OS X Auditor
github.com
github.com
Take for example, when we travelling into Australia, and they asked if we had any criminal convictions - I didn't know that a conviction was still an entry requirement for the island!
import Foundation, import calendar, import os, import sys, import shutil
I assuming os, sys, and shutil are part of the system (are they?). What about the other two? Also, which version of Python do I run this under?
Pip is an excellent package management system.
It appears the OSX specific modules are located (on latest Mavericks) in /System/Library/Frameworks/Python.framework/Versions/2.7/Extras/lib/python
So you need to add that directory (for xattr) as well as that directory + PyObjC (for Foundation) to your PYTHONPATH
After getting the error again, I looked at that location - it exists but the mods in question (Foundation and Calendar) are not there. I'm on OSX 10.9.4.
It doesn't really matter enough to waste time on though. Thanks for your help.
I just want to point out that in the docs "self contained" doesn't mean the user has to go hunting for mods.
sudo /usr/bin/python osxcollector.py
There's some neat stuff we've played with (though nothing short of manual analysis is giving really high confidence at this point). Some of the ideas we played with but haven't written about yet: * Feed the output through a parser that finds domains, URLs, and IPs. Feed those into threat feeds and passive DNS APIs. Occasionally this surfaces interesting stuff. * Feed all the hashes to VirusTotal, cymru, or known lists of nasty stuff. Hits are generally nasty. * We've got some known indicators of commodity malware persistence in launch agents. We grep for those cause we know they've hit us before.
One of the recent things we did add to OSXCollector was pulling xattr's from downloads. This allows us to find the source URL - sometimes even the redirect chain - for a download by reading extended attributes of the file. This has been helpful.
Is this a tool for a user who wants to learn more about their own machine, or a non-user who wants to know how a given machine has been used?
More information about the use cases of such a tool would be most helpful.
I've only had 3 major errors but they were significant: 1) I'm on Yosemite so GetAuditedSystemVersion() looks for a PatchVersion variable that simply isn't there. The header reads 10.10 not 10.10.patch as expected. 2) The Safari parsing snafu listed in my previous comment. Opening Safari isn't enough, you have to use the browser quite a bit. The same could likely be said for all browser tests and it would be a good idea to outline precisely what this needs to be. Hint: A new system or install of Yosemite for instance will produce the errors I saw. 3) There's a parsing bug in ParseMailAppAccount() and I just commented out the call completely.
Any number of these could just be Yosemite related but I don't think so. All of the bugs I ran into are variations on index out of bounds due to some hardcoded assumption that mostly works, except in this instance apparently. I'm not the only one with these nagging bugs based on the issues list but mine do seem very specific to Yosemite or how I do(n't) use my system.
But using raw md5 hashes to verify against a blacklist is kind of useless. Especially now.
You should be using smarter file signatures:
http://hooked-on-mnemonics.blogspot.com/2011/01/intro-to-cre...
MD5s are, despite their limitations, the lingua franca of the security industry. nearly everyone who provides a file reputation query service supports them (as opposed to SHA1s or other hashes like ssdeep).
so, i think i get what you're saying, but i don't think it's a relevant suggestion here.
If you are going to get hit with variant #11929 before the online databases obtains a hash of it, this tool is not going to pick it up but it will tell you that you are secure.
It's pretty relevant. Without sending the whole file to the third party, the file reputation service isn't 'outsourced' as you suggest. Sending the MD5 will not do any good if the program makes non-deterministic modifications to its binary.
~/Library/Safari/LastSession.plist Traceback (most recent call last): File "osxauditor.py", line 1702, in <module> Main() File "osxauditor.py", line 1663, in Main ParseBrowsers() File "osxauditor.py", line 808, in ParseBrowsers ParseSafari() File "osxauditor.py", line 745, in ParseSafari ParseSafariProfile(User, UserSafariProfilePath) File "osxauditor.py", line 717, in ParseSafariProfile LastSession = LastSessionPlist["SessionWindows"][0]["TabStates"][0] File "/System/Library/Frameworks/Python.framework/Versions/2.7/Extras/lib/python/PyObjC/objc/_convenience.py", line 451, in __getitem__objectAtIndex_ return container_unwrap(self.objectAtIndex_(idx), RuntimeError) IndexError: NSRangeException - -[__NSCFArray objectAtIndex:]: index (0) beyond bounds (0)
This, KeyError, NoneType exceptions and its Java friend NullPointerException drive me batty. They are so simple to defend against, if the author just took the time.
An option type is really the best way to kill this breed of problem, and thankfully Apple is including one in Swift, though it's still somewhat green.
If you're using the natively included python, pyobjc comes free.
As soon as I saw that mentioned in the documentation, I knew this project was going to have issues.
OS X has shipped with python for quite some time.
In addition, OS X python started including a build of pyobjc since OS X 10.5
You literally can fire up python from the terminal on OS X 10.5 and later and type: import Foundation and it will "just work".
No additional installs required.
[INFO] Users' LoginItems [INFO] 's LoginItems [INFO] /Users//Library/Preferences/com.apple.loginitems.plist [INFO] Cannot parse /Users//Library/Preferences/com.apple.loginitems.plist (Binary or JSON plist may FAIL)
Traceback (most recent call last): File "osxauditor.py", line 1702, in <module> Main() File "osxauditor.py", line 1651, in Main ParseStartup() File "osxauditor.py", line 550, in ParseStartup if "SessionItems" in LoginItemsPlist: TypeError: argument of type 'bool' is not iterable