MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

Deal of the Day

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Sat, Mar 20, 2010 - 01:07 PM EDT  —  AAPL: 222.2499 (-2.4001, -1.07%)  |  NASDAQ: 2374.41 (-16.87, -0.71%)

Apple MacBooks hold strong, remain unhacked after first day of $10,000 ‘Hack a Mac’ challenge
Friday, April 20, 2007 - 10:46 AM EDT

Apple Store"Two tricked-out MacBook laptops have survived the first day of a 'PWN to OWN' contest that dared hackers to take control of default Mac OS X installations," Ryan Naraine blogs for ZDNet.

"The contest started around midday Thursday, the second day of the CanSecWest conference here and triggered interest from hackers in attendance... Organizers say they have seen 'some activity' on the network set up with the two new MacBooks — a 17" and a 15" — but details remained scarce when the day ended," Naraine reports. "To win, the attacker must commandeer the machine and find a file with instructions on how to SSH to a server to authenticate the hijack."

Naraine reports, "On the second day, the barrier will be lowered a bit and the attackers will be allowed to put exploit code on a special wiki and launch drive-by exploits on the Mac's built-in Safari browser. If the machines survive this level, the attacker will be allowed to connect to over USB or Bluetooth."

Full article here.

MacDailyNews Take: If they really want to give away the MacBooks and the $10,00 prize, on the third day they ought to install Boot Camp and Windows on them. It would probably take about 10 minutes to find a winner.



Apple Store Advertisements
iPhone 3G S: From $199. Free shipping.
New 13-inch MacBook: From $999. Free shipping.
13-inch Macbook Pro: From $1199. Free shipping.
13-inch MacBook Air: From $1499. Free shipping.
15-inch Macbook Pro: From $1699. Free shipping.
17-inch MacBook Pro: From $2499. Free shipping.
New Mac mini: From $599. Free shipping.
New iMac 21.5-inch: From $1199. Free shipping.
New iMac 27-inch: From $1699. Free shipping.
Mac Pro: From $2499. Free shipping.
iPod touch: From $199. Free Shipping.
iPod nano: Now shoots video! From $149. Free shipping.
iPod shuffle: From $59. Free engraving. Free shipping.
Apple TV: From $229. Free shipping.

Send us links! Email: webmaster@macdailynews.com

MacDailyNews on Twitter

MacDailyNews app for iPhone and iPod touch

Related articles:
CanSecWest sweetens ‘Hack a Mac’ contest pot to $10,000 - April 20, 2007
CanSecWest to hold ‘PWN to OWN’ contest: pits Apple MacBook Pros vs. hackers - March 26, 2007
Microsoft’s oft-delayed, much-pared-down Windows Vista hacked at Black Hat - August 07, 2006
Microsoft publicity stunt asks hackers to attack Windows Vista - August 04, 2006
Apple Mac remains ‘unhacked’ as University of Wisconsin’s Mac OS X Security Challenge ends - March 08, 2006
Mac OS X ‘unhacked’ over 24 hours and counting in genuine security challenge - March 07, 2006

Bookmark and Share

Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: = registered.
Unregistered users: Feedback from multiple usernames are subject to deletion. Off-topic and posts from suspected astroturfers will be removed.

Reader feedback page 1 of 2 pages:  1 2 >
Apr 20, 07 - 10:59 am Comment from: Matrix3

@MDN:
That's so funny!!!
ROTFL

Apr 20, 07 - 11:00 am Comment from: Gilles

"Organizers say they have seen 'some activity' on the network set up with the two new MacBooks [...]"

It seems there is not much interest...

Apr 20, 07 - 11:02 am Comment from: Matrix3

Wow - first post without trying!
Cool

Apr 20, 07 - 11:02 am Comment from: PalmerDeville

So each day they're going to "lower the barrier" until the final story coming out of the conference is "Macbook hijacked!"

Apr 20, 07 - 11:03 am Comment from: Simple1

Great take MDN, this is why i come here

MW "lost" - As in all is lost when any form of windows is installed on a mac!! lol

Apr 20, 07 - 11:03 am Comment from: Nick Holla

hahahaha @ MDN

that's prob what they will end up doing!!!

Apr 20, 07 - 11:06 am Comment from: quito

its just sad they have to 'lower the barriers' so they can actually hijack the macbook (pro, since its a 15'' and 17''). Yea i can't wait for the headlines 'Macbook hijacked!!' cause everyone in the windows world won't take the time to read how they 'lowered the barriers' to even get the job done. Friggin idiots.

Apr 20, 07 - 11:11 am Comment from: ndelc

I agree. Why are they lowering the barriers? Not very realistic, and in the end whatever non-mac-enthusiast press that picks it up will do their typical half-assed job of fact finding. Waiting for it...

Apr 20, 07 - 11:12 am Comment from: Machiavelli

The stunt is sponsored by M$. Bill Gates is pissed because everyone is laughing at him for saying Macs are compromised every day.

The rigged rules drop the Mac's defences until an attack is successful. Then Gates can say, "Neener, neener. I was right."

Apr 20, 07 - 11:18 am Comment from: M.X.N.T.4.1

Does it count if they literally hijack and physically steal the thing?

Apr 20, 07 - 11:18 am Comment from: RevNeal

How far down must the defenses go before the Mac can be hijacked?
Anyone have an idea?

Apr 20, 07 - 11:19 am Comment from: G-Spank

It seems there is not much interest...

Yeah, there's rarely interest in $10,000. If there's any lack of interest, it's because hackers already know it's futile.

Apr 20, 07 - 11:20 am Comment from: Former MG

Hell no! And they won't get hacked into!
To Hell with Bill Gates and that fat monkey boy anyway.

Apr 20, 07 - 11:20 am Comment from: john

Let's see if anyone can actually hack them without cheating. So far everyone who has put up a challenge like this has gotten a winner but only because they cheated and had physical access to the Mac.

If this is legit than there will be no winner unless they reboot into Bootcamp and Windows like MDN said.

Apr 20, 07 - 11:22 am Comment from: Investor

Naraine reports, "On the second day, the barrier will be lowered a bit and the attackers will be allowed to put exploit code on a special wiki and launch drive-by exploits on the Mac's built-in Safari browser. If the machines survive this level, the attacker will be allowed to connect to over USB or Bluetooth."

Ok, that just seems wrong. It was too tough, so we'll let you gain physical access to it? Baah

Apr 20, 07 - 11:24 am Comment from: @ Matrix3

@ Matrix3

Way to go man.... first post without even trying.... you be da MAN!

Apr 20, 07 - 11:25 am Comment from: loganson

Common sense would tell you not to lower the barriers. It sounds like the public schools. The students can't pass the test so you just make the tests easier. This makes dumber students and an incompetent workforce.

What will they end up doing, giving the person hands-on access complete with admin password?

Apr 20, 07 - 11:28 am Comment from: Arnoso

That is the funniest MDTake i have read in many years.

Cheers!

Apr 20, 07 - 11:37 am Comment from: LordRobin

Whee! I'm gonna do the Smug Dance now! Smug smug smuggy smug, I'm so smug! Woo-hoo! Eat it, Windows-lovers!

Every time someone tries to engineer a publicity stunt to show folks like me how "insecure" our Macs are, it always backfires and demonstrates just how ridiculously safe Mac OS X really is!

Smugness level at 9 and climbing!

Apr 20, 07 - 11:43 am Comment from: Less is More

Meanwhile, back in Redmond, the security team is burning the midnight oil....

Apr 20, 07 - 11:49 am Comment from: MacMania

Kind of hard to say you "hijacked" the MacBooks when they'll basically end up giving the "hackers" the keys to the ride.

The sponsors and whoever in the end claims they "jacked" the Mac should feel pretty stupid.

raspberry

Apr 20, 07 - 12:00 pm Comment from: Drunk Cheney

Where is the VISTA $10,000 hack challenge?

Apr 20, 07 - 12:00 pm Comment from: One Guy

At the fourth day tbarrier will not only lowered, but removed and hackers will be allowed to install Windows Vista on the Macbook.

Apr 20, 07 - 12:08 pm Comment from: montex

I wonder if by "lower the barrier" they mean give out the administrator password. This contest would have been a lot more interesting if they had a Vista PC along with the Macs for hacking.

However, If I were to put myself in the hacker's shoes, I might find that this "contest" only proves that Macs are so much harder to get into and are far more secure. Having this demonstrated by an unsuccessful live hacking, why would I continue to use a PC? I wonder how many hackers will leave this conference convinced that Macs are inferior to PCs and how many will be visiting an Apple store soon.

Apr 20, 07 - 12:22 pm Comment from: loganson

To make things more interesting, they should have put a pc with XP and a pc with Vista in the contest.

Then we would have seen the huge contrast.

Apr 20, 07 - 12:24 pm Comment from: denuj

Yeah, it's pretty lame to lower the barrier. It's like leaving your front door unlocked or open, depending on how they lower the barrier, and then asking if the house can be burglarized. Hehehe.

Windows users will only want to hear a hijacked Mac, IF IT HAPPENS, and not how it was hijacked.

@MDN, can somebody please fix the link? Thanks.

Apr 20, 07 - 12:33 pm Comment from: Qka

Another article on this, with some different facts:

http://www.securityfocus.com/news/11460

So M.X.N.T.4.1, someone is actually sitting there watching the hardware, and has a third computer monitoring the other two.

Apr 20, 07 - 12:35 pm Comment from: Frank

Question for you readers in the know: Apple issued a Sec update yesterday. Assuming it is not applied to the MacBook pros used in this contest can hackers use the breaches the patch fixes and to gain control of the machines?

Apr 20, 07 - 12:36 pm Comment from: Bill

Gee, to hear them talk, Bill Gates and George Ou should have strolled in there and taken the MacBooks by now.

Apr 20, 07 - 12:43 pm Comment from: WiseGuy

[B]Not a true contest, conditions rigged

Under normal conditiions the Mac would on the internet 24/7.

Put those two bitches online, they would be pwned in a day guarranteed.

So put that fanboism back in the can right now.

Apr 20, 07 - 12:46 pm Comment from: M. T. MacPhee

Frank:

Yesterday's Security Update was applied to the machines, and then they were put online.

Apr 20, 07 - 12:51 pm Comment from: Jim - TIV

Wiseguy is smokin' that funny weed again.

Apr 20, 07 - 01:08 pm Comment from: DLMeyer

The first phase of "lowering the barriers" is entirely realistic! The second phase, direct connect, is not. Quite a number of the exploits hitting the Windows crowd are Web-based, so there's little reason to deny them the chance to take advantage of that option. USB or Bluetooth? You are not getting that close to my workstation ... not without an escort.

Oh, and Wiseguy? What's with the bogus attempt to open BOLD text without a "close" statement? Sounds like something a troll would do.

DLMeyer - the Voice of G.L.Horton's Stage Page Pod-Cast

Apr 20, 07 - 01:39 pm Comment from: drmacnut

Hey WiseGuy, isn't this a competition only for those at the conference? So the Macs are open to only them on the network. That's the point of the whole thing.

Apr 20, 07 - 01:49 pm Comment from: Traveler

@ Wiseguy. "Put those two bitches online, they would be pwned in a day guarranteed [sp]." I don't know how you would get the idea that these macs are not connected to the internet. Let me spell it out for you, these Macbooks are connected to the internet, Hackers are connecting remotely from their computers and trying to hack it to gain access to files on it. How would the contest work if the mac were not networked? Did you think the hackers were physically sitting in front of the laptop?

About people complaining about "lowering the barriers": I think that's an excellent idea, and the conditions are fair. On the second day, the mac will visit a wiki page in Safari that hackers will be using to attempt drive-by exploits. This is fair because in the wild, a user might run into a website specifically engineered to perform an exploit. I know a couple URLs like that, that will instantly fuck up a Windows computer on Internet Explorer. It's only fair to test the mac under these conditions, since computers are often hacked through malicious websites.

On the third day, hackers will be connecting directly through USB and Bluetooth. Again, this is fair, because users might be subjected to this type of thing in the wild. I've accidentally infected a Windows computer over USB before.

This will be a tough challenge, and I for one want to know the results. I have confidence that Mac OS X under default settings will once again emerge itself impervious. If it is possible to hack into Mac OS X, I want to know the truth. I don't want to be coddled like some half-retarded fanboy. If someone can hack into one of these Macbooks, I can handle the news, and have great interest in knowing the truth of the matter.

Apr 20, 07 - 02:31 pm Comment from: theloniousMac

CHEAT PEOPLE!!!!

CHEAT!!!!

THAT'S THE FOUNDATION OF HACKING!!! DON'T JUST TRY TO HACK THE COMPUTER!!! HACK THE CONTEST!!!

Jeeze. Do I have to do everything?

Apr 20, 07 - 03:17 pm Comment from: =[corrected]

@ Drunk Cheney
Where is the VISTA $10,000 hack challenge?

At $20 right now. (See my last post.)

@ theloniousMac
CHEAT PEOPLE!!!!

CHEAT!!!!

THAT'S THE FOUNDATION OF HACKING!!! DON'T JUST TRY TO HACK THE COMPUTER!!! HACK THE CONTEST!!!


Yeah, that's right! Go right to the contest location and manually use the machine. If the MacBook won't let you, then you know what they say…

IF YOU CAN'T HACK IT, WHACK IT!!!!

Thank you for your lack of support, and remember that the "Hack a PC" contest reward has just dropped from a $20 bill to a $18.96 bill.

Apr 20, 07 - 03:31 pm Comment from: Well well well

today is last day of the contest.

Seems those $10k were as safe as if in a bank.

Apr 20, 07 - 03:43 pm Comment from: BuriedCaesar

I'm certainly not going to be "lowering any barriers" to make it easier for a hacker/cracker to get into my machine, and I'm surrounded by PCs at work, so why should they? Realistic or not, doing that seems to me to be changing the terms of the contest in mid-stream. Lessens the impact of success, and will surely be fodder for FUD in the mainstream press if someone manages to do something with the "lesser" barrier, let alone the absolutely crazy notion of giving physical access.

My take is that if nobody could PWN the machines under the original parameters, then no one gets to OWN - and the $10k does not change hands.

Apr 20, 07 - 03:48 pm Comment from: ken1w

> How far down must the defenses go before the Mac can be hijacked?

Not until someone sticks a Post-It note on the edge of the display with the user name and password (an all too common practice).

Apr 20, 07 - 03:57 pm Comment from: Not Today

Bill Gates says Macs are hacked everyday.

Not yesterday!

Apr 20, 07 - 04:11 pm Comment from: ../.

BuriedCaesar: "I'm certainly not going to be "lowering any barriers" to make it easier for a hacker/cracker to get into my machine, and I'm surrounded by PCs at work, so why should they? Realistic or not, doing that seems to me to be changing the terms of the contest in mid-stream. Lessens the impact of success, and will surely be fodder for FUD in the mainstream press if someone manages to do something with the "lesser" barrier, let alone the absolutely crazy notion of giving physical access."

I think lowering the barrier is a good idea of a measure at how hard it is to hack into something. If you stick only with the original condition, all you know is no one hacked into it at that condition and did not investigate other vectors of attack based on easier conditions which are just as realistic (i.e. if you browse a suspicious website or if someone has a physical access to your computer). It is one way of finding that lowest level of the barrier and try to raise it from that level. This is a security conference and not a PR job. They probably couldn't care less about what journalists think.

Apr 20, 07 - 04:20 pm Comment from: BuriedCaesar

@../.

Good point, and I agree with you in principle about those parameters in that respect, but we can also be absolutely sure there are some "journalists" out there who are lurking around, hoping beyond hope that something DOES happen, and they're going to get their hands on this news one way or another, especially if there IS a successful crack, and they certainly won't care at what "level" that occurred, and they certainly won't attempt to explain it to the masses in any way that makes sense.

If there's no successful "attack", then it becomes non-news. A non-event. And sadly, it will be much, much less likely to get reported, because those same media sharks won't smell any blood.

Apr 20, 07 - 04:48 pm Comment from: WiseGuy

Hey WiseGuy, isn't this a competition only for those at the conference? So the Macs are open to only them on the (local) network. That's the point of the whole thing.

Well that's why I said it's rigged.

Put those bitches on the internet instead and they would be pwned.

It's not a matter of lowering the conditions, but making the challenge more realistic to actual conditions that all our Mac's face.

Apr 20, 07 - 05:53 pm Comment from: Big Al

Let's hope the Admin password is not steve or jobs or apple or something equally as obvious.

Physical access is physical access. Every previous proof of concept exploit used physical access.

Of course, every previous exploiter, with their proof of concept exploit, also had the admin password. Anyone can hack their own computer.

Apr 20, 07 - 06:39 pm Comment from: Say again?

There is no Airport Extreme wireless card in either machine, that's why no one has hacked 'em. Fooled ya!

Apr 20, 07 - 07:25 pm Comment from: t0mb0

One Macbook Pro down. An exploitable safari flaw, triggered by a malicious webpage.

Apr 20, 07 - 07:30 pm Comment from: jay

I love Apple, I use Apple. But I've NEVER understood the total smugness on the part of the fanboys-review all of the early comments, particularly MDN's. Apple is safer by far than Doze, but I hope this is a wakeup. A serious in the wild compromise WILL happen, it's just a matter of time.

Apr 20, 07 - 07:47 pm Comment from: Traveler

@t0mb0, do you have a link about this? I can't find coverage to confirm or deny that.

Apr 20, 07 - 07:50 pm Comment from: jay

Link below:

http://www.macworld.com/news/2007/04/20/hacker/index.php

Apr 20, 07 - 08:09 pm Comment from: Gilles

I'm sceptical. How come this was'nt done before ? And if it's real, maybe security through obscurity was true, after all.

Reader feedback page 1 of 2 pages:  1 2 >

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my info   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: