Mac hacked in 2 minutes


Recommended Posts

Someone had to surf to the page....

But the hacker himself doesn't need physical access. I have seen atleast three instances when Neowin itself served malicious code in its pages -- I am not sure whether Neowin was hacked or it was some compromised ad servers (more likely the later). Futhermore, the browser engine can itself be used by several other parts of the system for example to render gadgets, widgets. Any of these can be vector for exploiting the system.

Name an OS? I can tell you how to pull data. Remember, even encrypted drives can be thwarted by reading the keys form memory.

Really...

So you can read the data of an encrypted Bitlocker drive witht he encryption key on an USB stick ? you know one of the ways that actully secures your encrypted drives against those RAM memory rebot tricks ? that'd be interesting to see :)

----

Also this particular hack, since it uses a webpage exploit. Though no data is released about it, it would seem that a properly set up Vista laptop with UAC on and IE in protected mode would have stopped the exploit from reading this file. uless the exploit somehow manages to evade protected mode.

its userland, core libraries, and applications are almost entirely custom Apple code and design - with no real emphasis on security. Apple simply doesn't have the same experience writing secure software that Microsoft does. Ridicule Microsoft all you want, but they / we have learned a whole lot from what Windows has been through over the last decade.

You might want to be a little careful with those claims.

Someone had to surf to the page....

Of course. Macs aren't usually servers where they'll be running lots of things listening for connections, so someone would have to do something for it to get hacked. Most desktop hacks work that way, it's not every day a worm comes out that will infect your PC just by having it sitting there.

market share has nothing to do with vunerabilities,, the holes are there regardless of how many use a system

Not said by the people who know,imagine all this vulnerabilities in Mac OSX with this tiny market share,then imagine if Mac OSX has 93% of market share (DANG!),now imagine that windows (Vista and XP) has lesser vulnerabilites with 750 million computers than OSX with 50 million pc at the most,and im being optimistic.

Can you see the breach?

Hope so,otherwise i'm so sorry :)

He used Safari vulnerability that means Vista/XP and other Windows versions are vulnerable in the same way. As I remember there are three computers this year, Windows, Linux and Mac. And I think that each of them will be hacked. Most of security researches are working on ways to hack all three with the same method. First day no one tried, because only attack from internet was allowed and today (second day) is allowed to use preloaded software and I think later they will install more 3rd party software and that will definitely make all of them vulnerable.

If a Man made, Man can brake.

Wow man! $10 000 in 2 min! What a smart a**!

If there is anything cool worth doing in this world, it would be hacking! :p

... how about getting some greens while doing it!

Hacking for good is actually a good thing, but straight up hacking, I would have to reject to.

I'm not surprised really, no system is secure forever. You can only be vigilant to ensure nothing gets on to your computer, that's all.

Scirwode

... how about getting some greens while doing it!

Hacking for good is actually a good thing, but straight up hacking, I would have to reject to.

Hacking is always good. The guy in this article was actually "cracking". People always mistake cracking for hacking.

Crackers always demolish what hackers build, i.e. walls, security etc.

It was social engineering however so the cracking contest doesn't really count - this is no different than me putting up an iFrame vulnerability that exists in IE6/IE7 even today.

Anyone using MSN yesterday should be very aware how easy it's to blow up your IE because I kept getting messages from people asking me to click a certain link that opened an iframe and affects all IE6 and IE7 (Also Vista, because most of the people on the list who sent me the message were Vista users).

What now Mac? goes to show mac can be hacked just like windows there for then being an overpriced piece of metal.

Well, ANY OS can be cracked [not hacked really], it just depends on whether you want to....

And don't give me sh*t about how invincible Linux is :p

the overpriced part has been proven wrong so many times its not funny.

^ Thats clearly why i said its an overpriced piece of metal! :laugh:
Edited by Hell-In-A-Handbasket
the overpriced part has been proven wrong so many times its not funny.

"overpriced" is relative to what you think something is worth. As evident of Apple's PC market share, they are overpriced.

and of all the Windows machines i work on in a daily basis vs the mac's that i work on, your Mac's can be hacked like windows is also wrong, this " Hack " required a person to be walked through the entire process as though the hacker was at the actual computer. if given physical access to the computer by means of " hand-holding " or touch, any system will go down.

There was no "hand holding." The man told the victim, "Go to this site." That's it.

the only diffrence is that you turn on a Windows PC and its vunerable ( i have witnessed this by putting a non-firewalled/viri/adware windows system on the net, and not touched it, couple days later, its pretty much worthless( aka like a HoneyPot )

Bull.

Face it. Macs are made from the same parts as Windows PCs. The only difference is shiny plastic and a unified experience. They aren't more secure, they aren't better built. In fact, they're probably shiny because they're covered in lead paint. That would explain the bizarre behavior of Mac fanatics: too much smooching the computer.

Edited by GreyWolfSC

there was more involved then going to a site

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

there is no Bull***, its fact as iv done it, my job requires me to break into a system @ customers request, or recover files/information if they can no longer access their computer

"overpriced" is relative to what you think something is worth. As evident of Apple's PC market share, they are overpriced.

There was no "hand holding." The man told the victim, "Go to this site." That's it.

Bull****.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The 2TB Samsung 990 PRO NVMe SSD hits lowest price in over three months by Sayan Sen Yesterday, we covered a really good deal wherein you can get a 4TB TeamGroup T-FORCE G50 NVMe PCIe Gen4 SSD for a low price of just $400 with a special discount coupon. That's just $100 per TB, making it a very good offer during these hard times. The deal is still live, so you can check it out in its dedicated article here if you do not want to miss out. Meanwhile, if you don't have that kind of budget but still wish to buy an SSD for a good price, the 2TB variant of the TeamGroup SSD at $280 its lowest price in over three months. Meanwhile, those seeking 2TB but faster performance can check out Samsung's 990 PRO, which has hit the lowest price also in the last quarter or so, as it's on sale for $370 (purchase links under the specs table down below). Thus, you want a faster drive, get the 990 Pro, or you want more capacity, grab the TeamGroup 4TB linked in the first para. The 990 PRO is a PCIe Gen4 NVMe SSD and still one of the fastest drives available today for under $500. Speaking of fast, sequential reads and writes are rated at 7450 MB/s and 6900 MB/s, respectively. The random throughputs for reads and writes are 1400K IOPS and 1550K IOPS, respectively. The 990 PRO is based on Samsung's 7th Gen V-NAND flash, and it too is TLC. It packs 2 gigs of LPDDR4 DRAM cache, which helps the random performance. The endurance rating for this is 1200 TBW (terabytes written), which should be sufficient for most users. The Samsung 990 PRO is compatible with the PlayStation 5, but if you are going to use the 990 PRO on a PC, check out the Samsung Magician app that lets you track your drive's health, update its firmware, customize various settings, and more. The tech specs are given below: Specification TeamGroup T-FORCE G50 2TB Samsung 990 PRO 2TB Interface PCIe 4.0 x4, NVMe 1.4 PCIe Gen 4.0 x4, NVMe 2.0 Form Factor M.2 2280 M.2 2280 Controller InnoGrit Controller Samsung In-house Controller NAND Flash 3D TLC 3D TLC DRAM Cache None (HMB supported) 2GB LPDDR4 Sequential Read (Max) 5,000 MB/s 7,450 MB/s Sequential Write (Max) 4,500 MB/s 6,900 MB/s Random Read (4K) Up to 600,000 IOPS Up to 1,400,000 IOPS Random Write (4K) Up to 700,000 IOPS Up to 1,550,000 IOPS TBW (Endurance) 1,300 TBW 1,200 TBW MTBF 3,000,000 hours 1,500,000 hours Operating Temperature 0°C to 70°C 0°C to 70°C Storage Temperature -40°C to 85°C -40°C to 85°C Shock Resistance 1,500G / 0.5ms 1,500G / 0.5ms Heatsink Patented Graphene Heat Spreader No Get them at the links below: Samsung 990 PRO SSD 2TB (MZ-V9P2T0B/AM): $369.99 (Sold and Shipped by Amazon US) TEAMGROUP T-Force G50 2TB SSD (TM8FFE002T0C129): $279.99 (Sold by TeamGroup, Shipped by Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • If you can't spell a simple word that 2nd graders learn, your entire argument is suspect.
    • And here goes the "Won't someone think of the children" brigade. Get stuffed mate. This has NOTHING to do with making the internet safe. It's about tracking adults, spying on your online activity, and sending the boys around when they don't like something you post. Also, again, parliament have voted TWICE against this, and Starmer is going ahead anyway. THAT is anti-democratic bullsh**. They will use this law to track you, they will use this law to control you, and they will use this law to punish you if they don't like what you do, even if it's legal. And your data? Say bye bye to that. It'll be on the darkweb in weeks. I'm not some rando online. I've been an IT professional for 40 years, many of it in security. I know exactly what this means and what will happen to your data. I do not consent and I will not comply.
    • "...but it may not be Microsoft's fault" seems like a reasonable way to tease what is going on without leaving the user with a false impression that an update is the problem. A title isn't a summery, it is meant to entice the user to read the article. It should not contain a misleading premise; which this title does not. You could maybe complain that the first paragraph should have included that detail. The writing style popularized over 100 years ago in newspapers will cover the most important information as soon as possible with details and nuance added later; the idea being that with each new paragraph you have less of the reader's focus.
    • Samsung Galaxy XR arrives in the UK with new AI and enterprise features by Fiza Ali Samsung is bringing its Galaxy XR headset to the UK several months after the device made its debut as the first headset built on Google's Android XR platform. The headset was first teased in late 2024 alongside Google's introduction of Android XR before making its commercial debut in 2025. Developed in collaboration with Google and Qualcomm, Galaxy XR combines mixed reality experiences with Gemini-powered AI features, allowing users to interact with digital content using voice, gestures, and visual inputs. While the hardware itself remains largely unchanged from the version Samsung unveiled last year, the company is using the UK launch to spotlight several software enhancements that have arrived through recent updates. Among the most notable additions is deeper integration with Google's ecosystem. Galaxy XR users can explore destinations through Google Maps' Immersive View, receiving AI-powered recommendations and contextual information from Gemini while navigating virtual environments. Furthermore, entertainment experiences have also expanded; users can watch 180-degree and 360-degree videos on YouTube, browse spatial content converted into 3D, and ask Gemini questions about on-screen content without interrupting playback. Samsung is also highlighting mixed-reality features such as Circle to Search, which allows users to identify real-world objects through hand gestures while using the headset's video pass-through mode. Another feature automatically converts photos and videos into spatial 3D experiences. Moreover, the headset now also supports Android Enterprise, allowing organisations to manage deployments using existing Android management tools. Annika Bizon, Vice President, Product and Marketing, Mobile Experience, Samsung UK & Ireland, talked about the device, stating: The headset is powered by Qualcomm's Snapdragon XR2+ Gen 2 platform and features dual 4K Micro-OLED displays. The tech giant says that users can expect up to 2.5 hours of battery life. Samsung also confirmed that Galaxy XR will continue receiving software and security updates as the company works alongside Google and Qualcomm to expand the Android XR ecosystem. Galaxy XR is now available for pre-order and will go on sale on 8 July. Customers interested in trying the headset before launch can visit Samsung KX in London and selected Samsung Experience Stores from 17 June. Finally, the company will also host a livestream on 19 June showcasing the headset's capabilities and answering questions from prospective customers.
  • Recent Achievements

    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
    • Week One Done
      Prasann earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      519
    2. 2
      +Edouard
      174
    3. 3
      PsYcHoKiLLa
      95
    4. 4
      Steven P.
      84
    5. 5
      ATLien_0
      70
  • Tell a friend

    Love Neowin? Tell a friend!