MacBook Air hacked within two minutes at expo
updated 11:55 am EDT, Fri March 28, 2008
Two-minute MB Air hack
The defenses of MacBook Air were hacked within moments in a recent security expo contest, reports say. During the CanSecWest conference's "PWN 2 OWN" competition, participants were expected to hack into one of three notebooks, and read the contents of a file using only an original zero-day attack. An award of $10,000 plus an Air is said to have gone to Charlie Miller, who broke into the computer within two minutes. This was accomplished by redirecting a web browser to a site with exploit code by Miller.
Under the terms of the competition, Miller cannot talk about the details of his exploit until the contest's sponsor notifies Apple, giving it a chance to rectify the problem. It is believed however that since the rules of the competition dictate relying on pre-installed software, the hack was directed through Apple's Safari software.
The speed of the hack is considered especially impressive given that last year, a break-in for the MacBook Pro required nine hours. At the end of Thursday's competition timeframe, two PC notebooks -- a Sony Vaio and Fujitsu U810 -- had yet to be cracked, according to observers.












woopsie!
03/28, 12:04pm reply
Racers, start yer security software bashing engines.
Flying Meat
Fresh-Faced Recruit
Joined: Jan 2007
Not entirely accurate
03/28, 12:13pm reply
The supposed hack was on the second day of the challenge which isn't mentioned by MacNN. Not a single attendee entered the contest on day one, when all vulnerabilities had to reside in the machine's operating system, drivers or network stack. On day two, the attack surface was expanded to include browsers, mail applications and other common applications.
He exploited a bug in Safari. Nothing says this guy didn't find the exploit in Safari before going. Does this exploit affect firefox also?
t6hawk
Dedicated MacNNer
Joined: Jan 2001
Ah, not 2 minutes
03/28, 12:20pm reply
What the article does not point out is that on the first 24-hours of the contest, the contestants were suppose to do an attack on the Mac remotely via the network alone.
No one could hack the Mac remotely via the network alone.
The second day, they relaxed the rules and allowed the contestants physical access to the Mac so that they could install an automated user to receive emails or use a browser to go to a malicious website set up by the contestant.
Duh.
It took more than 24-hours to hack the Mac. It takes days to program an automated user or develop and program a malicious website. They had to do the work even before the contest.
And it took physical access to the computer to hack it. They could not hack it over the network at all!
Thus the contest is a crock.
I doubt any user will allow a crook or stranger physical access to their personal computer. Once a person has physical access to a computer then any computer can be hacked. Through the firewire ports, any Windows computer is instantly compromised, for example.
James Katt
Fresh-Faced Recruit
Joined: Mar 2008
I doubt
03/28, 12:30pm reply
anyone would click on a malicious link?
I agree this was a bit unlikely, but people do leave their machines on and unattended. People do click on what used to be a benign link. People do (sadly) click links in unsolicited email messages, and/or allow images to be displayed in their email messages automatically,..
I smelled something fishy with this when it was pointed out that the hack was a browser redirect/malicious link dealie. Someone had to be using the machine and directed to click said link. It wasn't an "unattended" machine being hacked.
Flying Meat
Fresh-Faced Recruit
Joined: Jan 2007
Any others?
03/28, 12:32pm reply
Were any Windows or Linux machines hacked on Day 1? Also, on day 2, were any Windows or Linux machines hacked before the Mac?
Answers to these questions are the interesting bit.
mr.mouse
Fresh-Faced Recruit
Joined: Feb 2008
yeah
03/28, 12:34pm reply
So...he had to use the browser to do it? Use the OS then get back to me with any serious claims of security flaws etc. with OS X.
manleycreative
Fresh-Faced Recruit
Joined: Sep 2005
Final Rule
03/28, 12:38pm reply
So, the final rule is that if I click on a bogus link or I allow somebody on my machine to have complete access while I'm away, I'm a good candidate for a break in. Well, that's good to know....
jameshays
Fresh-Faced Recruit
Joined: Mar 2003
Social Engineering hack
03/28, 12:39pm reply
More accurately. This took a user visiting a malicious or compromised site to work. Though no matter what version of Safari you are using, etc., this definitely has to be addressed by Apple, and it is. A lot of viruses, trojans, etc. are spread through socially engineered methods and so in my book are completely valid concerns. Obviously Mac OS X Leopard is much more secure than Windows at any level, but Apple really needs to be on top of releasing security patches quickly to show it's users that they take these matters seriously. ANd yeah, like te others have posted, this 'hack' did NOT take 2 minutes to craft. Execute, maybe, but not craft. There is a BIG difference.
mgpalma
Fresh-Faced Recruit
Joined: Sep 2000
Re: yeah
03/28, 12:39pm reply
Was it not an Apple browser? Safari?
Security issues on modern systems are often triggered by user behaviour. Some of the more virulent attacks in the past (usually on Windows) have been links in emails, or attachment that have been opened by users.
Therefore, if all systems passed an external attack (day 1), but a boxed Mac (running OS X, Apple Safari and any other Apple bundled software) fell over before a standard Windows install (with the bundled IE, etc.) or a Linux Distro, then I would argue the the Apple kit failed RELATIVE to Windows and Linux.
This is not good news for me, as an OS X user, that my machine is less secure that my wife's Windows laptop, despite the Apple rhetoric about how secure their systems are compared to Windows. Not good at all.
mr.mouse
Fresh-Faced Recruit
Joined: Feb 2008
What Version of Safari
03/28, 12:39pm reply
What Version of Safari was installed?
designr
Fresh-Faced Recruit
Joined: Apr 2002