Re: Apple pentesting

From: Javier Blanque (javier_at_blanque.com.ar)
Date: 04/07/05

  • Next message: Prashant Gawade: "Fingerprinting Firewall"
    Date: Thu, 7 Apr 2005 00:22:36 -0300
    To: "Todd Towles" <toddtowles@brookshires.com>
    
    

    Another aproach is to divide the problem in two parts, the open source
    part of Mac OS X (Darwin and os third part tools added to the system)
    may be trying to exploit the same vulns detected into BSD variants and
    doing a walkthrough over the source code trying to see buffer
    overflows, array limits not checked and memory leaks (which is what are
    doing several security groups lately), and take the propietary part (
    the Apple graphics, the tools) and try to make an attack plan by
    working with the known bugs in Quicktime or other tools, or by
    generating conditions of DOS giving the tools very long parameters or
    unexpected input. Applescript can be a great tool to automate pen
    testing of graphics tools within the MAC OS X environment. With TIGER,
    the new 'Automator' tool may make even easier to make automated pen
    testing on the platform.
    Public automated tools such as nessus will give you a preliminary view
    of the system, but nothing too deep, albeit it is a good sanity check.
    Best regards,
    Javier Blanque

    El 06/04/2005, a las 10:21, Todd Towles escribió:

    > Hey, Thanks guys,
    >
    > It was my mistake...I was talking in front of my mind for a bit.
    > Yesterday was a rough day, sorry for the confusion. Cory, sorry for
    > taking my displeasure of the day out on ya..my bad. I understand that
    > Apple has a very good security image and does inform their users.
    >
    > As far as pen-testing, Nessus is a good start, but false positives are
    > possible and they should be double checked with another tool or
    > manually. You will get both Mac OS X and UNIX type vulns. The other
    > links provided by the other members give some holes to check. I was
    > surprised to not find any attack info on packetstormsecurity as well.
    >
    > http://www.osvdb.org/ - Found several vulns for Mac OS X
    >
    > http://secunia.com/product/96/ - Mac OS X Vulnerabilities - Secunia
    >
    > Also, look at the other apps that are installed. If you do get local
    > access to the box, then installed apps and maybe unpatched local
    > access will help you gain higher access.
    >
    >> -----Original Message-----
    >> From: Javier Blanque [mailto:javier@blanque.com.ar]
    >> Sent: Tuesday, April 05, 2005 4:40 PM
    >> To: Todd Towles; Julian Totzek
    >> Cc: <pen-test@securityfocus.com>
    >> Subject: Re: Apple pentesting
    >>
    >> In general Corporations like Apple, Microsoft, Sun, Cisco,
    >> etc. do not help attackers to their products, even for good
    >> reason (pen testing), they do not give more than is needed to
    >> know about a bug. But Apple has been doing its homework about
    >> patching and describing these vulns. You should check at:
    >> http://www.macsecurity.org/
    >> http://www.securemac.com/
    >> and google for "mac security"
    >> Best regards,
    >> Javier Blanque
    >>
    >> El 05/04/2005, a las 14:47, Todd Towles escribió:
    >>
    >>> Nessus does work against Macs, the problem with testing
    >> Macs is they
    >>> never released vulnerability statements..never. If a hole is found,
    >>> Apple releases a patch and no ones says anything. If Microsoft did
    >>> this..everyone would go crazy.
    >>
    >>
    >


  • Next message: Prashant Gawade: "Fingerprinting Firewall"

    Relevant Pages

    • Re: An Apple for the Enterprise
      ... From the perspective of a steely eyed IT buyer, how is a Mac not like a garden-variety PC? ... The perfect fit for your Enterprise. ... Too bad it still won't solve OS X's fundamental problems in server applications. ... You also have to consider that Apple really isn't geared to provide adequate vendor support for enterprise customers. ...
      (comp.sys.mac.advocacy)
    • An Apple for the Enterprise
      ... mainstream enterprise Quintum VoIP solutions. ... Apple accepts that raising user and administrator productivity is the ... and power to users and server administrators alike. ... With the introduction of the Mac Pro workstation, ...
      (comp.sys.mac.advocacy)
    • Re: Why Snow Leopard will Bomb.
      ... Apple netbook being subsidized down to competitive levels ... anyone could afford a Mac. ... fact that Apple machines cost more and the fact that Apple's customers ... Macs can't run 64-bit apps because no such app exists for them. ...
      (comp.sys.mac.advocacy)
    • Re: Alan Baker fails to check his facts before posting... AGAIN!
      ... mainstream computing environments that Apple provides. ... "Mac OS X isn't completely open, ... "The main way through which Apple invites open source developers to ... jointly founded in April 2002 by Internet Systems ...
      (comp.sys.mac.advocacy)
    • Dvorak Writes Stupidest Computer Article Of All Time
      ... Hey Mac Advocates! ... Shame on them paying Dvorak to write it!! ... Will Apple Adopt Windows? ...
      (comp.sys.mac.advocacy)