Mac hacked in 2 minutes


Recommended Posts

the cracking contest doesn't really count

This is exactly the response I would expect from Steve Jobs because I think he honestly believes his gadgets are invincible, even with proof thrown in his face. Poor guy.

Back to reality now...

I hope this demonstrates to everyone who fell for Apple's hype and perhaps opens their eyes to the FACT that Macs are designed and programmed by humans. They are subject to human error and can never, ever be 100% perfect. This goes for any other hardware or software out there. No one should expect it and no one should promise it.

You might want to be a little careful with those claims.

Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

If it's more secure, why was it the first one hacked out of 2 Windows laptops and a MacBook? And that's exactly what the article is about.

Maybe he just wanted a macbook air for free?

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network
He was the first contestant to attempt an attack on any of the systems.

:huh:

Also, how do you measure the time it took him to hack it? It's just the time from the start of the contest? Does it count the time it took him to set up the web page? Or all the previous research?

Edited by ichi
Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

well put.

More to the point, rather than bashing Apple for having a computer than be be exploited by a person with physical access to it, (very very very very few workstations will not be exploitable) shouldn't we be lauding the guy who did it as a genius?

bloody fanboy threads! :)

true, but i think alot of exploits are with 3rd party software, like MS. but MS has more as there is more 3rd party software available making holes

Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

agreed, but genius would be to much i feel, more along the lines of "knows his stuff"

well put.

More to the point, rather than bashing Apple for having a computer than be be exploited by a person with physical access to it, (very very very very few workstations will not be exploitable) shouldn't we be lauding the guy who did it as a genius?

bloody fanboy threads!

It was social engineering however so the cracking contest doesn't really count - this is no different than me putting up an iFrame vulnerability that exists in IE6/IE7 even today.

99% of all hacks are via social engineering. There is no difference between tricking someone on the phone into believing you're with the IT department and need their password and tricking them into going to a web site that isn't what they expected.

Anyone using MSN yesterday should be very aware how easy it's to blow up your IE because I kept getting messages from people asking me to click a certain link that opened an iframe and affects all IE6 and IE7 (Also Vista, because most of the people on the list who sent me the message were Vista users).

Erm... "Open an IFrame?" It's part of a web page. an IFrame is simply a frame that isn't anchored to a page edge and may therefore be obfuscated. (Like overlaying a fake forum menu on top of the real one.)

I have to admit I'm glad to see this. To many times Apple (not all) users delude themselves and act as if Apple is the savior or something when it is really just the same <snipped> different pile

Edited by John S.
circumvention of swear filter
but then all the macusers couldnt say "hey i dont need antivirus, im on a mac"

Circaflex,

Contray to popular belief not all of us Mac users think like that or even consider that to be the case. Many of us are actually quite security conscious. I run antivirus to protect myself, as well as to prevent myself from inadvertantly sending nasties off to my PC using friends.

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

You have to be on the same network as the machine, and have the Admin password to do that...

there was more involved then going to a site

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

there is no Bull***, its fact as iv done it, my job requires me to break into a system @ customers request, or recover files/information if they can no longer access their computer

You need to stop posting and read the article.

"Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on."

ALSO

"Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser."

There was NOT more involved than visiting a web site.

And as for your security experiences, it's getting more fanciful every time, so I just don't believe a word of it now.

Edited by GreyWolfSC

you missed where i said "connect to a machine across the classroom"

and all passwords can be bypassed, or gotten

You have to be on the same network as the machine, and have the Admin password to do that...
Maybe he just wanted a macbook air for free?

:huh:

Also, how do you measure the time it took him to hack it? It's just the time from the start of the contest? Does it count the time it took him to set up the web page? Or all the previous research?

What he wanted makes no difference in whether the exploit happened or how long it took. And I think measuring it from "go" to the hack working is fair. How would you measure time for a real exploit? From the time that the user encounters it to the time that access is obtained, of course.

i would post my CompTia Cert's, but because i would block out the comp001003****** CareerID number as well as my name and date validated, it would jsut be the same as posting a random pic of a cert, just with more numbers

And as for your security experiences, it's getting more fanciful every time, so I just don't believe a word of it now.
i would post my CompTia Cert's, but because i would block out the comp001003****** CareerID number as well as my name and date validated, it would jsut be the same as posting a random pic of a cert, just with more numbers

Wouldn't help. I know people that have Bachelors in Computer Science that can hardly even use a computer.

you can get an A+ and can barely use a computer as that test was easy, the MS and above A+ actually require some thought, tests for MCSE where a pain when i took them 3-4 years ago

why i went with Certs instead of Computer Science, because iv experienced same people that your talking about, and alot of companies view Certs over Computer Science Degree, heck my Interview for MS ( Contractor in Reston VA for Network Engineer) main thing they asked about were my Cert's and RAID50 ( Mainly just asked if i was MCSE or could be in 3 months), didnt even ask once about a degree

but you got it in your head that i supposedly don't know squat, and im shure nothing will change that

Wouldn't help. I know people that have Bachelors in Computer Science that can hardly even use a computer.

*Edit* because i have a feelign it will come up, just because i had an interview, i do not work for MS, i don't like to sit behind a desk, it sucked @ DoE in Germantown, im pretty shure it still does.

Edited by Hell-In-A-Handbasket

agreed

ive been saying this for a while, as apples user base increases, more and more hackers will divert their attention towards macs. its only a matter of time before even more exploits are found. plain and simple.
market share has nothing to do with vunerabilities,the holes are there regardless of how many use a system

Well that assumption isn?t correct,can you explain why OSX had a surge in vulnerabilities the last 2 years? (aprox)

Obviosuly the OS has evolved since,but evolved negatively or positively? i have no doubt that has evolved in a positive manner,however the switching to the x86 architecture,the introduction of new features not related to designers,and the increasing user base,this bring a whole new choices of configurations in every system.

This reason make me belive that OSX is entering a dangerous era,in few words OSX isnt a Multistellar OS,and this transision will cause a lot of damage,this menas that apple has no idea in wich terrain is entering,competing with an expierenced and dominant Windows,that has been testes and tested by hundreds of million people all over the world,with i may say infinite configurations,and this is the day that winows still has problems with drivers from many manufacturers.

Apple proposed this chanllenge

and Microsoft says ?bring it on?

My opinion, if a human makes it, there is always another human who can break it. Whether it's Linux, Windows or OS X. So, I see no surprise in this. P.S. that guy already had hacked the iPhone last year, which runs the same browser, so no wonder he did it in 2 minutes.

P.S. Why are there 2 thread on the same topic?? This is the other one:

https://www.neowin.net/forum/index.php?show...628158&st=0

Well that assumption isn?t correct,can you explain why OSX had a surge in vulnerabilities the last 2 years? (aprox)

Obviosuly the OS has evolved since,but evolved negatively or positively? i have no doubt that has evolved in a positive manner,however the switching to the x86 architecture,the introduction of new features not related to designers,and the increasing user base,this bring a whole new choices of configurations in every system.

This reason make me belive that OSX is entering a dangerous era,in few words OSX isnt a Multistellar OS,and this transision will cause a lot of damage,this menas that apple has no idea in wich terrain is entering,competing with an expierenced and dominant Windows,that has been testes and tested by hundreds of million people all over the world,with i may say infinite configurations,and this is the day that winows still has problems with drivers from many manufacturers.

Apple proposed this chanllenge

and Microsoft says ?bring it on?

We a company called MSI in our hospital this week, doing security checks via DDOS attacks, etc on our network to see how secure we our, we run a strict MS network and so far they've managed to bring down 5 systems since Monday

Windows is scary.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Can you read? I've said I'm willing to pay more for a notchless (no notch) 3:2 screen.
    • Not even an OLED display on the laptops. Also it seems that the laptop design isn't the same as the Surface Ultra model. Looks like bargain bin at high prices.
    • make your own notch - it's not that hard
    • VirtualBox 7.2.10 by Razvan Serea VirtualBox is a powerful x86 and AMD64/Intel64 virtualization product for enterprise as well as home use. Targeted at server, desktop and embedded use, it is now the only professional-quality virtualization solution that is also Open Source Software. Presently, VirtualBox runs on Windows, Linux, macOS, and Solaris hosts and supports a large number of guest operating systems including but not limited to Windows (NT 4.0, 2000, XP, Server 2003, Vista, 7, 8, Windows 10 and Windows 11), DOS/Windows 3.x, Linux (2.4, 2.6, 3.x, 4.x, 5.x and 6.x), Solaris and OpenSolaris, OS/2, OpenBSD, NetBSD and FreeBSD. Some of the features of VirtualBox are: Modularity. VirtualBox has an extremely modular design with well-defined internal programming interfaces and a client/server design. This makes it easy to control it from several interfaces at once: for example, you can start a virtual machine in a typical virtual machine GUI and then control that machine from the command line, or possibly remotely. VirtualBox also comes with a full Software Development Kit: even though it is Open Source Software, you don't have to hack the source to write a new interface for VirtualBox. Virtual machine descriptions in XML. The configuration settings of virtual machines are stored entirely in XML and are independent of the local machines. Virtual machine definitions can therefore easily be ported to other computers. VirtualBox 7.2.10 changelog: VMM: Fixed issue when CentOS 10 VM was not booting due to the message "Fatal glibc error: CPU does not support x86-64-v3" (​github:gh-642) Devices/EFI: Fixed booting issue when ARM VM had less than 1024 MiB of RAM assigned (​github:gh-679) USB: Fixed issue when it was not possible to attach USB device to headless VM on Apple Silicon/macOS 26.4.1 (​github:gh-631) Storage: Fixed issue when VIRTIO-SCSI device was not recognized as SSD device by guest system (​github:gh-634) Network: Fixed issue in E1000 emulation code which triggered debug log creation (​github:gh-645) Network: Fixed issue in E1000 emulation code which prevented OS/2 guest from booting (​github:gh-683) Linux Host: Fixed issue when VMs could not be started due to kernel oops (​github:gh-639) Linux Host and Guest: Fixed issue when kernel modules were failing to build with openSUSE 16.0 kernel Linux Host and Guest: Added initial support for kernel 7.1 Linux Host and Guest: Added extra fixes for RHEL 9.8 kernel (​github:gh-676) Linux Host and Guest: Added possibility to build source code using NASM instead of YASM as the assembler (​github:gh-520) Linux Guest Additions: Added initial support for Extended Data Control Protocol for clipboard sharing with Plasma on Wayland guests (​github:gh-33) Linux Guest Additions: Added extra fixes for preventing vboxvideo kernel module build with kernel version 7.0 and newer (​github:gh-655) OS/2 Guest Additions: Fixed issue when Shared Folders automount and clipboard sharing stopped working (​github:gh-551) Download: VirtualBox 7.2.10 | 170.0 MB (Open Source) Download: VirtualBox 7.2.10 Extension Pack | 19.1 MB View: VirtualBox Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • OK, now ask yourself how are they going to enforce that law? By requiring every single adult to prove their age and provide their legal identity documents to an UNREGULATED 3rd party company that already has a long track record of multiple data breaches. Not to mention, parliament have voted AGAINST this ban, twice, and Starmer is going ahead anyway. So, where's the democracy here, because that looks like dictatorship to me. The solution here is parental responsibility, not government control. Run some public service announcements on TV and UK social media teaching parents how to setup parental controls. That's already been proven to actually work. But the, this is not and has NEVER been about keeping kids safe. It's about control and monitoring. Watching what you're doing online and controlling what you can see and what you can say.
  • Recent Achievements

    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
    • Week One Done
      Prasann earned a badge
      Week One Done
    • First Post
      Dys Topia earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      522
    2. 2
      +Edouard
      179
    3. 3
      PsYcHoKiLLa
      104
    4. 4
      Steven P.
      89
    5. 5
      ATLien_0
      70
  • Tell a friend

    Love Neowin? Tell a friend!