<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>정보보안 탈출기원</title>
    <link>https://aaaah05.tistory.com/</link>
    <description>실무자의 취약점 진단 / 보안 설정 가이드</description>
    <language>ko</language>
    <pubDate>Mon, 28 Sep 2026 14:30:53 +0900</pubDate>
    <generator>TISTORY</generator>
    <ttl>100</ttl>
    <managingEditor>굥만둣국</managingEditor>
    <image>
      <title>정보보안 탈출기원</title>
      <url>https://tistory1.daumcdn.net/tistory/8722700/attach/6e1a86d7b5424d19bd2cea5c3ce82c4b</url>
      <link>https://aaaah05.tistory.com</link>
    </image>
    <item>
      <title>[인프라진단] MySQL 설치와 실습 환경 준비 - Ubuntu에서 시작하기</title>
      <link>https://aaaah05.tistory.com/176</link>
      <description>&amp;nbsp;


1. 이번에 만드는 실습 환경
이번 글에서는 Ubuntu에 MySQL을 설치하고, 이후 보안 설정을 점검할 준비를 합니다. DB를 처음 접한다면 프로그램 설치보다 먼저 어느 컴퓨터에 무엇을 설치하는지부터 구분하면 편합니다.
내 Windows PC
  └─ VMware Workstation: 가상 컴퓨터를 실행하는 프로그램
       └─ Ubuntu VM: 실습용 가상 컴퓨터 한 대
            └─ MySQL Server: ..</description>
      <category>2026 주요정보통신기반시설 가이드/DBMS(MySQL)</category>
      <category>2026보안가이드</category>
      <category>DBMS</category>
      <category>MySQL</category>
      <category>mysql설치</category>
      <category>ubuntu</category>
      <category>VMware</category>
      <category>데이터베이스</category>
      <category>실습환경</category>
      <category>오프라인설치</category>
      <category>인프라진단</category>
      <author>굥만둣국</author>
      <guid isPermaLink="true">https://aaaah05.tistory.com/176</guid>
      <comments>https://aaaah05.tistory.com/176#entry176comment</comments>
      <pubDate>Wed, 16 Sep 2026 16:34:33 +0900</pubDate>
    </item>
    <item>
      <title>[인프라진단] #U-67 로그 디렉터리 소유자 및 권한 설정</title>
      <link>https://aaaah05.tistory.com/175</link>
      <description>1. 항목 설명
로그 파일의 소유자와 권한이 느슨하면 일반 사용자가 공격 흔적을 삭제&amp;middot;변조하거나 민감한 운영 정보를 읽을 수 있습니다.
판단 기준: 가이드 기준상 로그 파일이 root 소유이고 권한이 644 이하이면 양호, 아니면 취약입니다.
2026 가이드 근거

2. 점검 목적
로그를 관리자만 통제하게 하고 비인가 열람&amp;middot;변조를 방지하는 것이 목적입니다.
3. 실습 환경

원본 최초진단 환경: Ubuntu 24.04.4 LTS..</description>
      <category>2026 주요정보통신기반시설 가이드/Unix(Linux)</category>
      <category>2026보안가이드</category>
      <category>U-67</category>
      <category>ubuntu</category>
      <category>unix</category>
      <category>로그무결성</category>
      <category>로그보안</category>
      <category>리눅스보안</category>
      <category>인프라진단</category>
      <category>취약점진단</category>
      <category>파일권한</category>
      <author>굥만둣국</author>
      <guid isPermaLink="true">https://aaaah05.tistory.com/175</guid>
      <comments>https://aaaah05.tistory.com/175#entry175comment</comments>
      <pubDate>Wed, 9 Sep 2026 10:24:04 +0900</pubDate>
    </item>
    <item>
      <title>[인프라진단] #U-66 정책에 따른 시스템 로깅 설정</title>
      <link>https://aaaah05.tistory.com/174</link>
      <description>1. 항목 설명
로그 정책이 없거나 서비스가 기록하지 않으면 침해사고 원인과 행위 시점을 확인할 수 없고 감사&amp;middot;법적 증거도 부족해집니다.
판단 기준: 조직 정책에 따라 필요한 시설&amp;middot;중요도의 로그 경로가 설정되고 실제 기록이 생성되면 양호입니다.
2026 가이드 근거

2. 점검 목적
인증, 예약 작업, 커널, 메일과 보안 이벤트를 필요한 위치에 남겨 사고 조사와 운영 감사를 지원하는 것이 목적입니다.
3. 실습 환경

원본 최초..</description>
      <category>2026 주요정보통신기반시설 가이드/Unix(Linux)</category>
      <category>2026보안가이드</category>
      <category>rsyslog</category>
      <category>U-66</category>
      <category>ubuntu</category>
      <category>unix</category>
      <category>로그정책</category>
      <category>리눅스보안</category>
      <category>시스템로깅</category>
      <category>인프라진단</category>
      <category>취약점진단</category>
      <author>굥만둣국</author>
      <guid isPermaLink="true">https://aaaah05.tistory.com/174</guid>
      <comments>https://aaaah05.tistory.com/174#entry174comment</comments>
      <pubDate>Wed, 9 Sep 2026 10:23:09 +0900</pubDate>
    </item>
    <item>
      <title>[인프라진단] #U-65 NTP 및 시각 동기화 설정</title>
      <link>https://aaaah05.tistory.com/173</link>
      <description>1. 항목 설명
서버 시간이 다르면 인증 토큰, 인증서, 분산 처리와 사고 로그의 시간 관계를 신뢰하기 어렵습니다. 승인된 기준시와 지속적으로 동기화해야 합니다.
판단 기준: NTP 클라이언트가 승인된 기준시를 선택해 정상 동기화하고 있으면 양호입니다.
2026 가이드 근거

2. 점검 목적
시스템 간 일관된 시간을 유지해 인증과 장애&amp;middot;침해사고 분석의 신뢰성을 확보하는 것이 목적입니다.
3. 실습 환경

원본 최초진단 환경: Ubuntu 2..</description>
      <category>2026 주요정보통신기반시설 가이드/Unix(Linux)</category>
      <category>2026보안가이드</category>
      <category>Chrony</category>
      <category>ntp</category>
      <category>U-65</category>
      <category>ubuntu</category>
      <category>unix</category>
      <category>리눅스보안</category>
      <category>시간동기화</category>
      <category>인프라진단</category>
      <category>취약점진단</category>
      <author>굥만둣국</author>
      <guid isPermaLink="true">https://aaaah05.tistory.com/173</guid>
      <comments>https://aaaah05.tistory.com/173#entry173comment</comments>
      <pubDate>Wed, 9 Sep 2026 10:21:41 +0900</pubDate>
    </item>
    <item>
      <title>[인프라진단] #U-64 주기적 보안 패치 및 벤더 권고사항 적용</title>
      <link>https://aaaah05.tistory.com/172</link>
      <description>1. 항목 설명
운영체제와 패키지의 알려진 취약점은 벤더 보안 업데이트로 수정됩니다. 장기간 미적용하면 공개된 공격 코드에 그대로 노출될 수 있습니다.
판단 기준: 벤더 권고를 정기 확인하고 승인된 주기에 보안 패치를 적용해 미적용 업데이트가 관리되면 양호입니다.
2026 가이드 근거

2. 점검 목적
알려진 취약점을 적시에 제거하고 지원되는 운영체제&amp;middot;커널 상태를 유지하는 것이 목적입니다.
3. 실습 환경

원본 최초진단 환경: Ubuntu..</description>
      <category>2026 주요정보통신기반시설 가이드/Unix(Linux)</category>
      <category>2026보안가이드</category>
      <category>apt</category>
      <category>U-64</category>
      <category>ubuntu</category>
      <category>unix</category>
      <category>리눅스보안</category>
      <category>보안패치</category>
      <category>인프라진단</category>
      <category>취약점진단</category>
      <category>패치관리</category>
      <author>굥만둣국</author>
      <guid isPermaLink="true">https://aaaah05.tistory.com/172</guid>
      <comments>https://aaaah05.tistory.com/172#entry172comment</comments>
      <pubDate>Wed, 9 Sep 2026 10:19:30 +0900</pubDate>
    </item>
  </channel>
</rss>