Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > PC Technology Zone > Apple, Mac OS , and Power PC » MAC's are just as vulnerable as any other...it just takes money
Closed Thread
Old 04-23-2007, 08:06 AM   #1 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,217

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Thumbs down MAC's are just as vulnerable as any other...it just takes money

Say what you all want, because I know its going to be said, but the MAC is not immune to nothing just like every other OS. AS I and other people have said, why should a hacker waste their time when not that many people use it? What benefit will they get? Well if you had a brand new MAC and $10,000, you get a hacked machine in less than 12 hours on a fully patched machine. So maybe this stroy will lay to rest will all those MAC users who think they are immune and that they are better than the rest.................


A New York-based security researcher spent less than 12 hours to identify and exploit a zero-day vulnerability in Apple's Safari browser that allowed him to remotely gain full user rights to the hacked machine. The feat came during the second and final day of the CanSecWest "pwn-2-own" contest in which participants are able to walk away with a fully-patched MacBook Pro if they are first able to hack it.
The exploit means that Dino Dai Zovi is the rightful owner of the 2.3Ghz 15-inch MacBook Pro and a $10,000 prize offered by Tipping Point, which runs the Zero Day Initiative bug bounty program. More importantly, his work effectively throws cold water on tired claims from Apple and its many lackeys that the Mac is all but immune from the kind of security attacks more regularly perpetrated against Windows-based machines.
document.

Dai Zovi, who is not attending the conference, was recruited on Thursday night by Shane Macaulay, a friend and conference attendee. The ease Dai Zovi found in pwning the machine was all the more remarkable, given an update Apple pushed out yesterday patching 25 Mac security holes. Macaulay described Dai Zovi's vulnerability as a client-side javascript error that executed arbitrary code when Safari visited a booby-trapped website.
The pwn-2-own contest got off to a slow start on Thursday. The rules originally mandated an exploit that required no action on the part of the user. The reward for a successful hack was the machine that had been compromised. Conference attendees were underwhelmed, reasoning a Mac exploit that required no end-user interaction could be sold for upwards of $20,000. Things changed significantly on Day 2.
That's when Tipping Point upped the ante with its promise of a $10,000 bounty. Contest organizers also relaxed the rules so exploits could include malicious websites that attacked Safari. At the time of writing, a second MacBook Pro had successfully withstood attacks
__________________
Osiris is offline  
Old 04-23-2007, 09:09 AM   #2 (permalink)
zmatt's Avatar
 
The Bulldog

Join Date: Mar 2006

Location: In an empty Ramen packet

Posts: 4,381

zmatt has a spectacular aura aboutzmatt has a spectacular aura about

Default Re: MAC's are just as vulnerable as any other...it just takes money

I think this just goes to show that no OS is secure, its just safer. Alot of Apple fanboys have stated that MacOS is invulnerable for years. I believe it was 1995 when they had a really nasty Mac virus that did a great deal of damage. But i guess ignorance is bliss. its not that they are invulnerable, its just that windows pcs are 80% of the market. I think all well informed mac users know this, its only the "n00bs" who wouldn't get the flux capacitor joke who cause all the trouble.
__________________


ポップ・タルトが大好きです。
<<<<<<<Rep is always welcome
Ultimate Guitar exercises/ Songs for technique
zmatt is online now  
Old 04-23-2007, 12:06 PM   #3 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,217

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: MAC's are just as vulnerable as any other...it just takes money

Mac Hacked Via Safari Browser

A zero-day vulnerability in Safari allowed two attendees of CanSecWest security conference to walk away with a 17” MacBook and $10,000 prize for exploiting two MacBooks in the Pwn-2-Own contest. Not a bad haul considering it only took the contestants nine hours to come up with a working vulnerability.

Macaulay pwned the Mac by sending it an e-mail that directed a user to a malicious site. Upon visiting the site, the user—a CanSecWest organizer perched on the machine to protect it from physical assault—was infected with malware, without clicking on anything within the site.

__________________
Osiris is offline  
Old 04-23-2007, 05:48 PM   #4 (permalink)
Qiranworms's Avatar
 
Monster Techie

Join Date: Mar 2003

Posts: 1,637

Qiranworms is on a distinguished road

Default Re: MAC's are just as vulnerable as any other...it just takes money

The only true type of secure computer is an offline one. Any computer on the internet can be "pwned".

Now, you'll never hear me claim that Mac OS or Linux can't be hacked, but in a way, this whole thing sort of supports the security of one area of Mac OS X:
Quote:
The rules originally mandated an exploit that required no action on the part of the user. The reward for a successful hack was the machine that had been compromised. Conference attendees were underwhelmed, reasoning a Mac exploit that required no end-user interaction could be sold for upwards of $20,000. Things changed significantly on Day 2.
That's when Tipping Point upped the ante with its promise of a $10,000 bounty. Contest organizers also relaxed the rules so exploits could include malicious websites that attacked Safari.
If I understand that corrently, the original rules mandated a remote hack. Apparently nobody was making any progress, and it was determined to be too difficult. It seems the contestants were allowed to enter a URL on the target computer to visit a malicious website which they create and use to take over the machine.

It's not that visiting a site in Safara that can take over your computer isn't a significant security issue (that's obviously the cause of the Windows spyware epidemic). But it is interesting that nobody was able to remotely hack it (which, I'm sure is still possible to do)

By the way, nice post count of eighteen thousand .
__________________
-->Marc
Error: Keyboard not attached. Please press F1 to continue. <pre>-------OS----------Gentoo Linux-------<br>------Browser-----Mozilla Firefox-----</pre><form action="http://www.srsyo.org/tfsearch.php" method="get"><input type="text" name="search"> <input type="submit" name="submit" value="Search the Forums, thanks to Emily"></form>

|||Official Forum Rules|||<hr>

Last edited by Qiranworms; 04-23-2007 at 05:55 PM.
Qiranworms is offline  
Old 04-23-2007, 07:43 PM   #5 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,217

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: MAC's are just as vulnerable as any other...it just takes money

Y thanks
__________________
Osiris is offline  
Old 04-23-2007, 09:19 PM   #6 (permalink)
zmatt's Avatar
 
The Bulldog

Join Date: Mar 2006

Location: In an empty Ramen packet

Posts: 4,381

zmatt has a spectacular aura aboutzmatt has a spectacular aura about

Default Re: MAC's are just as vulnerable as any other...it just takes money

it might have been to difficult for the allotted time frame. if they really wanted to do it someone will find a way.
__________________


ポップ・タルトが大好きです。
<<<<<<<Rep is always welcome
Ultimate Guitar exercises/ Songs for technique
zmatt is online now  
Old 04-24-2007, 03:23 PM   #7 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,217

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: MAC's are just as vulnerable as any other...it just takes money

Its weird that most of the MAC guys didnt jump in on this, thats a first.....:rolleyes:
__________________
Osiris is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firefox Also Vulnerable To .ANI Exploits Osiris Browser & General Internet Questions 1 04-06-2007 01:14 PM