-----------------------------------------
´äº¯ÀÚ°¡ ±âº»ÀûÀ¸·Î Âü°íÇÒ ³»¿ëÀÔ´Ï´Ù.
- ¹èÆ÷ÆÇ(¿É¼Ç) : CENT OS 5.5
- Ä¿³Î¹öÀü(¿É¼Ç) :
- µ¥¸ó¹öÀü(¿¹:apache 1.3.27) :
- µ¥¸ó¼³Ä¡À¯Çü(RPM/ÄÄÆÄÀÏ/±âŸ)
:
-----------------------------------------
¾È³çÇϼ¼¿ä. »êÀÌ´Ô Àú¹ø¿¡ ¾Ë·ÁÁֽŠFilesMatch Á¤»óÀûÀ¸·Î Àû¿ëÇÏ¿©
³Ê¹« Àß »ç¿ëÇϰí ÀÖ½À´Ï´Ù. °¨»çÇÕ´Ï´Ù.
´Ù¸§À̾ƴϿÀ¶ó ¿À´ÃÀº ³×À̹ö½ÅµðÄÉÀÌ¼Ç ¹®Á¦·Î Á¶¾ðÀ» ¾ò°íÀÚ ÀÌ·¸°Ô ¹æ¹®Çß½À´Ï´Ù.
³×À̹ö ½ÅµðÄÉÀ̼ÇÀ» 12³â 6¿ù10ÀÏÂ¥ Àü±îÁö ¾à 6°³¿ù°£ ÀÌ»ó ¾øÀÌ »ç¿ëÇߴµ¥¿ä.
¼¹ö¸¦ ´Ù·Î °Çµç °ÍÀº ¾ø¾ú´ø °Í°°°í php.ini ¼³Á¤Á¤µµ¸¸ ¹Ù²ãÁá´ø°É·Î ±â¾ïÇϴµ¥
/var/log/httpd/access ·Î±×¸¦ È®ÀÎÇØº¸¸é
61.247.221.21 - - [06/Jun/2012:02:08:15 +0900] "GET
/?module=syndication&act=getSyndicationList&id=tag:www.clubsound.co.kr,2011:channel:
77427&type=article&max-entry=10000&start-time=2012-06-06T01:54:58.0%2b09:00
HTTP/1.1" 200 - "-" "Java/1.6.0_24"
ÀÌ·±½ÄÀ¸·Î Á¤»óÀûÀ¸·Î Á¢±ÙÀÌ °¡´ÉÇÏ´Ù°¡
¾î´À¼ø°£ºÎÅÍ´Â
61.247.221.30 - - [03/Jul/2012:01:55:10 +0900] "GET
/?module=syndication&act=getSyndicationList&id=tag:www.clubsound.co.kr,2012:site&typ
e=channel HTTP/1.0" 200 - "-" "Yeti"
30¹ø ¼¹ö Yeti¸¸ ¹æ¹®À»Çϰí
RSSÁ¤º¸¸¦ Àо´Â 21¹ø ¼¹ö°¡ Á¢±ÙÀ» ¾ÈÇÏ´Â Çö»óÀÌ »ý°å½À´Ï´Ù.
µ¿±âÈ »óÅ deleted by error
¼¹ö µî·ÏÀÏ 2011-10-31 21:40:04
¸¶Áö¸· ¾÷µ¥ÀÌÆ® 2012-06-10 01:46:37
³×À̹öÃø¿¡ ¹®ÀÇÇÏ´Ï
61.247.221.21
61.247.221.29
61.247.221.30
À§ ¼¼°³ IP¿¡ ´ëÇÑ Â÷´Ü¿©ºÎ¸¦ È®ÀÎÇØÁֽðí,
IP°¡ ¾Æ´Ñ User_Agent ³×ÀÓÀÌ Yeti ÀÎ °æ¿ì¿¡ Â÷´ÜÀÌ µÇ°í ÀÖ´Â °Ç
¾Æ´ÑÁöµµ È®ÀÎ ºÎŹ µå¸³´Ï´Ù.
ÀÌ·¸°Ô ´äº¯ÀÌ ¿Ô½À´Ï´Ù.
iptables´Â
Chain INPUT (policy ACCEPT)
target prot opt source destination
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain RH-Firewall-1-INPUT (0 references)
target prot opt source destination
¾Æ¹«°Íµµ ¾ø±¸¿ä IP¸¦ Â÷´ÜÇÑ ±â¾ïÀÌ ¾ø´Âµ¥.. ÀÌ»óÇϳ׿ä..
XE±â¹Ý ȨÆäÀÌÁöÀε¥ XE±â´É Áß¿¡¼ IPÂ÷´ÜÇÑ ³»¿ªµµ º¸ÀÌÁö ¾Ê±¸¿ä.
´Ù¸¸ Àǽɰ¡´Â ºÎºÐÀº
robots.txt ¼³Á¤À»
User-agent: *
disallow:
ÀÌ·¸°Ô Çß¾î¾ßÇߴµ¥
User-agent: *
allow: /
ÀÌ·¸°Ô µÇ¾îÀÖ¾ú½À´Ï´Ù. ¼¹ö ȨÆäÀÌÁö°¡ ¶Ç UTF-8 Àε¥ ANSI·Î robots.txt°¡
ÀúÀåµÇ¾îÀÖ¾ú±¸¿ä~
ÇѰ¡Áö ±Ã±ÝÇÑ Á¡Àº
³×À̹öÃø¿¡¼ ¾ÆÀÌÇÇ Â÷´ÜÀÌ µÇ¾ú´ÂÁö Á¦Â÷ È®ÀÎÀ» ¿ä±¸Çϴµ¥
61.247.221.21
61.247.221.29
61.247.221.30
À§ ¼¹ö´ë¿ªÀÌ ÀúÈñ¼¹ö·Î Á¢±ÙÀÌ °¡´ÉÇÑÁö È®ÀÎÀ» ÇÏ°í ºÒ°¡´ÉÇÏ¸é ¹®Á¦Á¡À»
ÇØ°áÇϰí½Í½À´Ï´Ù.
[root@localhost httpd]# tracert 61.247.221.21
traceroute to 61.247.221.21 (61.247.221.21), 30 hops max, 40 byte packets
1 gateway218-38-12-1.youiwe.co.kr (218.38.12.1) 0.401 ms 0.466 ms 0.563 ms
2 58.229.17.89 (58.229.17.89) 3.411 ms 3.508 ms 3.506 ms
3 58.229.8.69 (58.229.8.69) 5.158 ms 5.251 ms 5.249 ms
4 118.221.7.98 (118.221.7.98) 1.960 ms 1.956 ms 1.952 ms
5 * * *
6 * * *
7 * * *
[root@localhost httpd]# tracert 61.247.221.30
traceroute to 61.247.221.30 (61.247.221.30), 30 hops max, 40 byte packets
1 gateway218-38-12-1.youiwe.co.kr (218.38.12.1) 0.357 ms 0.435 ms 0.532 ms
2 58.229.17.89 (58.229.17.89) 0.519 ms 0.515 ms 0.506 ms
3 211.108.63.137 (211.108.63.137) 7.000 ms 7.049 ms 7.136 ms
4 118.221.7.198 (118.221.7.198) 1.740 ms 1.838 ms 1.836 ms
5 * * *
6 * * *
[root@localhost httpd]# ping 61.247.221.21
PING 61.247.221.21 (61.247.221.21) 56(84) bytes of data.
find -name "*" | xargs grep "61.247.221*" | more
³×À̹ö¼¹ö°¡ ÇÎÀÌ ¸·ÇôÀÖ¾î Á¦°¡ ¾Æ´Â¹æ¹ýÀ¸·Î´Â È®ÀÎÀÌ ºÒ°¡´ÉÇØ¼ µµ¿òÀÌ
ÇÊ¿äÇմϴ٤̤Ì
|