File: lidsconf.8

package info (click to toggle)
manpages-ja 0.5.0.0.20080615-1
  • links: PTS
  • area: main
  • in suites: lenny
  • size: 20,508 kB
  • ctags: 1
  • sloc: sh: 13,690; perl: 157; makefile: 114
file content (347 lines) | stat: -rw-r--r-- 10,026 bytes parent folder | download | duplicates (4)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
.TH LIDSCONF 8
.\"
.\" Man page written by Sander Klein <roedie@roedie.nl> (May 2003)
.\" It is based on the original lidsadm page by Steve Bremer.
.\" TODO: I will think of something in the end...
.\"
.\"	This program is free software; you can redistribute it and/or modify
.\"     it under the terms of the GNU General Public License as published by
.\"     the Free Software Foundation; either version 2 of the License, or
.\"     (at your option) any later version.
.\"
.\"     This program is distributed in the hope that it will be useful,
.\"     but WITHOUT ANY WARRANTY; without even the implied warranty of
.\"     MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
.\"     GNU General Public License for more details.
.\"
.\"     You should have received a copy of the GNU General Public License
.\"     along with this program; if not, write to the Free Software
.\"     Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
.\"
.\" Japanese Version Copyright (c) 2003 Omo Kazuki
.\"         all rights reserved.
.\" Translated Tue Oct 1 11:00:39 JST 2003
.\"         by Kazuki Omo
.\"
.SH ̾
lidsconf \- Linux Intrusion Detection System Ѥġ
.SH 
.B lidsconf -A [-s subject] -o object [-d] [-t from-to] [-i level] -j ACTION
.br
.B lidsconf -D [-s file] [-o file]
.br
.B lidsconf -Z
.br
.B lidsconf -U
.br
.B lidsconf -L [-e]
.br
.B lidsconf -P
.br
.B lidsconf -v
.br
.B lidsconf [-h|H]

.SH 

.I lidsconf 
ϡLinux Intrusion Detection System (LIDS) ġǤ롣

LIDS ϸߤLinux ͥĥ롢ͥѥåǤ롣LIDS ˤ
ơפʥե䡢ǥ쥯ȥ䡢ǥХݸ뤳ȤǤ롣
˥ƥΤФơ¤򤫤ACL 뤳Ȥ
롣LIDS ξܤ˴ؤƤϡ
.I http://www.lids.org
򻲾ȤΤȡ

.I lidsconf
LIDS ФƤΥ¾ꤹ뤿˻Ѥ롣
ؤƤξϡ"/etc/lids/lids.conf" ¸롣

.SH ץ (ACL )
ACL  "Access Control List" άǤ롣LIDS ACL ǤϡSubject ɤ
ͤObject ФƥΤƤ롣 Subject ϡ
ƥΡǤդΥץեؤƤ롣Object ϥե䡢ǥ
쥯ȥ䡢¾̤ʥץ (MEM ǥХRAW IOץ
)ؤƤ롣Target ϡSbject Object Ф륢פ
Ƥ롣
.TP
ACL ν񼰤 
.B
[-s subject] [-d|-i TTL] -o object [-t timescale] -j TARGET
.TP
Subject άȡACL ϤObject ФǥեȤΥ
.TP
.B -s subject
Subject Ȥϡƥ"/bin/login" Τ褦ʡǤդΥץǤ
.TP
.B -o object [portscale]
Object ϥե䡢ǥ쥯ȥ䡢¾̤ʥץ
(CAP_SYS_RAWIO, CAP_HIDDEN, CAP_INIT_KILL, ʤ) Ǥ롣.  Object 
CAP_NET_BIND_SERVICE ξˤϡ㤨С"20-299,400-1002" Τ褦ˡ³ƥݡֹϰϤꤹɬפ롣
.TP
.B -d
ϡDOMAIN ѤǤ롣ꤹȡSubject Domain 
ƤObject ˤΤߥǽˤʤ롣Domain ʳObject
˴ؤƤΥϡǤʤʤ롣
.TP
.B -i <inheritance level>
ǡSubjectλҥץФƤACL ηѾꤹ롣
.B inheritance level
ϡɤ줰餤ޤACL ƶΤɽƤ롣Ѿ٥"-1" ϡ
̵¤ηѾɽ
Ѿ٥1 ϡƥץˤȯ줿ƱץǤ̵ҥ
ACL Ѿ뤬ҥץȯҥץ(ʤ
ꥸʥΥץ鸫¹ץ)ˤϡACL ϷѾʤȤ
ȤɽƤ롣
Ѿ٥ϡƥץȤϰۤʤץΡҥץˤΤͭ
ʤ롣⤷ҥץƥץƱˤϡƥץȴ
Ʊ¤Ϳ롣

.TP
.B -t ॹ
ϡACL Ф¤Ǥ롣¤ϡSubject դACL 
ΤߡѤ롣¤ȤϡACL ͭˤʤӤǤ롣
ν񼰤ϡ"hourminute-hourminute" ˤʤ롣㤨С"0905-1021" ϡ
"9 5 ʬ顢10 21 ʬޤ" Ȥʤ롣

.TP
.B -j Target
Target ˤϡ̾Υե륢ACL ФREAD, APPEND, WRITE, 
뤤 IGNORE Ǥ롣üObject ФƤϡTarget GRANT
Ǥ롣

.TP
.SH Ѳǽʸ
LIDS ǻȤ븢¤ˤϡΤΤ롣ؤ򤹤
ˡ¤̵ͭˤ뤿̾Ѥ뤳ȤǤ롣
ˡ¤ƥΤ̵ˤʤäƤȤǤ⡢ץ˸
Ϳ뤳ȤǤ롣

.SP
.TP
.B CAP_CHOWN
chown(2)/chgrp(2)
.TP
.B    CAP_DAC_OVERRIDE
DAC access.
.TP
.B CAP_DAC_READ_SEARCH
DAC read.
.TP
.B          CAP_FOWNER
桼ID ȥʡID ʤ
.TP
.B          CAP_FSETID
¹ԥ桼ID ȥʡID ʤ
.TP
.B            CAP_KILL
/ͭID ȥץID ʤ
.TP 
.B         CAP_SETGID
setgid(2)
.TP 
.B          CAP_SETUID 
set*uid(2)
.TP
.B         CAP_SETPCAP
ž
.TP
.B  CAP_LINUX_IMMUTABLE
Ѥդäե
.TP
.B CAP_NET_BIND_SERVICE
1024 ̤ΥݡȤؤΥХǥ
.TP
.B   CAP_NET_BROADCAST
ޥ㥹ȤΥ֥ɥ㥹/ꥹ˥
.TP
.B       CAP_NET_ADMIN
󥿡ե/ե/롼ƥ ѹ
.TP
.B         CAP_NET_RAW
RAW å(ping) 
.TP
.B        CAP_IPC_LOCK
ͭ꡼ȤΥå
.TP
.B       CAP_IPC_OWNER
IPC ͭԤΥå
.TP
.B      CAP_SYS_MODULE
ͥ⥸塼Ⱥ
.TP
.B       CAP_SYS_RAWIO
ioperm(2)/iopl(2) 
.TP
.B      CAP_SYS_CHROOT
chroot(2)
.TP
.B      CAP_SYS_PTRACE
ptrace(2)
.TP
.B       CAP_SYS_PACCT
ץƥ󥰤
.TP
.B       CAP_SYS_ADMIN
ԤνŤ
.TP
.B        CAP_SYS_BOOT
reboot(2)
.TP
.B        CAP_SYS_NICE
nice(2)
.TP
.B    CAP_SYS_RESOURCE
꥽¤
.TP
.B        CAP_SYS_TIME
ƥ֤
.TP
.B  CAP_SYS_TTY_CONFIG
TTY 
.TP
.B  CAP_MKNOD
mknod() ̤ʵ
.TP
.B  CAP_LEASE
ե˥꡼
.TP
.B  CAP_HIDDEN
ƥफץ򱣤
.TP
.B  CAP_KILL_PROTECTED
ץˡݸƤץkill 뤳Ȥ/Ե
.TP
.B  CAP_PROTECTED
ʥ뤫ץݸ

.SH 
ʲˡĤlidsconf Ȥä򼨤ϴñ/ʿפʤ
Τ顢ʣ/ʤΤޤǤ롣 ºݤΥե̾ϤäȶŪ
ΤȤ뤳Ȥդ뤳ȡ
.B ºݤΥƥ
˹碌ƥե/ǥ쥯ȥ֤뤳ȡ
.TP
.B lidsconf -A -o /sbin -j READ
ACL ϡ/sbin ǥ쥯ȥɹѤݸ롣
.TP
.B lidsconf -A -o /var/log/message -j APPEND
/var/log/messages ղѤˤ롣
.TP
.B lidsconf -A -o /sbin/test -j IGNORE
/sbin ɹѤݸ뤬/sbin/test ݸʤ
.TP
.B lidsconf -A -o /etc/passwd -j DENY
/etc/passwd ƤΥ桼鱣ե򸫤褦ʤ
(open, stat, ʤ)ϡǤʤʤ롣
.TP
.B lidsconf -A -s /bin/login -o /etc/passwd -j READ
/bin/login ץˡۤɤDZեˤƤ
/etc/passwd ɤ߹ळȤĤ롣
ξ硢/bin/login Τߤ/etc/passwd ɤळȤǤ롣¾
ץ桼ϡΥե(/etc/passwd) 򸫤뤳ȤϤǤʤ
.TP
.B lidsconf -A -o /home/httpd -j DENY
.TP
.B lidsconf -A -s /usr/sbin/httpd -o /home/httpd -j READ
.TP
.B lidsconf -A -s /usr/sbin/httpd -o CAP_NET_BIND_SERVICE 80 -i -1 -j GRANT
Web СServerROOT (/home/httpd) DENY ݸhttpd 
ʥ꡼(/usr/sbin/httpd) ΤߤServerROOT (/home/httpd) ɤ߹
ȤĤơhttpd ݡֹ80 ֤ˤΤߥХɤǤ褦
ˤ뤳ȤĤ롣
.TP
.B lidsconf -A -s /bin/program -i 2 -o CAP_NET_ADMIN -j GRANT
/bin/program CAP_NET_ADMIN θ¤ͿѾ٥2 ꤷƤ
.TP
.B lidsconf -A -s /usr/X11/bin/XF86_SVGA -o CAP_SYS_RAWIO -j GRANT
XF86_SVGA CAP_SYS_RAWIO θ¤CAP_SYS_RAWIO /etc/lids/lids.cap
̵ˤʤäƤȤˤ⡢Ϳ롣
.TP
.B lidsconf -A -s /usr/sbin/httpd -d -o /home/httpd -j READ
httpd μ¹ԥɥᥤ/home/httpd ȤƤ롣/home/httpd ʳ
ΡɤΤ褦ʥڥ졼⡢httpd ưƤȤˤϵĤʤ
.TP
.B lidsconf -A -s /bin/login -o /etc/shadow -t 0900:1800 -j READ
/bin/login /etc/shadow ե09:00 18:00 δ֤ɤ߹
뤳ȤĤ롣ˤꡢ桼Υ򡢤λ֤
¤뤳ȤǤ롣
.TP
.B lidsconf -A -s /usr/sbin/sshd -o CAP_NET_BIND_SERVICE 10-22,300-1020 -j GRANT
/usr/sbin/sshd ݡֹ10 22 ޤǤȡ300 1020 ޤǥХ
ɤ뤳ȤǤ褦Ƥ롣ΥǤϡssh Ϥֹ
ϰϤΤߤǤХɤǤʤ

.SH ¾ξ
.TP
.B ᡼󥰥ꥹ
á񤹤ȤˤϡΥȤ򻲾-
.I http://lists.sourceforge.net/lists/listinfo/lids-user
.br
å-᡼󥰥ꥹȤƤȤϡ᡼򼡤ΤȤޤ
Ƥۤ-
.B lids-user@lists.sourceforge.net
.br
ǿLIDS ᡼󥰥ꥹȤΥ֤ϡΤȤˤ-
.I http://www.geocrawler.com/redir-sf.php3?list=lids-user
.br
Ť֤ϡΤȤˤ-
.I http://groups.yahoo.com/group/lids

.TP
.B LIDS FAQ
LIDS FAQ ϼΤȤˤ-
.br
.I http://www.lids.org/lids-faq/lids-faq.html
.br
뤤ϡ
.br
.I http://www.roedie.nl/lids-faq

.SH Х
LIDS ˴ؤХϡXie Phil 뤫뤤ϥ᡼󥰥ꥹ
.B (lids-user@lists.sourceforge.net)
äƤۤ
ͥ򥳥ѥ뤹Ȥ˻Ȥä.config եȡ/etc/lids 
lids.conf lids.cap ե뤳ȡޤΥ
˥奢ڡǥ顼դ顢Sander Klein ޤΤ餻ߤ
.SH ե
\fB/etc/lids/lids.conf\fR \- LIDS ե
.br
\fB/etc/lids/lids.cap\fR \- Τθ¤
.br
\fB/etc/lids/lids.net\fR \- e-mail 顼Ȥ
.br
\fB/etc/lids/lids.pw\fR \- Ź沽줿LIDS ѥ

.SH Ϣ
.BR lidsadm (8)

.SH AUTHORS
Huagang Xie
.I <xie@lids.org>
.PP
Philippe Biondi
.I <biondi@cartel-securite.fr>
.PP
ޥ˥奢ڡϡSander Klein ˤäƽ񤫤줿
.I <roedie@roedie.nl>
.PP

.SH 
.I LIDS 
κǿΥСϡ
.I http://www.lids.org/ 
ߥ顼ɤǤ롣

.\" See the lidsadm (8) man page for some funny remarks...
.\"

.Sp
.I LIDS 
.is (C) 1999-2003 by Huagang Xie(xie@lids.org)
¾ϡlidsadm (8) Υޥ˥奢򻲾ȤΤȡ