Notices
All Things Apple The Teamspeed Genius Bar!
Enter here to discuss your Apple products including iPhone, iPod, MacBooks and more!

Safari / Mac Hacked

Thread Tools
 
Search this Thread
 
Old Mar 20, 2009 | 04:57 PM
  #1  
Paul N's Avatar
Thread Starter
|
Teamspeed Member
Joined: Feb 2008
Posts: 109
From: California
Paul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura aboutPaul N has a spectacular aura about
Safari / Mac Hacked

Pwn2Own 2009: Safari/MacBook falls in seconds | Zero Day | ZDNet.com

VANCOUVER, BC — Charlie Miller has done it again. For the second consecutive year, the security researcher hacked into a fully patched MacBook computer by exploiting a security vulnerability in Apple’s Safari browser.

“It took a couple of seconds. They clicked on the link and I took control of the machine,” Miller said moments after his accomplishment.


The contest kicked off at exactly 3:15 PM and, within seconds, Miller launched his drive-by attack and claimed the $10,000 top prize. He also got to keep the MacBook machine.

Miller said he came to the CanSecWest security conference with a plan to hack into Safari and had tested the exploit carefully to ensure “it worked the first time.”

TippingPoint’s Zero Day Initiative has acquired the exclusive rights to the vulnerability and coordinate the disclosure and patch release process with Apple.

Technical details of the vulnerability will not be released until a patch is ready.

Several hackers are currently attempting exploits against Internet Explorer 8 and Firefox but those browsers are still standing.
 
Old Mar 20, 2009 | 05:33 PM
  #2  
Simba's Avatar
Banned
Joined: Jan 2008
Posts: 3,264
Simba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond reputeSimba has a reputation beyond repute
Poor reporting as usual. It's a javascript exploit in the beta 4 which has been known to developers for some time. It'll be patched shortly, and only has the ability to compromise those who are galactically stupid.
 
Old Mar 20, 2009 | 06:01 PM
  #3  
Craddosk's Avatar
Teamspeed Member
Joined: May 2008
Posts: 193
Craddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond reputeCraddosk has a reputation beyond repute
And, it requires a visit to a particular web page, and the user performing some tasks. I would only go with the most computer illiterate getting caught on the bug. Or those that don't pay attention to where they are surfing to.
 
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
cleanme
Gadgets & Electronics | Home Theater | Gaming
2
Aug 19, 2010 12:15 PM
Envious Eric
Detailing & Paint Protection
3
Oct 22, 2009 06:29 PM

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 



All times are GMT -4. The time now is 09:44 PM.