Macbook Hacked in 2 Minutes!


Recommended Posts

Only reason its said that OS X/Linux users are safer from hackers than windows users, is because the amount of people that use windows and dont have a clue what they are doing with a computer, thus makin them a easy target for hackers

I forgot that as well, you nailed it in the head

If anything, I'd say Windows users are a little better protected - not only do the browsers try and pick up on stuff (like phishing or fake sites), but they are also probably running Anti-Virus software and have a reasonable firewall in place - something which is rare on Mac OS X or Linux.

OS X has firewall up by default (as does almost every Linux), Firefox is available for both platforms hence you have the same "anti-phishing" filter and techniques available not to mention both OS' run "single user" mode as opposed to "god admin" on XP and previous Windows systems.

As for "UAC" protecting Vista users - I'm yet to see a Vista user who hasn't turned it off as the first thing they've done on the OS.

On that note, AV does not protect you against crafted attacks or browser vulnerabilities - thinking you're protected because you run an antivirus is delirious.

The way domain names work is like a hierarchy. the part all the way to the right of the domain name is the top level, and the part all the way to the left is at the bottom. So in the example us.abc.com, com is at the top, and us is at the bottom.

com

|

abc

/ | \

jp us uk

So, in order for someone to create the domain usa.abc.com, they would have to gain control over the abc domain. If someone were to gain control over the abc domain, they could cause a lot more damage than just creating a new URL to trick people.

Actually in the example us.abc.com., us is the host name, not a domain name, abc is a domain name and com is a top level domain name. us.abc.com. is a fully qualified domain name (note the dot at the end). Using regular domain names (not fully qualified) is actually a security risk.

Apple are already at work patching the exploit.

Topic diminished.

We've seen this before. And we're still waiting for something, anything, to show up in the wild.

It's been nothing but lab experiments and contests. Since March (I think) 2001.

Pretty much like taking your own sister to the prom. Technically, you're with a girl, but dude . . . . .

Actually since you provided no proof what so ever that apple is working on patching the exploit how can you say that the topic is diminished?
The TippingPoint blog reveals that the vulnerability was located within Safari, but they won't release specific details until Apple has had a chance to correct the problem

Sometimes reading TFA and related news helps.

That'll be a very short victory dance.

On a serious note.

There were three OS's up for cracking - OSX, Vista and Linux. OSX was cracked first. So ask yourselves why? Why not the Vista or Linux OS?

Well it's quite simple. Cracking Vista would amount to nothing more than yet another exploit in Vista. It would be non-newsworthy and that would be it.

Cracking Linux would find itself on serious tech news pages and have Linux enthusiasts dribbling with pride in the acknowledgement that it was an exploit triggered through a webpage that let the attacker in. Easy to fix.

But cracking OSX! Oh now, that's good news. That's deliciously great news. That's headline stuff.

Therefore have a crack at the big one, get in through an exploit and then watch the Microsoft world rejoice as they proclaim the current Apple ads a joke.

Meanwhile the rest of us who are not perturbed by such nonsense go about their lives in the same way they have since buying a Mac. Not worried.

Edited by .kvn

For those defending "physical access"...this is the way I would guess, 99% Windows exploits worked.

OS X has firewall up by default (as does almost every Linux), Firefox is available for both platforms hence you have the same "anti-phishing" filter and techniques available not to mention both OS' run "single user" mode as opposed to "god admin" on XP and previous Windows systems.

As for "UAC" protecting Vista users - I'm yet to see a Vista user who hasn't turned it off as the first thing they've done on the OS.

On that note, AV does not protect you against crafted attacks or browser vulnerabilities - thinking you're protected because you run an antivirus is delirious.

Meet me and many neowinians sometimes. Not everyone is ignorant to turn it off.

We've seen this before. And we're still waiting for something, anything, to show up in the wild.

It's been nothing but lab experiments and contests. Since March (I think) 2001.

Pretty much like taking your own sister to the prom. Technically, you're with a girl, but dude . . . . .

The amount of denial in your posts is amazing. The exploit did not go in the wild because he was under a contract. If this was somebody selling underground and reaching through spam/adware and god forbid Neowin! , it would be game over for you.

For once try to see that your beloved OS X is "secure" only because nobody cares writing viruses for such a small group.

That'll be a very short victory dance.

On a serious note.

There were three OS's up for cracking - OSX, Vista and Linux. OSX was cracked first. So ask yourselves why? Why not the Vista or Linux OS?

Well it's quite simple. Cracking Vista would amount to nothing more than yet another exploit in Vista. It would be non-newsworthy and that would be it.

Cracking Linux would find itself on serious tech news pages and have Linux enthusiasts dribbling with pride in the acknowledgement that it was an exploit triggered through a webpage that let the attacker in. Easy to fix.

But cracking OSX! Oh now, that's good news. That's deliciously great news. That's headline stuff.

Therefore have a crack at the big one, get in through an exploit and then watch the Microsoft world rejoice as they proclaim the current Apple ads a joke.

Meanwhile the rest of us who are not perturbed by such nonsense go about their lives in the same way they have since buying a Mac. Not worried.

Ah, the spin. Loving that Reality Distortion Field yet?

If you haven't noticed, Apple releases massive security patches, sometimes 80 or more, per update. Once a month, on Vista, I get maybe one or two minor patches - there has been only one major exploit discovered, and that was dealing with TCP/IP across multiple versions of Windows. OS X is much, much easier to hack than Vista. That is why it was hacked first. If they could hack Vista first, then you could bet that all the Mac sites would trumpet that fact, that it was more proof that OS X was more secure.

I think this thread shows that some people are still trying to come to grips that the OS they adore is more vulnerable than Windows (less exploited, definitely, but still more vulnerable). Us Windows users will be laughing when some major virus surfaces on OS X and decimates all those computers that don't have antivirus apps running, and whose users believe they are invulnerable.

personally it isnt hacking, dont think technically it is either. Personally using commands from 1 computer to another and sitting some code somewhere that somebody else wrote that you copy pasted are 2 different things

You're an idiot. Please learn to know what you're talking about before spewing uneducated ignorance from your pie hole.

You basically just said that phishing, browser exploiting, etc isn't hacking.

My opinion, if a human makes it, there is always another human who can break it. Whether it's Linux, Windows or OS X. So, I see no surprise in this. P.S. that guy already had hacked the iPhone last year, which runs the same browser, so no wonder he did it in 2 minutes.

there was a viri couple months ago

OSX.RSPlug.A and OSX/Puper ( both same thing i think ) that was gotten by goign to a Porn site and installing a Codec to watch a movie ( required user to give it access via their admin password )

also OSX.Exploit.MetaData.B ( Info )

dont know how legit either of them are as both companies that found them, also sell Anti-Viri that make their users immune

Us Windows users will be laughing when some major virus surfaces on OS X and decimates all those computers that don't have antivirus apps running, and whose users believe they are invulnerable.

i wonder if he used the iPhone Jailbreak exploit

P.S. that guy already had hacked the iPhone last year, which runs the same browser, so no wonder he did it in 2 minutes.
Edited by Hell-In-A-Handbasket
Ah, the spin. Loving that Reality Distortion Field yet?

You didn't just utter those words did you :blink:

After reading through some of the stinking turds that masquerade as knowledgeable I better go and turn off my Mac as I don't want it to get exploited by a piece of code that doesn't exist in the wild as I don't have any virus protection to fend off the thousands and thousands of current exploits that exist for Windows.

Oh wait. I don't have Windows so I guess I'm okay again.

Ah, the spin. Loving that Reality Distortion Field yet?

If you haven't noticed, Apple releases massive security patches, sometimes 80 or more, per update. Once a month, on Vista, I get maybe one or two minor patches - there has been only one major exploit discovered, and that was dealing with TCP/IP across multiple versions of Windows.

I'm not quite sure why I bother to respond but this'll be my last post on the subject.

A few reasons why Apple and most Linux vendors ship so many patches for their products is that they also ship tons more software with the operating system that Vista simply does not have without paying extra or acquiring the server version of the OS. Some things that come to mind are an LDAP server, a web server that supports PHP and other languages, a grid processing server (in other words a node in Windows talk), a fully blown development environment (XCode) and many - MANY more programs, in facts there are hundreds of utilities and free software that ships with every OS X.

Most of these are inert and not enabled unless you explicitly go and turn them on which?in?turn?"protects"?the?system?from?any?security?flaws?in?the?said?software.

Now, if you were to acquire the same software for Windows, then count ALL the flaws and patches in those programs the amount would grow ludicrously, just look at the amount of patches you have for Office and other Microsoft software that implements the same functionality as you'd find in a generic Linux distribution or even OS X.

As for the "Reality Distortion Field", perhaps you should step out of the "Ignorance Field" and study and experience computing a little more before you start making blanket statements about anything related to it.

Although I have to be grateful as well - all the Windows specialists and MCSE kids are one of the biggest sources of income for a consultant - after all I get to clean up the mess these people build, then make a whole ton of money out of it. Me and my house + car thank you all.

It doesn't matter if the exploit applies to a disabled program or not, it is still there. It's great Apple can add all sorts of free utilities to their OS (if Microsoft did that, they'd be sued out of business), but it is their responsibility to patch it when exploits are discovered. Apple has ignored security for so long it has to play catch up - we'll see if Apple gets more marketshare who's correct. Apple wrote their code poorly, and now has to patch it up. Spinning it around is just that, spin. What annoys me more than anything is the arrogance of some Mac users - thinking that they know it all and that Windows users are simply clueless about security and what's "really" going on. I'm sorry, but that simply isn't the case.

Oh, and viruses and Windows? I currently have not yet installed my antivirus for Vista x64 I installed a couple weeks ago - I'll bet I'm more secure than someone running a Mac. I have a router that serves as a firewall, I know what I'm doing online, plus I'm browsing with Protected Mode on and UAC on. As of today, there is not a single exploit that can get around UAC. I could browse all the shoddy sites I wanted and still not get infected (I might have to dismiss a couple dozen UAC prompts, but that is beside the point).

99.999999999999999999999999% of the malware today takes advantage of social engineering and the cluelessness of people to get themselves installed (on Vista). It only takes one mistake to start the infection. Cluelessness and stupid people are not confined to a single OS. I'll bet any sum of money that if OS X's marketshare was as high as Window's, there would be the same, if not more infections on OS X.

That'll be a very short victory dance.

On a serious note.

There were three OS's up for cracking - OSX, Vista and Linux. OSX was cracked first. So ask yourselves why? Why not the Vista or Linux OS?

Well it's quite simple. Cracking Vista would amount to nothing more than yet another exploit in Vista. It would be non-newsworthy and that would be it.

Cracking Linux would find itself on serious tech news pages and have Linux enthusiasts dribbling with pride in the acknowledgement that it was an exploit triggered through a webpage that let the attacker in. Easy to fix.

But cracking OSX! Oh now, that's good news. That's deliciously great news. That's headline stuff.

Therefore have a crack at the big one, get in through an exploit and then watch the Microsoft world rejoice as they proclaim the current Apple ads a joke.

Meanwhile the rest of us who are not perturbed by such nonsense go about their lives in the same way they have since buying a Mac. Not worried.

It's so painfully obvious that you own a Mac, I really feel for you. If I had spent that much money on a PC I would want to feel like there was something about it that differentiated it from other, half as expensive machines.

Now, if you were to acquire the same software for Windows, then count ALL the flaws and patches in those programs the amount would grow ludicrously, just look at the amount of patches you have for Office and other Microsoft software that implements the same functionality as you'd find in a generic Linux distribution or even OS X.

As for the "Reality Distortion Field", perhaps you should step out of the "Ignorance Field" and study and experience computing a little more before you start making blanket statements about anything related to it.

1. What extra software does OS/X come with that Windows does not? Last I checked the default stuff shipped with OS/X was pretty minimal.

2. OS/X is built on Darwin which has its own security team. I recall something about Apple failing to provide source code for their additions and changes to Darwin causing the x86 versions development to be stalled for some time in protest, but that is neither here nor there.

3. What makes you think that, for example, an FTP client written for Windows vs. and FTP client written for OS/X would be less secure?

MS already made all these mistakes once, they shipped XP without a firewall, you'd think Apple would have learned and shipped OS/X with one too initially, you'd think ALL of them would have learned from Unix which is 30 years old and not keep re-inventing things like restricted user permissions.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Flameshot 14.0 Final by Razvan Serea Flameshot is a free and open-source, cross-platform tool to take screenshots with many built-in features to save you time. Using Flameshot is as simple as launching, dragging the selection box to cover the area you want to capture, making annotations as needed in on-screen and saving the shot to your computer, all with a very simple and straightforward interface. Flameshot allows users to simply upload their screenshots directly to the cloud in order to easily share it with others. You can upload your image directly to Imgur with a single click and share the URL with others. In-app screenshot editing - You can choose to add an arrow mark, highlight text, blur a section (blur or pixelate an area), add a text, draw something, add a rectangular/circular shaped border, add an incrementing counter number, and add a solid color box with Flameshot's built-in editing tools. Command-line interface (CLI) - Flameshot has several commands you can use in the terminal without launching the GUI via a command line interface. The command line interface lets you script Flameshot and use it as the subject of key binds. Flameshot 14.0 release notes: This release brings major improvements to multi-monitor support, fractional scaling support, new capture workflows, and a long list of bug fixes across all platforms. Changelog: New Multi-Monitor Capture Workflow New monitor selection screen before capture for better multi-monitor and mixed-scaling support. Option to auto-capture the monitor under the cursor (X11 & Windows). Tray menu can directly select a monitor. Linux Improvements XDG Desktop Portal is now the primary screenshot method. Added legacy X11 fallback option for minimal window managers. New D-Bus capture API for scripting and automation. Windows Enhancements Global screenshot hotkeys now supported (not limited to Print Screen). New portable mode stores settings next to the executable. Clipboard now always uses PNG format for better compatibility. CLI & Platform Updates Redesigned flameshot screen command with per-monitor capture support. Added native Nix Flake support. More compact launcher UI and improved update notifications. Major Fixes Multiple Wayland stability fixes, including KDE Plasma crash fixes. Clipboard compatibility improvements for GNOME, Wayland, X11, Windows, and macOS. Fixed D-Bus hangs, capture crashes, and HiDPI region issues. Other Changes Dropped Ubuntu 20.04 (Focal) support. Updated translations and build infrastructure. Intel macOS builds are no longer provided. [full release notes] Download: Flameshot 14.0 | 18.1 MB (Open Source) Download: Flameshot Portable | 53.0 MB Links: Flameshot Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Helium Browser 0.13.4.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.4.1 changelog: 0a4f1149 revision: bump to 4 (#1969) 4848de1f helium/core: enable the chromium screenshot feature (#1968) e0dec3f5 onboarding: integrate strings to i18n system (#1948) 417fa5bc i18n: fix newline parsing for onboarding 7a339b39 i18n: add foraged translations for onboarding 4f090cff i18n/generate: add handling for onboarding strings bfe48d58 i18n_apply: manually override parent grd logic for onboarding strings ab214e3c onboarding: bump in deps, wire up grdp afa6a059 helium/core: disable pdf infobar feature (#1965) eba585e7 helium/ui/vertical: fix new tab button alignment and icon size (#1964) 6ecfc9e0 helium/ui/tabs: fix horizontal tab hover background color (#1963) 3db87dc0 helium/ui/tabs: fix new tab button hover/press colors (#1962) 6bbdcc3e helium/ui: improve tab group UI in all layouts (#1961) 53deb314 helium/ui/tabs: enable tab group hover cards e93aece7 helium/ui/vertical: fix tab group appearance, prevent line overlap 629f5495 helium/ui/tabs: restore solid group header colors, enable new colors 961c962e helium/ui/tabs: move horiz tab group underline to bottom, make it thick c96deab6 merge: update to chromium 149.0.7827.155 (#1959) 36db56b4 i18n: update source.gen.json 5ce006ae patches: refresh for chromium 149.0.7827.155 b4c1ea62 merge: update ungoogled-chromium to 149.0.7827.155 4e5e8671 Update to Chromium 149.0.7827.155 08a3e7da helium/ui/layout: disable mute on collapsed vertical tabs (#1778) a0a5bbaf helium/core: simplify context menu and prevent huge widths (#1951) c4732aac devutils/i18n: add forage command (#1944) 11d16986 devutils/i18n: add an option to translate using local CLI tools (#1942) d820c3a2 i18n/prompt: tighten translation rules to prevent common errors (#1940) cf827007 Update to Chromium 149.0.7827.114 6e3d5164 Update to Chromium 149.0.7827.102 Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Glow 26.10 by Razvan Serea Glow provides detailed reporting on every hardware component in your computer, saving you valuable time typically spent searching for CPU, motherboard, RAM, graphics card, and other stats. With Glow, all the information is conveniently presented in one clean interface, allowing you to easily access and review the comprehensive hardware details of your system. Glow provides detailed information on various system aspects, including OS, motherboard, processor, memory, graphics card, storage, network, battery, drivers, and services. The well-organized format ensures easy access to the required information. You can export all the gathered data to a plain text file, facilitating sharing with others for troubleshooting purposes. No installation needed. Just decompress the archive, launch the executable, and access computer-related information. Glow runs on Windows 11 and Windows 10 64-bit versions. Glow 26.10 changelog: New Features The bootstrapping algorithm has been completely redesigned. The software can now launch directly without requiring TS Preloader. As part of this change, the startup splash screen displayed during initialization has been removed. In addition, spikes in CPU usage have been eliminated, resulting in a more stable architecture with significantly lower memory consumption. The Microsoft Office detection infrastructure within the Operating System section has been enhanced. Additional detection support has been added for Office C2R (Click-to-Run) installations. Furthermore, the license status evaluation system has been improved, and the priority order has been revised as follows: Licensed > Grace Period > Other (NOTIFICATIONS, EVALUATION, etc.). Glow now includes preliminary support for Wi-Fi 8 technology, allowing more detailed information to be displayed for Wi-Fi 8-compatible network adapters. Glow now provides full support for Bluetooth 6.2. Adapters supporting Bluetooth 6.2 can be analyzed in greater detail and with improved accuracy. The disk distribution view in the Disk section has been modernized, replacing the traditional table layout with a new 2×2 card-based design. The TS Custom Controls module has been updated to v26.7. Thanks to the new custom controls, all Türkaysoft applications now offer a more modern and consistent user interface aligned with Windows 11 design standards. Bug Fixes Potential line-ending handling issues in the Office detection code within the Operating System section have been resolved. Additionally, the output format has been standardized to UTF-8 to prevent character encoding issues and ensure consistent data processing. Several stability and file management issues within the Debugging infrastructure have been addressed. Problems that prevented new log files from being created after Debugging was disabled, as well as issues causing debug records to be lost, have been fixed. File deletion and reaccess issues that occurred after file locks were released have also been resolved. In addition, a bug that caused newly recreated log files to remain locked after deletion has been eliminated. Unnecessary blank lines within debug logs and the extra empty line that could appear at the end of log files have also been corrected. A shortcut key conflict caused by assigning identical hotkeys to both the DNS Test Tool and the Donation page has been fixed. The DNS Test Tool can now be accessed using CTRL + Shift + D, while the Donation page is available via CTRL + Alt + D. Changes The service responsible for providing the Public IP Address and Internet Service Provider information in the Network section has been updated to use the ipinfo.io infrastructure. This change improves the accuracy and consistency of the displayed data. (No external requests are made while Hiding Mode is enabled.) Some terms in the Dutch and Korean language files have been updated to make them clearer and more user-friendly. [TS Updater] Before the update process begins, users are now prompted to choose whether they would like to view the release notes. Note: Always unzip the program before using it. Otherwise you may get an error. Download: Glow 26.10 | 1.8 MB (Open Source) Links: Glow Homepage | Screenshot | Github Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      582
    2. 2
      +Edouard
      183
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      73
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!