Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Community > MacNN Lounge > 1 of 2 MacBook Pros hacked at security conference.

1 of 2 MacBook Pros hacked at security conference.
Thread Tools
Clinically Insane
Join Date: Dec 1999
Status: Offline
Reply With Quote
Apr 24, 2007, 11:36 AM
 
� 10 questions for MacBook hacker Dino Dai Zovi | Zero Day | ZDNet.com

At the CanSecWest conference in Vancouver, Canada, they set up 2 MacBook Pros (one 15" and one 17") plus $10,000 to anyone who can hack the computers. Over three days, they laxed the security each day allowing security experts to try and break into the two computers.

One of the computers, a 15" MacBook Pro, was indeed hacked through a newly discovered JavaScript exploit through the Safari browser. However, the hacker only had user-level access. He couldn't get root access and couldn't modify any other user or system files because he didn't actually know any passwords.

He still won the prize for hacking the 15" MacBook Pro (which included the computer itself plus $10,000.) The 17" MacBook Pro required the user to get root access (not just any access) and all attempts were unsuccessful.

I think that was a pretty successful test. Even the computer that was cracked didn't pose a threat to even other users on the same computer. Kudos to the hacker, though, he did manage a browser based exploit that could've lead to identity theft of some sort.
"…I contend that we are both atheists. I just believe in one fewer god than
you do. When you understand why you dismiss all the other possible gods,
you will understand why I dismiss yours." - Stephen F. Roberts
     
Addicted to MacNN
Join Date: Aug 2004
Location: FFM
Status: Offline
Reply With Quote
Apr 24, 2007, 11:46 AM
 
Originally Posted by olePigeon View Post
[url=http://blogs.zdnet.com/security/?p=176]Even the computer that was cracked didn't pose a threat to even other users on the same computer.
That's cold comfort if you are the one user who got hacked.
     
Clinically Insane
Join Date: Dec 1999
Status: Offline
Reply With Quote
Apr 24, 2007, 11:51 AM
 
Originally Posted by TETENAL View Post
That's cold comfort if you are the one user who got hacked.
Yes, but if it were Windows, the entire computer would be at risk.
"…I contend that we are both atheists. I just believe in one fewer god than
you do. When you understand why you dismiss all the other possible gods,
you will understand why I dismiss yours." - Stephen F. Roberts
     
Addicted to MacNN
Join Date: Mar 2006
Location: California
Status: Offline
Reply With Quote
Apr 24, 2007, 03:17 PM
 
so the prizes are a hacked computer and monies? ....nice
     
Clinically Insane
Join Date: Oct 2001
Location: San Diego, CA, USA
Status: Offline
Reply With Quote
Apr 24, 2007, 03:55 PM
 
Most reports state that it's a Java exploit, not a JavaScript exploit.
Chuck
___
"Instead of either 'multi-talented' or 'multitalented' use 'bisexual'."
     
Professional Poster
Join Date: Jun 2006
Location: "Working"
Status: Offline
Reply With Quote
Apr 24, 2007, 04:24 PM
 
Originally Posted by brassplayersrock View Post
so the prizes are a hacked computer and monies? ....nice
No, just one money.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 03:51 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2