Mac hacked in security contest via undisclosed Safari vulnerability

“A team of security researchers has won $10,000 for hacking a MacBook Air in two minutes using an undisclosed Safari vulnerability,” Tom Krazit reports for CNET.

“IDG News Service is camped out at CanSecWest in lovely Vancouver, Canada, and has chronicled the exploits (gotta love security puns) of Charlie Miller, Jake Honoroff, and Mark Daniel of Independent Security Evaluators during the Pwn to Own contest sponsored by TippingPoint. The team was able to gain control of a MacBook Air on the second day of the hacking competition,” Krazit reports.

“The team had attack code already set up on a Web site, and was able to gain access to the MacBook Air and retrieve a file after judges were ‘tricked’ into visiting the site. According to the TippingPoint DVLabs blog, a newly discovered vulnerability in Safari was used to gain control of the Air,” Krazit reports.

Full article here.

Robert McMillan reports for IDG New Service, “Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network, but on Thursday the rules were relaxed so that attackers could direct contest organizers using the computers to do things like visit Web sites or open e-mail messages.”

“Miller was quickly given a nondisclosure agreement to sign and he’s not allowed to discuss particulars of his bug until the contest’s sponsor, TippingPoint, can notify the vendor,” McMillan reports.

“Last year’s contest winner, Dino Dai Zovi, exploited a vulnerability in QuickTime to take home the prize,” McMillan reports. “Dai Zovi, who congratulated Miller after his hack, didn’t participate in this year’s contest, saying it was time for someone else to win.”

Full article here.

[Thanks to MacDailyNews Readers “David,” “The_Wzrd,” and “RadDoc” for the heads up.]

MacDailyNews Take: Congrats to Charlie Miller, Jake Honoroff, and Mark Daniel! 10 grand and a new MacBook Air ain’t too shabby. And thanks for helping make Safari safer!

UPDATE: 3/28, 11:07am EDT: Please note that the time it took to “hack” the Mac is utterly irrelevant. Yes, it took a few minutes at the conference, but the amount of time that went into discovering the vulnerability within Safari and creating the malevolent website to deliver the payload should obviously be counted by those who are obsessed with timing.

Standby for the deluge of FUD that’s sure to result from those with agendas that differ from those who are dedicated to simply reporting the facts. There is a lot of money behind keeping the increasingly-antsy Windows sheep in their pen. And lies and distortion are the only effective ammo they have left.

We immediately wondered, why they didn’t install Safari on the Windows laptop and “hack” that instead. Although the rules may bar installing additional apps, regardless, they probably wanted that MacBook Air. Then we looked at the CanSecWest list of sponsors which — you guessed it — includes Microsoft, but not Apple.

Check out RoughlyDrafted for more on this charade here.

68 Comments

  1. I would like to know exactly how they were “tricked” into visiting a site. Did they think they were going to win a pink iPhone? Did they get a shaking pop-up window saying they have a virus? Or did they get an email saying that Visa needed to confirm their personal information?

    Those are all VERY tricky (especially the pop-up window when it looks like it came straight from Win95).

  2. I wonder if this is with the latest Safari that was just released 3.1??

    Also I wonder how many people tried to have the Mac compared to the Linux and Windows machines?? Like was it 50 people tried to hack the mac and 5 tried to hack Linux and Windows over the 2 day period? Kinda hard to believe no one has hacked Windows yet!!

    I figured the Mac would be the first one to go with all the security news and stuff that the Mac is the most secure……kinda a slap in the face to us Mac users!!

  3. Maybe they were tricked into thinking it was an MDN article … and then BOOM! Air foiled!

    Seriously though, if it is invoked simply by visiting a site then Apple has a problem to solve. Good thing they’ll know about it first.

  4. From what i’ve read, it seems this guy was the first to try to hack into ANY of the machines. Meaning the Windows and Linux machines were not being hacked into at all. This guy just happens to be the first one up and he chose to hack the Mac. And he had to get the organisers to go to a specific website for the exploit to work.

    Also, i”m sure it took him much more than 2 mins to come up with the exploit in the first place. Reports so far have not been accurate at all, misleading at worst.

    Well, lets hope Apple closes the bug asap. In the meantime, get ready for the “Macs are not secure” crap from losers everywhere.

  5. Prior setup of the security exploit…

    then two minutes to send the judges an email and get them to go to the site…

    he didn’t discover and create the exploit in two minutes.

    Lets be real, during the prior day nobody achieved a break-in but just like last year everybody new the “conditions” would change.

    bogus

  6. Oh for crying out loud. Be happy. This will improve Mac security. It’s a good thing. I have declared myself the world’s screechiest and most annoying fanboy. If you don’t believe me, check rip-ragged.com. But I still think it’s cool that hackers are trying to hack the Mac.

    The best part is, with $10k on the table, smart hackers still needed social engineering to get the job done. One more reason to be glad I have Macs.

    Well done, Charlie. Keep up the good work.

  7. Yep perfect take from MDN. Get Apple to see the problem now and fix it. So Macs are safer than ever. While Windows still has its big ass wide open, to match their big ass table. ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

  8. @ Just Wondering

    Is your question an acknowledgment that you’re really dumb?

    No intelligent Mac user has ever (EVER) suggested that Mac is immune from invasion. It’s just that there’s nothing to be immune from, yet.

    Fact: There is still no Mac malware in the wild that can be downloaded without social engineering.

    None.

  9. Obviously he wanted the MacBook Air, not the other two lap tops . . . .Maybe all three operating systems should have been natively set up on one of three MBA’s.
    ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

  10. From the first article:

    As of the time I posted this, no one had gained control of the Vista or Ubuntu machines, but I’ll update later as the results come in over the rest of the afternoon.

    Spin it anyway you want but that stings. Expect MS fanboys to be all over that one.

  11. And a friend of mine who literally was angry at me for trying to convince him to go for a mac, will now probably say “See, macs are vulnerable too” and he will feel vindicated he went with Toshiba/Vista, and venture on in his malware infested world with a sense of satisfaction.

  12. You won’t find a bigger Mac fanboy than me. I have been advocating Macs for years and am typing this on my new MacBook Air. I have worked in the security industry for 15 years and all of you who say that social engineering doesn’t count are morons. The biggest threats in all of security are due to social engineering. Phishing, e-mail attachments, free porn, any number of techniques can be used to trick someone to a site. That doesn’t even count the fact that a hacker could simply take over a legitimate site and include this hack on their site.

    Security is a serious challenge faced by all OS vendors and you won’t hear Steve Jobs say any differently because he’s not stupid. It’s brainless fanaticism that prevents people from recognizing the real superiority of the OSX operating system.

  13. “As of the time I posted this, no one had gained control of the Vista or Ubuntu machines, but I’ll update later as the results come in over the rest of the afternoon.”

    No one is interested to hack Vista. It’s not challenging enough.

  14. here’s an interesting quote

    “The team had attack code already set up on a Web site, and was able to gain access to the MacBook Air and retrieve a file after judges were “tricked” into visiting the site. According to the TippingPoint DVLabs blog, a newly discovered vulnerability in Safari was used to gain control of the Air.”

    From this it seems that the contestants who won came prepared for that day’s round, and didn’t spend any time crafting or looking for the exploit as they targeted a vulnerability in Safari that was already known; hence the small amount of time it took to take over the MBA.

    I wonder if it would’ve taken 2 mins the take over had they been forced to look for the exploit and spend the day writing the code.

    While I congratulate them on their work, it seems somewhat disingenuous. It would be more shocking if they had discovered a new vulnerability during the course of the day, and not had been prepped in some way.

  15. Sure, social engineering counts. But it requires each machine to be infected independently, through misguided operation. It isn’t a vulnerability of the machine, but a vulnerability of the user. Or as my sainted granddaddy used to say, “It’s the loose nut behind the wheel.”

    You can’t make cars or computers any safer than the people who operate them.

  16. Here is a question I have been wondering about. Can simply going to a website open up terminal access to that website? I always thought terminal required a password to access.

  17. My bad, I miss read the part about the Safari vulnerability, as the rules and the TippingPoint site blog states it has to be a “a brand new 0day vulnerability”. That being said, I take back my statement of exploiting a known vulnerability.

    I do still stand by my opinion regarding the amount of time it took to execute the exploit.

    BTW, if you look at the pic on TippingPoint blog it appears that the contestants used a MBPro to construct or at least “trick” the contest to surf to there predesigned site.

  18. Did read original article, and have a lot of questions.

    What does it mean when they say:

    “to gain access … and retrieve a file … a newly discovered vulnerability in Safari was used to gain control of the Air.”

    Did they gain “access” or did they gain “control” ?

    And all they did was transfer a file ?

    Which file, what kind, from where ?

    If one of the obscure System/Safari files that might hold keychain info or a password in cache not yet dumped from a previous site, or something along those lines, then they might have something.

    But if, say, an mp3 … c’mon, we let folks have access to our computer all the time for those files everytime we fire up a p2p program. So there’s a definition of how someone “gained access and retrieved a file.”

    Need to have some more info and details about this for me to buy it as a real problem and believe someone can truly gain “control” of my machine.

    Anyone with insight in all this, please comment.

    Thanks, BC in Tally

  19. I don’t know how many times MDN has posted this caveat for other reasons, but it applies here as well.

    All computers have vulnerabilities and every Mac (probably) has 3rd party software from apps to plug-ins that potentially could be exploited. The Macintosh OS has tons of code from open source that has shown itself less than impenetrable.

    Before you flame, I’m not dissing the Mac OS. I use it every day and only use Windoze when paid to (at work) or when bailing out someone I know with a virus-trashed or crashed PC.

    Complex systems (and Mac OS X qualifies) open so many possible combinations and interactions of code that there are bound to be vulnerabilities. What is amazing is how well Apple has been able to stay ahead of the game.

    Bottom line- although the Mac is a solid OS it is not invulnerable and use your head so as not to be a sucker for socially engineered malware. Nothing you can buy is a replacement for common sense.

  20. Remember Apple boys and girls to always use protection when surfing with strangers. Abstinence is still the best policy but if you must, proper protection and common sense will help protect you against many STDs (Safari Transmitted Diseases).

    Gotta go. My PC just contracted Bird Flu.

  21. Whilst you can’t argue that it was hacked, I find the repeated mention of the 2 minute time period interesting. The people who did this obviously new of the exploit beforehand, new how to make the page and then take advantage of it. I would guess that there was a lot more than 2 minutes work involved.

    It’s also a little vague as to what they achieved, I don’t expect (and wouldn’t want) them to release how they did it, but what did they do? Did they control everything, have access to certain areas, what?

    I’m not trying to lessen the security threat, but these things are always so vague, yet very specific in their conditions.

  22. Yup, RoughlyDrafted explains things very well.

    Little has changed, except now the media with drum up their feeding frenzy based on this “independent academic research.”

  23. Social engineering that lead to exploits certainly does count as a security threat.

    Or, if it doesn’t count for OS X then it should not count for Windows either.

    Anyway, the question left unanswered is if they are able to gain access to the computer, are they doing so in a way that allows them to destroy/modify its content or is it a simple, “I’m in” kinda thing?

  24. Why is it that every time I read about one of these contests, there’s always something like the line “Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network, but on Thursday the rules were relaxed…”

    How about, just once, establishing the rules and sticking to them..? If no one can compromise a computer remotely, then the contest ends with no winners.

    But it always becomes “After contestants were allowed to sit in front of the Mac…” This doesn’t really impress me. If I have direct access to a Mac, I can see and manipulate its contents using an OS X install disc, and so can everyone else on this forum.

  25. Here we go again with another supposed hacking contest of a Mac. How many times have we heard this story only to find out later that they all CHEATED!!!! I put this story under a BIG FAT FUD ALERT!!!!

  26. Based on what was reported, there is way to much excuse-making on this thread by Apple fans. I’m a fan too, but this is clearly a problem for Apple/Safari that must be fixed. It is simply not acceptable for a hacker to either “gain access” or “take control” of a Mac just because it visits a website. Period.

  27. Mac heads are going to try to brush this aside like they always do (particularly on this site), but listen to what the winner said: Leopard was CHOSEN because it was the EASIEST to hack. Hear that? EASIEST. “Every time I look for [a flaw in Leopard] I find one.” said Miller. “I can’t say the same for Linux or Windows.”

    Hey MDN, what’s your smug “take” on that one?

  28. I gotta say, I am worried about Leopard. Tiger is so rock solid. And it was so much more stable and secure on release. I keep hearing and experiencing problems on Leopard that are not consistent will any of my OSX experience beyond 10.1. Now this…

  29. This guy just happens to be the first one up and he chose to hack the Mac.

    While that may be true, this wouldn’t have worked on a PC. No additional software is allowed to be installed on the computers to be hacked. Since PC’s aren’t preinstalled with Safari, the vulnerability wouldn’t be present on PC’s. One quick way to make your Mac safe would be to run Firefox.

    MDNMW: own. Are you kidding??

  30. Here’s something for the chicken littles to chew on… This isn’t the first time that a mac has been overtaken at an event like this or in a lab… But has any mac user just surfing the web ever reported an attack like this? No. I’m thinking “congrats to this guy, but I won’t worry about mac security until I get hacked/exploited/whatever by just getting on the web.” besides, you know apple will fix it pretty quickly.

    Sent from my iPod

  31. Every year it seems we get the same old story. First day nobody is able to do it. So they relax the rules the second day to insure some level of success. Where is the excitement and more importantly, the news coverage if no one wins.

  32. It’s too late! I’ve already got carpal tunnel…

    Seriously, I fear this provides ammo for Mac-haters.. then again, they probably don’t need ammo- nothing stopped them from buying into Windows before….

  33. MDN take “And thanks for helping make Safari safer!”

    Oh, I see, but if Windows were the first to fall (whatever the circumstances involved), MDN take will some sort of “another Windows failure”….. as usual when some vulnerability in Windows is found.

    Being a Mac user myself, sometimes I’m amazed at double standards at the Mac Community.

  34. Was he able to install a program? Email a file from the users account? Attach a file and infect other systems? I tire of the hyperbole surrounding these events. The bias is awful, but Apple supporters are supposed to be “fanatics” when they point out the lies and distortions?

  35. The Great Khali

    MDN take “And thanks for helping make Safari safer!”

    Being a Mac user myself, sometimes I’m amazed at double standards at the Mac Community.

    Call it a preemptive strike. If you’ve used the Mac for any period of time, you know the ignorance and stupidity practiced by the Microsoft adherents. This pointless exercise will be the fodder for thousands more blogs and stupid tech posts about how Mac OS X is “just as vulnerable” as Windows, when we know for a fact that this is simply not true.

  36. MDN is truly pathetic at times…

    “And thanks for helping make Safari safer!” Oh pleassse!

    “Please note that the time it took to “hack” the Mac is utterly irrelevant.”
    Of course it’s irrelevant – it’s a Mac which makes that measure irrelevant but if it was Vista well that would have been proof postive how crappy Vista is – which may be true – however the hypocrisy is just staggering.

    Please note this the Second Year Running that the Mac was hacked first which I’m certain is irrelevant and that Vista and Linux OS’s have yet to be hacked in this contest which is also irrelevant.

    It’s all just FUD – a great conspiracy to make Macs look bad. Microsoft sponsored the events so the “fix” must be in – right? Sure!

    The article notes that people cheered which is further proof of the conspiracy. Their cheering had absolutely nothing to do with the arrogance and hubris displayed by the maczealot community.

  37. In spite of this, I still love my Mac(s), I have several. I also continue to encourage folks to choose Apple over microsoft. But my visits to this website have dropped off significantly. The rhetoric here has just become too much. I dropped in to see how snotty the writers would react. “Thanks for making safari safer!” What, no smug wisecracks? No excuses on how this was unfairly executed? Just the usual “FUD” remark. FYI, the exploit was done on a fully patched and up-to-date mac running the latest version of Safari.. 3.1. Anti virus software would not have stopped this either. Grow up, get real, no computer is infallible. While Macs are not perfect, they are certainly better than Windows. Now quit being such a cocky lil snit, grow up be careful out there, and enjoy your Mac.

  38. @hs,
    So funny. I have never owned a PeeCee, Own Apple Stock and virtually every apple product. Own iWork, Final Cut etc. I have 4 mac in my house and two at work and I work in a Windoz office where I have to face those shmoes everyday. Fortunately at work, I still use Tiger and they have never seen a kernel panic screen (I laugh at their blue screens) but at home I have seen several under Leopard. I have used Disk Utility, TechTool and Disk Warrior. Reinstalled and all that.
    But gosh, you really got me…
    Just call me Curly, Moe, or Larry. You probably think anyone who says a word against the good ol’ USofA is a terrorist and anti-American – don’t you? Don’t you?

    MDW – piece as in ‘ain’t I a piece o’ work’

  39. This is the downside to open source software. Yes, you get many sets of eyes looking at code, but you’ll always have the nefarious odd lot who will use this to their advantage at everyone else’s expense. The good news is that it is easier to fix once the problem is understood.

  40. “This is socially engineered BS that won’t work “in the wild.””

    Social Engineering is responsible for about 90% of computer break ins Dufus. Clearly you have no understanding of what does and doesnt work “In the Wild”.

    “Fact: There is still no Mac malware in the wild that can be downloaded without social engineering.”

    Would you like to add a few more conditions to the absoluteness of Mac Security? Most computer users are stupid. for Mac users that’s doubly true.

    “The people who did this obviously new of the exploit beforehand, new how to make the page and then take advantage of it. I would guess that there was a lot more than 2 minutes work involved.

    Pre preparing an attack! How unfair! All those windows viruses have people hacking each and every machine live in real time. Not.

    “How about, just once, establishing the rules and sticking to them..?”

    Because he rules for these contests usually start out with “Lets see if somebody can hack the system while its sitting turned off in it’s shipping box” and proceed through to “lets see if somebody can hack the systems when used in the way a normal Internet user uses them” That’s when the Mac fell.

    Or to put it another way, the rules state that each day the rules will change.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.