On mySimon: Forty Years on Abbey Road
BNET Business Network:
BNET
TechRepublic
ZDNet

April 23rd, 2007

Safari vulnerability exposed in MacBook Pro hacking contest

Posted by Jason D. O'Grady @ 6:52 am

Categories: Hack, MacBook Pro, Security

Tags:

If you bought a Mac because you thought that it was an impenetrable fortress immune from being hacked, you may want to think again.

Hackers Dino Dai Zovi and Shane Macaulay were able to hijack a MacBook Pro as part of the "PWN to OWN" contest at the CanSecWest security conference in Vancouver, British Columbia.

From the conference Web site

We've announced that we will be having a contest "PWN to OWN" where two, pimp, loaded up, Apple Macbook Pro's will be set up on their own AP (with security updates but otherwise default) and attendees will be able to connect to the ethernet or WiFi. The first to exploit it (there are victory conditions, and progressive rules over the three days) gets to go home with it. (Limit one per person, Can't use the same vuln on both.) If they survive the three days in the "jungle," they become prizes for best lightning talk and best speaker.

The duo was only successful after the contest rules were relaxed after nobody had breached either of the Macs on the first day. Dai Zovi found the Safari vulnerability and wrote the exploit overnight in about 9 hours, he said. News.com's Joris Evers quoted Dai Zovi in a telephone interview from New York as saying "The vulnerability and the exploit are mine… Shane is my man on the ground."

Macaulay will take home the loaded MacBook Pro while Dai Zovi has his eye on a larger prize. He plans to apply for TippingPoint's Zero Day Initiative bug bounty program which is offering a US$10,000 prize for a previously unknown Apple bug.

Apple isn't saying anything about the exploit but you can probably expect another security update to address the Safari vulnerability in the coming weeks. 

Jason D. O'GradyJason D. O'Grady is the editor of PowerPage.org, which has been publishing daily mobile technology news since December 1995. For disclosures on Jason's industry affiliations, click here or to view Jason's full profile click here.

Email Jason D. O'Grady

Subscribe to The Apple Core via Email alerts or RSS.

  • Talkback
  • Most Recent of 30 Talkback(s)
Old Yeller would be an excellent name for you Tic.
"What ad is entirely truthful? Parse the exact wording of any Apple ad and you'll find that they are literally truthful, but they imply things that may or may not be true.

They imply a l... (Read the rest)
Posted by: Scrat Posted on: 04/25/07 You are currently: a Guest | | Terms of Use
couple things to note  rwahrens1952 | 04/23/07
Also note  tic swayback | 04/23/07
So a drive-by install then. I thought Macs didn't suffer those...  Scrat | 04/23/07
no reason to get snarky  rwahrens1952 | 04/23/07
You can secure anything if you don't use it  Imaginos1892 | 04/23/07
safe enough  rwahrens1952 | 04/23/07
Funny, isn't it?  NonZealot | 04/23/07
No  rwahrens1952 | 04/23/07
Pre Vista, no, not funny  TripleII | 04/23/07
Pre-Vista no longer counts when...  ye | 04/23/07
When you are wrong, you are wrong  TripleII | 04/23/07
Triplell: Read up about it  NonZealot | 04/23/07
Since XP is still available..  msalzberg | 04/23/07
Tis I've run XP as a limited user for years...  toadlife | 04/24/07
Twice as much?  ewelch | 04/24/07
To quoque strawmen  frgough | 04/23/07
OS X has more than one vulnerability.  ye | 04/23/07
look back  rwahrens1952 | 04/23/07
I smell Bu.......  Scrat | 04/23/07
Who ever said that?  tic swayback | 04/23/07
Raw nerve?  Scrat | 04/23/07
Naive  ewelch | 04/24/07
Not naive enough to buy into the Mac security BS though (NT)  Scrat | 04/25/07
Don't mistake laughter for "raw nerves"  tic swayback | 04/24/07
Old Yeller would be an excellent name for you Tic.  Scrat | 04/25/07
Thanks for the info  TripleII | 04/23/07
Button Mixup, for NonZealot  TripleII | 04/23/07
Java Vulnerability, not Safari  V-Train | 04/23/07
Try no-script extension  phatkat | 04/23/07
Victory, huh?  Swift48 | 04/24/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here