Macbook Hacked in 2 Minutes!


Recommended Posts

Macbook (MacbookAir) got hacked withing 2 minutes!! :-)

Source: From Macworld

(http://www.macworld.com/article/132733/2008/03/hack.html)

Where: Security Conference open (http://cansecwest.com/post/2008-03-20.21:33:00.CanSecWest_PWN2OWN_2008)

:-D

Prize he won: 3 laptops (Sony Vaio, Fujitsu U810 and the MacBook ) + US$10,000

Edited by guruparan
Link to comment
https://www.neowin.net/forum/topic/628158-macbook-hacked-in-2-minutes/
Share on other sites

OMG a computer got hacked when the hacker was actually at the computer, im so in trouble from hackers /sarcasm

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network, but on Thursday the rules were relaxed so that attackers could direct contest organizers using the computers to do things like visit Web sites or open e-mail messages

ha.

so did he pick the macbook? :p

OMG a computer got hacked when the hacker was actually at the computer, im so in trouble from hackers /sarcasm

read the article....he wasnt on the computer, he took control of it by "tricking" someone into going to a certain webpage, which has a malicious script on it, and gives him control of the hosts computer.

directed people to go to a site, instructing somebody is about the same as actually doing it personally.

thats like ariving at somebodys door saying your from their bank and telling them to go to www.whatever.tv and having them enter their bank information to confirm they are who they say they are

directed people to go to a site, instructing somebody is about the same as actually doing it personally.

thats like ariving at somebodys door saying your from their bank and telling them to go to www.whatever.tv and having them enter their bank information to confirm they are who they say they are

You fail. Most sites tailored for specific countries start with two letters, for example, us.abc.com, i'm sure it would be simple to have someone click a link going to usa.abc.com which is controlled by the hacker who then gains access to your computer, not that hard and the person doing the clicking probably didn't suspect a thing.

directed people to go to a site, instructing somebody is about the same as actually doing it personally.

thats like ariving at somebodys door saying your from their bank and telling them to go to www.whatever.tv and having them enter their bank information to confirm they are who they say they are

No, you can get someone to go to a site by a maliciously placed link at a number of places (like a youtube video or something) or an email.

Honestly. OS X sux0rs. I bet my IE 7 with UAC protected mode wouldn't fall for something like this, lol.

Now all those snob Mac users can weep with their false brainwashed statements. IT just goes to show you no OS even LINUX is safe from hackers. Just use COMMON SENSE when computing and don't tell me the Average Joe crap because he'd even hang himself trying to follow common sense.

there is a track history that proves that it would, especially since the hacker would have directed the operator to allow it

I bet my IE 7 with UAC protected mode wouldn't fall for something like this, lol.
directed people to go to a site, instructing somebody is about the same as actually doing it personally.

thats like ariving at somebodys door saying your from their bank and telling them to go to www.whatever.tv and having them enter their bank information to confirm they are who they say they are

No, that's like saying, "hey, check this new blog out at blog.whatever.tv" and it's not a blog, but a site that serves a maliciously crafted page.

the .tv was not serious, i didnt actually mean the country

and besides

Except for reserved names like .com.tv, .net.tv, .org.tv and others, any person in the world can register a .tv domain for a fee. In 2000, Tuvalu negotiated a contract leasing its Internet domain name ".tv" for $50 million in royalties over a 12-year period
You fail. Most sites tailored for specific countries start with two letters, for example, us.abc.com, i'm sure it would be simple to have someone click a link going to usa.abc.com which is controlled by the hacker who then gains access to your computer, not that hard and the person doing the clicking probably didn't suspect a thing.

and besides even that, this is not the least bit worrying

You fail. Most sites tailored for specific countries start with two letters, for example, us.abc.com, i'm sure it would be simple to have someone click a link going to usa.abc.com which is controlled by the hacker who then gains access to your computer, not that hard and the person doing the clicking probably didn't suspect a thing.

The way domain names work is like a hierarchy. the part all the way to the right of the domain name is the top level, and the part all the way to the left is at the bottom. So in the example us.abc.com, com is at the top, and us is at the bottom.

com

|

abc

/ | \

jp us uk

So, in order for someone to create the domain usa.abc.com, they would have to gain control over the abc domain. If someone were to gain control over the abc domain, they could cause a lot more damage than just creating a new URL to trick people.

Now all those snob Mac users can weep with their false brainwashed statements. IT just goes to show you no OS even LINUX is safe from hackers. Just use COMMON SENSE when computing and don't tell me the Average Joe crap because he'd even hang himself trying to follow common sense.

Only reason its said that OS X/Linux users are safer from hackers than windows users, is because the amount of people that use windows and dont have a clue what they are doing with a computer, thus makin them a easy target for hackers

The way domain names work is like a hierarchy. the part all the way to the right of the domain name is the top level, and the part all the way to the left is at the bottom. So in the example us.abc.com, com is at the top, and us is at the bottom.

com

|

abc

/ | \

jp us uk

So, in order for someone to create the domain usa.abc.com, they would have to gain control over the abc domain. If someone were to gain control over the abc domain, they could cause a lot more damage than just creating a new URL to trick people.

I understand how domains are formed, i was commenting in regards to copycat/phishing sites where the goal is to look exactly like a legit site. In my example, a hacker could take that a step further and create a domain that looks very similar to the legit site.

I'm glad this has come out.

I'd rather that other Mac users woke up and realised that we AREN'T magically protected by Mac OS X and that given the knowledge of a flaw and what seems harmless to a user, damage can be done.

If anything, I'd say Windows users are a little better protected - not only do the browsers try and pick up on stuff (like phishing or fake sites), but they are also probably running Anti-Virus software and have a reasonable firewall in place - something which is rare on Mac OS X or Linux.

Edited by daveoc64
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Flameshot 14.0 Final by Razvan Serea Flameshot is a free and open-source, cross-platform tool to take screenshots with many built-in features to save you time. Using Flameshot is as simple as launching, dragging the selection box to cover the area you want to capture, making annotations as needed in on-screen and saving the shot to your computer, all with a very simple and straightforward interface. Flameshot allows users to simply upload their screenshots directly to the cloud in order to easily share it with others. You can upload your image directly to Imgur with a single click and share the URL with others. In-app screenshot editing - You can choose to add an arrow mark, highlight text, blur a section (blur or pixelate an area), add a text, draw something, add a rectangular/circular shaped border, add an incrementing counter number, and add a solid color box with Flameshot's built-in editing tools. Command-line interface (CLI) - Flameshot has several commands you can use in the terminal without launching the GUI via a command line interface. The command line interface lets you script Flameshot and use it as the subject of key binds. Flameshot 14.0 release notes: This release brings major improvements to multi-monitor support, fractional scaling support, new capture workflows, and a long list of bug fixes across all platforms. Changelog: New Multi-Monitor Capture Workflow New monitor selection screen before capture for better multi-monitor and mixed-scaling support. Option to auto-capture the monitor under the cursor (X11 & Windows). Tray menu can directly select a monitor. Linux Improvements XDG Desktop Portal is now the primary screenshot method. Added legacy X11 fallback option for minimal window managers. New D-Bus capture API for scripting and automation. Windows Enhancements Global screenshot hotkeys now supported (not limited to Print Screen). New portable mode stores settings next to the executable. Clipboard now always uses PNG format for better compatibility. CLI & Platform Updates Redesigned flameshot screen command with per-monitor capture support. Added native Nix Flake support. More compact launcher UI and improved update notifications. Major Fixes Multiple Wayland stability fixes, including KDE Plasma crash fixes. Clipboard compatibility improvements for GNOME, Wayland, X11, Windows, and macOS. Fixed D-Bus hangs, capture crashes, and HiDPI region issues. Other Changes Dropped Ubuntu 20.04 (Focal) support. Updated translations and build infrastructure. Intel macOS builds are no longer provided. [full release notes] Download: Flameshot 14.0 | 18.1 MB (Open Source) Download: Flameshot Portable | 53.0 MB Links: Flameshot Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Helium Browser 0.13.4.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.4.1 changelog: 0a4f1149 revision: bump to 4 (#1969) 4848de1f helium/core: enable the chromium screenshot feature (#1968) e0dec3f5 onboarding: integrate strings to i18n system (#1948) 417fa5bc i18n: fix newline parsing for onboarding 7a339b39 i18n: add foraged translations for onboarding 4f090cff i18n/generate: add handling for onboarding strings bfe48d58 i18n_apply: manually override parent grd logic for onboarding strings ab214e3c onboarding: bump in deps, wire up grdp afa6a059 helium/core: disable pdf infobar feature (#1965) eba585e7 helium/ui/vertical: fix new tab button alignment and icon size (#1964) 6ecfc9e0 helium/ui/tabs: fix horizontal tab hover background color (#1963) 3db87dc0 helium/ui/tabs: fix new tab button hover/press colors (#1962) 6bbdcc3e helium/ui: improve tab group UI in all layouts (#1961) 53deb314 helium/ui/tabs: enable tab group hover cards e93aece7 helium/ui/vertical: fix tab group appearance, prevent line overlap 629f5495 helium/ui/tabs: restore solid group header colors, enable new colors 961c962e helium/ui/tabs: move horiz tab group underline to bottom, make it thick c96deab6 merge: update to chromium 149.0.7827.155 (#1959) 36db56b4 i18n: update source.gen.json 5ce006ae patches: refresh for chromium 149.0.7827.155 b4c1ea62 merge: update ungoogled-chromium to 149.0.7827.155 4e5e8671 Update to Chromium 149.0.7827.155 08a3e7da helium/ui/layout: disable mute on collapsed vertical tabs (#1778) a0a5bbaf helium/core: simplify context menu and prevent huge widths (#1951) c4732aac devutils/i18n: add forage command (#1944) 11d16986 devutils/i18n: add an option to translate using local CLI tools (#1942) d820c3a2 i18n/prompt: tighten translation rules to prevent common errors (#1940) cf827007 Update to Chromium 149.0.7827.114 6e3d5164 Update to Chromium 149.0.7827.102 Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      579
    2. 2
      +Edouard
      182
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      73
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!