Skip to content

๐Ÿชต 3. ์ธํ”„๋ผ ์‹ค์Šต(1) : ์ธ์Šคํ„ด์Šค ์ƒ์„ฑ

ssum1ra edited this page Dec 5, 2024 · 1 revision

์ธ์Šคํ„ด์Šค ์ƒ์„ฑ

์„œ๋ฒ„ ์ด๋ฏธ์ง€ ์„ ํƒ

image (2)

  • ubuntu-22.04

VPC ์ƒ์„ฑ

image (3)

Public Subnet ์ƒ์„ฑ

image (4)

์„œ๋ฒ„ ์„ค์ •

image (5)

์Šคํ† ๋ฆฌ์ง€ ์„ค์ •

image (6)

์ธ์ฆํ‚ค ์„ค์ •

image (7)

๋„คํŠธ์›Œํฌ ์ ‘๊ทผ ์„ค์ •

image (8)

Public IP ํ• ๋‹น

image (9)

  • ์ธ์Šคํ„ด์Šค์— ํ• ๋‹น๋˜๋Š” ip ์ฃผ์†Œ

ACG ์„ค์ •

  • Brute Force Attack ๋•Œ๋ฌธ์— ์ถ”ํ›„ ์„ค์ •
  • ๊ธฐ๋ณธ ์„ค์ •

image (10)

image (11)

.pem์œผ๋กœ ๋กœ๊ทธ์ธ

1. root ๊ณ„์ • ๋น„๋ฐ€๋ฒˆํ˜ธ ํ™•์ธ

image (12)

2. ๊ณ„์ • ์ƒ์„ฑ

~# useradd -c "NCLOUD Default User" -m -s /bin/bash ncloud
~# id ncloud
~# gpasswd -a ncloud systemd-journal
~# cat << EOF > /etc/sudoers.d/10-ncloud-users
> ncloud ALL=(ALL) NOPASSWD:ALL
> EOF
~# chmod 440 /etc/sudoers.d/10-ncloud-users

3. Key ํŒŒ์ผ ์„ค์ •

// ์ƒˆ cmd ์ฐฝ 
> scp "[pem ํŒŒ์ผ ์ฃผ์†Œ]" root@[IP์ฃผ์†Œ]:/home/ncloud

// ssh
~# passwd -l root

~# cd /home/ncloud/
~/home/ncloud# chmod 600 [pem ํŒŒ์ผ]
~/home/ncloud# chown ncloud:ncloud [pem ํŒŒ์ผ]
~/home/ncloud# mkdir .ssh
~/home/ncloud# ssh-keygen -y -f [pemํŒŒ์ผ] > .ssh/authorized_keys
~/home/ncloud# chmod 700 .ssh
~/home/ncloud# chmod 600 .ssh/authorized_keys
~/home/ncloud# chown -R ncloud:ncloud .ssh

4. sshd.config ์ˆ˜์ •

~# sudo vi /etc/ssh/sshd_config
> 38: PermitRootLogin yes -> #PermitRootLogin yes // ์ฃผ์„์ฒ˜๋ฆฌ
> 65: #PermitRootLogin yes -> PasswordAuthentication no // no๋กœ ๋ณ€๊ฒฝ

5. SSH ์„œ๋ฒ„ ์„œ๋น„์Šค ์žฌ์‹œ์ž‘

~# sudo systemctl restart sshd

6. ncloud ๊ณ„์ •์œผ๋กœ ์ ‘์†

ssh -i "[pem ํŒŒ์ผ ์ฃผ์†Œ]" ncloud@[ip ์ฃผ์†Œ]

์ฐธ๊ณ 

๐Ÿ˜Ž ์›จ๋ฒ ๋ฒ ๋ฒ ๋ฒฑ

๐Ÿ‘ฎ๐Ÿป ํŒ€ ๊ทœ์น™

๐Ÿ’ป ํ”„๋กœ์ ํŠธ

๐Ÿชต ์›จ๋ฒ ๋ฒฑ ๊ธฐ์ˆ ๋กœ๊ทธ

๐Ÿช„ ๋ฐ๋ชจ ๊ณต์œ 

๐Ÿ”„ ์Šคํ”„๋ฆฐํŠธ ๊ธฐ๋ก

๐Ÿ“— ํšŒ์˜๋ก

Clone this wiki locally