eWeek Security Watch
Advertisement
Advertisement
April 20, 2007 12:17 AM

Unpatched Macs Snatched from Hackers' Clasp



Two shiny, new and delightfully unpatched Mac systems were sitting ducks at the CanSecWest security conference on April 19, while top-notch hackers were clustered in hotel rooms, frantically trying to remotely pwn the systems before the show organizers had a chance to apply 25 patches Apple released on the same day.

Apple released the security patches for Mac OS X and then made a beeline to the phone to inform the organizers of CanSecWest, where, as Apple was well aware, a "pwn-2-own" contest was ongoing.

To the dismay of conference hackers, CanSecWest organizers beat them to the punch, patching the systems before they were pwned.

(Pwn is a slang term; Wikipedia defines it thus: "...'to compromise' or 'to control', specifically another computer [server or PC], web site, gateway device, or application; it is synonymous with one of the definitions of hacking. An outside party who has 'owned' or 'pwned' a system has obtained unauthorized administrative control of the system." Wikipedia notes that the term is used primarily in the gaming culture, where it is sometimes used for taunting enemies and rubbing in victories; Wikipedia fails to note, however, that the same gleeful needling is employed in hacking circles.)

Winners of the pwn-2-own contest take home either a 2.3Ghz 15" Macbook Pro, for which they have to gain remote access as a default user, or a 2.3Ghz 17" Macbook Pro if they remotely gain administrative rights and dig out a file at root level. As HD Moore and other famed hackers noted, however, the value of the systems isn't near what a hacker could get by selling a Mac zero-day vulnerability. Therefore, a representative from TippingPoint announced on Thursday that the jackpot had been sweetened by a cash award of $10,000.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/10805

Comments (4)

Joe Blow :

More irresponsible urinalism...

So how long did they try to hack them before the updates?

You give the impression they could've been owned had they not been patched. Of course you convienently fail to provide any proof.

Morons!

Sean Comeau :

You made a typo.

The Macs were FULLY patched. There is not yet a patch for the flaw used.

Qurmudjin :

I have held off buying OSX mainly because I like the full security I feel on the internet using OS 9.2.2, but this news makes me feel a little better about the relative safety of OSX.
Does anyone know of previously "pwned" Macs running OSX?

The unpatched machines were identical to the ones that clueless Apple customers would have received from their local store, eh?

Shame on Apple! They should either patch the machines prior to shipping, have the store do it prior to release to customer, or only allow limited operation until the machine is brought up to current patch standards.

This is a completely valid approach, because Apple manufactures 100% of the hardware and software on the machine, and hence has a commensurate level of responsibility to assure that the machine cannot be hacked out of the box.

Post a Comment

 
 
RSS Syndication
Advertisement

CAG

SEO

Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise