On Fri, 24 Jan 2003, Pari Sahai wrote:

> Hi:
> 
> What are Nessus' capabilities with regards to scanning Mac machines? OS 9 and X?
> I'm just getting familiar with Macs and would like to know if I can tweak Nessus to 
>get better/different results as far as Macs are concerned. Right now, most Mac 
>machines appear to be extremely secure and locked down.
> 
> Please advise.
> 
> thanks,
> Pari Sahai.
> 

Give kudos to Apple.  The MacOS's are some of the most secure operating
systems.  Due to this security, nmap and nessus will provide less
information. Also, a majority of the scripts in nessus specifically target
vulnerabilities in PC-only software (Windows and Linux).

For best performance, I would enable nessus's NIDS evasion as Mac's have
a built-in firewall (if I remember correctly). Most of the vulnerabilities
you'll find will be on cross-platform software (i.e. Apache, ssh).

Currently there are two OS X specific plugins:
OS X Apache Finder
OS X Apache Finder Content

also, Http Version can detect the Apple Share IP

Hope that helps.
----------------------
William Heinbockel
Information Security Incident Response Assistant
Co-op Risk & Safety Management
Rochester Institute of Technology
E-mail: [EMAIL PROTECTED]

Reply via email to