Welcome | Sign In
TechNewsWorld.com
Exploits & Vulnerabilities

Hackers Knock the Air Out of MacBook

Print Version
E-Mail Article
Reprints
Hackers Knock the Air Out of MacBook

A MacBook Air was successfully hacked in two minutes at a recent hacking contest, though it stood up to a full day of trials before that. The Air -- along with the computers in the contest running Ubuntu and Vista -- all hung tough during the first full day of hacking via remote zero-day exploits. Only when hackers were allowed to try and trick surfers to click on a malicious Web link did the Air finally fall.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

A computer with a sky-high public profile these days -- the much talked-about and often coveted MacBook Air from Apple (Nasdaq: AAPL) -- was the first laptop to get cracked in a security hacking contest Thursday.

While headlines around the Web are claiming that it took only two minutes, there's more to the story.

The cracking went down at the CanSecWest security conference in Vancouver, British Columbia, at the PWN to OWN 2008 contest, where security gurus attempt to hack into laptops for US$10,000 in prize money. They also win the laptop they manage to compromise first. The challenge is to read the contents of a designated file located on each of the machines.

The contest includes three laptops that are running the most up-to-date and patched installations of Mac OS X Leopard, Windows Vista and Ubuntu Linux. Their hardware included a Sony (NYSE: SNE) Vaio VGN-TZ37CN running Ubuntu 7.10, a Fujitsu U810 running Vista Ultimate SP1, and -- at least until Thursday -- a MacBook Air running OSX 10.5.2.

The main purpose of the event, contest organizers said, is to responsibly unearth new vulnerabilities within these systems so that the affected vendors can address them. The prize money is sponsored by security firm TippingPoint's Zero Day Initiative (ZDI) program. ZDI hosts a Digital Vaccine (DV) Laboratories blog that serves as a portal to the company's security research and services. Last year the ZDI program was able to identify an Apple QuickTime flaw. The company handed it over to Apple, which then issued a security update.

MacBook Air Breaks First

Charlie Miller, Jake Honoroff and Mark Daniel from Independent Security Evaluators (ISE) successfully compromised the Apple MacBook Air -- the first laptop to become compromised -- in two minutes. However, that two minutes was the result of directing an end-user to click on a specially crafted link that went to a Web server with a specially crafted exploit. The details, of course, are being kept under wraps until Apple can address them.

So, two minutes? Not exactly. It hasn't been revealed how long it took the ISE crew to build the exploit in the first place and have it ready for the contest, nor is it clear that ISE even bothered to attempt a crack at the other two laptops. Still, a flaw is a flaw, even one that requires special action by the computer's owner.

Two Minutes or Two Days?

In the first day of the hacking fest, participants tried to bust into the laptops using only a remote zero-day exploit, and all three laptops survived. Day two included the ability to utilize default-installed client side applications as well, which is when the MacBook Air went down. By the early hours of the third day, the Vista and Ubuntu laptops where still standing.

The most obvious question that comes to mind is whether Vista and Ubuntu -- and their related default applications -- are inherently stronger than Mac OS X and its default applications. Can any reasonable conclusions be drawn from the results of the contest?

Mike Haro, a senior security analyst for Sophos, cut to the chase: "From this, you can't conclude anything about which of those platforms is more secure," he told MacNewsWorld.

Overall, many of the latest exploits depend on the action of end-user to download a file or click on a special link in an e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse or on a Web site. Those kinds of exploits happening a lot in the wild right now, Rich Mogull, an independent security consultant, told MacNewsWorld.

"It is probably the biggest attack vector today, more than traditional viruses. It's not that much social engineering -- the attackers break into trusted Web sites and place these links there in ways to make them run. It's called a 'drive-by,'" he explained.

Vista, Mogull noted, has a number of anti-exploitation technologies to make attacks harder. "But I do have reports of a number of security problems with Safari," he added.


Print Version E-Mail Article Reprints More by Chris Maxcer


Talkback: Join the Discussion.
Re: Hackers Knock the Air Out of MacBook
gregorylmyers
Posted 2008-03-29
What the contest proved is that the MacBook Air was the most desired prize, and nobody wanted ...

More by Chris Maxcer

The Gphone That Could Catch My Eye
November 20, 2009
Rumors are cropping up that Google is preparing to sell its own Gphone -- an Android handset using Google-branded hardware. There are some reasons to doubt it will happen, of course, but the possibility is intriguing. What would Google have to build to make something worthy of an iPhone fan's attention?
Apple's House Rules Won't Be the Death of App Development
November 13, 2009
Facebook's iPhone app is one of the most popular wares the App Store has ever carried. But its developer, Joe Hewitt, says he's through with it, stating that Apple's review policies are starting a bad precedent for other platforms. However, good apps from talented developers will always find platforms, and Apple's policies won't prevent that from happening. They may even help.
Let's Give the iPhone Hackers a Big Round of Applause
November 06, 2009
It's safe to say most Apple customers are satisfied living in the walled-off ecosystem that the company has created for products like the iPhone. Still, it's good to know that it is possible -- and relatively easy, even -- to bust through those walls if one should ever want to. The work of iPhone hackers is appreciated even by those who've never felt the jailbreak itch.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network