Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Firewall configuration, low level policy config, plist, etc...

Hi,


After my recent upgrade from Snow Leopard 10.6.8 to OS X Lion 10.7.4, I noticed that there's an addtional line in the Firewall Configuration list box,

Screen Sharing Allow incoming connections

I've also noticed that the +- button below the list box (with the removal button [-] disabled).


I suspect my machine might have been hacked. I need some guidance on low level config to enable the - button, as well as some command line config of the application firewall. I did some ipfw command line configuration, my guess is that the application firewall sits above the ipfw, is there anyway to use low level config of the application firewall, maybe through plist file ?


User uploaded file

Thanks.


MacUser

MacBook, Mac OS X (10.7.4)

Posted on Jun 25, 2012 7:10 AM

Reply
4 replies

Jun 25, 2012 7:14 AM in response to CommonMacUser

You have not been hacked. Most likely, you have simply turned on Screen Sharing in System Preferences -> Sharing. Screen Sharing is totally useless if the firewall blocks those connections, so the firewall must allow those connections if Screen Sharing is turned on.


Also, note that you most likely don't need the firewall at all. See Do I need a firewall?

Jun 25, 2012 7:41 AM in response to thomas_r.

Thanks, the puzzling thing is, I have never turn on sharing on the System Preference Panel, and I always check to ensure that it is always off, for all sharings under the System Preference -> Sharing. Any idea what could have cause the additional service to be added to firewall ?


By the way, would you know if there are ways, low level configuration to set the lock for Network panel under System Preferences ? Whenever I boot up the Network settings is always unlock, and I need to manually lock it, before I starts anything on MacBook. I think the Network and Sharing lock works in tandem, whenever the Network lock is on, the Sharing lock is on as well, similar traits for unlock. Any idea?


User uploaded file

MacUser

Jun 25, 2012 7:55 AM in response to CommonMacUser

Thanks, the puzzling thing is, I have never turn on sharing on the System Preference Panel, and I always check to ensure that it is always off


Have you checked it recently? I'm not sure what could have caused it to turn on... perhaps you set up an iCloud account and turned on Back to My Mac, which would require Screen Sharing in order to work? I don't know if that might cause Screen Sharing to be enabled the first time it's set up. It's definitely not hacker activity, though, unless you've got a hacker who has physical access to your Mac, while it is logged in, and who turned that on.


By the way, would you know if there are ways, low level configuration to set the lock forNetwork panel under System Preferences ? Whenever I boot up the Network settings is always unlock, and I need to manually lock it


I've seen similar questions, but never any resolution. I don't know whether this is a bug or working as intended. However, every time it has ever come up, as far as I have seen, it has been a concern based on overly-paranoid and unrealistic fears about hackers. If that's what you're worried about, set your mind at ease. There's no way a remote hacker can access those settings, or anything else, locked or not, firewall or not. The only way that hackers can get access to your machine is through malware (easily avoided, see my Mac Malware Guide) or through physical access.


See Apple's Mac OS X Security Configuration Guides for more information on securing your computer.

Jun 27, 2012 3:48 AM in response to thomas_r.

Thanks.


I am currently looking at packer filter, pf.conf, which is recommended for 10.7 onwards. Do you have a good reference material on configuring it manually or through IceFloor (http://www.hanynet.com/icefloor/). Preferably with a layer 2 filter configuration included as well, besides the layer 3 IP filter, ... my concern is on hacks made through Bluetooth / Wi-Fi via layer 2.


MacUser

Firewall configuration, low level policy config, plist, etc...

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.