Tech ARP Forums

Go Back   Tech ARP Forums > Site Updates & Promotions > News
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

News Post your comments about the top news posted at Adrian's Rojak Pot!

Reply
 
LinkBack Thread Tools
Old 29th Mar 2008, 12:34 PM   #1 (permalink)
Administrator!
 
Dashken's Avatar
 
Join Date: 21 Apr 2003
Location: Penang
Posts: 29,763
Reputation: 2162
Dashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond repute
Rep Power: 56
Default Gone in 2 minutes: Mac gets hacked first in contest

Quote:
It may be the quickest $10,000 Charlie Miller ever earned.

He took the first of three laptop computers -- and a $10,000 cash prize -- Thursday after breaking into a MacBook Air at the CanSecWest security conference's PWN 2 OWN hacking contest.

Show organizers offered a Sony Vaio, Fujitsu U810 and the MacBook as prizes, saying that they could be won by anybody at the show who could find a way to hack into each of them and read the contents of a file on the system, using a previously undisclosed "0day" attack.

Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network, but on Thursday the rules were relaxed so that attackers could direct contest organizers using the computers to do things like visit Web sites or open e-mail messages.

The MacBook was the only system to be hacked by Thursday, however, the word on the show floor is that the Linux and Vista systems will meet with some serious challenges on Friday.

Miller, a former National Security Agency employee best known as one of the researchers who first hacked Apple's iPhone last year, didn't take much time. Within 2 minutes, he directed the contest's organizers to visit a Web site that contained his exploit code, which then allowed him to seize control of the computer, as about 20 onlookers cheered him on.

He was the first contestant to attempt an attack on any of the systems.

Miller was quickly given a nondisclosure agreement to sign and he's not allowed to discuss particulars of his bug until the contest's sponsor, TippingPoint, can notify the vendor.

Contest rules state that Miller could only take advantage of software that was pre-installed on the Mac, so the flaw he exploited must have been accessible, or possibly inside, Apple's Safari browser.

By late Thursday, Apple engineers were already working on patching the issue, said Aaron Portnoy, a TippingPoint researcher who is one of the contest's judges.

Miller's $10,000 payday may sound sweet, but it's not the most Miller has been paid for his work. In 2005, he earned $50,000 for a Linux bug he delivered to an unnamed government agency.

Last year's contest winner, Dino Dai Zovi, exploited a vulnerability in QuickTime to take home the prize.

Dai Zovi, who congratulated Miller after his hack, didn't participate in this year's contest, saying it was time for someone else to win.

Shane Macaulay, who was Dai Zovi's co-winner last year, spent much of Thursday trying to hack into the Fujitsu Vista laptop, at one point rushing back to his Vancouver area home to retrieve a file that he thought might help him hack into the system.

But it was all in vain.

"It's one thing to find a vulnerability, it's another thing to make working exploit code," said Terri Forslof, TippingPoint's Manager of Security Response.

Forslof said that a number of "high quality" researchers have said that they will attempt to hack the machines on Friday, the last day of the conference.

She expects both systems to be hacked on Friday, when contest rules will be further eased, and hackers will be able to attack popular third-party software that can be installed on the systems. "I don't think we'll have to take any home," she said.

Source: Gone in 2 minutes: Mac gets hacked first in contest | IDGNS | News | March 27, 2008 | By Robert McMillan, IDG News Service
__________________
| Intel Core 2 Duo E6850 @ 3.2Ghz | ASUS P5B-E Plus | G.SKILL 2x1GB DDR2 800 | 6 HDDs (2TB+ only ) | NVIDIA GeForce 7600GT | Dell E248WFP 24" Widescreen |


Blog : Dashken's I-Blog
Gallery : Dashken's I-Paintings
Dashken is offline   Reply With Quote
SPONSOR

Old 29th Mar 2008, 06:40 PM   #2 (permalink)
Pickin' Da Gitfiddle
 
Mac Daddy's Avatar
 
Join Date: 19 Nov 2007
Location: Canada
Posts: 2,048
Reputation: 802
Mac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to behold
Rep Power: 12
Default

Saw the title and was hoping it wasn't me lol

Is it just me or is there something a little off about awarding prizes to hackers
Mac Daddy is offline   Reply With Quote
Old 30th Mar 2008, 01:21 AM   #3 (permalink)
Administrator
 
Chai's Avatar
 
Join Date: 6 Oct 2002
Location: Maranello
Posts: 26,757
Reputation: 3984
Chai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond repute
Rep Power: 72
Default

Quote:
Originally Posted by Mac Daddy View Post
Saw the title and was hoping it wasn't me lol

Is it just me or is there something a little off about awarding prizes to hackers
lol...

Interesting to have such contest...
__________________
Chai (Contributor & Forum Admin)
http://www.techarp.com/
Chai is offline   Reply With Quote
Old 31st Mar 2008, 11:35 AM   #4 (permalink)
beat around the bush
 
aKho's Avatar
 
Join Date: 3 Jun 2005
Location: Kuching, Sarawak
Posts: 2,806
Reputation: 1169
aKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud ofaKho has much to be proud of
Rep Power: 17
Default

it's good la, help expand the minds of us users and at the same time, fixing loopholes and ensuring our privacy. especially when most of us have "pink folders" we don't wish people to know about.
__________________
aKho is offline   Reply With Quote
Old 31st Mar 2008, 03:00 PM   #5 (permalink)
Administrator!
 
Dashken's Avatar
 
Join Date: 21 Apr 2003
Location: Penang
Posts: 29,763
Reputation: 2162
Dashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond repute
Rep Power: 56
Default Vista was PWN!

Quote:
Vista notebook falls in hacker challenge

March 30, 2008 (Computerworld) A security researcher on Friday exploited a critical bug in Adobe Systems Inc.'s Flash Player to hack a notebook running Windows Vista Ultimate, the second machine to fall in this year's "PWN To OWN" challenge.

The only unclaimed laptop of the original trio by the contest's end was a Sony Vaio running the Ubuntu distribution of Linux.

Shane Macaulay, a consultant with Security Objectives, claimed the $5,000 cash prize by breaking into a Fujitsu U810 running Windows Vista Ultimate SP1 late Friday. According to 3Com Inc.'s TippingPoint, which put up the prizes for the three-day hacker challenge at CanSecWest, Macaulay exploited an unidentified zero-day vulnerability of the ubiquitous Flash Player.

Macaulay, who was assisted by Derek Callaway, also of Security Objectives, and Alexander Sotirov, an independent researcher, was the second PWN To OWN winner. Thursday, Charlie Miller from Independent Security Evaluators hacked a MacBook Air using a vulnerability in Apple Inc.'s Safari browser to win the notebook and a $10,000 check from TippingPoint.

The Austin, Tex.-based security company, perhaps best known for its Zero Day Initiative (ZDI) bug bounty program, announced Macaulay's win in a post to its blog.

Like Miller, Macaulay was bound by a nondisclosure agreement with TippingPoint, which under the PWN To OWN rules acquired the vulnerability its ZDI. TippingPoint said it has reported the bug to Adobe. "Until Adobe releases a patch for this issue, neither we nor the contestants will be giving out any additional information about the vulnerability," the company said in the blog post.

The hack challenge, which kicked off last Wednesday, expanded the notebooks' exposure to attack after the first and second days. No one, for example, walked away with the first day's $20,000 prize, which had required that researchers break into one of the laptops using a remote code-execution exploit that didn't rely on any user interaction. Miller won his $10,000 and the MacBook Air after attacks were allowed on installed-by-default applications, and user action could be replicated.

On Friday, when Macaulay took down Windows Vista, contest organizers added a number of popular third-party client applications to the remaining two notebooks, including Adobe's Acrobat Reader and Flash Player, the Firefox browser, and Skype, a voice-over-Internet program.

Adobe patched Flash Player several times last year. The most recent large-scale security update was issued last December to plug nine holes in the software.

Macaulay also had a part in 2007's inaugural PWN To OWN contest, which pitted a single computer, a MacBook Pro, against all comers for a $10,000 prize. Although Dino Dai Zovi provided the QuickTime exploit that hacked the machine last year, Macaulay served as his on-site partner.

Source: Vista notebook falls in hacker challenge
__________________
| Intel Core 2 Duo E6850 @ 3.2Ghz | ASUS P5B-E Plus | G.SKILL 2x1GB DDR2 800 | 6 HDDs (2TB+ only ) | NVIDIA GeForce 7600GT | Dell E248WFP 24" Widescreen |


Blog : Dashken's I-Blog
Gallery : Dashken's I-Paintings
Dashken is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Kingston to Launch HyperX Girl Design Contest Dashken News 3 25th Mar 2008 08:51 AM
Seagate Momentus Hard Disk Giveaway Contest! Dashken Contests! 280 30th Sep 2005 12:40 AM
The PDP Gigabyte Memory Giveaway Contest! Dashken Contests! 237 7th Aug 2005 12:12 PM
The Hunt For The BOG Book Contest! Dashken Contests! 117 1st Mar 2005 10:27 PM


All times are GMT +8. The time now is 03:23 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2007 Tech ARP. All rights reserved.