Comments on: Winner mocks OS X hacking contest
Hacker gains operating control of a Mac Mini using an unpublished vulnerability, says machine is "easy pickings."
Hacker gains operating control of a Mac Mini using an unpublished vulnerability, says machine is "easy pickings."
January 3, 2010 3:10 PM PST
January 3, 2010 12:20 PM PST
January 3, 2010 12:10 PM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
Apple seriously need to do a security review like what M$ did a few years back.
By WHOM? 3rd party security companies that have proven to hack Windows time and time again?
HAH...
first step involved setting up a valid user account on the system, a
process which the contest designer helpfully opened up to the
public. For this to mean something I would really like to see the
same contest results based upon a system where the user accounts
must be hacked first.
Mike
nature - extremely secure and stop jumping on every, half-
assed, unproved "hacking" of an OSX system.
From what I can see on the RM My Mac web site, not only was
root turned on (why would you do that unless you wanted a
mountain of trouble, you sure as hell don't *need* to do it to run
the machine) but the guy setting the "challenge" turned every
single service on to make the job easier.
And isn't it funny that the hacker who "cracked" the machine did
so with an exploit he won't outline, the web site appears to be
enjoying that it was "cracked" so easily (would a real Mac user be
joyful about this?) and - yet again - we get the old "well, if you
had decent market share you'd be toast" argument, as if
successfully proving you've hacked an OS deemed to be one of
the most secure wouldn't be incentive enough?
Please can c|net et al stop printing these "half stories" until
something real happens.
TIA
RB
--
"If you think you know everything, you should know about http://www.enthem.com by now"
MY HOUSE WAS ROBBED IN THIRTY SECONDS!!
Oh yeah... forgot to mention that I unlocked my front gate and left a pile of front-door keys there next to my "please try to rob me" sign. So really the robber only had to figure out where my cookie-jar was. But still, I got ROBBED IN 30 SECONDS! Oh no!
using a wab page which you could then log into using SSH.
Obviously this is not a situation a normal user would run into.
They fact that he allowed others to have access to the mini is
just stupid and proves that this is nothing other than someone
trying to get attention.
From the Owner's website: "That's why I set up an LDAP server
and linked it to the Macs naming and authentication services, to
let people add their own account to this machine. That way, they
will all be able to enjoy the beauty of Mac OS X Tiger. And, of
course, get a better chance of rm'ing it!"
go check it out for yourself....
http://rm-my-mac.wideopenbsd.org.nyud.net:8090/
Just ignore him and he'll go away.
like all cars can be pimped.
So please stop publishing reports that state the obvious and
then try to feed it to the masses as a "SHOCKER".
Here, let me help you with your next FUD:
Mac OS X can get viruses and worms...and spyware...just like any
other computer.
What is 8 seconds referring to? The last record break in to a patched OS X computer? lol
Continue crying Mac Zealots as OS X is hadily violated.
I would like to see a reputable security firm or group setup a Mac, Windows, Linux, Unix, and BSD system. Configure it the way a good administrator would. Then ask hacker to break into it.
Then have them detail how they did it and how long it took. It must be repeatable. After that we would have a better view of how easy or hard those systems are to break. Of course in reality it doesn't really make much difference because OS's change regularly so vulnerability changes regularly.
third party (not an AV manufacturer) needs to set up the
machine and then there needs to be a detailed explanation for
the intrusion.
Two nobodies and a contest where the winner used
"unpublished weaknesses" do not a valid story make.
Unix-type kernel. There's bound to be some bugs and
vulnerabilities but they will be very few compared to the amount
to be found in any Windows environment.
This contest was essentially 'rigged' from the beginning and
used the Mac OS X, essentially a single user version, in some
extended and non-standard ways to achieve a desired result.
Would the same have happened with OS X server?
Also OS X itself has very few of its own services open to
networks and most of it's networking is taking care of by open
source networking apps: Apache, SAMBA, SSH etc., so it benefits
from many eyes and much peer review.
If the supposed "undocumented vulnerability' exploited in this
case, turns out to be legitimate and becomes discussed openly,
it will probably turn out to be something that has been
overlooked at the local gui level and will be patched very quickly.
But this story has too little information and too much hype to be
believed and seems to be bent upon spreading nothing more
than FUD.
The University of Wisconsin is answering with a similar challenge
which you can read about here: http://test.doit.wisc.edu/
Let's all watch and see what happens. Let's get some real facts
on OS X security for a change.
realistic security challege: simply alter a web page on a machine
that is configured more like a normal machine.
http://test.doit.wisc.edu/
He does leave ssh and http open, which most consumer Macs
will not have open. Unlike the "hacked in 30 minutes" machine,
potential hackers will not be given a user account on the
machine itself.
This is a far more realistic challenge. The Mac that was hacked
in this article was *not* hacked simply by being connected to the
internet -- it was done locally, essentially, since the hackers
were given accounts to ssh into the machine.
How about someone run a security challenge for XP? Give
someone an account on the machine and see how long it takes
for that person to bring the machine down.
happened - it's just someone posting a website entry saying it
happened.
Come on guys, what happened to "don't believe everything you
read"?
SSH account. He was already logged into the system when he
"hacked" the web page. This is a non-event. Every shipping Mac
has SSH disabled and its web server disabled. This is another
sensationalist story about Mac OS X and security.
Really, maybe you should title your "news" article "Mac OS X
allegedly hacked in under 30 minutes". Then you'd have a story.
A nice fluff piece.
I wonder how it has stayed online?
http://toolbar.netcraft.com/site_report?url=http://www.army.mil
I wonder how it has stayed online?
http://toolbar.netcraft.com/site_report?url=http://www.army.mil
from hacking into some unknown system.
But the Army DID switch to the Mac then, and they're using OSX
Server now. It's just unfortunate that Apple doesn't note the
original switch was to OS9.
http://www.apple.com/itpro/profiles/army/
operating system on BeOS. So sad the move was decided on by
politics instead of good ideas.
at least in terms of backwards compatibility.
Also, with the NeXT acquisition came the return of Steve Jobs.
This, more than anything else, has been the MOST influential
element of Apple's rebirth and renaissance. no argument there.
With Be, who would they have got?? Jean Louis Gasse??! PASS!!
The proof is in the pudding. Mac OS X is awesome. There is very
little wrong with Apple's products and ongoing strategies for the
past several years. The company implemented several MAJOR
transitions (68000x0 CPU->PPC, Mac OS Classic->OS X,
PowerPC->x86) with each one better than the last and they've
never executed as well as they are right now. Thank Steve jobs
for that.
If you set up any machine to be hacked and someone hacks it, how is this news?
managed to wreck the 2006 Honda Civic by ramming it into a
telephone pole.
This proves the Honda Civic is less safe than previously imagined.
year-old used an undisclosed technique to reach the pedals.
Proof positive. Bad Honda, everyone should buy Ford instead.
Hurry news.com, the market closes in 15 minutes!
Only joking - I find the stock manipulation techniques of wall street and financial reporters heinous. Yet another example of one technique used to do this...
http://news.com.com/2008-1030-6046300.html?tag=yt
Certainly this article could be classed as an attempt to do this since it is almost criminal that they don't mention anywhere in the article that this machine was setup to eb hacked by giving hackers the ability to create user accounts and thereby hack form within, whereas no other Mac on the internet provides that access, or has that vulnerability.- read here for more info: http://test.doit.wisc.edu/
- Normal people don't set up their computers for hacking!
- by TravisHB April 25, 2008 1:58 AM PDT
- I have been using OS X for about a year. No anti-spyware software,
- Like this Reply to this comment
-
-
- So what's the point...
- by FutureGuy March 6, 2006 12:47 PM PST
- ..I run XP and it has never been hacked or have any spyware/viruses on it.
- Like this View all 2 replies
Processing -
(77 Comments)no extra security software- and I have not experienced any
problems such as viruses, hackers, or spyware. As a matter of fact,
I have not had any problems.