Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Apple pentesting |
|---|---|
| Date: | Wed, 6 Apr 2005 08:21:58 -0500 |
Hey, Thanks guys, It was my mistake...I was talking in front of my mind for a bit. Yesterday was a rough day, sorry for the confusion. Cory, sorry for taking my displeasure of the day out on ya..my bad. I understand that Apple has a very good security image and does inform their users. As far as pen-testing, Nessus is a good start, but false positives are possible and they should be double checked with another tool or manually. You will get both Mac OS X and UNIX type vulns. The other links provided by the other members give some holes to check. I was surprised to not find any attack info on packetstormsecurity as well. http://www.osvdb.org/ - Found several vulns for Mac OS X http://secunia.com/product/96/ - Mac OS X Vulnerabilities - Secunia Also, look at the other apps that are installed. If you do get local access to the box, then installed apps and maybe unpatched local access will help you gain higher access.
-----Original Message----- From: Javier Blanque [mailto:javier@blanque.com.ar] Sent: Tuesday, April 05, 2005 4:40 PM To: Todd Towles; Julian Totzek Cc: <pen-test@securityfocus.com> Subject: Re: Apple pentesting In general Corporations like Apple, Microsoft, Sun, Cisco, etc. do not help attackers to their products, even for good reason (pen testing), they do not give more than is needed to know about a bug. But Apple has been doing its homework about patching and describing these vulns. You should check at: http://www.macsecurity.org/ http://www.securemac.com/ and google for "mac security" Best regards, Javier Blanque El 05/04/2005, a las 14:47, Todd Towles escribió:Nessus does work against Macs, the problem with testingMacs is theynever released vulnerability statements..never. If a hole is found, Apple releases a patch and no ones says anything. If Microsoft did this..everyone would go crazy.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Samba hacking ?, David Cravshaw |
|---|---|
| Next by Date: | Re: Apple pentesting, Mike |
| Previous by Thread: | RE: Apple pentesting, Altheide, Cory B. (IARC) |
| Next by Thread: | Re: Apple pentesting, Javier Blanque |
| Indexes: | [Date] [Thread] [Top] [All Lists] |