Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

Tuesday, October 16, 2007

Securing Mac PC’s

Macs are much more secure than Windows systems. In addition to having most unnecessary services disabled by default, Macs face very little threat from viruses, spyware, adware, and other malware, but this does not mean that Macs are immune from security threats though.

Apple computers need good security practice to remain secure just as Windows systems do. By configuring user accounts, assigning proper permissions, complex passwords, regularly updating Mac OS X and installed applications, ensuring the Mac’s built-in firewall is properly configured, and by following other steps reviewed here, users can help ensure they have taken steps to protect their systems from unwanted breaches.

Antivirus and antispyware options

Spyware on the Mac platform, however, is basically not an issue. Unlike the Windows OS, which is sometimes crippled by the never-ending onslaught, Macs are relatively immune from the threat. However, there are very few utilities exist to protect Macs from unwanted software and malware. Such offerings include SmithMicro Software’s Internet Cleanup and SecureMac.com Inc.’s MacScan.

Security efforts on the Mac, therefore, quickly turn to focusing on user account security. Once user accounts have been implemented and separate, complex passwords assigned to both user and local administrator accounts, users can take several steps to help ensure Mac OS X systems remain secure.

Software update

Keeping systems current with the latest security updates and patches is a necessity. The Mac’s Software Update feature is the equivalent of Windows Update. By configuring Software Update to automatically download and apply security updates, users can keep systems current and help protect Mac OS X from unwanted breaches.

To configure Software Update, users should follow these steps on Mac OS X version 10.4 systems:Open System Preferences. Double-click Software Update within the System section. Press the Update Software tab. Select the Check For Updates box.

Specify how often the Mac system should check for updates (options include Daily, Weekly, and Monthly). Weekly updates should be sufficient for most users.

If you want to review downloads before they install you should check the Download Important Updates In The Background box. When the box is checked, the Mac will notify you that important software updates have been downloaded and are awaiting installation.

If you want to review which software updates have been loaded you can check the Software Update’s Installed Updates tab. A window will appear listing installed updates, for which version number information also appears.

You can check for new updates at any time by pressing the Software Update’s Check Now button.

Application updates

In addition to ensuring Mac OS X remains up-to-date with the latest security patches and fixes, you should ensure that all installed applications remain current. For example, a number of Mac programs connect the Internet and other resources. Those programs must remain secure with the latest security patches. By regularly updating Web browsers, office applications, utilities, antivirus programs, and other software, users can help prevent common causes of system breaches.

IP Firewall

It is essential to familiarize yourself with the Mac OS X IP Firewall, known as IPFW. The built-in firewall offers a powerful tool for protecting against unwanted network access.

To enable Mac’s IP Firewall and reduce network threats, follow these steps:
Open System Preferences.
Double-click the Sharing option within the Internet & Network section.
Select the Firewall tab.
Press the padlock icon and enter an account username administrator password and press OK.
Ensure the firewall is enabled (press the Start button if the firewall is stopped).
Disable as many of the incoming network services as is practical within your operating environment.

To disable services (for which default options include Personal File Sharing, Windows Sharing, Personal Web Sharing, Remote Login — SSH, FTP Access, Apple Remote Desktop, Remote Apple Events, Printer Sharing, iChat Bonjour, iTunes Music Sharing, iPhoto Bonjour Sharing, Network Time and CVS), simply uncheck the respective checkbox. You can add new services using the supplied New button.

When enabling new incoming services, you must specify a port name - options include ICQ, IRC, Timbuktu, VNC, and Other - TCP port number, UDP port number, and a description.

Under Advanced Options you can choose to block all UDP traffic, enable firewall logging and trigger Stealth Mode. In Stealth Mode, uninvited traffic receives no response from the Mac system, which increases security by preventing the Mac from automatically responding to even simple attempts to learn whether it is online.

FileVault

To ensure Mac data remains secure you can take advantage of Apple’s FileVault feature, which is particularly important on laptops used by mobile users. FileVault automatically encrypts all the data within each user’s Home folder. Without knowing a user’s password, the 128-bit encryption makes it much more difficult for another user or hacker to access another Mac user’s files.
To enable FileVault, follow these steps:
Open System Preferences.
Double-click the Security icon within the Personal section.
Select Turn On FileVault (you’ll be prompted to set a Master Password for the system if one hasn’t already been assigned).

The Mac will present a warning message stating that files will be encrypted. Users must enter the administrator password to proceed. Once the password has been entered the Mac begins to encrypt the user’s Home Folder. This process can take some time depending upon the number and size of files stored within the Home Folder.

When complete, the Mac will present the login Window. You can then log back in to the Mac system and will find the Home Folder contents are now encrypted, as shown by a FileVault icon on the user’s login window.

Secure virtual memory

Virtual memory is the data the Mac stores on the hard drive when operations exceed available RAM.

By enabling Secure Virtual Memory you can prevent hackers from accessing information including passwords etc. from a user’s live swap file. While it sounds unlikely, the increase of unencrypted Wi-Fi hotspots has increased the chances of such a breach.

To enable Secure Virtual Memory, follow these steps:
Open System Preferences.
Double-click the Security icon from within the Personal section.
Press on the padlock to enable changes.
Supply a username and administrator password.
Check the box for Use Secure Virtual Memory.

Other recommendations

Mac users can also take further steps to help secure their system. In addition to disabling automatic login (the checkbox is accessed using the Security applet within System Preferences), you should disable fast user switching (accessed from the Accounts applet in System Preferences). When using new Macs, care should be taken to leave the UNIX-powered machine’s root account off.

To disable the root user account (if enabled), follow these steps:
Open the Mac’s Finder application.
Navigate to the Applications folder.
Open the Utilities folder.
Open NetInfo Manager.
Select Security from the top menu bar and select Authenticate.
Enter a username and administrator password and press OK.
Highlight Security from the menu bar.
Select Disable Root User.

Securing Your Wireless Network

Working from home while using a wireless local area network (WLAN) may lead to theft of sensitive information and hacker or virus infiltration unless proper measures are taken.

As WLANs send information over radio waves, someone with a receiver in your area could be picking up the transmission, therefore gaining access to your computer. They could load viruses on to your computer which could be transferred to other computers on your network.

Up to 75 per cent of WLAN users do not have basic security features installed, while 20 per cent are left completely open with the default configurations.

It is recommended that wireless router/access point setup be always done though a wired client.

You can setup your security by follow these steps:

Change default admin password on wireless router/access point to a secured password.

Change your WEP keys periodically.

Change the channel your router uses to transmit and receive data on a regularly basis.

Use encryption such as WEP and WPA. If equipment does not support at least 128-bit WEP encryption, consider replacing it.

Change the default SSID on your router/access point to a hard to guess name. Setup your computer device to connect to this SSID by default.

Setup router/access point not to broadcast the SSID. The same SSID needs to be setup on the client side manually. This feature may not be available on all equipment.

Block anonymous Internet requests or pings.

On each computer having a wireless network card, network connection properties should be configured to allow connection to Access Point Networks Only.

Computer to Computer (peer to peer) Connection should not be allowed. Enable MAC filtering. Deny availability to your wireless network for unspecified MAC addresses.

Mac or Physical addresses are available through your computer device network connection setup and they are physically written on network cards.

When adding new wireless cards / computers to the network, their MAC addresses should be registered with the router /access point.

Network router should have firewall features enabled and demilitarized zone (DMZ) feature disabled.

All computers should have a properly configured personal firewall in addition to a hardware firewall. You should also update router/access point firmware when new versions become available.

There is no guarantee of a full protection of your wireless network, but following these suggested tips can definitely lessen your risk of exposing to attackers aiming at insecure networks.

Monday, October 01, 2007

Securing Mac's

Macs are much more secure than Windows systems. In addition to having most unnecessary services disabled by default, Macs face very little threat from viruses, spyware, adware, and other malware, but this does not mean that Macs are immune from security threats though.

Apple computers need good security practice to remain secure just as Windows systems do. By configuring user accounts, assigning proper permissions, complex passwords, regularly updating Mac OS X and installed applications, ensuring the Mac’s built-in firewall is properly configured, and by following other steps reviewed here, users can help ensure they have taken steps to protect their systems from unwanted breaches.

Antivirus and antispyware options

Spyware on the Mac platform, however, is basically not an issue. Unlike the Windows OS, which is sometimes crippled by the never-ending onslaught, Macs are relatively immune from the threat. However, there are very few utilities exist to protect Macs from unwanted software and malware. Such offerings include SmithMicro Software’s Internet Cleanup and SecureMac.com Inc.’s MacScan.

Security efforts on the Mac, therefore, quickly turn to focusing on user account security. Once user accounts have been implemented and separate, complex passwords assigned to both user and local administrator accounts, users can take several steps to help ensure Mac OS X systems remain secure.

Software update

Keeping systems current with the latest security updates and patches is a necessity. The Mac’s Software Update feature is the equivalent of Windows Update. By configuring Software Update to automatically download and apply security updates, users can keep systems current and help protect Mac OS X from unwanted breaches.

To configure Software Update, users should follow these steps on Mac OS X version 10.4 systems:Open System Preferences. Double-click Software Update within the System section. Press the Update Software tab. Select the Check For Updates box.

Specify how often the Mac system should check for updates (options include Daily, Weekly, and Monthly). Weekly updates should be sufficient for most users.

If you want to review downloads before they install you should check the Download Important Updates In The Background box. When the box is checked, the Mac will notify you that important software updates have been downloaded and are awaiting installation.

If you want to review which software updates have been loaded you can check the Software Update’s Installed Updates tab. A window will appear listing installed updates, for which version number information also appears.

You can check for new updates at any time by pressing the Software Update’s Check Now button.

Application updates

In addition to ensuring Mac OS X remains up-to-date with the latest security patches and fixes, you should ensure that all installed applications remain current. For example, a number of Mac programs connect the Internet and other resources. Those programs must remain secure with the latest security patches. By regularly updating Web browsers, office applications, utilities, antivirus programs, and other software, users can help prevent common causes of system breaches.

IP Firewall

It is essential to familiarize yourself with the Mac OS X IP Firewall, known as IPFW. The built-in firewall offers a powerful tool for protecting against unwanted network access.

To enable Mac’s IP Firewall and reduce network threats, follow these steps:
Open System Preferences.
Double-click the Sharing option within the Internet & Network section.
Select the Firewall tab.
Press the padlock icon and enter an account username administrator password and press OK.
Ensure the firewall is enabled (press the Start button if the firewall is stopped).
Disable as many of the incoming network services as is practical within your operating environment.

To disable services (for which default options include Personal File Sharing, Windows Sharing, Personal Web Sharing, Remote Login — SSH, FTP Access, Apple Remote Desktop, Remote Apple Events, Printer Sharing, iChat Bonjour, iTunes Music Sharing, iPhoto Bonjour Sharing, Network Time and CVS), simply uncheck the respective checkbox. You can add new services using the supplied New button.

When enabling new incoming services, you must specify a port name - options include ICQ, IRC, Timbuktu, VNC, and Other - TCP port number, UDP port number, and a description.

Under Advanced Options you can choose to block all UDP traffic, enable firewall logging and trigger Stealth Mode. In Stealth Mode, uninvited traffic receives no response from the Mac system, which increases security by preventing the Mac from automatically responding to even simple attempts to learn whether it is online.

FileVault

To ensure Mac data remains secure you can take advantage of Apple’s FileVault feature, which is particularly important on laptops used by mobile users. FileVault automatically encrypts all the data within each user’s Home folder. Without knowing a user’s password, the 128-bit encryption makes it much more difficult for another user or hacker to access another Mac user’s files.
To enable FileVault, follow these steps:
Open System Preferences.
Double-click the Security icon within the Personal section.
Select Turn On FileVault (you’ll be prompted to set a Master Password for the system if one hasn’t already been assigned).

The Mac will present a warning message stating that files will be encrypted. Users must enter the administrator password to proceed. Once the password has been entered the Mac begins to encrypt the user’s Home Folder. This process can take some time depending upon the number and size of files stored within the Home Folder.

When complete, the Mac will present the login Window. You can then log back in to the Mac system and will find the Home Folder contents are now encrypted, as shown by a FileVault icon on the user’s login window.

Secure virtual memory

Virtual memory is the data the Mac stores on the hard drive when operations exceed available RAM.

By enabling Secure Virtual Memory you can prevent hackers from accessing information including passwords etc. from a user’s live swap file. While it sounds unlikely, the increase of unencrypted Wi-Fi hotspots has increased the chances of such a breach.

To enable Secure Virtual Memory, follow these steps:
Open System Preferences.
Double-click the Security icon from within the Personal section.
Press on the padlock to enable changes.
Supply a username and administrator password.
Check the box for Use Secure Virtual Memory.

Other recommendations

Mac users can also take further steps to help secure their system. In addition to disabling automatic login (the checkbox is accessed using the Security applet within System Preferences), you should disable fast user switching (accessed from the Accounts applet in System Preferences). When using new Macs, care should be taken to leave the UNIX-powered machine’s root account off.

To disable the root user account (if enabled), follow these steps:
Open the Mac’s Finder application.
Navigate to the Applications folder.
Open the Utilities folder.
Open NetInfo Manager.
Select Security from the top menu bar and select Authenticate.
Enter a username and administrator password and press OK.
Highlight Security from the menu bar.
Select Disable Root User.

Friday, September 21, 2007

Securing Your Wireless Network

Working from home while using a wireless local area network (WLAN) may lead to theft of sensitive information and hacker or virus infiltration unless proper measures are taken.

As WLANs send information over radio waves, someone with a receiver in your area could be picking up the transmission, therefore gaining access to your computer. They could load viruses on to your computer which could be transferred to other computers on your network.

Up to 75 per cent of WLAN users do not have basic security features installed, while 20 per cent are left completely open with the default configurations.

It is recommended that wireless router/access point setup be always done though a wired client.

You can setup your security by follow these steps:

Change default admin password on wireless router/access point to a secured password.
Change your WEP keys periodically.

Change the channel your router uses to transmit and receive data on a regularly basis.

Use encryption such as WEP and WPA. If equipment does not support at least 128-bit WEP encryption, consider replacing it.

Change the default SSID on your router/access point to a hard to guess name. Setup your computer device to connect to this SSID by default.

Setup router/access point not to broadcast the SSID. The same SSID needs to be setup on the client side manually. This feature may not be available on all equipment.

Block anonymous Internet requests or pings.

On each computer having a wireless network card, network connection properties should be configured to allow connection to Access Point Networks Only.

Computer to Computer (peer to peer) Connection should not be allowed.

Enable MAC filtering. Deny availability to your wireless network for unspecified MAC addresses.

Mac or Physical addresses are available through your computer device network connection setup and they are physically written on network cards.

When adding new wireless cards / computers to the network, their MAC addresses should be registered with the router /access point.

Network router should have firewall features enabled and demilitarized zone (DMZ) feature disabled.

All computers should have a properly configured personal firewall in addition to a hardware firewall. You should also update router/access point firmware when new versions become available.

There is no guarantee of a full protection of your wireless network, but following these suggested tips can definitely lessen your risk of exposing to attackers aiming at insecure networks

Monday, September 03, 2007

Zone Alarm Setup - Video Tutorial

Through search engine results I have noticed that there are many of you looking for more assistance with setting up ZoneAlarm Free Firewall and whether it is safe to use.

I have been using ZoneAlarm for many years, it is simple to download and install and is used by millions worldwide, it is extremely safe.

It will set up the basic permissions for internet access and a balloon will open above the taskbar for other programs asking for permission to access the internet. The balloon also has a 'Remember this decision' tickbox, so once you have granted or denied a program permission it won't ask again.

If you are setting up a wireless network, simply open the main ZoneAlarm program from the taskbar, first go to the Firewall Tab on the left, under the main tab change the setting for Internet Zone to High and Trusted Zone to Medium.

Then click on the Program Control Tab on the left, under the Main tab, set Program Control to Medium. If this is your first or new installation, set it to Low (Learning Mode) for about 4 weeks.

Remember to add folders etc that you wish to share on your machine to the Shared Folders in My Computer.

The easiest way to set all of this up, especially if you are a novice, is to use Network Magic. This will set up ZoneAlarm permissions for sharing, add printers etc to your wireless network.

If you are going to use Network Magic, download and install it on each machine that you are going to connect to a wireless network. You will have the full version for 7 days to set everything up, before it reverts to a limited version.

Thursday, May 10, 2007

Zone Alarm Free Firewall

Get Into the Zone

Malware. An odd sounding word created to lump all
malicious software programs, including viruses, worms,
trojans, spyware, adware, and other malevolent codes into
one cause-your-computer-serious-hurt category.

In 2005, Computer Economics released a report on malware.
The good news was that for the first time since 2002, the
total worldwide financial losses from malware actually
declined to a mere $14.2 billion. The bad news was that the
nature of malware was changing from overt threats to more
focused, covert attacks. This definitely is not great news
for the average computer user just trying to keep up with
the hundreds of malware programs that bombard us daily.

It’s not an easy task keeping malware out of your computer
system. In order to accomplish this, you need a strong
antivirus program. I have covered that with AVG Anti-Virus.

Now you need a good firewall to complement it.
One such program that can deliver the
goods is ZoneAlarm Internet Security Suite 7 from Zone
Labs. Zone Labs is one of the most trusted brands in
Internet Security for good reason. Their product, simply
put, kicks serious malware gluteus maximus.

ZoneAlarm has received more review recommendations that
any other Internet-security software suite because of its
superb firewallprotection. It blocks pop-up
ads, protects against identify theft and provides adequate
spam filters that are flexible. It even beats the market
leader, Norton Internet Security, which is often criticized
for excessive system drag.

The bonus for the average user who cringes at the idea of
setting-up one of these systems is that the interface is
easier to understand and use in comparison to most if its
competitors. If you choose to venture beyond the out-of-the-
box default settings, and install a more elaborate
filtering, know that this will require some additional time
to set up on your part.

Overall, ZoneAlarm is a user-friendly, solution that will
have your computer safe from Internet hazards and cyber
criminals within minutes of installation and it also has
an auto-update feature, very useful.

ZoneAlarm makes it easy. Unlike other personal firewalls,
ZoneAlarm protects automatically from the moment it’s
installed - no programming required. ZoneAlarm barricades
your PC with immediate and complete port blocking. And
then runs in Stealth Mode to make your PC invisible on the
Internet - if you can’t be seen, you can’t be attacked.
ZoneAlarm is a simple to use Firewall without compromising
your security. A getting started tutorial explains controls
and alerts to get you up and running quickly. And, to keep
you confident that you’re always protected, intuitive color-
coded alerts rate security risks - in real time. For basic,
“no frills” firewall protection, ZoneAlarm® is the popular
first step for many home PC users. And it’s still FREE for
individual & non-profit use.

Install it and forget it. ZoneAlarm comes configured to
deliver “out-of the-box” safety and security. As you use
your computer and applications that access the Internet, a
bubble will open on the lower left of your screen and
ZoneAlarm asks you whether you want applications to access
the Internet. It quietly protects you while logging
unauthorized repelled attempts to access your computer.
Security Levels make ZoneAlarm easy to use. In just a few
seconds you can decide how secure you want your system to
be. In contrast to other security solutions, ZoneAlarm does
not require you to learn about ports, protocols and
firewall programming. Security Levels automatically
configure the Firewall and eliminate the risk of improper
use that comes with other products. With ZoneAlarm’s
Security Levels, you get peace of mind, not confusion.
ZoneAlarm makes Internet safety and security hassle-free.

Remember……either back-up your system or create a
Restore Point BEFORE making any changes.

So what are you waiting for? Click the link below, click on
‘I only want basic ZoneAlarm Protection’ and
download and install it.


http://www.zonealarm.com/store/content/company/products/znalm/freeDownload.jsp