On Metacritic: How good is BioShock2?
BNET Business Network:
BNET
TechRepublic
ZDNet

March 3rd, 2009

Pwn2Own hacker: Apple Safari is 'easy pickings'

Posted by Ryan Naraine @ 9:05 am

Categories: Adobe, Apple, Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Firefox, Flash, Hackers, Microsoft, Mobile (In)Security, Mozilla, Patch Watch, Research, Reverse Engineering, Vulnerability research, Web Applications, iPhone

Tags: Apple Safari, Apple Inc., Hacker, Hacking, Smart Phones, Web Browsers, Security, Handhelds, Consumer Electronics, Personal Technology

Charlie Miller, the security researcher who won last year’s Pwn2Own hacker contest, is predicting that Apple’s Safari browser will be the easiest target this year.

In a note posted on the popular Daily Dave mailing list, Miller describes Safari as “easy pickin’s” and forecasts that at least four zero-day Safari flaws will be used during the contest at CanSecWest later this month.

[ SEE: Pwn2Own hacker contest targets browsers, smart phones ]

This year’s contest will pit hackers against browsers and smart phones with Internet Explorer, Firefox, Safari, Opera and Chrome among the high-profile targets.  It will also include attacks against fully patched BlackBerry, Android, iPhone, Symbian and Windows Mobile phones in their default configurations.

Here are Miller’s predictions:

  • Safari: hacked by 4 different people.  Easy pickin’s as usual.
  • Android: hacked by 1 person.  Not too tough but no one owns one.
  • IE8, Firefox: Survive unscathed.  The bugs to exploit equation is too hard for $5k.
  • iPhone, Symbian: Survive due to non-executable heap.
  • Blackberry, Windows Mobile, Chrome: I don’t know enough to say anything intelligent.  That said, they’re probably hard/obscure and so survive.

Last year, Miller exploited a Safari flaw to hijack a fully patched MacBook Pro machine.  He is also known for launching successful attacks against Apple’s iPhone and Google’s Android platform.

ALSO SEE: 10 questions for MacBook hacker Dino Dai Zovi

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 69 Talkback(s)
RE: Pwn2Own hacker: Apple Safari is 'easy pickings'
So it seems to me that we cant use Safari?
Mike the external hard drive dude.... (Read the rest)
Posted by: charismaseeker Posted on: 12/12/09 You are currently: a Guest | | Terms of Use
This would be the Charlie Miller  frgough | 03/03/09
That would the the vulnerability  honeymonster | 03/03/09
@honeymonster  Axsimulate | 03/03/09
An unfound exploit  LiquidLearner | 03/03/09
@LiquidLearner  Axsimulate | 03/03/09
I'm guessing you missed..  rtk | 03/03/09
@rtk  Axsimulate | 03/04/09
@rtk  nblackmarr@... | 03/04/09
Yeah, that's the one where they gave the domain admin...  hasta la Vista, bah-bie | 03/04/09
@nblackmarr  rtk | 03/04/09
@rtk  Axsimulate | 03/04/09
@Axsimulate  rtk | 03/04/09
You'll never get an straight answer, Axsimulate  hasta la Vista, bah-bie | 03/04/09
What's the numbers on Apple users  gkrwc | 03/04/09
@gkrwc  Axsimulate | 03/04/09
Blah Blah Blah  DannyO_0x98 | 03/03/09
Seems fair to me  rapson | 03/03/09
frgough now this is rich!!!  CrashPad | 03/04/09
Cheating?  rjacksix | 03/04/09
pwned complete  paul_bruford@... | 03/04/09
cheating?  aussieblnd@... | 03/04/09
This year  mjolnar@... | 03/04/09
There was no cheating. Otherwise he wouldn't have qualified...  ye | 03/03/09
nope, sorry.  rtk | 03/03/09
@rtk  lost65 | 03/05/09
....  Badgered | 03/05/09
@lost65  rtk | 03/05/09
Crackers never cheat.  NonZealot | 03/03/09
Hey NZ...  MGP2 | 03/03/09
No surprise  honeymonster | 03/04/09
That RDF...  tikigawd | 03/04/09
@honeymonster  Axsimulate | 03/04/09
Koolaid baby koolaid  CrashPad | 03/04/09
It's contagious  hasta la Vista, bah-bie | 03/04/09
Most mac owners are finacially well off. You have to be to afford one.  invmgr@... | 03/05/09
I hear ya  tikigawd | 03/05/09
@invmgr  Axsimulate | 03/05/09
Not Microsoft!  hasta la Vista, bah-bie | 03/05/09
@b8375629  Axsimulate | 03/06/09
I said "Most". If you pay cash for a new Mac, you're financially well off.  invmgr@... | 03/06/09
@ invmgr  Axsimulate | 03/06/09
 balaknair | 03/04/09
RE: Pwn2Own hacker: Apple Safari is 'easy pickings'  johnpall@... | 03/04/09
RE: Pwn2Own hacker: Apple Safari is 'easy pickings'  Sirgwain | 03/04/09
Actual Numbers  Jkirk3279 | 03/04/09
interesting...  David the Nerd | 03/04/09
Uhm, no  Jkirk3279 | 05/22/09
Why wasn't the exploit used?  nfhiggs@... | 03/04/09
Thief  Jkirk3279 | 05/22/09
Mac doesn't have the market share to be hacked  baileysc | 03/04/09
What better publicity...  User07734 | 03/04/09
It's your theory that's flawed.  rtk | 03/04/09
Too late  hasta la Vista, bah-bie | 03/04/09
Neutering User07734  PMC-CON | 03/04/09
In support ... Read The Ad-Ware Hacker Interview  PMC-CON | 03/04/09
Funny  Axsimulate | 03/05/09
Neutering Jkirk3279  PMC-CON | 03/04/09
Uh,  Axsimulate | 03/05/09
And...  Jkirk3279 | 05/22/09
It isn't their hardware.  mjolnar@... | 03/04/09
You do realize...  Jkirk3279 | 05/22/09
RE: Pwn2Own hacker: Apple Safari is 'easy pickings'  musician88 | 03/04/09
And yet it does not seem to be a problem for Safari users...  lundp@... | 03/04/09
RE: Pwn2Own hacker: Apple Safari is 'easy pickings'  tjalving | 03/04/09
RE: Pwn2Own hacker: Apple Safari is 'easy pickings'  penile@... | 03/04/09
Upstanding hackers never cheat! (nt)  viztor | 03/05/09
Have you applied your Mac OS security patches today?  Crash2100 | 03/06/09
RE: Pwn2Own hacker: Apple Safari is 'easy pickings'  bbonis@... | 03/17/09
RE: Pwn2Own hacker: Apple Safari is 'easy pickings'  charismaseeker | 12/12/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here