News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Hardware
Average Rating:
Rate this article:  
MacBook Air Hacked -- But It Was the Browser MacBook Air Hacked -- But It Was the Browser's Fault
By Jennifer LeClaire
March 28, 2008 10:56AM

    Bookmark and Share
Hacker Charlie Miller nets $10,000 and a laptop for hacking Apple, Inc.'s MacBook Air in two minutes. But analysts say it could just as well have been a Windows PC since Miller was using Apple's flawed Safari browser at the CanSecWest conference. Apple has been notified of the new, undisclosed vulnerability in Apple's Safari browser.
 

Related Topics

Apple
Safari
MacBook Air
Security



First he hacked Apple's iPhone. Now he's hacked Apple's MacBook Air. But some analysts are warning not to be quick to judge security based on Charlie Miller's work.

Miller, a researcher at Independent Security Evaluators, won $10,000 and a laptop Thursday at the CanSecWest security conference's Pwn 2 Own hacking contest. He did it by hacking the MacBook Air -- and it took him all of two minutes.

CanSecWest organizers offered a Sony Vaio, Fujitsu U810 and a MacBook as booty for hackers who could find a way to breach security and gain access to the contents of system Relevant Products/Services files using a previously undisclosed zero-day attack. A zero-day attack is the exploitation of unpatched software vulnerabilities.

Picking on Apple

The first day of the contest, hackers were only allowed to hack into the computers over a network Relevant Products/Services. No one was able to claim the prizes. On the second day, the rules changed. Contestants were allowed to use the machines to visit Web sites and open e-mail messages. The new rules were a game-changer for Miller, who almost immediately found a way in.

Miller is familiar with Apple's architecture. He is perhaps best known as one of the first researchers to hack Apple's iPhone. This time around, he hacked the MacBook Air by visiting a Web site with exploit code he created. That code allowed him to take control of the computer as onlookers enjoyed the show. Jake Honoroff and Mark Daniel were on the Miller team from Independent Security Evaluators.

"They were able to exploit a brand-new zero-day vulnerability in Apple's Safari Web browser. Coincidentally, Apple has just started to ship Safari to some Windows Relevant Products/Services machines through its iTunes update service Relevant Products/Services. The vulnerability has been acquired by the Zero-Day Initiative, and has been responsibly disclosed to Apple, who is now working on the issue," according to the TippingPoint Relevant Products/Services DVLabs blog. TippingPoint sponsored the contest.

Until Apple releases a patch for this issue, TippingPoint said neither the company nor the contestants will offer additional information about the vulnerability. Apple could not immediately be reached for comment.

Missing the Security Point?

"Contest results like these are not indicative of how generally secure any of these devices or their respective browsers are," said Mike Haro, a senior security analyst at Sophos, referring to Windows Vista and Ubuntu machines that were also part of the contest. "Anyone looking to draw conclusions about the inherent security of Apple's MacBook Air based on this contest is missing the point."

The point is that browsers continue to be a major security issue. Browsers are the vector through which attackers lure victims to Web sites that contain malicious code. And the Safari browser is coming up with dangerous flaws lately -- for both Mac and Windows.

Indeed, Miller's hack into a MacBook Air could have just as easily have been a PC running Windows and Safari. Just this week, Argentinian hacker Juan Pablo Lopez Yacubian discovered two critical flaws in Apple's Safari 3.1 browser for Windows.
 

Tell Us What You Think
Your Comment:



Advertisement


 Hardware
1.   IBM Power7 Server Takes on Big Load
2.   Embattled JooJoo Tablet To Ship Soon
3.   The iPad's Potential Threat to PCs
4.   Oracle Moves To Calm Sun Customers
5.   Apple Talks To Publishers on Tablet


advertisement
The iPad's Potential Threat to PCsThe iPad's Potential Threat to PCs
Could erode sales of netbooks, tablets.
Average Rating:
Apple Talks To Publishers on TabletApple Talks To Publishers on Tablet
To include e-book titles on new device.
Average Rating:
Configuring a Notebook ComputerConfiguring a Notebook Computer
Pick processors, speed and memory.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.