Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

Preferred OSX Security/Server Lists

 

 

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


thor at hammerofgod

Jul 9, 2012, 10:45 AM

Post #1 of 7 (213 views)
Permalink
Preferred OSX Security/Server Lists

Greets all.

I was hoping to get some opinions on your "favorite" OSX security/server admin sites/lists. I'm converting the HoG internal and production networks over to OSX and OSX Server and would like some "pre-vetting" suggestions for a decent source of information.

Thanks much.

t


0x90 at phocean

Jul 11, 2012, 12:32 PM

Post #2 of 7 (169 views)
Permalink
Re: Preferred OSX Security/Server Lists [In reply to]

Hi,

I do not know any specific stuff yet, though I have been a recent switcher myself.
I had a quick look but it seems that there are not many resources.
So this is going to be an interesting topic.
Just curious: what are the motives for your switch?

Regards,
--- phocean


Le 9 juil. 2012 à 19:45, Thor (Hammer of God) a écrit :

> Greets all.
>
> I was hoping to get some opinions on your "favorite" OSX security/server admin sites/lists. I'm converting the HoG internal and production networks over to OSX and OSX Server and would like some "pre-vetting" suggestions for a decent source of information.
>
> Thanks much.
>
> t
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
Attachments: signature.asc (0.82 KB)


thor at hammerofgod

Jul 11, 2012, 3:00 PM

Post #3 of 7 (167 views)
Permalink
Re: Preferred OSX Security/Server Lists [In reply to]

Same here… I couldn't find anything that really served my needs. It was hard enough to find the right resource to enable a single user to have multiple email addresses for OSX Lion Server Mail – but I figured that out. Maybe we should start one then? I'm moving the HoG website over as well and I'll be including the Wiki stuff, so I'll have the resources to host something like that.

Regarding the actual reason for moving, there are several, but I'll focus on the most important. I'm a big music and media person, and I like to be able to have my music accessible when and where I want it and have options for redirection of equipment. Setting up Windows Media Center was a pain, and it was slow and very limited in features. And there were issues with "Zune" files working or not working, the general requirement for network configuration, and just a lot of complexity. With OSX I just run it, tell iTunes to share my library, and then I can play whatever I want on my iPad or iPhone. Then I just plugged in the AppleTV to my main entertainment system, and then I could remotely play stuff on my iPhone directly to that stereo. I have speakers run outside, so I can literally be in the backyard and tell my iPhone "Play Robert Plant" and it plays from my phone to the Apple TV and out the speakers. SUPER smooth.

So after that I starting digging in to OSX more and have liked it more and more as I go. Having the same features with such a dramatically less complex installation is really a huge benefit to me. iCal, iChat, Mail, and iContact servers and amazingly simple and do exactly what I need – compared to Exchange and PS, and all that stuff, well… :)

Of course my main concern (and reason for posting) is that I want to make sure I do my due diligence and learn what I need to learn in order to properly secure the services I put out on the Internet. For instance, I can set up IIS to be tremendously secure in my sleep as I've done it for years. However, I don't know what to do with Apache. I just don't know it. So I want to find out about principal accounts, service contexts, virtual directories, server-side applications, etc etc. HoG has never been hacked (to my knowledge) but I'm totally expecting to be pwned now that I'm basically doing a 180 in my production environment.

I think starting an actual Mac security list would be a good idea. Hell, maybe I can sell enough "Thor's Microsoft Security Bible" copies to help buy more Mac equipment :) LOL.

t

From: phocean <0x90 [at] phocean<mailto:0x90 [at] phocean>>
Date: Wednesday, July 11, 2012 12:32 PM
To: Timothy Mullen <thor [at] hammerofgod<mailto:thor [at] hammerofgod>>
Cc: "full-disclosure [at] lists<mailto:full-disclosure [at] lists>" <full-disclosure [at] lists<mailto:full-disclosure [at] lists>>
Subject: Re: [Full-disclosure] Preferred OSX Security/Server Lists

Hi,

I do not know any specific stuff yet, though I have been a recent switcher myself.
I had a quick look but it seems that there are not many resources.
So this is going to be an interesting topic.
Just curious: what are the motives for your switch?

Regards,
--- phocean


Le 9 juil. 2012 à 19:45, Thor (Hammer of God) a écrit :

Greets all.

I was hoping to get some opinions on your "favorite" OSX security/server admin sites/lists. I'm converting the HoG internal and production networks over to OSX and OSX Server and would like some "pre-vetting" suggestions for a decent source of information.

Thanks much.

t
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


noloader at gmail

Jul 11, 2012, 3:38 PM

Post #4 of 7 (169 views)
Permalink
Re: Preferred OSX Security/Server Lists [In reply to]

On Wed, Jul 11, 2012 at 6:00 PM, Thor (Hammer of God)
<thor [at] hammerofgod> wrote:
> Same here… I couldn't find anything that really served my needs. It was
> hard enough to find the right resource to enable a single user to have
> multiple email addresses for OSX Lion Server Mail – but I figured that out.
> Maybe we should start one then? I'm moving the HoG website over as well and
> I'll be including the Wiki stuff, so I'll have the resources to host
> something like that.
> [SNIP]

https://www.google.com/#hl=en&sclient=psy-ab&q=osx+server+security+configuration+guide

The first two hits are the NSA and Apple.

Jeff

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


thor at hammerofgod

Jul 11, 2012, 5:44 PM

Post #5 of 7 (170 views)
Permalink
Re: Preferred OSX Security/Server Lists [In reply to]

Yep, saw those. There's some good material there, but it is dated and I
was hoping for more of a "discussion" environment like we have on the list
(when we actually discuss security here). I'm just a bit surprised as
most of the "hacks" all run Mac. But I guess they don't run it in a
production environment and serve up public services.

That said, look at the Focus-MS listŠ With constant barrage of MSFT
configuration questions and security requirements, there's not been a
single post there in years it seemsŠ


t

On 7/11/12 3:38 PM, "Jeffrey Walton" <noloader [at] gmail> wrote:

>On Wed, Jul 11, 2012 at 6:00 PM, Thor (Hammer of God)
><thor [at] hammerofgod> wrote:
>> Same hereŠ I couldn't find anything that really served my needs. It was
>> hard enough to find the right resource to enable a single user to have
>> multiple email addresses for OSX Lion Server Mail ­ but I figured that
>>out.
>> Maybe we should start one then? I'm moving the HoG website over as
>>well and
>> I'll be including the Wiki stuff, so I'll have the resources to host
>> something like that.
>> [SNIP]
>
>https://www.google.com/#hl=en&sclient=psy-ab&q=osx+server+security+configu
>ration+guide
>
>The first two hits are the NSA and Apple.
>
>Jeff

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


noloader at gmail

Jul 11, 2012, 5:53 PM

Post #6 of 7 (169 views)
Permalink
Re: Preferred OSX Security/Server Lists [In reply to]

Hi Thor,

My bad. I was not sure if you wanted a check list or mailing list.

https://lists.apple.com/mailman/listinfo. The server stuff looks like
its covered under
https://lists.apple.com/mailman/listinfo/macos-x-server. There's a low
volume security list at
https://lists.apple.com/mailman/listinfo/apple-cdsa.

Jeff

On Wed, Jul 11, 2012 at 8:44 PM, Thor (Hammer of God)
<thor [at] hammerofgod> wrote:
> Yep, saw those. There's some good material there, but it is dated and I
> was hoping for more of a "discussion" environment like we have on the list
> (when we actually discuss security here). I'm just a bit surprised as
> most of the "hacks" all run Mac. But I guess they don't run it in a
> production environment and serve up public services.
>
> That said, look at the Focus-MS listÅ  With constant barrage of MSFT
> configuration questions and security requirements, there's not been a
> single post there in years it seemsÅ 
>
> On 7/11/12 3:38 PM, "Jeffrey Walton" <noloader [at] gmail> wrote:
>
>>On Wed, Jul 11, 2012 at 6:00 PM, Thor (Hammer of God)
>><thor [at] hammerofgod> wrote:
>>> Same hereÅ  I couldn't find anything that really served my needs. It was
>>> hard enough to find the right resource to enable a single user to have
>>> multiple email addresses for OSX Lion Server Mail ­ but I figured that
>>>out.
>>> Maybe we should start one then? I'm moving the HoG website over as
>>>well and
>>> I'll be including the Wiki stuff, so I'll have the resources to host
>>> something like that.
>>> [SNIP]
>>
>>https://www.google.com/#hl=en&sclient=psy-ab&q=osx+server+security+configu
>>ration+guide
>>
>>The first two hits are the NSA and Apple.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


thor at hammerofgod

Jul 11, 2012, 6:00 PM

Post #7 of 7 (167 views)
Permalink
Re: Preferred OSX Security/Server Lists [In reply to]

Hey, no worries at all… I appreciate the response! The more infoz the
better! I'll check these out too…

On 7/11/12 5:53 PM, "Jeffrey Walton" <noloader [at] gmail> wrote:

>Hi Thor,
>
>My bad. I was not sure if you wanted a check list or mailing list.
>
>https://lists.apple.com/mailman/listinfo. The server stuff looks like
>its covered under
>https://lists.apple.com/mailman/listinfo/macos-x-server. There's a low
>volume security list at
>https://lists.apple.com/mailman/listinfo/apple-cdsa.
>
>Jeff
>
>On Wed, Jul 11, 2012 at 8:44 PM, Thor (Hammer of God)
><thor [at] hammerofgod> wrote:
>> Yep, saw those. There's some good material there, but it is dated and I
>> was hoping for more of a "discussion" environment like we have on the
>>list
>> (when we actually discuss security here). I'm just a bit surprised as
>> most of the "hacks" all run Mac. But I guess they don't run it in a
>> production environment and serve up public services.
>>
>> That said, look at the Focus-MS listÅ  With constant barrage of MSFT
>> configuration questions and security requirements, there's not been a
>> single post there in years it seemsÅ 
>>
>> On 7/11/12 3:38 PM, "Jeffrey Walton" <noloader [at] gmail> wrote:
>>
>>>On Wed, Jul 11, 2012 at 6:00 PM, Thor (Hammer of God)
>>><thor [at] hammerofgod> wrote:
>>>> Same hereÅ  I couldn't find anything that really served my needs. It
>>>>was
>>>> hard enough to find the right resource to enable a single user to have
>>>> multiple email addresses for OSX Lion Server Mail ­ but I figured that
>>>>out.
>>>> Maybe we should start one then? I'm moving the HoG website over as
>>>>well and
>>>> I'll be including the Wiki stuff, so I'll have the resources to host
>>>> something like that.
>>>> [SNIP]
>>>
>>>https://www.google.com/#hl=en&sclient=psy-ab&q=osx+server+security+confi
>>>gu
>>>ration+guide
>>>
>>>The first two hits are the NSA and Apple.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.