Thanks for the response. > Sorry for the delay in my reply. I don't know if there's a "clean" way > to identify a non-patched AFP server - I've seen an exploit, but it is > too intrusive to be used in Nessus... > > The good news is that when Apple releases 10.3.4 it will be easy to > add a check based on the OS version number, even though that's less > clean... Are you referring to Apple Incrementing the version number within AFP? Such that it would read "AFP Versions: AFP3.2" rather than "3.1" or is the TCP/IP stack changing enough to be able to identify a 10.3.4 box with active fingerprinting?
Thanks, JC > > > -- Renaud _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
