Born2beRoot - KimTaebin-ai/study_posts GitHub Wiki

ํ‰๊ฐ€์ง€

ํ‰๊ฐ€์ง€ ํ•œ๊ตญ์–ด ๋งํฌ

ํ‰๊ฐ€ ๋ฐฉ๋ฒ• ๋ฐ ๋ช…๋ น์–ด

ํ•„์š” ๊ฐœ๋… ๋ฐ ํ•™์Šต ๋‚ด์šฉ

์„ค์น˜

๋ณด๋„ˆ์Šค ์—†๋Š” ๊ธฐ๋ณธ์„ธํŒ…

๋ณด๋„ˆ์Šค ์›Œํ”„๋ถ€๋ถ„๋งŒ

๊ณผ์ œ ํ•ด์„

OS ์„ค์น˜ ๋ฐ ๊ธฐ๋ณธ ์„ค์ •

GUI๋ฅผ ์ œ๊ณตํ•˜๋Š” ์„œ๋น„์Šค(X.org ๋“ฑ)๋Š” ์„ค์น˜ํ•ด์„œ๋Š” ์•ˆ๋œ๋‹ค.

LVM์„ ์‚ฌ์šฉํ•ด์„œ ์ ์–ด๋„ 2๊ฐœ์˜ ์•”ํ˜ธํ™”๋œ ํŒŒํ‹ฐ์…˜์„ ์ƒ์„ฑํ•ด์•ผ ํ•œ๋‹ค.

image

SSH

SSH ์„œ๋น„์Šค๊ฐ€ ๋™์ž‘์ค‘์ด๊ณ , 4242 port๋กœ๋งŒ ์—ด๋ ค์žˆ์–ด์•ผ ํ•œ๋‹ค.

SSH ์„œ๋น„์Šค๋กœ root์— ์ ‘์†ํ•  ์ˆ˜ ์žˆ์œผ๋ฉด ์•ˆ๋œ๋‹ค.

๋™๋ฃŒ ํ‰๊ฐ€ ์ค‘์— ์ƒˆ๋กœ์šด ์œ ์ €๋ฅผ ๋งŒ๋“ค์–ด์„œ SSH๋กœ ์ ‘์†ํ•˜๋Š” ๊ณผ์ •์— ๋Œ€ํ•ด ํ‰๊ฐ€ ๋ฐ›์„ ๊ฒƒ์ด๋‹ค. ๋”ฐ๋ผ์„œ ์ƒˆ๋กœ์šด ์œ ์ €๋ฅผ ๋งŒ๋“ค๊ณ , SSH๋กœ ๊ทธ ์œ ์ €์— ๋กœ๊ทธ์ธ ํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•ด์„œ ์•Œ์•„๋‘ฌ์•ผ ํ•œ๋‹ค.

๋ฐฉํ™”๋ฒฝ - UFW

UFW๋ฅผ ์‚ฌ์šฉํ•ด์„œ 4242 port๋งŒ ์—ด์–ด๋‘๋„๋ก ์„ค์ •ํ•œ๋‹ค.

๊ฐ€์ƒ ๋จธ์‹ ์„ ์‹คํ–‰ํ–ˆ์„ ๋•Œ, ๋ฐฉํ™”๋ฒฝ์ด ํ•ญ์ƒ ์ผœ์ ธ ์žˆ์–ด์•ผ ํ•œ๋‹ค.

CentOS์˜ ๊ฒฝ์šฐ UFW๋ฅผ ์„ค์น˜ํ•ด์„œ ๊ธฐ๋ณธ ๋ฐฉํ™”๋ฒฝ์œผ๋กœ ์„ค์ •ํ•ด์ค˜์•ผ ํ•œ๋‹ค.

๋น„๋ฐ€๋ฒˆํ˜ธ ์ •์ฑ…

๋งค 30์ผ๋งˆ๋‹ค ํŒŒ๊ธฐ๋˜์–ด์•ผ ํ•œ๋‹ค.

๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณ€๊ฒฝ์€ ๋ฐ”๋กœ ์ง์ „ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณ€๊ฒฝ ๋‚ ์งœ๋ฅผ ๊ธฐ์ค€์œผ๋กœ 2์ผ ์ดํ›„๋ถ€ํ„ฐ ๊ฐ€๋Šฅํ•ด์•ผ ํ•œ๋‹ค. (์›๋ฌธ : The minimum number of days allowed before the modification of a password will be set to 2.)

์œ ์ €๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ ํŒŒ๊ธฐ์ผ 7์ผ ์ „์— ๊ฒฝ๊ณ  ๋ฉ”์„ธ์ง€๋ฅผ ๋ฐ›์•„์•ผ ํ•œ๋‹ค.

10 ๊ธ€์ž ์ด์ƒ, ๋Œ€๋ฌธ์ž ๋ฐ ์ˆซ์ž ํฌํ•จ, ์—ฐ์†๋œ ๋™์ผํ•œ ๊ธ€์ž๋Š” 3๊ธ€์ž ๊นŒ์ง€๋งŒ ํ—ˆ์šฉ.

๋น„๋ฐ€๋ฒˆํ˜ธ์— ์œ ์ € ์ด๋ฆ„์ด ํฌํ•จ๋˜์–ด์„œ๋Š” ์•ˆ๋œ๋‹ค.

๋ฐ”๋กœ ์ด์ „์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ์— ํฌํ•จ๋˜์–ด ์žˆ์ง€ ์•Š์€ ๋ฌธ์ž๊ฐ€ ์ตœ์†Œ 7๊ธ€์ž ์ด์ƒ ์กด์žฌํ•ด์•ผ ํ•œ๋‹ค - ๋‹จ ์ด ๊ทœ์น™์€ root ์œ ์ €์—๋Š” ํ•ด๋‹นํ•˜์ง€ ์•Š๋Š”๋‹ค.

Root ์œ ์ €๋„ ์œ„์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ ์ •์ฑ…์„ ๋”ฐ๋ผ์•ผ ํ•œ๋‹ค.

*๋น„๋ฐ€๋ฒˆํ˜ธ ์ •์ฑ…์„ ์ˆ˜์ •ํ•œ ์ดํ›„์—๋Š” ๋ฐ˜๋“œ์‹œ ๊ธฐ์กด์— ์กด์žฌํ•˜๋Š” ๋ชจ๋“  ์œ ์ €์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ •์ฑ…์— ๋งž๊ฒŒ ์ˆ˜์ •ํ•ด์•ผ ํ•œ๋‹ค (root๋ฅผ ํฌํ•จํ•ด์„œ!)

sudo

sudo๊ฐ€ ์„ค์น˜๋˜์–ด ์žˆ์–ด์•ผ ํ•œ๋‹ค.

sudo ์‚ฌ์šฉ ์‹œ ๋น„๋ฐ€๋ฒˆํ˜ธ ์ธ์ฆ์€ ์ตœ๋Œ€ 3ํšŒ๊นŒ์ง€ ๊ฐ€๋Šฅํ•˜๋‹ค (3๋ฒˆ ํ‹€๋ฆฌ๋ฉด ๋‹ค์‹œ ์‹œ๋„ ํ•ด์•ผ ํ•จ)

๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ํ‹€๋ ธ์„ ์‹œ (๋ฐ”๋กœ ์œ„ ์„ค์ •์— ์˜ํ•ด 3๋ฒˆ ํ‹€๋ ธ์„ ์‹œ ์ธ ๊ฒƒ์œผ๋กœ ์ถ”์ •) custom message๊ฐ€ ๋‚˜ํƒ€๋‚˜๊ฒŒ ํ•ด์•ผ ํ•œ๋‹ค.

sudo๋ฅผ ํ†ตํ•œ ๋ชจ๋“  ํ–‰๋™ (์ž…์ถœ๋ ฅ ๋ชจ๋‘ ํฌํ•จ)์€ ๊ธฐ๋ก๋˜์–ด์•ผ ํ•œ๋‹ค. /var/log/sudo/ ๋””๋ ‰ํ† ๋ฆฌ์— ๋กœ๊ทธ ํŒŒ์ผ๋กœ ์ €์žฅ๋˜์–ด์•ผ ํ•œ๋‹ค.

๋ณด์•ˆ์„ ์ด์œ ๋กœ TTY ๋ชจ๋“œ๊ฐ€ ํ—ˆ์šฉ๋˜์–ด ์žˆ์–ด์•ผ ํ•œ๋‹ค.

๋ณด์•ˆ์„ ์ด์œ ๋กœ, sudo๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” paths๊ฐ€ ์ œํ•œ๋˜๋„๋ก ์„ค์ •ํ•ด์•ผ ํ•œ๋‹ค. (์˜ˆ์‹œ: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin)

Monitoring script

์„œ๋ฒ„์— ๋Œ€ํ•œ ํ˜„์žฌ ์ƒํƒœ ๋ฐ ์ •๋ณด๋ฅผ ์ถœ๋ ฅํ•˜๋Š” ์‰˜ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ•ด์•ผ ํ•œ๋‹ค. bash ์‰˜์„ ๊ธฐ์ค€์œผ๋กœ ์ž‘์„ฑํ•ด์•ผ ํ•œ๋‹ค

์„œ๋ฒ„๊ฐ€ ์ž‘๋™์ค‘์ผ ๋•Œ, ๋งค 10๋ถ„๋งˆ๋‹ค ์ด ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์‹คํ–‰๋˜์–ด์„œ ์„œ๋ฒ„ ์ƒํƒœ๋ฅผ ์ถœ๋ ฅํ•ด์•ผ ํ•œ๋‹ค. (wall ์„ ์‚ฌ์šฉํ•  ๊ฒƒ. ๋ฐฐ๋„ˆ๋Š” ์˜ต์…˜)

ํ‰๊ฐ€ ๊ณผ์ • ์ค‘์— ์ด ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์–ด๋–ป๊ฒŒ ๋™์ž‘ํ•˜๋Š”์ง€ ์„ค๋ช…ํ•ด์•ผ ํ•œ๋‹ค. ๋˜ cron์„ ์‚ฌ์šฉํ•ด์„œ ์ด ์Šคํฌ๋ฆฝํŠธ ๋™์ž‘์— interrupt๋ฅผ ํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•œ๋‹ค.

์Šคํฌ๋ฆฝํŠธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ •๋ณด๋ฅผ ์ถœ๋ ฅํ•ด์•ผ ํ•œ๋‹ค.

The architecture of your operating system and its kernel version.

์šด์˜์ฒด์ œ ์•„ํ‚คํ…์ณ์™€ ์ปค๋„ ๋ฒ„์ „

The number of physical processors

๋ฌผ๋ฆฌ ํ”„๋กœ์„ธ์„œ๋“ค์˜ ์ˆ˜

The number of virtual processors.

๊ฐ€์ƒ ํ”„๋กœ์„ธ์„œ๋“ค์˜ ์ˆ˜

The current available RAM on your server and its utilization rate as a percentage.

ํ˜„์žฌ ์„œ๋ฒ„์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ RAM๊ณผ ๋ฐฑ๋ถ„์œจ๋กœ ํ‘œ์‹œ๋œ ์‚ฌ์šฉ๋ฅ 

The current available memory on your server and its utilization rate as a percentage.

ํ˜„์žฌ ์„œ๋ฒ„์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ memory์™€ ๋ฐฑ๋ถ„์œจ๋กœ ํ‘œ์‹œ๋œ ์‚ฌ์šฉ๋ฅ 

The current utilization rate of your processors as a percentage.

๋ฐฑ๋ถ„์œจ๋กœ ํ‘œ์‹œ๋œ ํ”„๋กœ์„ธ์„œ๋“ค์˜ ํ˜„์žฌ ์‚ฌ์šฉ๋ฅ 

The date and time of the last reboot.

๋งˆ์ง€๋ง‰์œผ๋กœ ์žฌ์‹œ์ž‘๋œ ๋‚ ์งœ์™€ ์‹œ๊ฐ„

Whether LVM is active or not.

LVM์˜ ํ™œ์„ฑํ™” ์—ฌ๋ถ€

The number of active connections.

ํ™œ์„ฑ ์—ฐ๊ฒฐ์˜ ๊ฐœ์ˆ˜

The number of users using the server.

์„œ๋ฒ„๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š” ์‚ฌ์šฉ์ž์˜ ์ˆ˜

The IPv4 address of your server and its MAC (Media Access Control) address.

์„œ๋ฒ„์˜ IPv4 ์ฃผ์†Œ์™€ MAC ์ฃผ์†Œ

The number of commands executed with the sudo program

sudo ํ”„๋กœ๊ทธ๋žจ์„ ํ†ตํ•ด ์‹คํ–‰๋œ ๋ช…๋ น์˜ ์ˆ˜

Broadcast message from root@wil (tty1) (Sun Apr 25 15:45:00 2021):
#Architecture: Linux wil 4.19.0-16-amd64 #1 SMP Debian 4.19.181-1 (2021-03-19) x86_64 GNU/Linux
#CPU physical : 1
#vCPU : 1
#Memory Usage: 74/987MB (7.50%)
#Disk Usage: 1009/2Gb (39%)
#CPU load: 6.7%
#Last boot: 2021-04-25 14:45
#LVM use: yes
#Connexions TCP : 1 ESTABLISHED
#User log: 1
#Network: IP 10.0.2.15 (08:00:27:51:9b:a5)
#Sudo : 42 cmd

์œ„์˜ ์ •๋ณด ์ค‘ ์ผ๋ถ€๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ฐฉ๋ฒ•์œผ๋กœ ์ฐพ์„ ์ˆ˜ ์žˆ๋‹ค.

image

image

๊ธฐํƒ€

๊ฐ€์ƒ ๋จธ์‹ ์˜ hostname์€ <42 ๋กœ๊ทธ์ธ ์•„์ด๋””> + 42 (ex wil42) ์—ฌ์•ผ ํ•œ๋‹ค. ํ‰๊ฐ€ ์ค‘์— hostname์„ ๋ณ€๊ฒฝํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ํ‰๊ฐ€๊ฐ€ ์žˆ์„ ๊ฒƒ์ด๋‹ค.

42 ๋กœ๊ทธ์ธ ์•„์ด๋””์˜ ์œ ์ €๊ฐ€ ์กด์žฌํ•ด์•ผ ํ•œ๋‹ค. ์ด ์œ ์ €๋Š” user42์™€ sudo ๊ทธ๋ฃน์— ์†ํ•ด์žˆ์–ด์•ผ ํ•œ๋‹ค.

์ œ์ถœ ๋ฐ ํ‰๊ฐ€ ๋ฐฉ๋ฒ•

Git repository์— signature.txt ํŒŒ์ผ ํ•˜๋‚˜๋งŒ ์—…๋กœ๋“œํ•œ๋‹ค.

Virtual disk์˜ disk signature๋ฅผ ๋ณต๋ถ™ํ•ด์„œ ์—…๋กœ๋“œํ•œ๋‹ค.

Virtual disk์˜ disk signature๋ฅผ ์ถ”์ถœํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๊ฐ€์ƒ ๋จธ์‹ ์ด ์„ค์น˜๋œ ํด๋”๋กœ ๊ฐ€์„œ .vdi ํŒŒ์ผ์„ ์ฐพ์€ ๋’ค ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋œ๋‹ค.

shasum <ํŒŒ์ผ๋ช…>.vdi

*ํ‰๊ฐ€ ํ›„์— disk signature๊ฐ€ ๋ณ€๊ฒฝ๋  ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์œผ๋ฏ€๋กœ, ์Šค๋ƒ…์ƒท์œผ๋กœ ๋ฐฑ์—…์„ ํ•ด๋‘๊ฑฐ๋‚˜ ์‚ฌ๋ณธ์„ ๋งŒ๋“ค์–ด๋‘์ž.

bonus

์•„๋ž˜์˜ ๊ตฌ์กฐ์™€ ๊ฐ™์ด ํŒŒํ‹ฐ์…˜์„ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๊ตฌ์„ฑํ•˜์„ธ์š”:

image

Set up a functional WordPress website with the following services: lighttpd, MariaDB, and PHP.

lighttpd, MariaDB, PHP๋ฅผ ์ด์šฉํ•ด์„œ ์‹ค์ œ๋กœ ์ž‘๋™ํ•˜๋Š” WordPress ์›น์‚ฌ์ดํŠธ๋ฅผ ๊ตฌ์„ฑํ•˜์„ธ์š”.

Set up a service of your choice that you think is useful (NGINX / Apache2 excluded!). During the defense, you will have to justify your choice

์—ฌ๋Ÿฌ๋ถ„์ด ์ƒ๊ฐํ•˜๊ธฐ์— ์œ ์šฉํ•œ ์„œ๋น„์Šค๋ฅผ ๊ตฌ์„ฑํ•˜์„ธ์š”(NGINX / Apache2๋Š” ์ œ์™ธ!). ํ‰๊ฐ€ ์ค‘์—, ์—ฌ๋Ÿฌ๋ถ„์˜ ์„ ํƒ์„ ์ •๋‹นํ™”ํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๋ณด๋„ˆ์Šค ํŒŒํŠธ๋ฅผ ์™„๋ฃŒํ•˜๊ธฐ ์œ„ํ•ด์„œ, ์ถ”๊ฐ€์ ์ธ ์„œ๋น„์Šค๋“ค์„ ์„ค์น˜ํ•ด์•ผ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ์—๋Š”, ํ•„์š”์— ๋”ฐ๋ผ์„œ ์ถ”๊ฐ€์ ์ธ ํฌํŠธ๋ฅผ ์—ด ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹น์—ฐํžˆ, UFW/Firewalld ๊ทœ์น™๋„ ๊ทธ์— ๋งž์ถ”์–ด ์ ์šฉ๋˜์–ด ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๋ณด๋„ˆ์Šค ํŒŒํŠธ๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ์š”๊ตฌ๋œ ํŒŒํŠธ๊ฐ€ ์™„๋ฒฝํ•œ ๊ฒฝ์šฐ์—๋งŒ ํ‰๊ฐ€๋ฉ๋‹ˆ๋‹ค. ์™„๋ฒฝ์˜ ์˜๋ฏธ๋Š” ์ข…ํ•ฉ์ ์œผ๋กœ ์ฒ˜์Œ๋ถ€ํ„ฐ ๋๊นŒ์ง€ ์˜ค๋ฅ˜ ์—†์ด ์ž˜ ์ž‘๋™ํ•˜๋Š” ์ƒํƒœ๋ฅผ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ๋งŒ์•ฝ ๊ธฐ๋ณธ ์š”๊ตฌ์‚ฌํ•ญ์„ ๋ชจ๋‘ ์ถฉ์กฑํ•˜์ง€ ๋ชปํ–ˆ๋‹ค๋ฉด, ๋ณด๋„ˆ์Šค ํŒŒํŠธ๋Š” ํ‰๊ฐ€๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

image

โš ๏ธ **GitHub.com Fallback** โš ๏ธ