Mac Hacked In Contest… Sort Of
April 22nd, 2007 at 3:00 PM - News by Jeff Gamet
The CanSecWest 2007 security conference hosted a "Hack a Mac" contest where contestants worked to gain unauthorized access to a Mac OS X system. Yes, there was a winner, but not until the contest rules were relaxed to the point that someone actually could win.
Shane Macaulay and Dino Dai Zovi won a US$10,000 prize and the compromised Mac for their efforts which included discovering a bug in Safari that allowed them to use a maliciously crafted URL to gain user level access to the computer. The vulnerability is known as a "zero day exploit," meaning an exploit is released the same day it is announced, that there is little or no protection for.
In this case, the security flaw requires a local user attempting to open the malicious URL with Safari before unauthorized user level access can be obtained. Apple has been alerted to the security flaw, and the exploit has not been released to the public.
The original rules required the attackers to gain root level access to a Mac running Mac OS X 10.4.9 with the latest security updates from a different point on the same network. Contestants were not able to gain root access to a second Mac during the two-day conference even after the rules were modified to allow for local attacks using Safari.
Although the prospect of a potential Safari exploit that allows unauthorized access to a Mac is a serious concern, it also underscores the importance of user vigilance. Clicking a Web site link thatis in am email message from someone you donit know, for example, is a really bad idea. The URL may be legit, or it could take you to a Web site that you would rather not see, or it could be constructed to allow someone else to gain control of your Mac.
Unfortunately, many news outlets are taking advantage of this potential exploit to run sensationalized headlines and to incorrectly state that the Mac used in the contest was remotely hacked. It appears that zero day exploits and remote hacks for Windows PCs are par for the course, but a potential Mac exploit - now thatis news.
Recent Headlines - Updated November 22nd
- Fri, 7:07 PM
- Games - Soccer Sim Championship Manager 2010 Released for Mac
- 6:47 PM
- Games - EA Publishes Original Monopoly for iPhone
- 6:15 PM
- News - Original Apple I on Ebay for $50K, w/Letter from Steve Jobs
- 6:11 PM
- Games - New iPhone Games: Secret of the Lost Cavern Ep 1, New DJ Nights, More
- 5:47 PM
- Games - Star Trek D-A-C Game Headed to the Mac Next Month
- 4:57 PM
- Product News - TidBITS Releases “Take Control of Syncing Data in Snow Leopard”
- 4:26 PM
- John Martellaro's Blog - Particle Debris (week ending 11/20) Stationery Pads Go Poof
- 2:59 PM
- Free on iTunes - Musée du Louvre, Art Lite, SketchBook Mobile X and More.
- 1:50 PM
- Deal Brothers - Acer P215H bmid 21.5” Widescreen LCD Monitor: $139.99
- 11:24 AM
- TMO Appearances - Jeff Gamet Shares More Holiday Gift Ideas on MacJury
- 10:43 AM
- Product News - Cocktail 4.5 for Leopard Adds QuickLook Cache Clearing
- 10:06 AM
- News - Hack Enables Mac OS X 10.6.2 on Netbooks
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
OWC: Get the Right Memory / Ram for your Mac. Top Quality, Competitive Prices, Lifetime Warranty. Expert Support and Video Installation Guidies too! 4.0GB Matched Sets from $87.99, Options up to 32GB. Click here
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.


The Evolved Canon Digital Rebel XSi 12MP Camera: $583.03 Delivered - $16.00 Drop
Panasonic Lumix 10MP Digital Camera: $275.95 Delivered - Additional $6 Drop!