xinetd-FAQ
xined FAQ ¹ø¿ª
Contents
2. ³ª´Â ½Ã½ºÅÛ °ü¸®ÀÚ°¡ ¾Æ´Õ´Ï´Ù. inetd ´ëü¿¡ ½Å°æ ¾µ ÇÊ¿ä ¾øÁö¿ä? ¶xinetd´Â ´Ü¼øÈ÷ inetd¸¦ ´ëüÇÏ´Â °Í¸¸ÀÌ ¾Æ´Õ´Ï´Ù. xinetd¿¡¼´Â ¼³Á¤ ÆÄÀÏ ³»ÀÇ ¼ºñ½º°¡ ²À /etc/services¿¡ ÀÖ¾î¾ß ÇÏ´Â °Ô ¾Æ´Ï±â¿¡, ¾î¶² »ç¿ëÀÚµç xinetd¸¦ ÀÌ¿ëÇØ Æ¯±Ç(¿ªÁÖ: 1024 ÀÌÇÏÀÇ) Æ÷Æ®¸¦ ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â ¼¹ö¸¦ ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.
3. inetd¿Í ȣȯ µË´Ï±î? ¶¾Æ´Ï¿À. ÀÌ°ÍÀÇ ¼³Á¤ ÆÄÀÏÀº inetd¿Í´Â ´Ù¸¥ Çü½ÄÀ» °¡Áý´Ï´Ù. ±×¸®°í ½Ã±×³ÎÀ» ´Ù¸£°Ô ÀνÄÇÕ´Ï´Ù. ±×·¯³ª ½ÅÈ£¿¡ ´ëÇÑ ÇൿÀÇ ÇÒ´çÀ» ¹Ù²Ü ¼ö ÀÖ°í, inetd.conf¸¦ xinetd.conf·Î º¯È¯ÇÏ´Â ÇÁ·Î±×·¥ÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.
4. ¿Ö ÀÌ°ÍÀ» »ç¿ëÇØ¾ß Çմϱî? ¶¿Ö³ÄÇϸé ÀÌ°ÍÀº (Á¦ ¼Ò°ßÀ¸·Î´Â) inetd º¸´Ù ´õ ÁÁ±â ¶§¹®ÀÔ´Ï´Ù. ¿©±â ±× ÀÌÀ¯°¡ ÀÖ½À´Ï´Ù.
5. ÀÌ ÇÁ·Î±×·¥¿¡ ´ëÇØ ´©±¸¿¡°Ô °¨»ç/ºñ³ ÇØ¾ß Çϳª¿ä? ¶panos@cs.colorado.edu°¡ ÀÌ ÇÁ·Î±×·¥ÀÇ ¿ø·¡ ÀúÀÚÀÌÁö¸¸, ÇöÀç Á¦(bbraun@synaok.net)°¡ ¹ö±× ¸®Æ÷Æ®¸¦ ¹Þ°í ÀÖ½À´Ï´Ù.
6. xinetdÀÇ 2.2.1 ¹öÀüÀº ¹«¾ùÀÌ ÁÁ¾ÆÁ³³ª¿ä? ¶xinetdÀÇ ¿ø·¡ ÃֽŠ¹öÀüÀº 2.1.1°ú 2.1.8±îÁö ¿Ã¸± ¼ö ÀÖ´Â ÆÐÄ¡µéÀÔ´Ï´Ù. Nick Hilliard°¡ PanosÀÇ ¹ßÇ¥µÇÁö ¾ÊÀº xinetd 2.2.0À» ±â¹ÝÀ¸·Î Çؼ xinetd 2.2.1Àº ¸¸µé¾ú½À´Ï´Ù. xinetd¿¡ Æ÷ÇÔµÈ ÀúÀÛ±Ç ¹®¼¿¡¼´Â xinetdÀÇ °ø½ÄÆÇ(ÀÌ °æ¿ì 2.1.8)ÀÌ ÁöÄÑ¾ß ÇÒ ¹öÀü ±ÔÄ¢À» ¸í½ÃÇÏ¿´´Âµ¥, µ¡ºÙÀÎ ³× ¹ø° ¹öÀü ¹øÈ£´Â º¯°æ ¼öÁØ(modification level)À» ³ªÅ¸³À´Ï´Ù. ÀÌ°ÍÀº Á¦°¡ äÅÃÇÑ ¹öÀü ±ÔÄ¢ÀÔ´Ï´Ù. ¿©±â¿¡ ÀÖ´Â xinetd 2.1.8.X´Â xinetd 2.2.0À̳ª ±× »óÀ§ ¹öÀüÀ» ±â¹ÝÀ¸·Î ÇÏÁö ¾Ê½À´Ï´Ù. ÀÌ°ÍÀº 2.1.8ÀÇ ÄÚµå ±â¹ÝÀ» °¡Áö°í ÀÛ¼ºÇÑ °ÍÀÔ´Ï´Ù. ´Ù¸¸ xinetd-2.2.1¿¡¼ µµÀÔÇÑ ¸î °¡Áö ±â´ÉµéÀ» À籸Çö Çϱâ´Â Çß½À´Ï´Ù.
7. ¾îµð¼ ÃÖ½ÅÀÌÀÚ ÃÖ°íÀÇ ¹öÀüÀ» ãÀ» ¼ö ÀÖ³ª¿ä? ¶xinetd ¼Ò½º´Â http://www.synack.net/xinetd¿¡¼ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.
8. xinetd¸¦ °¡Áö°í qmailÀÌ µ¿ÀÛÇϵµ·Ï ÇÑ »ç¶÷ ¾ø³ª¿ä? ¶ÀÖ½À´Ï´Ù, ¿©±â ±âº» Á¤º¸°¡ ÀÖ½À´Ï´Ù.
service smtp { flags = REUSE NAMEINARGS socket_type = stream protocol = tcp wait = no user = qmaild server = /usr/sbin/tcpd server_args = /var/qmail/bin/tcp-env -R /var/qmail/bin/qmail-smtpd } /etc/hosts.allow ¿¡¼ ȯ°æ º¯¼ö¿Í ÀÌ°ÍÀú°ÍµéÀ» ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. xinetd¸¦ libwrap Áö¿øÀ» Æ÷ÇÔÇؼ ÄÄÆÄÀÏ ÇÒ ¼ö ÀÖ±â´Â ÇÏÁö¸¸, ÀÌ´Â tcpdÀÇ ±â´ÉÀ» ¿Ïº®ÇÏ°Ô ´ë½ÅÇÒ ¼ö ÀÖ´Ù´Â ¶æÀº ¾Æ´Õ´Ï´Ù. xinetd´Â host_access(5) ¸ÇÆäÀÌÁö¿¡¼ ¼³¸íÇÏ´Â Á¢±Ù Á¦¾î¸¦ ¼öÇàÇÏ´Â host_access() ¸¦ È£ÃâÇÕ´Ï´Ù. ÀÌ°ÍÀº tcpd°¡ Á¦°øÇÏ´Â ±â´Éµé Áß ÀϺÎÀÔ´Ï´Ù.
9. xinetd°¡ µ¿ÀÛÇÑ´Ù°í ¾Ë·ÁÁø Ç÷§ÆûÀº ¹«¾ùÀԴϱî? ¶Àú´Â ¼Ö¶ó¸®½º 2.6(sparc¿Í x86), ¸®´ª½º, BSDi, ±×¸®°í IRIX 5.3°ú 6.2¿¡¼ ½ÇÇàÇØ ºÃ½À´Ï´Ù. ¿øº» ÆÐÅ°Áö´Â SunOS 4¿Í Ultrix¿¡¼ µ¿ÀÛÇß½À´Ï´Ù.
10. ¼ºñ½º¿¡ ´ëÇØ chroot ȯ°æÀº ¾î¶»°Ô ¼³Á¤Çϳª¿ä? ¶¿©±â °£´ÜÇÑ ¼³Á¤ ÆÄÀÏÀÌ ÀÖ½À´Ï´Ù.
service telnet_chroot { log_on_sucess = HOST PID DURATION USERID log_on_failure = HOST RECORD USERID no_access = 152.30.11.93 socket_type = stream protocol = tcp port = 8000 wait = no user = root server = /usr/sbin/chroot server_args = /var/public/servers /usr/libexec/telnetd } 11. itox´Â ¾î¶»°Ô »ç¿ëÇϳª¿ä? ¶itox´Â Ç¥ÁØ ÀÔ·ÂÀ¸·Î ¿Ã¹Ù¸¥ inetd.conf¸¦ ÀÐ¾î¼ Ç¥ÁØ Ãâ·ÂÀ¸·Î xinetd.conf¸¦ ±â·ÏÇÕ´Ï´Ù. ÀϹÝÀûÀ¸·Î ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.
itox < /etc/inetd.conf > /etc/xinetd.conf itox -daemon_dir=/usr/sbin < /etc/inetd.conf > /etc/xinetd.conf 12. xinetd´Â libwrap (tcpwrappers)¸¦ Áö¿øÇմϱî? ¶¿¹.
configure ½ºÅ©¸³Æ® ¿É¼ÇÀ¸·Î --with-libwrap À» Àü´ÞÇÏ¿© xinetd°¡ libwrapÀ» Áö¿øÇϵµ·Ï ÄÄÆÄÀÏ ÇÒ ¼ö ÀÖ½À´Ï´Ù. libwrap Áö¿øÀ» Æ÷ÇÔÇؼ xinetd¸¦ ÄÄÆÄÀÏ ÇÏ¸é ¸ðµç ¼ºñ½ºµéÀÌ /etc/hosts.allow ¹× /etc/hosts.deny ¹æ½ÄÀÇ Á¢±Ù Á¦¾î¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. ¶ÇÇÑ ÀüÅëÀûÀÎ inetd ¹æ½ÄÀ¸·Î tcpd¸¦ »ç¿ëÇϵµ·Ï xinetd¸¦ ±¸¼ºÇØ ÁÙ ¼öµµ ÀÖ½À´Ï´Ù. ÀÌ´Â NAMEINARGS Ç÷¡±× »ç¿ëÀ» ÇÊ¿ä·Î Çϸç, ½ÇÁ¦ µ¥¸óÀÇ À̸§´Â server_args·Î Àü´ÞÇØ ÁÖ¾î¾ß ÇÕ´Ï´Ù. ¿©±â tcpd·Î ÅÚ³ÝÀ» »ç¿ëÇÏ´Â ¿¹Á¦°¡ ÀÖ½À´Ï´Ù.
service telnet { flags = REUSE NAMEINARGS protocol = tcp socket_type = stream wait = no user = telnetd server = /usr/sbin/tcpd server_args = /usr/sbin/in.telnetd } 15. setgroups(0, NULL) ¿À·ù´Â ¹«¾ùÀԴϱî? ¶±âº»ÀûÀ¸·Î xinetd´Â ¼¹ö ÇÁ·Î¼¼½ºµé¿¡ ´ëÇÑ ±×·ì ±ÇÇÑÀ» Çã¿ëÇÏÁö ¾ÊÀ¸¸ç, ÀÌ´Â ÀÚ½Ä ÇÁ·Î¼¼½ºÀÇ ±×·ìÀ» ºó°ª(nothing)À¸·Î ¼³Á¤ÇÏ´Â ¹æ½ÄÀ¸·Î ÀÌ·ïÁý´Ï´Ù. ¾î¶² BSD´Â ÀÌ¿Í °ü·ÃÇØ ¹®Á¦°¡ ÀÖ½À´Ï´Ù. ÀÌ ¿À·ù¸¦ ÇÇÇÏ·Á¸é ´ç½ÅÀÇ ¼ºñ½º¿¡
groups = yes ¶ó´Â Áö½ÃÀÚ¸¦ ³ÖÀ¸¸é µË´Ï´Ù. ÀÌ´Â ¼¹ö ÇÁ·Î¼¼½º°¡ µ¿ÀÛÁßÀÎ »ç¿ëÀÚ¿Í µ¿µîÇÏ°Ô ¸ðµç ±×·ì ±ÇÇÑÀ» ¼¹ö ÇÁ·Î¼¼½º°¡ °¡Áú ¼ö ÀÖµµ·Ï ÇØÁÝ´Ï´Ù.
16. ¿Ö ¸®´ª½º¿¡¼ teletd°¡ Á¤»óÀûÀ¸·Î ½ÇÇàµÇÁö ¾Ê½À´Ï±î? ¶¸î¸î ¸®´ª½º ¹èÆ÷Æǵ鿡¼´Â ±ÇÇÑ ¾ø´Â »ç¿ëÀÚ·Î ÅÚ³Ý µ¥¸óÀ» ½ÃÀÛÇÕ´Ï´Ù. ´ë½Å ±× »ç¿ëÀÚ´Â »õ·Î¿î tty¸¦ ¿°í utmp¸¦ ¼öÁ¤ÇÒ ¼ö ÀÖ´Â ±×·ì¿¡ ¼Ò¼ÓµÇ¾î ÀÖ½À´Ï´Ù. ±âº»ÀûÀ¸·Î xinetd´Â ¼¹ö ÇÁ·Î¼¼¼¿¡ ±×·ì ±ÇÇÑÀ» Çã¿ëÇÏÁö ¾ÊÀ¸¸ç, µû¶ó¼ telnetd°¡ ¿Ã¹Ù¸£°Ô ½ÃÀÛÇÏÁö ¸øÇÒ ¼ö ÀÖ½À´Ï´Ù. ¼¹ö ÇÁ·Î¼¼½º°¡ ¿Ã¹Ù¸¥ ±×·ìÀ» °®Ãßµµ·Ï ÇÏ·Á¸é ÅÚ³Ý ¼ºñ½º¿¡
groups = yes Áö½ÃÀÚ¸¦ »ç¿ëÇÏ¸é µË´Ï´Ù. ÀÌ´Â xinetd¿¡°Ô »ç¿ëÀÚ°¡ Æ÷ÇÔµÈ ¸ðµç ±×·ìÀ» °®Ãß°í ¼¹ö ÇÁ·Î¼¼½º¸¦ ½ÃÀÛÇصµ ±¦Âú´Ù´Â °ÍÀ» ¾Ë·ÁÁÝ´Ï´Ù.
17. xinet¸¦ ÀÌ¿ëÇؼ ¼ºñ½º¸¦ SSL·Î °¨½Î·Á¸é ¾î¶»°Ô ÇØ¾ß µÇ³ª¿ä? ¶¼ºñ½º¸¦ SSL·Î °¨½Î·Á¸é stunnel ÇÁ·Î±×·¥À» »ç¿ëÇϼ¼¿ä. ÀÌ°Ç inetd¸¦ ÅëÇØ ½ÇÁ¦·Î »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
18. cvs ¼¹ö¸¦ xinetd¿¡ ¾î¶»°Ô ¼³Á¤Çմϱî? ¶¾î¶² »ç¿ë°¡ ´ÙÀ½ Á¦¾ÈÀ» ½è½À´Ï´Ù.
cvpserver stream tcp nowait root /usr/bin/cvs cvs --allow-root=/home/pauljohn/cvsroot --allow-root=/home/pauljohn/cvsmisc pserver service cvspserver { socket_type = stream protocol = tcp wait = no user = root passenv = server = /usr/bin/cvs server_args = --allow-root=/home/pauljohn/cvsroot --allow-root=/home/pauljohn/cvsmisc pserver -f } |
Good fortune in love, as well as a better position. |