Flash flaw leads to Vista laptop's fall
It held out as long as possible, but a Windows Vista laptop fell to a determined bunch of hackers Friday evening at the Pwn to Own contest at CanSecWest.
Since it was the third day of the contest, which saw a MacBook Air get hacked on Thursday, the TippingPoint Zero Day Initiative relaxed the rules even further. On the first day of the contest, only the operating system could be targeted, but on the second day that was expanded to include standard applications. An undisclosed Safari flaw led to the MacBook Air's downfall.
TippingPoint's Aaron Portnoy, with Shane Macauley and Alexander Sotirov (left to right) take control of a Windows Vista laptop.
(Credit: TippingPoint)But on Friday, hackers could target any "popular" piece of application software that you might find on a system. The Fujitsu laptop, running Vista Ultimate, was compromised by a previously undiscovered flaw in Adobe's Flash software.
Shane Macaulay, Derek Callaway and Alexander Sotirov, were able to gain control of the laptop, which also means they get to keep it. However, since the rules had been relaxed, they only get $5,000; the MacBook Air winners collected $10,000.
The contest rules stipulated that any winner sign a nondisclosure agreement immediately after a successful hack, so that the nature of the flaw could be disclosed to the vendor. Once Adobe and Apple patch their flaws, the nature of the flaw will be disclosed.
A Sony Vaio laptop running Ubuntu remained unscathed at the end of the conference.
Tom Krazit writes about the ever-expanding world of Internet search, including Google, Yahoo, online advertising, and portals, as well as the evolution of mobile computing. He has written about traditional PC companies, chip manufacturers, and mobile computers, spending the last three years covering Apple. E-mail Tom. 






- No good researcher?
- by kool_skatkat April 1, 2008 1:47 AM PDT
- On their site, they've only got two things in 9 months to brag about. They both had to do with Safari. MMM... Gold-diggers ridding on Apple's success? Or who's paying them?<br /><br />March 27, 2008<br />ISE wins Pwn to Own at CanSecWest by taking over a MacBook Air.<br /><br />July 23, 2007<br />ISE discovers security vulnerabilities in the iPhone.
- Like this Reply to this comment
-
(119 Comments)