Overclock.net banner

[zdnet] Pwn2Own 2009: Safari/MacBook falls in seconds

3462 Views 62 Replies 44 Participants Last post by  Lige
Quote:
VANCOUVER, BC â€" Charlie Miller has done it again. For the second consecutive year, the security researcher hacked into a fully patched MacBook computer by exploiting a security vulnerability in Apple’s Safari browser.

“It took a couple of seconds. They clicked on the link and I took control of the machine,†Miller said moments after his accomplishment.
Source
1 - 20 of 63 Posts
ahahahhaahahhh
Quote:
"It took a couple of seconds. They clicked on the link and I took control of the machine,"
Proving that once again the greatest security flaw is users.
2


Quote:
Several hackers are currently attempting exploits against Internet Explorer 8 and Firefox but those browsers are still standing.


Quote:
It took a while longer but Microsoft's Internet Explorer 8 did not survive the hacker onslaught at this year's CanSecWest Pwn2Own contest.
http://blogs.zdnet.com/security/?p=2934
See less See more
Quote:

Originally Posted by Modki View Post
Proving that once again the greatest security flaw is users.
Yulp.
See less See more
Yeah, it would be trivial to really lock down those systems, but the users keep wanting to get work done!
See less See more
Quote:

Originally Posted by Modki View Post
Proving that once again the greatest security flaw is users.
Yeop.
See less See more
Good, maybe this will show people that Mac's are not completley secure and that you still need to be careful.
Firefox and IE8 have fallen now as well.

Chrome is the only browser atm that is still standing. Opera is not part of Pwn2Own.

Link

EDIT: Nils will supposedly crack Chrome tomorrow. 15k ain't bad for a days work.
Same as last year, Apple is proven to be by far the most insecure platform.
Wow...not good.
However this really doesn't say too much; all these attacks were planned weeks and months ago; so how quickly it "fell" doesn't really correspond to much.

No matter what OS, security and being careful is paramount.
Quote:

Originally Posted by arekieh View Post
ahahahhaahahhh
x2.

OSX and linux really aren't more secure than Windows. Most of the Windows viruses need user interaction to work. As long as you aren't stupid you are no more likely to get a virus using Windows as you are with Linux/OSX. In fact Windows is likely more secure as most Windows users have anti-viruses that protect the user from their own stupidity.

It comes down to the market share. This contest is proof that if people cared about writing non-windows viruses, its pretty easy to do.

Hackers don't care about OSX, and of the non-revenue driven Windows viruses, I would wager that most of them are made by linux enthusiasts, who would have no desire to target their own system.
See less See more
  • Rep+
Reactions: 1
Why can't they just get it right? They've got a fast browser out with some good features, but they can't get the security right. What a shame.
Quote:


Originally Posted by The Hundred Gunner
View Post

Why can't they just get it right? They've got a fast browser out with some good features, but they can't get the security right. What a shame.

Nothing will ever be 100% secure because of one variable you can't count on....people. People as a whole are stupid and will click on anything you want them to as long as you have some flashy graphics or the promise of money/prizes. The only way to make anything completely secure is not let any idiots use it. So until they make a browser that can't be used by the general populace they're all gonna have security issues.
See less See more
Quote:


Originally Posted by Puscifer
View Post

Nothing will ever be 100% secure because of one variable you can't count on....people.

I understand that, but I'm sure a corporation can do better than getting owned within seconds two years in a row.
See less See more
1 - 20 of 63 Posts
This is an older thread, you may not receive a response, and could be reviving an old thread. Please consider creating a new thread.
Top