net_rawaccess ÆÃ¸¢¤Ç°ìÈ̥桼¥¶¤Ë snoop ¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤µ¤»¤ë
Solaris10¤Ç¤Ï¡¢net_rawaccess ÆÃ¸¢¤ò°ìÈ̥桼¥¶¤ËÍ¿¤¨¤ë¤³¤È¤Ç snoop ¥³¥Þ¥ó¥É¤Î¼Â¹Ô¤òµö²Ä¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£
Solaris 9 °ÊÁ°¤Ç¤âRBACµ¡Ç½¤ò»È¤¨¤Ð¡¢ root ¸¢¸Â¤Ç¤Î snoop
¥³¥Þ¥ó¥É¤Î¼Â¹Ô¤ò°ìÈ̥桼¥¶¤Ëµö²Ä¤¹¤ë¤³¤È¤ÏÍÆ°×¤À¤¬¡¢Solaris10
¤Ç¤ÏɬÍ׺ÇÄã¸Â¤ÎÆÃ¸¢¤òÍ¿¤¨¤ë¤³¤È¤Ç¡¢¥»¥¥å¥ê¥Æ¥£¥ê¥¹¥¯¤òºÇ¾®²½¤·¤Æ¤³¤Î¤è¤¦¤Ê¥Ë¡¼¥º¤ËÂбþ¤¹¤ë¤³¤È¤¬²Äǽ¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡£¡Ê¢ªºÇ¾®ÆÃ¸¢µ¡Ç½¤È¸Æ¤Ð¤ì¤Æ¤¤
¤ë¡Ë
¤½¤Î¾¤ÎÆÃ¸¢¤Î°ìÍ÷¤Ï¤³¤Á¤é
¢£¡¡°ìÈ̥桼¥¶¤ÎÄɲáÊǤ°Õ¡Ë
°Ê²¼¤Î¤è¤¦¤Ë net_rawaccess ÆÃ¸¢¤òÍ¿¤¨¤ë¥æ¡¼¥¶¡¼ test ¤òºîÀ®¤¹¤ë¡£
bash-3.00#
useradd -d
/export/home/test -m -s /bin/bash test
¢£¡¡ÆÃ¸¢¤Î³ä¤êÅö¤Æ
°Ê²¼¤Î¤è¤¦¤Ë test ¥æ¡¼¥¶¡¼¤Î¥Ç¥Õ¥©¥ë¥ÈÆÃ¸¢¤òÊѹ¹¤¹¤ë¡£
²¼µ¤ÎÎã¤Ç¤Ï°ìÈ̥桼¥¶¤Î¥Ç¥Õ¥©¥ë¥È¤ÎÆÃ¸¢¤Ç¤¢¤ë basic ¤Ë net_rawaccess ¤ò²Ã¤¨¤Æ¤¤¤ë¡£
bash-3.00#
usermod -K
defaultpriv=basic,net_rawaccess test
¢¨basic ÆÃ¸¢¤È¤Ï¥¨¥¤¥ê¥¢¥¹¤ß¤¿¤¤¤Ê¤â¤Î¤Ç¡¢¼Â¤Ï²¼µ£µ¤Ä¤ÎÆÃ¸¢¤Î½¸¹ç¤òɽ¤·¤Æ¤¤¤ë¡£
file_link_any, proc_exec, proc_fork, proc_info, proc_session
¾åµ¥³¥Þ¥ó¥É¤Ç /etc/user_attr ¥Õ¥¡¥¤¥ë¤Ë°Ê²¼¤Î¥¨¥ó¥È¥ê¤¬Äɲ䵤ì¤ë¡£
¡Êusermod ¥³¥Þ¥ó¥É¤ò»ÈÍѤ»¤º¤Ë /etc/user_attr ¥Õ¥¡¥¤¥ë¤òľÀÜÊÔ½¸¤·¤Æ¤â¤è¤¤¡Ë
bash-3.00#
more /etc/user_attr
...
test::::type=normal;defaultpriv=basic,net_rawaccess
¢£¡¡Æ°ºî³Îǧ
°Ê²¼¤Î¤è¤¦¤Ë¥æ¡¼¥¶¡¼ test ¤ËÊѹ¹¤·¤Æ¡¢Æ°ºî¤ò³Îǧ¤¹¤ë¡£
bash-3.00#
su - test
-bash-3.00$
ppriv $$
22451: -bash
flags = <none>
E: basic,net_rawaccess
I: basic,net_rawaccess
P: basic,net_rawaccess
L: all
¾åµ¤Î·ë²Ì¤«¤é¤ï¤«¤ë¤è¤¦¤Ë¡¢¸½ºß¤Î¥·¥§¥ë(bash)¤Ë¤Á¤ã¤ó¤È net_rawaccess ¤È¤¤¤¦ÆÃ¸¢¤¬Í¿¤¨¤é¤ì¤Æ¤¤¤ë¡£
-bash-3.00$
/usr/sbin/snoop
Using device /dev/hme (promiscuous mode)
...
...
¤³¤Î¤è¤¦¤Ë°ìÈ̥桼¥¶¤Ë´Êñ¤Ë snoop ¥³¥Þ¥ó¥É¤¬¼Â¹Ô¤µ¤»¤ë¤³¤È¤¬¤Ç¤¤ë¡£
========================================
¢¨¾Ü¤·¤¤¾ðÊó¤Ï°Ê²¼¤Î¥È¥ì¡¼¥Ë¥ó¥°¥³¡¼¥¹»²¾È
Solaris10¿·µ¡Ç½¡Ê¥·¥¹¥Æ¥à´ÉÍýÊÔ¡Ë
========================================
¡Ú¥¢¥ó¥±¡¼¥È¡Û
¤³¤Îµ»ö¤Ï¤¿¤á¤Ë¤Ê¤ê¤Þ¤·¤¿¤«¡©
¡¡¡¡¡¡¤Ï¤¤¡¡¡¡/¡¡¡¡¤¤¤¤¤¨