Security Study/Server(Linux)

apmsetup์—์„œ forbidden๋ฌธ์ œ ํ•ด๊ฒฐ

๐“›๐“พ๐“ฌ๐“ฎ๐“ฝ๐“ฎ_๐“ข๐“ฝ๐“ฎ๐“ต๐“ต๐“ช 2016. 3. 2.
728x90
๋ฐ˜์‘ํ˜•


apmํด๋”๋ฅผ ๋“ค์–ด๊ฐ€์„œ (ex)C:\APM_Setup\Server\Apache\conf) < -์ด๋ ‡๊ฒŒ ๋“ค์–ด๊ฐ€์„œ httpd.confํŒŒ์ผ์„ ๋ฉ”๋ชจ์žฅ์œผ๋กœ ์—ด์–ด 

์•„๋ž˜์™€๊ฐ™์ด ์ˆ˜์ •ํ•ด์ค€๋‹ค.


<Directory "C:/APM_Setup/htdocs">

    #

    # Possible values for the Options directive are "None", "All",

    # or any combination of:

    #   Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews

    #

    # Note that "MultiViews" must be named *explicitly* --- "Options All"

    # doesn't give it to you.

    #

    # The Options directive is both complicated and important.  Please see

    # http://httpd.apache.org/docs/2.2/mod/core.html#options

    # for more information.

    #

    Options Indexes FollowSymLinks










APMSET7์„ ์ฒ˜์Œ ์„ค์น˜ํ•˜๋ฉด ๋””๋ ‰ํ† ๋ฆฌ ๋ฐ ํŒŒ์ผ๋ชฉ๋ก์„ ๋ณผ ์ˆ˜๊ฐ€ ์—†๋Š”๋ฐ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์„ค์ •์„ ํ•˜๋ฉด ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

(1) AMP_Setup ์ด ์„ค์น˜๋œ ํด๋”๋กœ ์ด๋™ ํ•ฉ๋‹ˆ๋‹ค.

(2) Server > Apache > conf > httpd.conf ํŒŒ์ผ์„ ๋ฉ”๋ชจ์žฅ, ์—๋””ํŠธ ํ”Œ๋Ÿฌ์Šค๋“ฑ ์‚ฌ์šฉํ•˜๋Š” ํŽธ์ง‘๊ธฐ๋กœ ์—ฝ๋‹ˆ๋‹ค.

(3) 178๋ฒˆ์งธ ์ค„์— ์ž์‹ ์ด ์„ค์ •ํ•ด ๋†“์€ ๋กœ์ปฌํด๋”๊ฐ€ ๋งž๋‚˜ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

(4) 188๋ฒˆ์งธ <Directory />๋กœ ์‹œ์ž‘ํ•˜๋Š” ๊ณณ์— ๋ณด๋ฉด Options FollowSymLinks ๋ผ๊ณ  ์ ํ˜€์žˆ๋Š” ๊ณณ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

๊ทธ ๋ถ€๋ถ„์„ Options Indexes FollowSymLinks๋กœ ๋ณ€๊ฒฝํ•ด ์ฃผ๊ณ  Allow from all ๋ผ๊ณ  ์“ฐ์—ฌ์žˆ๋Š” ๋ถ€๋ถ„์ด ํ˜น์‹œ Deny from all ์ด๋ผ๊ณ  ์“ฐ์—ฌ์žˆ์œผ๋ฉด Allow๋กœ ๋ฐ”๊ฟ”์ค˜์•ผ ํ•ฉ๋‹ˆ๋‹ค.

(5) 205๋ฒˆ์งธ ์ค„์— ๋ณด๋ฉด <Directory โ€œํ•ด๋‹น๊ฒฝ๋กœโ€> ๋กœ ์ ํ˜€์žˆ๋Š” ๊ณณ๋„ ์œ„์˜ ๊ฒฝ๋กœ๋กœ ๋งž์ถฐ์ฃผ๊ณ  218๋ฒˆ์งธ ์ค„์— ๋ณด๋ฉด 4๋ฒˆ์—์„œ ์„ค๋ช…ํ•œ ๊ฒƒ๊ณผ ๊ฐ™์ด Indexes๋ฅผ ๋„ฃ์–ด์ค˜์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋˜ํ•œ 231๋ฒˆ์งธ ์ค„์—๋„ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ Deny๋กœ ๋˜์–ด์žˆ์ง€ ์•Š์€์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

(6) ์•„ํŒŒ์น˜ ์„œ๋ฒ„๋ฅผ ์žฌ๋ถ€ํŒ… ํ•˜๋ฉด ๋.

728x90
๋ฐ˜์‘ํ˜•

๋Œ“๊ธ€