¥È¥Ã¥×¥Ú¡¼¥¸ » Solaris10ºÇ¾®ÆÃ¸¢(Least Privilege)µ¡Ç½ » net_rawaccess ÆÃ¸¢¤Ç°ìÈ̥桼¥¶¤Ë snoop ¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤µ¤»¤ë
¥«¥Æ¥´¥ê¡¼
Solaris10Âбþ¥³¡¼¥¹
¢£Solaris½é¿´¼Ô¸þ¤±
ÆþÌ祳¡¼¥¹¡¡
¥·¥¹¥Æ¥à´ÉÍý­µ¡¡¡Êx86ÈǤϤ³¤Á¤é¡Ë
¥·¥¹¥Æ¥à´ÉÍý­¶¡¡¡Êx86ÈǤϤ³¤Á¤é¡Ë
¥·¥¹¥Æ¥à´ÉÍý­·¡¡¡Êx86ÈǤϤ³¤Á¤é¡Ë
¥·¥¹¥Æ¥à´ÉÍý­¸¡¡¡Êx86ÈǤϤ³¤Á¤é¡Ë
¥Í¥Ã¥È¥ï¡¼¥¯´ÉÍý­µ
¥Í¥Ã¥È¥ï¡¼¥¯´ÉÍý­¶

¢£·Ð¸³¼Ô¡¦¾åµé¼Ô¸þ¤±
Solaris10¥È¥é¥Ö¥ë¥·¥å¡¼¥Æ¥£¥ó¥° ¡úNEW¡ú
¥»¥­¥å¥¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ð¡¼¹½ÃÛ ¡úNEW¡ú
Solaris 10 ZFS ´ÉÍý
Solaris 10¥³¥ó¥Æ¥Ê(¥¾¡¼¥ó)
·Ð¸³¼Ô¸þ¤±Â®½¬¥³¡¼¥¹
Solaris10¿·µ¡Ç½¡Ê¥·¥¹¥Æ¥à´ÉÍýÊÔ¡Ë
Solaris10¿·µ¡Ç½¡Ê¥Í¥Ã¥È¥ï¡¼¥¯ÊÔ¡Ë
Solaris ¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹´ÉÍý
DTrace ¤ò»È¤Ã¤¿¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹¥Á¥å¡¼¥Ë¥ó¥°¤È ¥È¥é¥Ö¥ë¥·¥å¡¼¥Æ¥£¥ó¥°

Solaris 8/9 Âбþ¥³¡¼¥¹
¢£½é¿´¼Ô¸þ¤±
ǧÄê»î¸³Âкö¥³¡¼¥¹
UNIXÆþÌç
¥·¥¹¥Æ¥à´ÉÍý­µ
¥·¥¹¥Æ¥à´ÉÍý­¶
¥·¥¹¥Æ¥à´ÉÍý­·
¥Í¥Ã¥È¥ï¡¼¥¯´ÉÍý´ðÁÃ

¢£·Ð¸³¼Ô¡¦¾åµé¼Ô¸þ¤±
¥È¥é¥Ö¥ë¥·¥å¡¼¥Æ¥£¥ó¥°´ðÁÃ
OS¥»¥­¥å¥ê¥Æ¥£ for Solaris
Solaris ¥Í¥Ã¥È¥ï¡¼¥¯¿¯Æþ¸¡ÃÎ
Sun Ray ¥·¥¹¥Æ¥à¤Î¥¤¥ó¥¹¥È¡¼¥ë¤È´ÉÍý ¡úNEW¡ú
Sun Systems Fault Analysis Workshop
Crash Dump Analysis and the SunOS Kernel
Solaris¥¤¥ó¥¿¡¼¥Ê¥ë(ÆâÉô¹½Â¤)

¢£DNS,Apache,¥×¥í¥­¥·,¥á¡¼¥ë·Ï
Solaris10¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ð¡¼¹½ÃÛ ¡úNEW¡ú
¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ð¹½ÃÛ
¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ð¥»¥­¥å¥ê¥Æ¥£

¢£¥Ü¥ê¥å¡¼¥à´ÉÍý¡¢¥¯¥é¥¹¥¿·Ï
Solaris Volume Manager ´ÉÍý
VERITAS Volume Manager4.0´ÉÍý
Sun Cluster 3.x ´ÉÍý
Sun Cluster 3.2 ´ÉÍý ¡úNEW¡ú

¢£¥Ï¡¼¥É¥¦¥§¥¢¡¢¥á¥ó¥Æ¥Ê¥ó¥¹·Ï
Sun Fire¥µ¡¼¥Ð¡¼´ÉÍý
Sun Fire 15K ¥µ¡¼¥Ð¡¼´ÉÍý

¢£¥·¥§¥ë¥×¥í¥°¥é¥ß¥ó¥°·Ï
C¥·¥§¥ë¥×¥í¥°¥é¥ß¥ó¥°
B¥·¥§¥ë/K¥·¥§¥ë¥×¥í¥°¥é¥ß¥ó¥°

SunJavaSystem¥³¡¼¥¹
¢£¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£´ÉÍý
¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£´ÉÍý¡Ê´ðËÜÊÔ¡Ë
¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£´ÉÍý¡Ê±þÍÑÊÔ¡Ë
¥¢¥¯¥»¥¹¥Þ¥Í¡¼¥¸¥ã¡¼
¢£LDAP¥µ¡¼¥Ð¡¢¥á¡¼¥ë¥µ¡¼¥Ð
¥Ç¥£¥ì¥¯¥È¥ê¥µ¡¼¥Ó¥¹ 5.x
¥á¥Ã¥»¡¼¥¸¥ó¥°¥µ¡¼¥Ó¥¹ 5.x

net_rawaccess ÆÃ¸¢¤Ç°ìÈ̥桼¥¶¤Ë snoop ¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤µ¤»¤ë

Solaris10¤Ç¤Ï¡¢net_rawaccess ÆÃ¸¢¤ò°ìÈ̥桼¥¶¤ËÍ¿¤¨¤ë¤³¤È¤Ç snoop ¥³¥Þ¥ó¥É¤Î¼Â¹Ô¤òµö²Ä¤¹¤ë¤³¤È¤¬¤Ç¤­¤ë¡£
Solaris 9 °ÊÁ°¤Ç¤âRBACµ¡Ç½¤ò»È¤¨¤Ð¡¢ root ¸¢¸Â¤Ç¤Î snoop ¥³¥Þ¥ó¥É¤Î¼Â¹Ô¤ò°ìÈ̥桼¥¶¤Ëµö²Ä¤¹¤ë¤³¤È¤ÏÍÆ°×¤À¤¬¡¢Solaris10 ¤Ç¤ÏɬÍ׺ÇÄã¸Â¤ÎÆÃ¸¢¤òÍ¿¤¨¤ë¤³¤È¤Ç¡¢¥»¥­¥å¥ê¥Æ¥£¥ê¥¹¥¯¤òºÇ¾®²½¤·¤Æ¤³¤Î¤è¤¦¤Ê¥Ë¡¼¥º¤ËÂбþ¤¹¤ë¤³¤È¤¬²Äǽ¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡£¡Ê¢ªºÇ¾®ÆÃ¸¢µ¡Ç½¤È¸Æ¤Ð¤ì¤Æ¤¤ ¤ë¡Ë

¤½¤Î¾¤ÎÆÃ¸¢¤Î°ìÍ÷¤Ï¤³¤Á¤é

¢£¡¡°ìÈ̥桼¥¶¤ÎÄɲáÊǤ°Õ¡Ë
°Ê²¼¤Î¤è¤¦¤Ë net_rawaccess ÆÃ¸¢¤òÍ¿¤¨¤ë¥æ¡¼¥¶¡¼ test ¤òºîÀ®¤¹¤ë¡£

bash-3.00# useradd -d /export/home/test -m -s /bin/bash test

¢£¡¡ÆÃ¸¢¤Î³ä¤êÅö¤Æ
°Ê²¼¤Î¤è¤¦¤Ë test ¥æ¡¼¥¶¡¼¤Î¥Ç¥Õ¥©¥ë¥ÈÆÃ¸¢¤òÊѹ¹¤¹¤ë¡£
²¼µ­¤ÎÎã¤Ç¤Ï°ìÈ̥桼¥¶¤Î¥Ç¥Õ¥©¥ë¥È¤ÎÆÃ¸¢¤Ç¤¢¤ë basic ¤Ë net_rawaccess ¤ò²Ã¤¨¤Æ¤¤¤ë¡£

bash-3.00# usermod -K defaultpriv=basic,net_rawaccess test

¢¨basic ÆÃ¸¢¤È¤Ï¥¨¥¤¥ê¥¢¥¹¤ß¤¿¤¤¤Ê¤â¤Î¤Ç¡¢¼Â¤Ï²¼µ­£µ¤Ä¤ÎÆÃ¸¢¤Î½¸¹ç¤òɽ¤·¤Æ¤¤¤ë¡£
file_link_any, proc_exec, proc_fork, proc_info, proc_session
¾åµ­¥³¥Þ¥ó¥É¤Ç /etc/user_attr ¥Õ¥¡¥¤¥ë¤Ë°Ê²¼¤Î¥¨¥ó¥È¥ê¤¬Äɲ䵤ì¤ë¡£
¡Êusermod ¥³¥Þ¥ó¥É¤ò»ÈÍѤ»¤º¤Ë /etc/user_attr ¥Õ¥¡¥¤¥ë¤òľÀÜÊÔ½¸¤·¤Æ¤â¤è¤¤¡Ë

bash-3.00# more /etc/user_attr
...
test::::type=normal;defaultpriv=basic,net_rawaccess

¢£¡¡Æ°ºî³Îǧ
°Ê²¼¤Î¤è¤¦¤Ë¥æ¡¼¥¶¡¼ test ¤ËÊѹ¹¤·¤Æ¡¢Æ°ºî¤ò³Îǧ¤¹¤ë¡£

bash-3.00# su - test
-bash-3.00$ ppriv $$
22451:  -bash
flags = <none>
        E: basic,net_rawaccess
        I: basic,net_rawaccess
        P: basic,net_rawaccess
        L: all

¾åµ­¤Î·ë²Ì¤«¤é¤ï¤«¤ë¤è¤¦¤Ë¡¢¸½ºß¤Î¥·¥§¥ë(bash)¤Ë¤Á¤ã¤ó¤È net_rawaccess ¤È¤¤¤¦ÆÃ¸¢¤¬Í¿¤¨¤é¤ì¤Æ¤¤¤ë¡£

-bash-3.00$ /usr/sbin/snoop
Using device /dev/hme (promiscuous mode)
...
...

¤³¤Î¤è¤¦¤Ë°ìÈ̥桼¥¶¤Ë´Êñ¤Ë snoop ¥³¥Þ¥ó¥É¤¬¼Â¹Ô¤µ¤»¤ë¤³¤È¤¬¤Ç¤­¤ë¡£

========================================
¢¨¾Ü¤·¤¤¾ðÊó¤Ï°Ê²¼¤Î¥È¥ì¡¼¥Ë¥ó¥°¥³¡¼¥¹»²¾È
Solaris10¿·µ¡Ç½¡Ê¥·¥¹¥Æ¥à´ÉÍýÊÔ¡Ë
========================================

¡Ú¥¢¥ó¥±¡¼¥È¡Û
¤³¤Îµ­»ö¤Ï¤¿¤á¤Ë¤Ê¤ê¤Þ¤·¤¿¤«¡©
¡¡¡¡¡¡¤Ï¤¤¡¡¡¡/¡¡¡¡¤¤¤¤¤¨

My Yahoo!¤ËÄɲÃ


¥³¥á¥ó¥È
¥³¥á¥ó¥È¤¹¤ë









̾Á°¡¢¥¢¥É¥ì¥¹¤òÅÐÏ¿¤·¤Þ¤¹¤«?