Sponsors

Friday, December 4, 2009

Mac Security: How to Harden the Mac Operating System

Mac Security Recommendations





After my previous two blog posting about Macs having the most security vulnerabilities and Windows 7 being more secure than Apple's Snow Leopard OS for the Mac, I received requests for advice on how to secure the operating system. I compiled recommended security information that will help individuals harden their Mac OS, based on the level of security for their needs.

First thing, you must understand why we safeguard the operating system and where to find information on the most severe and common computer risks. After you become aware of the risks associated with your Information Technology, you then harden the system for your needs.

SANS Top 20 Internet Security Problems, Threats and Risks
The SANS Top 20 Internet Security Problems, Threats and Risks, lists the top 20 security vulnerabilities across a wide array of Information technology platforms.

Make your self familiar with vulnerabilities in the SANS Top 20. It contains vulnerabilities and their mitigating controls for the most widely used Information Technology.
For more go to: http://www.sans.org/top20/

Vulnerability Catagories:

Server-side Vulnerabilities in:
  • S1. Web Applications
  • S2. Windows Services
  • S3. Unix and Mac OS Services
  • S4. Backup SoftwareS5. Anti-virus Software
  • S6. Management Servers
  • S7. Database Software

Security Policy and Personnel:
  • H1. Excessive User Rights and Unauthorized Devices
  • H2. Phishing/Spear Phishing

Application Abuse:
  • A1. Instant Messaging
  • A2. Peer-to-Peer Programs

Network Devices:
  • N1. VoIP Servers and Phones

Zero Day Attacks:
  • Z1. Zero Day Attacks

Client-side Vulnerabilities in:
  • C1. Web Browsers
  • C2. Office Software
  • C3. Email Clients
  • C4. Media Players
The S3. section "UNIX/ MAc OS Services", addresses the countermeasures to safeguard the Mac OS.

S3. Section - UNIX/Mac OS Services

S3.1 Description

Most Unix/Linux systems include multiple standard services in their default installation. Mac OS X often suffers from the same vulnerabilities as Unix systems, since it is based on Unix. Unnecessary services should be disabled, and all servers facing open networks should be protected by a firewall.

For services which provide remote login and/or remote service, traffic cannot be simply blocked by firewalls. Buffer overflow vulnerabilities and flaws in authentication functions can often allow a vector for arbitrary code execution, sometimes with administrative privileges, so gathering vulnerability information and patching rapidly are very important. Every year, buffer overflow vulnerabilities in Unix/Linux services are found.

These services, even if fully patched, can be the cause of unintended compromises. Brute-force attacks against remote services such as SSH, FTP, and telnet are still the most common form of attack to compromise servers facing the Internet. Over the last couple of years a concerted effort has been made by attackers to recover passwords used by these applications via brute-force attacks. Increasingly worms and bots have brute-force password engines built into them. Systems with weak passwords for user accounts are actively and routinely compromised; often privilege escalations are used to gain further privileges, and rootkits installed to hide the compromise. It is important to remember that brute forcing passwords can be a used as a technique to compromise even a fully patched system.

Security-conscious administrators should use SSH or another encrypted protocol as their method of interactive remote access. If the version of SSH is current and it is fully patched, the service is generally assumed to be safe. However, regardless of whether it is up to date and patched SSH can still be compromised via brute-force password-guessing attacks. Use public key authentication mechanism for SSH to thwart such attacks. For the other interactive services, audit passwords to ensure they are of sufficient complexity to resist a brute-force attack.
Minimizing the number of running services on a host will also make it more secure. Many services have been used to further exploits.

The Most Exploited Mac Vulnerabilities of the Last 6 Months
SANS Top Cyber Security Risks, For more information go to:
http://www.sans.org/top-cyber-security-risks/

The graphic below highlights the SANS Top Risks and Vulnerabilities being exploited on Macs now!

SANS Top Cyber Security Risks
Attacks on Critical Apple Vulnerabilities (last 6 months)


How to Harden the Mac Operating System


Now that you understand the treats, risks and countermeasures needed to safeguard your Mac system, we go on to implement control changes based on the level of security you want for your needs. Read through the following Mac OS X Security Guides to determine the level of security rigor for your needs. Additionally, I included some links from other sites that offer other hardening tips and recommendations.


Mac OS X Security Configuration Guides - Taken from apple.com

The Security Configuration Guides provide an overview of features in Mac OS X that can be used to enhance security, known as hardening your computer.
The guides are designed to give instructions and recommendations for securing Mac OS X and for maintaining a secure computer.
To use these guides, you should be an experienced Mac OS X user, be familiar with the Mac OS X user interface, and have at least some experience using the Terminal application’s command-line interface. You should also be familiar with basic networking concepts.
Certain instructions in the guides are complex, and deviation could result in serious adverse effects on the computer and its security. The guides should only be used by experienced Mac OS X users, and any changes made to your settings should be thoroughly tested.

Mac OS X v10.5 (Leopard)

Mac OS X v10.4 (Tiger)

Mac OS X v10.3 (Panther)

Other Mac Hardening Reference Sites

National Security Agency (NSA) Mac Hardening Tips
University of Texas at Austin - Mac OS X Server Hardening Checklist
Corsaire Research provides the latest security intelligence
Macshadows - Advice on Mac System Harding
Sign Up For Mac Security notifications - Taken from apple.com

For the protection of our customers, Apple does not disclose, discuss or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. Apple usually distributes information about security issues in its products through this site and the mailing list below.

Mailing list

The Security-Announce mailing list is provided to obtain product security information from Apple.
You can subscribe via http://lists.apple.com/mailman/listinfo/security-announce, also available via RSS.
Notifications developed by Apple are signed with the Apple Product Security PGP key. We encourage you to check the signature to ensure that the document was indeed written by our staff and has not been changed.

Updates

Check the Apple Security Updates page for released updates.

Finally


Hopefully you will find the security recommendations presented here helpful. My desire is to help ensure that you have pleasant computer and Internet experiences.

Enjoy,

Julius



Thursday, December 3, 2009

Windows 7 Has Better Security Than Apple's Mac Snow Leopard

Windows 7 Bests Snow Leopard Says Mac Hacker



An infamous white hat hacker after his penetration testing found that the Microsoft Windows 7 operating system has better security than Apple's Mac in overall operating system security.

Article:
http://news.softpedia.com/news/Windows-7-Bests-Snow-Leopard-Says-Mac-Hacker-121895.shtml

The improved Windows 7 security advantage has to do with a security approach called:

Address Space Layout Randomization (ASLR)

According to Wikipedia
http://en.wikipedia.org/wiki/Address_space_layout_randomization
ASLR has the following effect and benefits on security:


Benefits

Address space randomization hinders some types of security attacks by making it more difficult for an attacker to predict target addresses. For example, attackers trying to executereturn-to-libc attacks must locate the code to be executed; while other attackers trying to execute shellcode injected on the stack have to first find the stack. In both cases, the related memory addresses are obscured from the attackers; these values have to be guessed, and a mistaken guess is not usually recoverable due to the application crashing.

Effectiveness


Address space layout randomization relies on the low chance of an attacker guessing where randomly-placed areas are located; security is increased by increasing the search space. Thus, address space randomization is more effective when more entropy is present in the random offsets. Entropy is increased by either raising the amount of virtual memory area space the randomization occurs over, or reducing the period the randomization occurs over; the period is typically implemented as small as possible, so most systems must increase VMA space randomization.

This methodology is known as Entropy, which basically means the multiple way that you can rearrange something. Its a good security measure to employ because memory space is constantly rearranged. Malicious code and hackers often take advantage of certain flaws in software which must reside in the same static memory space.

This is sure to shake many Mac owners up who confuse better Mac Performance with better Mac Security as well. It's Apples and Oranges; performance does not mean security!

Enjoy!

Julius


Fact Check: Apple's Mac Operating System has the Most Security Vulnerabilities


"Hey, I'm a Mac...and I have the Most Vulnerability Risks!"



You see the brilliant marketing of Mac computers by Apple, but most people are surprised and shocked to learn that Apple's Mac operating system has the most security vulnerabilities disclosed; they have had the most vulnerability discloses for the last 3 years. The commercials tout the Apple Mac as the worry free computer, but with more security vulnerabilities than Windows, which someone can take advantage of and steal control of your computer.

According to IBM's 2008 XForce Risk & Trends report, Apple's Mac Server and Mac OS products top the list as the most vulnerable OS. Microsoft's operating systems don't appear until 5th place after Linux and the Sun OS.

TOP 10 Most Vulnerable Operating Systems



Now it’s true that Microsoft's Windows operating systems have more individuals targeting it to do a bad things, which is due to Windows products running on over 80% of the worlds computers; it's basically similar to having more robbers determined to rob you than your friend, but your friend has more weaknesses. Apple's Mac operating systems have about 3X more disclosed attack weaknesses than all the variations of currently supported Microsoft Windows products.

Keeping them honest!

Complete 2008 IBM XForce Security report
http://docs.bankinfosecurity.com/files/whitepapers/pdf/255_ibm_xforce_report.pdf

Enjoy,

Julius Clark


Monday, November 16, 2009

My First IT Security Aritcle Published: Was Harriet Tubman a CISSP?

The National Society of Black Engineers (NSBE), in their November 2009 issue of the Alumni Arsenal published my February 2009 blog:

Was Harriet Tubman a CISSP?

I am extremely excited and motivated to write more articles now. I originally wrote the blog because of my passion for Information Security, The prestigious Certified Information Systems Security Professional Certification (CISSP) that I hold and for my deep admiration and respect of the accomplishments of the Freedom Fighter Harriet Tubman. I wanted to combine these three areas to motivate and influence more African Americans to pursue careers in Information Security. I felt that if I could demonstrate how Important Information Security was to the African American experience for freedom, then more students regardless of their background or race would be interested in becoming an Information Security Professional.

So click on the cover or the link at the bottom and take a look. I still can't believe that I have original work in print.

Check out my blog article on the front cover! I am so excited!



Enjoy,

Julius Clark, MBA, MSIS, CISSP, CISA
Information Security Professional

In addition, if you are new to the IT Security field, or have no experience and want to change your career consult with me at:


M69RCC7BKYKC




Friday, October 23, 2009

Finally, A Useful Update for the LinkedIn IPhone App

IPhone LinkedIn App Update v1.5



The LinkedIn IPhone Application has been upgraded with a more usable Inbox, with the robust features we are used to having in the full browswer version!

Summary of new features:
  1. Easy to Browse Network Updates.
  2. Pictures associated with your connections.
  3. Search the connections you have and search by keywords.
  4. Status Update.
  5. Last but not least, you can conveniently use the Inbox and Send box to get to messages with pictures associated with them.
Enjoy,

Julius






, , , , ,

Thursday, October 22, 2009

Blogging: Who, What, When, Where, Why and How


Many people still don't understand the blogging revolution. So let me lend my thought leadership on the issue to those that follow my blog.

Blogger Audience
People Think of things and Needs.
People Google search on Things and Needs.
People inspect the Google search results retrieved.

The Blogger
If you have hot ideas, products, Services, talent or skills, and you love to share information, then blog! Your blog could appear in the Google search results of the People who search for things and needs.

Below are a some excellent videos I found on Youtube that uniquely describe what a blog is, and what RSS feeds do. They were created by Lee Lefever of Commoncraft.com. Additionally, I added another one of their of videos titled RSS in Plain English. Hopefully they will those who are new to blogging understand the Who, What, When, Where, Why and How about them.

Explaining Blogs in Plain English



Explaining RSS in Plain English



Enjoy,

Julius




Sunday, October 18, 2009

Your tax dollars at work: Information Security For Small Business


The National Institute of Standards and Technology (NIST), along with the U.S. Department of  Commerce recently released a video for Small Business titled:


Information Technology Security For Small Business








I recently presented an online webinar based on the video above and the following NIST Security Guidelines:

Small Business Information Security : The Fundamentals (Security Guide for Small Business)
http://csrc.nist.gov/publications/drafts/ir-7621/draft-nistir-7621.pdf
 

According to the U.S. Department of Commerce, there are over 26 Million small businesses in the U.S. The reasoning why small business is considered a Critical Infrastructure Asset for America, which must be protected from Cyber Threats.

Please share this information with individuals and small business owners you know.

Enjoy,

Julius, MBA, CISSP, CISA




Friday, October 16, 2009

Stop Losing Perfectly Good Email To The Junk Mail Folder!



When is the last time you inspected your junk mail folder? Junk mail filters are great Information Security tools to keep spam and other unwanted emails out of your main email Inbox; junk email filters are not intelligent, you will need to peep into your junk mail folder often to find important emails that you may need to reply to. I recently looked in my Outlook Junk Mail folder and found lots of valid emails, that I needed to see. The lesson I learned was to view my junk email folder more often, and do create rules for the type of emails that my junk email filter grabbed. I would bet that many people just forget about the junk email folder and never view its contents. When is the last time you viewed your junk email folder?

 Email Filter & Rules Tips!
  1. View your junk email folder often; I will now view mine everyday.
  2. When you find good email in your junk email folder, adjust your junk email filters to prevent emails sent from that person, domain (@microsoft.com) or catagory from being dumped into your junk email folder.
  3. Gain email Inbox efficiency and organization by creating email rules that automatically move the email types mentioned above into folders, which would assit in finding emails quicker. 
Enjoy,

Julius




, , , , , ,

Tuesday, October 13, 2009

Information Security For Small Business

 The following is a SlideShare I first presented via a live online webinar for the Orlando, FL chapter of the BDPA.

"IT INCLUDES VIDEO ON SMALL BUSINESS SECURITY BY NIST SECURITY PROFESSIONALS AT THE END OF PRESENTATION!

If you are a small business with need of Information Security knowledge. Review this presentation and if you need help protecting your critical systems or data contact me.

Enjoy,

Julius Clark

Information Security for Small Business

Tuesday, October 6, 2009

The Unemployed Information Security Professional: How To Keep Your Skills Sharp






Former Chairman of the U.S. Federal Reserve, Alan Greenspan, yesterday when asked for a statement regarding the recovery of the nation's economy said; "expect unemployment to reach 10 percent and hover there for awhile."




He said this is of concern because the longer people are unemployed, they start to loose their job skills. To help Information Security professionals who are unemployed retain their skills I suggest the following:


10 Things for the Unemployed Information Technology Security Professional to Do To Stay Competitive When Between Jobs

  1. Review all of the IT Security Information you can for Microsoft's new Windows 7 .Operating System; you will be ahead of most security professionals in this area if you do.
  2. Refresh your knowledge of the SANS TOP 20 vulnerabilities; the most critical of IT Security vulnerabilities.
  3. Refresh your knowledge of NIST.gov IT Security Control Guidelines; in-depth information about security controls and countermeasures; most company's use some adaptation of NIST security guidelines.
  4. Review CCCure.org's FREE security training videos and test quizzes; can't believe this resource is free! Incrdible!
  5. Studying for a highly sought after Information Security Certification; gaining a cert will help market yourself to prospective employers.
  6. View free online IT Security Webinars; easy way to get cutting edge training.
  7. Become a speaker for other professional organizations on IT Security topics.
  8. Participate in LinkedIn Group discussions and answer questions related to IT Security; become an IT Security Thought Leader!
  9. Volunteer on an IT Security organization's Board and/ or volunteer your time teaching Computer/ Internet Security to schools or non-profit agencies; great networking opportunities.
  10. Take advantage of the time and consider creating a business plan and start an IT Security consultancy; market your services to local businesses or non-profits who normally don't have access to expert security professionals.
Best of luck,


Julius Clark, MBA, CISSP, CISA








, , ,

Get Expert Advice!