{"id":6390,"date":"2016-06-27T11:48:41","date_gmt":"2016-06-27T02:48:41","guid":{"rendered":"http:\/\/www.skyarch.net\/blog\/?p=6390"},"modified":"2016-06-27T11:48:41","modified_gmt":"2016-06-27T02:48:41","slug":"vuls%e3%82%a4%e3%83%b3%e3%82%b9%e3%83%88%e3%83%bc%e3%83%ab","status":"publish","type":"post","link":"https:\/\/www.skyarch.net\/blog\/vuls%e3%82%a4%e3%83%b3%e3%82%b9%e3%83%88%e3%83%bc%e3%83%ab\/","title":{"rendered":"vuls\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb"},"content":{"rendered":"<ul>\n<li><a href=\"#overview\">\u6982\u8981<\/a><\/li>\n<li><a href=\"#env\">\u74b0\u5883<\/a><\/li>\n<li><a href=\"#install\">\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u65b9\u6cd5<\/a><\/li>\n<li><a href=\"#install1\">Log\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u4f5c\u6210<\/a><\/li>\n<li><a href=\"#install2\">Go\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/a><\/li>\n<li><a href=\"#install3\">\u5fc5\u8981\u30d1\u30c3\u30b1\u30fc\u30b8\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/a><\/li>\n<li><a href=\"#install4\">go-cve-dictionary\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/a><\/li>\n<li><a href=\"#install5\">vuls\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/a><\/li>\n<\/ul>\n<h2 id=\"overview\">\u6982\u8981<\/h2>\n<p>SSH\u7d4c\u7531\u3067\u7279\u5b9a\u30b5\u30fc\u30d0\u306e\u8106\u5f31\u6027\u3092\u78ba\u8a8d\u51fa\u6765\u308b\u30c4\u30fc\u30eb\u3067\u3059\u3002<br \/>\n\u5bfe\u8c61\u306f\u30df\u30c9\u30eb\u30a6\u30a7\u30a2\u30fb\u30e9\u30a4\u30d6\u30e9\u30ea\u30fb\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u3002<\/p>\n<h2 id=\"env\">\u74b0\u5883<\/h2>\n<table>\n<thead>\n<tr>\n<th align=\"center\"><\/th>\n<th align=\"center\"><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td align=\"center\">OS<\/td>\n<td align=\"center\">Amazon Linux 2016.03<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">Type<\/td>\n<td align=\"center\">t2.nano<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u203bt2.nano\u306e\u5834\u5408\u30e1\u30e2\u30ea\u4e0d\u8db3\u3067\u30a8\u30e9\u30fc\u306b\u306a\u308b\u305f\u3081SWAP\u8a2d\u5b9a\u5fc5\u9808\u3067\u3059\u3002<\/p>\n<h2 id=\"install\">\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u65b9\u6cd5<\/h2>\n<p>\u4eca\u56de\u306f\u30ea\u30e2\u30fc\u30c8\u306e\u30b5\u30fc\u30d0\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u81ea\u8eab(localhost)\u306e\u8106\u5f31\u6027\u3092\u78ba\u8a8d\u3057\u3066\u307f\u307e\u3059\u3002<\/p>\n<h3 id=\"install1\">Log\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u4f5c\u6210<\/h3>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\nsudo su -\nmkdir \/var\/log\/vuls\n<\/pre>\n<h3 id=\"install2\">Go\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h3>\n<p>\u4e0b\u8a18\u30b5\u30a4\u30c8\u304b\u3089\u6700\u65b0\u306e\u30b3\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9<br \/>\nhttps:\/\/golang.org\/dl\/<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\ncd \/usr\/local\/src\/\nwget https:\/\/storage.googleapis.com\/golang\/go1.6.2.linux-amd64.tar.gz\ntar zxf go1.6.2.linux-amd64.tar.gz\nmv .\/go ..\/\nvi \/etc\/profile.d\/goenv.sh\n---\u4e0b\u8a18\u3092\u8a18\u8f09---\nexport GOROOT=\/usr\/local\/go\nexport GOPATH=\/opt\/go\nexport PATH=$PATH:$GOROOT\/bin:$GOPATH\/bin\n---\u3053\u3053\u307e\u3067---\nsource \/etc\/profile.d\/goenv.sh\n<\/pre>\n<h3 id=\"install3\">\u5fc5\u8981\u30d1\u30c3\u30b1\u30fc\u30b8\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h3>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\nyum install git gcc\n<\/pre>\n<h3 id=\"install4\">go-cve-dictionary\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h3>\n<p>vuls\u306f\u8106\u5f31\u6027\u306e\u7167\u5408\u306bCVE\u3092\u4f7f\u7528\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\nt2.nano\u3092\u4f7f\u7528\u3059\u308b\u5834\u5408\u306f\u30e1\u30e2\u30ea\u4e0d\u8db3\u3067\u30a8\u30e9\u30fc\u306b\u306a\u308b\u305f\u3081SWAP\u8a2d\u5b9a\u5fc5\u9808\u3067\u3059\u3002<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\ngo get github.com\/kotakanbe\/go-cve-dictionary\nfor i in {2002..2016}; do go-cve-dictionary fetchnvd -years $i; done\n---1\u6642\u9593\u7a0b\u5ea6\u639b\u304b\u308b---\ngo-cve-dictionary fetchjvn -entire\n---1\u6642\u9593\u7a0b\u5ea6\u639b\u304b\u308b---\ngo-cve-dictionary server &amp;amp;\ncurl http:\/\/localhost:1323\/cves\/CVE-2015-0235\n<\/pre>\n<h3 id=\"install5\">vuls\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h3>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\ngo get github.com\/future-architect\/vuls\nssh-keygen\ncat ~\/.ssh\/id_rsa.pub &amp;gt;&amp;gt; ~\/.ssh\/authorized_keys\nchmod 600 ~\/.ssh\/authorized_keys\nvi \/etc\/ssh\/sshd_config\n---\u4e0b\u8a18\u3092\u5909\u66f4---\n#PermitRootLogin yes\n\u2193\nPermitRootLogin yes\n\nPermitRootLogin forced-commands-only\n\u2193\n#PermitRootLogin forced-commands-only\n---\u3053\u3053\u307e\u3067---\n\/etc\/init.d\/sshd restart\nssh localhost\nexit\nvi config.toml\n---\u4e0b\u8a18\u3092\u8a18\u8f09---\n&#x5B;servers]\n&#x5B;servers.localhost]\nhost = &amp;quot;localhost&amp;quot;\nport = &amp;quot;22&amp;quot;\nuser = &amp;quot;root&amp;quot;\nkeyPath = &amp;quot;\/root\/.ssh\/id_rsa&amp;quot;\n---\u3053\u3053\u307e\u3067---\nvuls prepare\nvuls scan\n<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u74b0\u5883 \u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u65b9\u6cd5 Log\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u4f5c\u6210 Go\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb \u5fc5\u8981\u30d1\u30c3\u30b1\u30fc\u30b8\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb go-cve-dictionary\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb vuls\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb \u6982\u8981 SSH\u7d4c\u7531\u3067\u7279\u5b9a\u30b5\u30fc\u30d0\u306e\u8106\u5f31\u6027\u3092\u78ba\u8a8d\u51fa\u6765\u308b\u30c4&#8230;<\/p>\n","protected":false},"author":1,"featured_media":5484,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_locale":"ja","_original_post":"6390","footnotes":""},"categories":[7],"tags":[],"class_list":{"0":"post-6390","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security","8":"ja"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/posts\/6390","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/comments?post=6390"}],"version-history":[{"count":12,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/posts\/6390\/revisions"}],"predecessor-version":[{"id":6955,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/posts\/6390\/revisions\/6955"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/media\/5484"}],"wp:attachment":[{"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/media?parent=6390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/categories?post=6390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.skyarch.net\/blog\/wp-json\/wp\/v2\/tags?post=6390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}