|
Penetration Testing
Penetration of HP/UX Jun 08 2011 07:30AM Philipp Lachberger (ph_lachi yahoo de) (4 replies) Re: Penetration of HP/UX Jun 13 2011 11:05AM Marco Ivaldi (raptor mediaservice net) (1 replies) Re: Penetration of HP/UX Jun 12 2011 10:23PM Nur Agus (nuragus linux gmail com) (1 replies) Re: Penetration of HP/UX Jun 18 2011 09:58PM Abuse 007 (abuse007 gmail com) (1 replies) Re: Penetration of HP/UX Jun 19 2011 04:59AM michael getachew (michaelhoustong yahoo com) (2 replies) Re: Penetration of HP/UX Jun 19 2011 12:09PM Paul Melson (pmelson gmail com) (2 replies) |
|
Privacy Statement |
I've recently encountered a HP/UX Box in a penetration test. Now I've been searching for materials on HP/UX as it is (over here) not a common system to encounter.
All I've found on public search engines were links to exploits from < 2001. Have I just not searched thoroughly enough or are there hardly any papers?
I would greatly appreciate it if you could give me directions to look at.
Now what kind of makes me wonder:
How do you usually approach a system you haven't encountered before? I have been doing a "usual suspect"-analysis in mapping the OS with your-favourite-port-scanner-here and your-favourite-vulnerability-scanner-here - but beyond that? There are two services listening - Sendmail and ProFTPD, both not obviously wrong configured.
Exploits don't work for HP/UX as they do for "normal" Linuxes/Unixes. This is because HP/UX (as far as I know) mainly works on SPARC CPU's, thus having Big Endian instructions which is different from standard x86 - or am I wrong?
Thank you all for your time!
Best Regards,
-Philipp
------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------
[ reply ]