Mac hacked in 2 minutes


Recommended Posts

the cracking contest doesn't really count

This is exactly the response I would expect from Steve Jobs because I think he honestly believes his gadgets are invincible, even with proof thrown in his face. Poor guy.

Back to reality now...

I hope this demonstrates to everyone who fell for Apple's hype and perhaps opens their eyes to the FACT that Macs are designed and programmed by humans. They are subject to human error and can never, ever be 100% perfect. This goes for any other hardware or software out there. No one should expect it and no one should promise it.

You might want to be a little careful with those claims.

Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

If it's more secure, why was it the first one hacked out of 2 Windows laptops and a MacBook? And that's exactly what the article is about.

Maybe he just wanted a macbook air for free?

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network
He was the first contestant to attempt an attack on any of the systems.

:huh:

Also, how do you measure the time it took him to hack it? It's just the time from the start of the contest? Does it count the time it took him to set up the web page? Or all the previous research?

Edited by ichi
Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

well put.

More to the point, rather than bashing Apple for having a computer than be be exploited by a person with physical access to it, (very very very very few workstations will not be exploitable) shouldn't we be lauding the guy who did it as a genius?

bloody fanboy threads! :)

true, but i think alot of exploits are with 3rd party software, like MS. but MS has more as there is more 3rd party software available making holes

Actually, the claims appear to be valid. Microsoft did a tremendous amount of security work in the past few years. The number of exploits in MS products since they started rolling out in 2005 are quite low. On the other hand Apple seems to be patching more lately, and their number of unpatched exploits is slowly creeping up.

agreed, but genius would be to much i feel, more along the lines of "knows his stuff"

well put.

More to the point, rather than bashing Apple for having a computer than be be exploited by a person with physical access to it, (very very very very few workstations will not be exploitable) shouldn't we be lauding the guy who did it as a genius?

bloody fanboy threads!

It was social engineering however so the cracking contest doesn't really count - this is no different than me putting up an iFrame vulnerability that exists in IE6/IE7 even today.

99% of all hacks are via social engineering. There is no difference between tricking someone on the phone into believing you're with the IT department and need their password and tricking them into going to a web site that isn't what they expected.

Anyone using MSN yesterday should be very aware how easy it's to blow up your IE because I kept getting messages from people asking me to click a certain link that opened an iframe and affects all IE6 and IE7 (Also Vista, because most of the people on the list who sent me the message were Vista users).

Erm... "Open an IFrame?" It's part of a web page. an IFrame is simply a frame that isn't anchored to a page edge and may therefore be obfuscated. (Like overlaying a fake forum menu on top of the real one.)

I have to admit I'm glad to see this. To many times Apple (not all) users delude themselves and act as if Apple is the savior or something when it is really just the same <snipped> different pile

Edited by John S.
circumvention of swear filter
but then all the macusers couldnt say "hey i dont need antivirus, im on a mac"

Circaflex,

Contray to popular belief not all of us Mac users think like that or even consider that to be the case. Many of us are actually quite security conscious. I run antivirus to protect myself, as well as to prevent myself from inadvertantly sending nasties off to my PC using friends.

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

You have to be on the same network as the machine, and have the Admin password to do that...

there was more involved then going to a site

and your reply to the windows PC, is actually true, it was done in my Security Class before i graduated, just like i also used the MMC to remotely connect to a machine across the classroom and edited their registry(entrys in MMC go to registry) to lock their startmenu, edit permissions. and at a LAN party as a practical joke, inserted a couple porn vid's to a friends startup. if i have physical access to it but its locked, i can BART it, remove the PW, load the registry into BART Edit that, and do whatever else to the system

there is no Bull***, its fact as iv done it, my job requires me to break into a system @ customers request, or recover files/information if they can no longer access their computer

You need to stop posting and read the article.

"Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on."

ALSO

"Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser."

There was NOT more involved than visiting a web site.

And as for your security experiences, it's getting more fanciful every time, so I just don't believe a word of it now.

Edited by GreyWolfSC

you missed where i said "connect to a machine across the classroom"

and all passwords can be bypassed, or gotten

You have to be on the same network as the machine, and have the Admin password to do that...
Maybe he just wanted a macbook air for free?

:huh:

Also, how do you measure the time it took him to hack it? It's just the time from the start of the contest? Does it count the time it took him to set up the web page? Or all the previous research?

What he wanted makes no difference in whether the exploit happened or how long it took. And I think measuring it from "go" to the hack working is fair. How would you measure time for a real exploit? From the time that the user encounters it to the time that access is obtained, of course.

i would post my CompTia Cert's, but because i would block out the comp001003****** CareerID number as well as my name and date validated, it would jsut be the same as posting a random pic of a cert, just with more numbers

And as for your security experiences, it's getting more fanciful every time, so I just don't believe a word of it now.
i would post my CompTia Cert's, but because i would block out the comp001003****** CareerID number as well as my name and date validated, it would jsut be the same as posting a random pic of a cert, just with more numbers

Wouldn't help. I know people that have Bachelors in Computer Science that can hardly even use a computer.

you can get an A+ and can barely use a computer as that test was easy, the MS and above A+ actually require some thought, tests for MCSE where a pain when i took them 3-4 years ago

why i went with Certs instead of Computer Science, because iv experienced same people that your talking about, and alot of companies view Certs over Computer Science Degree, heck my Interview for MS ( Contractor in Reston VA for Network Engineer) main thing they asked about were my Cert's and RAID50 ( Mainly just asked if i was MCSE or could be in 3 months), didnt even ask once about a degree

but you got it in your head that i supposedly don't know squat, and im shure nothing will change that

Wouldn't help. I know people that have Bachelors in Computer Science that can hardly even use a computer.

*Edit* because i have a feelign it will come up, just because i had an interview, i do not work for MS, i don't like to sit behind a desk, it sucked @ DoE in Germantown, im pretty shure it still does.

Edited by Hell-In-A-Handbasket

agreed

ive been saying this for a while, as apples user base increases, more and more hackers will divert their attention towards macs. its only a matter of time before even more exploits are found. plain and simple.
market share has nothing to do with vunerabilities,the holes are there regardless of how many use a system

Well that assumption isn?t correct,can you explain why OSX had a surge in vulnerabilities the last 2 years? (aprox)

Obviosuly the OS has evolved since,but evolved negatively or positively? i have no doubt that has evolved in a positive manner,however the switching to the x86 architecture,the introduction of new features not related to designers,and the increasing user base,this bring a whole new choices of configurations in every system.

This reason make me belive that OSX is entering a dangerous era,in few words OSX isnt a Multistellar OS,and this transision will cause a lot of damage,this menas that apple has no idea in wich terrain is entering,competing with an expierenced and dominant Windows,that has been testes and tested by hundreds of million people all over the world,with i may say infinite configurations,and this is the day that winows still has problems with drivers from many manufacturers.

Apple proposed this chanllenge

and Microsoft says ?bring it on?

My opinion, if a human makes it, there is always another human who can break it. Whether it's Linux, Windows or OS X. So, I see no surprise in this. P.S. that guy already had hacked the iPhone last year, which runs the same browser, so no wonder he did it in 2 minutes.

P.S. Why are there 2 thread on the same topic?? This is the other one:

https://www.neowin.net/forum/index.php?show...628158&st=0

Well that assumption isn?t correct,can you explain why OSX had a surge in vulnerabilities the last 2 years? (aprox)

Obviosuly the OS has evolved since,but evolved negatively or positively? i have no doubt that has evolved in a positive manner,however the switching to the x86 architecture,the introduction of new features not related to designers,and the increasing user base,this bring a whole new choices of configurations in every system.

This reason make me belive that OSX is entering a dangerous era,in few words OSX isnt a Multistellar OS,and this transision will cause a lot of damage,this menas that apple has no idea in wich terrain is entering,competing with an expierenced and dominant Windows,that has been testes and tested by hundreds of million people all over the world,with i may say infinite configurations,and this is the day that winows still has problems with drivers from many manufacturers.

Apple proposed this chanllenge

and Microsoft says ?bring it on?

We a company called MSI in our hospital this week, doing security checks via DDOS attacks, etc on our network to see how secure we our, we run a strict MS network and so far they've managed to bring down 5 systems since Monday

Windows is scary.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • A few years ago walmart had the 512 models on clearance for $35. I bought 3 of them. I should have purchased more.
    • I'm fine with a little reasonable promotion of Edge, but the degree which they do it right now I consider extremely unreasonable. 
    • Microsoft AI boss no longer believes that AI will replace human workers by David Uzondu Mustafa Suleyman, the head of Microsoft AI, recently took back his statements concerning white-collar jobs that he gave to the Financial Times in an interview made back in February, where he claimed that AI would replace office workers within 12 to 18 months. On Monday's episode of The Verge's Decoder, Suleyman recast the technology as more like a helpmate than a tool designed to take over your job. He explained that smaller office duties will "increasingly become digitized, automated" as people generate more digital materials. During the discussion, Suleyman emphasized a "very important distinction" between "tasks" and "jobs" to clarify his previous claims. He argued that his earlier comments only referred to individual actions that people perform at their desks. Suleyman used to work for DeepMind, the research lab he co-founded in 2010 alongside Demis Hassabis and Shane Legg, before he left in 2022 to establish Inflection AI and build an empathetic digital assistant. Microsoft hired him in March 2024 to lead its newly formed "Microsoft AI" division, placing him in charge of consumer products like Copilot, Bing, and Edge. His February comments also detailed plans for Microsoft to achieve self-sufficiency with a $140 billion infrastructure budget to train frontier models, predicting that creating a customized AI will soon feel like creating a podcast or a new blog: The 41-year-old is not the only AI executive who's softened his "AI will replace you" stance. OpenAI's CEO, Sam Altman, last month used X to push back against employment panic by arguing that his startup builds tools to assist humans rather than build replacements. He had previously garnered backlash by suggesting that many modern office roles that AI might replace did not qualify as "real work" in the first place, at least when you compare desk jobs to physical, historical labor like farming.
    • Adobe Acrobat Reader DC 2026.001.21662 by Razvan Serea Adobe Acrobat Reader DC software is the free, trusted standard for viewing, printing, signing, and annotating PDFs. Its the only PDF viewer that can open and interact with all types of PDF content – including forms and multimedia. It’s connected to Adobe Document Cloud – so you can work with PDFs on computers and mobile devices. Adobe Document Cloud is a revolutionary, modern and efficient way to get work done with documents in the office, at home or on-the-go. At the heart of Document Cloud is the all-new Adobe Acrobat DC, which will take e-signatures mainstream by delivering free e-signing with every individual subscription. Document Cloud includes a set of integrated services that use a consistent online profile and personal document hub. With Adobe Document Cloud, people will be able to create, review, approve, sign and track documents whether on a desktop or mobile device. Businesses will be able to take advantage of Document Cloud for enterprise which provides enterprise-class document services that integrate into systems of record such as CRM, HCM, CLM, and CMS, adding speed, efficiency and transparency to getting business done with documents. Adobe Acrobat Reader DC new feature highlights: Work with PDFs from anywhere with the new, free Acrobat DC mobile app for Android or iOS. Select functionality is also available on Windows Phone. Use the new Fill & Sign tool in your desktop software to complete PDF forms fast with smart autofill. Download the free Adobe Fill & Sign mobile app to add the same option to your iPad or Android tablet device. Save money on ink and toner when printing from your Windows PC. Store and access files in Adobe Document Cloud with 5GB of free storage. Get instant access to recent files across desktop, web, and mobile devices with Mobile Link. Sync your Fill & Sign autofill collection across desktop, web, and iPad devices. Adobe PDF Pack premium features includes: Convert documents and images to PDF files. Use your mobile device camera to take a picture of a paper document or form and convert it to PDF. Turn PDFs into editable Microsoft Word, Excel, PowerPoint, or RTF files. Combine multiple files into a single PDF (web only). Get signatures from others with a complete e-signature service. Send, track, and confirm delivery of documents electronically instead of using fax or overnight services (tracking not available on mobile). Store and access files online with 20GB of storage. Download: Adobe Acrobat Reader DC 64-bit | 719.0 MB (Freeware) Link: Adobe Acrobat Reader DC Home Page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Meta will now use data from outside businesses to personalize AI responses by David Uzondu In an update that's rolling out globally (except in a handful of countries), Meta will use your data from outside businesses to personalize your AI responses and your primary feeds. Meta already utilizes your shopping activity to target ads, but the company now plans to expand this tracking to personalize other "parts of your experience" like feed algorithms and AI assistant chats. The company is replacing the two settings ("Your activity off Meta technologies" and "Activity from other businesses") that currently let you disconnect off-platform activity with a single, renamed setting called Activity from other businesses. If you don't want Meta to manipulate your feed and AI responses using your outside history, you can just turn the Activity from other businesses setting off in your account settings. This toggle resides within your Accounts Center, applying your choice to every connected profile. Turning this off will not stop companies from sending your data to Meta. The company will still collect your web interactions, but it only uses them to train products, while still accessing external accounts you connect. When The Verge spoke to Meta spokesperson Emil Vazquez, the representative said that this update will exclude several locations at launch, including the European region, the UK, Brazil, Thailand, South Africa, Turkey, South Korea, Ecuador, Nigeria, and Kenya. The new update comes at a time when the social media giant is recovering from a major PR disaster involving generative AI. Last week, there was a huge security issue on Instagram where attackers figured out a way to trick Meta AI into handing over account ownership (even if the victim had 2FA enabled). Some of the affected accounts include the dormant Obama White House profile, cosmetics brand Sephora, the Chief Master Sergeant of the Space Force, and security researcher Jane Manchun Wong. Internally, the company also had to scale back plans on its Model Capability Initiative (MCI), an employee-monitoring program designed to train corporate AI models by recording worker keystrokes and screen activity, after employees raised privacy concerns and complained about severe battery life drain.
  • Recent Achievements

    • One Year In
      Primer1st earned a badge
      One Year In
    • Experienced
      JayZJay went up a rank
      Experienced
    • Reacting Well
      Sir_Timbit earned a badge
      Reacting Well
    • Week One Done
      rubentuben8 earned a badge
      Week One Done
    • Week One Done
      ARaclen earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      512
    2. 2
      PsYcHoKiLLa
      229
    3. 3
      Edouard
      134
    4. 4
      ATLien_0
      87
    5. 5
      Steven P.
      80
  • Tell a friend

    Love Neowin? Tell a friend!