DAY_32 apache

2021. 2. 8. 18:16

web#1 에서 sbsuser/public_html 디렉터리의 apache 사용자가 접근 할 수 없도록 설정한다.

 

web1# chmod -c o= ~sbsuser/public_html

권한을 바꾸면 lynx로 접근하면 forbidden된다.

 

다시 웹사용자가 읽을 수 있도록 설정을 변경하면 웹사용자가 웹페이지를 읽을 수 있으므로 클라이언트에게 문서의 내용을 전달해주므로 웹페이지 문서를 확인할 수 있다.

 

web1# chmod -c o+x ~sbsuser/public_html

 

web1# vi /etc/httpd/httpd.conf

 

ServerAdmin 관리자이메일주소

ServerName 192.168.1.101:80

 


실습> <Directory> 컨테이너

아파치가 접근할 수 있는 각 디렉터리에 대하여 어떤 서비스와 기능을 허용할 것인지 거부할 것인지 여부를 설정할 수 있다.

 

형식 :

<Directory 디렉토리명>

옵션 지시어 값 ...

옵션 지시어 값 ...

    :

    :

</Directory>

 

web1# vi /etc/http/httpd.conf

 

 

-- 원래 설정 값 --

<Directory />

AllowOverride none

Require all denied

</Directory>

 

<Directory "/var/www">

AllowOverride None

Require all granted

</Directory>

 

<Directory "/var/www/html">

Options Indexes FollowSymLinks

AllowOverride None

Require all granted

</Directory>

-- 원래 설정 값 --

 

Require all granted : 전체 접근을 허용

Require all denied : 전체 접근을 거부

 


실습 > 디렉터리 컨테이서 사용해보기

 

sbsuser에 들어가서 public_html디렉터리 밑에 하나의 디렉터리 만들어주기

sbsuser$ mkdir pds

sbsuser$ cd pds 

pds디렉터리안에 bin디렉터리안에 있는 a로 시작하는 파일을 현재 디렉터리안에 복사한다.

sbsuser$ cp /bin/a* .

 

브라우저로 가서 확인한다.

sbsuser$ exit

web1 # lynx --dump sbs.com/pds

 

lynx 명령어로도 확인 할 수 있다. 

지금 index.html파일이 없기 때문에 발생한 취약점이다.

sbsuser 사용자로 해당 디렉터리에 DirectoryIndex 지시어에 해당하는 파일인

index.html을 생성하면 디렉터리 인덱싱이 출력되지 않는다.

index.html 파일을 만들어서 이 문제를 해결할 수 있다.

 

사용자로 들어가지 않고도 index.html파일을 만들 수 있다.

web1# su - sbsuser -c "touch public_html/pds/index.html"

web1# ls -l ~sbsuser/public_html/pds/index.html

 

web1# lynx --dump sbs.com/pds

pds 디렉터리 안에 index.html파일이 있지만 index.html파일 안에 내용이 없어서

아무것도 출력되지 않는다.

 

 

이렇게 항상 빈 index.html을 만들어서 넣어주지 않으니 디렉터리 컨테이너를 수정한다.

web1 # rm -rf ~sbsbuser/public_html/pds/index.html

 

web1 # vi /etc/httpd/conf/httpd.conf

 

<Directory "/home/sbsuser/public_html/pds">

# http://httpd.apache.org/docs/2.4/mod/core.html#options

#Options Indexes FollowSymLinks

Options FollowSymLinks

AllowOverride None

#Require all granted

Require all denied

</Directory>

 

브라우저에서 확인해봐도 forbidden이 뜬것을 확인할 수 있다.

 

기존에 설정해 준 /etc/httpd/conf/httpd.conf 에서

<Directory "/home/sbsuser/public_html/pds">

# http://httpd.apache.org/docs/2.4/mod/core.html#options

#Options Indexes FollowSymLinks

Options FollowSymLinks

AllowOverride None

#Require all granted

Require all denied

</Directory>

위 설정을 지우고

 

web1 # vi /etc/httpd/conf.d/userdir.conf

web1 # systemctl restart httpd

 

web1 # lynx --dump sbs.com/pds

 

 

web1 # su - sbsuser

web1 # cd public_html

web1 # ln -s /etc/passwd .

web1 # ls -l passwd

링크파일도 열리지 않는다.

 


실습 > ServerToken 지시어

설정값에 올 수 있는 값

Prod : 웹서버 이름만 출력한다.

Major : 웹서버 이름과 Major 버전을 출력한다.

Minor : 웹서버 이름과 Minor 버전을 출력한다.

Min : 웹서버 이름과 Mininum 버전을 출력한다.

OS : 웹서버 이름과 버전, 운영체제까지 출력한다. (기본값)

Full : 최대한의 모든 정보를 출력한다. (웹서버 이름, 버전, OS, PHP버전)

 

 

기본적으로 아래 정보를 막아줘야한다.

버전 정보이지만 이것도 취약점으로 사용될 수 있다. 

web1 # vi /etc/httpd/conf/httpd.conf

  아래와 같이 추가해주기

web1 # systemctl restart httpd

버전 정보가 보이지 않고 Apache만 나오는것을 알 수 있다.

 

vi로 /etc/httpd/conf/httpd.conf로 한번 ServerTokens를 설정해 줬는데

이제 다시 vi로 열지 않고도 수정할 수 있다.

web1# sed -i 's/ServerTokens.*/ServerTokens Major/' /etc/httpd/conf/httpd.conf

web1# systemctl restart httpd

web1# curl -I sbs.com

 

prod로 설정해주는것이 제일 안전하다.

 

파이썬으로 만들어서 테스트하기

import os
import time

sedCmd  = "sed -i 's/ServerTokens.*/ServerTokens %s/' /etc/httpd/conf/httpd.conf"
ServerTokensValue = ['Prod','Major', 'Minor', 'Min', 'OS', 'Full']
cmd2 = ";systemctl restart httpd; curl -I http://sbs.com"

for value in ServerTokensValue:
    print("ServerTokens:", value)
    cmd = sedCmd %value
    cmd += cmd2
    os.system(cmd)
    time.sleep(1)


DocumentRoot : 웹 페이지가 제공되는 문서

단독으로 밖으로 나와있는 DocumentRoot "var/www/html" 디렉터리는 웹 서버 1개당 하나의 도메인을

제공할 때만 제공되는 디렉터리이고 가상 호스트로 설정할 때는 이 부분은 인식되지 않는다.

 

이유는 가상 호스트를 설정할 때 가상 호스트 컨테이너에서 Document 지시어가 제공되기 때문이다.

 

DocumentRoot "/var/www/html" <-- 가상호스트를 지정하면 인식되지 않는다.

 

<VirtualHost *:80>

ServerAdmin webmaster@sbs.com

DocumentRoot /home/sbsuser/public_html   <----- 여기가 DocumentRoot가 설정된다.

ServerName sbs.com

ServerAlias www.sbs.com

ErrorLog logs/sbs.com-error_log

CustomLog logs/sbs.com-access_log common

</VirtualHost>

 

이 서버는 가상호스트를 지정하기 때문에 /var/www 디렉터리는 사용하지 않는다.

그러므로 모두 주석처리를 하거나 삭제한다.

 

가상 호스트가 설정되어있는지 확인하기 위해서

web1# httpd -S

 

-- httpd.conf --

 

#DocumentRoot "/var/www/html"

#<Directory "/var/www">

# AllowOverride None

# #Require all granted

#</Directory>

 

# Further relax access to the default document root:

#<Directory "/var/www/html">

# # http://httpd.apache.org/docs/2.4/mod/core.html#options

# Options Indexes FollowSymLinks

# AllowOverride None

# #Require all granted

# Require all denied

#</Directory>

-- httpd.conf --

 

[root@server2 conf]# httpd -t

Syntax OK

[root@server2 conf]# systemctl restart httpd

 

[root@server2 conf]# lynx --dump sbs.com

sbs.com 에 오신 것을 환영합니다.


 

DirectoryIndex

웹 서버의 도메인 or IP주소로 접근 시 파일명을 명시하지 않으면 DirectoryIndex 지시어에 설정된

순서대로 파일을 찾아서 클라이언트에서 전달한다.

DirectoryIndex 파일명

 

이 DirectoryIndex 지시어는 

/etc/httpd/conf/httpd.conf 에도 있고

/etc/httpd/conf.d/php.conf 에도 있다.

 

이 두개의 설정에서 우선순위는 /etc/httpd/conf/httpd.conf가 가지고 있다.

 

php 연동 시 httpd.conf 의 DirectoryIndex 지시어는 삭제하고

httpd.d/php.conf 의 DirectoryIndex 만 사용한다.

-- httpd.conf --

#<IfModule dir_module>

# DirectoryIndex index.html

#</IfModule>

-- httpd.conf --

 

 

----------------------------> 오른쪽으로 가면서 index.php가 없으면 index.html을 찾는다.

-- httpd.d/php.conf --

DirectoryIndex index.php index.html

-- httpd.d/php.conf --

 


실습> 정기 점검 시간 표시하기

 

1. DirectoryIndex 지시어로 변경하는 방법

서비스를 하다가 서버의 정기점검을 보여주고 싶을 때 DirectoryIndex 지시어를 변경하면 된다.

단점은 메인 페이지만 수정되어 있기 때문에 브라우저에 저장된 것은 접속이 가능하다.

 

-- /etc/httpd/conf.d/php.conf --

#DirectoryIndex index.php index.html

DirectoryIndex imsi.html index.php index.html

-- /etc/httpd/conf.d/php.conf --

 

[root@server2 conf]# vi ~sbsuser/public_html/imsi.html

<html>

<head>

<meta charset="utf8">

<title> ::: sbs.com ::: </title>

</head>

 

<body>

 

<center>

정기점검 입니다. <br>

점검시간 : 2021.2.8 01:00 ~ 18:00

</center>

 

</body>

</html>

 

[root@server2 conf]# lynx --dump sbs.com

정기점검 입니다.

점검시간 : 2021.2.8 01:00 ~ 18:00

 

 

2. 웹 페이지 경로 수정하기

-- conf.d/php.conf --

DirectoryIndex index.php index.html

-- conf.d/php.conf --

 

web1 # vi /etc/httpd/conf.d/vhostalias.conf

 디렉터리도 설정해준다. 

 

web1# su - sbsuser

마지막 로그인: 금 2월 5 08:00:40 KST 2021 일시 pts/0

[sbsuser@server2 ~]$ mkdir public_html_imsi

[sbsuser@server2 ~]$ mv public_html/imsi.html public_html_imsi/index.html

[sbsuser@server2 ~]$ chcon -Rt httpd_sys_content_t public_html_imsi

[sbsuser@server2 ~]$ logout

 

web1# systemctl restart httpd

web1# lynx --dump sbs.com

정기점검 입니다.

점검시간 : 2021.2.8 01:00 ~ 18:00

 

3. DNS 주소 변경하는 방법

DNS 를 배우고 처리!!!

 

4. 원래대로 돌리기

<VirtualHost *:80>

ServerAdmin webmaster@sbs.com

DocumentRoot /home/sbsuser/public_html

#DocumentRoot /home/sbsuser/public_html_imsi

ServerName sbs.com

ServerAlias www.sbs.com

ErrorLog logs/sbs.com-error_log

CustomLog logs/sbs.com-access_log common

</VirtualHost>

 

 

향후 관리 프로그램을 만들어서 웹 에서 통합으로 관리 할 수 있다.

 

[root@server2 conf]# setenforce 0

[root@server2 conf]# su - sbsuser

[sbsuser@server2 ~]$ cd public_html

[sbsuser@server2 public_html]$ mkdir -m 777 tmp

[sbsuser@server2 public_html]$ vi fileTest.php

<?

system("echo '1234' > tmp/a.txt");

?>

 

[sbsuser@server2 public_html]$ lynx --dump sbs.com/fileTest.php

[sbsuser@server2 public_html]$ ll tmp/

합계 4

-rw-r--r--. 1 apache apache 5 2월 5 10:38 a.txt

 


실습 > Files 지시어

 

Files : 웹 서버에 업로드된 파일에 대해서 접근 허용 유무를 설정하는 지시어

 

.htaccess : 접근 제어 파일

 

.ht 로 시작하는 파일에 대해서는 웹에서 보여지지 않게 설정한다.

<Files ".ht*">

Require all denied

</Files>

 

1. denied / granted

기본값 : Require all denied 

기본값으로 되어있을때는 .ht로 시작하는 파일을 실행할 수 없다.

 

sbsuser에 .ht로 시작하는 파일을 만들고 실행 해 보면 forbidden이 된다.

 

이 기본값을 granted로 바꾸면 실행가능하다.

web1 # systemctl restart httpd

 

실습 후에는 다시 기본값으로 막아둔다.

 

 

2. 접근 제어 파일 생성하기

일반사용자에서도 생성할 수 있다.

 

[sbsuser@server2 public_html]$ vi .htaccess

# 인증에 사용할 영역

AuthName "Admin Auth:"

# 사용자를 인증할 방법 (기본 Basic)

AuthType Basic

# 사용자

AuthUserFile "/home/sbsuser/webauth/.htpasswd"

<Limit GET POST>

# 사용자로 접근을 허용

require valid-user

</Limit>

 

 

[sbsuser@server2 public_html]$ cd ..

[sbsuser@server2 ~]$ mkdir webauth

[sbsuser@server2 ~]$ cd webauth

 

[sbsuser@server2 ~]$ htpasswd -c .htpasswd sbsuser

New password:

Re-type new password:

Adding password for user sbsuser

[sbsuser@server2 webauth]$ cat .htpasswd

sbsuser:$apr1$Y6fmMwBg$TdtDpGkkBAcJp9zR4XFZ10

 

더보기

 

-- 조건 --

1. kbs.com 도메인의 files 디렉터리를 생성하고 이 디렉터리를 자료실로 활용한다.

- 이 디렉터리는 디렉터리에 저장된 파일이 웹상에서 출력된다.

- 웹으로 접근하는 사용자는 클릭 시 파일을 다운로드 받을 수 있다.

- 접근 사용자는 아파치인증인 IP/PW 설정한다.

- ID : kbsuser, PW : 111111

 

2. mbc.com 도메인의 data 디렉터리를 생성하고 이 디렉터리를 자료실로 활용한다.

- 이 디렉터리는 디렉터리에 저장된 파일이 웹상에서 출력된다.

- 웹으로 접근하는 사용자는 클릭 시 파일을 다운로드 받을 수 있다.

- 접근 사용자는 아파치인증인 IP/PW 설정한다.

- ID : mbcuser, PW : 111111

-- 조건 --

 

1. kbs.com 도메인의 files 디렉터리를 생성하고 이 디렉터리를 자료실로 활용한다.

- 이 디렉터리는 디렉터리에 저장된 파일이 웹상에서 출력된다.

- 웹으로 접근하는 사용자는 클릭 시 파일을 다운로드 받을 수 있다.

- 접근 사용자는 아파치인증인 IP/PW 설정한다.

- ID : kbsuser, PW : 111111

 

[kbsuser@server2 ~]$ mkdir -m 755 public_html/files/

[kbsuser@server2 ~]$ cp /bin/a* public_html/files/

[kbsuser@server2 ~]$ vi public_html/files/.htaccess

# 인증에 사용할 영역

AuthName "Admin Auth:"

# 사용자를 인증할 방법 (기본 Basic)

AuthType Basic

# 사용자

AuthUserFile "/home/kbsuser/webauth/.htpasswd"

<Limit GET POST>

# 사용자로 접근을 허용

require valid-user

</Limit>

 

[kbsuser@server2 ~]$ mkdir webauth

[kbsuser@server2 ~]$ htpasswd -c webauth/.htpasswd kbsuser

New password:

Re-type new password:

Adding password for user kbsuser

[kbsuser@server2 ~]$ cat webauth/.htpasswd

kbsuser:$apr1$yK7X30VF$5HUOfJ65I8k51.1bvbmiH1

 

[root@server2 kbsuser]# vi /etc/httpd/conf.d/vhostalias.conf

<VirtualHost *:80>

ServerAdmin webmaster@kbs.com

DocumentRoot /home/kbsuser/public_html

ServerName kbs.com

ServerAlias www.kbs.com

ErrorLog logs/kbs.com-error_log

CustomLog logs/kbs.com-access_log common

 

<Directory /home/kbsuser/public_html/files>

#AllowOverride All

Options Indexes

Require all granted

</Directory>

</VirtualHost>

 

[root@server2 kbsuser]# systemctl restart httpd

 

 

아래가 안되면은 httpd_sys_content_t 로 바꾸기

[kbsuser@server2 ~]$ chcon -t httpd_user_content_t webauth/ -R

 

[root@server2 kbsuser]# sestatus

SELinux status: enabled

SELinuxfs mount: /sys/fs/selinux

SELinux root directory: /etc/selinux

Loaded policy name: targeted

Current mode: enforcing

Mode from config file: enforcing

Policy MLS status: enabled

Policy deny_unknown status: allowed

Max kernel policy version: 31

 

 

[kbsuser@server2 ~]$ lynx --dump kbs.com/files

HTTP: Access authorization required.

Use the -auth=id:pw parameter.

 

Looking up kbs.com

Making HTTP connection to kbs.com

Sending HTTP request.

HTTP request sent; waiting for response.

Alert!: Access without authorization denied -- retrying

 

lynx: Can't access startfile http://kbs.com/files

 

 

[kbsuser@server2 ~]$ lynx -auth=kbsuser:111111 --dump kbs.com/files

Index of /files

 

[ICO] [1]Name [2]Last modified [3]Size [4]Description

__________________________________________________________________

 

[PARENTDIR] [5]Parent Directory -

[ ] [6]a2p 2021-02-05 13:32 105K

[ ] [7]aaaaaaaaaaaaa 2021-02-05 13:32 115K

[ ] [8]ab 2021-02-05 13:32 51K

[ ] [9]abs2rel 2021-02-05 13:32 1.6K

[TXT] [10]aclocal 2021-02-05 13:32 36K

[TXT] [11]aclocal-1.13 2021-02-05 13:32 36K

[ ] [12]addr2line 2021-02-05 13:32 28K

[ ] [13]alias 2021-02-05 13:32 29

[ ] [14]alt-java 2021-02-05 13:32 8.8K

[ ] [15]appletviewer 2021-02-05 13:32 9.0K

[ ] [16]apropos 2021-02-05 13:32 45K

[ ] [17]ar 2021-02-05 13:32 61K

[ ] [18]arch 2021-02-05 13:32 32K

[ ] [19]aria_chk 2021-02-05 13:32 3.8M

[ ] [20]aria_dump_log 2021-02-05 13:32 3.6M

[ ] [21]aria_ftdump 2021-02-05 13:32 3.6M

[ ] [22]aria_pack 2021-02-05 13:32 3.6M

[ ] [23]aria_read_log 2021-02-05 13:32 3.8M

[ ] [24]as 2021-02-05 13:32 377K

[ ] [25]aserver 2021-02-05 13:32 28K

[ ] [26]attr 2021-02-05 13:32 11K

[TXT] [27]audit2allow 2021-02-05 13:32 14K

[TXT] [28]audit2why 2021-02-05 13:32 14K

[ ] [29]aulast 2021-02-05 13:32 15K

[ ] [30]aulastlog 2021-02-05 13:32 11K

[ ] [31]ausyscall 2021-02-05 13:32 11K

[TXT] [32]autoconf 2021-02-05 13:32 14K

[TXT] [33]autoheader 2021-02-05 13:32 8.3K

[TXT] [34]autom4te 2021-02-05 13:32 31K

[TXT] [35]automake 2021-02-05 13:32 246K

[TXT] [36]automake-1.13 2021-02-05 13:32 246K

[TXT] [37]autoreconf 2021-02-05 13:32 21K

[TXT] [38]autoscan 2021-02-05 13:32 17K

[TXT] [39]autoupdate 2021-02-05 13:32 33K

[ ] [40]auvirt 2021-02-05 13:32 32K

[ ] [41]awk 2021-02-05 13:32 419K

[DIR] [42]webauth/ 2021-02-05 12:53 -

__________________________________________________________________

 

References

 

1. http://kbs.com/files/?C=N;O=D

2. http://kbs.com/files/?C=M;O=A

3. http://kbs.com/files/?C=S;O=A

4. http://kbs.com/files/?C=D;O=A

5. http://kbs.com/

6. http://kbs.com/files/a2p

7. http://kbs.com/files/aaaaaaaaaaaaa

8. http://kbs.com/files/ab

9. http://kbs.com/files/abs2rel

10. http://kbs.com/files/aclocal

11. http://kbs.com/files/aclocal-1.13

12. http://kbs.com/files/addr2line

13. http://kbs.com/files/alias

14. http://kbs.com/files/alt-java

15. http://kbs.com/files/appletviewer

16. http://kbs.com/files/apropos

17. http://kbs.com/files/ar

18. http://kbs.com/files/arch

19. http://kbs.com/files/aria_chk

20. http://kbs.com/files/aria_dump_log

21. http://kbs.com/files/aria_ftdump

22. http://kbs.com/files/aria_pack

23. http://kbs.com/files/aria_read_log

24. http://kbs.com/files/as

25. http://kbs.com/files/aserver

26. http://kbs.com/files/attr

27. http://kbs.com/files/audit2allow

28. http://kbs.com/files/audit2why

29. http://kbs.com/files/aulast

30. http://kbs.com/files/aulastlog

31. http://kbs.com/files/ausyscall

32. http://kbs.com/files/autoconf

33. http://kbs.com/files/autoheader

34. http://kbs.com/files/autom4te

35. http://kbs.com/files/automake

36. http://kbs.com/files/automake-1.13

37. http://kbs.com/files/autoreconf

38. http://kbs.com/files/autoscan

39. http://kbs.com/files/autoupdate

40. http://kbs.com/files/auvirt

41. http://kbs.com/files/awk

42. http://kbs.com/files/webauth/

 

2. mbc.com 도메인의 data 디렉터리를 생성하고 이 디렉터리를 자료실로 활용한다.

- 이 디렉터리는 디렉터리에 저장된 파일이 웹상에서 출력된다.

- 웹으로 접근하는 사용자는 클릭 시 파일을 다운로드 받을 수 있다.

- 접근 사용자는 아파치인증인 IP/PW 설정한다.

- ID : mbcuser, PW : 111111

 

 

[mbcuser@server2 ~]$ mkdir -m 755 public_html/data

[mbcuser@server2 ~]$ cp -a /bin/a* public_html/data/

[mbcuser@server2 ~]$ vi public_html/data/.htaccess

# 인증에 사용할 영역

AuthName "Admin Auth:"

# 사용자를 인증할 방법 (기본 Basic)

AuthType Basic

# 사용자

AuthUserFile "/home/mbcuser/webauth/.htpasswd"

<Limit GET POST>

# 사용자로 접근을 허용

require valid-user

</Limit>

[mbcuser@server2 ~]$ mkdir webauth

[mbcuser@server2 ~]$ htpasswd -c webauth/.htpasswd mbcuser

New password:

Re-type new password:

Adding password for user mbcuser

[mbcuser@server2 ~]$ cat webauth/.htpasswd

mbcuser:$apr1$RD9n7zu0$CsT1DX70edA0/DLfmMNjg1

 

[mbcuser@server2 ~]$ chcon -Rt httpd_user_content_t webauth/

 

[root@server2 ~]# vi /etc/httpd/conf.d/vhostalias.conf

 

<VirtualHost *:80>

ServerAdmin webmaster@mbc.com

DocumentRoot /home/mbcuser/public_html

ServerName mbc.com

ServerAlias www.mbc.com

ErrorLog logs/mbc.com-error_log

CustomLog logs/mbc.com-access_log common

 

<Directory /home/mbcuser/public_html/data>

Options Indexes

Require all granted

</Directory>

</VirtualHost>

 

[root@server2 ~]# systemctl restart httpd

 

 

크롬에서 도메인으로 접근해서 인증이 나오면 id/pw 를 입력해서 로그인해서 파일 리스트가

출력되는지 확인한다.

http://mbc.com/data/

 

mbc.com 접속 시 디렉터리에 인증이 설정되어 있어서 접근할 수 없다.

[mbcuser@server2 data]$ lynx --dump mbc.com/data

HTTP: Access authorization required.

Use the -auth=id:pw parameter.

 

Looking up mbc.com

Making HTTP connection to mbc.com

Sending HTTP request.

HTTP request sent; waiting for response.

Alert!: Access without authorization denied -- retrying

 

lynx: Can't access startfile http://mbc.com/data

 

lynx에서 메인으로 접근해서 id/pw 를 입력해서 로그인해서 파일 리스트가 출력되는지 확인한다.

[root@server2 ~]# lynx --dump --auth=mbcuser:111111 mbc.com/data

Index of /data

 

[ICO] [1]Name [2]Last modified [3]Size [4]Description

__________________________________________________________________

 

[PARENTDIR] [5]Parent Directory -

[ ] [6]a2p 2020-10-02 01:55 105K

[ ] [7]aaaaaaaaaaaaa 2019-08-20 15:25 115K

[ ] [8]ab 2020-11-17 01:19 51K

[ ] [9]abs2rel 2015-11-21 05:02 1.6K

[TXT] [10]aclocal 2014-06-10 17:03 36K

[TXT] [11]aclocal-1.13 2014-06-10 17:03 36K

[ ] [12]addr2line 2020-10-02 01:37 28K

[ ] [13]alias 2020-04-01 11:17 29

[ ] [14]ar 2020-10-02 01:37 61K

[ ] [15]arch 2020-11-17 07:24 32K

[ ] [16]aria_chk 2020-10-02 01:56 3.8M

[ ] [17]aria_dump_log 2020-10-02 01:56 3.6M

[ ] [18]aria_ftdump 2020-10-02 01:56 3.6M

[ ] [19]aria_pack 2020-10-02 01:56 3.6M

[ ] [20]aria_read_log 2020-10-02 01:56 3.8M

[ ] [21]as 2020-10-02 01:37 377K

[ ] [22]aserver 2019-08-08 21:00 28K

[ ] [23]attr 2018-04-11 09:40 11K

[TXT] [24]audit2allow 2020-04-01 13:04 14K

[ ] [25]aulast 2019-08-08 21:06 15K

[ ] [26]aulastlog 2019-08-08 21:06 11K

[ ] [27]ausyscall 2019-08-08 21:06 11K

[TXT] [28]autoconf 2014-06-10 14:41 14K

[TXT] [29]autoheader 2014-06-10 14:41 8.3K

[TXT] [30]autom4te 2014-06-10 14:41 31K

[TXT] [31]automake 2014-06-10 17:03 246K

[TXT] [32]automake-1.13 2014-06-10 17:03 246K

[TXT] [33]autoreconf 2014-06-10 14:41 21K

[TXT] [34]autoscan 2014-06-10 14:41 17K

[TXT] [35]autoupdate 2014-06-10 14:41 33K

[ ] [36]auvirt 2019-08-08 21:06 32K

__________________________________________________________________

 

References

 

1. http://mbc.com/data/?C=N;O=D

2. http://mbc.com/data/?C=M;O=A

3. http://mbc.com/data/?C=S;O=A

4. http://mbc.com/data/?C=D;O=A

5. http://mbc.com/

6. http://mbc.com/data/a2p

7. http://mbc.com/data/aaaaaaaaaaaaa

8. http://mbc.com/data/ab

9. http://mbc.com/data/abs2rel

10. http://mbc.com/data/aclocal

11. http://mbc.com/data/aclocal-1.13

12. http://mbc.com/data/addr2line

13. http://mbc.com/data/alias

14. http://mbc.com/data/ar

15. http://mbc.com/data/arch

16. http://mbc.com/data/aria_chk

17. http://mbc.com/data/aria_dump_log

18. http://mbc.com/data/aria_ftdump

19. http://mbc.com/data/aria_pack

20. http://mbc.com/data/aria_read_log

21. http://mbc.com/data/as

22. http://mbc.com/data/aserver

23. http://mbc.com/data/attr

24. http://mbc.com/data/audit2allow

25. http://mbc.com/data/aulast

26. http://mbc.com/data/aulastlog

27. http://mbc.com/data/ausyscall

28. http://mbc.com/data/autoconf

29. http://mbc.com/data/autoheader

30. http://mbc.com/data/autom4te

31. http://mbc.com/data/automake

32. http://mbc.com/data/automake-1.13

33. http://mbc.com/data/autoreconf

34. http://mbc.com/data/autoscan

35. http://mbc.com/data/autoupdate

36. http://mbc.com/data/auvirt

 

 

 

 

 


ErrorLog 지시어

 

ErrorLog : 에러가 기록되는 파일의 경로를 가지는 지시어

 

가상호스트에서도 지정이 가능해서 가상호스트에 ErrorLog가 지정되어 있으면 에러로그가 그쪽으로 저장되고 없으면 

<VirtualHost> 밖에 있는 ErrorLog에 기록된다.

 

ErrorLog : "logs/error_log" => /var/log/httpd/error_log 에 기록된다.

 

<VirtualHost *:80>

ServerAdmin webmaster@sbs.com

DocumentRoot /home/sbsuser/public_html

#DocumentRoot /home/sbsuser/public_html_imsi

ServerName sbs.com

ServerAlias www.sbs.com

ErrorLog logs/sbs.com-error_log <== /var/log/httpd/sbs.com-error.log 에 기록된다.

CustomLog logs/sbs.com-access_log common

</VirtualHost>


LogFormat & CustomLog

 

아파치 로그는 텍스트 파일로 로그가 기록되므로 텍스트 파일을 볼 수 있는 명령어로 내용을 볼 수 있다.

 

LogFormat : 로그가 기록되는 형식

CustomLog : 클라이언트가 접근 시 기록되는 로그

 

리눅스에서 기록되는 로그는 크게 2가지 종류가 있다.

첫 번째 텍스트 형태로 기록되는 로그

- cat, tail, head 이용해서 확인한다.

- 텍스트 파일이므로 실시간 로그 모니터링이 가능하다.

- tail -f /var/log/httpd/access_log

두 번째 바이너리 형태로 기록되는 로그

- 특정 프로그램을 이용해서 확인한다.

 

 

로그포맷

 

%h : 원격 호스트 (클라이언트 IP주소)

%u : 인증 모듈 사용시 로그인한 ID

%t : common log format 시간 형식(표준 영어 형식)의 시간

%r : 요청의 첫번째 줄

%>s : 상태(status)

%b : HTTP 헤더를 제외한 전송 바이트수. CLF 형식과 같이 전송한 내용이 없는 경우 0 대신 '-'가 출력됨

%{Referer} : Referer 어디에서 왔는지 알수 있음.

%{User-Agent} : User agent 접속한 클라이언트의 브라우저 종류

 

 

LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined

CustomLog "logs/access_log" combined

 

 


실습 > LogFormat 변경

 

User-Agent : 클라이언트의 브라우저 정보를 가지고 있는 환경변수

 

User-Agent 가 있는 로그

-- httpd.conf --

<IfModule log_config_module>

:

:(생략)

# 아래 설정 추가

Logformat "%h %t \"%r\" \"%{User-Agent}i\"" linuxmasternet

</IfModule>

 

-- httpd.conf --

 

-- vhostalias.conf --

<VirtualHost *:80>

ServerAdmin webmaster@sbs.com

DocumentRoot /home/sbsuser/public_html

ServerName sbs.com

ServerAlias www.sbs.com

ErrorLog logs/sbs.com-error_log

CustomLog logs/sbs.com-access_log linuxmasternet

</VirtualHost>

 

-- vhostalias.conf --

 

[root@server2 ~]# systemctl restart httpd

 

User-Agent 가 없는 로그

LogFormat 변경

-- httpd.conf --

<IfModule log_config_module>

:

:(생략)

# 아래 설정 추가

#Logformat "%h %t \"%r\" \"%{User-Agent}i\"" linuxmasternet

Logformat "%h %t \"%r\"" linuxmasternet

</IfModule>

 

-- httpd.conf --

 


실습 > 포트 포워딩 설정

 

자신의 host 컴퓨터 ip를 확인한다. 

cmd -> ipconfig -> 

vmnet8의 nat을 수정한다.

그리고 C:\Windows\System32\drivers\etc 의 hosts 파일을 수정한다.

 

http://sbs.com

 

자신의 host ip로 로그가 남는다.

 

 

 

 


핸드폰에서 접속해보기

 

1. 검색에서 제어판을 선택

2. 시스템 및 보안

3. 방화벽 상태확인(firewall.cpl)

4. 고급 설정

 

5. 새 규칙

 

80번 포트로 지정해준다.

# vi /etc/hosts 파일을 수정해준다.

핸드폰으로도 접속 가능하다.

반응형

'정보보안(시스템,네트워크) > 리눅스' 카테고리의 다른 글

DAY_34 MPM, Nginx  (0) 2021.02.10
DAY_33 CGI  (0) 2021.02.09
DAY_31 두번째 DB연결해주기  (0) 2021.02.05
DAY_30 서버 교체해보기  (0) 2021.02.04
DAY_29 가상호스트  (0) 2021.02.03

BELATED ARTICLES

more