{"id":20,"date":"2008-02-21T09:27:43","date_gmt":"2008-02-21T00:27:43","guid":{"rendered":"https:\/\/hiro7216.mydns.jp\/blog\/?p=20"},"modified":"2024-01-30T23:39:54","modified_gmt":"2024-01-30T14:39:54","slug":"%e3%82%a2%e3%82%bf%e3%83%83%e3%82%af%e3%81%ab%e5%af%be%e5%87%a6%e3%81%99%e3%82%8b%e3%83%ab%e3%83%bc%e3%83%ab%e3%82%92%e8%bf%bd%e5%8a%a0","status":"publish","type":"post","link":"https:\/\/hiro7216.mydns.jp\/blog\/?p=20","title":{"rendered":"\u30a2\u30bf\u30c3\u30af\u306b\u5bfe\u51e6\u3059\u308b\u30eb\u30fc\u30eb\u3092\u8ffd\u52a0"},"content":{"rendered":"\n<p>\u7279\u5b9a\u306e\u30dd\u30fc\u30c8\u306b\u81ea\u52d5\u3067\u7e70\u308a\u8fd4\u3057\u30a2\u30af\u30bb\u30b9\u3057ID\u3084PASS\u3092\u76d7\u3082\u3046\u3068\u3059\u308b\u884c\u70ba\u304c\u65e5\u5e38\u7684\u306b\u8d77\u304d\u3066\u3044\u307e\u3059\u3002<br>\u3053\u308c\u306f\u6c17\u4ed8\u304b\u306a\u304f\u3066\u3082\u30cd\u30c3\u30c8\u306b\u7e4b\u3044\u3067\u3044\u308b\u4ee5\u4e0a\u306f\u3069\u306a\u305f\u3082\u7d4c\u9a13\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3067\u3059\u3002<br>\u901a\u5e38\u5229\u7528\u3067\u306f\u30eb\u30fc\u30bf\u30fc\u7d4c\u7531\u3067\u3042\u308c\u3070\u30d5\u30a9\u30ef\u30fc\u30c7\u30a3\u30f3\u30b0\u306e\u5b9b\u5148\u304c\u7121\u3044\u306e\u3067\u30d1\u30b1\u30c3\u30c8\u304c\u7834\u68c4\u3055\u308c\u7279\u306b\u554f\u984c\u306f\u3042\u308a\u307e\u305b\u3093\u3002<br>\uff08\u507d\u88c5\u30d1\u30b1\u30c3\u30c8\u3060\u3068\u554f\u984c\u306b\u306a\u308a\u307e\u3059\uff09<\/p>\n\n\n\n<p>\u3053\u3053\u3067\u554f\u984c\u306b\u306a\u308b\u306e\u306f\u30b5\u30fc\u30d0\u30fc\u3092\u516c\u958b\u3055\u308c\u3066\u3044\u308b\u65b9\u3067\u3059\u3002<br>\u30b5\u30fc\u30d0\u30fc\u3092\u30eb\u30fc\u30bf\u30fc\u306e\u5916\u5074\u306b\u8a2d\u7f6e\u3059\u308b\u306e\u306f\u3082\u3061\u308d\u3093\u3067\u3059\u304c<br>\u9759\u7684NAT\u3067\u7279\u5b9a\u306e\u30dd\u30fc\u30c8\u3092\u516c\u958b\u3057\u3066\u3044\u308b\u5834\u5408\u3082\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u8a66\u3057\u306bssh\u306e\u30dd\u30fc\u30c8\u3092\u958b\u3051\u3066\u307f\u308b\u3068\u304b\u306a\u308a\u306e\u30a2\u30bf\u30c3\u30af\u304c\u3042\u308b\u3053\u3068\u304c\u30ed\u30b0\u304b\u3089\u5206\u304b\u308b\u3068\u601d\u3044\u307e\u3059\u3002<br>IP\u30d5\u30a3\u30eb\u30bf\u30fc\u3067\u30a2\u30bf\u30c3\u30af\u306e\u591a\u3044\u56fd\u306e\u30a2\u30af\u30bb\u30b9\u3092\u906e\u65ad\u3059\u308c\u3070\u304b\u306a\u308a\u6e1b\u308a\u307e\u3059\u304c<br>\u305d\u308c\u3067\u3082\u30a2\u30bf\u30c3\u30af\u306e\u5f62\u8de1\u306f\u30ed\u30b0\u306b\u6b8b\u3063\u305f\u308a\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u3053\u308c\u3089\u306e\u30a2\u30bf\u30c3\u30af\u3092iptables\u3067\u30d6\u30ed\u30c3\u30af\u3059\u308b\u306e\u304c\u4eca\u56de\u306e\u76ee\u7684\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u6642\u9593\u5f53\u305f\u308a\u306e\u30a2\u30af\u30bb\u30b9\u56de\u6570\u3067\u5236\u9650\u3059\u308b\u70ba\u306biptables\u306erecent\u6a5f\u80fd\u3092\u4f7f\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u203b\u4ee5\u4e0b\u306e\u30b5\u30a4\u30c8\u3092\u53c2\u8003\u306b\u8a2d\u5b9a\u3057\u307e\u3057\u305f\u3002<br><a href=\"https:\/\/www.netfilter.org\/documentation\/HOWTO\/netfilter-extensions-HOWTO-3.html#ss3.16\" target=\"_blank\" rel=\"noopener noreferrer\">Netfilter Extensions HOWTO: New netfilter matches<\/a><\/p>\n\n\n\n<p>\u57fa\u672c\u7684\u306a\u69cb\u6587\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u66f8\u304f\u3088\u3046\u3067\u3059\u3002<\/p>\n\n\n\n<p># iptables -A FORWARD -m recent &#8211;name badguy &#8211;rcheck &#8211;seconds 60 -j DROP<br># iptables -A FORWARD -p tcp -i eth0 &#8211;dport 139 -m recent &#8211;name badguy &#8211;set -j DROP<\/p>\n\n\n\n<p>\u30aa\u30d7\u30b7\u30e7\u30f3\u306e\u8aac\u660e\u3092\u8aad\u3093\u3067\u307f\u308b\u3068\u8272\u3005\u3068\u8aac\u660e\u304c\u66f8\u3044\u3066\u3042\u308a\u307e\u3059\u306d\u3002<br>\u81ea\u5206\u306e\u74b0\u5883\u306b\u5408\u308f\u305b\u3066\u66f8\u304d\u63db\u3048\u3066\u307f\u307e\u3057\u3087\u3046\u3002<\/p>\n\n\n\n<p>iptables -A INPUT -p tcp -i eth1 &#8211;dport 22 -m recent &#8211;name SSH -m state &#8211;state NEW &#8211;set<br>iptables -A INPUT -m recent &#8211;name SSH -i eth1 -p tcp &#8211;dport 22 -m state &#8211;state NEW &#8211;update &#8211;seconds 60 &#8211;hitcount 6 &#8211;rttl -j DROP<\/p>\n\n\n\n<p>\u3053\u306e\u8a2d\u5b9a\u5185\u5bb9\u306feth1\u30c7\u30d0\u30a4\u30b9\u306eTCP22\u756a\u30dd\u30fc\u30c8\u307860\u79d2\u9593\u306b\uff16\u56de\u4ee5\u4e0a\u30a2\u30af\u30bb\u30b9\u304c\u3042\u3063\u305f\u30db\u30b9\u30c8\u3092\u62d2\u5426\u3059\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<p>&#8211;name SSH \u30eb\u30fc\u30eb\u306e\u540d\u524d\u306f\u4ed6\u306e\u30eb\u30fc\u30eb\u3068\u91cd\u8907\u3057\u306a\u3044\u540d\u524d\u306a\u3089\u306a\u3093\u3067\u3082\u826f\u3044\u3088\u3046\u3067\u3059\u3002<br>-i\u30aa\u30d7\u30b7\u30e7\u30f3\u306eeth1\u3068\u66f8\u3044\u3066\u3042\u308b\u90e8\u5206\u306f\u81ea\u5206\u306e\u74b0\u5883\u306eWAN\u5074\u306b\u63a5\u7d9a\u3055\u308c\u3066\u3044\u308b\u30c7\u30d0\u30a4\u30b9\u306b\u66f8\u304d\u63db\u3048\u307e\u3059\u3002<br>&#8211;dport 22 \u306e22\u306f\u898f\u5236\u306e\u5bfe\u8c61\u3068\u3059\u308b\u30dd\u30fc\u30c8\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002<br>&#8211;seconds 60 \u6700\u5f8c\u306e\u30a2\u30af\u30bb\u30b9\u304b\u3089\u30ed\u30b0\u3092\u3055\u304b\u306e\u307c\u308b\u79d2\u6570\u306e\u7bc4\u56f2\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002\u3064\u307e\u308a\u300c\u25cb\u79d2\u9593\u306e\u9593\u306b\u300d\u3068\u306a\u308a\u307e\u3059\u3002<br>&#8211;hitcount 6 \u4e0a\u306e&#8211;seconds\u3067\u8a2d\u5b9a\u3057\u305f\u6642\u9593\u30ed\u30b0\u306e\u4e2d\u306b\u4f55\u56de\u4ee5\u4e0a\u30d2\u30c3\u30c8\u3059\u308b\u3082\u306e\u3092\u5bfe\u8c61\u306b\u3059\u308b\u304b\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u3053\u308c\u306f\u4e00\u5ea6\u5b9f\u884c\u3057\u3066\u3082reboot\u3059\u308b\u3068\u8a2d\u5b9a\u306f\u6d88\u3048\u3066\u3057\u307e\u3044\u307e\u3059\u3002<br>\u4ed6\u306eiptables\u306e\u8a2d\u5b9a\u3068\u540c\u3058\u3088\u3046\u306b\u8d77\u52d5\u6642\u7b49\u306b\u5b9f\u884c\u3055\u308c\u308b\u3088\u3046\u306b\u8a2d\u5b9a\u3092\u884c\u3063\u3066\u4e0b\u3055\u3044\u3002<br>\u203b\u500b\u4eba\u7684\u306b\u306f\u8d77\u52d5\u6642\u306b\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u8aad\u307f\u8fbc\u3093\u3067\u307e\u3059\u304ciptables\u306e\u8a2d\u5b9a\u3092\u4e00\u62ec\u3057\u3066<br>\u3000\u3000iptables-save\u3001iptables-restore\u306a\u3069\u3067\u884c\u3063\u3066\u3082\u826f\u3044\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u6700\u5f8c\u306b\u30fb\u30fb\u30fb<br>\u3053\u306e\u6a5f\u80fd\u3067\u306f\u3086\u3063\u304f\u308a\u3068\u7e70\u308a\u8fd4\u3055\u308c\u308b\u30a2\u30bf\u30c3\u30af\u306b\u306f\u5bfe\u5fdc\u51fa\u6765\u307e\u305b\u3093\u3002<br>\u4ed6\u306e\u6a5f\u80fd\u3068\u7d44\u307f\u5408\u308f\u305b\u3066\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u9ad8\u3081\u308b\u3053\u3068\u3067\u9ad8\u3044\u52b9\u679c\u3092\u767a\u63ee\u51fa\u6765\u308b\u6a5f\u80fd\u3060\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7279\u5b9a\u306e\u30dd\u30fc\u30c8\u306b\u81ea\u52d5\u3067\u7e70\u308a\u8fd4\u3057\u30a2\u30af\u30bb\u30b9\u3057ID\u3084PASS\u3092\u76d7\u3082\u3046\u3068\u3059\u308b\u884c\u70ba\u304c\u65e5\u5e38\u7684\u306b\u8d77\u304d\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306f\u6c17\u4ed8\u304b\u306a\u304f\u3066\u3082\u30cd\u30c3\u30c8\u306b\u7e4b\u3044\u3067\u3044\u308b\u4ee5\u4e0a\u306f\u3069\u306a\u305f\u3082\u7d4c\u9a13\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3067\u3059\u3002\u901a\u5e38\u5229\u7528\u3067\u306f\u30eb\u30fc\u30bf\u30fc\u7d4c\u7531\u3067\u3042\u308c\u3070\u30d5\u30a9\u30ef\u30fc\u30c7\u30a3\u30f3\u30b0\u306e &hellip; <a href=\"https:\/\/hiro7216.mydns.jp\/blog\/?p=20\" class=\"more-link\">\u7d9a\u304d\u3092\u8aad\u3080 <span class=\"screen-reader-text\">\u30a2\u30bf\u30c3\u30af\u306b\u5bfe\u51e6\u3059\u308b\u30eb\u30fc\u30eb\u3092\u8ffd\u52a0<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,287],"tags":[166],"class_list":["post-20","post","type-post","status-publish","format-standard","hentry","category-linkstation","category-nas","tag-linkstation"],"_links":{"self":[{"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=\/wp\/v2\/posts\/20","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20"}],"version-history":[{"count":0,"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=\/wp\/v2\/posts\/20\/revisions"}],"wp:attachment":[{"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hiro7216.mydns.jp\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}