|
|
|
OS X Firewall: Give me transparency or give me... a GUI! |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
OS X Firewall: Give me transparency or give me... a GUI! Par Security SauceLe [2009-01-15] à 22:24:04
Présentation : I had an "entertaining" time getting a handle on OS X's firewall last night on my newest Mac Mini. For those of you unfamiliar with the OS X firewall's inner workings, I suggest you take a look at Jay Beale's DefCon presentation. Here's the basic problem with OS X's firewall and it's configuration: It's not transparent to the user. The OS X firewall configuration interface is highly simplified and accessible but omits critical information about ports that it is leaving open regardless of the state indicated by the configuration GUI. For security conscious users like myself, it is unacceptable for the system to lead me to believe that I've blocked all ports but SSH (for example) and "stealthed" the machine when in fact it has left several other service ports wide open for access by anyone on the network and not stealthed the machine in any credible manner. Apple needs to take this seriously. I can understand hiding complexity in UNIX systems from the user in a consumer OS , but when I ask for Advanced configuration what I'd like to see is an honest summary of which ports are not being blocked on my network interfaces. It doesn't seem like too much to ask but for some reason you just can't get that information from your Mac unless you're willing to go out to the command line and punch in some ipfw commands yourself. As has been illustrated time after time, the cost of doing security right the first time is far less than fixing it later. Once I achieved frustration with the transparency of Apple's firewall preferences panel, I figured that someone else must have had this problem in the past and solved it with a good and completely transparent firewall configuration GUI for OS X. I checked out Flying Buttress and it was pretty good, but it seemed to have issues with hanging from time to time and it was difficult to get the actual firewall status and configuration after a policy apply. It had further problems once I accidentally tried to explore Apple's FirewallTool and it reestablished the default configuration in addition to Flying Butress's, the worst of both worlds. I then tried out Firewall Builder but there was all sorts of flakiness with it in terms of the GUI display as well as its intuitiveness. Then it crashed on me, and since they wanted money for that version I decided to pass on working with it any further. I checked out a couple other interfaces but they all had issues with transparency, utility and functionality. Flying Buttress was the closest, but it was still hiding configuration options from me while not displaying all of the ports it was leaving open. It does have an "expert" display mode that shows the exact configuration used, but it seems to be impossible to reflect any changes made to the expert mode in the regular GUI mode. This is the exactly the sort of thing that gets people to start Open Source Projects and normally I'd use this as the perfect lead-in to starting to do some work with Cocoa (which I am deeply interested in) but I have another project on the front burner right now (more about that later). This is exactly the kind of thing that Apple excels at, making complexity accessible to users. If they can make real-time video editing, movie creation, music creation and the like as easy and accessible to users as they have, they certainly can take on a task like configuration of the firewall for both casual and advanced users in a way that will be useful for both the casual and pro crowds. For the record, at the end of the day I located this post (which was derived from this article) and used the info to create my final firewall rule set manually with vi and some scripting. Not exactly Apple-simple, but it got the job done. So, anyone want to make a real firewall GUI for OS X? Is this anyone else's Dream App? Technorati Tags: OS X, Firewalls, Security
Les mots clés de la revue de presse pour cet article : firewall Les videos sur SecuObs pour les mots clés : firewall Les mots clés pour les articles publiés sur SecuObs : firewall Les éléments de la revue Twitter pour les mots clés : firewall
Les derniers articles du site "Security Sauce" :
- IP Blacklisting Version 2 for Snort 2.8.4.1 available - IP Blacklisting for Snort 2.8.4.1 available - RSA 2009 - Snort 3.0 Beta 3 Released - Saving the data on an iPhone in Recovery Mode - MacBook Pro and the slow-motion beachball of death crash - So, here we are... - Missing BlackHat - CtrlAltItsNeat! - Off to London
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|