Showing posts with label Mac Security. Show all posts
Showing posts with label Mac Security. Show all posts

Friday, November 09, 2007

Browser Exploit Prevention

NoScript for Firefox.

Experts agree that Firefox is safer with the NoScript Firefox extension, which provides extra protection for Firefox, and other mozilla-based browsers.

This is a free open source addon makes Firefox which allows JavaScript and Java execution only for trusted domains of your choice and made even safer through preemptive whitelist-based JavaScript/Java/Plugins blocking.

You have the option to block Flash and other potentially harmful plugins.

Click for larger image

It offers many useful features which you have complete control over.

Browser based anti-XSS - Cross-Site Scripting vulnerabilities allow someone to insert their own malicious code from one site into another, which can lead to identity theft etc.

You have the ability to enable or disable Java/Javascript for Trusted Sitesusing either the NoScript status bar or the contextual menu.

There is an installation video that is well worth watching before considering deploying this tool.

Watch the video here.

Download NoScript here

http://noscript.net/faq covers general FAQ, installing, uninstalling, migrating, updates, troubleshooting, XSS, tips and tricks

LinkScanner Lite

When you start to install this utility, you have the option to use the full Pro version for 15 days, after this it will revert to the Lite version.

Also on the installation window there is the option to participate in the Community Intelligence Network. This is optional and is explained on the install window.

The installation adds a BHO (Browser Helper Object)which is necessary for the program to function.

After installation it is necessary to reboot your computer.


The Pro version gives you Websearch results inspection, On-demand url scanning, Always-on exploit blocking, Internet connectivity monitor and Real-time site risk analysis. The Lite version will give you Websearch results inspection and On-demand url scanning.

This program analyzes sites in real time to detect a wide range of online threats including malicious content, phishing, social engineering and targeted software exploits.

You have the Link Scanner Console which resides in the Taskbar, simply right click the icon and you can open the Console.

Enter a URL, checkmark the ‘Automatically advance to the page if it is Safe’ and scan.

Exploit Prevention Labs say that LinkScanner Lite and LinkScanner Pro scan individual pages in real time, knowing that malicious hackers can hop from site to site, temporarily infecting them.
LinkScanner integrates with Google, Yahoo and MSN to check the search results and can warn you of exploits, hacked pages, malicious sites and phishing/fraud scams.

Enter a search term into a search engine and the results displayed will have symbols beside them.

Hold your cursor over the icons and a description will appear, click the icon and you will be taken to a definition page giving further information about the site and the reason for the rating.

The simplest method to check any link is to right-click the link and select Quickscan with LinkScanner. You will get a full report as to whether the site is safe or not.

NoScript and LinkScanner also bolster your Firewall defences.

Download LinkScanner Lite here

Comprehensive User Guide here

Tuesday, October 16, 2007

Securing Mac PC’s

Macs are much more secure than Windows systems. In addition to having most unnecessary services disabled by default, Macs face very little threat from viruses, spyware, adware, and other malware, but this does not mean that Macs are immune from security threats though.

Apple computers need good security practice to remain secure just as Windows systems do. By configuring user accounts, assigning proper permissions, complex passwords, regularly updating Mac OS X and installed applications, ensuring the Mac’s built-in firewall is properly configured, and by following other steps reviewed here, users can help ensure they have taken steps to protect their systems from unwanted breaches.

Antivirus and antispyware options

Spyware on the Mac platform, however, is basically not an issue. Unlike the Windows OS, which is sometimes crippled by the never-ending onslaught, Macs are relatively immune from the threat. However, there are very few utilities exist to protect Macs from unwanted software and malware. Such offerings include SmithMicro Software’s Internet Cleanup and SecureMac.com Inc.’s MacScan.

Security efforts on the Mac, therefore, quickly turn to focusing on user account security. Once user accounts have been implemented and separate, complex passwords assigned to both user and local administrator accounts, users can take several steps to help ensure Mac OS X systems remain secure.

Software update

Keeping systems current with the latest security updates and patches is a necessity. The Mac’s Software Update feature is the equivalent of Windows Update. By configuring Software Update to automatically download and apply security updates, users can keep systems current and help protect Mac OS X from unwanted breaches.

To configure Software Update, users should follow these steps on Mac OS X version 10.4 systems:Open System Preferences. Double-click Software Update within the System section. Press the Update Software tab. Select the Check For Updates box.

Specify how often the Mac system should check for updates (options include Daily, Weekly, and Monthly). Weekly updates should be sufficient for most users.

If you want to review downloads before they install you should check the Download Important Updates In The Background box. When the box is checked, the Mac will notify you that important software updates have been downloaded and are awaiting installation.

If you want to review which software updates have been loaded you can check the Software Update’s Installed Updates tab. A window will appear listing installed updates, for which version number information also appears.

You can check for new updates at any time by pressing the Software Update’s Check Now button.

Application updates

In addition to ensuring Mac OS X remains up-to-date with the latest security patches and fixes, you should ensure that all installed applications remain current. For example, a number of Mac programs connect the Internet and other resources. Those programs must remain secure with the latest security patches. By regularly updating Web browsers, office applications, utilities, antivirus programs, and other software, users can help prevent common causes of system breaches.

IP Firewall

It is essential to familiarize yourself with the Mac OS X IP Firewall, known as IPFW. The built-in firewall offers a powerful tool for protecting against unwanted network access.

To enable Mac’s IP Firewall and reduce network threats, follow these steps:
Open System Preferences.
Double-click the Sharing option within the Internet & Network section.
Select the Firewall tab.
Press the padlock icon and enter an account username administrator password and press OK.
Ensure the firewall is enabled (press the Start button if the firewall is stopped).
Disable as many of the incoming network services as is practical within your operating environment.

To disable services (for which default options include Personal File Sharing, Windows Sharing, Personal Web Sharing, Remote Login — SSH, FTP Access, Apple Remote Desktop, Remote Apple Events, Printer Sharing, iChat Bonjour, iTunes Music Sharing, iPhoto Bonjour Sharing, Network Time and CVS), simply uncheck the respective checkbox. You can add new services using the supplied New button.

When enabling new incoming services, you must specify a port name - options include ICQ, IRC, Timbuktu, VNC, and Other - TCP port number, UDP port number, and a description.

Under Advanced Options you can choose to block all UDP traffic, enable firewall logging and trigger Stealth Mode. In Stealth Mode, uninvited traffic receives no response from the Mac system, which increases security by preventing the Mac from automatically responding to even simple attempts to learn whether it is online.

FileVault

To ensure Mac data remains secure you can take advantage of Apple’s FileVault feature, which is particularly important on laptops used by mobile users. FileVault automatically encrypts all the data within each user’s Home folder. Without knowing a user’s password, the 128-bit encryption makes it much more difficult for another user or hacker to access another Mac user’s files.
To enable FileVault, follow these steps:
Open System Preferences.
Double-click the Security icon within the Personal section.
Select Turn On FileVault (you’ll be prompted to set a Master Password for the system if one hasn’t already been assigned).

The Mac will present a warning message stating that files will be encrypted. Users must enter the administrator password to proceed. Once the password has been entered the Mac begins to encrypt the user’s Home Folder. This process can take some time depending upon the number and size of files stored within the Home Folder.

When complete, the Mac will present the login Window. You can then log back in to the Mac system and will find the Home Folder contents are now encrypted, as shown by a FileVault icon on the user’s login window.

Secure virtual memory

Virtual memory is the data the Mac stores on the hard drive when operations exceed available RAM.

By enabling Secure Virtual Memory you can prevent hackers from accessing information including passwords etc. from a user’s live swap file. While it sounds unlikely, the increase of unencrypted Wi-Fi hotspots has increased the chances of such a breach.

To enable Secure Virtual Memory, follow these steps:
Open System Preferences.
Double-click the Security icon from within the Personal section.
Press on the padlock to enable changes.
Supply a username and administrator password.
Check the box for Use Secure Virtual Memory.

Other recommendations

Mac users can also take further steps to help secure their system. In addition to disabling automatic login (the checkbox is accessed using the Security applet within System Preferences), you should disable fast user switching (accessed from the Accounts applet in System Preferences). When using new Macs, care should be taken to leave the UNIX-powered machine’s root account off.

To disable the root user account (if enabled), follow these steps:
Open the Mac’s Finder application.
Navigate to the Applications folder.
Open the Utilities folder.
Open NetInfo Manager.
Select Security from the top menu bar and select Authenticate.
Enter a username and administrator password and press OK.
Highlight Security from the menu bar.
Select Disable Root User.