Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple's OS X is First OS to be Hacked at This Year's Pwn2Own(Hacked in 5 Seconds)
DailyTech ^ | 3/10/2011

Posted on 03/10/2011 1:46:37 PM PST by BobSimons

Apple's OS X is First OS to be Hacked at This Year's Pwn2Own

Charlie Miller lets someone else win a MacBook for a change

The conception that Apple, Inc. computers running OS X are magically more secure than Windows computers was dealt another setback this week. Using a flaw in Apple's pre-installed first-party Safari browser, it took French security pro Chaouki Bekrar merely 5 seconds to hijack the unwitting MacBook at the CanSecWest Conference's pwn2own contest in Vancouver, British Columbia.

On a most basic level the attack exploited Apple's weak memory protections in OS X Snow Leopard. Microsoft, more popular and more commonly attacked, includes two critical types of memory protection -- data execution prevention and robust address space layout optimization (ASLR) -- both of which attempt to prevent memory injection attacks. By contrast, Snow Leopard only supports ASLR and the implementation is badly botched according to hackers.

The attack also exploited poor coding in Apple's branch of WebKit, which features many bugs and security flaws. While Apple's WebKit branch, which powers its Safari browser, shares a certain amount of code with Google's WebKit browser Chrome, Google has added much more robust security layers and is less buggy.

So if Apple computers are less secure than Windows machines, why are Windows machines attacked so much more frequently? Generally, the answer boils down to that there's far fewer Macs and that hackers often have misgivings about mass attacks Unix-like operating systems (Linux, OS X) as they view it as "attacking their own." Ultimately these two factors combine into a greater barrier -- lack of information.

read more here

(Excerpt) Read more at dailytech.com ...


TOPICS:
KEYWORDS: apple; hacked; osx
Navigation: use the links below to view more comments.
first 1-2021-4041-49 next last

1 posted on 03/10/2011 1:46:41 PM PST by BobSimons
[ Post Reply | Private Reply | View Replies]

To: BobSimons

LMAO.. 5seconds to hack a mac.


2 posted on 03/10/2011 1:48:03 PM PST by BobSimons
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

ping


3 posted on 03/10/2011 1:50:57 PM PST by raybbr (People who still support Obama are either a Marxist or a moron.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BobSimons

Why, that’s impossible. Only Windoze can be hacked. /s


4 posted on 03/10/2011 1:53:30 PM PST by reagan_fanatic (A communist is just a liberal in a hurry)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BobSimons

It’s like the “Hack a Shaq”...only computer like...


5 posted on 03/10/2011 1:54:08 PM PST by Fedupwithit ("The welfare of humanity is always the alibi of tyrants" -Albert Camus)
[ Post Reply | Private Reply | To 2 | View Replies]

To: BobSimons

The title is a little mis-leading.

A 3-man team worked 2 weeks to reverse engineer Webkit, then discovered an exploit in the way Webkit processes data. Once they had this, they were able to write code to take advantage of this exploit.

So, when the Pwn2own contest started .... hey, first team to crack the Mac - wins the Mac and $15K.

All they had to do was pull the trigger.


6 posted on 03/10/2011 1:55:49 PM PST by Hodar (Who needs laws .... when this "feels" so right?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BobSimons
The conception that Apple, Inc. computers running OS X are magically more secure than Windows computers

I don't know anyone who ever thought this "conception" was magic.

And, as Hodar says, the title is phony.

But if Windows security is good enough for you, then have at it. Just count the working exploits out there in the real world for Mac vs. for Windows.

7 posted on 03/10/2011 2:02:34 PM PST by Izzy Dunne (Hello, I'm a TAGLINE virus. Please help me spread by copying me into YOUR tag line.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: reagan_fanatic
Why, that’s impossible. Only Windoze can be hacked. /s

Or so the iTards tell us.

8 posted on 03/10/2011 2:06:16 PM PST by Drill Thrawl (I don't prep for the disaster. I prepare for the rebuilding.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Izzy Dunne

If the fact that MS has more exploits than Apple is good enough for you, then don’t worry about it. Relax.


9 posted on 03/10/2011 2:07:14 PM PST by SgtHooper (The last thing I want to do is hurt you. But it's still on the list.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: BobSimons
And how long did they work on the exploit -- developing it, testing it, etc.? Weeks at least.

You are an Apple-hater -- that's okay, not everybody likes Apple.

But are you also really completely ignorant of how these inane hacking contests work? The amount of time it takes to RUN the script is nothing whatsoever compared to the time it takes to try a dozen different tacks, find one that works, and develop it into a successful exploit.

Headlines and articles like this are just stupid. I'm sorry to see such drivel posted on FreeRepublic.

A discussion of the exploit would be interesting.

A bunch of loons crowing about "5 seconds" is just juvenile.

10 posted on 03/10/2011 2:07:15 PM PST by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BobSimons

UNIX bases OSes are very difficult to hack. There are no viruses, as that concept doesn’t work in Unix. Without the root passwd there is very little distruction that can take place. Believe me.


11 posted on 03/10/2011 2:11:39 PM PST by central_va (I won't be reconstructed, and I do not give a damn.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BobSimons; dayglored
BTW, Bob...

> A bunch of loons crowing about "5 seconds" is just juvenile.

The "loons" I'm referring to are the tech whores at DailyTech, not anybody at FR.

12 posted on 03/10/2011 2:15:58 PM PST by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 10 | View Replies]

from the article

But the results show that when somebody puts in the work to enter that undiscovered country, that Macs prove as hackable as Windows computers or more so.

Luring the user to a suspect site in Safari, the VUPEN researcher remotely launched OS X's calculator app and wrote a file to the disc -- essentially paving the way for a full hijack of the machine. This was all done without the browser crashing or showing any irregularities.

He describes, "The victim visits a web page, he gets owned. No other interaction is needed."

The victim would likely think they merely clicked on a bad URL.

Thats scary going to a webpage and getting pwned..
At least Windows users utilize proactive defenses that block bad or otherwise malicious websites..

13 posted on 03/10/2011 2:16:49 PM PST by BobSimons
[ Post Reply | Private Reply | To 11 | View Replies]

To: central_va

quit blowing smoke.


14 posted on 03/10/2011 2:18:08 PM PST by BobSimons
[ Post Reply | Private Reply | To 11 | View Replies]

To: BobSimons

>>>>quit blowing smoke.

Physician, heal thyself.


15 posted on 03/10/2011 2:19:38 PM PST by Keith in Iowa (FR Class of 1998 | TV News is an oxymoron. | MSNBC = Moonbats Spouting Nothing But Crap.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored
And how long did they work on the exploit -- developing it, testing it, etc.? Weeks at least.

why cant you even admit when Apple is wrong? Apple had flawed code

16 posted on 03/10/2011 2:22:02 PM PST by BobSimons
[ Post Reply | Private Reply | To 10 | View Replies]

To: Hodar

So that makes it illegitimate?

The exploit was there and they got in.

But with any Apple issue, it’s everyone fault but Apple’s.


17 posted on 03/10/2011 2:23:04 PM PST by VanDeKoik (1 million in stimulus dollars paid for this tagline!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: BobSimons
At least Windows users utilize proactive defenses that block bad or otherwise malicious websites..

Only because Windows users have had to deal with a never ending stream of such attacks for years. So they are constantly fixing the problems and making it more secure. To compare the two situations it is like saying a house in the in Queens is more secure than one in Omaha because they have more locks on their doors. The moronic reporter or the unsavy reader might instantly conclude that if you want to be secure from break-ins all you have to do is move to New York City.
18 posted on 03/10/2011 2:23:20 PM PST by TalonDJ
[ Post Reply | Private Reply | To 13 | View Replies]

To: BobSimons

Apple to some of their users is more beloved than their own country.


19 posted on 03/10/2011 2:24:10 PM PST by VanDeKoik (1 million in stimulus dollars paid for this tagline!)
[ Post Reply | Private Reply | To 16 | View Replies]

To: BobSimons
why cant you even admit when Apple is wrong? Apple had flawed code

Of course they had flawed code! So what? Have Macs been getting hacked this way often? No. Have Windows PCs been getting it this way? Yes. That is why they are more secure. Because hackers have been doing this trick or one similar to PCs for YEARS. Now that someone found this hack Apple will fix it. Just like MS fixes ones in their stuff when they are found. Life goes on. No code is perfect. Why do people have to go orgasmic if Apple makes a mistake?
20 posted on 03/10/2011 2:26:54 PM PST by TalonDJ
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-49 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson