Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




pen-test logo Penetration Testing mailing list archives

Re: Apple pentesting
From: Mike <secfocus () mikesbytes com>
Date: Wed, 06 Apr 2005 11:56:20 -0700

At 4/5/2005 08:51 AM, Julian Totzek wrote:


I have to do a pentest in a environment where mac's should be located. Never
tested MacOS somebody have some tips for me? They normally should only be
clients no servers.
Do you know of special tools to test them, or is it possible to test them
with progs like nesuss?

Metasploit (http://www.metasploit.com) has exploits for three different MacOS vulnerabilities:

AppleFileServer LoginExt PathName Overflow
        http://www.metasploit.com/projects/Framework/exploits.html#afp_loginext
Arkeia Backup Client Type 77 Overflow (Mac OS X)
        http://www.metasploit.com/projects/Framework/exploits.html#arkeia_type77_macos
Samba trans2open Overflow (Mac OS X)
        http://www.metasploit.com/projects/Framework/exploits.html#samba_trans2open_osx

Any pen testing tools you use for BSD systems should work fairly well against MacOS X machines.



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]