Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 37 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Hardware
OS X as a Pentest Platform
EH-Net
May 25, 2013, 10:39:23 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Hardware
(Moderator:
don
) >
OS X as a Pentest Platform
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: OS X as a Pentest Platform (Read 20222 times)
0 Members and 1 Guest are viewing this topic.
SynJunkie
Jr. Member
Offline
Posts: 71
OS X as a Pentest Platform
«
on:
February 05, 2009, 03:14:20 PM »
Hi guys,
i've recently gotten hold of a macbook and i gotta say that i'm totally lovin it. Now I have it running pretty well with kismet (yes that's kismet), nmap, metasploiot, ettercap etc... and all seems to be working well.
My question is, do any of you pentesters out there use a mac as your main pentest platform? or through experience have you found it to not be as flexible as Linux?
i've done a little testing in the week that i've had it and it seems to be working well but I just wondered if theres a "gotcha" just waiting to happen.
Any thoughts on this would be great.
Cheers
Syn
p.s Has anyone read Johnny Long's book on OS X Hacking and if so was it any good?
Logged
----------------------------------
http://synjunkie.blogspot.com
geekyone
Full Member
Offline
Posts: 180
Re: OS X as a Pentest Platform
«
Reply #1 on:
February 05, 2009, 03:34:56 PM »
Well I don't use Mac but that's mostly because I am poor. I think Ed Skoudis uses a Mac for pentesting though.
Logged
CISSP, CEH, GPEN, GCIH, GCFA
SynJunkie
Jr. Member
Offline
Posts: 71
Re: OS X as a Pentest Platform
«
Reply #2 on:
February 05, 2009, 03:38:42 PM »
After getting the mac I too am poor, and my family are pretty hungry!
Logged
----------------------------------
http://synjunkie.blogspot.com
Malware
Newbie
Offline
Posts: 1
Re: OS X as a Pentest Platform
«
Reply #3 on:
February 05, 2009, 03:47:22 PM »
I use Mac to test, even tho I run linux on it, not its original Mac OS
Logged
SynJunkie
Jr. Member
Offline
Posts: 71
Re: OS X as a Pentest Platform
«
Reply #4 on:
February 05, 2009, 04:20:26 PM »
Malware
Why do you choose linux rather than OS X, is it familiarity or a shortcoming with OS X as a pentest platform?
Logged
----------------------------------
http://synjunkie.blogspot.com
vijay2
Full Member
Offline
Posts: 220
Re: OS X as a Pentest Platform
«
Reply #5 on:
February 06, 2009, 10:44:42 AM »
The people I have seen who uses MAC run VMware Fusion and VMs for pentesting. OS X can be a lil bit difficult to get all your fav tools working.
VJ
Logged
GPEN GCFA GCIH CISSP CISA GSEC OSCP C|EH Security+
SynJunkie
Jr. Member
Offline
Posts: 71
Re: OS X as a Pentest Platform
«
Reply #6 on:
February 12, 2009, 07:18:18 AM »
After setting up macports the apps i use seem to download and work pretty good. But i an see myself having a Linux VM to hand just in case.
Rather than VM Fusion i opted for Parallels though, being a total Mac newb could you tell me if VM Fusion is preffered and why?
Cheers
Syn
Logged
----------------------------------
http://synjunkie.blogspot.com
vijay2
Full Member
Offline
Posts: 220
Re: OS X as a Pentest Platform
«
Reply #7 on:
February 12, 2009, 08:16:08 AM »
Fusion Vs Parallel, umm i might not be the right person to answer that, though I think its matter of prefference.
I think one of the key to success is to be very confortable with the tools you use for pentesting.
I like to go with Fusion because I am comfortable with Vmware and it give me the ability to move around my VMs easily from different Hosts ( PC / MAC)
VJ
Logged
GPEN GCFA GCIH CISSP CISA GSEC OSCP C|EH Security+
Chan
Newbie
Offline
Posts: 32
Re: OS X as a Pentest Platform
«
Reply #8 on:
February 12, 2009, 11:58:48 AM »
I'm currently rocking a MBP. Mac Ports have most things, and I fall back to a Samurai/BT3 installation on VM Fusion if needed.
There's quite a Fusion Vs Parrallels argument on various different sites (also if it's a linux guest OS you're looking at, I've heard good things of VirtualBox) and with the current releases they're about neck and neck. I chose Fusion because of my familiarity with VM products. There are some arguments about better video hardware acceleration, but if it that important go bootcamp and install whatever OS you want.
I've also got the OSX for Hackers book, it's good but it's starting to look a bit dated (there's a chapter on setting up kisMAC which is no longer needed as kismet works fine from ports), but if you're totally new to OSX it's worth a quick read.
I'm still with the "whatever you're most comfortable with" camp, I just happen to be comfortable with overpriced eyecandy
Logged
CCNA, 100m Swimming cert.
Thegmandrive
Newbie
Offline
Posts: 43
Re: OS X as a Pentest Platform
«
Reply #9 on:
February 17, 2009, 08:23:52 PM »
I love my Mac absolutely love it. I have a sweet setup, I have Mac Os X Server, Linux Red Hat, and Windows (I know, I know, it's a sin to have windows on my apple, Dont Ye Judge least ye be Judged... or something like that), All natively installed. I use Fusion for quick switching. For my wireless security testing I use AirCrack. I have a virtual machine I use just for that. I also have AirCrack installed on my Mac Via Macports but the linux version can do much more easier.
I have used both Parallels, and Fusion, I prefer Fusion.
I use Kismac NOT Kismet, to gather information about networks and import the findings into AirCrack, and use that to test my Wireless Security.
With a few easy work arounds, in my personal opinion, Macs are the way to go... If you can afford them of course... Im still paying for mine
Logged
DrivinTin
Jr. Member
Offline
Posts: 51
Net+, Sec+, C|EH, ECSA, CISSP, CASP
Re: OS X as a Pentest Platform
«
Reply #10 on:
March 14, 2009, 04:34:48 AM »
I also have a MacBook that i LOVE for pen testing. The only thing i hated was i would have to reboot to BT to do packet injection, and a few other wireless tools, that is till i found this baby:
hxxps://shop.fon.com/FonShop/shop/US/ShopController?view=product&product=PRD-001
Currently going for $29, but you can find promos and codes all the time to get them for $5 or sometimes free! And the antenna comes right off to put something a bit bigger on it. Then you take it and put this firmware on it:
hxxp://fonerahacks.com/index.php/Tutorials-and-Guides/Flash-Legend-Firmware-to-Fonera.html
And now you have a little guy, that can do all kinds of fun things, running Airserv so that you can actually do the computing on your machine while the packets are grabbed via the Fon. Man it works like a charm, and i even built a batter pack on mine out of 4 AAs so that I don't have to use a power adapter
Zac
Logged
Currently working on:
A UAV Project
Speaking and conferences
Thegmandrive
Newbie
Offline
Posts: 43
Re: OS X as a Pentest Platform
«
Reply #11 on:
April 07, 2009, 04:41:52 PM »
Sweeeeet, I'm going to have to try that.. its cheap enough
Thanks for the info dude.
Logged
decrypt_keeper
Guest
Re: OS X as a Pentest Platform
«
Reply #12 on:
May 12, 2009, 07:15:16 PM »
I'd get a Mac just for their physical design, but I'd probably just end up wiping out OS X and running Linux 100%.
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: OS X as a Pentest Platform
«
Reply #13 on:
May 12, 2009, 09:29:40 PM »
I don't get how people use a system where you still cannot right-click on something and you have to hold option+clover+shift+f8+scratch_your_butt+power to reboot the thing.
Logged
~~~~~~~~~~~~~~
Ketchup
timmedin
Sr. Member
Offline
Posts: 469
Re: OS X as a Pentest Platform
«
Reply #14 on:
May 14, 2009, 07:27:35 AM »
You can right click.
http://lifehacker.com/software/mac-tip/right+click-from-the-trackpad-323322.php
Also, the one button looking mouse also senses your finger and will allow you to right click if you enable the options (I forget where it is and I don't have one in front of me).
Logged
twitter.com/timmedin |
http://blog.securitywhole.com
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.