
“Two tricked-out MacBook laptops have survived the first day of a ‘PWN to OWN’ contest that dared hackers to take control of default Mac OS X installations,” Ryan Naraine blogs for ZDNet.
“The contest started around midday Thursday, the second day of the CanSecWest conference here and triggered interest from hackers in attendance… Organizers say they have seen ‘some activity’ on the network set up with the two new MacBooks — a 17″ and a 15″ — but details remained scarce when the day ended,” Naraine reports. “To win, the attacker must commandeer the machine and find a file with instructions on how to SSH to a server to authenticate the hijack.”
Naraine reports, “On the second day, the barrier will be lowered a bit and the attackers will be allowed to put exploit code on a special wiki and launch drive-by exploits on the Mac’s built-in Safari browser. If the machines survive this level, the attacker will be allowed to connect to over USB or Bluetooth.”
Full article here.
If they really want to give away the MacBooks and the $10,00 prize, on the third day they ought to install Boot Camp and Windows on them. It would probably take about 10 minutes to find a winner.
Related articles:
CanSecWest sweetens ‘Hack a Mac’ contest pot to $10,000 – April 20, 2007
CanSecWest to hold ‘PWN to OWN’ contest: pits Apple MacBook Pros vs. hackers – March 26, 2007
Microsoft’s oft-delayed, much-pared-down Windows Vista hacked at Black Hat – August 07, 2006
Microsoft publicity stunt asks hackers to attack Windows Vista – August 04, 2006
Apple Mac remains ‘unhacked’ as University of Wisconsin’s Mac OS X Security Challenge ends – March 08, 2006
Mac OS X ‘unhacked’ over 24 hours and counting in genuine security challenge – March 07, 2006
@MDN:
That’s so funny!!!
ROTFL
“Organizers say they have seen ‘some activity’ on the network set up with the two new MacBooks […]”
It seems there is not much interest…
Wow – first post without trying!
Cool
So each day they’re going to “lower the barrier” until the final story coming out of the conference is “Macbook hijacked!”
Great take MDN, this is why i come here
MW “lost” – As in all is lost when any form of windows is installed on a mac!! lol
hahahaha @ MDN
that’s prob what they will end up doing!!!
its just sad they have to ‘lower the barriers’ so they can actually hijack the macbook (pro, since its a 15” and 17”). Yea i can’t wait for the headlines ‘Macbook hijacked!!’ cause everyone in the windows world won’t take the time to read how they ‘lowered the barriers’ to even get the job done. Friggin idiots.
I agree. Why are they lowering the barriers? Not very realistic, and in the end whatever non-mac-enthusiast press that picks it up will do their typical half-assed job of fact finding. Waiting for it…
The stunt is sponsored by M$. Bill Gates is pissed because everyone is laughing at him for saying Macs are compromised every day.
The rigged rules drop the Mac’s defences until an attack is successful. Then Gates can say, “Neener, neener. I was right.”
Does it count if they literally hijack and physically steal the thing?
How far down must the defenses go before the Mac can be hijacked?
Anyone have an idea?
It seems there is not much interest…
Yeah, there’s rarely interest in $10,000. If there’s any lack of interest, it’s because hackers already know it’s futile.
Hell no! And they won’t get hacked into!
To Hell with Bill Gates and that fat monkey boy anyway.
Let’s see if anyone can actually hack them without cheating. So far everyone who has put up a challenge like this has gotten a winner but only because they cheated and had physical access to the Mac.
If this is legit than there will be no winner unless they reboot into Bootcamp and Windows like MDN said.
Naraine reports, “On the second day, the barrier will be lowered a bit and the attackers will be allowed to put exploit code on a special wiki and launch drive-by exploits on the Mac’s built-in Safari browser. If the machines survive this level, the attacker will be allowed to connect to over USB or Bluetooth.”
Ok, that just seems wrong. It was too tough, so we’ll let you gain physical access to it? Baah
@ Matrix3
Way to go man…. first post without even trying…. you be da MAN!
Common sense would tell you not to lower the barriers. It sounds like the public schools. The students can’t pass the test so you just make the tests easier. This makes dumber students and an incompetent workforce.
What will they end up doing, giving the person hands-on access complete with admin password?
That is the funniest MDTake i have read in many years.
Cheers!
Whee! I’m gonna do the Smug Dance now! Smug smug smuggy smug, I’m so smug! Woo-hoo! Eat it, Windows-lovers!
Every time someone tries to engineer a publicity stunt to show folks like me how “insecure” our Macs are, it always backfires and demonstrates just how ridiculously safe Mac OS X really is!
Smugness level at 9 and climbing!
Meanwhile, back in Redmond, the security team is burning the midnight oil….
Kind of hard to say you “hijacked” the MacBooks when they’ll basically end up giving the “hackers” the keys to the ride.
The sponsors and whoever in the end claims they “jacked” the Mac should feel pretty stupid.
Where is the VISTA $10,000 hack challenge?
At the fourth day tbarrier will not only lowered, but removed and hackers will be allowed to install Windows Vista on the Macbook.
I wonder if by “lower the barrier” they mean give out the administrator password. This contest would have been a lot more interesting if they had a Vista PC along with the Macs for hacking.
However, If I were to put myself in the hacker’s shoes, I might find that this “contest” only proves that Macs are so much harder to get into and are far more secure. Having this demonstrated by an unsuccessful live hacking, why would I continue to use a PC? I wonder how many hackers will leave this conference convinced that Macs are inferior to PCs and how many will be visiting an Apple store soon.
To make things more interesting, they should have put a pc with XP and a pc with Vista in the contest.
Then we would have seen the huge contrast.
Yeah, it’s pretty lame to lower the barrier. It’s like leaving your front door unlocked or open, depending on how they lower the barrier, and then asking if the house can be burglarized. Hehehe.
Windows users will only want to hear a hijacked Mac, IF IT HAPPENS, and not how it was hijacked.
@MDN, can somebody please fix the link? Thanks.
Another article on this, with some different facts:
http://www.securityfocus.com/news/11460
So M.X.N.T.4.1, someone is actually sitting there watching the hardware, and has a third computer monitoring the other two.
Question for you readers in the know: Apple issued a Sec update yesterday. Assuming it is not applied to the MacBook pros used in this contest can hackers use the breaches the patch fixes and to gain control of the machines?
Gee, to hear them talk, Bill Gates and George Ou should have strolled in there and taken the MacBooks by now.
[B]Not a true contest, conditions rigged
Under normal conditiions the Mac would on the internet 24/7.
Put those two bitches online, they would be pwned in a day guarranteed.
So put that fanboism back in the can right now.
Frank:
Yesterday’s Security Update was applied to the machines, and then they were put online.
Wiseguy is smokin’ that funny weed again.
The first phase of “lowering the barriers” is entirely realistic! The second phase, direct connect, is not. Quite a number of the exploits hitting the Windows crowd are Web-based, so there’s little reason to deny them the chance to take advantage of that option. USB or Bluetooth? You are not getting that close to my workstation … not without an escort.
Oh, and Wiseguy? What’s with the bogus attempt to open BOLD text without a “close” statement? Sounds like something a troll would do.
DLMeyer – the Voice of G.L.Horton’s Stage Page Pod-Cast
Hey WiseGuy, isn’t this a competition only for those at the conference? So the Macs are open to only them on the network. That’s the point of the whole thing.
@ Wiseguy. “Put those two bitches online, they would be pwned in a day guarranteed [sp].” I don’t know how you would get the idea that these macs are not connected to the internet. Let me spell it out for you, these Macbooks are connected to the internet, Hackers are connecting remotely from their computers and trying to hack it to gain access to files on it. How would the contest work if the mac were not networked? Did you think the hackers were physically sitting in front of the laptop?
About people complaining about “lowering the barriers”: I think that’s an excellent idea, and the conditions are fair. On the second day, the mac will visit a wiki page in Safari that hackers will be using to attempt drive-by exploits. This is fair because in the wild, a user might run into a website specifically engineered to perform an exploit. I know a couple URLs like that, that will instantly fuck up a Windows computer on Internet Explorer. It’s only fair to test the mac under these conditions, since computers are often hacked through malicious websites.
On the third day, hackers will be connecting directly through USB and Bluetooth. Again, this is fair, because users might be subjected to this type of thing in the wild. I’ve accidentally infected a Windows computer over USB before.
This will be a tough challenge, and I for one want to know the results. I have confidence that Mac OS X under default settings will once again emerge itself impervious. If it is possible to hack into Mac OS X, I want to know the truth. I don’t want to be coddled like some half-retarded fanboy. If someone can hack into one of these Macbooks, I can handle the news, and have great interest in knowing the truth of the matter.
CHEAT PEOPLE!!!!
CHEAT!!!!
THAT’S THE FOUNDATION OF HACKING!!! DON’T JUST TRY TO HACK THE COMPUTER!!! HACK THE CONTEST!!!
Jeeze. Do I have to do everything?
@ Drunk Cheney
Where is the VISTA $10,000 hack challenge?
At $20 right now. (See my last post.)
@ theloniousMac
CHEAT PEOPLE!!!!
CHEAT!!!!
THAT’S THE FOUNDATION OF HACKING!!! DON’T JUST TRY TO HACK THE COMPUTER!!! HACK THE CONTEST!!!
Yeah, that’s right! Go right to the contest location and manually use the machine. If the MacBook won’t let you, then you know what they say…
IF YOU CAN’T HACK IT, WHACK IT!!!!
Thank you for your lack of support, and remember that the “Hack a PC” contest reward has just dropped from a $20 bill to a $18.96 bill.
today is last day of the contest.
Seems those $10k were as safe as if in a bank.
I’m certainly not going to be “lowering any barriers” to make it easier for a hacker/cracker to get into my machine, and I’m surrounded by PCs at work, so why should they? Realistic or not, doing that seems to me to be changing the terms of the contest in mid-stream. Lessens the impact of success, and will surely be fodder for FUD in the mainstream press if someone manages to do something with the “lesser” barrier, let alone the absolutely crazy notion of giving physical access.
My take is that if nobody could PWN the machines under the original parameters, then no one gets to OWN – and the $10k does not change hands.
> How far down must the defenses go before the Mac can be hijacked?
Not until someone sticks a Post-It note on the edge of the display with the user name and password (an all too common practice).
Bill Gates says Macs are hacked everyday.
Not yesterday!
BuriedCaesar: “I’m certainly not going to be “lowering any barriers” to make it easier for a hacker/cracker to get into my machine, and I’m surrounded by PCs at work, so why should they? Realistic or not, doing that seems to me to be changing the terms of the contest in mid-stream. Lessens the impact of success, and will surely be fodder for FUD in the mainstream press if someone manages to do something with the “lesser” barrier, let alone the absolutely crazy notion of giving physical access.”
I think lowering the barrier is a good idea of a measure at how hard it is to hack into something. If you stick only with the original condition, all you know is no one hacked into it at that condition and did not investigate other vectors of attack based on easier conditions which are just as realistic (i.e. if you browse a suspicious website or if someone has a physical access to your computer). It is one way of finding that lowest level of the barrier and try to raise it from that level. This is a security conference and not a PR job. They probably couldn’t care less about what journalists think.
@../.
Good point, and I agree with you in principle about those parameters in that respect, but we can also be absolutely sure there are some “journalists” out there who are lurking around, hoping beyond hope that something DOES happen, and they’re going to get their hands on this news one way or another, especially if there IS a successful crack, and they certainly won’t care at what “level” that occurred, and they certainly won’t attempt to explain it to the masses in any way that makes sense.
If there’s no successful “attack”, then it becomes non-news. A non-event. And sadly, it will be much, much less likely to get reported, because those same media sharks won’t smell any blood.
Hey WiseGuy, isn’t this a competition only for those at the conference? So the Macs are open to only them on the (local) network. That’s the point of the whole thing.
Well that’s why I said it’s rigged.
Put those bitches on the internet instead and they would be pwned.
It’s not a matter of lowering the conditions, but making the challenge more realistic to actual conditions that all our Mac’s face.
Let’s hope the Admin password is not steve or jobs or apple or something equally as obvious.
Physical access is physical access. Every previous proof of concept exploit used physical access.
Of course, every previous exploiter, with their proof of concept exploit, also had the admin password. Anyone can hack their own computer.
There is no Airport Extreme wireless card in either machine, that’s why no one has hacked ’em. Fooled ya!
One Macbook Pro down. An exploitable safari flaw, triggered by a malicious webpage.
I love Apple, I use Apple. But I’ve NEVER understood the total smugness on the part of the fanboys-review all of the early comments, particularly MDN’s. Apple is safer by far than Doze, but I hope this is a wakeup. A serious in the wild compromise WILL happen, it’s just a matter of time.
@t0mb0, do you have a link about this? I can’t find coverage to confirm or deny that.
Link below:
http://www.macworld.com/news/2007/04/20/hacker/index.php
I’m sceptical. How come this was’nt done before ? And if it’s real, maybe security through obscurity was true, after all.
I love the Mac, but this is got to be the funniest thing ever. Specially after reading so many OS X is impregnable comments. It been creaked!
2007-04-20-14:54:00.First_Mac_Hacked_Cancel_Or_Allow
One OSX box has been owned! At this point all we can say is there is an exploitable flaw in Safari which can be triggered within a malicious web page. Of course all of the latest security patches have been applied. This one is 0day folks. Technical details will be forthcoming as the winner works out the release. There is still one more Mac to go. (the same flaw cannot be used again, but other Safari bugs are allowed)
Just to review the rules, the first box required a flaw that allows the attacker to get a shell with user level privilages. The second box, still up for grabs, requires the same, plus the attacker needs to get root.
2007-04-20-14:54:00.First_Mac_Hacked_Cancel_Or_Allow
One OSX box has been owned! At this point all we can say is there is an exploitable flaw in Safari which can be triggered within a malicious web page. Of course all of the latest security patches have been applied. This one is 0day folks. Technical details will be forthcoming as the winner works out the release. There is still one more Mac to go. (the same flaw cannot be used again, but other Safari bugs are allowed)
Just to review the rules, the first box required a flaw that allows the attacker to get a shell with user level privilages. The second box, still up for grabs, requires the same, plus the attacker needs to get root.
Sorry, it looks like I double posted.
Was this successful attack accomplished after they “lowered the bar” for security?
So a hacker would have to have my email address to send me a URL in order for this to work? I feel pretty safe still.
Safari has always been weak.
The Reality Distortion Field collapses.
I think I’ll take up gardening, at least there I can squash the bugs with success.
This exploit gives the malicious website the ability to access anything in the users folder.
It’s not “root” at least not yet.
It could place a malicious process in the user folder to auto-start and wait for the admin password (aka sudo window) to open.
Or it could simply ask the user, but that’s too obvious.
The only thing protecting us Mac users is our low market share.
Nice to see they were able to cheat to get in. I bet you could hack my system too if I was stupid enough to go to a website setup to make that happen.
” width=”19″ height=”19″ alt=”rolleyes” style=”border:0;” />
Proof of Concept!
http://www.metacafe.com/watch/421856/satisfy_your_appetency/
“Was this successful attack accomplished after they “lowered the bar” for security?”
Umm yes, lowered considerably.
Sorry Windows fanboyz, but this hardly proves that OS X is as weak as the shit you have.
It doesn’t matter if the so called “bar was lowered”, Safari is used by most Mac users nearly all the time.
Far as I’m concerned, the contest is rigged anyway.
Give the whole internet accesss to those Macs and they would be pwned in minutes.
It’s a shame to Apple that it only took a day to hack a Mac.
Imagine what the entire internet with months could accomplish.
What is really funny is how it took an entire conference room full of geek hackers 2 full days to finally get in, and only then after the security had been lowered a great deal on the target machine.
Had they been hacking at Windows, they would have been able to pull it off in only 2 minutes, not 2 days.
” agree. Why are they lowering the barriers? Not very realistic, “
If by Lowering the Barriers you mean having the machine actually do something an end user will do all the time like browse the Internet, send/receive mail etc, rather than just sit there not running any services with nobody doing anything on it, it doesn’t sound unreasonable.
Winner mentioned here too:
http://www.theregister.co.uk/2007/04/20/pwn-2-own_winner/
At the time of writing there are 2 comments on that article and the second warrants a good response.
“Imagine what the entire internet with months could accomplish.”
Umm, they’ve had 6 years now and they still haven’t accomplished jack squat yet. No Mac with OS X has been hacked out in the wild yet. Hacking a rigged machine at a conference doesn’t qualify as “in the wild” ya know….
Of course we will see what the spin masters of MDN will do with this recent turn of events.
Maybe they should just say, “OK, Safari and Mac OS X needs some work”
Hopefully Apple has been paying attention and will make some MAJOR Compartmentalized changes to Mac OS 10.5’s security structure.
95% of exploits are application based.
There isn’t a reason in the world why simple programs like NeoOffice need a admin password (root access) to install.
There isn’t a reason in the world why any program outside of cloning or system maintainence software needs root level access to our operating system.
But they demand it anyway.
“Hacking a rigged machine at a conference doesn’t qualify as “in the wild” ya know….”
All it proves is nobody can be bothered hacking a Mac for less than $12,500 in cash and hardware, and when the reward is high enough, it’s done within hours.
Headline: Hacker breaks into Mac at security conference
Link:
http://computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=cybercrime_and_hacking&articleId=9017380&taxonomyId=82&intsrc=kc_top
MW: Never. Ooops.
Don’t worry, Steve will announce new security features..soon.
The smugness that oozes from MDN needs to be tempered with common sense. It looks like Safari has it’s own share of problems that need addressing given the Mac has been hacked and the contest is now over – who knows what other avenues remain open?
Until MDN can stop bleating like a child it will continue to perpetuate the negative perceptions of Macs and Mac users that are still so prevalent. Is there any wonder that Mac users are described as fanatics when you read the rampant chest-beating on these pages?
Instead of trying to spin every article it mirrors, MDN would better serve its readers by removing the adolescent diatribes and presenting the facts in an honest and balanced way.
Grow up MDN – Mac users deserve better.
Wasn’t this a contest to hack into Mac OS X? They didn’t do that. They found a flaw in Safari, which is an application that runs on OS X.
Also, were the hackers allowed to sit down and use the Macs to surf to a specific web site that contained the hacker’s code? How is that “real-world”? I’m certainly not going to let some random person use my laptop. I thought the point was to prove that anyone’s Mac could be compromised, not just those use let strangers use Safari to access questionable web sites.
As expected, the Mac-haters are crowing very loudly (WiseGuy – who obviously isn’t). By tomorrow there will be stories in every tech web-site loudly proclaiming that the Mac Is Every Bit As Insecure As All Windows PCs! Doesn’t mean that this contest was over-contrived and unfair.
I wonder if the sponsors of the prize money just-so-happen to sell security software for the Mac…
Tom
I totally agree with your statement.
Apple has really been trying to get away from rabid fanaticism that it needed earlier to survive.
It’s sites like this one, as well as rumor sites, that have to “invent” something in order for them to attract people.
Many Mac sites just give the “news” but sites like this one create controversy, combined with it’s no registration “freewheeling” posting feature, do generate a lot of interest.
So don’t assume all Mac users are rabid vocalists, it’s just those get all the attention.
does this mean my Mac is vulnerable? (closes Macbook, opens IBM ThinkPad)….
the Mac-haters are crowing very loudly (WiseGuy – who obviously isn’t)
Don’t lump me in the “Mac-hater” crowd just because I don’t praise Apple when they did something wrong.
I’ve only used Macs since the very first Apple IIe, never bought a PC in my life.
I’m just totally disgusted with Mac OS X security “promises” and very disillusioned with Apple for the last few years.
The security issues are mounting and it doesn’t seem like it’s going to stop.
does this mean my Mac is vulnerable? (closes Macbook, opens IBM ThinkPad)….
Yes your Mac is vulnerable, but less so than Windows because Windows has a much larger market share of people interested in compromising it.
If that brings any consolation.
Wow, Jay
I feel as if my back door has been violated……
“Wasn’t this a contest to hack into Mac OS X? They didn’t do that. They found a flaw in Safari, which is an application that runs on OS X.”
And 90% of Windows flaws are the same thing.
Who really cares if the OS is compromised through a bad app bundled with the OS, or the OS itself. And where do you draw the line?
personally I draw the line of Apple’s responsibility at the OS and all apps bundled with it by Apple.
is there any consumer with a Mac as their main machine who doesn’t browse the web on it?
@WiseGuy
Vista was hacked just the other day with only 3% market share (compared to Macs 6%) so I disagree with your security through obscurity theory. Vista was hacked by way of a flaw in IE.
Market share figures here
http://marketshare.hitslink.com/report.aspx?qprid=2
Hi Guys!,
Just putting here what I posted elsewhere on MDN tonight.
It’s 4.10am in the morning in Ireland (& yes tonight, it’s sad, I’ve nothing better to do!)
I came across this story of which we on MDN forums were following earlier today.
The majority of us were right in our assumptions about the “Hack a Mac” competition!
I sent the following to MDN:
Dear MDN,
I don’t often swear, but please read this fu*kin crap:
Link:
http://www.macworld.com/news/2007/04/20/hacker/index.php
Just as we all predicted on MDN! & after CanSecWest stated:
“On the second day, the barrier will be lowered a bit and the attackers will be allowed to put exploit code on a special wiki and launch drive-by exploits on the Mac’s built-in Safari browser.
“the barrier will be lowered”
Of coarse the above is not stated in the released statment, as we all knew would be the case!
FUD, FUD & again I say FUD!!
“According to the security blog Matasano Chargen, Shane Macaulay and Dino Dai Zovi won the contest by gaining shell access to a Mac by pointing the Mac’s Safari browser at a specially-constructed Web page.”
“You see a lot of people running OS X saying it’s so secure and frankly Microsoft is putting more work into security than Apple has,” said Dragos Ruiu, the principal organizer of security conferences including CanSecWest.
!!!!
If your going to exploit OS X, do it for real & don’t lower the barrier. Then I will Listen.
From,
A not surprised, but really annoyed,
Another Irish Dude
PS:Link
http://www.matasano.com/log/806/hot-off-the-matasano-sms-queue-cansec-macbook-challenge-won/
Quote:
More details as they become available. In the meantime, a drinking game: predict the rationalizations given by Mac zealots for why this finding “doesn’t count”.
I’ll start: “It took $10,000 to break a Mac, but people break Windows machines for free every day!”
MacPro is hacked, MDN doesn’t know jack, Macfanbois’ smugness cracked, Apple gets whacked, OS X got smacked, no Mac left intact, Steve doesn’t watch yer back, Apple core suffers impact, and that’s a fact, Jack.
“I’ll start: “It took $10,000 to break a Mac, but people break Windows machines for free every day!””
Counterpoint: Nobody will hack a Mac just to own one, the free Mac alone is not enough. If that’s the case there must be even less desire to hack them just to control them remotely.