Calendar Awards Members List FAQ
  #1   [ ]
Old 03-27-2008, 06:41 PM
Hylian Knight
Join Date: Oct 2006
View Posts: 695
Apple receives and an F+ at Sytem Security

http://news.yahoo.com/s/infoworld/20080327...infoworld/96676

Quote:
San Francisco - It may be the quickest $10,000 Charlie Miller ever earned.


He took the first of three laptop computers -- and a $10,000 cash prize -- Thursday after breaking into a MacBook Air at the CanSecWest security conference's PWN 2 OWN hacking contest.

Show organizers offered a Sony Vaio, Fujitsu U810, and the MacBook as prizes, saying that they could be won by anybody at the show who could find a way to hack into each of them and read the contents of a file on the system using a previously undisclosed "0day" attack.

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network, but on Thursday, the rules were relaxed so that attackers could direct contest organizers using the computers to do things like visit Web sites or open e-mail messages.

Miller, best known as one of the researchers who first hacked Apple's iPhone last year, didn't take much time. Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on.

He was the first contestant to attempt an attack on any of the systems.

Miller was quickly given a nondisclosure agreement to sign, and he's not allowed to discuss particulars of his bug until the contest's sponsor, TippingPoint, can notify the vendor.

Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser.

Last year's contest winner, Dino Dai Zovi, exploited a vulnerability in QuickTime to take home the prize.

Dai Zovi, who congratulated Miller after his hack, didn't participate in this year's contest, saying it was time for someone else to win.
__________________

system: Intel Core 2 Duo e6400 @ 3.6GHz; 4*1GB RAM(micron D9GCT) @ 450mhz(DDR2-900) 4-4-3-8; Enermax Liberty 400AWT PSU; nvidia GeForce 8800GTS 640mb (660mhz core; 2120mhz mem)
OBAMA and BIDEN - 'we fight for you, blah blah we fight for you', theres only one man in this election that has fought for you, ONLY ONE and its not Obama.
Reply With Quote
  #2   [ ]
Old 03-27-2008, 06:55 PM
is Everyones friend!
SSBB Code: 4253 3236 8620
Join Date: Mar 2005
Location: hell if I know
View Posts: 5,514
Re: Apple receives and an F+ at Sytem Security

wow, now that's interesting.
__________________
Near a tree by a river there's a hole in the ground
where an old man of iron goes around and around
and his mind is a beacon in the veil of the night
for a strange kind of fashion there's a wrong and a right.
Reply With Quote
Sponsored Links
  #3   [ ]
Old 03-28-2008, 07:09 PM
V99 V99 is offline
Let Your V99 Do The Walking.
Send a message via MSN to V99

Join Date: Aug 2004
Location: in PS making ur sig ok?=\
View Posts: 4,686
Re: Apple receives and an F+ at Sytem Security

Wish I could do that sorta stuff.
__________________
Reply With Quote
  #4   [ ]
Old 03-28-2008, 11:53 PM
[insert clever custom title]
Join Date: Jan 2005
Location: Realm of Darkness.
View Posts: 3,179
Re: Apple receives and an F+ at Sytem Security

I too wish I could so something like this. Mostly to just say I can.
__________________
http://www.zeldauniverse.net/forums/image.php?type=sigpic&userid=10294&dateline=121834  1237
[original looks better, but the site wont allow its awsomeness, so i had to shrink it a bit]
Reply With Quote
Sponsored Links
  #5   [ ]
Old 03-29-2008, 12:47 AM
Who do you love?
Wii Code: 8624-4982-5422-5009 SSBB Code: 1848-1339-0612 Phantom Hourglass Code: 4682-6474-2013
Join Date: Jan 2006
Location: Come Sail Away
View Posts: 5,322
Re: Apple receives and an F+ at Sytem Security

Hah. Take that Apple users.
__________________


Reply With Quote
  #6   [ ]
Old 04-04-2008, 01:22 AM
Hylian Knight
Join Date: Oct 2006
View Posts: 695
Re: Apple receives and an F+ at Sytem Security

Quote:
Originally Posted by http://dvlabs.tippingpoint.com/blog/2008/03/28/pwn-to-own-final-day-and-wrap-up
Vista Laptop was Won!: Congratulations to Shane Macaulay from Security Objectives - he has just won the Fujitsu U810 laptop running Vista Ultimate SP1 after it was installed with the latest version of Adobe Flash. Not only is he the official winner of the Fujitsu laptop, but also $5,000 from us. Shane received some assistance from his friends Derek Callaway (also from Security Objectives) and Alexander Sotirov. If you'll also remember, Shane Macaulay was Dino Dai Zovi's on-site team member at last year's PWN to OWN event in which they ultimately took the top prize.

Quote:
Originally Posted by http://www.allheadlinenews.com/articles/7010483023
Vancouver, British Columbia (AHN)-- The Linux running on a Sony Vaio remained undefeated at the end of a three-way computer hacking challenge Friday at the CanSecWest conference.
Sponsors had wagered three laptops to anyone who could hack into one of the systems and run their own software. A $20,000 cash prize sweetened the deal.
The MacBook Air went first; Independent Security Evaluators' Charlie Miller took the Mac after about two minutes work on Thursday. Miller took home $10,000, courtesy of 3Com's TippingPoint division, in addition to the new laptop.
After two days of work, Shane Macaulay finally cracked the tiny Fujitsu laptop running Vista on Friday, with a little help from his friends.
Macaulay said the flaw he exploited was a cross-platform bug that took advantage of Java to circumvent Vista's security.Macaulay said he chose to work on Vista because he had done contract work for Microsoft in the past and was more familiar with its products.
TippingPoint Manager Terri Forslof said several attendees tried to crack the Linux box, but nobody could pull it off. She noted that some had found bugs in the Linux operating system but many of them didn't want to put the work into developing the exploit code that would be required to win the contest.
so they got the OSX box in 2 minutes, they got the vista box in 2 days and they gave up on the linux box...
__________________

system: Intel Core 2 Duo e6400 @ 3.6GHz; 4*1GB RAM(micron D9GCT) @ 450mhz(DDR2-900) 4-4-3-8; Enermax Liberty 400AWT PSU; nvidia GeForce 8800GTS 640mb (660mhz core; 2120mhz mem)
OBAMA and BIDEN - 'we fight for you, blah blah we fight for you', theres only one man in this election that has fought for you, ONLY ONE and its not Obama.
Reply With Quote
Sponsored Links
  #7   [ ]
Old 04-06-2008, 06:23 PM
Gerudo Thief
Send a message via Yahoo to I <3 Midna
Join Date: Apr 2008
Location: Texas
View Posts: 39
Re: Apple receives and an F+ at Sytem Security

To be fair, none of the systems were hacked on the first day. Only on the second day, when the rules were relaxed a bit, was the Mac hacked.
__________________

Midna, My Princess...
Reply With Quote
  #8   [ ]
Old 04-06-2008, 08:25 PM
"Do they always take years to record?"
Send a message via AIM to Aniday Send a message via Skype™ to Aniday
Join Date: Nov 2003
View Posts: 908
Re: Apple receives and an F+ at Sytem Security

Quote:
Originally Posted by I <3 Midna View Post
To be fair, none of the systems were hacked on the first day. Only on the second day, when the rules were relaxed a bit, was the Mac hacked.
Very true.

And when a Mac is hacked at every one of these conventions, Apple patches the weakness they found pretty quickly. Apple is really good with their patches.
__________________
Reply With Quote
Sponsored Links
  #9   [ ]
Old 04-06-2008, 09:00 PM
Fighting for the truth and the freedom, Gloria!!!!
Join Date: Nov 2005
Location: holding a GH controller
View Posts: 2,159
Re: Apple receives and an F+ at Sytem Security

wow, apple sucks. What else is new?
__________________
C:\Documents and Settings\Family\My Documents\My Pictures\new skateboarding+punkrock.JPG

You know that crazy kid on your bus that laughs at random moments because he's thinking about something funny that happened yesterday? Yeah, that's me
Reply With Quote
  #10   [ ]
Old 04-06-2008, 11:00 PM
Hylian Knight
Join Date: Oct 2006
View Posts: 695
Re: Apple receives and an F+ at Sytem Security

Quote:
Originally Posted by Aniday View Post
Very true.

And when a Mac is hacked at every one of these conventions, Apple patches the weakness they found pretty quickly. Apple is really good with their patches.
as far as 0 day patching, apple is dead last amoung most considerations. M$ beats them, a few other *nix distributions beat them and...

well let google talk
apple 0 day - Google Search

that said it is undeniable that OS X is targeted FAR less than winblows, though not nearly as infrequently as most other *nix based OSes.
Quote:
Originally Posted by I <3 Midna View Post
To be fair, none of the systems were hacked on the first day. Only on the second day, when the rules were relaxed a bit, was the Mac hacked.
to be fair this vulnerability was "Go to this website and download this cool product"
and Apple makes claims that they're rock solid in regards to security for the average idiot. The average idiot could potentially have had f'ed themselves over there.

and the vulnerability affecting vista also affected OS X(and ubuntu) but due to the rules of the contest it could not be used more than once.
__________________

system: Intel Core 2 Duo e6400 @ 3.6GHz; 4*1GB RAM(micron D9GCT) @ 450mhz(DDR2-900) 4-4-3-8; Enermax Liberty 400AWT PSU; nvidia GeForce 8800GTS 640mb (660mhz core; 2120mhz mem)
OBAMA and BIDEN - 'we fight for you, blah blah we fight for you', theres only one man in this election that has fought for you, ONLY ONE and its not Obama.

Last edited by nighthawkx; 04-06-2008 at 11:06 PM.
Reply With Quote
Sponsored Links
  #11   [ ]
Old 04-07-2008, 05:06 PM
"Do they always take years to record?"
Send a message via AIM to Aniday Send a message via Skype™ to Aniday
Join Date: Nov 2003
View Posts: 908
Re: Apple receives and an F+ at Sytem Security

Quote:
Originally Posted by zeldask8r View Post
wow, apple sucks. What else is new?
Wow, you don't know what you're talking about. What else is new?


Quote:
as far as 0 day patching, apple is dead last amoung most considerations. M$ beats them, a few other *nix distributions beat them and...
Maybe I should have said 'most times'. I didn't read about any patching from this latest convention, but I remember that it was patched pretty quickly last time.
__________________
Reply With Quote
  #12   [ ]
Old 04-07-2008, 05:37 PM
Alpha Kenny Body
Send a message via AIM to Samus Aran Send a message via Yahoo to Samus Aran
Join Date: May 2003
Location: Xbox Live Arcade
View Posts: 3,185
Re: Apple receives and an F+ at Sytem Security

Quote:
Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser.
Well, considering the way the dude hacked was with a flaw in Apple's Safari browser. I believe Safari is a pretty recent browser, and I remember recently (looks for article) there was a period of time that paypal insisted that no Safari user were to use their paypal information until a patch was made.

PayPal warns: Steer clear of Apple's Safari browser | InfoWorld | News | 2008-02-28 | By Robert McMillan, IDG News Service

One of many articles by Googling.
__________________
Din's Scavenger Hunt!
August, The Month of Jodd
Reply With Quote
Sponsored Links
  #13   [ ]
Old 04-07-2008, 09:52 PM
Hylian Knight
Join Date: Oct 2006
View Posts: 695
Re: Apple receives and an F+ at Sytem Security

Quote:
Originally Posted by Aniday View Post
Maybe I should have said 'most times'. I didn't read about any patching from this latest convention, but I remember that it was patched pretty quickly last time.
if you read more or less any of the links going off of that google search you'de have found that apple was more or less last when it came to giving timely patches.

by your very own standards that'd put M$ up there as being incredible with Apple being a few steps below. M$ is not incredible by any means.
__________________

system: Intel Core 2 Duo e6400 @ 3.6GHz; 4*1GB RAM(micron D9GCT) @ 450mhz(DDR2-900) 4-4-3-8; Enermax Liberty 400AWT PSU; nvidia GeForce 8800GTS 640mb (660mhz core; 2120mhz mem)
OBAMA and BIDEN - 'we fight for you, blah blah we fight for you', theres only one man in this election that has fought for you, ONLY ONE and its not Obama.
Reply With Quote
  #14   [ ]
Old 04-08-2008, 05:25 PM
Gerudo Thief
Send a message via Yahoo to I <3 Midna
Join Date: Apr 2008
Location: Texas
View Posts: 39
Re: Apple receives and an F+ at Sytem Security

I must admit even though I am an Apple fan, I'm pretty disappointed in Safari. Apple knows it has some serious security issues, and yet they continue to do nothing... Hopefully this changes soon.
__________________

Midna, My Princess...
Reply With Quote
Sponsored Links
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -5. The time now is 11:08 PM.

Contact Us - Zelda Universe - Archive - Privacy Statement - Top