Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > Locking Down OSX---from Defcon 11

Locking Down OSX---from Defcon 11
Thread Tools
Forum Regular
Join Date: Jan 2003
Status: Offline
Reply With Quote
Aug 14, 2003, 12:06 AM
 
All right, here is a link for the PDF of the speech that Jay Beale gave at DefCon 11 in Vegas (hacker convention for those that didn't know) It was on Locking Down OSX.
Also you can contact Jay Beale (JJB Security) at his website:

http://www.bastille-linux.org/jay/

Speech:
http://opensores.thebunker.net/pub/m...s-03-beale.pdf
Powerbook 12" 640MB 60GB AirportExteme Canon 10D and my good looks 8^D
     
Senior User
Join Date: Jan 2001
Location: Mahwah, NJ USA
Status: Offline
Reply With Quote
Aug 14, 2003, 07:24 AM
 
Originally posted by carnagex2000:
All right, here is a link for the PDF of the speech that Jay Beale gave at DefCon 11 in Vegas (hacker convention for those that didn't know) It was on Locking Down OSX.
Also you can contact Jay Beale (JJB Security) at his website:

http://www.bastille-linux.org/jay/

Speech:
http://opensores.thebunker.net/pub/m...s-03-beale.pdf
Very interesting! Thanks for posting those links.

Jay misses a very important, IMO, step... to change permissions on the netinfo utility files, namely:

Code:
-r-xr-xr-x 1 root wheel 40088 Apr 28 12:49 /usr/bin/nicl -r-xr-xr-x 1 root wheel 23996 Apr 28 12:49 /usr/bin/nidump -r-xr-xr-x 1 root wheel 19928 Apr 28 12:49 /usr/bin/nifind -r-xr-xr-x 1 root wheel 15268 Apr 28 12:49 /usr/bin/nigrep -r-xr-xr-x 1 root wheel 81480 Apr 28 12:49 /usr/bin/niload -r-xr-xr-x 1 root wheel 15284 Apr 28 12:49 /usr/bin/nireport -r-xr-xr-x 1 root wheel 29088 Apr 28 12:49 /usr/bin/niutil
should all be set to mode 0550 or 0500.
This is because a simple:

nidump passwd .

can be done by anyone that gets shell access to the machine either directly or remotely. Then they have a list of all the password hashes... they can copy that list to another host and run John the Ripper (or whatever) at their convenience.
-DU-...etc...
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 08:17 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2