######################################################################### # # # ProFTPD Korea User Groups # # http://proftpd.oops.org # # # ######################################################################### # ¼³Á¤ : ±èÁ¤±Õ < http://www.oops.org > # À߸øµÈ ¼³Á¤ÀÌ ÀÖÀ¸¸é ¿¬¶ô Áֽñ⠹ٶø´Ï´Ù. ######################################################################### ServerName "FTP Server" # ServerType Àº Server ¸¦ standalone mode ·Î ÇÒ°ÍÀÎÁö inet mode·Î ÇÒ°Í ÀÎ # Áö¸¦ Á¤ÇÑ´Ù. default·Î inetd mode·Î ÇÑ´Ù. standalone mode·Î ÇÒ°æ¿ì ¾Æ·¡ # MaxInstances Áö½ÃÀÚÀÇ ÁÖ¼®À» ÇØÁ¦ ÇÑ´Ù. inetd mode·Î ÀÛµ¿À» ÇÒ °æ¿ì¿¡´Â # /etc/inetd.confÁß¿¡¼­ # ftp stream tcp nowait root /usr/sbin/tcpd in.ftpd -l -a # ÇàÀ» ¾Æ·¡¿Í °°ÀÌ # ftp stream tcp nowait root /usr/sbin/tcpd in.ftpd # ¼öÁ¤À» ÇØ ÁÖ°í Inet demonÀ» Àç ½ÇÇà ÇØ Áà¾ß ÇÑ´Ù. # # ServerType standalone ServerType inetd DefaultServer on ServerAdmin root@localhost # ¿äÁò¿¡´Â inverse domain ÀÌ °ÅÀÇ Áö¿øµÇÁö ¾ÊÀ¸´Ï, ÀÌ ¼³Á¤Àº Çʼö¶ó°í »ý°¢ # ÇÏ°í ¼öÁ¤ÇÏÁö ¾Ê´Â´Ù. # UseReverseDNS off IdentLookups off # Server ¿¡ Á¢¼ÓÇßÀ» °æ¿ì º¸³»ÁÖ´Â Defualt ¸Þ¼¼Áö¸¦ ¼³Á¤ÇÑ´Ù. Off ·Î ÁöÁ¤ # ÇÏ¿´À» °æ¿ì Proftpd Server Ready ServerName ÀÌ Ãâ·ÂµÈ´Ù. # ServerIdent On "FTP Server Ready .. " # User login À» ÇßÀ»½Ã¿¡ user µéÀÌ ÀÚ½ÅÀÇ È¨»óÀ§ µð·ºÅ丮µéÀ» ¸¶À½´ë·Î µ¹ # ¾Æ´Ù´ÏÁö ¸øÇÏ°Ô chroot() ¸¦ ¼³Á¤ÇÑ´Ù. group º°·Î ¼³Á¤À» ÇÏ°Ô µÇ¸ç "!"´Â # Á¦¿ÜÇ϶ó´Â Àǹ̸¦ °¡Áö°Ô µÈ´Ù. # #DefaultRoot ~ !groupname # ServerTypeÀÌ standaloneÀ̸é ÀÌ Ç׸ñÀÇ ÁÖ¼®À» Ç®¾î Áà¾ß ÇÑ´Ù. inetd·Î ÀÛ # µ¿À» ½Ãų½Ã¿¡´Â /etc/services¿¡¼­ port¸¦ ÁöÁ¤ÇÑ´Ù. # #Port 21 # root login À» Çã¶ôÇÒÁöÀÇ ¿©ºÎ¸¦ ÁöÁ¤ÇÑ´Ù. PAM modules¸¦ »ç¿ëÇÑ´Ù¸é ¸ÕÀú # /etc/proftpd/ftpusers¿¡¼­ root¸¦ »èÁ¦ÇØ¾ß ÇÑ´Ù. # http://proftpd.oops.org/board/read.php?table=ProftpdFAQ&no=7 ÂüÁ¶ # RootLogin off # timin attack À» ¹æÁöÇϱâ À§ÇÑ ¼³Á¤ DelayEngine on DelayTable /var/run/proftpd/proftpd.delay # Global sectionÀº proftpdÀÇ ÀüüÀûÀÎ ¼³Á¤¿¡ ¸ðµÎ Àû¿ë½ÃŲ´Ù. # group °ú world writable ·Î ºÎÅÍ »õ·Î¿î dir °ú file µéÀ» »ý¼ºÇÏ´Â °ÍÀ» # ¸·±âÀ§ÇÏ¿© ±âº»ÀûÀ¸·Î umask´Â 022·Î ¼³Á¤À» ÇÑ´Ù. Umask 022 # PAM ÀÎÁõ ¸ðµâÀ» »ç¿ëÇÒÁö ¾ÈÇÒÁö °áÁ¤À» ÇÑ´Ù. ±âº»°ªÀº 'On' ÀÌ´Ù. ¿øÇÏ # Áö ¾ÊÀ¸¸é 'Off' ·Î ¼³Á¤À» ÇÑ´Ù. AuthPAM On # proftpd ¿¡¼­ »ç¿ëÇÒ pam.d ÀÇ ÆÄÀÏ À̸§À» ÁöÁ¤ÇÑ´Ù. ftpusers ¸¦ ÅëÇÏ¿© # À¯ÀúÀÇ Á¢±Ù Á¦ÇÑÀ» Çϱâ À§Çؼ­´Â ÀÌ Áö½ÃÀÚ¸¦ »ç¿ëÇØ¾ß ÇÑ´Ù. AuthPAMConfig ftp # ÀÎÁõÀÇ ¼ø¼­¸¦ ÁöÁ¤ÇÑ´Ù. ¸ÕÀú PAM ÀÇ ÀÎÁõÀ» Åë°úÇÑ ÈÄ¿¡ UNIX ÀÎÁõÀ» ü # Å©ÇÑ´Ù. AuthOrder mod_auth_pam.c* mod_auth_unix.c # service¸¦ ½ÃÀÛÇÏ°í ¸¶Ä¥ ½Ã°£À» 24½Ã°£ Ç¥±â¹ýÀ¸·Î ÁöÁ¤À» ÇÑ´Ù. ÀÌ ¼³Á¤ # Àº Korea User Group ÀÇ time limit ÆÐÄ¡°¡ Àû¿ëÀÌ µÇ¾î ÀÖ¾î¾ß »ç¿ëÀÌ °¡ # ´ÉÇÏ´Ù. # # UpTime 10 # DownTime 23 # Server ÀÇ Ftpd ½Ã°£À» Áö¿ª½Ã°£À¸·Î °íÁ¤ÇÑ´Ù. on À¸·Î ÇßÀ» °æ¿ì GMT ½Ã # °£À» Ç¥½Ã Çϱ⠶§¹®¿¡ Çѱ¹ÀÇ °æ¿ì 9½Ã°£ÀÇ ¿ÀÂ÷°¡ ¹ß»ýÇÑ´Ù. TimesGMT off # 1.2.1 ÀÌÇÏ ¹öÁ¯¿¡¼­ÀÇ ¹ö±×¸¦ À§ÇÑ ¼³Á¤ DenyFilter \*.*/ # ¹æÈ­º® ¾ÈÀÇ PASV mode ¿¡ ´ëÇÑ ¼³Á¤ PassivePorts 32768 61000 # ȸ¼±ÀÇ Bandwidth¸¦ ƯÁ¤ ¼Óµµ·Î Á¦ÇÑÀ» ÇÑ´Ù. ´ÜÀ§´Â Byte per Sec ÀÌ´Ù. # ´Ù¿î·Îµå¿Í ¾÷·Îµå¸¦ 16KB/s (128Kb/s) ·Î Á¦ÇÑ #TransferRate RETR,STOR 16 # ÃÖ´ë Á¢¼Ó Àοø¼ö¸¦ ÁöÁ¤ÇÑ´Ù. MaxClients 10 "Sorry, Max %m uses are already connected" # ÇϳªÀÇ È£½ºÆ®·Î ºÎÅÍ µ¿½Ã¿¡ Á¢±ÙÇÒ ¼ö ÀÖ´Â ¼ö¸¦ ÁöÁ¤ÇÑ´Ù. ¾Æ·¡ÀÇ ±âº» # ¼³Á¤À¸·Î´Â ÇϳªÀÇ È£½ºÆ®¿¡¼­ ÇѹøÀÇ Á¢±Ù¸¸ Çã¿ëÇÑ´Ù. MaxClientsPerHost 3 "Sorry, %m connection allow per one host" # ÇϳªÀÇ °èÁ¤ ID ·Î µ¿½Ã¿¡ Á¢±ÙÇÒ ¼ö Àִ ȣ½ºÆ® ¼ö¸¦ ÁöÁ¤ ÇÑ´Ù. ¾Æ·¡ÀÇ # ±âº» ¼³Á¤À¸·Î´Â ÇϳªÀÇ °èÁ¤ Çϳª È£½ºÆ®¿¡¼­¸¸ Á¢±Ù¸¸ Çã¿ëÇÑ´Ù. ÇϳªÀÇ # °èÁ¤¿¡ ÇϳªÀÇ Á¢±Ù¸¸À» Çã¶ôÇÏ·Á¸é À§ÀÇ MaxClientsPerHostÀÇ °ª°ú # MaxHostsPerUserÀÇ °ªÀÌ µÑ´Ù 1ÀÌ¸é µÈ´Ù. #MaxHostsPerUser 1 "Sorry, %m hosts allow per one user" # Á¢¼Ó ´ë±â½Ã°£À» ¼³Á¤ÇÑ´Ù. user °¡ Á¢¼ÓÈÄ ¾Æ¹« ÀÛµ¿µµ ¾ÈÇÒ¶§ ÀÏÁ¤ ½Ã°£ÈÄ # ¿¡ Á¢¼ÓÀÌ Á¾·áµÇ°Ô ÇÑ´Ù TimeoutIdle 900 TimeoutNoTransfer 900 TimeoutLogin 300 # DeferWelcome ´Â client°¡ ÀÎÁõÀ» Çϱâ Àü¿¡ servernameÀ» displayÇÏ´Â °ÍÀ» # ¹æÁöÇÑ´Ù. DeferWelcome off # 'welcome.msg ´Â login ½Ã¿¡ º¸¿©Áö°í, 'message' ´Â °¢ ÇÏÀ§ µð·ºÅ丮¿¡ Á¢ # ¼Ó ÇßÀ»¶§ º¸¿©Áö°Ô µÈ´Ù. DisplayLogin /etc/proftpd/welcome.msg DisplayFirstChdir .message # DoS(Denial Of Service) °ø°ÝÀ» ¸·±â À§ÇØ, ÀÚ½Ä process ÀÇ maximun number # ¸¦ 30 À¸·Î ¼³Á¤ÇÑ´Ù. ¸¸¾à 30ÀÌ»óÀÇ Á¢¼ÓÀ» Çã¶ôÇÒ ÇÊ¿ä°¡ ÀÖ´Ù¸é °£´ÜÇÏ°Ô # ÀÌ Ä¡¼ö¸¦ Áõ°¡ ½ÃÅ°µµ·Ï ÇÑ´Ù. ÀÌ°ÍÀº ¿ÀÁ÷ standalone mode ¿¡¼­¸¸ °¡´ÉÇÏ # ´Ù. inetd mode ¿¡¼­´Â service ´ç maximun number¸¦ Á¦ÇÑ ÇÏ´Â °ÍÀ» Çã¶ôÇÏ # ´Â inetd server¿¡¼­ ¼³Á¤À» ÇØ¾ß ÇÑ´Ù.(xinetd ¿ª½Ã ¸¶Âù°¡Áö ÀÌ´Ù) # MaxInstances 30 # Proftpd °¡ ±¸µ¿µÉ ¼­¹öÀÇ À¯Àú/±×·ì ±ÇÇÑÀ» ¼³Á¤ÇÑ´Ù. User nobody Group nobody # ÀϹÝÀûÀ¸·Î fileµéÀ» overwrite¸¦ °¡´ÉÇÏ°Ô ÇÑ´Ù. AllowOverwrite on AllowRetrieveRestart on AllowStoreRestart on # ls ¸í·É¾îÀÇ ¿É¼ÇÀ» °­Á¦ ÁöÁ¤Çϰųª »ç¿ëÇÏÁö ¸øÇϵµ·Ï ¸·À» ¼ö ÀÖ´Ù. - ¿Í # ¿É¼ÇÀ» °áÇÕÀ» Çϸé, ls ¸í·É¿¡ ±âº»À¸·Î ÁöÁ¤ µÈ ¿É¼ÇÀÌ »ç¿ëÀÌ µÇ¾îÁö¸ç, + # ¿Í ¿É¼ÇÀ» °áÇÕÇϸé, ÁöÁ¤ÇÑ ¿É¼ÇÀÇ »ç¿ëÀ» ¸·À» ¼ö ÀÖ´Ù. # # ls ¿¡ -l ¿É¼ÇÀ» ±âº»ÀûÀ¸·Î Ãß°¡ÇÏ°í, -a ¿É¼ÇÀº »ç¿ëÇÏÁö ¸øÇϵµ·Ï ÇÒ °æ¿ì # ListOptions "+a -l" # # Ç×»ó ¿É¼Ç ¾øÀÌ ls °á°ú¸¦ º¸¿©ÁÙ °æ¿ì # ListOptions "" strict # # ls ÀÇ °á°ú¿¡ -a ¿É¼ÇÀ» Ãß°¡ÇÒ °æ¿ì # # ListOptions "-a" # TLS/SSL ¼³Á¤ # ÀÌ ¼³Á¤Àº °¢ °¡»ó È£½ºÆ® º°·Îµµ °¡´ÉÇÏ´Ù. ÀÌ ¼³Á¤À» »ç¿ëÇϱâ À§Çؼ­´Â ¾È # ³çÀÇ openssl ¿¡¼­ Á¦°øÇÏ´Â make_ssl_cert ¸í·ÉÀ» ¼öÇàÇÏ¿© key ÆÄÀÏÀ» »ý¼º # ÇØ¾ß Á¢¼ÓÀÌ °¡´ÉÇÏ´Ï ÁÖÀÇÇϵµ·Ï ÇÑ´Ù. # # # # TLS ¸¦ È°¼ºÈ­ ÇÑ´Ù. # TLSEngine on # # # TLS °¡ °¡´ÉÇÑ Å¬¶óÀ̾ðÆ®¸¸ Á¢¼ÓÀ» Çã¿ë # #TLSRequired on # # TLSProtocol TLSv1 # TLSRSACertificateFile /usr/share/ssl/certs/server.crt # TLSRSACertificateKeyFile /usr/share/ssl/certs/server.key # # ´ÙÀ½Àº À͸í FTP ¸¦ À§ÇÑ ¼³Á¤ÀÔ´Ï´Ù. À͸í FTP ¼­ºñ½º¸¦ Çϱ⸦ ¿øÇÑ´Ù¸é ¾Æ # ·¡ÀÇ ... ±îÁöÀÇ ÁÖ¼®À» Ç®¾î ÁֽʽÿÀ. # # # User ftp # Group ftp # WtmpLog off # # # /etc/shells ¿¡ µî·ÏµÇ¾î ÀÖ´Â shell ÀÌ ÁöÁ¤µÇ¾î ÀÖ´Â À¯Àúµé¸¸ ·Î±×ÀÎÀÌ # # °¡´ÉÇÏ°Ô ÇÑ´Ù. ftp user ÀÇ shell ÀÌ º¸Åë /bin/false ·Î ÁöÁ¤ÀÌ µÇ¾î ÀÖ # # À¸¹Ç·Î ÀÌ °ªÀ» off ·Î ÇØÁØ´Ù. # RequireValidShell off # # # À͸í Á¢±Ù½ÃÀÇ Æнº¿öµå üũÁ¤µµ ¿©ºÎ¸¦ °áÁ¤À» ÇÑ´Ù. AnonPassType Áö½Ã # # ÀÚ´Â Korean User Group ÀÇ µ¶ÀÚÀûÀÎ ÆÐÄ¡ÀÌ´Ù. # # none -> ¾Æ¹«·± üũ¸¦ ÇÏÁö ¾Ê´Â´Ù. # # trivial -> Æнº¿öµå¿¡ @ ¹®ÀÚ°¡ Á¸ÀçÇÏ´ÂÁö¸¸ üũÇÑ´Ù. # # complete-email -> Æнº¿öµå°¡ ¿ÏÀüÇÑ ÇüÅÂÀÇ À̸ÞÀÏ ÁÖ¼ÒÇü½ÄÀ» °¡Áö´ÂÁö # # üũÇÑ´Ù. # AnonPassType none # # # À͸í Á¢±Ù½Ã »ç¿ëÇÏÁö ¸øÇÏ°Ô ÇÒ Æнº¿öµå¸¦ Á¤±ÔÇ¥Çö½ÄÀ¸·Î ¼³Á¤ÇÑ´Ù. ÀÌ # # Áö½ÃÀÚ´Â Korean User Group ÀÇ µ¶ÀÚÀûÀÎ ÆÐÄ¡ÀÌ´Ù. # # # #AnonRejectPasswords ^(IEUser|mozilla|username|test)@? # # # À͸í Á¢±ÙÀ» ÇÒ¶§ ƯÁ¤ password¸¦ ÁöÁ¤ÇÒ¼ö ÀÖ´Ù. ´Ü À§ÀÇ User Áö½ÃÀÚÀÇ # # nameÀÌ passwd file¿¡ µî·ÏÀÌ µÇ¾îÁ® ÀÖ¾î¾ß ÇÑ´Ù. ÀÌ Áö½ÃÀÚ°¡ onÀÏ °æ¿ì # # À̸ÞÀÏ ÁÖ¼Ò·Î loginÀ» ÇÒ¼ö ¾ø´Ù. # # # # ÀÌ Áö½ÃÀÚ°¡ ¼³Á¤µÇ¸é, AnonPassType ÀÌ ¹«½ÃµÈ´Ù. # # # # AnonRequirePassword on # # # ¸µÅ©µÈ ½Ç °æ·Î Ãâ·Â ¿©ºÎ # # ShowSymlinks off # # # User name "ftp"·Î anonymous loginÀ» ÇÒ¼ö ÀÖµµ·Ï ÇÑ´Ù # UserAlias anonymous ftp # # # AllowAll # # # DisplayLogin welcome.msg # DisplayFirstChdir .message # # # ÃÖ´ë Á¢¼Ó Àοø¼ö¸¦ ÁöÁ¤ÇÑ´Ù. # MaxClients 10 # # # ÇϳªÀÇ È£½ºÆ®·Î ºÎÅÍ µ¿½Ã¿¡ Á¢±ÙÇÒ ¼ö ÀÖ´Â ¼ö¸¦ ÁöÁ¤ÇÑ´Ù. ¾Æ·¡ÀÇ ±âº» # # ¼³Á¤À¸·Î´Â ÇϳªÀÇ È£½ºÆ®¿¡¼­ ÇѹøÀÇ Á¢±Ù¸¸ Çã¿ëÇÑ´Ù. # MaxClientsPerHost 3 "Sorry, %m connection allow per one host" # # # ¼ÒÀ¯±ÇÀÌ rootÀÎ fileÀ̳ª directoryµéÀ» º¸¿©ÁÖÁö ¾Ê´Â´Ù # #HideUser root # # # ±×·ì±ÇÇÑÀÌ rootÀÎ fileÀ̳ª directoryµéÀ» º¸¿©ÁÖÁö ¾Ê´Â´Ù # #HideGroup root # # # upload/download ºñÀ²À» Áö¿øÇÑ´Ù. # # http://proftpd.oops.org/document.php?t=doc&m=ratio ÂüÁ¶ # # # # Ratios on # # HostRatio foobar.net 100 10 5 100000 # # # ¼­¹ö¸¦ ½Ã°£´ë·Î ¿î¿µÇÏ´Â °ÍÀ» ÁöÁ¤ÇÑ´Ù. ¾Æ·¡ÀÇ ¿¹´Â ¿ÀÈÄ 3 ½Ã ºÎÅÍ ¿À # # ÈÄ 6½Ã±îÁö¸¸ ¼­¹öÀÇ Á¢¼ÓÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù. # # # # Korean User Group ÀÇ time limit ÆÐÄ¡°¡ Àû¿ëÀÌ µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù. # # # # UpTime 15 # # DownTime 18 # # # DenyAll # # # # Upload directory, allow upload and mkdir, deny download. # # Upload directory ¼³Á¤ÀÌ´Ù. upload¿Í mkdirÀº Çã¶ôÇϸç, # # download´Â °ÅÀýÇÑ´Ù # # # # # # # # DenyALL # # # # # # AllowALL # # # # # # # »ç¿ëÀÚ°¡ Á¢±ÙÇϱ⸦ ¿øÇÏÁö ¾Ê´Â private directory # # # # # # DenyAll # # # # # #