Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > OSX and Hackint0sh/OSX86 > OSX Security

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-13-2009, 11:59 AM
MrGamma
Status: Offline
Junior Member
 
Join Date: Jun 2009
Posts: 4
Rep Power: 0
MrGamma is on a distinguished road
Default Remote Desktop Security

Hello,

I have an issue with my OSX machine. I have consistently locked down the remote desktop sharing preferences only to have the lock come undone after casual usage.

Now I realize I could be paranoid, however, I have also run root kits to try and find any issues, and they say that my remote login is enabled.

Where are the logs for this? Is there any way I can know who is remotely logging into my machine?

The computer I am on was supplied by an employer who refused to provide the root password and installer disks with the machine.

I am convinced that there is a security breach.

What can I do.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 06-26-2009, 08:58 AM
digitol
Status: Offline
Junior Member
 
Join Date: Jul 2007
Posts: 9
Rep Power: 0
digitol is on a distinguished road
Default

Quote:
I have also run root kits to try and find any issues
Explain this? ^

Anyhow, Things to try: Edit sudoers file. Disable/enable root user and set your preferences (lock remote desktop) from there. Now a bit more invasive; boot single user, use .SetupDone to make admin user if needed. All logs can be viewed via the console. If the remote-sharing box is unchecked chances are your ok. Install outbound/inbound firwalls or sentry. ipnetsentry is boss. Yea. That should do it.

-Digitol-
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 07-08-2009, 04:12 PM
MrGamma
Status: Offline
Junior Member
 
Join Date: Jun 2009
Posts: 4
Rep Power: 0
MrGamma is on a distinguished road
Default

Quote:
Originally Posted by digitol View Post
Explain this? ^

Anyhow, Things to try: Edit sudoers file. Disable/enable root user and set your preferences (lock remote desktop) from there. Now a bit more invasive; boot single user, use .SetupDone to make admin user if needed. All logs can be viewed via the console. If the remote-sharing box is unchecked chances are your ok. Install outbound/inbound firwalls or sentry. ipnetsentry is boss. Yea. That should do it.

-Digitol-
Sorry...

it should have read... "I have also run root kit detectors. to try and find any issues "

In any event... I have downloaded and installed Fyling Butress. Man I was amazed at how often Google down in California felt the need to ping me...

I will look into ipsentry. I have looked into the sudoers file as well but I couldn;t really make sense of it and will have to look into it again.

What I am really interested in is figuring out where the "Login" or "Remote access log is".

I am systematically trying to find all the possible entry points to the system and I have recently discovered you can even grant remote access with LDAP which I am not even sure if a firewall would block. Then there is UUCP (unix to unix copy) which is another one I am concerned about.

Will a firewall block these and will the sudoers file show if these items are active and running or a threat.

In addition I have looked into TripWire but I am rusty on compiling my own applications. Not sure if it is worth it or if there is something better yet. I have looked into this specific application because some of my permissions are changing on my files and I want to know why. I think Tripwire might be a little over my head at this point.

I also managed to disable root access... but I have another concern with actually finding all the users on the system. Specifically ones which require no password to get access or anoymous users. I can't figure out where the file is which lists them all. I am sorry if this seems stupid. I haven't used a mac for quite a few years now.


Quote:
If the remote-sharing box is unchecked chances are your ok
To be specific... My Remote Sharing preferences where casually unlocking nearly every day. When I installed Flying Butress. The lock came off once and it has never come off again. To be very speculative and paranoid. That sounds to me like flying butress may have prevented some sort of monitoring system from watching my machine and then perhaps, the "remote admin" came back into machine and changed something again... Since after the firewall installation I found a problem while running a root kit detector. It said the UUCP user on my machine had changed. I don't know how to monitor UUCP. In addition, the flying butress is currently blocking alot of stealth connections. These are harmless correct?

Last edited by MrGamma; 07-08-2009 at 04:27 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #4 (permalink)  
Old 07-09-2009, 09:09 AM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 368
Rep Power: 23
JayBird will become famous soon enough
Default

or you could just go to system pref's then on the first tab 'General' put a tick in the box - 'require password to unlock each system preferences pane'.
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 07-10-2009, 01:18 AM
MrGamma
Status: Offline
Junior Member
 
Join Date: Jun 2009
Posts: 4
Rep Power: 0
MrGamma is on a distinguished road
Default

Quote:
Originally Posted by JayBird View Post
or you could just go to system pref's then on the first tab 'General' put a tick in the box - 'require password to unlock each system preferences pane'.
That's what I did and it still came unlocked. That's why I am worried about where the users file is and how I can monitor exactly who is remotely connecting. I am worried that perhaps a UUCP or LDAP connection or something which would slip by the firewall could be in use...

Or even maybe I just have an account somewhere which requires no password.

Remember this is an employer who handed me this machine without the disks and they had all the time in the world to set it up however they wanted. I have changed my password... I am just worried there are other accounts, programs or even some strange anonymous user with some sort of stealth connection has access...

I am asking these questions because I don't know. And the more I look... BSD seems to have a lot of possibilities... and Mac OS seems to have changed things around enough that there is so little documentation floating around to make deciphering it very hard...

Last edited by MrGamma; 07-10-2009 at 01:23 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 07-11-2009, 07:06 PM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 368
Rep Power: 23
JayBird will become famous soon enough
Default

http://images.apple.com/support/secu...fig_2nd_Ed.pdf
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #7 (permalink)  
Old 07-11-2009, 07:07 PM
JayBird's Avatar
JayBird
Status: Offline
Senior Member
 
Join Date: Oct 2008
Posts: 368
Rep Power: 23
JayBird will become famous soon enough
Default

Operating Systems - NSA/CSS - Props to Sam
__________________
I Do Not Condone Piracy, If You Like It BUY IT! - It's Ok To Test But Not Steal - MacBook Pro Owner

iPhone Owner 3G
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 07-13-2009, 11:15 PM
MrGamma
Status: Offline
Junior Member
 
Join Date: Jun 2009
Posts: 4
Rep Power: 0
MrGamma is on a distinguished road
Default

That's looks like what I was having trouble finding... Thanks Guys...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
MacNN: Remote Desktop, Server Admin Tools fixes, more hackint0sh Latest Headlines 0 09-17-2008 03:30 AM
MacNN: Microsoft ships Remote Desktop Connection Client v2.0 hackint0sh Latest Headlines 0 07-02-2008 08:20 AM
MacRumors: Microsoft Releases Remote Desktop Connection Client 2 hackint0sh Latest Headlines 0 07-02-2008 03:50 AM
[REQ] windows remote desktop app Gregsen Free Toolchain Software 2 01-15-2008 02:57 PM
ipod touch+VNC= remote desktop to a windows machine? hyoo82 General 2 11-16-2007 04:39 PM



All times are GMT +2. The time now is 07:29 PM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105