Sponsors

Showing posts with label hardening. Show all posts
Showing posts with label hardening. Show all posts

Monday, February 15, 2010

All You Ever Wanted To Know About Joomla Security


https://www.palmettomastersingers.org/Joomla/images/stories/Links/Joomla_Logo_Vert_Color.png

All You Ever Wanted To Know About Joomla Security


Due to the time I spent rebuilding and cleaning up a recent Joomla hack and defacement of a web by an individual from the country of Turkey, I have become much more knowledgeable of Joomla security issues.

Looking through the monitoring statistics of the attacked site, it only took 4 minutes for the person hacking the site to compromise it; they found the site by searching for vulnerable Joomla 3rd party extensions which were installed in the site, which can get indexed on Google.

Joomla has become on of the hottest, easy to use, and simple to setup web site Content Managmet Systems  out there. With that, it has increasingly become the target of hackers. Just like Microsoft did with the popularity of the Windows Operating System, Joomla is reaping the success of developing software that helps people work and communicate more efficiently,  but at the cost of being on the radar for individuals who like to destroy and cause havoc on websites.

So for all of those looking for guidance on Joomla security I have provided a list of sources from various places that offer great Joomla security advance. The Majority of what you need to know about staying in the know and securing your Joomla site can be found here on my blog.



1)     Getting Started with your Joomla site
A.     Official Joomla Documentation

·   http://docs.joomla.org/

B.     How to Choose a Hosting Provider

·   http://docs.joomla.org/Security_and_Performance_FAQs

C.     Look at Ultra Secure Web Host Providers Like, FireHost.com a Secure Web Hosting Probider Who Defends against DDoS and Provides Top Notch, Corporate Enterprise Class Intrution Detection (IDS) & Intrusion Provention (IPS) Services.

2)      Install most up-to-date version of Joomla
·   http://www.joomla.org/download.html

3)      Test and Patch Joomla installation as Soon as a New Patch Update is Released
·   http://joomlacode.org/gf/project/joomla/frs/?action=FrsReleaseBrowse&frs_package_id=4947

4)      Rename admin account

5)      Change default password “admin” to a strong password

6)      Redirect Joomla Management Console Default
http://www.yoursite.com/administrator to something else by using a secure plug-in or something else. plugins/system/404.html

A.     Consider Using JSecure Authentication for Console Access and Re-Direction

·   http://extensions.joomla.org/extensions/access-a-security/site-security/5809

7)     Joomla Permissions  Give Write and Execute permissions only to files and folders that need them. See #12 below: Joomla Hardening.

8)      Don’t Use High Risk Joomla Extensions that appear on Vulnerablity Extensions lists
A.     Vulnerable Extensions List

·   http://docs.joomla.org/Vulnerable_Extensions_List

B.     U.S. Vulnerabilities Database: Enter Joomla or Names of Joomla Extensions

·   http://web.nvd.nist.gov/view/vuln/search?cid=1.

9)      Scan your Joomla site often to check for vulnerabilities
A.     OWASP’s free JoomaScan Vulnerability Scanner- Usage : Note to run on Windows, you will first need to install a Perl Distribution; Such as ActivePerl.  Real easy to install, then begin your scanning!

·   http://sourceforge.net/projects/joomscan/

·   Mailing List

·   Subscribe: https://lists.owasp.org/mailman/listinfo/owasp-joomla-vulnerability-scanner

·    or Use: owasp-joomla-vulnerability-scanner@lists.owasp.org

B.     Hacker Targets’ free web based Joomla site scanner

·   http://hackertarget.com/joomla-security-scan

·   Web site protection http://yehg.net/lab/pr0js/papers/MULTIPLE%20TRICKY%20WAYS%20TO%20PROTECT.pdf

10)   Disaster Recovery: Backup Your Site!

A.     JoomPack Site Back Up

·   http://extensions.joomla.org/extensions/1606/details

·   Restore JoomPack: http://joomlapack.net/download/itemlist/category/52-kickstart.html

11)   Create a Test Site on a Local Host/ Workstation Before Making Changes To Your Joomla Site
A.      Joomla Downloadable Local Host Instant Infrastructure!

·   http://demo.joomla.org- Jumpbox, TurnKey & Online Joomla Demo Site

B.      Manually Install/Setup a Windows Test/Development Joomla Environment

·   Part 1 -  http://docs.joomla.org/Setting_up_your_workstation_for_Joomla!_development

·   Part 2 -  http://docs.joomla.org/Setting_up_your_workstation_for_Joomla!_development_--_Part_2
C.      How To Copy From Host to Remote Host and Vice-Versa

·   http://docs.joomla.org/How_do_you_copy_a_site_from_localhost_to_a_remote_host%3F


12)   Joomla Website Hardening


A.      Joomla Security Guide

·   http://www.myjoomlasecurity.com/index.php/Main_PageCheck


13)   More Joomla Security Resources

A.      Joomla Administrators Security Checklist

·   http://developer.joomla.org/security/articles-tutorials/260-joomla-administrators-security-checklist.html

B.     Joomla Security Strike Team

·   http://developer.joomla.org/security.html

C.     Joomla Security FAQs

  http://docs.joomla.org/Category:Security_FAQ
D. Top 10 Joomla Security Problems and How To Avoid Them

·  http://joomplaza.com/index.php/tutorials/82-top-ten-joomla-security-problems---and-how-to-avoid-them

E. Top 10 Joomla Security Extentions

. http://hostingword.com/web-hosting-reviews/10-most-popular-joomla-security-extensions/

 If any of the above links disappear or are not working properly, please let me know. Thanks in advance!

Enjoy your Joomla Content Management Experience Safely and with no Headaches!

Sincerely,

Julius, CISSP, CISA

 In addition, if you are new to the IT Security field, or have no experience and want to change your career consult with me at:











Friday, December 4, 2009

Mac Security: How to Harden the Mac Operating System

Mac Security Recommendations





After my previous two blog posting about Macs having the most security vulnerabilities and Windows 7 being more secure than Apple's Snow Leopard OS for the Mac, I received requests for advice on how to secure the operating system. I compiled recommended security information that will help individuals harden their Mac OS, based on the level of security for their needs.

First thing, you must understand why we safeguard the operating system and where to find information on the most severe and common computer risks. After you become aware of the risks associated with your Information Technology, you then harden the system for your needs.

SANS Top 20 Internet Security Problems, Threats and Risks
The SANS Top 20 Internet Security Problems, Threats and Risks, lists the top 20 security vulnerabilities across a wide array of Information technology platforms.

Make your self familiar with vulnerabilities in the SANS Top 20. It contains vulnerabilities and their mitigating controls for the most widely used Information Technology.
For more go to: http://www.sans.org/top20/

Vulnerability Catagories:

Server-side Vulnerabilities in:
  • S1. Web Applications
  • S2. Windows Services
  • S3. Unix and Mac OS Services
  • S4. Backup SoftwareS5. Anti-virus Software
  • S6. Management Servers
  • S7. Database Software

Security Policy and Personnel:
  • H1. Excessive User Rights and Unauthorized Devices
  • H2. Phishing/Spear Phishing

Application Abuse:
  • A1. Instant Messaging
  • A2. Peer-to-Peer Programs

Network Devices:
  • N1. VoIP Servers and Phones

Zero Day Attacks:
  • Z1. Zero Day Attacks

Client-side Vulnerabilities in:
  • C1. Web Browsers
  • C2. Office Software
  • C3. Email Clients
  • C4. Media Players
The S3. section "UNIX/ MAc OS Services", addresses the countermeasures to safeguard the Mac OS.

S3. Section - UNIX/Mac OS Services

S3.1 Description

Most Unix/Linux systems include multiple standard services in their default installation. Mac OS X often suffers from the same vulnerabilities as Unix systems, since it is based on Unix. Unnecessary services should be disabled, and all servers facing open networks should be protected by a firewall.

For services which provide remote login and/or remote service, traffic cannot be simply blocked by firewalls. Buffer overflow vulnerabilities and flaws in authentication functions can often allow a vector for arbitrary code execution, sometimes with administrative privileges, so gathering vulnerability information and patching rapidly are very important. Every year, buffer overflow vulnerabilities in Unix/Linux services are found.

These services, even if fully patched, can be the cause of unintended compromises. Brute-force attacks against remote services such as SSH, FTP, and telnet are still the most common form of attack to compromise servers facing the Internet. Over the last couple of years a concerted effort has been made by attackers to recover passwords used by these applications via brute-force attacks. Increasingly worms and bots have brute-force password engines built into them. Systems with weak passwords for user accounts are actively and routinely compromised; often privilege escalations are used to gain further privileges, and rootkits installed to hide the compromise. It is important to remember that brute forcing passwords can be a used as a technique to compromise even a fully patched system.

Security-conscious administrators should use SSH or another encrypted protocol as their method of interactive remote access. If the version of SSH is current and it is fully patched, the service is generally assumed to be safe. However, regardless of whether it is up to date and patched SSH can still be compromised via brute-force password-guessing attacks. Use public key authentication mechanism for SSH to thwart such attacks. For the other interactive services, audit passwords to ensure they are of sufficient complexity to resist a brute-force attack.
Minimizing the number of running services on a host will also make it more secure. Many services have been used to further exploits.

The Most Exploited Mac Vulnerabilities of the Last 6 Months
SANS Top Cyber Security Risks, For more information go to:
http://www.sans.org/top-cyber-security-risks/

The graphic below highlights the SANS Top Risks and Vulnerabilities being exploited on Macs now!

SANS Top Cyber Security Risks
Attacks on Critical Apple Vulnerabilities (last 6 months)


How to Harden the Mac Operating System


Now that you understand the treats, risks and countermeasures needed to safeguard your Mac system, we go on to implement control changes based on the level of security you want for your needs. Read through the following Mac OS X Security Guides to determine the level of security rigor for your needs. Additionally, I included some links from other sites that offer other hardening tips and recommendations.


Mac OS X Security Configuration Guides - Taken from apple.com

The Security Configuration Guides provide an overview of features in Mac OS X that can be used to enhance security, known as hardening your computer.
The guides are designed to give instructions and recommendations for securing Mac OS X and for maintaining a secure computer.
To use these guides, you should be an experienced Mac OS X user, be familiar with the Mac OS X user interface, and have at least some experience using the Terminal application’s command-line interface. You should also be familiar with basic networking concepts.
Certain instructions in the guides are complex, and deviation could result in serious adverse effects on the computer and its security. The guides should only be used by experienced Mac OS X users, and any changes made to your settings should be thoroughly tested.

Mac OS X v10.5 (Leopard)

Mac OS X v10.4 (Tiger)

Mac OS X v10.3 (Panther)

Other Mac Hardening Reference Sites

National Security Agency (NSA) Mac Hardening Tips
University of Texas at Austin - Mac OS X Server Hardening Checklist
Corsaire Research provides the latest security intelligence
Macshadows - Advice on Mac System Harding
Sign Up For Mac Security notifications - Taken from apple.com

For the protection of our customers, Apple does not disclose, discuss or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. Apple usually distributes information about security issues in its products through this site and the mailing list below.

Mailing list

The Security-Announce mailing list is provided to obtain product security information from Apple.
You can subscribe via http://lists.apple.com/mailman/listinfo/security-announce, also available via RSS.
Notifications developed by Apple are signed with the Apple Product Security PGP key. We encourage you to check the signature to ensure that the document was indeed written by our staff and has not been changed.

Updates

Check the Apple Security Updates page for released updates.

Finally


Hopefully you will find the security recommendations presented here helpful. My desire is to help ensure that you have pleasant computer and Internet experiences.

Enjoy,

Julius



Get Expert Advice!