Gone in 2 minutes...

Gone in 2 Minutes:

Mac Gets Hacked First in Contest

A MacBook Air goes down first at the CanSecWest security conference's hacking contest.

http://www.pcworld.com/article/id,143901-pg,1/article.html

I'm curious to find out what Safari hole he used to get in.

#496114

Olawd...

Curious, how can visiting a website up**** your computer anyways? If you dont click anything.... what can happen?

#496149

Simple and easy... especially with Java and Flash.

#496156

Had to have been an embedded Java routine.

We all know how well Safari and Flash get along.

#496166

I knew it. Macs do have troubles too even though Apple claims it doesn't:).

#496172

This may be true but as we don't actually know how the guy done this, we can only speculate. Also the problem with this is, is this the only way at the moment to hack the macbook air or are there other ways. This means that Apple now have a chance to rectify the problem. Don't you have to run the hack on a mac before it can take full control first anyway so it was simple enough for him to get the virus (i presume he already knew the workings of the macbook air as he did it so fast!) and run it.

Please correct me if im wrong.

#496178

It had nothing to do with the fact that it was a Mac Book Air.

It was OS X and a hole in Safari's security that he exploited.

The user didn't have to install anything.

That is why I'm curious to know what the hole was he exploited.

Here were the rules...

Three targets, all patched. All in typical client configurations with typical user configurations. You hack it, you get to keep it...

Each has a file on them and it contains the instructions and how to claim the prize.

Targets (typical road-warrior clients):

* VAIO VGN-TZ37CN running Ubuntu 7.10

* Fujitsu U810 running Vista Ultimate SP1

* MacBook Air running OSX 10.5.2

...Once you extract your claim ticket file from a laptop (note that doing so will involve executing code on the box, simple directory traversal style bugs are inadequate), you get to keep it.

#496200

Hmmm, but they only had to read the file correct? Therefore we don't currently know if the exploit allowed him admin access which I doubt tbh.

#496288

Rjohnstone... you should know better than to post this.

lol. *AS noobs go hysterical*.

Yes, a Mac is a computer, it can be hacked.

*Runs software update, installs security patch from Apple... Ironic?*.

There will be viruses, there will be worms, there will be hackers on the Mac platform, but im not worried. There's always going to be less, and they're less threatening.

#496327

Lolwut.

LEVI JUST SHOOPED TEH WHOOP.

#496329

Rjohnstone... you should know better than to post this.

lol. *AS noobs go hysterical*.

Yes, a Mac is a computer, it can be hacked.

*Runs software update, installs security patch from Apple... Ironic?*.

There will be viruses, there will be worms, there will be hackers on the Mac platform, but im not worried. There's always going to be less, and they're less threatening.

Ya know I love this stuff. :P

I get a kick out of the nooobs that live in denial.

Hmmm, but they only had to read the file correct? Therefore we don't currently know if the exploit allowed him admin access which I doubt tbh.

Did you actually read the rules for the hack?

Obviously not.

You had to EXECUTE CODE on the system to extract the file and THEN view the files content.

It's a legitimate hack.

We all know that ANY system can be hacked.

I'm more curious to see what method they guy used.

He won't release the details until Apple plugs the hole.

#496381

Did you actually read the rules for the hack?

Obviously not.

You had to EXECUTE CODE on the system to extract the file and THEN view the files content.

It's a legitimate hack.

Obviously I didn't lol. We will find out soon enough how it actually worked.

#496382