๊ธ€ ์ž‘์„ฑ์ž: heogi

์ ๊ฒ€ ๋‚ด์šฉ

  • ์‹œ์Šคํ…œ ์ •์ฑ…์— root ๊ณ„์ •์˜ ์›๊ฒฉ ํ„ฐ๋ฏธ๋„ ์ ‘์†์ฐจ๋‹จ ์„ค์ •์ด ์ ์šฉ๋˜์–ด ์žˆ๋Š”์ง€ ์ ๊ฒ€

 

์ ๊ฒ€ ๋ชฉ์ 

  • ๊ด€๋ฆฌ์ž ๊ณ„์ • ํƒˆ์ทจ๋กœ ์ธํ•œ ์‹œ์Šคํ…œ ์žฅ์•…์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ์™ธ๋ถ€ ๋น„์ธ๊ฐ€์ž์˜ root ๊ณ„์ • ์ ‘๊ทผ ์‹œ๋„๋ฅผ ์›์ฒœ์ ์œผ๋กœ ์ฐจ๋‹จํ•˜๊ธฐ ์œ„ํ•จ

 

๋ณด์•ˆ์œ„ํ˜‘

  • root ๊ณ„์ •์€ ์šด์˜์ฒด์ œ์˜ ๋ชจ๋“  ๊ธฐ๋Šฅ์„ ์„ค์ • ๋ฐ ๋ณ€๊ฒฝ์ด ๊ฐ€๋Šฅํ•˜์—ฌ(ํ”„๋กœ์„ธ์Šค, ์ปค๋„ ๋ณ€๊ฒฝ ๋“ฑ) root ๊ณ„์ •์„ ํƒˆ์ทจํ•˜์—ฌ ์™ธ๋ถ€์—์„œ ์›๊ฒฉ์„ ์ด์šฉํ•œ ์‹œ์Šคํ…œ ์žฅ์•… ๋ฐ ๊ฐ์ข… ๊ณต๊ฒฉ์œผ๋กœ(๋ฌด์ž‘์œ„ ๋Œ€์ž… ๊ณต๊ฒฉ) ์ธํ•œ root ๊ณ„์ • ์‚ฌ์šฉ ๋ถˆ๊ฐ€ ์œ„ํ˜‘

 

ํŒ๋‹จ๊ธฐ์ค€

ํŒ๋‹จ๊ธฐ์ค€
์–‘ํ˜ธ ์›๊ฒฉ ํ„ฐ๋ฏธ๋„ ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ฑฐ๋‚˜, ์‚ฌ์šฉ ์‹œ root ์ง์ ‘ ์ ‘์†์„ ์ฐจ๋‹จํ•œ ๊ฒฝ์šฐ
์ทจ์•ฝ ์›๊ฒฉ ํ„ฐ๋ฏธ๋„ ์„œ๋น„์Šค ์‚ฌ์šฉ ์‹œ root ์ง์ ‘ ์ ‘์†์„ ํ—ˆ์šฉํ•œ ๊ฒฝ์šฐ

 

์กฐ์น˜๋ฐฉ๋ฒ•

  • ์›๊ฒฉ ์ ‘์† ์‹œ root ๊ณ„์ •์œผ๋กœ ๋ฐ”๋กœ ์ ‘์†ํ•  ์ˆ˜ ์—†๋„๋ก ์„ค์ • ํŒŒ์ผ ์ˆ˜์ •
OS ๋ณ„ ์ ๊ฒ€ ํŒŒ์ผ ์œ„์น˜ ๋ฐ ์ ๊ฒ€ ๋ฐฉ๋ฒ•
Solaris [Telnet]
#vim /etc/default/login
CONSOLE=/dev/console ๋‚ด์šฉ์„ ์ฃผ์„ ํ•ด์ œ ๋˜๋Š” ์ถ”๊ฐ€

[SSH]
#vim /etc/ssh/sshd_config
PermitRootLogin no ๋‚ด์šฉ์„ ์ฃผ์„ ํ•ด์ œ ๋˜๋Š” ์ถ”๊ฐ€
Linux [Telnet]
#vim /etc/securetty
pts/0 ~ pts/x ๋‚ด์šฉ์„ ์ฃผ์„ ์ฒ˜๋ฆฌ ๋˜๋Š” ์‚ญ์ œ
#vim /etc/pam.d/login
auth required /lib/pam.d/pam_securetty.so ๋‚ด์šฉ์„ ์ฃผ์„ ํ•ด์ œ ๋˜๋Š” ์ถ”๊ฐ€

๐Ÿ‘พ /etc/securetty : Telnet ์ ‘์† ์‹œ root ์ ‘๊ทผ ์ œํ•œ ์„ค์ • ํŒŒ์ผ
"/etc/securetty" ํŒŒ์ผ ๋‚ด pts/x ๋‚ด์šฉ์ด ์กด์žฌํ•˜๋Š” ๊ฒฝ์šฐ PAM ๋ชจ๋“ˆ ์„ค์ •๊ณผ ๊ด€๊ณ„ ์—†์ด ๊ฐ€์ƒ ํ„ฐ๋ฏธ๋„์„ ํ†ตํ•ด root ๊ณ„์ •
์ ‘์†์„ ํ—ˆ์šฉํ•˜๋ฏ€๋กœ pts/x ๋‚ด์šฉ ์ œ๊ฑฐ ํ•„์š”

[SSH]
#vim /etc/ssh/sshd_config
PermitRootLogin no ๋‚ด์šฉ์„ ์ฃผ์„ ํ•ด์ œ ๋˜๋Š” ์ถ”๊ฐ€
AIX [Telnet]
#vim /etc/security/user
rlogin=false ๋‚ด์šฉ์„ ์ฃผ์„ ํ•ด์ œ ๋˜๋Š” ์ถ”๊ฐ€

[SSH]
#vim /etc/ssh/sshd_config
PermitRootLogin no ๋‚ด์šฉ์„ ์ฃผ์„ ํ•ด์ œ ๋˜๋Š” ์ถ”๊ฐ€
HP-UX [Telnet]
#vim /etc/securetty
console ๋‚ด์šฉ์„ ์ฃผ์„ ํ•ด์ œ ๋˜๋Š” ์ถ”๊ฐ€

[SSH]
#vim /etc/ssh/sshd_config
PermitRootLogin no ๋‚ด์šฉ์„ ์ฃผ์„ ํ•ด์ œ ๋˜๋Š” ์ถ”๊ฐ€

 

Linux - Telnet ์กฐ์น˜ ํ™”๋ฉด 

  • ์กฐ์น˜ ์ „ root ์ ‘์†์ด ๊ฐ€๋Šฅํ•œ ํ™”๋ฉด

  • /etc/pam.d/login ํŒŒ์ผ ์ˆ˜์ •

  • /etc/securetty ํŒŒ์ผ ์ˆ˜์ •

  • root ์ ‘์† ์‹œ ์‹คํŒจํ•˜๋Š” ํ™”๋ฉด

Linux - SSH ์กฐ์น˜ ํ™”๋ฉด 

  • /etc/ssh/sshd_config ํŒŒ์ผ ์„ค์ •
    PermitRootLogin prohibit-password๊ฐ€ ๋””ํดํŠธ์ด๋‹ค. ํŒจ์Šค์›Œ๋“œ๋กœ๋Š” ์ ‘์†์ด ๋ถˆ๊ฐ€ํ•˜๊ณ  ํ‚ค ํŒŒ์ผ๋กœ๋งŒ ์ ‘์†์ด ๊ฐ€๋Šฅํ•˜๊ฒŒํ•˜๋Š” ์˜ต์…˜์ด์ง€๋งŒ
    root๋กœ์˜ ์ ‘์† ์ž์ฒด๋ฅผ ์ฐจ๋‹จํ•˜๋Š”๊ฒŒ ํ•ญ๋ชฉ์˜ ์š”๊ตฌ์‚ฌํ•ญ์œผ๋กœ ์ƒ๊ฐ๋˜์–ด PermitRootLogin No ๋กœ ๋ช…์‹œํ•ด์ค˜์•ผํ• ๊ฑฐ๊ฐ™๋‹ค.
PermitRootLogin ์˜ต์…˜
Yes Root๋กœ ์ ‘์† ํ—ˆ์šฉ
No Root๋กœ ์ ‘์† ์ฐจ๋‹จ
Prohibit-password Root๋กœ ํŒจ์Šค์›Œ๋“œ ์ ‘์†์€ ์ฐจ๋‹จ, ํ‚ค ํŒŒ์ผ๋กœ ์ ‘์†์€ ํ—ˆ์šฉ

์ ๊ฒ€ ์Šคํฌ๋ฆฝํŠธ

#1 ๊ณ„์ •๊ด€๋ฆฌ > root ๊ณ„์ • ์›๊ฒฉ ์ ‘์† ์ œํ•œ
SSH_SERVICE_STATUS=$(service ssh status | grep Active | awk '{print $2}')

# SSH Service ๋™์ž‘ ํ™•์ธ
if [ $SSH_SERVICE_STATUS == "active" ]; then
    echo "SSH SERVICE IS ACTIVE"
        #csse insensitive ํ™•์ธ ํ•„์š”
        if [ "$(cat /etc/ssh/sshd_config | grep ^PermitRootLogin -m 1 | awk '{print $2}')" == "no" ]; then
            echo "[์–‘ํ˜ธ] ssh root ์ ‘์†์ด ๋ถˆ๊ฐ€ํ•ฉ๋‹ˆ๋‹ค."
        else
            echo "[์ทจ์•ฝ] ssh root ์ ‘์† ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค."
        fi
else
    echo "SSH SERVICE IS NOT ACTIVE"
fi
#Telnet Service ํ™•์ธ
if [ -z $(grep "^pts/\?" /etc/securetty) ]; then
    echo "[์–‘ํ˜ธ] Telnet root ์ ‘์†์ด ๋ถˆ๊ฐ€ํ•ฉ๋‹ˆ๋‹ค."
else
    echo "[์ทจ์•ฝ] Telnet root ์ ‘์†์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค."
fi