Mac hacked in 2 minutes


Recommended Posts

We a company called MSI in our hospital this week, doing security checks via DDOS attacks, etc on our network to see how secure we our, we run a strict MS network and so far they've managed to bring down 5 systems since Monday

Windows is scary.

Well i wasn?t saying that Windows is completely secure,by the other hand you say that only 5 systems has been compromised

Of how many?

In other instance the unknown is more scary,since OSX is unknown to security threats from the hacking and cracking community.Simply OSX isn?t designed for this payload.

Do you know why many hackers give propaganda to install linux or other non operating system?

Answer: Beacuse they know more possible vulnerabilites than Windows

You can take that for granted si:):)

We a company called MSI in our hospital this week, doing security checks via DDOS attacks, etc on our network to see how secure we our, we run a strict MS network and so far they've managed to bring down 5 systems since Monday

Windows is scary.

A DDOS will bring down anything.

Well i wasn?t saying that Windows is completely secure,by the other hand you say that only 5 systems has been compromised

Of how many?

In other instance the unknown is more scary,since OSX is unknown to security threats from the hacking and cracking community.Simply OSX isn?t designed for this payload.

Do you know why many hackers give propaganda to install linux or other non operating system?

Answer: Beacuse they know more possible vulnerabilites than Windows

You can take that for granted si:):)

If you could follow Bill gates around with a roll of toilet tissue you would huh?

agreed, but was meaning along the lines of they would have to be doing something other then just a DDOS to bypass the router/Gateway and hit the machine in question.

wouldnt a DDOS would bring the whole network down, not just an individual machine not touching the others ( when they said it brought down 5 systems since monday ) may be reading into his post to much though

Probably, so that would mean routers are scary, not Windows. :)
If you could follow Bill gates around with a roll of toilet tissue you would huh?

Nahh Microsoft has comitted various mistakes in my opinion

The only difference between you and me,is that i?m based on facts,given here in neowin in other threads.Obviously i prefer Windows because the broader range of applications that can be installed,this security topic is a plus given for my criteria.

If you want to talk about Microsoft and Apple zealots,who do you think has more ego,and kneels more in front of their desired system?

you asnwre is the Mac zealots,hated for that sole reason.

If you want to talk about Microsoft and Apple zealots,who do you think has more ego,and kneels more in front of their desired system?

you asnwre is the Mac zealots,hated for that sole reason.

id have to disagree and say Linux Zealots, lol, with Mac close behind, but Mac VS Windows, yea Mac

My sister wanted to get a Mac because she said she heard they were a hell of a lot more secure than windows. I set her straight...

What people do not realize is that Macs are not more secure that Windows. In fact, they can quit possibly be less secure. This article is proof of that. 2 minutes and the Mac was hacked. Hahaha...that is pathetic. And for all you Mac fanboys and people looking for flame bait, I said it is possible Macs can be less secure...not that they are.

People are getting in to a false sense of security with the Macs. Saying they dont need antivirus is a BIG mistake as there are viruses for Macs as well.

And it is all about the Market as well. If Macs control the majority of the market, they will be nailed left and right like a $2 hooker. Its that simple and its common sense. If Macs start to control more and more of the market, you can bet you will see them getting hacked.

*Edit* mistook the yellow Network cable as the older PPC Power cable

Here's a picture of Charlie (in the foreground) exploiting the MacBook Air from his own laptop, while Aaron from TippingPoint verifies the pwnage in real time.

charlie_miller.jpg

http://dvlabs.tippingpoint.com/blog/2008/0...er-with-picture

Edited by Hell-In-A-Handbasket
Macs are not more secure that Windows. In fact, they can quit possibly be less secure.

Wrong. Currently they are a lot more secure because there just aren't nowhere near as much real security threats circulating for Mac. Infact the number of those is close to ZERO.

Saying they dont need antivirus is a BIG mistake as there are viruses for Macs as well.

Have they ever spread very far or were able to do anything harmful?

And it is all about the Market as well. If Macs control the majority of the market, they will be nailed left and right like a $2 hooker. Its that simple and its common sense.

So if Vista will reach the marketshare XP has (won't happen :woot: ) it will be as unsecure as XP?

so those security updates on my Software Update are just bandwidth filler, i want my bandwidth back.

Wrong. Currently they are a lot more secure because there just aren't nowhere near as much real security threats circulating for Mac. Infact the number of those is close to ZERO.

I love my Mac dont get me wrong, but to say there are close to 0 threats is not true, there are threats, just notobody willing enough to put the effort to target a small user base,, heck this dude did it cause he wanted a new Macbook+10 Grand

because somewhere it said he did the iPhone jailbreak, he might have used the same exploit as iPhone/iPod ( im assuming the jailbreak is done by injecting code in the Safari TIFF exploit, last jailbreak i did was 1.1.1 iPod touch, but i had to Tiff crack it, then SSH the installer into it. dont know how its done now

Right :rolleyes: and Vista and UAC is bulletproof too.

UAC is bulletproof in the sense that it attempts to absolve Microsoft of any liability by giving them the out that THEY ASKED YOU if you wanted your computer hacked and you said yes, I think that is the only real function of UAC.

But yeah, Mac security sucks because Apple has never proactively tested it, they have no idea how, MS has been doing this for years out of necessity.

It was social engineering however so the cracking contest doesn't really count - this is no different than me putting up an iFrame vulnerability that exists in IE6/IE7 even today.

Anyone using MSN yesterday should be very aware how easy it's to blow up your IE because I kept getting messages from people asking me to click a certain link that opened an iframe and affects all IE6 and IE7 (Also Vista, because most of the people on the list who sent me the message were Vista users).

So you say you know a way to exploit a vulnerability in IE7 in such a way that UAC stops working and IE7 isn't in protected mode anymore? show me...

Now that's going to be fun to watch.

You see, one exploit in Safari has its good points. It provides discussion and fixes. Maybe not here on Neowin where this thread seems to have taken a turn towards the usual 'mine's bigger than yours' philosophy but good will come of this exploit and Mac users and probably any other OS user that uses Safari will benefit.

This is not a game of this is better than that, but one where every OS wins and long may these sort of competitions and events run. They will make our enjoyment of any OS and the internet a better experience in the long run.

would this work Buffer Overflow via Web Page lists FreeBSD as probably vunerable, because its via Nvidia Grafix driver, i dont think the Filesystem would make a diffrence as with the injected code you could have the OS do anything

there is also a proof of concept included

took me a 10 second search in google

*Edit* unknown if it will as its dated Oct 06, should have been fixed by now i would think

FreeBSD 8, ZFS. You have one day. :laugh:
Edited by Hell-In-A-Handbasket
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Same Internet Archive seemed to grab the new version https://web.archive.org/web/20...d/Setup_MakeMKV_v1.18.4.exe Here's the link to an additional file it periodically downloads https://web.archive.org/web/20260213092148/https://www.makemkv.com/sdf.bin I think update's keys, etc. To manually trigger this update, put the sdf.bin file in the root of where the program is installed. When you launch the program it will pick up the file and import it. Typically put it here: C:\Program Files (x86)\MakeMKV\sdf.bin
    • Windows 11 KB5094126, KB5093998 bugging out Office apps but it may not be Microsoft's fault by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. Although the tech giant did not acknowledge any major problems, some users online reported various issues ranging from OneDrive and Dropbox access problems, BitLocker recovery lockouts, to blue screens and BSODs. You can read about them in this dedicated piece. While there is still no confirmation about those problems from Microsoft the company has admitted to another bug which we did not report on. The tech giant has confirmed it has received reports of an issue in which certain third-party applications may be unable to launch Microsoft Office apps or open Office documents after installing the Patch Tuesday. This affects both Windows 11 as well as Windows 10. The company says the problem impacts a subset of applications that rely on OLE (Object Linking and Embedding) automation to communicate with Microsoft Office programs. According to Microsoft, affected scenarios involve third-party software attempting to open Office applications or documents from within their own interface. In such cases, the Office program may fail to launch altogether, or the requested document may not open. Oddly there may not be any error message, which probably makes the issue difficult to diagnose. The bug affects several Office products, including Word, Excel, PowerPoint, Access, and other apps in the Microsoft Office suite when they are launched through the affected software. These include tax and accounting software such as CCH Engagement and Workpaper Manager, dental practice management solutions like Dentrix and Softdent, as well as the popular research and reference management tool Zotero. Microsoft adds that other applications using similar Office integration methods could also experience the same problematic behavior. To understand the issue it is important to look at OLE, the Microsoft technology involved. OLE allows different applications to work together and share data, while its Automation feature lets one program control another. Thus this enables third-party software to launch Microsoft Office apps, open documents, and perform tasks automatically without requiring users to switch between programs. Because many accounting, healthcare, research, and business applications rely on OLE automation to interact with Word, Excel, PowerPoint, and other Office apps, any disruption can break those workflows. As a result, affected software may be unable to open Office documents or launch Office applications even though the programs themselves continue to work normally. At the moment the company has not provided a permanent fix though it has confirmed that engineers are actively working on a resolution, which will be delivered through a future Windows update. As such additional details will be shared once more information becomes available. In the meantime, Microsoft recommends a simple workaround for affected users whic is to open the Office application or document directly rather than launching it through the third-party program. For enterprise customers and organizations managing larger deployments, Microsoft says an additional mitigation is available. Admins experiencing the problem on their managed devices are advised to contact Microsoft Support for business to obtain and apply the workaround.
    • It saddens me when cars are such dull colours now. Mine is bright metallic blue and I absolutely adore it for standing out in contrast to that depressing backdrop of traffic.
    • Sparkle 2.20.0 by Razvan Serea Sparkle is a free, open-source Windows optimization tool designed to make your PC faster, cleaner, and more private. With Sparkle, you can easily debloat Windows by removing unnecessary apps and services, disable Microsoft tracking to enhance privacy, and apply performance tweaks to boost speed. Its cleaner removes junk and temporary files, while every change is safe and fully reversible. Sparkle also features a modern, user-friendly interface with automatic updates, making system maintenance simple. Explore over 39 tweaks, from disabling telemetry and hibernation to optimizing network and game settings, all aimed at customizing and enhancing your Windows experience. Sparkle supports Windows 10 and 11. Sparkle 2.20.0 changelog: Debloat Tweak has animated border New homepage loading UI New Tweak Modal (Markdown Supported) Refactored GPU Detection Added Tests with vitest Added foobar2000 to apps Added Localsend to apps Updated Modal Styles Added styles for disabled inputs Added Animated Border to debloat-windows tweak Bumped dependencies Refactor System info logic for speed Tweak info modals now support Markdown Added Clear System info cache to settings Redesigned Home Page Loading UI Changed Some Icons around the app Download: Sparkle 2.20.0 | Portable | ~100.0 MB (Open Source) Links: Sparkle Website | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • lol it was a typo, fixed! haha imagine an actual 4TB Gen4 NVMe for $40 in 2026
  • Recent Achievements

    • Reacting Well
      Dys Topia earned a badge
      Reacting Well
    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      106
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      68
  • Tell a friend

    Love Neowin? Tell a friend!