Higher-level kernel and userland functions in Mac OS X are taken from
FreeBSD.  Even the UNIX manpages are the same from FreeBSD 4.4 as they
are for OS X Jaguar.  As a result, the built-in OS X firewall uses the
FreeBSD "ipfw" firewall software, which works great.  It also, when
Internet Sharing is enabled, uses natd and ISC dhcpd to support internal
clients.  If you are scanning a mac from an internal network acting as a
DHCP server, the new dhcpd remote root exploit will probably be
discovered.

Cheers,
Ben

------
Ben Vaughn
Security Analyst
Blackbird Technologies
703-796-1438 W / 703-582-4551 C
[EMAIL PROTECTED]
------
 

-----Original Message-----
From: Pari Sahai [mailto:[EMAIL PROTECTED]] 
Sent: Friday, January 24, 2003 6:08 PM
To: William Heinbockel
Cc: [EMAIL PROTECTED]
Subject: RE: Mac related question


Hmm... Interesting..

I did a little reading on how Mac OS 9 and previous versions worked and
their architecture. What about OS X? Its Unix based... and I can't seem
to find any instance of ipchains or iptables etc. on it. Wonder how it
does any firewall'ing.

thanks for the feedback.. I'll try these tonight.

Pari Sahai


-----Original Message-----
From: William Heinbockel [mailto:[EMAIL PROTECTED]]
Sent: Friday, January 24, 2003 4:50 PM
To: Pari Sahai
Cc: [EMAIL PROTECTED]
Subject: Re: Mac related question


On Fri, 24 Jan 2003, Pari Sahai wrote:

> Hi:
> 
> What are Nessus' capabilities with regards to scanning Mac machines?
OS 9 and X?
> I'm just getting familiar with Macs and would like to know if I can
tweak Nessus to get better/different results as far as Macs are
concerned. Right now, most Mac machines appear to be extremely secure
and locked down.
> 
> Please advise.
> 
> thanks,
> Pari Sahai.
> 

Give kudos to Apple.  The MacOS's are some of the most secure operating
systems.  Due to this security, nmap and nessus will provide less
information. Also, a majority of the scripts in nessus specifically
target
vulnerabilities in PC-only software (Windows and Linux).

For best performance, I would enable nessus's NIDS evasion as Mac's have
a built-in firewall (if I remember correctly). Most of the
vulnerabilities
you'll find will be on cross-platform software (i.e. Apache, ssh).

Currently there are two OS X specific plugins:
OS X Apache Finder
OS X Apache Finder Content

also, Http Version can detect the Apple Share IP

Hope that helps.
----------------------
William Heinbockel
Information Security Incident Response Assistant
Co-op Risk & Safety Management
Rochester Institute of Technology
E-mail: [EMAIL PROTECTED]


Attachment: smime.p7s
Description: application/pkcs7-signature

Reply via email to