Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 03-27-2008, 06:45 PM   #1
iMind
Confirmed User
 
Join Date: Nov 2007
Posts: 937
Mac Book Air PWNED in hacking contest

I remember this last year, and it was a big challenge and took 9 hours of hacking to beat the mac and they even had to reduce the rules, this year it was hacked in 2 minutes flat although they did reduce the rules to the local network again this year aswell.


"Mac gets hacked first in contest
Robert McMillan
Thu Mar 27, 4:25 PM ET
San Francisco - It may be the quickest $10,000 Charlie Miller ever earned.

ADVERTISEMENT

He took the first of three laptop computers -- and a $10,000 cash prize -- Thursday after breaking into a MacBook Air at the CanSecWest security conference's PWN 2 OWN hacking contest.

Show organizers offered a Sony Vaio, Fujitsu U810, and the MacBook as prizes, saying that they could be won by anybody at the show who could find a way to hack into each of them and read the contents of a file on the system using a previously undisclosed "0day" attack.

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network, but on Thursday, the rules were relaxed so that attackers could direct contest organizers using the computers to do things like visit Web sites or open e-mail messages.

Miller, best known as one of the researchers who first hacked Apple's iPhone last year, didn't take much time. Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on.

He was the first contestant to attempt an attack on any of the systems.

Miller was quickly given a nondisclosure agreement to sign, and he's not allowed to discuss particulars of his bug until the contest's sponsor, TippingPoint, can notify the vendor.

Contest rules state that Miller could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser.

Last year's contest winner, Dino Dai Zovi, exploited a vulnerability in QuickTime to take home the prize.

Dai Zovi, who congratulated Miller after his hack, didn't participate in this year's contest, saying it was time for someone else to win."


http://news.yahoo.com/s/infoworld/20...nfoworld/96676
iMind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 08:04 PM   #2
BOSS1
Confirmed User
 
BOSS1's Avatar
 
Join Date: Sep 2005
Location: Montreal / Sparta
Posts: 4,331
interesting news, will keep in mind not to use safari
__________________

NEW SITE: Stockings Kingdom
Lesbians in Latex, Lesbians in Stockings, Granny Sex, BDSM Porn, Latex and Sex, Custom Foot Fetish, Femdom Movies and Kinky Porn Pass.
300+ hosted flvs, 500+ hosted galleries, Page Peel ADs.. NATS export and payouts twice a month
BOSS1 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 08:31 PM   #3
crockett
in a van by the river
 
crockett's Avatar
 
Industry Role:
Join Date: May 2003
Posts: 76,806
lol I love it.. now maybe those Mac users can quit being so uppity about how much better and more secure they are.
__________________
In November, you can vote for America's next president or its first dictator.
crockett is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 09:06 PM   #4
CyR
Registered User
 
Join Date: Sep 2002
Posts: 50
Nothing really special in that report.

Windows: Idiots use IE.
MacOS: Idiots use Safari.

It's the standard thing installed on both OS', so in turn if the user had a clue, they would install something that wouldn't be targeted first by exploits. I use both OS' and I don't use either of those browsers.

Currently there's a few exploits going around that involve little to no user interaction on behalf of IE's wide variety of exploitable holes. I'm not saying that either OS is better than the other, it's more a scary fact that a majority of surfers (the ones that we target) have next to no idea about browser/OS security and are running around with hijacked machines.

In other words the more out of the spotlight your browser is, and the more the developers fix and update their software, the chance of your machine getting exploited due to some well known unpatched hole.

Random trivia: Back in the day, due to certain IE vulnerabilities you were able to grab a surfers complete MSN contacts list (emails and all) just from them surfing to your page. What a wonderful world we lived in.... not!
CyR is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 09:09 PM   #5
Pleasurepays
BANNED - SUPPORTING TUBES
 
Join Date: Aug 2002
Location: I live in a pile of boogers
Posts: 11,913
guess its time to THINK DIFFERENT..... just a little more
Pleasurepays is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 09:17 PM   #6
L-Pink
working on my tan
 
L-Pink's Avatar
 
Industry Role:
Join Date: Mar 2005
Location: Florida/Kentucky
Posts: 39,151
Safari? I thought Leopard was installed on all new macs?
L-Pink is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 10:13 PM   #7
GatorB
The Demon & 12clicks
 
Industry Role:
Join Date: Oct 2001
Location: SallyRand is a FAGGOT
Posts: 18,208
Quote:
Originally Posted by L-Pink View Post
Safari? I thought Leopard was installed on all new macs?
Safari=browser Leopard=OS you're thinking of Tiger.
GatorB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 10:18 PM   #8
iMind
Confirmed User
 
Join Date: Nov 2007
Posts: 937
Quote:
Originally Posted by CyR View Post
Nothing really special in that report.

Windows: Idiots use IE.
MacOS: Idiots use Safari.

It's the standard thing installed on both OS', so in turn if the user had a clue, they would install something that wouldn't be targeted first by exploits. I use both OS' and I don't use either of those browsers.

Currently there's a few exploits going around that involve little to no user interaction on behalf of IE's wide variety of exploitable holes. I'm not saying that either OS is better than the other, it's more a scary fact that a majority of surfers (the ones that we target) have next to no idea about browser/OS security and are running around with hijacked machines.

In other words the more out of the spotlight your browser is, and the more the developers fix and update their software, the chance of your machine getting exploited due to some well known unpatched hole.

Random trivia: Back in the day, due to certain IE vulnerabilities you were able to grab a surfers complete MSN contacts list (emails and all) just from them surfing to your page. What a wonderful world we lived in.... not!
I like safari, but am getting pretty used to Camino aswell...
For the most part I've been using Webkit but I'm not sure if it can be targeted the same as safari or not.

I expect any OS or browser to have holes in it really, no matter who coded it, there's someone smarter out there somewhere

Wonder if Apple will end up hiring this guy.
iMind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 10:26 PM   #9
CyR
Registered User
 
Join Date: Sep 2002
Posts: 50
Well if you keep yourself up to date, then any browser is fine. My beef is more with IE since it ties into the OS more than what Safari does.

There's a chance they might hire, but also, if you look at it a different way and wave a carrot infront of his face, $10,000 for each major exploit you find... you would have a loyal employee for life busy at messing with the OS. I think that if you are there with the developers you might overlook something, but if you are on the outside trying to get in, your efforts to find the holes are more thorough.
CyR is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 10:30 PM   #10
L-Pink
working on my tan
 
L-Pink's Avatar
 
Industry Role:
Join Date: Mar 2005
Location: Florida/Kentucky
Posts: 39,151
Quote:
Originally Posted by GatorB View Post
Safari=browser Leopard=OS you're thinking of Tiger.
You're right thanks (and I'm staring right at it)
L-Pink is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-27-2008, 10:38 PM   #11
pornask
So Fucking Banned
 
Join Date: Aug 2006
Location: 253-233-241
Posts: 6,518
sucks for that dude. He hacked piece of shit computer and got a piece of shit as his prize.
pornask is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-28-2008, 12:46 AM   #12
bDok
Confirmed User
 
bDok's Avatar
 
Join Date: Feb 2005
Location: SD/OC/LA
Posts: 1,917
I'm curious to know eventually what the disclosed attack was. Until it's actually reported I'm not going to read to much into this.
__________________
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Warriors come out to plaAAaayyy!
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
bDok is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.