¡¡LIDS - LIDS ¤Ï Linux Áȹþ·¿¸¡½Ð¥·¥¹¥Æ¥à¤Ç¤¹¡£¥â¥¸¥å¡¼¥ë¤ä¥Þ¥¦¥ó¥È¥Ý¥¤¥ó¥È¤ò¸ÇÄꤹ¤ë¥«¡¼¥Í¥ë¤Î¥Ñ¥Ã¥Á¤Ç¤¹¡£LIDS ¤Î¾ðÊó¤Ï¤³¤Á¤é¤ò¤´Í÷²¼¤µ¤¤¡£http://www.soaring-bird.com.cn/oss_proj/lids/

¡¡Bastille*6 Linux ¤Ï¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤äµ¡Ç½¤ò̵¸ú²½¤¹¤ë¤³¤È¤Ë¤è¤Ã¤Æ Linux ¥·¥¹¥Æ¥à¤ò°ú¤­Äù¤á¤ë¥¹¥¯¥ê¥×¥È¤Ç¤¹¡£¶Ëü¤Ë¸À¤¨¤Ð¡¢Æ³Æþ¤Ë¤è¤Ã¤Æ¹çˡŪ¤Êºî¶È¤ò˸¤²¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¤·¡¢¤à¤·¤í¥í¥°Êݸ¥Û¥¹¥È¤ä¥Õ¥¡¥¤¥ë¥µ¡¼¥Ð¤È¤¤¤Ã¤¿³«È¯¥·¥¹¥Æ¥à¤Ë¤Õ¤µ¤ï¤·¤¤¤Ç¤·¤ç¤¦¡£
¡¡Bastille ¤Î¾ðÊó¤Ï¤³¤Á¤é¤«¤é¡£ http://www.bastille-linux.org/

¡¡PortSentry ¤Ï¥·¥¹¥Æ¥à¾å¤Î TCP ¤È UDP ¥×¥í¥È¥³¥ë¤Ë¤è¤ë¥¢¥¯¥»¥¹¤Î¥í¥°¤ò¤È¤ê¡¢¥ª¥×¥·¥ç¥ó¤È¤·¤ÆÄÌ¿®¤ò¼×ÃǤ¹¤ëµ¡Ç½¤âÈ÷¤¨¤Æ¤¤¤Þ¤¹¡£¤Þ¤¿¡¢¹¶·â¤ò¼õ¤±¤ä¤¹¤¤¥µ¡¼¥Ó¥¹¡Ê¸Å¤¤¥Ð¡¼¥¸¥ç¥ó¤Î imap ¤ä ftp ¡Ë¤Î¸¡ºº¤ä¥È¥í¥¤¤ÎÌÚÇÏ(Back Orifice ¤ä Netbus ¤Ê¤É)¤Î¸¡½Ð¤âÈ÷¤¨¤Æ¤¤¤Þ¤¹¡£
¡¡PortSentry ¤Ï http://www.psionic.com ¤ò¤´Í÷²¼¤µ¤¤¡£

Caveat - ·Ù¹ð

¡¡¸¡ººÂоݤȤʤäƤ¤¤ë¥Õ¥¡¥¤¥ë¤Î¹¹¿·¤ä¥¢¥Ã¥×¥°¥ì¡¼¥É¤ÎÁ°¤Ë rkdet ¤òÄä»ß¤·¤Æ¤¯¤À¤µ¤¤¡Ê¤½¤¦¤·¤Ê¤¤¤È¼«Æ°¤Ç¥Í¥Ã¥È¥ï¡¼¥¯¤¬ÀÚÃǤµ¤ì¤¿¤ê¥µ¡¼¥Ð¤¬Ää»ß¤·¤Þ¤¹¡Ë¡£ºî¶È¸å¤Ë rkdet ¥µ¡¼¥Ó¥¹¤òºÆ³«¤·¤Æ¤¯¤À¤µ¤¤¡£

¡¡¼«Æ°¥¢¥Ã¥×¥Ç¡¼¥È¤ò¹Ô¤¦¥·¥¹¥Æ¥à¤ò¼ÂÁõ¤·¤Æ¤¤¤ë¾ì¹ç¤Ë¤Ï¡¢ÆÃÊ̤ËÂбþ¤¹¤ë¼êÃʤòÀߤ±¤Æ¤¯¤À¤µ¤¤¡Ê¤¿¤È¤¨¤Ð apt ¥µ¡¼¥Ó¥¹¤ò»È¤Ã¤Æ¼«Æ°¥¢¥Ã¥×¥°¥ì¡¼¥É¤ò¹Ô¤¦¤è¤¦¤Ê¥·¥¹¥Æ¥à¤Ç¤Ï¡¢¹¹¿·¤¹¤ëÁ°¤Ë rkdet ¤òÄä»ß¤·¡¢¹¹¿·¸å¤Ë rkdet ¤òºÆ³«¤¹¤ë¤è¤¦¤Ë¤·¤Ê¤¯¤Æ¤Ï¤¤¤±¤Þ¤»¤ó¡Ë¡£

¡¡


*1 ¥·¥¹¥Æ¥à¤ËÆþ¤ê¹þ¤ó¤Ç¥×¥í¥»¥¹¤ò±£Êä·¤¿¤ê¥Ð¥Ã¥¯¥É¥¢¤òÉßÀߤ·¤¿¤êÇ˲õ³èÆ°¤òÌÜŪ¤È¤·¤¿¥·¥¹¥Æ¥à²þãâ¥Ä¡¼¥ë·²¤Î¤³¤È¤Ç¤¹
*2 PDF¡Ä¤ß¤ó¤Ê¤¬ÊØÍø¤Ë»È¤¨¤ë¤è¤¦Ãøºî¸¢¤òÊü´þ¤·¤¿¥½¥Õ¥È¥¦¥§¥¢¤ò»Ø¤·¤Þ¤¹
*3 °­°Õ¤Î¤¢¤ë¥Ï¥Ã¥«¡¼
*4 ¥½¡¼¥¹¤òŸ³«¤·¤¿¥Ç¥£¥ì¥¯¥È¥ê¤Ë¤¢¤ë xfiles.txt
*5 ¥×¥í¥ß¥¹¥­¥ã¥¹¡¦¥â¡¼¥É¡á¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Ç¥Ñ¥±¥Ã¥È¤ò¼ý½¸¤¹¤ëÆ°ºî¥â¡¼¥É
*6 ¥Ð¥¹¥Á¡¼¥æ

¥È¥Ã¥×   ÊÔ½¸ Åà·ë º¹Ê¬ ¥Ð¥Ã¥¯¥¢¥Ã¥× źÉÕ Ê£À½ ̾Á°Êѹ¹ ¥ê¥í¡¼¥É   ¿·µ¬ °ìÍ÷ ñ¸ì¸¡º÷ ºÇ½ª¹¹¿·   ¥Ø¥ë¥×   ºÇ½ª¹¹¿·¤ÎRSS
Last-modified: Tue, 19 Jul 2005 17:38:28 JST (6849d)