The Mac Observer

Skip navigational links

You're viewing an article in TMO's historic archive vault. Here, we've preserved the comments and how the site looked along with the article. Use this link to view the article on our current site:
Mac Hacked In Contest... Sort Of

Mac Hacked In Contest... Sort Of

by , 7:55 AM EDT, April 23rd, 2007

The CanSecWest 2007 security conference hosted a "Hack a Mac" contest where contestants worked to gain unauthorized access to a Mac OS X system. Yes, there was a winner, but not until the contest rules were relaxed to the point that someone actually could win.

Shane Macaulay and Dino Dai Zovi won a US$10,000 prize and the compromised Mac for their efforts which included discovering a bug in Safari that allowed them to use a maliciously crafted URL to gain user level access to the computer. The vulnerability is known as a "zero day exploit," meaning an exploit is released the same day it is announced, that there is little or no protection for.

In this case, the security flaw requires a local user attempting to open the malicious URL with Safari before unauthorized user level access can be obtained. Apple has been alerted to the security flaw, and the exploit has not been released to the public.

The original rules required the attackers to gain root level access to a Mac running Mac OS X 10.4.9 with the latest security updates from a different point on the same network. Contestants were not able to gain root access to a second Mac during the two-day conference even after the rules were modified to allow for local attacks using Safari.

Although the prospect of a potential Safari exploit that allows unauthorized access to a Mac is a serious concern, it also underscores the importance of user vigilance. Clicking a Web site link that's in am email message from someone you don't know, for example, is a really bad idea. The URL may be legit, or it could take you to a Web site that you would rather not see, or it could be constructed to allow someone else to gain control of your Mac.

Unfortunately, many news outlets are taking advantage of this potential exploit to run sensationalized headlines and to incorrectly state that the Mac used in the contest was remotely hacked. It appears that zero day exploits and remote hacks for Windows PCs are par for the course, but a potential Mac exploit - now that's news.

Recent Headlines - Updated July 24th

Wed,7:35 PM
ACM 264: Diving Deep into Amazon’s Kindle Unlimited
6:10 PM
Apple Granted ‘iTime’ Patent for Wearable Mobile Electronic Device (Plus Wristband)
4:10 PM
UAG Scout iPad Air Case Offers Full Protection
3:30 PM
How to Upgrade Your Mac to Python 3
3:09 PM
8 UI Kits For iOS 8: $24.99
1:27 PM
TMO Daily Observations: 2014-07-23
10:52 AM
OS X Yosemite Public Beta Coming July 24
9:40 AM
Wells Fargo: AAPL Q3 was Meh, but the Future Looks Bright
8:45 AM
iPhoto: A Shortcut to Help Fix Red-Eye
Tue,8:30 PM
Class-Action Suit Against Apple for Alleged Labor Violations
8:04 PM
Apple Buys 29 Companies (plus Beats) in 21 months, 5 Since March
6:40 PM
Apple’s Tim Cook Says iPad Sales Behind IBM Partnership
  • __________
  • Buy Stuff, Support TMO!
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!