ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

MacBook hacked in security contest

Joris Evers CNET News.com

Published: 23 Apr 2007 10:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Shane Macaulay just got himself a free MacBook.

Macaulay, a software engineer, was able to hack into a MacBook through a zero-day security hole in Apple's Safari browser. The computer was one of two offered as a prize in the "PWN to Own" hack-a-Mac contest at the CanSecWest conference in Vancouver.

The successful attack on the second and final day of the contest required a conference organiser to surf to a malicious website using Safari on the MacBook — a type of attack familiar to Windows users. CanSecWest organisers relaxed the rules Friday after nobody at the event had breached either of the Macs on the previous day.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Macaulay teamed with Dino Dai Zovi, a security researcher until recently with Matasano Security. Dai Zovi, who has previously been credited by Apple for finding flaws in Mac software, found the Safari vulnerability and wrote the exploit overnight in about nine hours, he said.

"The vulnerability and the exploit are mine," Dai Zovi said in a telephone interview from New York. "Shane is my man on the ground."

Apple spokeswoman Lynn Fox declined to comment on the MacBook hack specifically, but provided Apple's standard security comment: "Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users."

Dai Zovi plans to apply for a $10,000 bug bounty TippingPoint announced on Thursday if a previously unknown Apple bug was used. "Shane can have the laptop, I want the money," Dai Zovi said. TippingPoint runs the Zero Day Initiative bug bounty programme.

A TippingPoint representative said the company would pay, after looking at the vulnerability. "If it is an actual zero-day in Safari that's fine with us," said Terri Forslof, manager of security response at TippingPoint.

The successful hack comes a day after Apple release its fourth security update for Mac OS X this year. The update repairs 25 vulnerabilities.

CanSecWest organisers set up the MacBooks connected to a wireless router and with all security updates installed, but without additional security software or settings.

 

MacBook hacker

Hack-a-Mac winner Shane Macaulay attacks a MacBook at the CanSecWest conference
 

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
6 out of 8 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

ARE YOU AN APPLE MAC SPECIALIST? URGENT - PARK ROYAL - 25-30k

They are seeking a strong individual who has had exposure to the following skills: WINDOWS, MAC, VMWARE and strong NETWORKING SKILLS. A leading ...

Unix Administrator - Solaris - 10 Months rolling

Windows and MAC OS expeirence is a bonus. Competitive rates, immediate start. Unix engineer required for fast paced media client. Experience with ...

Support Manager-International IT/Conference Co.-35,000 City

Support Manager-International IT/Conference Co. City Manage the support of this international IT/Video conference organisation that has seen huge ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment