Text Size

MacBook Air hacked within two minutes at expo

updated 11:55 am EDT, Fri March 28, 2008

Two-minute MB Air hack

The defenses of MacBook Air were hacked within moments in a recent security expo contest, reports say. During the CanSecWest conference's "PWN 2 OWN" competition, participants were expected to hack into one of three notebooks, and read the contents of a file using only an original zero-day attack. An award of $10,000 plus an Air is said to have gone to Charlie Miller, who broke into the computer within two minutes. This was accomplished by redirecting a web browser to a site with exploit code by Miller.

Under the terms of the competition, Miller cannot talk about the details of his exploit until the contest's sponsor notifies Apple, giving it a chance to rectify the problem. It is believed however that since the rules of the competition dictate relying on pre-installed software, the hack was directed through Apple's Safari software.

The speed of the hack is considered especially impressive given that last year, a break-in for the MacBook Pro required nine hours. At the end of Thursday's competition timeframe, two PC notebooks -- a Sony Vaio and Fujitsu U810 -- had yet to be cracked, according to observers.

 
Previous Comments

woopsie!

03/28, 12:04pm reply

Racers, start yer security software bashing engines.

Flying Meat

Fresh-Faced Recruit

Joined: Jan 2007

0

Not entirely accurate

03/28, 12:13pm reply

The supposed hack was on the second day of the challenge which isn't mentioned by MacNN. Not a single attendee entered the contest on day one, when all vulnerabilities had to reside in the machine's operating system, drivers or network stack. On day two, the attack surface was expanded to include browsers, mail applications and other common applications.

He exploited a bug in Safari. Nothing says this guy didn't find the exploit in Safari before going. Does this exploit affect firefox also?

t6hawk

Dedicated MacNNer

Joined: Jan 2001

0

Ah, not 2 minutes

03/28, 12:20pm reply

What the article does not point out is that on the first 24-hours of the contest, the contestants were suppose to do an attack on the Mac remotely via the network alone.

No one could hack the Mac remotely via the network alone.

The second day, they relaxed the rules and allowed the contestants physical access to the Mac so that they could install an automated user to receive emails or use a browser to go to a malicious website set up by the contestant.

Duh.

It took more than 24-hours to hack the Mac. It takes days to program an automated user or develop and program a malicious website. They had to do the work even before the contest.

And it took physical access to the computer to hack it. They could not hack it over the network at all!

Thus the contest is a crock.

I doubt any user will allow a crook or stranger physical access to their personal computer. Once a person has physical access to a computer then any computer can be hacked. Through the firewire ports, any Windows computer is instantly compromised, for example.

James Katt

Fresh-Faced Recruit

Joined: Mar 2008

0

I doubt

03/28, 12:30pm reply

anyone would click on a malicious link?

I agree this was a bit unlikely, but people do leave their machines on and unattended. People do click on what used to be a benign link. People do (sadly) click links in unsolicited email messages, and/or allow images to be displayed in their email messages automatically,..

I smelled something fishy with this when it was pointed out that the hack was a browser redirect/malicious link dealie. Someone had to be using the machine and directed to click said link. It wasn't an "unattended" machine being hacked.

Flying Meat

Fresh-Faced Recruit

Joined: Jan 2007

0

Any others?

03/28, 12:32pm reply

Were any Windows or Linux machines hacked on Day 1? Also, on day 2, were any Windows or Linux machines hacked before the Mac?

Answers to these questions are the interesting bit.

mr.mouse

Fresh-Faced Recruit

Joined: Feb 2008

0

yeah

03/28, 12:34pm reply

So...he had to use the browser to do it? Use the OS then get back to me with any serious claims of security flaws etc. with OS X.

manleycreative

Fresh-Faced Recruit

Joined: Sep 2005

0

Final Rule

03/28, 12:38pm reply

So, the final rule is that if I click on a bogus link or I allow somebody on my machine to have complete access while I'm away, I'm a good candidate for a break in. Well, that's good to know....

jameshays

Fresh-Faced Recruit

Joined: Mar 2003

0

Social Engineering hack

03/28, 12:39pm reply

More accurately. This took a user visiting a malicious or compromised site to work. Though no matter what version of Safari you are using, etc., this definitely has to be addressed by Apple, and it is. A lot of viruses, trojans, etc. are spread through socially engineered methods and so in my book are completely valid concerns. Obviously Mac OS X Leopard is much more secure than Windows at any level, but Apple really needs to be on top of releasing security patches quickly to show it's users that they take these matters seriously. ANd yeah, like te others have posted, this 'hack' did NOT take 2 minutes to craft. Execute, maybe, but not craft. There is a BIG difference.

mgpalma

Fresh-Faced Recruit

Joined: Sep 2000

0

Re: yeah

03/28, 12:39pm reply

Was it not an Apple browser? Safari?

Security issues on modern systems are often triggered by user behaviour. Some of the more virulent attacks in the past (usually on Windows) have been links in emails, or attachment that have been opened by users.

Therefore, if all systems passed an external attack (day 1), but a boxed Mac (running OS X, Apple Safari and any other Apple bundled software) fell over before a standard Windows install (with the bundled IE, etc.) or a Linux Distro, then I would argue the the Apple kit failed RELATIVE to Windows and Linux.

This is not good news for me, as an OS X user, that my machine is less secure that my wife's Windows laptop, despite the Apple rhetoric about how secure their systems are compared to Windows. Not good at all.

mr.mouse

Fresh-Faced Recruit

Joined: Feb 2008

0

What Version of Safari

03/28, 12:39pm reply

What Version of Safari was installed?

designr

Fresh-Faced Recruit

Joined: Apr 2002

0

Popular News