apple news/media reports

03/07/2006, 9:40am, EST

Tuesday, March 7th

Mac OS X Security Challenge launches

A new Mac OS X Security Challenge has emerged, following a report that one user was able to hack into Mac OS X within 30 minutes. Created in direct response to the "woefully misleading ZDnet article," the challenge ends on March 10 and offers no prize. The creators of the new challenge say that the reports on the previous Mac OS X Hack failed to mention an extremely important factor--that users were given an SSH account on the box. The ZDnet article, first referenced by MacNN yesterday, has since been updated to note that user were given local accounts. Some, however, have objected to the challenge, saying that it is merely a test of Apache and SSH on PowerPC-based Mac; however, Dave Schroeder, the contest creator, says that "that is how most of the world will see Mac OS X externally."

"Anyone who wished it was given a local account on the machine (which could be accessed via ssh). Yes, there are local privilege escalation vulnerabilities; likely some that are 'unpublished'. But this machine was not hacked from the outside just by being on the Internet. It was hacked from within, by someone who was allowed to have a local account on the box. That is a huge distinction."

Local accounts could allow hackers to exploit many 'unpublished' (as noted by the "gwerdna" hacker) and older known security vulnerabilities that Apple has not yet addressed. However, most users will not offer hackers these accounts, thus dramatically distorted the overall security picture of Mac OS X, according to Schroeder.

The challenge invites hackers to alter the web page at test.doit.wisc.edu, hosted on PowerPC-based Mac mini running Mac OS X 10.4.5 with Security Update 2006-001 and two local accounts; the creators note that the machine has both SSH and http ports open, which is "a lot more than most Mac OS X machines will ever have open."


Filed under: Apple

, , 4comments, del.icio.us, slashdot, digg, buzz


4 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Outrageous
0
03/07, 10:41am, EST
ZDNet should be forced to publish a public apology and retraction.

If I were Jobs, I'd have my lawyers all OVER their ass, both in order to extract said retraction AND to send a message that other companies who have a *vested interest* in making the Mac look as bad on security as PCs had better not try CHEATING as a method to making the Mac look bad.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
One Question
0
03/07, 11:19am, EST
Where's gweirdnuts now? It's been way more than 30 minutes ...
Fresh-Faced Recruit
Joined Feb 2005
User is offline
Re: outrageous
0
03/07, 11:44am, EST
ZDNet should be forced to publish a public apology and retraction.

Oh, please. They publish crap on-line. If we're going to force ZDNet to publish apologies, they'll be spending all their time just trying to keep up with Dvorak's crap. And then all web-sites would be forced to post apologies because they all post crap

(Wait, a news organization using sensationalism to push sales. Man, when did that start happening in the world???)
Fresh-Faced Recruit
Joined Aug 2001
User is offline
uh...
0
03/07, 12:17pm, EST
Wait - "most users will not offer hackers these accounts"???? Since when did everyone stop offering hackers ssh accounts on their machines??!?!?!
Fresh-Faced Recruit
Joined May 2004
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News

Convert PDF to Word: Easily Convert PDF to Word Doc, Excel, and More. Fast and Accurate. No Registration Trial

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

Get an IT Degree Online: Get solid credentials. Take your hobby to the next level. Adult Programs. Affordable.

Convert PDF to Word: Easily Convert PDF to Word Doc, Excel, and More. Fast and Accurate. No Registration Trial

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.