Mac hacked in 2 minutes


Recommended Posts

the cracking contest doesn't really count

This is exactly the response I would expect from Steve Jobs because I think he honestly believes his gadgets are invincible, even with proof thrown in his face. Poor guy.

Back to reality now...

I hope this demonstrates to everyone who fell for Apple's hype and perhaps opens their eyes to the FACT that Macs are designed and programmed by humans. They are subject to human error and can never, ever be 100% perfect. This goes for any other hardware or software out there. No one should expect it and no one should promise it.

You might want to be a little careful with those claims.

Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

If it's more secure, why was it the first one hacked out of 2 Windows laptops and a MacBook? And that's exactly what the article is about.

Maybe he just wanted a macbook air for free?

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network
He was the first contestant to attempt an attack on any of the systems.

:huh:

Also, how do you measure the time it took him to hack it? It's just the time from the start of the contest? Does it count the time it took him to set up the web page? Or all the previous research?

Edited by ichi
Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

well put.

More to the point, rather than bashing Apple for having a computer than be be exploited by a person with physical access to it, (very very very very few workstations will not be exploitable) shouldn't we be lauding the guy who did it as a genius?

bloody fanboy threads! :)

true, but i think alot of exploits are with 3rd party software, like MS. but MS has more as there is more 3rd party software available making holes

Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

agreed, but genius would be to much i feel, more along the lines of "knows his stuff"

well put.

More to the point, rather than bashing Apple for having a computer than be be exploited by a person with physical access to it, (very very very very few workstations will not be exploitable) shouldn't we be lauding the guy who did it as a genius?

bloody fanboy threads!

It was social engineering however so the cracking contest doesn't really count - this is no different than me putting up an iFrame vulnerability that exists in IE6/IE7 even today.

99% of all hacks are via social engineering. There is no difference between tricking someone on the phone into believing you're with the IT department and need their password and tricking them into going to a web site that isn't what they expected.

Anyone using MSN yesterday should be very aware how easy it's to blow up your IE because I kept getting messages from people asking me to click a certain link that opened an iframe and affects all IE6 and IE7 (Also Vista, because most of the people on the list who sent me the message were Vista users).

Erm... "Open an IFrame?" It's part of a web page. an IFrame is simply a frame that isn't anchored to a page edge and may therefore be obfuscated. (Like overlaying a fake forum menu on top of the real one.)

I have to admit I'm glad to see this. To many times Apple (not all) users delude themselves and act as if Apple is the savior or something when it is really just the same <snipped> different pile

Edited by John S.
circumvention of swear filter
but then all the macusers couldnt say "hey i dont need antivirus, im on a mac"

Circaflex,

Contray to popular belief not all of us Mac users think like that or even consider that to be the case. Many of us are actually quite security conscious. I run antivirus to protect myself, as well as to prevent myself from inadvertantly sending nasties off to my PC using friends.

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

You have to be on the same network as the machine, and have the Admin password to do that...

there was more involved then going to a site

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

there is no Bull***, its fact as iv done it, my job requires me to break into a system @ customers request, or recover files/information if they can no longer access their computer

You need to stop posting and read the article.

"Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on."

ALSO

"Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser."

There was NOT more involved than visiting a web site.

And as for your security experiences, it's getting more fanciful every time, so I just don't believe a word of it now.

Edited by GreyWolfSC

you missed where i said "connect to a machine across the classroom"

and all passwords can be bypassed, or gotten

You have to be on the same network as the machine, and have the Admin password to do that...
Maybe he just wanted a macbook air for free?

:huh:

Also, how do you measure the time it took him to hack it? It's just the time from the start of the contest? Does it count the time it took him to set up the web page? Or all the previous research?

What he wanted makes no difference in whether the exploit happened or how long it took. And I think measuring it from "go" to the hack working is fair. How would you measure time for a real exploit? From the time that the user encounters it to the time that access is obtained, of course.

i would post my CompTia Cert's, but because i would block out the comp001003****** CareerID number as well as my name and date validated, it would jsut be the same as posting a random pic of a cert, just with more numbers

And as for your security experiences, it's getting more fanciful every time, so I just don't believe a word of it now.
i would post my CompTia Cert's, but because i would block out the comp001003****** CareerID number as well as my name and date validated, it would jsut be the same as posting a random pic of a cert, just with more numbers

Wouldn't help. I know people that have Bachelors in Computer Science that can hardly even use a computer.

you can get an A+ and can barely use a computer as that test was easy, the MS and above A+ actually require some thought, tests for MCSE where a pain when i took them 3-4 years ago

why i went with Certs instead of Computer Science, because iv experienced same people that your talking about, and alot of companies view Certs over Computer Science Degree, heck my Interview for MS ( Contractor in Reston VA for Network Engineer) main thing they asked about were my Cert's and RAID50 ( Mainly just asked if i was MCSE or could be in 3 months), didnt even ask once about a degree

but you got it in your head that i supposedly don't know squat, and im shure nothing will change that

Wouldn't help. I know people that have Bachelors in Computer Science that can hardly even use a computer.

*Edit* because i have a feelign it will come up, just because i had an interview, i do not work for MS, i don't like to sit behind a desk, it sucked @ DoE in Germantown, im pretty shure it still does.

Edited by Hell-In-A-Handbasket

agreed

ive been saying this for a while, as apples user base increases, more and more hackers will divert their attention towards macs. its only a matter of time before even more exploits are found. plain and simple.
market share has nothing to do with vunerabilities,the holes are there regardless of how many use a system

Well that assumption isn?t correct,can you explain why OSX had a surge in vulnerabilities the last 2 years? (aprox)

Obviosuly the OS has evolved since,but evolved negatively or positively? i have no doubt that has evolved in a positive manner,however the switching to the x86 architecture,the introduction of new features not related to designers,and the increasing user base,this bring a whole new choices of configurations in every system.

This reason make me belive that OSX is entering a dangerous era,in few words OSX isnt a Multistellar OS,and this transision will cause a lot of damage,this menas that apple has no idea in wich terrain is entering,competing with an expierenced and dominant Windows,that has been testes and tested by hundreds of million people all over the world,with i may say infinite configurations,and this is the day that winows still has problems with drivers from many manufacturers.

Apple proposed this chanllenge

and Microsoft says ?bring it on?

My opinion, if a human makes it, there is always another human who can break it. Whether it's Linux, Windows or OS X. So, I see no surprise in this. P.S. that guy already had hacked the iPhone last year, which runs the same browser, so no wonder he did it in 2 minutes.

P.S. Why are there 2 thread on the same topic?? This is the other one:

https://www.neowin.net/forum/index.php?show...628158&st=0

Well that assumption isn?t correct,can you explain why OSX had a surge in vulnerabilities the last 2 years? (aprox)

Obviosuly the OS has evolved since,but evolved negatively or positively? i have no doubt that has evolved in a positive manner,however the switching to the x86 architecture,the introduction of new features not related to designers,and the increasing user base,this bring a whole new choices of configurations in every system.

This reason make me belive that OSX is entering a dangerous era,in few words OSX isnt a Multistellar OS,and this transision will cause a lot of damage,this menas that apple has no idea in wich terrain is entering,competing with an expierenced and dominant Windows,that has been testes and tested by hundreds of million people all over the world,with i may say infinite configurations,and this is the day that winows still has problems with drivers from many manufacturers.

Apple proposed this chanllenge

and Microsoft says ?bring it on?

We a company called MSI in our hospital this week, doing security checks via DDOS attacks, etc on our network to see how secure we our, we run a strict MS network and so far they've managed to bring down 5 systems since Monday

Windows is scary.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Firefox 152.0 by Razvan Serea Firefox is a fast, full-featured Web browser. It offers great security, privacy, and protection against viruses, spyware, malware, and it can also easily block pop-up windows. The key features that have made Firefox so popular are the simple and effective UI, browser speed and strong security capabilities. Firefox has complete features for browsing the Internet. It is very reliable and flexible due to its implemented security features, along with customization options. Firefox includes pop-up blocking, tab-browsing, integrated Google search, simplified privacy controls, a streamlined browser window that shows you more of the page than any other browser and a number of additional features that work with you to help you get the most out of your time online. Firefox key features Enhanced Tracking Protection (ETP) – Blocks trackers, cookies, cryptominers, and fingerprinters by default. Private Browsing Mode – Deletes history, cookies, and temporary files when closed. Lightweight & Fast Performance – Optimized memory usage with efficient page loading. Cross-Platform Sync – Sync bookmarks, passwords, history, and open tabs across devices. Customizable Interface – Toolbars, themes, and extensions can be tailored to user needs. Strong Privacy Controls – Options to manage cookies, permissions, and site data easily. Reader Mode – Strips away clutter for distraction-free reading. Pocket Integration – Save and read articles offline with Pocket built into Firefox. Picture-in-Picture (PiP) – Watch videos in a floating window while multitasking. Extensions & Add-ons – Vast library for productivity, security, and personalization. Built-in PDF Viewer – No need for external software to view PDFs. Firefox Monitor – Alerts users if their email is part of a known data breach. Multi-Account Containers – Isolate browsing sessions (e.g., work, personal, shopping). Performance & Resource Efficiency – Uses fewer system resources than some competitors. Open Source & Community-Driven – Transparent development with global contributions. Download: Firefox 64-bit | Firefox 32-bit | ARM64 | ~70.0 MB (Freeware) Download: Firefox for MacOS | 145.0 MB View: Firefox Home Page | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft Visio 2024 Professional for Windows is still at 90% off by Steven Parker Created by ChatGPT Today's highlighted Neowin Deal comes from our Apps & Software section of the Neowin Deals store, where you can save 90% on Microsoft Visio 2024 Professional for Windows [Digital License]. Microsoft Visio: Turn Complex Ideas into Clear Visuals Microsoft Visio 2024 is a robust diagramming software designed to empower individuals and businesses to visually represent complex data, processes, and workflows. With a host of advanced features, it caters to professionals from various industries, including IT, engineering, business, and architecture. Visio 2024 makes it easy for individuals and teams to create and share clear, professional diagrams that simplify complex information. It offers updated shapes, templates, and styles, along with a new search bar to improve your experience. Visio 2024 also has a fresh design that matches other Office apps you use. Create stunning diagrams Extensive Diagramming Capabilities: Visio 2024 offers a wide array of diagram types, including flowcharts, process maps, floor plans, network diagrams, and organizational charts. The software comes with a comprehensive set of pre-built templates and shapes, making it easier to get started on projects quickly. Professional Templates and Shapes: The software includes over 250,000 shapes across multiple diagram types, ensuring that users from any field-whether creating a simple flowchart or a complex engineering design-have the tools they need to represent their ideas visually. Data-Linked Diagrams: One of the most powerful features of Visio 2024 is its ability to link data to diagrams, allowing users to visualize real-time data directly within their diagrams. Whether you're pulling data from Excel, SQL Server, or other databases, the software ensures that your diagrams are automatically updated as data changes, giving users better insights and control. Advanced Formatting Options: Visio 2024 comes equipped with a range of formatting tools to create highly customized diagrams. These include shape formatting, text adjustments, and the ability to apply various themes, ensuring diagrams not only serve their functional purpose but also look professional. Enhanced Visual Styles: This version of Visio includes new visual styles and layouts that make complex diagrams easier to interpret. Whether you're designing an IT network, a business process flow, or a floor plan, the enhanced visual options improve clarity and presentation quality. Easy, secure collaboration Real-Time Collaboration: With Visio 2024's improved collaboration tools, multiple users can work on the same diagram simultaneously from anywhere, with changes being tracked in real-time. This makes it a highly efficient tool for teams working remotely or across different locations. Mobile and Cloud Access: Users can view and edit diagrams on the go with the Visio web app. This ensures that even when you're away from your desktop, you can access and make critical changes to diagrams via mobile devices. Integration with Microsoft 365: Visio 2024 integrates seamlessly with the Microsoft 365 suite, allowing users to easily embed diagrams into PowerPoint presentations, Word documents, or Teams chats. You can also store diagrams in OneDrive or SharePoint for easy sharing and access from any device. Security and Compliance: Built with enterprise-grade security, Visio 2024 ensures that your diagrams are protected. Microsoft's trusted cloud infrastructure means that your data is encrypted and safeguarded, with compliance with international standards. Good to know Length of access: lifetime Redemption deadline: redeem your code within 7 days of purchase Access options: desktop Bound to account - Limited to one device activation at a time Only available to existing and new users Version: 2024 Updates included Click here to verify Microsoft partnership Microsoft Visio 2024 Professional for Windows normally costs $579.99, but it can be yours for just $39.97 for a limited time, that's a saving of $520 (90%). For terms, specifications, and license info please click the link below. Microsoft Visio 2024 Professional for Windows for $54.97 (was $579.99) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • I totally disagree. Very little good comes out of governments all around the world manipulating everything they can and usually the people are not the benefactors. What you say about being restricted and expensive sounds almost like the arguments against firearms and why banning them will protect people as if making something illegal somehow will prevent the criminals from having and using them. AI being far less mainstream could simply mean the average person will not benefit, but "big brother" and the corporations will benefit, which is almost for sure NOT a good thing.
    • I do apologize to the author Mr. Sen for my rude comment, questioning his knowledge of the subject. It is I whom lacked knowledge of the subject. Sorry!
    • Hello All Have a MSI Pro B650 VC Wifi Rev 1.0 motherboard Ryzen 7 7700X Radeon 7800XT OC 16GB 32GB Teamgroup DDR 5 5600mhz Samsung 990 Pro 1TB Boot NVMe Samsung 990 Pro 2TB Game NVMe Lian Li Lancool Black ARGB 216 Case Seasonic Focus GX 750 Watt Power supply   Wondering today what is best spot to plug in the following items on system for performance and not bottle neck anything if i can help it Creative Pebble Pro USB C or A Speakers, ((Powered by External USB C to C PD Adapter)  Logitech G513 USB Gaming Keyboard Logitech G502X Wired Gaming Mouse Cyberpower UPS USB Cable for UPS Power Management/System shutdown External drives connected occasionally are as follows---WD My Book 8TB (primary backup drive)   Seagate 8TB in External USB 3.0 Enclosure,  Seagate Portable 1TB USB 3.0 drive,   WD My Passport (Blue) 2TB, and WD My Passport (Red) 2TB,    WD Elements 500GB USB 2.0 External (Oldest one, Christmas 2003)       **Do have a 7 Port Powered  USB Hub as well, but when i use that--that leaves only the USB Flash spot for something to directly connect to system if needed.    Rear USB C 2x2 unused right now as moved the Creative speakers off it to USB A port next to it, with a USB C to A Cable, as figured speakers didn't near audio from USB C port and tie up the high speed port**   Front Ports trying to limit use of, so i don't have Front I/O port go bad again, already had it replaced once by Lian Li support all the way from Taiwan over night ((Do get extra nervous at times on things,  so i might just be extra nervous for nothing lol))
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      499
    2. 2
      +Edouard
      201
    3. 3
      PsYcHoKiLLa
      127
    4. 4
      Steven P.
      82
    5. 5
      ATLien_0
      77
  • Tell a friend

    Love Neowin? Tell a friend!