Infra & DevOps 42

[Linux] Fail2Ban์ด SSH ํฌํŠธ์—์„œ ๋™์ž‘ํ•˜์ง€ ์•Š๋Š” ์ด์œ ์™€ ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…

์ ์šฉํ•ด๋‘์—ˆ๋˜ fail2ban์ด ์ œ๋Œ€๋กœ ์ž‘๋™์ด ์•ˆ๋˜์–ด ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ… ๊ณผ์ •์„ ๊ธฐ๋กํ•ด๋ณด๊ณ ์ž ํ•œ๋‹ค. ์ด์ „์— ์ ์šฉํ–ˆ๋˜ Fail2ban ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๊ฐ€ ์ œ๋Œ€๋กœ ์ž‘๋™๋˜์ง€ ์•Š๋Š” ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ–ˆ๋‹ค. ์•„๋ž˜์˜ ๋ช…๋ น์–ด๋กœ ์ƒํƒœ๋ฅผ ํ™•์ธํ–ˆ์„ ๋•Œ๋Š” Banned IP List์— SSH ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•œ IP๊ฐ€ ์ œ๋Œ€๋กœ ban๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋Š”๋ฐ, ์‹ค์ œ๋กœ ssh ์ ‘์†์„ ์‹œ๋„ํ•˜๋ฉด ์ ‘์†์ด ๋˜์—ˆ์Œfail2ban-client status sshd๋ถ„๋ช… iptables ๋ช…๋ น์–ด๋กœ ํ™•์ธํ•ด๋„ REJECT๋˜์–ด์žˆ๋Š”๋ฐ... ์™œ ์ ‘์†์ด ๋˜๋Š”์ง€ ๊ฒ€์ƒ‰ํ•ด๋ณด์•˜๋‹ค. 1. conf ํŒŒ์ผ ํ™•์ธ/etc/fail2ban/jail.local ๊ฒฝ๋กœ๋กœ ์ ‘์†ํ•˜์—ฌ config ํŒŒ์ผ์„ ํ™•์ธํ–ˆ๋‹ค.[DEFAULT]bantime = -1 findtime = 2mmaxretry = 8[sshd]en..

Infra & DevOps 2025.02.04

[Linux] Fail2ban์„ ์‚ฌ์šฉํ•˜์—ฌ Rocky Linux ๋ณด์•ˆ ์„ค์ •ํ•˜๊ธฐ

Fail2ban ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์„ค์น˜ํ•˜๊ณ  ์‚ฌ์šฉํ•˜๋Š” ๊ณผ์ •์„ ์ž‘์„ฑํ–ˆ๋‹ค. ํ…Œ์ŠคํŠธ ์„œ๋ฒ„๋กœ ์ผœ๋†“์€ ๋ฆฌ๋ˆ…์Šค ์„œ๋ฒ„์— SSH ์ ‘๊ทผ ์‹œ๋„๊ฐ€ ๋„ˆ๋ฌด ๋งŽ์•„์กŒ๋‹ค.์›๋ž˜ ๊ณต์œ ๊ธฐ ๋‹จ์—์„œ ํŠน์ • IP๋ฅผ ์ฐจ๋‹จํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•ด์™”๋Š”๋ฐ ์‹œ๊ฐ„์ด ์ง€๋‚ ์ˆ˜๋ก ์‹œ๋„๊ฐ€ ๋” ๋งŽ์•„์ ธ์„œ ์˜ค๋Š˜ ์ƒˆ๋ฒฝ์—๋งŒ 1,2149๊ฑด์˜ ์‹œ๋„๊ฐ€ ๋ฐœ์ƒํ–ˆ์Œ...๋ฐฉ๋ฒ•์„ ์ฐพ์•„๋ณด๋‹ค Fail2ban์ด๋ผ๋Š” ๋ณด์•ˆ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์„ค์น˜ํ•˜๊ธฐ๋กœ ํ–ˆ๋‹ค. Fail2ban ์„ค์น˜Fail2ban์€ ๋ฆฌ๋ˆ…์Šค/์œ ๋‹‰์Šค ์‹œ์Šคํ…œ์—์„œ ๋กœ๊ทธ ํŒŒ์ผ(์ฃผ๋กœ ssh ๋กœ๊ทธ)์„ ๋ถ„์„ํ•˜์—ฌ ๋ฐ˜๋ณต์ ์ธ ๋น„์ •์ƒ ์ ‘๊ทผ ์‹œ๋„๋ฅผ ๋ฐฉ์ง€ํ•˜๋Š” ๋ณด์•ˆ ์†Œํ”„ํŠธ์›จ์–ด์ด๋‹ค. SSH, FTP, HTTP์™€ ๊ฐ™์€ ์„œ๋น„์Šค์— ๋Œ€ํ•œ Brute force ๊ณต๊ฒฉ์„ ์ฐจ๋‹จํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋œ๋‹ค.dnf install fail2ban -ysystemctl status fail2ban.servi..

[AWS] Native Observability - Logs ์‹ค์Šต

AWS Community Day์—์„œ ์‹ค์Šตํ•œ ๋‚ด์šฉ์„ ๋ฐ”ํƒ•์œผ๋กœ ๊ณต๋ถ€ํ•œ ๊ฒƒ์„ ์ •๋ฆฌํ•ด๋ณด๊ณ ์ž ํ•œ๋‹ค. AWS๊ฐ€ ์ž์ฒด์ ์œผ๋กœ ์ œ๊ณตํ•˜๋Š” ๋ชจ๋‹ˆํ„ฐ๋ง ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•ด๋ณด๋Š” ์‹ค์ŠตCloudWatch, X-Ray์™€ ๊ฐ™์€ ๋ชจ๋‹ˆํ„ฐ๋ง ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค์–‘ํ•œ ํ™˜๊ฒฝ์—์„œ ์‹œ์Šคํ…œ์˜ ๋™์ž‘, ์„ฑ๋Šฅ ๋“ฑ์„ ๋Šฅ๋™์ ์œผ๋กœ ํŒŒ์•…ํ•  ์ˆ˜ ์žˆ๋‹ค. CloudWatch Logs๋ž€?CloudWatch Logs๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์‹œ์Šคํ…œ, ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜, AWS ์„œ๋น„์Šค์˜ ๋กœ๊ทธ๋ฅผ ํ•œ ๊ณณ์—์„œ ์‰ฝ๊ฒŒ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ ํŠน์ • ์—๋Ÿฌ ์ฝ”๋“œ๋‚˜ ํŒจํ„ด์„ ๊ฒ€์ƒ‰ํ•˜๊ธฐ ์šฉ์ดํ•˜๋ฉฐ, ๋กœ๊ทธ๋ฅผ ํŠน์ • ํ•„๋“œ๋กœ ํ•„ํ„ฐ๋งํ•˜๊ฑฐ๋‚˜ ์•„์นด์ด๋ธŒํ•˜์—ฌ ์ถ”ํ›„ ๋ถ„์„ํ•˜๊ธฐ์—๋„ ํŽธํ•˜๋‹ค. ๋˜ํ•œ, CloudWatch Logs Insights๋กœ ์ฟผ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•ด ๋กœ๊ทธ ๋ฐ์ดํ„ฐ๋ฅผ ๊ฒ€์ƒ‰ ๋ฐ ๋ถ„์„ํ•  ์ˆ˜ ์žˆ๋‹ค. Logs Insights ์‹ค์Šต - ์‹œ๊ฐ„์ด ์ง€..

Infra & DevOps 2024.11.12

[Linux] Rocky Linux 9.4 IP ์„ค์ •์„ Static์—์„œ DHCP๋กœ ๋ณ€๊ฒฝํ•˜๊ธฐ

๊ฐ€์ƒ OS์˜ IP ์„ค์ •์„ Static์—์„œ DHCP๋กœ ๋ณ€๊ฒฝํ•˜๋Š” ๊ณผ์ •์—์„œ ๋ฐฐ์šด ๋‚ด์šฉ์„ ๊ธฐ๋กํ–ˆ๋‹ค. ์นด๊ณต์„ ์ž์ฃผํ•ด์„œ ๋‹ค์–‘ํ•œ ์™€์ดํŒŒ์ด๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ๋•Œ๋ฌธ์— ํ˜ธ์ŠคํŠธ OS(๋กœ์ปฌ ํ™˜๊ฒฝ)์˜ ๋„คํŠธ์›Œํฌ๊ฐ€ ์ž์ฃผ ๋ฐ”๋€Œ๊ฒŒ ๋˜์—ˆ๋‹ค. ๊ทธ์— ๋”ฐ๋ผ Static์œผ๋กœ ์„ค์ •ํ–ˆ๋˜ ๊ฐ€์ƒ OS์˜ ๋„คํŠธ์›Œํฌ ์„ค์ •์„ ๊ณ„์†ํ•ด์„œ ์ˆ˜๋™์œผ๋กœ ๋ฐ”๊ฟ”์•ผ ํ•˜๋Š” ๋ถˆํŽธํ•จ์ด ์ƒ๊ฒผ๋‹ค.๋งค๋ฒˆ ๋„คํŠธ์›Œํฌ ๋Œ€์—ญ์ด ๋ณ€๊ฒฝ๋  ๋•Œ๋งˆ๋‹ค IP๋ฅผ ์ˆ˜์ •ํ•˜๋Š” ๊ฒƒ์ด ๊ท€์ฐฎ์•„์„œ ๊ฐ€์ƒ OS์˜ IP ์„ค์ •์„ DHCP๋กœ ๋ณ€๊ฒฝํ•ด ์ž๋™์œผ๋กœ IP๋ฅผ ํ• ๋‹น๋ฐ›์„ ์ˆ˜ ์žˆ๋„๋ก ์„ค์ •ํ•˜๊ธฐ๋กœ ํ–ˆ๋‹ค. Static IP์™€ DHCP์˜ ์ฐจ์ดStatic IP์‚ฌ์šฉ์ž๊ฐ€ IP ์ฃผ์†Œ๋ฅผ ์ง์ ‘ ์ง€์ •ํ•˜๊ณ  ๊ณ ์ •๋œ ๊ฐ’์œผ๋กœ ๋„คํŠธ์›Œํฌ๋ฅผ ์„ค์ •ํ•œ๋‹ค. ๋„คํŠธ์›Œํฌ ๋Œ€์—ญ๋Œ€๊ฐ€ ๋ฐ”๋€Œ๋”๋ผ๋„ IP ์ฃผ์†Œ๋Š” ๋ณ€๊ฒฝ๋˜์ง€ ์•Š๋Š”๋‹ค. ์„œ๋ฒ„๋‚˜ ํŠน์ • ์žฅ์น˜์—์„œ IP๊ฐ€ ๋ฐ”๋€Œ์ง€ ์•Š์•„์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ์— ..

[Linux] Rocky Linux 9.x ๋ฒ„์ „ SSH Root ๋กœ๊ทธ์ธํ•˜๋Š” ๋ฐฉ๋ฒ•

Rocky Linux 9๋ฒ„์ „๋ถ€ํ„ฐ ๋ณด์•ˆ์ƒ์˜ ์ด์œ ๋กœ root ๊ณ„์ •์œผ๋กœ ssh๋ฅผ ํ†ตํ•œ ์ง์ ‘ ์ ‘์†์ด ๋น„ํ™œ์„ฑํ™”๋˜์—ˆ๋‹ค.์ด๋ฅผ ํ™œ์„ฑํ™”์‹œํ‚ค๊ธฐ ์œ„ํ•ด์„œ๋Š” sshd_config ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ด์•ผ ํ•œ๋‹ค.1. ssh config ํŒŒ์ผ ์ˆ˜์ •sudo vi /etc/ssh/sshd_config2. PermitRootLogin yes๋กœ ๋ณ€๊ฒฝ๊ธฐ๋ณธ๊ฐ’์€ prohibit-password๋กœ ๋˜์–ด์žˆ๋Š”๋ฐ ์ด๊ฑด root ๊ณ„์ •์œผ๋กœ์˜ ssh ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•˜๊ธด ํ•˜์ง€๋งŒ, ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ํ†ตํ•œ ์ธ์ฆ์€ ํ—ˆ์šฉํ•˜์ง€ ์•Š๋Š”๋‹ค๋Š” ๋œป์ด๋‹ค. ์ด๋ฅผ yes๋กœ ๋ฐ”๊ฟ”์ค€๋‹ค.3. ssh ์„œ๋น„์Šค ์žฌ์‹œ์ž‘sudo systemctl restart sshd ์ดํ›„ ssh๋กœ ๋‹ค์‹œ ์ ‘์†ํ•ด๋ณด๋ฉด ์ ‘์†์ด ๋˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.