翻訳と辞書
Words near each other
・ TDK Cross Central
・ TDK Mediactive
・ TDKR
・ TDL
・ TDL-4
・ TDLR 1 to 3, 6, and 8
・ TDLR 5
・ TDLR 7 and 8
・ TDLS
・ TDM
・ TCP tuning
・ TCP Vegas
・ TCP Westwood
・ TCP Westwood plus
・ TCP window scale option
TCP Wrapper
・ TCP-1/cpn60 chaperonin family
・ TCP-Illinois
・ TCP/IP Illustrated
・ TCP/IP stack fingerprinting
・ TCP10L
・ TCP11
・ TCPA
・ TCPaccess
・ Tcpcrypt
・ TCPDF
・ Tcpdump
・ Tcpkill
・ TCPO
・ Tcptrace


Dictionary Lists
翻訳と辞書 辞書検索 [ 開発暫定版 ]
スポンサード リンク

TCP Wrapper : ウィキペディア英語版
TCP Wrapper
__NOTOC__
TCP Wrapper is a host-based networking ACL system, used to filter network access to Internet Protocol servers on (Unix-like) operating systems such as GNU/Linux or BSD. It allows host or subnetwork IP addresses, names and/or ident query replies, to be used as tokens on which to filter for access control purposes.
The original code was written by Dutchman Wietse Venema in 1990 to monitor a cracker's activities on the Unix workstations at the Dept. of Math and Computer Science at the Eindhoven University of Technology.〔( ''TCP WRAPPER - Network monitoring, access control, and booby traps.'' by Wietse Venema )〕 He maintained it until 1995, and on June 1, 2001, released it under its own BSD-style license.
The tarball includes a library named libwrap that implements the actual functionality. Initially, only services that were spawned for each connection from a super-server (such as inetd) got ''wrapped'', utilizing the tcpd program. However most common network service daemons today can be linked against libwrap directly. This is used by daemons that operate without being spawned from a super-server, or when a single process handles multiple connections. Otherwise, only the first connection attempt would get checked against its ACLs.
When compared to host access control directives often found in daemons' configuration files, TCP Wrappers have the benefit of runtime ACL reconfiguration (i.e., services don't have to be reloaded or restarted) and a generic approach to network administration.
This makes it easy to use for anti-worm scripts, such as DenyHosts or Fail2ban, to add and expire client-blocking rules, when excessive connections and/or many failed login attempts are encountered.
While originally written to protect TCP and UDP accepting services, examples of usage to filter on certain ICMP packets exist too, such as 'pingd' – the userspace ping request responder.〔(GNU/Linux Ping Daemon ) by route|daemon9 - Phrack Magazine Volume 8, Issue 52 January 26, 1998, article 07〕
==1999 Trojan==
In January 1999, the distribution package at Eindhoven University of Technology (the primary distribution site until that day) was replaced by a modified version. The replacement contained a trojaned version of the software that would allow the intruder access to any server that it was installed on. The author spotted this within hours, upon which he relocated the primary distribution to his personal site.〔(CC/CERT Advisory CA-1999-01 )〕〔(CC/CERT Advisory CA-1999-02 )〕〔(''backdoored tcp wrapper source code'', by Wietse Venema, on Bugtraq, Jan 21, 1999 )〕〔(''Announcement: Wietse's FTP site has moved'', by Wietse Venema, on Bugtraq, Jan 21, 1999 )〕

抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)
ウィキペディアで「TCP Wrapper」の詳細全文を読む



スポンサード リンク
翻訳と辞書 : 翻訳のためのインターネットリソース

Copyright(C) kotoba.ne.jp 1997-2016. All Rights Reserved.