Safari/MacBook First To Fall At Pwn2Own 2011
recoiledsnake writes "A team of security researchers from the French pen-testing firm VUPEN successfully exploited a zero-day flaw in Apple's Safari browser to win this year's Pwn2Own hacker challenge. The hijacked machine was running a fully patched version of Mac OS X (64-bit). Bekrar's winning exploit did not even crash the browser after exploitation. Within five seconds of surfing to the rigged site, he successfully launched the calculator app and wrote a file on the disk without crashing the browser. Apple has just released Safari 5.0.4 and iOS 4.3 a few minutes before the Pwn2Own contest in an attempt to save face (a last minute patch for Chrome was also released) but failed."
It's called "Pwn2Own": the hackers win the machines they hack.
Everyone wants Macs. They hack them first. The other computers come down minutes later.
I'm a Mac user and fortunately not a mindless one (honest, promise!). That Apple has been extremely lucky in not being overrun in exploited machines has more to do with the normal target area for exploiters being windows due to marketshare, but Macs have a big enough marketshare these days to make it worthwhile for crackers. I'm pretty sure that the time will come when Macs will be running dubious AV products like most Windows people do.
The most interesting and disappointing thing about Pwn2Own for me was that all the recent development of sand-boxing in browsers suggested that they were going to herald in a new era of browser security.
In actual fact it turns out that, thanks sloppy implementations, they aren't very good at their job.
Avantslash - View Slashdot cleanly on your mobile phone.
I'm not talking just about Apple - note that I was talking generally, and even specifically mentioned Google as an example - it's right there in my comment. I am talking about the contest as a whole, including all of the operating systems and browsers involved, but feel free to ignore my point and just have an Apple bash. After all, we are on slashdot.
Also, talking about this specific bug, it was an exploit in WebKit - so are you now saying that WebKit is an Apple product? After so many years of "Apple just took KHTML and rebranded it and claimed all the credit" posts on slashdot, now suddenly it *is* an Apple product? You can't have it both ways.
My original point was referring to all browsers and operating systems involved, both with OSS components and closed code.
There is no other way of putting it. When you get served, you get served. and apple, has got served. much better for apple and its fans to take lessons from it, accepting the result, to better their stuff, than to try to spin and defend it.
Read radical news here
Well that headline is misleading at best I'd say. I suggest reading pwn2own day one: Safari, IE8 fall, Chrome unchallenged in which it states that both Safari and IE fell at the first attempt, clearly it was a matter of nothing more than the ordering. Apologies for disturbing all the anti-apple ranting but both systems are weak. Please feel free to resume posting uninformed comments now.
There is something strange about how this is worded, as the first hacker - taking down Safari/MacOS - won 15k$. It sounds really strange if that price was decided just by the ordering of attempts.
Every year headlines claim platforms "pwned" in seconds but it's misleading and sensationalist.
The exploits are researched and practiced over days or weeks, rehearsed and simply repeated on the day. Yes it's bad, yes it demonstrates insecurity but the headlines imply that some guy just sits down at a fresh machine, sight unseen, decides to have a go at hacking it and within seconds it's done.
Of course the exploits take seconds to run - they are running them on computers - they are fast.
I'm sure they get faster every year.
It's funny how those of that *do* say those things about Macs are conveniently ignored on slashdot, or lumped in as one job lot with people who know nothing about security and claim that OS X is immune. Or even have our intelligence questioned for our choice of computing environment. It's really quite tiresome.
The specific bug that was exploited in this case is in WebKit, so it's a concern for any browser based on it - Apple or not. The purpose of the contest is PR, but does lead to exploits being exposed and patched (albeit held back by the people going for the prizes so they have something to deploy as soon as the contest begins - it took those guys a lot of work to get it to the stage where they could deploy it quickly - they could have disclosed their method some time ago [but the same is true for all the exploits used in this contest, on all of the platforms]).
The attack order of the machines really has little ultimate value in the end - the fact that security holes exist in the first place is the take home message. I hope OS X keeps getting attacked - the more exploits are found, the more get closed off. I am careful with my machine, but I welcome disclosure and patching of bugs.