Disease Posted March 28, 2008 Posted March 28, 2008 MacBook Air falls in two minutes at PWN 2 OWN | Zero Day | ZDNet.com Told you Mac's sucked Be interesting to see who wins between vista and linux today.
Disease Posted March 28, 2008 Author Posted March 28, 2008 ho ho I could not be arsed to search. oh well.
torledo Posted March 28, 2008 Posted March 28, 2008 'According to sources at the conference, Miller used an exploit against the Safari browser that ships standard with Mac OS X. Details of the vulnerability and the attack vector are now the property of TippingPoint’s ZDI (Zero Day Initiative), the sponsor of the Pwn2Own challenge' More like Safari sucks.
Geoff Posted March 28, 2008 Posted March 28, 2008 TippingPoint | DVLabs | PWN to OWN: Final Day's Results and Wrap Up The vista and the ubuntu machine are still standing. The rules have been further relaxed. we are now opening up the the scope of the targets beyond just default installed applications on those laptops; any popular 3rd party application (as deemed "popular" by the judges) can now be installed on the laptops for a prize of $5,000 upon a successful compromise I'm expecting the Vista machine wont last long under these circumstances.
mac_shinobi Posted March 28, 2008 Posted March 28, 2008 can't open that article ( at least not from work ) but was curious as to how they set up each machine do they configure firewalls and other mechanisms before they allow them to try to gain access to each machine or is it just a base line pre installed image that each machine already came with ?
joe90bass Posted March 28, 2008 Posted March 28, 2008 @gecko They're as shipped by the vendor: The Cash Prizes All machines will be fully patched and in a default configuration. Simply put, if the vendor shipped it on the box and it's enabled, it's in scope. Day 1: March 26th: Remote pre-auth All laptops will be open only for Remotely exploitable Pre-Auth vulnerabilities which require no user interaction. First one to pwn it, receives the laptop and a $20,000 cash prize. The pwned machine(s) will be taken out of the contest at that time. Day 2: March 27th: Default client-side apps The attack surfaces increases to also include any default installed client-side applications which can be exploited by following a link through email, vendor supplied IM client or visiting a malicious website. First one to pwn it receives the laptop and a $10,000 cash prize. The pwned machine(s) will be taken out of the contest at that time. Day 3: March 28th: Third Party apps Assuming the laptops are still standing, we will finally add some popular 3rd party client applications to the scope. That list will be made available at CanSecWest, and will be also posted here on the blog. First to pwn it receives the laptop and a $5,000 cash prize. *To accommodate any individuals who may not have gotten a chance to take a stab at the machines, we'll provide the opportunity onsite for folks to submit their vulns through the normal ZDI process if they'd like to be compensated for their discovery. The awards ceremony will take place at the end of the day on the 28th. More details and daily results from the contest will be posted here on our blog. Please feel free to ask questions in the Comments section of this posting and we will try to answer them in a timely manner. Update - see our main blog index for the most recent daily updates from the contest.
CyberNerd Posted March 29, 2008 Posted March 29, 2008 Be interesting to see who wins between vista and linux today. Vista was compromised. So at the end of the last day of the contest, only the Sony VAIO laptop running Ubuntu was left standing. Cue MS apologist: It's more secure because no-one uses it, its adobe's fault etc.....
tech_guy Posted March 29, 2008 Posted March 29, 2008 More woes for Apple: Some MacBooks have premature age spots | Tech News on ZDNet
bizzel Posted March 29, 2008 Posted March 29, 2008 More woes for Apple: Some MacBooks have premature age spots | Tech News on ZDNet I thought this was long fixed? The article is from 2006.
kingswood Posted March 29, 2008 Posted March 29, 2008 (edited) Edited: a 2006 article is used to try and prove something. What, I don't know! I mean- imagine a hardware vendor having hardware issues? Edited March 29, 2008 by kingswood
tech_guy Posted March 29, 2008 Posted March 29, 2008 D'oh, I just clicked on the link at the bottom of the original story about the hack - didn't see the date. Whoops. Oh poop. Whatever.
CyberNerd Posted March 29, 2008 Posted March 29, 2008 D'oh, I just clicked on the link at the bottom of the original story about the hack - didn't see the date. Whoops. Oh poop. Whatever. I guess Zdnet don't carry so many OSX security stories
kingswood Posted March 29, 2008 Posted March 29, 2008 I guess Zdnet don't carry so many OSX security stories I wouldn't see why ZDNet wouldn't carry more OS X articles...
Michael Posted March 30, 2008 Posted March 30, 2008 Vista hacked was on Day 3, but through Adobe Flash Clearly Apple were the losers here, with Microsoft second and Linux the winner. I don't have much sympathy for Apple really, as Safari is appalling, but as for Microsoft I do have a degree of sympathy. Although security of the OS has been beefed up, it's weakened by an application that probably 90% of all users have installed as it's widely used across the web. Would of been interesting if they put Windows XP SP2 or indeed SP3 to see how (in practice) this competes with Vista in the real world security wise
CyberNerd Posted March 30, 2008 Posted March 30, 2008 Although security of the OS has been beefed up, it's weakened by an application that probably 90% of all users have installed as it's widely used across the web lol, @ the MS shill response.
Michael Posted March 30, 2008 Posted March 30, 2008 lol, @ the MS shill response. Oh well, back to the drawing board. Tomorrow's another day etc etc...
ITWombat Posted March 30, 2008 Posted March 30, 2008 lol, @ the MS shill response. That's a bit harsh. It has been a matter of debate the extent to which the OS developer can be held responsible for the quality of OEM bundled software. In this case it is half and half between Adobe and Microsoft. Although it was Adobe 's software that contained the exploited vulnerability, it was Microsoft's Active X technology framework that makes it possible for the cracker to own the own the box.
CyberNerd Posted March 30, 2008 Posted March 30, 2008 (edited) Oh well, back to the drawing board. Tomorrow's another day etc etc... Really. Linux was tested against the same criteria. In this case it is half and half between Adobe and Microsoft. Although it was Adobe 's software that contained the exploited vulnerability, it was Microsoft's Active X technology framework that makes it possible for the cracker to own the own the box. That's not really half and half if linux isn't vulnerable ! Edited March 30, 2008 by CyberNerd
kingswood Posted March 30, 2008 Posted March 30, 2008 No operating system is devoid of exploitative code- not even Linux with all it's great stability and power (hence so many patches). But patching- and plugging security holes- is a Good Thing . What this event showed is that Apple and Microsoft have a long way to go before they can hold up a crown- and it shows only that *on this occasion* Linux stayed safe. I *like* that OS X was "hacked" in this way. Safari isn't as bad as MS supporters believe, and yet still has a long way to go before it can be considered as seasoned and safe as it should be. With exploits like this being revealed Apple will have to react before it becomes common knowledge; likewise Microsoft have every right to now send a few fiery darts Adobe's direction for releasing hole-ridden code (if it is indeed "hole ridden" and not just in need of a patch). When all is said and done we should all be aware of the need for security- no matter the OS. What this competition does *not* prove- and you would have to be silly to think it does- is that any one OS came out the secure "victor". On the day Linux stood against the hacks attempted against the system. On another day this may not be the case. Paul
Michael Posted March 30, 2008 Posted March 30, 2008 What this competition does *not* prove- and you would have to be silly to think it does- is that any one OS came out the secure "victor". On the day Linux stood against the hacks attempted against the system. On another day this may not be the case. Absolutely I agree! Any OS is breakable, just some easier than others I think the Adobe flaw was a combination of Flash and Windows itself (as mentioned by ITWombat), but nevertheless, it goes to show MS needs to work closer with developers so they harden their software too.
Michael Posted March 30, 2008 Posted March 30, 2008 Really. Linux was tested against the same criteria. I don't disagree with you here, Linux was glorious on the day. I meant MS need to go back to the drawing board and work closer with developers (as I mentioned above)
GrumbleDook Posted March 30, 2008 Posted March 30, 2008 It is one thing for out of the box sessions like this, but it is more fun to watch the competitions against hardened machines. InfoSec used to do a session each year of it, but I didn't see it at all last year. I won't be attending this year, but it is always a good session to look for.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now