• »Sign In
  • »Sign Up
  • Check Out
  • »FAQs

    China Electronics Wholesaler

    E-mail:
    Password:
    • SHOPPING
    • Features
    • Specials
    • New Arrivals
    • NEWS
    • BLOG
    0 Items(s)(US$0.000)
    • All Topics
    • >>
    • Gadgets
    • Submit a New Story
    • 19
    • dig it

    MacBook Air Hacked -- But It Was the Browser's Fault

    Jennifer LeClaire, newsfactor.com Fri Mar 28, 1:56 PM ET

    First he hacked Apple's iPhone. Now he's hacked Apple's MacBook Air. But some analysts are warning not to be quick to judge security based on Charlie Miller's work. ADVERTISEMENT

    Miller, a researcher at Independent Security Evaluators, won $10,000 and a laptop Thursday at the CanSecWest security conference's Pwn 2 Own hacking contest. He did it by hacking the MacBook Air -- and it took him all of two minutes.

    CanSecWest organizers offered a Sony Vaio, Fujitsu U810 and a MacBook as booty for hackers who could find a way to breach security and gain access to the contents of system files using a previously undisclosed zero-day attack. A zero-day attack is the exploitation of unpatched software vulnerabilities.

    Picking on Apple

    The first day of the contest, hackers were only allowed to hack into the computers over a network. No one was able to claim the prizes. On the second day, the rules changed. Contestants were allowed to use the machines to visit Web sites and open e-mail messages. The new rules were a game-changer for Miller, who almost immediately found a way in.

    Miller is familiar with Apple's architecture. He is perhaps best known as one of the first researchers to hack Apple's iPhone. This time around, he hacked the MacBook Air by visiting a Web site with exploit code he created. That code allowed him to take control of the computer as onlookers enjoyed the show. Jake Honoroff and Mark Daniel were on the Miller team from Independent Security Evaluators.

    "They were able to exploit a brand-new zero-day vulnerability in Apple's Safari Web browser. Coincidentally, Apple has just started to ship Safari to some Windows machines through its iTunes update service. The vulnerability has been acquired by the Zero-Day Initiative, and has been responsibly disclosed to Apple, who is now working on the issue," according to the TippingPoint DVLabs blog. TippingPoint sponsored the contest.

    Until Apple releases a patch for this issue, TippingPoint said neither the company nor the contestants will offer additional information about the vulnerability. Apple could not immediately be reached for comment.

    Missing the Security Point?

    "Contest results like these are not indicative of how generally secure any of these devices or their respective browsers are," said Mike Haro, a senior security analyst at Sophos, referring to Windows Vista and Ubuntu machines that were also part of the contest. "Anyone looking to draw conclusions about the inherent security of Apple's MacBook Air based on this contest is missing the point."

    The point is that browsers continue to be a major security issue. Browsers are the vector through which attackers lure victims to Web sites that contain malicious code. And the Safari browser is coming up with dangerous flaws lately -- for both Mac and Windows.

    Indeed, Miller's hack into a MacBook Air could have just as easily have been a PC running Windows and Safari. Just this week, Argentinian hacker Juan Pablo Lopez Yacubian discovered two critical flaws in Apple's Safari 3.1 browser for Windows.

    Submitted:
    245 days ago
    Submitter:
    robot_post
    Topic:
    Gadgets
    Source:
    news.yahoo.com
    • Take-Two urges stockholders not to sell to Electronic Arts
    • Wii Leads Jump in Japan's Game Market
    • Xbox Live Cheaters Hit With Penalties
    • New "Rainbow Six" game refines formula
    • Dell Rolls Out Sub-$900 Laptop with Blu-ray Drive
    • Sony unveils new Gran Turismo in London "pit lane"
     
    3.5 inch IDE or SATA HDD Enclosure Portable Media Player with Print Server and Bit Torrent, CHHP-IAS-035-01
    Sample Price:US$69.372
     
    Chessboard Style - 2.1 Inch Touch Screen - Metal GSM Watch Mobile Phone, MADB-W1025
    Sample Price:US$154.826
    Comments (0)
    • Add Your Comment
    • Please login or register to submit your comment.
      • What are the benefits of having a Dig account?
      • Share your opinion by posting comments on the stories that interest you
      • Dig the stories that you like and help determine what should be popular on Digg
      • Create a network of friends, so you can help each other find interesting stories
      • Start building a history of content that you've Dugg, for easy reference later
     
    Longevity and a Good Harvest I
    Sample Price:US$57.924
     
    Longevity and a Good Harvest II
    Sample Price:US$57.924
    CUSTOMER SERVICE SHOPPING HELP MY ACCOUNT COMPANY INFO TOOLS & RESOURCES
    • Contact Us
    • RMA Request
    • Looking for a item
    • Send Us a Message
    • Shopping Process
    • Return Policy
    • FAQs
    • Knowledge Base
    • Login/Register
    • My Account
    • Order History
    • My Wish list
    • About Us
    • Wholesale News
    • Customer Comments
    • Bank Account Info
    • Site Map
    • Downloads
    • Search
    • Links

    visamastercarddiscoverecheckamexpaypalPayPal VerifiedUCC

    Policies | Privacy Notice | Copyright © 2006 China Electronics Wholesaler Inc. All rights reserved.