µî·ÏÀÏ 2008-03-08 11:14:02 Á¶È¸¼ö 281
ÀÛ¼ºÀÚ lsyus µµ¸ÞÀÎ
Á¦¸ñ iptables¿¡ º¸´Ï...
¾È³çÇÏ½Ê´Ï±î ¿ì¶ß³ÝÀÔ´Ï´Ù.

Root ±ÇÇÑÀ¸·Î ó¸®ÇÏ¼Å¾ß ÇÕ´Ï´Ù.
ÀϹݱÇÇÑÀ¸·Î ÇϽôٺ¸´Ï ÆÛ¹Ì¼Ç ¹®Á¦°¡ ¹ß»ýÇϰí ÀÖ½À´Ï´Ù.
°ü·Ã Root ÆÐ½º¿öµå´Â ÀúÈñÃø¿¡¼­ È®ÀÎÀÎ ºÒ°¡´ÉÇÕ´Ï´Ù. Ãʱâºñ¹Ð¹øÈ£¸¦ º¯°æÇØµÎ½Å°Í °°½À´Ï´Ù.

¾Æ¿ï·¯ ȸ¿ø´Ô ¼­¹öÁ¤º¸¸¦ °ø°³ÇϽǶ© ºñ¹Ð±ÛÀ» ÀÌ¿ëÇϽñ⠹ٶø´Ï´Ù.

°¨»çÇÕ´Ï´Ù.

> --------------------- :: lsyus wrote :: ----------------------- <
110¹øÀÌ Çã¿ëµÇÁö ¾ÊÀº°Í ¾Æ´Ñ°¡¿ä?

¶Ç /etc/xinetd.d/pop3s
bash: /etc/xinetd.d/pop3s: Çã°¡ °ÅºÎµÊ
À̶ó°í ³ª¿É´Ï´Ù

Çã¿ëµÇÁö ¾Ê¾Ò´Ù¸é ¾îÄÉ 110À» ¿­¼ö ÀÖ³ª¿©?

<iptables>
# Firewall configuration written by lokkit
# Manual customization of this file is not recommended.
# Note: ifup-post will punch the current nameservers through the
# firewall; such entries will *not* be listed here.
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Lokkit-0-50-INPUT - [0:0]
-A INPUT -j RH-Lokkit-0-50-INPUT
-A FORWARD -j RH-Lokkit-0-50-INPUT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 25 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 53 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 80 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 21 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 22 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p udp -s 220.80.107.2 --sport 53 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p udp -s 220.80.107.5 --sport 53 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p udp -s 168.126.63.1 --sport 53 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p udp --dport 53 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -i lo -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --syn -j REJECT
-A RH-Lokkit-0-50-INPUT -p udp -m udp -j REJECT


COMMIT