tombrennan.org

it’s good to know things

Mac gets cracked in under 10 seconds.

Just because your computer is a Mac doesn’t make you safe from attacks that can get into your system.  That was proven at the CanSecWest convention’s PWN2OWN contest in which a Mac running Safari was cracked in under 10 seconds.

safari iconCharlie Miller, who is a security researcher, could not discuss many details due to the nature of the contest rules simply stated that the Mac was fully patched and was running the Safari web browser, which was also fully patched.
Miller works as a principal analyst at Independent Security Evaluators LLC.  He is now a proud owner of the MacBook he used to show the exploit and a $5,000 cash prize.

In the same contest a researcher cracked a Sony laptop using the beta version of Windows 7 and Internet Explorer 8.  The Windows version of Safari was also used on the same laptop.

Although not disclosed, it is highly likely that bother instances of these exploits could be executed by using a phishing attack, in which a user would click on a link that they think is for a legitimate use.  This link really points to a website that hosts the exploit.

Thu, March 19 2009 » tech