EXWOLF°Q½×°Ï's Archiver

wolf µoªí©ó 2008-1-6 14:45

LinuxÀ³¥Î¨Ï¥ÎTSIG©MDNSSEC¥[©T°ì¦WªA°È¾¹

¤@¡BDNSªA°È¾¹ªº­«­n©Ê
DNS¬O¦]¯Sºô«Ø³]ªº°ò¦¡A´X¥G©Ò¦³ªººôµ¸À³¥Î¡A³£¥²¶·¨Ì¿àDNS«Y²Î°µºô§}¬d¸ßªº«ü¤Þ°Ê§@¡C¦pªGDNS«Y²Î¹B§@¤£¥¿±`¡A§Y¨ÏWebªA°È¾¹³£§¹¦n¦pªì¡A¨¾¤õùÙ«Y²Î³£µ½ºÉ¨ä¾¡A¬ÛÃöªº«áºÝÀ³¥ÎªA°È¾¹¥H¤Î¼Æ¾Ú®w«Y²Î¹B§@¥¿±`¡A¦]¬°µLªk¦b´Á­­®É¶¡¤º¬d±o¨ìºô§}¡A±N·|¾É­P¹q¤l¶l¥óµLªk¶Ç»¼¡A·Q­n¨Ï¥Îºô°ì¦WºÙ¥h³s±µ¬Y­Óºô­¶¡A¤]·|¦]¬d¤£¥Xºôµ¸¦a§}¡A¥H­PÁp¾÷¥¢±Ñ¡C2001¦~1¤ë24¤é¡A¬ü°ê·L³n¤½¥q©ÒºÞ²zªº¬ÛÃöºôµ¸«Y²Î¡A¾D¨üºôµ¸¶Â«Èªº©Úµ´ªA°È§ðÀ»«á¾É­P¥þ²y¦U¦aªº¥Î¤á±µªñ24¤p®Éªº®É¶¡µLªk³s¤W¸Ó¤½¥q¬ÛÃöªººô¯¸¡A³y¦¨¸Ó¤½¥q¬Û·íÄY­«ªº°Ó·~·l¥¢¡C®Ú¾Ú¥H©¹ªº¸gÅ礧¤¤¡Aºôµ¸§ðÀ»ªº¹ï¶H¦h¼Æ¥D­n¶°¤¤¦b±±¨îºôµ¸¸ô¥Ñªº³]³Æ(¸ô¥Ñ¾¹¡A¨¾¤õùÙµ¥)©M¦UÃþÀ³¥ÎªA°È¾¹(Web¡B¶l¥óµ¥)¡C¦]¦¹¡A¥Ø«e¦h¼Æªººôµ¸«Y²Î¦w¥þ«OÅ@¡A³q±`³£¶°¤¤¦b¸ô¥Ñ³]³Æ©MÀ³¥ÎªA°È¾¹¥»¨­¡CµM¦Ó¡A³o¤@¦¸ªº·L³n¤½¥q³Q§ðÀ»¨Æ¥ó¡A»P¥H©¹¨ä¥¦ºô¯¸§ðÀ»¨Æ¥óªº³Ì¤j¤£¦P¡A´N¦b©ó³o¤@¦¸³Q§ðÀ»ªº¹ï¶H¬ODNSªA°È¾¹¦Ó¤£¬OWEBªA°È¾¹¥»¨­¡C³o¦¸ªº¨Æ¥ó«Å§i¥t¤@ºØ·s«¬ªººôµ¸§ðÀ»Ãþ§O¡A©¹«á±N¥i¯à¦¨¬°±`ºA¡C

¤¬Ápºô¤WDNSªA°È¾¹ªº¨Æ¹ê¼Ð·Ç´N¬OISC¡][url]http://www.isc.org/[/url] ¡^¤½¥qªºBerkeley Internert Name Domain(BIND)¡A¥¦¨ã¦³¼sªxªº¨Ï¥Î°ò¦¡A¤¬Ápºô¤Wªºµ´¤j¦h¼ÆDNSªA°È¾¹³£¬O°ò©ó³o­Ó³n¥óªº¡CNetcraft¦b°ì¦WªA°È¾¹¤Wªº²Î­p ([url]http://www.netcraft.com/[/url] )Åã¥Ü 2003¦~²Ä¤G©u«×¶i¦æªº¤@­Ó½Õ¬dµo²{¡A¦b¤¬Ápºô¤W¹B¦æµÛªºDNSªA°È¾¹¤¤¡AISCªºBIND¦û¾Ú¤F95%ªº¥«³õ¥÷ÃB¡C¤¬Ápºô¬O¥Ñ«Ü¦h¤£¥i¨£ªº°ò¦ºc¥ó²Õ¦¨¡C³o¨ä¤¤´N¥]§t¤FDNS¡A¥¦µ¹¥Î¤á´£¨Ñ¤F©ö©ó°O¾Ðªº¾÷¾¹¦WºÙ(¤ñ¦psina.com)¡A¨Ã¥B±N¥¦­Ì½Ķ¦¨¼Æ¦r¦a§}ªº§Î¦¡¡C¹ï©ó¨º¨Ç¥Î©ó¤½¦@ªA°Èªº¾÷¾¹¤@¯ëÁÙ´£¨Ñ¡§¤Ï¦V¬d¸ß¡¨ªº¥\¯à¡A³oºØ¥\¯à¥i¥H§â¼Æ¦rÂà´«¦¨¦W¦r¡C¥Ñ©ó¾ú¥vªº­ì¦]¡A³oºØ¥\¯à¨Ï¥Îªº¬O³QÁôÂ꺡§in-addr.arpa¡¨°ì¡C¹ïin- addr°ìªº½Õ¬d¡A¥i¥HÅý§Ú­Ì§ó¥[¤F¸Ñ¾ã­ÓInternet¬O¦p¦ó¹B§@ªº¡CBill Manning¹ïin-addr°ìªº½Õ¬dµo²{¡A¦³95%ªº°ì¦WªA°È¾¹(2ªº2000¦¸¤è­ÓªA°È¾¹¤¤)¨Ï¥Îªº¬O¦UºØª©¥»ªº¡§bind¡¨¡C³o¨ä¤¤¥]¬A¤F©Ò¦³ªº DNS®ÚªA°È¾¹¡A¦Ó³o¨Ç®ÚªA°È¾¹¹ï¾ã­ÓªA°È¾¹ªº¥¿±`¹BÂà°_µÛ¦ÜÃö­«­nªº§@¥Î¡C¦p¦ó¯à¥[±j½T«O DNS «Y²Îªº¹B§@¥¿±`¡A©ÎªÌ·íDNS«Y²Î¦b¾D¨üºôµ¸§ðÀ»®É­Ô¡A ¯à°÷ÅýºÞ²zªÌ¤Î¦­µo²{¬O¤é¯q­«­nªº«Y²Î¦w¥þªº½ÒÃD¡C­º¥ý§Ú­Ì­n¤F¸ÑDNSªA°È­±Á{ªº¦w¥þ°ÝÃD¡C [color=#f5fafe][/color]
¤G¡BDNSªA°È­±Á{ªº¦w¥þ°ÝÃD¡G

DNSªA°È­±Á{ªº¦w¥þ°ÝÃD¥D­n¥]¬A¡GDNS´ÛÄF¡]DNS Spoffing¡^¡B©Úµ´ªA°È¡]Denial of service¡ADoS¡^§ðÀ»¡B¤À¥¬¦¡©Úµ´ªA°È§ðÀ»©M½w½Ä°Ïº|¬}·¸¥X§ðÀ»¡]Buffer Overflow¡^¡C  
1¡BDNS´ÛÄF

DNS´ÛÄF§Y°ì¦W«H®§´ÛÄF¬O³Ì±`¨£ªºDNS¦w¥þ°ÝÃD¡C·í¤@­ÓDNSªA°È¾¹±¼¤J³´¨À¡A¨Ï¥Î¤F¨Ó¦Û¤@­Ó´c·NDNSªA°È¾¹ªº¿ù»~«H®§¡A¨º¤\¸ÓDNSªA°È¾¹´N³Q´ÛÄF¤F¡CDNS´ÛÄF·|¨Ï¨º¨Ç©ö¨ü§ðÀ»ªºDNSªA°È¾¹²£¥Í³\¦h¦w¥þ°ÝÃD¡A¨Ò¦p¡G±N¥Î¤á¤Þ¾É¨ì¿ù»~ªº¤¬Ápºô¯¸ÂI¡A©ÎªÌµo°e¤@­Ó¹q¤l¶l¥ó¨ì¤@­Ó¥¼¸g±ÂÅvªº¶l¥óªA°È¾¹¡Cºôµ¸§ðÀ»ªÌ³q±`³q¹L¤TºØ¤èªk¶i¦æDNS´ÛÄF¡C¹Ï1¬O¤@­Ó¨å«¬ªºDNS´ÛÄFªº¥Ü·N¹Ï¡C ¤¤°ê
[align=center] [attach]693[/attach][color=#f5fafe][/color] [/align][align=center]¹Ï1 ¨å«¬DNS´ÛÄF¹Lµ{  [/align]¡]1¡^½w¦s·P¬V ¤¤°ê
¶Â«È·|¼ô½mªº¨Ï¥ÎDNS½Ð¨D¡A±N¼Æ¾Ú©ñ¤J¤@­Ó¨S¦³³]¨¾ªºDNSªA°È¾¹ªº½w¦s·í¤¤¡C³o¨Ç½w¦s«H®§·|¦b«È¤á¶i¦æDNS³X°Ý®Éªð¦^µ¹«È¤á¡A±q¦Ó±N«È¤á¤Þ¾É¨ì¤J«IªÌ©Ò³]¸mªº¹B¦æ¤ì°¨ªºWebªA°È¾¹©Î¶l¥óªA°È¾¹¤W¡AµM«á¶Â«È±q³o¨ÇªA°È¾¹¤WÀò¨ú¥Î¤á«H®§¡C

¡]2¡^DNS«H®§§T«ù
¤¤°ê
¤J«IªÌ³q¹LºÊÅ¥«È¤áºÝ©MDNSªA°È¾¹ªº¹ï¸Ü¡A³q¹L²q´úªA°È¾¹ÅTÀ³µ¹«È¤áºÝªºDNS¬d¸ßID¡C¨C­ÓDNS³ø¤å¥]¬A¤@­Ó¬ÛÃöÁpªº16¦ìID¸¹¡ADNSªA°È¾¹®Ú¾Ú³o­ÓID¸¹Àò¨ú½Ð¨D·½¦ì¸m¡C¶Â«È¦bDNSªA°È¾¹¤§«e±Nµê°²ªºÅTÀ³¥æµ¹¥Î¤á¡A±q¦Ó´ÛÄF«È¤áºÝ¥h³X°Ý´c·Nªººô¯¸¡C

¡]3¡^DNS´_¦ì©w¦V

§ðÀ»ªÌ¯à°÷±NDNS¦WºÙ¬d¸ß´_¦ì¦V¨ì´c·NDNSªA°È¾¹¡C³o¼Ë§ðÀ»ªÌ¥i¥HÀò±oDNSªA°È¾¹ªº¼gÅv­­¡C

2¡B©Úµ´ªA°È§ðÀ» [color=#f5fafe][/color]
¶Â«È¥D­n§Q¥Î¤@¨ÇDNS³n¥óªºº|¬}¡A¦p¦bBIND 9ª©¥»¡]ª©¥»9.2.0¥H«eªº 9«Y¦C¡^¦pªG¦³¤H¦V¹B¦æBINDªº³]³Æµo°e¯S©wªºDNS¼Æ¾Ú¥]½Ð¨D¡ABIND´N·|¦Û°ÊÃö³¬¡C§ðÀ»ªÌ¥u¯à¨ÏBINDÃö³¬¡A¦ÓµLªk¦bªA°È¾¹¤W°õ¦æ¥ô·N©R¥O¡C¦pªG±o¤£¨ìDNSªA°È¡A¨º¤\´N·|²£¥Í¤@³õ¨aÃø¡G¥Ñ©óºô§}¤£¯à¸ÑªR¬°IP¦a§}¡A¥Î¤á±NµL¤è³X°Ý¤¬Ápºô¡C³o¼Ë¡ADNS²£¥Íªº°ÝÃD´N¦n¹³¬O¤¬Ápºô¥»¨­©Ò²£¥Íªº°ÝÃD¡A³o±N¾É­P¤j¶qªº²V¶Ã¡C [color=#f5fafe][/color]
3¡B¤À¥¬¦¡©Úµ´ªA°È§ðÀ»

DDOS §ðÀ»³q¹L¨Ï¥Î§ðÀ»ªÌ±±¨îªº´X¤Q»O©Î´X¦Ê»O­pºâ¾÷§ðÀ»¤@»O¥D¾÷¡A¨Ï±oªA°È©Úµ´§ðÀ»§óÃø¥H¨¾½d¡G¨ÏªA°È©Úµ´§ðÀ»§óÃø¥H³q¹Lªý¶ë³æ¤@§ðÀ»·½¥D¾÷ªº¼Æ¾Ú¬y¡A¨Ó¨¾½dªA°È©Úµ´§ðÀ»¡CSyn Flood¬O°w¹ïDNSªA°È¾¹³Ì±`¨£ªº¤À¥¬¦¡©Úµ´ªA°È§ðÀ»¡C

4¡B½w½Ä°Ïº|¬} [color=#f5fafe][/color]
Bind³n¥óªº¯Ê¬Ù³]¸m¬O¤¹³\¥D¾÷¶¡¶i¦æ°Ï°ì¶Ç¿é¡]zone transfer¡^¡C°Ï°ì¶Ç¿é¥D­n¥Î©ó¥D°ì¦WªA°È¾¹»P»²°ì¦WªA°È¾¹¤§¶¡ªº¼Æ¾Ú¦P¨B¡A¨Ï»²°ì¦WªA°È¾¹¥i¥H±q¥D°ì¦WªA°È¾¹Àò±o·sªº¼Æ¾Ú«H®§¡C¤@¥¹°_¥Î°Ï°ì¶Ç¿é¦Ó¤£°µ¥ô¦ó­­¨î¡A«Ü¥i¯à·|³y¦¨«H®§ªnº|¡A¶Â«È±N¥i¥HÀò±o¾ã­Ó±ÂÅv°Ï°ì¤ºªº©Ò¦³¥D¾÷ªº«H®§¡A§PÂ_¥D¾÷¥\¯à¤Î¦w¥þ©Ê¡A±q¤¤µo²{¥Ø¼Ð¶i¦æ§ðÀ»¡C  
À³¹ï¥H¤W³o¨Ç¦w¥þ°ÝÃD¦³¨â­Ó¤ñ¸û¦³®Ä¤èªk¡GTSIG©MDNSSEC§Þ³N¡C

¤G¡BTSIG§Þ³N [color=#f5fafe][/color]
DNSªº¨Æ°Èñ¦W¤À¬° TSIG (Transaction Signatures) »P SIG0 (SIGnature)¨âºØ¡C¸Ó¦p¦ó¿ï¾Ü©O? ­º¥ý¡A­n¥ý§PÂ_«È¤áºÝ»PªA°È¾¹¶¡ªº«H¥ôÃö«Y¬°¦ó¡A­Y¬O¥i«H¥ôªÌ¡A¥i¿ï¾Ü¹ïºÙ¦¡ªº TSIG¡CTSIG ¥u¦³¤@²Õ±K½X¡A¨ÃµL¤½¶}/¨p±Kª÷Æ_¤§¤À¡F­Y¬O«D§¹¥þ«H¥ôªÌ¡A¥i¿ï¾Ü«D¹ïºÙ¦¡ª÷Æ_ªº SIG0¡AÁö¦³¤½¶}/¨p±Kª÷Æ_¤§¤À¡A¬Û¹ïªº¡A³]©w¤W¤]¸û´_Âø¡C¦Ü©ó­n¿ï¥Î­þºØ¸û¾A¦X¡A´N¥Ñ¦Û¤v¨Ó§PÂ_¡C³q±`°Ï±a¶Ç¿é¬O¥D°ì¦WªA°È¾¹¨ì»²§U°ì¦WªA°È¾¹¡C³q±`¦b¥D°ì¦WªA°È¾¹°t¸m¤å¥ó/etc/named.confªºdns-ip-listªº³X°Ý±±¨î¦Cªí¡]ACL¡Aaccess control list¡^·|¦C¥X¤@¨ÇIP¦a§}¡A¥¦­Ì¥u¯à¬°¥D°ì¶i¦æ¶Ç¿é°Ï±a«H®§¡C¤@­Ó¨å«¬¨Ò¤l¦p¤U¡G Www.

[table=95%][tr][td][color=#ff0000]¥H¤U¬°¤Þ¥Îªº¤º®e¡G[/color]
acl ¡§dns-ip-list¡¨ {
172.20.15.100;
172.20.15.123;
};
zone ¡§yourdomain.com¡¨ {
type master;
file ¡§mydomain.dns¡¨;
allow-query { any; };
allow-update { none; };
allow-transfer { dns-ip-list; }; };[/td][/tr][/table][color=#f5fafe][/color] ³£¬O¶Â«È·|§Q¥ÎIP´ÛÄF¤@­ÓDNSªA°È¾¹¡A­¢¨Ï¨ä¶i¦æ«Dªk°Ï±a¶Ç¿é¡CTSIG§Þ³N¥i¥H¶i¦æ¦³®Ä¨¾½d¡C

1¡BTSIG§Þ³N

¥æ©öñ³¹ (TSIGRFC 2845)¡A¬O¬°¤F«OÅ@ DNS¦w¥þ¦Óµo®iªº¡C±qBIND 8.2ª©¥»¶}©l¤Þ¤J TSIG ¾÷¨î¡A¨äÅçÃÒ DNS °T®§¤è¦¡¬O¨Ï¥Î¦@¨Éª÷Æ_(Secret Key) ¤Î³æ¦VÂø´ê¨ç¦¡(One-way hash function) ¨Ó´£¨Ñ°T®§ªºÅçÃÒ©M¼Æ¾Úªº§¹¾ã©Ê¡C¥D­n°w¹ï°Ï±a¶Ç¿é¡]ZONE Transfer¡^¶i¦æ«OÅ@ªº§@¥Î¡A§Q¥Î±K½X¾Ç½s½X¤è¦¡¬°³q°T¶Ç¿é«H®§¥[±K¥H«OÃÒ DNS °T®§ªº¦w¥þ¡A¯S§O¬OÅTÀ³»P§ó·sªº°T®§¼Æ¾Ú¡C¤]´N¬O»¡¦bDNSªA°È¾¹¤§¶¡¶i¦æÁҰ϶ǰe®É©Ò´£¨Ñ«OÅ@ªº¾÷¨î¡A¥H½T«O¶Ç¿é¼Æ¾Ú¤£³QÅѨú¤ÎºÊÅ¥¡C¤U­±¥HBIND 9.21¬°¨Ò¡G [color=#f5fafe][/color]
­º¥ý¦b¶}©l³]¸m¡A¥²¶·¬°¥D°ì¦WªA°È¾¹¡]master DNS¡^©M»²§U°ì¦W¡] slave DNS¡^ ¶i¦æ®É¶¡¦P¨B¡A§_«h·|³y¦¨°Ï±a¶Ç¿éªº¥¢±Ñ¡C¥i¥H¨Ï¥Întp©ÎªÌrdate¤u¨ã¶i¦æªA°È¾¹®É¶¡¦P¨B¡C  
°²³]­n­­¨îyourdomain.comªº¥D°ì¨ìIP¦a§}¤À§O¬O172.20.15.100 (ns1.yourdomain. com) ©M 172.20.15.123 (ns2.yourdomain.com). ªº¨â­Ó»²§U°ì¦WªA°È¾¹¤§¶¡¶i¦æ°Ï±a¶Ç¿é¡C¦b¦¹±N¸Ô­z TSIG ªº¹ê»Ú¾Þ§@¡A¥i¥H¨¾¤îDNSªA°È¾¹©M¶Â«ÈªºDNSªA°È¾¹¤§¶¡¤£·|µo¥ÍIP´ÛÄF¡C [color=#f5fafe][/color]
¨BÆJ¤@¡G°õ¦æ dnssec-keygen function ²£¥Í¥[±Kª÷Æ_¡A¤@­Ó¬° public key ¤å¥ó¡A¥t¤@­Ó¬° private key ¤å¥ó¡G

²£¥Í¥[±Kª÷Æ_¡G [color=#f5fafe][/color]
dnssec-keygen -a hmac-md5 -b 128 -n HOST zone-xfr-key

¸Ó¤å¥ó¤¤¤½¶}ª÷Æ_¡]public key¡^¬O¡G Kzone-xfr-key.+157+08825.key¡F¨p¦³ª÷Æ_¡]private key¡^¬OKzone-xfr-key.+157+08825.private¡C¦¹®É¬d¬Ý¤å¥ó³q±`¥]¬A¥H¤U¤º®e¡G ¤¤°ê

[table=95%][tr][td][color=#ff0000]¥H¤U¬°¤Þ¥Îªº¤º®e¡G[/color]
Private-key-format: v1.2
Algorithm: 157 (HMAC_MD5)
Key: YH8Onz5x0/twQnvYPyh1qg==[/td][/tr][/table][color=#f5fafe][/color] ¨BÆJ¤G¡G¨Ï¥ÎTSIG ª÷Æ_¦b¥D°ì¦WªA°È¾¹©M»²§U°ì¦WªA°È¾¹ªº³]¸m¤å¥ónamed.conf³]©w¡G


[table=95%][tr][td][color=#ff0000]¥H¤U¬°¤Þ¥Îªº¤º®e¡G[/color]
key zone-xfr-key {
algorithm hmac-md5;
secret ¡§YH8Onz5x0/twQnvYPyh1qg==¡¨;
};[/td][/tr][/table] ¨BÆJ¤T¡G±N¤U­±ªºÁn©ú¥[¤JªA°È¾¹ns1.yourdomain.comªº³]¸m¤å¥ó/etc/named.conf¤¤¡G


[table=95%][tr][td][color=#ff0000]¥H¤U¬°¤Þ¥Îªº¤º®e¡G[/color]
server 172.20.15.123 {
keys { zone-xfr-key; };
};[/td][/tr][/table]
¨BÆJ¥|¡G±N¤U­±ªºÁn©ú¥[¤JªA°È¾¹ns2.yourdomain.comªº³]¸m¤å¥ó/etc/named.conf¤¤¡G [color=#f5fafe][/color]

[table=95%][tr][td][color=#ff0000]¥H¤U¬°¤Þ¥Îªº¤º®e¡G[/color]
server 172.20.15.100 {
keys { zone-xfr-key; };
};[/td][/tr][/table]
¨BÆJ¤­¡G¬°¥D°ì¦WªA°È¾¹ns1.yourdomain.comªºyourdomain.com°Ï±aªº³]¸m¤å¥ó/etc/named.conf¼g¤J¥H¤U°t¸m¡G [color=#f5fafe][/color]

[table=95%][tr][td][color=#ff0000]¥H¤U¬°¤Þ¥Îªº¤º®e¡G[/color]
acl ¡§dns-ip-list¡¨ {
172.20.15.100;
172.20.15.123;
};
key zone-xfr-key {
algorithm hmac-md5;
secret ¡§YH8Onz5x0/twQnvYPyh1qg==¡¨;
};
server 172.20.15.123 {
keys { zone-xfr-key; };
};
zone ¡§yourdomain.com¡¨ {
type master;
file ¡§mydomain.dns¡¨;
allow-query { any; };
allow-update { none; };
allow-transfer { dns-ip-list; };
};[/td][/tr][/table]
¨BÆJ¤»¡G¬°»²§U°ì¦WªA°È¾¹ns2.yourdomain.comªºyourdomain.com°Ï±aªº³]¸m¤å¥ó/etc/named.conf¼g¤J¥H¤U°t¸m¡G [color=#f5fafe][/color]

[table=95%][tr][td][color=#ff0000]¥H¤U¬°¤Þ¥Îªº¤º®e¡G[/color]
acl ¡§dns-ip-list¡¨ {
172.20.15.100;
172.20.15.123;
};
key zone-xfr-key {
algorithm hmac-md5;
secret ¡§YH8Onz5x0/twQnvYPyh1qg==¡¨;
};
server 172.20.15.100 {
keys { zone-xfr-key; };
};
zone ¡§yourdomain.com¡¨ {
type master;
file ¡§mydomain.dns¡¨;
allow-query { any; };
allow-update { none; };
allow-transfer { dns-ip-list; };
};[/td][/tr][/table] ¨BÆJ¤C¡G¦A¦¸­«·s±Ò°Ê¥D°ì¦WªA°È¾¹©M»²§U°ì¦WªA°È¾¹¡C

»¡©ú¬°½T«O¦w¥þ©Êªº°ÝÃD¡ATSIG ¥i½T»{ DNS ¤§«H®§¬O¥Ñ¬Y¯S©w DNS Server ©Ò´£¨Ñ¡C³q±`TSIG À³¥Î©ó°ì¦WªA°È¾¹¶¡ªº°Ï±a¶Ç¿é¡A½T«O¼Æ¾Ú¤£·|³Q¿y§ï©Î²£¥Í dns spoofing¡C [color=#f5fafe][/color]
¨BÆJ¤K¡G

ÅçÃÒTSIG§Þ³N¬O§_¥Í®Ä¡A¨BÆJ¦p¤U¡G  
§R°£»²§U°ì¦WªA°È¾¹(ns2.yourdomain.com)ªº°Ï±a¤å¥ó¡C [color=#f5fafe][/color]
­«·s±Ò°Ê»²§U°ì¦WªA°È¾¹¡C [color=#f5fafe][/color]
Àˬd»²§U°ì¦WªA°È¾¹ªº°Ï±a¤å¥ó¬O§_¦Û°Ê«Ø¥ß¡C»²§U°ì¦WªA°È¾¹¥Î¨Ó±q¥DªA°È¾¹¤¤Âಾ¤@¾ã®M°ì«H®§¡C°Ï±a¤å¥ó¬O±q¥DªA°È¾¹Âಾ¥Xªº¡A§@¬°ºÏ½L¤å¥ó«O¦s¦b»²§U°ì¦WªA°È¾¹¤¤¡C
¤¤°ê
ª`·N¨Æ¶µ¡G¦pªG¬°°ì¦WªA°È¾¹°t¸m¤FTSIG¡A¨º¤\­n½T«O´¶³q¥Î¤á¤£¯à±µÄ²¥D°ì¦WªA°È¾¹©M»²§U°ì¦WªA°È¾¹ªº°t¸m¤å¥ó/etc/named.conf¡C¥t¥~¤]¤£¯à­×§ï¨â»OªA°È¾¹ªº¦@¨ÉªºTSIG±KÆ_¡C

2¡BSIG0 §Þ³N²¤¶

SIG0¬O¤@¤E¤E¤E¦~¤T¤ë ¥Ñ IBM¤½¥qªºD. Eastlake ´£¥X¦¨¬°¼Ð·Ç¡C¨ä¬O§Q¥Î¤½¶}ª÷Æ_¾÷¨î¬°ÁÒ°Ï¸ê®Æ¶i¦æ¼Æ¦rñ³¹ªº°Ê§@¡A¥H«OÃÒ¨Cµ§¶Ç¿éªº source record ¨ã¦³¥iÅçÃÒ©Ê»P¤£¥i§_»{©Ê¡C¹ê»Ú¤W SIG0 ¤~¬O¨¾¤î DNS Spoofing µo¥Í³Ì¥D­nªº§Þ³N¡ASIG0 ¬O¨Ï¥Î¤½¶}ª÷Æ_¥[±Kªk¡AÅýÁҰϺ޲zªÌ¬°¨äÁҰϼƾڥ[¤W¼Æ¦rñ³¹¡A¥Ñ¦¹ÃÒ©úÁÒ°Ï¸ê®Æªº¥i«H¿à©Ê¡C°£¦¹¤§¥~¡ASIG0 «O¦³¬O§_¿ï¾Ü»{ÃÒ¾÷¨îªº¼u©Ê¡A¥H¤Î¥iÆF¬¡¦a°t¦X¦Û­qªº¦w¥þ¾÷¨î¡C  
¤T¡BDNSSEC§Þ³N
¤¤°ê
DNS´ÛÄF¬O¹ï¥Ø«eºôµ¸À³¥Î¡A³Ì¤jªº½ÄÀ»¦b©ó«_¦WªÌ­ÉµÛ´£¨Ñ°²ªººô°ì¦WºÙ»Pºô§}ªº¹ï·Ó«H®§¡A¥i¥H±N¤£ª¾±¡¥Î¤áªººô­¶Áp¾÷¡A¾É¤Þ¨ì¿ù»~ªººô¯¸¡A­ì¥»ÄÝ©ó¥Î¤áªº¹q¤l¶l¥ó¤]¥i¯à¦]¦Ó¿ò¥¢¡A¬Æ¦Ó¶i¤@¨BªÅ¶}¦¨¬°ªýÂ_ªA°Èªº§ðÀ»¡C©Ò©¯¡A¥Ø«e¸û·sªº BIND ª©¥»¡A°w¹ï³o¤@Ãþ°ÝÃD¡A¤w¸g¦³¥[¤J³\¦h§ï¶iªº¤èªk¡A¤£¹L¯u¥¿ªº¸Ñ¨M¤è®×¡A«h¦³¿à«Ê¥]»{ÃÒ¾÷¨îªº«Ø¥ß»P±À°Ê¡CDNSSEC´N¬O¸Õ¹Ï¸Ñ¨M³o¤@Ãþ°ÝÃDªº¥þ·s¾÷¨î¡A BIND9 ¤w¸g§¹¾ã¥[¥H³]­p¨Ã§¹¦¨¡CDNSSEC¤Þ¤J¨â­Ó¥þ·sªº¸ê·½°O¿ýÃþ«¬¡GKEY©MSIG¡A¤¹³\«È¤áºÝ©M°ì¦WªA°È¾¹¹ï¥ô¦óDNS¼Æ¾Úªº¨Ó·½¶i¦æ±K½XÅçÃÒ¡C Www.
DNSSEC¥D­n¨Ì¾a¤½Æ_§Þ³N¹ï©ó¥]§t¦bDNS¤¤ªº«H®§³Ð«Ø±K½Xñ¦W¡C±K½Xñ¦W³q¹L­pºâ¥X¤@­Ó±K½Xhash¼Æ¨Ó´£¨ÑDNS¤¤¼Æ¾Úªº§¹¾ã©Ê¡A¨Ã±N¸Ó hash ¼Æ«Ê¸Ë¶i¦æ«OÅ@¡C¨p/¤½Æ_¹ï¤¤ªº¨pÆ_¥Î¨Ó«Ê¸Ëhash¼Æ¡AµM«á¥i¥H¥Î¤½Æ_§âhash¼ÆÄ¶¥X¨Ó¡C¦pªG³o­ÓĶ¥Xªºhash­È¤Ç°t±µ¦¬ªÌ­è­è­pºâ¥X¨Óªºhash ¾ð¡A¨º¤\ªí©ú¼Æ¾Ú¬O§¹¾ãªº¡C¤£ºÞĶ¥X¨Óªºhash¼Æ©M­pºâ¥X¨Óªºhash¼Æ¬O§_¤Ç°t¡A¹ï©ó±K½Xñ¦W³oºØ»{ÃҤ覡³£¬Oµ´¹ï¥¿½Tªº¡A¦]¬°¤½Æ_¶È¶È¥Î©ó¸Ñ±K¦Xªkªºhash¼Æ¡A©Ò¥H¥u¦³¾Ö¦³¨pÆ_ªº¾Ö¦³ªÌ¥i¥H¥[±K³o¨Ç«H®§¡C¤U­±§Ú­Ì¬Ý¬Ý¦p¦ó¬°¦WºÙ¬Odomain.comªº°ì«Ø¥ßDESSEC°t¸m¡C [color=#f5fafe][/color]
¨BÆJ¤@¡G¬° domain.com °ì«Ø¥ß¤@¹ï±KÆ_¡C¦b /var/named ¥Ø¿ý¤U¡A¨Ï¥Î©R¥O¡G ¡§/usr/local/sbin/dnssec-keygen -a DSA -b 768 -n ZONE domain.com¡¨ ³o­Ó©R¥O²£¥Í¤@¹ïªø«×768¦ìDSAºâªkªº¨p¦³±KÆ_¡]Kdomain.com.+003+29462.private¡^©M¤½¦@±KÆ_¡]Kdomain.com.+003+29462.key¡^¡C¨ä¤¤29462ºÙ§@±KÆ_¼Ðñ¡] key tag¡^¡C  
¨BÆJ¤G¡G¨Ï¥Î©R¥O¡G¡§ /usr/local/sbin/dnssec-makekeyset -t 3600 -e now+30 Kdomain.com.+003+29462¡§«Ø¥ß¤@­Ó±KÆ_¶°¦X¡C¸Ó©R¥O¥H3¡A600 seconds ªº¥Í¦s®É¶¡¡]time-to-live¡^«Ø¥ß±KÆ_¶°¦X¡A¦³®Ä´Á­­¤T¤Q¤Ñ¡A¨Ã¥B³Ð«Ø¤@­Ó¤å¥ó¡Gdomain.com.keyset¡C  
¨BÆJ¤T¡G¨Ï¥Î©R¥O¡§ /usr/local/sbin/dnssec-signkey domain.com.keyset Kdomain.com.+003+29462 ¡§¬°±KÆ_¶°¦Xñ¦r¡CµM«á«Ø¥ß¤@­Óñ¦r¤å¥ó¡Gdomain.com.signedkey¡C

¨BÆJ¥|¡G¨Ï¥Î©R¥O ¡§/usr/local/sbin/dnssec-signzone -o domain.com domain.db command¡A where domain.db ¡¨¬°°Ï±a¤å¥óñ¦r¡CµM«á«Ø¥ß¤@­Óñ¦r¤å¥ó¡G domain.db.signed¡C [color=#f5fafe][/color]
¨BÆJ¤­¡G´À´« °t¸m¤å¥ó/etc/named.conf¤¤ domain.comªº°Ï±a¤å¥ó³¡¤À¡C²M³æ¦p¤U¡G
¤¤°ê

[table=95%][tr][td][color=#ff0000]¥H¤U¬°¤Þ¥Îªº¤º®e¡G[/color]
zone ¡§domain.com¡¨ IN {
type master;
file ¡§domain.db.signed¡¨;
allow-update { none; }; }; [/td][/tr][/table]
±q¤W­±ªº°t¸m¹Lµ{§Ú­Ì¤]¬Ý¨ìDNSSECªº¤@¨Ç¯ÊÂI¡G [color=#f5fafe][/color]
°£¤F°t¸m­t³d¡AÁÙ¦³¼Ð°O©M®ÕÅçDNS¼Æ¾ÚÅãµM·|²£¥ÍÃB¥~ªº¶}¾P¡A±q¦Ó¼vÅTºôµ¸©MªA°È¾¹ªº©Ê¯à¡Cñ¦Wªº¼Æ¾Ú¶q«Ü¤j¡A³o´N¥[­«¤F°ì¦WªA°È¾¹¹ï¤¬Ápºô°©·F¥H¤Î¤@¨Ç«D°©·F³s±µªº­t¾á¡C²£¥Í©M®ÕÅçñ¦W¤]¦û¥Î¤F«Ü¦h¤¤¥¡³B²z¾¹ªº®É¶¡¡C¦³®É­Ô¡A¤£±o¤£§â³æ³B²z¾¹ªºDNSªA°È¾¹´«¦¨¦h³B²z¾¹ªºDNSSECªA°È¾¹¡Cñ¦W©M±KÆ_¦û¥ÎªººÏ½LªÅ¶¡©MRAM®e¶q¹F¨ì¥¦­Ìªí¥Üªº¼Æ¾Ú©Ò¦û®e¶qªº10­¿¡C¦P®É¼Æ¾Ú®w©MºÞ²z«Y²Î¤]¤£±o¤£¶i¦æ¬ÛÀ³ªº¤É¯Å©MÂX®e¡C

Á`µ²¡G°ì¦W«Y²Îªº°t¸m©MºÞ²z¬O¤@¶µ¤ñ¸û´_Âø©MÁcº¾ªº«Y²ÎºÞ²z¥ô°È¡A¥¦¹ï¾ã­Óºôµ¸ªº¹B¦æ¼vÅT·¥¤j¡C¬°¤F«OÃÒDNSªA°È¾¹ªº¦w¥þ¹B¦æ¡A¤£¶È­n¨Ï¥Î¥i¾aªºªA°È¾¹³n¥óª©¥»¡A¦Ó¥B­n¹ïDNSªA°È¾¹¶i¦æ¦w¥þ°t¸m¡A¥»¤å¤¶²Ð¤FTISG©MDNSSEC§Þ³N¦³§U©ó´î¤Ö DNS Spoofing §ðÀ»ªºµo¥Í¡A¼W¶iºôµ¸¨Ï¥ÎªÌ¹ï¦]¯Sºô¨Ï¥Îªº«H¥ô¡A§ùµ´«H®§«Y²Î¾D¨ü¤J«I»P§ðÀ»ªº²£¥Í¡C

­¶: [1]

Powered by Discuz! Archiver 6.1.0  © 2001-2007 Comsenz Inc.