Mac hacked in 2 minutes


Recommended Posts

the cracking contest doesn't really count

This is exactly the response I would expect from Steve Jobs because I think he honestly believes his gadgets are invincible, even with proof thrown in his face. Poor guy.

Back to reality now...

I hope this demonstrates to everyone who fell for Apple's hype and perhaps opens their eyes to the FACT that Macs are designed and programmed by humans. They are subject to human error and can never, ever be 100% perfect. This goes for any other hardware or software out there. No one should expect it and no one should promise it.

You might want to be a little careful with those claims.

Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

If it's more secure, why was it the first one hacked out of 2 Windows laptops and a MacBook? And that's exactly what the article is about.

Maybe he just wanted a macbook air for free?

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network
He was the first contestant to attempt an attack on any of the systems.

:huh:

Also, how do you measure the time it took him to hack it? It's just the time from the start of the contest? Does it count the time it took him to set up the web page? Or all the previous research?

Edited by ichi
Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

well put.

More to the point, rather than bashing Apple for having a computer than be be exploited by a person with physical access to it, (very very very very few workstations will not be exploitable) shouldn't we be lauding the guy who did it as a genius?

bloody fanboy threads! :)

true, but i think alot of exploits are with 3rd party software, like MS. but MS has more as there is more 3rd party software available making holes

Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

agreed, but genius would be to much i feel, more along the lines of "knows his stuff"

well put.

More to the point, rather than bashing Apple for having a computer than be be exploited by a person with physical access to it, (very very very very few workstations will not be exploitable) shouldn't we be lauding the guy who did it as a genius?

bloody fanboy threads!

It was social engineering however so the cracking contest doesn't really count - this is no different than me putting up an iFrame vulnerability that exists in IE6/IE7 even today.

99% of all hacks are via social engineering. There is no difference between tricking someone on the phone into believing you're with the IT department and need their password and tricking them into going to a web site that isn't what they expected.

Anyone using MSN yesterday should be very aware how easy it's to blow up your IE because I kept getting messages from people asking me to click a certain link that opened an iframe and affects all IE6 and IE7 (Also Vista, because most of the people on the list who sent me the message were Vista users).

Erm... "Open an IFrame?" It's part of a web page. an IFrame is simply a frame that isn't anchored to a page edge and may therefore be obfuscated. (Like overlaying a fake forum menu on top of the real one.)

I have to admit I'm glad to see this. To many times Apple (not all) users delude themselves and act as if Apple is the savior or something when it is really just the same <snipped> different pile

Edited by John S.
circumvention of swear filter
but then all the macusers couldnt say "hey i dont need antivirus, im on a mac"

Circaflex,

Contray to popular belief not all of us Mac users think like that or even consider that to be the case. Many of us are actually quite security conscious. I run antivirus to protect myself, as well as to prevent myself from inadvertantly sending nasties off to my PC using friends.

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

You have to be on the same network as the machine, and have the Admin password to do that...

there was more involved then going to a site

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

there is no Bull***, its fact as iv done it, my job requires me to break into a system @ customers request, or recover files/information if they can no longer access their computer

You need to stop posting and read the article.

"Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on."

ALSO

"Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser."

There was NOT more involved than visiting a web site.

And as for your security experiences, it's getting more fanciful every time, so I just don't believe a word of it now.

Edited by GreyWolfSC

you missed where i said "connect to a machine across the classroom"

and all passwords can be bypassed, or gotten

You have to be on the same network as the machine, and have the Admin password to do that...
Maybe he just wanted a macbook air for free?

:huh:

Also, how do you measure the time it took him to hack it? It's just the time from the start of the contest? Does it count the time it took him to set up the web page? Or all the previous research?

What he wanted makes no difference in whether the exploit happened or how long it took. And I think measuring it from "go" to the hack working is fair. How would you measure time for a real exploit? From the time that the user encounters it to the time that access is obtained, of course.

i would post my CompTia Cert's, but because i would block out the comp001003****** CareerID number as well as my name and date validated, it would jsut be the same as posting a random pic of a cert, just with more numbers

And as for your security experiences, it's getting more fanciful every time, so I just don't believe a word of it now.
i would post my CompTia Cert's, but because i would block out the comp001003****** CareerID number as well as my name and date validated, it would jsut be the same as posting a random pic of a cert, just with more numbers

Wouldn't help. I know people that have Bachelors in Computer Science that can hardly even use a computer.

you can get an A+ and can barely use a computer as that test was easy, the MS and above A+ actually require some thought, tests for MCSE where a pain when i took them 3-4 years ago

why i went with Certs instead of Computer Science, because iv experienced same people that your talking about, and alot of companies view Certs over Computer Science Degree, heck my Interview for MS ( Contractor in Reston VA for Network Engineer) main thing they asked about were my Cert's and RAID50 ( Mainly just asked if i was MCSE or could be in 3 months), didnt even ask once about a degree

but you got it in your head that i supposedly don't know squat, and im shure nothing will change that

Wouldn't help. I know people that have Bachelors in Computer Science that can hardly even use a computer.

*Edit* because i have a feelign it will come up, just because i had an interview, i do not work for MS, i don't like to sit behind a desk, it sucked @ DoE in Germantown, im pretty shure it still does.

Edited by Hell-In-A-Handbasket

agreed

ive been saying this for a while, as apples user base increases, more and more hackers will divert their attention towards macs. its only a matter of time before even more exploits are found. plain and simple.
market share has nothing to do with vunerabilities,the holes are there regardless of how many use a system

Well that assumption isn?t correct,can you explain why OSX had a surge in vulnerabilities the last 2 years? (aprox)

Obviosuly the OS has evolved since,but evolved negatively or positively? i have no doubt that has evolved in a positive manner,however the switching to the x86 architecture,the introduction of new features not related to designers,and the increasing user base,this bring a whole new choices of configurations in every system.

This reason make me belive that OSX is entering a dangerous era,in few words OSX isnt a Multistellar OS,and this transision will cause a lot of damage,this menas that apple has no idea in wich terrain is entering,competing with an expierenced and dominant Windows,that has been testes and tested by hundreds of million people all over the world,with i may say infinite configurations,and this is the day that winows still has problems with drivers from many manufacturers.

Apple proposed this chanllenge

and Microsoft says ?bring it on?

My opinion, if a human makes it, there is always another human who can break it. Whether it's Linux, Windows or OS X. So, I see no surprise in this. P.S. that guy already had hacked the iPhone last year, which runs the same browser, so no wonder he did it in 2 minutes.

P.S. Why are there 2 thread on the same topic?? This is the other one:

https://www.neowin.net/forum/index.php?show...628158&st=0

Well that assumption isn?t correct,can you explain why OSX had a surge in vulnerabilities the last 2 years? (aprox)

Obviosuly the OS has evolved since,but evolved negatively or positively? i have no doubt that has evolved in a positive manner,however the switching to the x86 architecture,the introduction of new features not related to designers,and the increasing user base,this bring a whole new choices of configurations in every system.

This reason make me belive that OSX is entering a dangerous era,in few words OSX isnt a Multistellar OS,and this transision will cause a lot of damage,this menas that apple has no idea in wich terrain is entering,competing with an expierenced and dominant Windows,that has been testes and tested by hundreds of million people all over the world,with i may say infinite configurations,and this is the day that winows still has problems with drivers from many manufacturers.

Apple proposed this chanllenge

and Microsoft says ?bring it on?

We a company called MSI in our hospital this week, doing security checks via DDOS attacks, etc on our network to see how secure we our, we run a strict MS network and so far they've managed to bring down 5 systems since Monday

Windows is scary.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft unveils new Surface Laptop with improved trackpad, Snapdragon X2, and more by Taras Buria Microsoft's new Surface Laptop Ultra generated a lot of buzz earlier this month, but in addition to its most powerful laptop with an NVIDIA chip, Microsoft also has a more affordable laptop lineup, which has been waiting for an update for quite a while. Today, Microsoft announced the eighth-generation Surface Laptop. The new Surface Laptop is powered by the Snapdragon X2 Plus and X2 Elite processors. These chips offer faster CPU performance, up to 58% faster graphics, and 80 TOPS Neural Processing Units (NPUs) for on-device AI processing. Like the previous models, these chips retain their great energy efficiency, and Microsoft says that buyers can expect up to 20 hours of work on a single charge. The laptop is available in two sizes: 13.8-inch and 15-inch. You will have a hard time finding visual differences between the new and previous models, as Microsoft is not taking any major design leaps, except for the new Jade color, which may look familiar to Surface Laptop 5 owners. Other colors include Platinum, Black, and Dune. The 15-inch variant got a higher-resolution display. It is a 3,270 x 2,180 resolution screen with a pixel density of 262 ppi (the 13-inch model has a 201 ppi density) and a maximum brightness of 600 nits SDR and HDR. Unlike the Surface Pro 12th-gen, which is available with optional OLED displays, the Surface Laptop sticks with IPS, a 1,300:1 contrast ratio, a 120Hz refresh rate, and a 3:2 aspect ratio. Another notable change in the Surface Laptop 8 is its trackpad. It now provides haptic feedback when you perform various actions in apps and the operating system. It is a relatively new feature that Microsoft brought to Windows 11 in recent updates, and it is only available on certain devices, such as the Logitech MX Master 4, Surface Slim Pen 2, the upcoming Surface Laptop Ultra, and now the Surface Laptop 8. The new Surface Laptop with the new Surface Pro Like its tablet-shaped sibling, the new Surface Laptop is notably more expensive. It starts at a $1,599 for a 13.8-inch configuration with a 256GB SSD and 16GB of RAM. However, in the US, the base model has double the storage while keeping the same price. Available configurations include up to 64GB of memory and up to 2TB SSD (user-removable PCIe Gen4). The Surface Laptop 8 is now available for purchase on the official Microsoft website.
    • Microsoft announces 12th-gen Surface Pro with Snapdragon X2 processors by Taras Buria So far, 2026 has been rich in Surface announcements. Microsoft started with a fresh lineup of Surface for Business devices powered by Intel's new Core Ultra 300 processors. Then the company revealed the Surface Laptop Ultra, its most powerful laptop with NVIDIA's RTX Spark processor. Now, it is time for new Surface Pro and Surface Laptop models with Qualcomm processors. Microsoft's original Copilot+ PCs with Snapdragon X1 chips debuted in late May 2024. Two years later, Microsoft is finally updating the lineup with new models featuring Snapdragon X2 processors. The 12th-gen Surface Pro continues the well-established formula of Microsoft's flagship tablet, and Microsoft is not even changing colors, as the tablet will be available in three colors: Dune, Black, and Platinum. The most important changes are mostly hidden inside. Microsoft switched from the Snapdragon X1 to the new Snapdragon X2, which promises up to 53% faster graphics performance than the previous generation and up to 15.5 hours of battery life. The built-in NPU is also much more powerful, and it can run at up to 80 TOPS for on-device AI processing. Like before, the new Surface Pro is available with a 13-inch IPS display, and Microsoft is still offering OLED as a separate, more expensive configuration. Speaking of configurations, the Surface Pro will be available with a 10-core Snapdragon X2 Plus or a 12-core Snapdragon X2 Elite. Microsoft expanded the available RAM configurations to 64GB (previously 32GB was the maximum), while storage remains unchanged at 256GB, 512GB, or 1TB of user-replaceable PCIe Gen4 SSDs. The new Surface Pro and the Surface Laptop Other specs remain mostly unchanged. The computer has the same 1440p Windows Hello webcam, two USB4 ports for charging, data, and display output, Wi-Fi 7 and Bluetooth 5.4 support, dual speakers, and compatibility with Surface Pro Signature and Flex keyboards. With that said, there is one very important aspect of the Surface Pro that changed significantly, and it is the price. While the previous-gen Surface Pro launched at $999 for the base configuration, in 2026, the entry-level Surface Pro with Snapdragon X2, 16GB of memory, and 256GB will set you back an eye-watering $1,499. To sweeten the pill, Microsoft is running a limited-time promotion where Surface Pro buyers can get a free Surface Pro 13-inch Keyboard. The promo runs from June 16 through June 30. The new Surface Pro is available now on the official Microsoft Store website.
    • MakeMKV 1.18.4 Beta by Razvan Serea MakeMKV is a format converter, otherwise called "transcoder". It converts the video clips from proprietary (and usually encrypted) disc into a set of MKV files, preserving most information but not changing it in any way. The MKV format can store multiple video/audio tracks with all meta-information and preserve chapters. There are many players that can play MKV files nearly on all platforms, and there are tools to convert MKV files to many formats, including DVD and Blu-ray discs. Additionally MakeMKV can instantly stream decrypted video without intermediate conversion to wide range of players, so you may watch Blu-ray and DVD discs with your favorite player on your favorite OS or on your favorite device. Reads DVD and Blu-ray discs Reads Blu-ray discs protected with latest versions of AACS and BD+ Preserves all video and audio tracks, including HD audio Preserves chapters information Preserves all meta-information (track language, audio type) Fast conversion - converts as fast as your drive can read data. No additional software is required for conversion or decryption. Available for Windows, Mac OS X and Linux Functionality to open DVD discs is free and will always stay free. All features (including Blu-ray decryption and processing) are free during BETA. MakeMKV 1.18.4 changelog: Small improvements and bugfixes Notable bug fixes: Fixed linux armhf binary crash on certain architectures Download: MakeMKV 1.18.4 Beta | 15.7 MB (Free, paid upgrade available) Download: MakeMKV for Mac OS X | 41.9 MB Links: MakeMKV Website | MakeMKV for Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • They probably should have it where they can open other formats but only save in the open formats.
    • The next time you apply for a shift at Taco Bell or KFC, you may be interviewed, assessed, and onboarded by three AI agents named Maria, Daniel, and Claire — and those agents will continue scoring your behavior long after you clock in for the first time.................... For workers applying to or already employed at those chains, the implication is concrete: an AI system is assessing their conversational behavior over WhatsApp and phone calls, storing that behavioral data, and using it to inform decisions about whether they are hired, how they are onboarded, and whether they are flagged as a flight risk https://www.techtimes.com/articles/318390/20260615/ai-agents-now-score-taco-bell-kfc-workers-via-whatsapp-day-one.htm  
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      523
    2. 2
      +Edouard
      207
    3. 3
      PsYcHoKiLLa
      114
    4. 4
      Steven P.
      90
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!