MacBook hacked in contest at security event

update VANCOUVER, B.C.--Shane Macaulay just got himself a free MacBook.

Macaulay, a software engineer, was able to hack into a MacBook through a zero-day security hole in Apple's Safari browser. The computer was one of two offered as a prize in the "PWN to Own" hack-a-Mac contest at the CanSecWest conference here.

MacBook hacker
Credit: Joris Evers
Hack-a-Mac winner Shane Macaulay
attacks a MacBook at the
CanSecWest conference.

The successful attack on the second and final day of the contest required a conference organizer to surf to a malicious Web site using Safari on the MacBook--a type of attack familiar to Windows users. CanSecWest organizers relaxed the rules Friday after nobody at the event had breached either of the Macs on the previous day.

Macaulay teamed with Dino Dai Zovi, a security researcher until recently with Matasano Security. Dai Zovi, who has previously been credited by Apple for finding flaws in Mac software, found the Safari vulnerability and wrote the exploit overnight in about 9 hours, he said.

"The vulnerability and the exploit are mine," Dai Zovi said in a telephone interview from New York. "Shane is my man on the ground."

Apple spokeswoman Lynn Fox declined to comment on the MacBook hack specifically, but provided Apple's standard security comment: "Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users."

Dai Zovi plans to apply for a $10,000 bug bounty TippingPoint announced on Thursday if a previously unknown Apple bug was used. "Shane can have the laptop, I want the money," Dai Zovi said. TippingPoint runs the Zero Day Initiative bug bounty program.

A TippingPoint representative said the company would pay, after looking at the vulnerability. "If it is an actual zero-day in Safari that's fine with us," said Terri Forslof, manager of security response at TippingPoint.

The successful hack comes a day after Apple release its fourth security update for Mac OS X this year. The update repairs 25 vulnerabilities.

CanSecWest organizers set up the MacBooks connected to a wireless router and with all security updates installed, but without additional security software or settings.

More from News.com on this story's topics

Flaws

RSS feed

IDS

Create an email alert | RSS feed

Events

RSS feed

Safari

RSS feed

Security

Create an email alert | RSS feed

Apple

Create an email alert | RSS feed

See more CNET content tagged:
TippingPoint Technologies, Apple MacBook, contest, vulnerability, Apple Safari

Add a Comment (Log in or register) 194 comments (Page 1 of 3)
Safari got hacked.
by Macsaresafer April 20, 2007 5:03 PM PDT
Still no root level hack. But Cnet will be cnet, so we get this title.
Reply to this comment View all 4 replies
Shine some light on anything
by sanenazok April 20, 2007 5:03 PM PDT
and you'll find flaws. I feel bad for the guy who wasted perfectly good 9 hours to hack into this platform.
Reply to this comment View all 2 replies
Security Software Updates?
by Llib Setag April 20, 2007 5:23 PM PDT
Did this MacBook have the latest Mac OSX Security Software updates that CNET reported very recently about on this site?

Which version of MAC OSX was on the MacBook? OSX 10.4.9 with latest security updates?

Mac & PCS both are not hack proof & Apple has never said it was, but Apple & MacOSX has a loooooooooooooooong way to go before ever catching up to Windows security problems ( even VISTA OS ).
Reply to this comment View reply
What got Hacked
by dscottbuch April 20, 2007 5:40 PM PDT
Once again typical CNet reporting. What exactly got hacked.

"The successful attack on the second and final day of the contest
required participants to surf to a malicious Web site using
Safari--a type of attack familiar to Windows users. CanSecWest
organizers relaxed the rules Friday after nobody at the event had
breached either of the Macs on the previous day."

So its considered to be hacked to simply surf to a web site?
Also, how were the rules relaxed???? It seem they COULDN'T
hack it as originally set up???

Why can't CNET at least provide a link to the real story.
Reply to this comment View all 2 replies
I wonder...
by System Tyrant April 20, 2007 7:05 PM PDT
what people will say if the Mac is every hacked and root access is gained?

That's a rhetorical question because if the Mac is successfully hacked someday like that Mac fanboys will find some way that it wasn't really a hack. On the other hand Windows and maybe Linux fanboys will be pointed and saying we told you so.

The reality is that all software has flaws and some flaws in some software will allow the hacker to gain full control over a entire system. I think it's a much safer and less arrogant statement to say that the Mac could possibly be hacked, but due to flaws being fixed quickly and the fact that it has a good platform under it it's less likely to be hack in any meaning full manner.

But that's probably asking to much. :-P
Reply to this comment View reply
Not correct
by keaggy220 April 20, 2007 7:56 PM PDT
Go back and read the article...

The article states the hack occured on the second day and only
after the rules were relaxed. Personally, I can't believe how tight
OSX is...

i imagine a lot of Mac haters that participated are having a bad
weekend - haha...
Reply to this comment
Dude don't let your Mac hate
by keaggy220 April 20, 2007 8:00 PM PDT
screw up your logic... It was hacked at user level and only after the
people running the contest realized they were about to be totally
embarrassed because nobody was even able to do that - so bent
the rules... This, to me, is priceless... haha
Reply to this comment View reply
Good News!
by jypeterson April 20, 2007 9:23 PM PDT
This is good news on several levels.

1) The Mac was exploited which means that it is one more flaw that will be corrected by Apple.

2) The first day went by without a successful attack. Macs will be able to continue to fend off attacks.

3) The root level test is still not won. This is very good because the hierarchy within OSX is robust.

4) No successful wild viruses or Trojans for OSX (so far). It continues to be the case for the ~22 million OSX users (and five years of OSX) that there is not a virus in the wild that exploits OSX. Impressive.

There are flaws in all software, but the fact remains that OSX (and Linux) is far more secure than any Windows operating system.
Reply to this comment View reply
Hacked only after rules were relaxed...
by Matthew R. April 21, 2007 4:09 AM PDT
You notice something, the caveat to the entire hack issue is that it
was hacked after, and only after the rules were changed. If the
rules stayed the same, there could of been a very good chance the
MacBook Pro may never of been hacked. I'd like to know what rules
they changed, and how it affected the end results.
Reply to this comment View all 2 replies
How about a truly meaningful "real world" hack?
by drdocument April 21, 2007 7:51 AM PDT
Rather than creating an artificial set of conditions, how about a
practical test?

I consider myself an "average" Mac user, OS 10.4.9 with all updates,
OS X firewall on (default), one user with admin privileges, always-
on DSL connection with firewall enabled in DSL router (default).

Can you reach my Mac? If so, can you do any meaningful harm?
Reply to this comment View all 3 replies
1 | 2 | 3 | Next 10 Comments >>
Powered by Jive Software
advertisement
RSS Feeds
Add headlines from CNET News.com to your homepage or feedreader.
Google
Yahoo
MSN
More feeds available in our RSS feed index.
Today's Top Stories
YouTube can't blame Viacom for ad woes
Study: Prescription-free drug sites still abound
Australia's Telstra restricts iPhone supply lines
DailyCandy and the blogs-to-books trend
Bank of America may finally support Firefox
Most Popular Stories
T-Mobile rumored to be readying Android phone for 3G launch
Photos: Supercomputing at Oak Ridge
Geeks get a word in with Merriam-Webster
3G iPhone up for grabs online--or is it?
Formula One design vet creating eco-smart city car
Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

Markets

Market news, charts, SEC filings, and more

Related quotes

Apple (0.25%) 0.45 180.00
Dow Jones Industrials (0.00%) 0.00 11,384.21
S&P 500 (0.00%) 0.00 1,273.70
NASDAQ (-0.14%) -3.22 2,291.22
CNET TECH (0.00%) 0.00 1,604.34
  Symbol Lookup
Update your drivers with Version Tracker Pro
Learn more about Version Tracker Pro

advertisement
On GameSpot: Wii Fit tells 10-year-old she's fat
Advanced
search
Advanced
search
Visit other CBS Interactive sites