¥Ï¡¼¥É¥Ç¥£¥¹¥¯¥á¥ó¥Æ¥Ê¥ó¥¹

Åö¥µ¥¤¥È¤Ë¤Ï¹­¹ð¤¬´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£

¥¿¥°¡§Apache



Apache¤Î¥¢¥¯¥»¥¹¥í¥°¤Ë¡Ö¥¨¥é¡¼¡×¤È¤·¤Æ»Ä¤ë¥í¥°¤¬¤¢¤ë¡£

¹ñ³°IP¥¢¥É¥ì¥¹¥Õ¥£¥ë¥¿

½ÅÍפʥ¨¥é¡¼¤Ç¤¢¤ì¤Ðľ¤¹É¬Íפ¬¤¢¤ë¤¬¡¢¸µ¡¹Â¸ºß¤·¤Ê¤¤¥Õ¥¡¥¤¥ë¤Ø¤Î¥¢¥¯¥»¥¹¤ÏÌäÂê¤Ë¤Ê¤é¤Ê¤¤¤³¤È¤¬Â¿¤¤¡£

ÌäÂê¤Ë¤Ê¤é¤Ê¤¯¤Æ¤â¡¢¥¨¥é¡¼¥í¥°¤¬µ­Ï¿¤µ¤ì¤Æ¤·¤Þ¤¦¤Î¤Ç¡¢µ¤Ê¬Åª¤ËÎɤ¯¤Ê¤¤(¾Ð)

ͭ̾¤Ê¤È¤³¤í¤Ç¤Ï

¡¦favicon.ico
¡¦robots.txt

¤¬¤¢¤ë¤Í¡£

¤³¤ì¤é¤Ï¤Ê¤¯¤Æ¤â¥Ú¡¼¥¸¤Îɽ¼¨¤Ë¤ÏÌäÂê¤Ê¤¤¤¬¡¢Â¿¤¯¤Î¥Ö¥é¥¦¥¶¤¬Í׵᤹¤ë¤Î¤Ç¡¢·ë²Ì¤È¤·¤Æ

File does not exist

¤È¤¤¤¦¥¨¥é¡¼¥í¥°¤¬µ­Ï¿¤µ¤ì¤Æ¤·¤Þ¤¦¡£

Èæ³ÓŪ¿·¤·¤¤¤È¤³¤í¤Ç¤Ï¡¢iOS¤¬Í׵᤹¤ë

¡¦apple-touch-icon-precomposed.png
¡¦apple-touch-icon.png

¤¬¤¢¤ë¡£

iPhone¤Ê¤É¤ÎiOSüËö¤Ï¡¢¤³¤ì¤é¤Î¥Õ¥¡¥¤¥ë¤òÍ׵᤹¤ë¤Î¤Ç¡¢¥Õ¥¡¥¤¥ë¤¬¤Ê¤±¤ì¤Ð¡¢Æ±¤¸¤¯ File does not exist ¤È¤·¤Æµ­Ï¿¤µ¤ì¤Æ¤·¤Þ¤¦¡£

¤É¤ó¤ÊüËö¤Ç¥¢¥¯¥»¥¹¤µ¤ì¤ë¤«¤ÏÉÔÌÀ¤Ê¤Î¤Ç¡¢¥¨¥é¡¼¥í¥°¤ò»Ä¤·¤¿¤¯¤Ê¤±¤ì¤Ð¡¢¤³¤ì¤é¤Î¥Õ¥¡¥¤¥ë¤òÃÖ¤¤¤Æ¤ª¤³¤¦¡£

¤Þ¤¿¡¢¥µ¡¼¥Ð¡¼¤ÎÀßÄê¤Ç¥¢¥¯¥»¥¹¤¬µñÈݤµ¤ì¡¢¤½¤Î¥¨¥é¡¼¥í¥°¤¬»Ä¤ë¤³¤È¤¬¤¢¤ë¡£

client denied by server configuration : /home/xxx/www/wp-login.php

¤³¤ì¤ÏWordPress¤Î¥í¥°¥¤¥ó²èÌ̤Υե¡¥¤¥ë̾¤À¤¬¡¢ÉÔÀµ¥¢¥¯¥»¥¹¤òËɤ°¤¿¤á¤ËµñÈݤÎÀßÄê¤Ë¤µ¤ì¤Æ¤¤¤ë¤³¤È¤¬¤¢¤ë¡£

¹­¤¯¹­¤Þ¤Ã¤Æ¤¤¤ë¥Ö¥í¥°¥Ä¡¼¥ë¤Ê¤É¤Ï¡¢¥í¥°¥¤¥ó²èÌ̤ÎURL¤ä¥Õ¥¡¥¤¥ë̾¤¬·è¤Þ¤Ã¤Æ¤¤¤ë¤³¤È¤¬Â¿¤¤¤Î¤Ç¡¢ÉÔÀµ¥¢¥¯¥»¥¹¤ò»Å³Ý¤±¤ë¼Ô¤Ï¡¢¤½¤³¤òÁÀ¤Ã¤Æ¤¯¤ë¡£

¡ÖÉÔÀµ¥¢¥¯¥»¥¹¤òËɤ°¤¿¤á¤ËµñÈݤÎÀßÄê¤Ë¤µ¤ì¤Æ¤¤¤ë¡×¤Ë¤Ï¡¢¤µ¤¯¤é¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤Î¹ñ³°IP¥¢¥É¥ì¥¹¥Õ¥£¥ë¥¿¤Ê¤É¤¬¤¢¤ë¡£

ÃΤé¤Ì´Ö¤ËµñÈݤµ¤ì¤Æ¤¤¤ë¡ª¤È¶Ã¤¯¤³¤È¤Î¤Ê¤¤¤è¤¦¡¢¹ñ³°IP¥¢¥É¥ì¥¹¥Õ¥£¥ë¥¿¤ÎÀßÄêÊýË¡(¤µ¤¯¤é¥¤¥ó¥¿¡¼¥Í¥Ã¥È)¤ò°ìÆÉ¤·¤Æ¤ª¤³¤¦¡£

¾å¤Î wp-login.php ¤Î¥¢¥¯¥»¥¹µñÈÝ¥í¥°¤¬¤¢¤ë¤Î¤Ï¡¢¤½¤ì¤¬Íýͳ¡£

¤Ç¤­¤ëPRO Apache Web¥µ¡¼¥Ð¡¼ ²þÄûÈÇ Version 2.4/2.2/2.0Âбþ (¤Ç¤­¤ëPRO¥·¥ê¡¼¥º)
ÄÔ ½¨Åµ ÅÏÊÕ ¹â»Ö ÎëÌÚ ¹¬ÉÒ ¤Ç¤­¤ë¥·¥ê¡¼¥ºÊÔ½¸Éô
¥¤¥ó¥×¥ì¥¹¥¸¥ã¥Ñ¥ó
Çä¤ê¾å¤²¥é¥ó¥­¥ó¥°: 103,441


¥µ¡¼¥Ð¹½Ãۤμºݤ¬¤ï¤«¤ë Apache[¼ÂÁ©]±¿ÍÑ/´ÉÍý (Software Design plus)
ÄáĹ Äðì
µ»½ÑɾÏÀ¼Ò
Çä¤ê¾å¤²¥é¥ó¥­¥ó¥°: 70,426

[PR] au PAY / au WALLET ¥«¡¼¥É ¾ðÊó

¤³¤Î¥¨¥ó¥È¥ê¡¼¤ò¤Ï¤Æ¤Ê¥Ö¥Ã¥¯¥Þ¡¼¥¯¤ËÄɲà mixi¥Á¥§¥Ã¥¯



(Debian7.4 , Apache2.2.22)

http://xxx.xxx.xxx.xxx/index.php?pid=001
http://xxx.xxx.xxx.xxx/index.php?pid=002

¤È¤¤¤¦¤è¤¦¤Ê¡¢GET¤òURL¤Î°ìÉô¤È¤·¤ÆÁ÷¤ë¤Î¤ÏŤ¤¤Î¤Ç¡¢

http://xxx.xxx.xxx.xxx/001.html
http://xxx.xxx.xxx.xxx/002.html

¤Î¤è¤¦¤Ë½ñ¤­´¹¤¨¤ë¤Î¤¬¡¢mod_rewrite¤À¡£

´ØÏ¢¡§Apache Module mod_rewrite

http://xxx.xxx.xxx.xxx/index.php?aaa=001&bbb=002&ccc=003
¢­
http://xxx.xxx.xxx.xxx/aaa_001-bbb_002-ccc_003.html

Åù¡¢¥Ñ¥é¥á¡¼¥¿¡¼¤Î¿¤¤¡¢Ê£»¨¤ÊURL¤òû¤¯¤¹¤ë¤³¤È¤¬²Äǽ¡£

¤³¤Î¡¢URL¤Î½ñ¤­´¹¤¨¤ò¹Ô¤¦¤Ë¤Ï¡¢

­¡ mod_rewrite¤ÎÆÉ¤ß¹þ¤ß

¤È

­¢ .htaccess¤Î»ÈÍѵö²Ä

¤ÎξÊý¤¬É¬Íס£

¥ì¥ó¥¿¥ë¥µ¡¼¥Ð¡¼¤Ç¤Ï¿¤¯¤Î¾ì¹ç¡¢¤³¤ì¤é¤¬ºÇ½é¤«¤éÍ­¸ú¤È¤Ê¤Ã¤Æ¤¤¤ë¤Î¤Ç¡¢½ñ´¹µ¬Â§¤ò.htaccess¤Ë½ñ¤±¤Ð½ªÎ»¤À¤¬¡¢¼«Ê¬¤ÇΩ¤Æ¤¿¾ì¹ç¤ÏξÊý¤È¤â̵¸ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤³¤È¤¬Â¿¤¤¡£

¢£ ­¡ mod_rewrite¤ÎÆÉ¤ß¹þ¤ß ¢£

Apache¤ÎÀßÄê¥Õ¥¡¥¤¥ë¤Ï

/etc/apache2/apache2.conf

¤Ë¤¢¤ë¤¬¡¢¤½¤Î²¼¤Î

/etc/apache2/mods-available

¤Ë

rewrite.load

¤¬¤¢¤ë¡£

¤³¤ì¤¬rewrite¥â¥¸¥å¡¼¥ë¡£

Apache¤Îµ¯Æ°»þ¤Ë¡¢¤³¤ì¤¬load¤µ¤ì¤Æ¤¤¤Ê¤¤¾ì¹ç¤¬¤¢¤ë¤Î¤Ç¡¢load¤¹¤ë¤è¤¦¤ËÀßÄꤹ¤ë¡£

¤Ê¤ª¡¢rewrite.load¤ÎÃæ¿È¤Ï¡¢¤ª¤Ê¤¸¤ß¤Î(¾Ð)

LoadModule rewrite_module /usr/lib/apache2/modules/mod_rewrite.so

¤Ç¤¢¤ë¡£

¤Þ¤º¡¢¥³¥Þ¥ó¥É¤Ç

apache2ctl -M

¤È¤·¡¢mod_rewrite¤¬¥í¡¼¥É¤µ¤ì¤Æ¤¤¤ë¤«³Îǧ¡£

root@debian:~# apache2ctl -M

[PR] au PAY / au WALLET ¥«¡¼¥É ¾ðÊó

¤³¤Î¥¨¥ó¥È¥ê¡¼¤ò¤Ï¤Æ¤Ê¥Ö¥Ã¥¯¥Þ¡¼¥¯¤ËÄɲà mixi¥Á¥§¥Ã¥¯



Windows´Ä¶­¤Ç¤âXAMPP¤òÆþ¤ì¤ë¤È´Ä¶­¤¬À°¤¦¤Î¤Ç(¤½¤ÎüËö¤Ê¤Î¤ÇFTPÉÔÍ×)¡¢Ê̤ËLinux¥µ¡¼¥Ð¡¼¤ÏɬÍפǤϤʤ¤¤«¤â¤·¤ì¤Ê¤¤¤¬¡¢Linux¤Ë¤Ä¤¤¤Æ´·¤ì¤ë¤Ê¤é¡¢¼«Ê¬¤ÇΩ¤Æ¤ë¤Ù¤­¤À¤í¤¦¡£

¤È¤¤¤¦¤³¤È¤Ç¡¢Debian7.4¤ò»È¤Ã¤¿»î¸³¥µ¡¼¥Ð¡¼¤ÎΩ¤ÆÊý¤ò°Ê²¼¤Ëµ­¤¹¡£

¤Ê¤ª¡¢¥µ¡¼¥Ð¡¼¤ò±¿ÍѤ¹¤ë¤Ë¤Ï¡¢¥»¥­¥å¥ê¥Æ¥£¡¼¤Ë¤ÏÃí°Õ¤¹¤Ù¤­¤Ç¤¢¤ë¡£

º£²ó¤Ï°ì¿Í¤Ç»ÈÍѤ¹¤ëÆâÉô»î¸³¥µ¡¼¥Ð¡¼¤È¤·¤Æ¤¤¤ë¤¬¡¢³°Éô¤Ë¸ø³«¤¹¤ë¾ì¹ç¤ä¡¢ÆâÉô¤Ç¤¢¤Ã¤Æ¤âÊ£¿ô¿Í¤Ç»È¤¦¾ì¹ç¡¢½ÅÍ×¾ðÊó¤ò³ÊǼ¤¹¤ë¾ì¹ç¤Ï¡¢SSL¤Ë¤è¤ë°Å¹æ²½ÄÌ¿®¤ò²Äǽ¤Ë¤¹¤ëÅù¤·¡¢¥»¥­¥å¥ê¥Æ¥£¡¼¤òËüÁ´¤Ë¤¹¤ë¤³¤È¡£

[PR] au PAY / au WALLET ¥«¡¼¥É ¾ðÊó

¤³¤Î¥¨¥ó¥È¥ê¡¼¤ò¤Ï¤Æ¤Ê¥Ö¥Ã¥¯¥Þ¡¼¥¯¤ËÄɲà mixi¥Á¥§¥Ã¥¯



Apache/2.2.22 (Debian7.4)

/etc/apache2/conf.d ¤Î security ¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤Î ServerTokens Éôʬ

# ServerTokens
# This directive configures what you return as the Server HTTP response
# Header. The default is 'Full' which sends information about the OS-Type
# and compiled in modules.
# Set to one of: Full | OS | Minimal | Minor | Major | Prod
# where Full conveys the most information, and Prod the least.
#
#ServerTokens Minimal
ServerTokens OS
#ServerTokens Full

ÀèÆ¬¤Ë¤¢¤ë¡Ö#¡×¤ò³°¤¹(¥Ç¥Õ¥©¥ë¥È¤Ç¤ÏOS¤Ë¤Ê¤Ã¤Æ¤¤¤ë)¡£

¡¦ServerTokens Minimal¡§Apache/2.2.22 Server at 192.168.0.10 Port 80
¡¦ServerTokens OS¡§Apache/2.2.22 (Debian) Server at 192.168.0.10 Port 80
¡¦ServerTokens Full¡§Apache/2.2.22 (Debian) PHP/5.4.4-14+deb7u7 mod_ssl/2.2.22 OpenSSL/1.0.1e Server at 192.168.0.10 Port 80

¾¤Ë¤â¡¢

¡¦ServerTokens Prod¡§Apache Server at 192.168.0.10 Port 80
¡¦ServerTokens Major¡§Apache/2 Server at 192.168.0.10 Port 80
¡¦ServerTokens Minor¡§Apache/2.2 Server at 192.168.0.10 Port 80

¤¬¤¢¤ë¡£

ÀßÄê¤Î¸å¡¢Apache¤òºÆµ¯Æ°¡£

service apache2 restart

ÅöÁ³¤À¤¬¡¢root¤Ç¤Ê¤¤¤ÈÁàºî¤Ç¤­¤Ê¤¤¤Î¤ÇÃí°Õ¡£

¥µ¡¼¥Ð¹½Ãۤμºݤ¬¤ï¤«¤ë Apache[¼ÂÁ©]±¿ÍÑ/´ÉÍý (Software Design plus)
ÄáĹ Äðì
µ»½ÑɾÏÀ¼Ò
Çä¤ê¾å¤²¥é¥ó¥­¥ó¥°: 22,001

[PR] au PAY / au WALLET ¥«¡¼¥É ¾ðÊó

¤³¤Î¥¨¥ó¥È¥ê¡¼¤ò¤Ï¤Æ¤Ê¥Ö¥Ã¥¯¥Þ¡¼¥¯¤ËÄɲà mixi¥Á¥§¥Ã¥¯



Apache/2.2.22 (Debian7.4)

¥¨¥é¡¼¥Ú¡¼¥¸¤Ë

Apache/2.2.22 (Debian) Server at 192.168.0.10 Port 80

Apache/2.2.22 (Debian) Server at 192.168.0.10 Port 80

¤Èɽ¼¨¤µ¤ì¤Æ¤¤¤ë(¥Ç¥Õ¥©¥ë¥È)¤¬¡¢¤³¤ì¤â¥»¥­¥å¥ê¥Æ¥£¡¼Åª¤ËÎɤ¯¤Ê¤¤¡£

¤³¤ì¤òÈóɽ¼¨¤Ë¤¹¤ë¤Ë¤Ï¡¢

/etc/apache2/conf.d ¤Î security ¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤Î ServerSignature Éôʬ

# Optionally add a line containing the server version and virtual host
# name to server-generated pages (internal error documents, FTP directory
# listings, mod_status and mod_info output etc., but not CGI generated
# documents or custom error documents).
# Set to "EMail" to also include a mailto: link to the ServerAdmin.
# Set to one of: On | Off | EMail
#
#ServerSignature Off
ServerSignature On

¢­

ServerSignature Off
#ServerSignature On

ÀèÆ¬¤Ë¤¢¤ë¡Ö#¡×(¥³¥á¥ó¥È)¤òOn¤ÎÊý¤Ë°Üư¤µ¤»¡¢Off¤Ë¤¹¤ë¡£

ÀßÄê¤Î¸å¡¢Apache¤òºÆµ¯Æ°¡£

service apache2 restart

¤¹¤ë¤È¡¢

¥µ¡¼¥Ð¡¼¾ðÊó¤¬Èóɽ¼¨

¤È¤Ê¤ê¡¢¥µ¡¼¥Ð¡¼¾ðÊó¤¬Èóɽ¼¨¤Ë¤Ê¤ë¡£

¤Ê¤ª¡¢On¤Ç¤âOff¤Ç¤â¤Ê¤¯¡¢

ServerSignature Email

¤È¤¹¤ë¤È¡¢IP¥¢¥É¥ì¥¹¤ÎÉôʬ¤Ë¥á¡¼¥ë¥¢¥É¥ì¥¹¤Ø¤Î¥ê¥ó¥¯¤¬Ä¥¤é¤ì¤ë¡£

¥ê¥ó¥¯¤¬Ä¥¤é¤ì¤ë¥á¡¼¥ë¥¢¥É¥ì¥¹¤Ï¡¢

/etc/apache2/sites-available ¤Ë¤¢¤ë default ¤Ë¤¢¤ë°Ê²¼¤Îµ­½Ò¤Ë¤¢¤ë¡£

¡ãVirtualHost *:80¡ä
¡¡ServerAdmin admin@test.com

ÅöÁ³¤À¤¬¡¢root¤Ç¤Ê¤¤¤ÈÁàºî¤Ç¤­¤Ê¤¤¤Î¤ÇÃí°Õ¡£

´°Á´¤ËÈóɽ¼¨¤È¤Ï¤»¤º¡¢°ìÉô¤Î¤ßɽ¼¨¤¹¤ë¤Ë¤Ï¡¢Æ±¥Õ¥¡¥¤¥ë¤ÎServerTokens¤òÀßÄꤹ¤ë(¼¡²ó)¡£

¥µ¡¼¥Ð¹½Ãۤμºݤ¬¤ï¤«¤ë Apache[¼ÂÁ©]±¿ÍÑ/´ÉÍý (Software Design plus)
ÄáĹ Äðì
µ»½ÑɾÏÀ¼Ò
Çä¤ê¾å¤²¥é¥ó¥­¥ó¥°: 22,001

[PR] au PAY / au WALLET ¥«¡¼¥É ¾ðÊó

¤³¤Î¥¨¥ó¥È¥ê¡¼¤ò¤Ï¤Æ¤Ê¥Ö¥Ã¥¯¥Þ¡¼¥¯¤ËÄɲà mixi¥Á¥§¥Ã¥¯

¤³¤Î¥Ú¡¼¥¸¤Î¥È¥Ã¥×¥Ø