Least Privilege¡ÊºÇ¾®ÆÃ¸¢µ¡Ç½¡Ë¤Ç¥í¥°¥¤¥ó»þ¤Ë¥æ¡¼¥¶¤ËÆÃ¸¢¤òÍ¿¤¨¤ë¤Ë¤Ï
º£²ó¤ÏÆÉ¤ß¼è¤ê¸¢¤Î¤Ê¤¤¥Õ¥¡¥¤¥ë¤ä¥Ç¥£¥ì¥¯¥È¥ê¤Ë¥¢¥¯¥»¥¹¤Ç¤¤ë file_dac_read ÆÃ¸¢¤ò¥í¥°¥¤¥ó»þ¤Ë¥æ¡¼¥¶¤ËÍ¿¤¨¤ëÊýË¡¤ò¾Ò²ð¤¹¤ë¡£¡Ê¢Í
³ÆÆÃ¸¢¤ÎÀâÌÀ¤Ï¤³¤Á¤é¡Ë
¤Þ¤º¡¢°Ê²¼¤Î¤è¤¦¤Ë°ìÈ̥桼¥¶¤Ç/etc/shadow¥Õ¥¡¥¤¥ë¤ò³«¤¤¤Æ¤ß¤ë¡£
#
su - user1
Sun Microsystems Inc. SunOS
5.10 Generic January 2005
$
$
$
more /etc/shadow
/etc/shadow: ¥¢¥¯¥»¥¹¸¢¤¬¤¢¤ê¤Þ¤»¤ó¡£
¤È¡¢¤Þ¤¡ÅöÁ³¼ºÇÔ¤¹¤ë¡£
¤½¤³¤Ç/etc/user_attr¥Õ¥¡¥¤¥ë¤Ëdefaultpriv¥¡¼¥ï¡¼¥É¤ò»È¤¤¡¢°Ê²¼¤Î¤è¤¦¤Ëfile_dac_readÆÃ¸¢¤òŬÍѤ¹¤ë¡£
¤³¤Î»ØÄê¤ÇEffective¥»¥Ã¥È¡¢Permitted¥»¥Ã¥È¡¢Inheritable¥»¥Ã¥È¤Ëfile_dac_readÆÃ¸¢¤¬Äɲ䵤ì¤ë¡£
¤³¤Î¤Û¤«¤Ë¤âlimitpriv¥¡¼¥ï¡¼¥É¤¬¤¢¤ê¡¢Limit¥»¥Ã¥È¤â¥«¥¹¥¿¥Þ¥¤¥º²Äǽ¤À¤¬¡¢¤³¤Á¤é¤Ï¥°¥í¡¼¥Ð¥ë¥½¡¼¥ó¤Ç¤Ï°ìÈ̥桼¥¶¤Ç¤â¥Ç¥Õ¥©¥ë¥È¤Ç
all¤Ê¤Î¤Ç¡¢ÆÃ¤Ë¸¢¸Â¤ò³ÈÄ¥¤¹¤ëɬÍפϤʤ¤¡£
#
cat /etc/user_attr
...
adm::::profiles=Log Management
lp::::profiles=Printer Management
root::::auths=solaris.*,solaris.grant;profiles=Web Console
Management,All;lock_a
fter_retries=no
user1::::defaultpriv=basic,file_dac_read
¾åµ¡¢ÀßÄê¤Ë¤·¤Æ¡¢¤â¤¦°ìÅÙ¡¢°ìÈ̥桼¥¶¤Ç/etc/shadow¥Õ¥¡¥¤¥ë¤ò³«¤¤¤Æ¤ß¤ë¡£
#
su - user1
Sun Microsystems Inc. SunOS
5.10 Generic January 2005
$
more /etc/shadow
...
listen:*LK*:::::::
gdm:*LK*:::::::
webservd:*LK*:::::::
nobody:*LK*:6445::::::
noaccess:*LK*:6445::::::
nobody4:*LK*:6445::::::
user1:AxEfnuHATDQB2:12930::::::
¤È¤Þ¤¡¤³¤ó¤Ê¶ñ¹ç¤Ë¥¢¥¯¥»¥¹¸¢¤ò̵»ë¤·¤Æ¡¢¥Õ¥¡¥¤¥ë¤òÆÉ¤ß¼è¤ë¤³¤È¤¬²Äǽ¤Ë¤Ê¤ë¡£
°Ê²¼¤Î¤è¤¦¤Ë¡¢ppriv¥³¥Þ¥ó¥É¤Ç¸½ºß¤Î¥·¥§¥ë¤Î»ý¤Ã¤Æ¤¤¤ëÆÃ¸¢¤ò¸«¤Æ¤â E, I, P
¤½¤ì¤¾¤ì¤ÎÆÃ¸¢¥»¥Ã¥È¤Ëfile_dac_readÆÃ¸¢¤¬Äɲäµ¤ì¤Æ¤¤¤ë¤³¤È¤¬³Îǧ¤Ç¤¤ë¡£
$
ppriv $$
1020: bash
flags = <none>
E: basic,file_dac_read
I: basic,file_dac_read
P: basic,file_dac_read
L: all
RBAC¤ÈÍí¤á¤ÆÆÃÄê¤Î¥³¥Þ¥ó¥É¤Ë¸ÂÄꤷ¤ÆÆÃ¸¢¤ò³ä¤êÅö¤Æ¤ëÊýË¡¤Ï¤³¤Á¤é
========================================
¢¨¾Ü¤·¤¤¾ðÊó¤Ï°Ê²¼¤Î¥È¥ì¡¼¥Ë¥ó¥°¥³¡¼¥¹»²¾È
Solaris10¿·µ¡Ç½¡Ê¥·¥¹¥Æ¥à´ÉÍýÊÔ¡Ë
========================================
¡Ú¥¢¥ó¥±¡¼¥È¡Û
¤³¤Îµ»ö¤Ï¤¿¤á¤Ë¤Ê¤ê¤Þ¤·¤¿¤«¡©
¡¡¡¡¡¡¤Ï¤¤¡¡¡¡/¡¡¡¡¤¤¤¤¤¨