pen-test
[Top] [All Lists]

Re: Penetration Testing on Mac OS X

To: michael-hermann@hotmail.com
Subject: Re: Penetration Testing on Mac OS X
From: Carl Jongsma <info@skiifwrald.com>
Date: Sat, 21 Jul 2007 12:17:47 +0930
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <20070720120533.21051.qmail@securityfocus.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <20070720120533.21051.qmail@securityfocus.com>
Resent-date: Fri, 20 Jul 2007 22:48:23 -0600 (MDT)
Resent-from: pen-test-return-1078484649@securityfocus.com
Resent-message-id: <20070721044823.F3D2723796B@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Hi Michael,

OS X comes out of the box in a fairly secure state, though there are a small number of services that are running that could be of interest to the pentester. The recent talk of a new vulnerability targeting mDNSResponder could provide a means to enter a default installation.

What is of interest to pentesters will depend on how the target system has been setup. Apple patches for included third party software are a little bit delayed from when the developers release them, so if the target system allows Kerberos authentication for accessing services (for example), then there are some openings that can be targeted (if the system maintainer hasn't already patched them).

As with all systems, the choice and implementation of weak passwords is a common problem and probably the most significant over time.

An excellent resource for security related issues affecting Apple (besides news sources) is hackintosh.org. There is also the Apple Developer Connection and online source to Darwin. The NSA have released a paper detailing their recommendations on how to secure OS X, which may be a good read if you haven't already read it. Other than that, have a bit of a look around the net, there are a number of resources that can easily be found via Google.


Carl

Sûnnet Beskerming Pty. Ltd.
Adelaide, Australia
http://www.beskerming.com



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>