Macbook Hacked in 2 Minutes!


Recommended Posts

Macbook (MacbookAir) got hacked withing 2 minutes!! :-)

Source: From Macworld

(http://www.macworld.com/article/132733/2008/03/hack.html)

Where: Security Conference open (http://cansecwest.com/post/2008-03-20.21:33:00.CanSecWest_PWN2OWN_2008)

:-D

Prize he won: 3 laptops (Sony Vaio, Fujitsu U810 and the MacBook ) + US$10,000

Edited by guruparan
Link to comment
https://www.neowin.net/forum/topic/628158-macbook-hacked-in-2-minutes/
Share on other sites

OMG a computer got hacked when the hacker was actually at the computer, im so in trouble from hackers /sarcasm

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network, but on Thursday the rules were relaxed so that attackers could direct contest organizers using the computers to do things like visit Web sites or open e-mail messages

ha.

so did he pick the macbook? :p

OMG a computer got hacked when the hacker was actually at the computer, im so in trouble from hackers /sarcasm

read the article....he wasnt on the computer, he took control of it by "tricking" someone into going to a certain webpage, which has a malicious script on it, and gives him control of the hosts computer.

directed people to go to a site, instructing somebody is about the same as actually doing it personally.

thats like ariving at somebodys door saying your from their bank and telling them to go to www.whatever.tv and having them enter their bank information to confirm they are who they say they are

directed people to go to a site, instructing somebody is about the same as actually doing it personally.

thats like ariving at somebodys door saying your from their bank and telling them to go to www.whatever.tv and having them enter their bank information to confirm they are who they say they are

You fail. Most sites tailored for specific countries start with two letters, for example, us.abc.com, i'm sure it would be simple to have someone click a link going to usa.abc.com which is controlled by the hacker who then gains access to your computer, not that hard and the person doing the clicking probably didn't suspect a thing.

directed people to go to a site, instructing somebody is about the same as actually doing it personally.

thats like ariving at somebodys door saying your from their bank and telling them to go to www.whatever.tv and having them enter their bank information to confirm they are who they say they are

No, you can get someone to go to a site by a maliciously placed link at a number of places (like a youtube video or something) or an email.

Honestly. OS X sux0rs. I bet my IE 7 with UAC protected mode wouldn't fall for something like this, lol.

Now all those snob Mac users can weep with their false brainwashed statements. IT just goes to show you no OS even LINUX is safe from hackers. Just use COMMON SENSE when computing and don't tell me the Average Joe crap because he'd even hang himself trying to follow common sense.

there is a track history that proves that it would, especially since the hacker would have directed the operator to allow it

I bet my IE 7 with UAC protected mode wouldn't fall for something like this, lol.
directed people to go to a site, instructing somebody is about the same as actually doing it personally.

thats like ariving at somebodys door saying your from their bank and telling them to go to www.whatever.tv and having them enter their bank information to confirm they are who they say they are

No, that's like saying, "hey, check this new blog out at blog.whatever.tv" and it's not a blog, but a site that serves a maliciously crafted page.

the .tv was not serious, i didnt actually mean the country

and besides

Except for reserved names like .com.tv, .net.tv, .org.tv and others, any person in the world can register a .tv domain for a fee. In 2000, Tuvalu negotiated a contract leasing its Internet domain name ".tv" for $50 million in royalties over a 12-year period
You fail. Most sites tailored for specific countries start with two letters, for example, us.abc.com, i'm sure it would be simple to have someone click a link going to usa.abc.com which is controlled by the hacker who then gains access to your computer, not that hard and the person doing the clicking probably didn't suspect a thing.

and besides even that, this is not the least bit worrying

You fail. Most sites tailored for specific countries start with two letters, for example, us.abc.com, i'm sure it would be simple to have someone click a link going to usa.abc.com which is controlled by the hacker who then gains access to your computer, not that hard and the person doing the clicking probably didn't suspect a thing.

The way domain names work is like a hierarchy. the part all the way to the right of the domain name is the top level, and the part all the way to the left is at the bottom. So in the example us.abc.com, com is at the top, and us is at the bottom.

com

|

abc

/ | \

jp us uk

So, in order for someone to create the domain usa.abc.com, they would have to gain control over the abc domain. If someone were to gain control over the abc domain, they could cause a lot more damage than just creating a new URL to trick people.

Now all those snob Mac users can weep with their false brainwashed statements. IT just goes to show you no OS even LINUX is safe from hackers. Just use COMMON SENSE when computing and don't tell me the Average Joe crap because he'd even hang himself trying to follow common sense.

Only reason its said that OS X/Linux users are safer from hackers than windows users, is because the amount of people that use windows and dont have a clue what they are doing with a computer, thus makin them a easy target for hackers

The way domain names work is like a hierarchy. the part all the way to the right of the domain name is the top level, and the part all the way to the left is at the bottom. So in the example us.abc.com, com is at the top, and us is at the bottom.

com

|

abc

/ | \

jp us uk

So, in order for someone to create the domain usa.abc.com, they would have to gain control over the abc domain. If someone were to gain control over the abc domain, they could cause a lot more damage than just creating a new URL to trick people.

I understand how domains are formed, i was commenting in regards to copycat/phishing sites where the goal is to look exactly like a legit site. In my example, a hacker could take that a step further and create a domain that looks very similar to the legit site.

I'm glad this has come out.

I'd rather that other Mac users woke up and realised that we AREN'T magically protected by Mac OS X and that given the knowledge of a flaw and what seems harmless to a user, damage can be done.

If anything, I'd say Windows users are a little better protected - not only do the browsers try and pick up on stuff (like phishing or fake sites), but they are also probably running Anti-Virus software and have a reasonable firewall in place - something which is rare on Mac OS X or Linux.

Edited by daveoc64
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Couple years ago I got a brand new 4TB Samsung 990 Pro for $250 during Black Friday
    • Thanks
    • Can confirm, I've built stuff for others and no complaints using their products.
    • Yes I agree, it's annoying. You can now miss tabs unless you point low enough.
    • Sysinternals Suite 2026.17.06 by Razvan Serea The Sysinternals Suite is a comprehensive package of advanced Windows utilities created by Mark Russinovich, who launched the Sysinternals website in 1996 to share his system tools and technical resources. This suite combines a wide range of troubleshooting and diagnostic tools, including Process Explorer, Process Monitor, Sysmon, Autoruns, ProcDump, the PsTools collection, and many others. It provides everything IT professionals and developers need to manage, monitor, and troubleshoot Windows systems and applications. The Suite bundles all of the core troubleshooting utilities along with their help files. Non-troubleshooting extras—such as the BSOD Screen Saver or NotMyFault—are excluded. In addition to the well-known tools, it also includes AccessChk, Autologon, Ctrl2Cap, DiskView, Disk Usage (DU), LogonSessions, PageDefrag, PsLogList, PsPasswd, RegMon, RootkitRevealer, TCPView, VMMap, ZoomIt, and more. Sysinternals Suite 2026.17.06 changelog: Autoruns v14.3 - This update to Autoruns, a utility for monitoring startup items, adds bug fixes and improves the command-line application autorunsc. ZoomIt v12.1 - This update to ZoomIt, a screen magnification and annotation tool, adds image backgrounds, webcam background blur and microphone noise cancellation support. Coreinfo v4.01 - This update to Coreinfo, a tool that reports processor, socket, NUMA memory, and cache topology of a system, as well as processor features supported, adds support for new processor features. DebugView v5.02 - This update to DebugView, a tool for displaying both kernel-mode and Win32 debug output, adds Ctrl-Shift-A support for selecting all output, and agent skills support for the CLI utility. LiveKd v5.64 - This update to LiveKd, a utility that allows running the kernel debugger on a live system, fixes a debugging privileges issue. ProcDump 3.5.2 for Linux - This update to ProcDump for Linux, a tool for capturing process dumps, adds .NET counters and a custom core dumper. Process Monitor v4.04 - This update to Process Monitor, a utility for observing real-time file system, Registry, and process or thread activity, adds some bug fixes Sysmon v15.21 - This update to Sysmon, an advanced host security monitoring tool, adds some bug fixes. Download: Sysinternals Suite 2026.17.06 | 168.0 MB (Freeware) Download: Sysinternals Suite for ARM64 | 15.4 MB Link: Sysinternals Suite Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
    • One Month Later
      Vincian earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      542
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      85
    4. 4
      ATLien_0
      64
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!