|
|||||||||||||||||
Safari zero-day exploit nets $10,000 prize20th April 2007 23:38 GMT
A New York-based security researcher spent less than 12 hours to identify and exploit a zero-day vulnerability in Apple's Safari browser that allowed him to remotely gain full user rights to the hacked machine. The feat came during the second and final day of the CanSecWest "pwn-2-own" contest in which participants are able to walk away with a fully-patched MacBook Pro if they are first able to hack it.
The exploit means that Dino Dai Zovi is the rightful owner of the 2.3Ghz 15-inch MacBook Pro and a $10,000 prize offered by Tipping Point, which runs the Zero Day Initiative bug bounty program. More importantly, his work effectively throws cold water on tired claims from Apple and its many lackeys that the Mac is all but immune from the kind of security attacks more regularly perpetrated against Windows-based machines. Related stories
Dai Zovi, who is not attending the conference, was recruited on Thursday night by Shane Macaulay, a friend and conference attendee. The ease Dai Zovi found in pwning the machine was all the more remarkable, given an update Apple pushed out yesterday patching 25 Mac security holes. Macaulay described Dai Zovi's vulnerability as a client-side javascript error that executed arbitrary code when Safari visited a booby-trapped website. The pwn-2-own contest got off to a slow start on Thursday. The rules originally mandated an exploit that required no action on the part of the user. The reward for a successful hack was the machine that had been compromised. Conference attendees were underwhelmed, reasoning a Mac exploit that required no end-user interaction could be sold for upwards of $20,000. Things changed significantly on Day 2. That's when Tipping Point upped the ante with its promise of a $10,000 bounty. Contest organizers also relaxed the rules so exploits could include malicious websites that attacked Safari. At the time of writing, a second MacBook Pro had successfully withstood attacks. ® 31 comments posted — Comment period finished Of course...Posted: 23:55 20th April 2007 Yup...Posted: 00:04 21st April 2007 Oh, give me a break.Posted: 00:54 21st April 2007 95% of exploits are application basedPosted: 01:28 21st April 2007 This contest is dead.Posted: 01:29 21st April 2007 |
Hot Product ReviewsSony Walkman S seriesMost Wanted Mac
Data from Pricegrabber Review FinderAccessories
Price FinderTop Stories
ChannelsSmart SearchClick on these links for subjects, companies, and products related to the page you’re viewing. |
||||||||||||||||
|
|||||||||||||||||