On CBS MoneyWatch: 10 Most Expensive U.S. Colleges
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Mar 7, 2006 2:38:00 AM

A clarification was made to this story. Read below for details.

update Gaining root access to a Mac is "easy pickings," according to an individual who won an OS X hacking challenge last month by gaining root control of a machine using an unpublished security vulnerability.

On Feb. 22, the Sweden-based Mac enthusiast set up his Mac Mini as a server and invited hackers to break through the computer's security and gain root control, which would allow the attacker to take charge of the computer and delete files and folders or install applications.

Participants were given local client access to the target computer and invited to try their luck.

Within hours of going live, the "rm-my-mac" competition was over. The challenger posted this message on his Web site: "This sucks. Six hours later, this poor little Mac was owned, and this page got defaced."

The hacker who won the challenge, who asked ZDNet Australia to identify him only as "Gwerdna," said he gained root control of the Mac in less than 30 minutes.

"It probably took about 20 or 30 minutes to get root on the box. Initially, I tried looking around the box for certain misconfigurations and other obvious things, but then I decided to use some unpublished exploits--of which there are a lot for Mac OS X," Gwerdna told ZDNet Australia.

According to Gwerdna, the hacked Mac could have been better protected, but it would not have stopped him because he exploited a vulnerability that has not yet been made public or patched by Apple Computer.

"The rm-my-mac challenge was set up similar to how you would have a Mac acting as a server--with various remote services running and local access to users...There are various Mac OS X-hardening guides out there that could have been used to harden the machine, however, it wouldn't have stopped the vulnerability I used to gain access. There are only limited things you can do with unknown and unpublished vulnerabilities. One is to use additional hardening patches--good examples for Linux are the PaX patch and the Grsecurity patches. They provide numerous hardening options on the system and implement nonexecutable memory, which prevent memory-based corruption exploits," Gwerdna said.

Gwerdna concluded that OS X contains "easy pickings" when it comes to vulnerabilities that could allow hackers to break into Apple's operating system.

"Mac OS X is easy pickings for bug finders. That said, it doesn't have the market share to really interest most serious bug finders," Gwerdna added.

Apple's OS X has come under fire in recent weeks with the appearance of two viruses and a number of serious security flaws, which have since been patched by the Mac maker.

In January, security researcher Neil Archibald, who has already been credited with finding numerous vulnerabilities in OS X, told ZDNet Australia that he knows of numerous security vulnerabilities in Apple's operating system that could be exploited by attackers.

"The only thing which has kept Mac OS X relatively safe up until now is the fact that the market share is significantly lower than that of Microsoft Windows or the more common Unix platforms...If this situation was to change, in my opinion, things could be a lot worse on Mac OS X than they currently are on other operating systems," Archibald said at the time.

An Apple Australia representative said on Monday that the company was unable to comment at this stage. Representatives at Apple's Cupertino, Calif., headquarters could not be reached for comment.

Munir Kotadia of ZDNet Australia reported from Sydney.

 

Clarification: The story has been updated to clarify that participants were given local client access to the target computer.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 289 Talkback(s)
Finally
Finally some one who is educated to understand what this story is
about - Thumbs up. (Read the rest)
Posted by: keydesignz Posted on: 04/08/06 You are currently: a Guest | | Terms of Use
The article author is obviously pro-MS  NonZealot | 03/06/06
RE: The article author is obviously pro-MS  richdave | 03/06/06
He's joking  george_ou | 03/06/06
Since ZDNet editors have both Mac and PC - ...  Vily Clay | 03/06/06
Suggestions: ...  Vily Clay | 03/06/06
suse 10?  Scott W | 03/06/06
Because real life competition will drive progress and SuSe too. (NT)  Vily Clay | 03/07/06
i dont have trouble  linuxoverwindows | 03/08/06
Repot this George  Fred Fredrickson | 03/07/06
I disagree with the facts reported  tic swayback | 03/06/06
RE: I disagree with the facts reported  richdave | 03/06/06
Funny how ZDNet left that out  tic swayback | 03/06/06
Not so huge a distinction  NonZealot | 03/06/06
Can't take it as seriously  tic swayback | 03/06/06
Tic, you could have said it shorter ? Mac is better because YOU want to...  Vily Clay | 03/06/06
Vily, that is so freaking funny  tic swayback | 03/06/06
Didn't you, Tic, take lessions from Stalin?  Vily Clay | 03/06/06
Put a Win2kSP4 server on the Internet...  The King's Servant | 03/06/06
Oh Vily  tic swayback | 03/06/06
Tic, if you?d have half a brain ? you?d check it. Note ? I checked it (NT)  Vily Clay | 03/06/06
RE: Funny how ZDNet left that out  richdave | 03/06/06
Sort of  tic swayback | 03/06/06
Remotely exploiting Macs is easier  joopbraak | 03/12/06
This just in, Windows XP hacked in 20 seconds,,,  jinko | 03/06/06
You've been drinking the zealot kool aid again.  No_Ax_to_Grind | 03/06/06
It's true though  voska | 03/06/06
Yup, yet the FUD keeps on rollin'  NonZealot | 03/06/06
How old?  ianbetteridge | 03/07/06
Does it matter?  rapson | 03/06/06
Yes! No local user logging required  The King's Servant | 03/06/06
That's not the point  rapson | 03/07/06
Ya. Sure, Go back to bed.  Cayble | 03/06/06
count  Network Support | 03/06/06
And Apple is  Mectron | 03/06/06
heh..  thatxbxtchxnicoll | 03/06/06
Mac vs Windows  amaref | 03/06/06
Does it change anything for Joe Average?  dddd_z | 03/06/06
It shows that Joe Average...  doctormoriarty | 03/07/06
It's a bird! It's a plane!  handydan918 | 03/07/06
Never mind, It's just  handydan918 | 03/07/06
Does anything ever change  suirauqa | 03/08/06
This is a story?  wearthefoxhat | 03/06/06
RE: This is a story?  richdave | 03/06/06
A Mac fan here w/ sense  GSavage777 | 03/06/06
RE: A Mac fan here w/ sense  richdave | 03/06/06
Well isn't this true of ANY OS even BSD?  Laff | 03/06/06
How do you know OS X is more secure than XP?  Anton Philidor | 03/06/06
Thought this was an interesting piece  tic swayback | 03/06/06
Because George Ou says it is!  thelemite | 03/07/06
I haven't seen it.  nomorems | 03/06/06
Nice  GaryN | 03/07/06
Gee, that's wird................  wearthefoxhat | 03/06/06
RE: Gee, that's wird................  richdave | 03/06/06
The fact that you clicks the link to read the new says it all.  KOR_Hian_Loon@... | 03/07/06
This is a pathetically bad joke  tic swayback | 03/06/06
Interesting..  Patrick Jones | 03/06/06
They gave the hacker an account???  jinko | 03/06/06
And you are making a pathetically bad excuse  toadlife | 03/06/06
Read for a change  BitTwiddler | 03/06/06
take off the Apple tinted goggles  toadlife | 03/06/06
Understand what this means  tic swayback | 03/06/06
Welcome to the Internet, Tic.  JetJaguar | 03/06/06
Go back to what I said  tic swayback | 03/06/06
No, I'm not  tic swayback | 03/06/06
I agree  toadlife | 03/06/06
He's not arguing that fact.  thatxbxtchxnicoll | 03/06/06
A very good point..  No_Ax_to_Grind | 03/06/06
Yes - imagine a publishing house who  Hugh Jass | 03/06/06
Whoa... noone mentioned that...  el1jones | 03/06/06
Like I wrote earlier...  nomorems | 03/06/06
Microsoft?  Dragonn | 03/10/06
Tic, I found this challenge interesting for another reason  NonZealot | 03/06/06
I think it proves he's an idiot  tic swayback | 03/06/06
Question..  cashaww | 03/07/06
I think it proves he is a liar  nomorems | 03/06/06
Where did you obtain this information?  ye | 03/06/06
Try here  tic swayback | 03/06/06
Who is Dave Schroeder?  ye | 03/06/06
Find out for yourself  tic swayback | 03/06/06
Thanks...  ye | 03/06/06
OK...Dave responded to my e-mail and...  ye | 03/06/06
More details here  tic swayback | 03/06/06
I see no facts to support that success was the...  ye | 03/06/06
Well...  tic swayback | 03/06/06
Also note  tic swayback | 03/06/06
How do we know it's the same challenge?  ye | 03/06/06
I guess it doesn't matter  tic swayback | 03/07/06
It does matter if you're going to...  ye | 03/07/06
True, but...  tic swayback | 03/07/06
Given the limited amount of information...  ye | 03/07/06
Unfounded conclusions and worst case scenarios  tic swayback | 03/07/06
Here's my own for Windows: 71.56.240.67  ye | 03/07/06
Double standard...  ye | 03/07/06
I said it was an unfounded conclusion  tic swayback | 03/08/06
Yes you did...thus my "Double Standard"...  ye | 03/08/06
My comments were addressed...  tic swayback | 03/08/06
Then you have my apologies.  ye | 03/08/06
What this does prove is...  3D0G | 03/06/06
Which 5 to 10 machines do you refer to?  tic swayback | 03/06/06
what it proves..  Network Support | 03/06/06
Here's a real challenge  tic swayback | 03/06/06
Sounds like a plan  nucrash | 03/06/06
the test closes tonight... lol  linuxoverwindows | 03/07/06
Mac OS X hacked in under 30 minutes  Loverock Davidson | 03/06/06
Not quite  tic swayback | 03/06/06
I know  Loverock Davidson | 03/06/06
1 out of 10  Expatriate US Geek | 03/06/06
Take that George Ou  nucrash | 03/06/06
Hehe!  NonZealot | 03/06/06
The article was the pro-MS spin...  nomorems | 03/06/06
a lil too much MS paranoia, calm down  Dragonn | 03/10/06
He-he  george_ou | 03/06/06
Hope you'll find out what really happened here  tic swayback | 03/06/06
Should we compare this to Windows?  nucrash | 03/06/06
What would the purpose be?  NonZealot | 03/06/06
You're right...  tic swayback | 03/06/06
Oh I HATE those Linux dudes!!  NonZealot | 03/06/06
You're kidding, NonZealot!! Who'd a thunk?  Hugh Jass | 03/06/06
Shiver me timbers!  nomorems | 03/06/06
Re: Shiver me timbers!  joopbraak | 03/12/06
We,,  cashaww | 03/06/06
Hac Mac  bernoulli | 03/06/06
Wise in not commenting  Richard Flude | 03/06/06
Such good reporting they dropped it off the front page of ZDNet  Anon_ymous | 03/06/06
exploit unknown  mrlinux | 03/06/06
Secure BSD  baggins_z | 03/07/06
The hacker cheated  NonZealot | 03/06/06
I think we just need to crack down..  nucrash | 03/06/06
"To just hack is OK?"  3D0G | 03/06/06
theres a difference...  linuxoverwindows | 03/07/06
NZ, stop gloating  tic swayback | 03/06/06
I'm not gloating  NonZealot | 03/06/06
Don't put words in my mouth  tic swayback | 03/06/06
I'm not  NonZealot | 03/06/06
Thanks for your input  tic swayback | 03/06/06
How dare he use the Apache analogy!  thelemite | 03/07/06
Yeah, real hackers would never do that..  No_Ax_to_Grind | 03/06/06
Strawman  tic swayback | 03/06/06
Hmm, at least one user thought OSX was 100% safe  NonZealot | 03/06/06
Still a made-up argument  tic swayback | 03/06/06
this is a poor argument to justify your behaviour  stevey_d | 03/06/06
Anyone notice a pattern?  nomorems | 03/06/06
not fair?  doctormoriarty | 03/07/06
That's still twice as long as XP  Chad_z | 03/06/06
Get a clue  toadlife | 03/06/06
To be fair  tic swayback | 03/06/06
Good question  toadlife | 03/06/06
Question  tic swayback | 03/06/06
Google them  voska | 03/06/06
Office?  ianbetteridge | 03/07/06
I think you already gave us one  NonZealot | 03/06/06
Shatter Attacks are easy to prevent  toadlife | 03/06/06
I don't know  toadlife | 03/06/06
Leave it alone  Richard Flude | 03/06/06
Thanks Mr. Rude.  toadlife | 03/06/06
Clarification  Richard Flude | 03/06/06
Not blaming UNIX  toadlife | 03/06/06
Non-shatter attacks  tic swayback | 03/06/06
Google privilege escalation windows  Richard Flude | 03/06/06
Playing the Google game  toadlife | 03/06/06
Line wrap issues on links  tic swayback | 03/06/06
Tic  toadlife | 03/06/06
Thanks  tic swayback | 03/07/06
Smokers of the Mac-pipe, time for your intervention!  Mr. Roboto | 03/06/06
Pack another bowl  tic swayback | 03/06/06
Hey don't hog that pipe!  Len Rooney | 03/06/06
Pass it over here...  Hugh Jass | 03/06/06
puff puff give  linuxoverwindows | 03/07/06
You are correct of course......  Laff | 03/06/06
oh, i thought for a second...  linuxoverwindows | 03/07/06
Who cares?  nomorems | 03/06/06
Thank GAWD  No_Ax_to_Grind | 03/06/06
Sorry, but no.  nomorems | 03/06/06
Good, cause you're  Real World | 03/07/06
This article is a lie zdnet, you should edit it[you are doing in microsoft]  stevey_d | 03/06/06
You need a life.  Narg | 03/06/06
i have a life  stevey_d | 03/06/06
Grown up, M$muchomoney, grown up? You must love kidding yourself  sergiovf@... | 03/06/06
Funny  Narg | 03/06/06
Whats funny  nomorems | 03/06/06
why is it  Shelendrea | 03/06/06
Double secret reverse psychology  tic swayback | 03/06/06
I think it's the tirade of articles about Mac OSX security  stevey_d | 03/06/06
It's within the realm of possiblity  Len Rooney | 03/06/06
realm of possibility or not  Shelendrea | 03/07/06
Sorry,  nomorems | 03/07/06
Who's blaming?  Len Rooney | 03/07/06
Not just MS  tic swayback | 03/07/06
like MS had nothing to do with the SCO IBM court case  stevey_d | 03/07/06
Less than 30 minutes, huh?  Anthony Volpe | 03/06/06
ZDNet MS bias, as usual  boobasaurus | 03/06/06
not only misleading, but articles like this sadly prove  BillyB40 | 03/06/06
SSH Doesn't Get Used In The Real World?  nikoli | 03/06/06
Glad you're not running my web servers  tic swayback | 03/06/06
You Can't See A Real World Scenario  nikoli | 03/07/06
And you know this is what happened?  tic swayback | 03/07/06
the diff here  linuxoverwindows | 03/07/06
Windows OS Compromised In Less Than 30 Seconds  itanalyst | 03/06/06
Amazing  ianbetteridge | 03/07/06
30 seconds for XP  Gregory.J.Bradley@... | 03/07/06
I can do it in 3 seconds  xuniL_z | 03/07/06
i like the tongue face better  linuxoverwindows | 03/07/06
He speaks the truth  zmud | 03/07/06
When will you tell that he had local access priveleges?  Dan Brantley | 03/06/06
Really  nikoli | 03/06/06
Really?  tic swayback | 03/06/06
How Did I Know Tic Would Be The First To Reply?  nikoli | 03/06/06
Whippy skippy  tic swayback | 03/06/06
Of Course It's All About You And You Only Tic  nikoli | 03/06/06
Sure anything. If I get my admin password to you for instance,  Laff | 03/06/06
nikoli  Network Support | 03/06/06
Yes, the world does revolve around me  tic swayback | 03/07/06
give out the admin password?  linuxoverwindows | 03/07/06
You have a crystal ball? What's the other one made of?  Laff | 03/06/06
what if they  linuxoverwindows | 03/07/06
Much worst than that  Richard Flude | 03/06/06
You mean George lied?  Fred Fredrickson | 03/07/06
Why Is This About XP Now???  nikoli | 03/07/06
Silly boy....  thelemite | 03/07/06
Laugh All You Want, You Completely Missed The Point  nikoli | 03/07/06
You mean like the same attention Apache gets compared to IIs?  thelemite | 03/07/06
Typical OS X users are usually administrators?  nikoli | 03/07/06
Typical OSX users grant the public local access?  thelemite | 03/07/06
Local Accounts  ITTech001 | 03/06/06
Gwerdna = Andrew G.  Geotopia | 03/06/06
I've Read The Article And The Respones And I've Concluded...  nikoli | 03/06/06
30 seconds for XP  Gregory.J.Bradley@... | 03/07/06
This is desperation at it's worst...  xuniL_z | 03/07/06
Very Desperate  nikoli | 03/07/06
mac owners need windows for their own securty  glocks out | 03/06/06
Please tell the whole story  adamsp | 03/06/06
It's not about Microsoft, it's about Apple  Toiyabe | 03/06/06
It's not about Microsoft or Apple, it's about ZDNet  tic swayback | 03/06/06
The Point Has Been Made Whether You Like It Or Not  nikoli | 03/06/06
Duh  tic swayback | 03/06/06
You Are Hopeless!!!  nikoli | 03/07/06
Guess that answers my question  tic swayback | 03/07/06
Let's talk about FUD  Qbt | 03/06/06
Interesting given the correction now posted  Richard Flude | 03/06/06
Pure Windows Idealist  keydesignz | 04/08/06
Apple's "sloppy coding" ???  sergiovf@... | 03/06/06
Finally  keydesignz | 04/08/06
Sounds like FUD to me!  MacGeek2121 | 03/06/06
So much hype, so little substance  cr33 | 03/06/06
New challenge has been arranged  berck | 03/06/06
Still up and running...  TheCrow_z | 03/06/06
wasn't a fair test  2max67 | 03/06/06
Ok then...  zkiwi | 03/06/06
Hacked Interest?  Aylwin | 03/06/06
The only 100% secure computer now is the one that is off.  DanielBlessing | 03/06/06
Flawed story  jefmud | 03/06/06
Oh, just face it...  Qbt | 03/06/06
Stating the obvious.  johnsmith222 | 03/06/06
Hacking  WEBKILLER | 03/07/06
Run OS-uX as a VM on top of Windows  jpr75_z | 03/07/06
Wow, I never thought I'd lose this much respect for ZDNet  merlin747 | 03/07/06
Yeah, kind of lowers ZDnet to giant blog...  el1jones | 03/07/06
So who is "Andrew G.?" (gwerdna)  bwebster | 03/07/06
XP  Gregory.J.Bradley@... | 03/07/06
Complete rubbish, the real test is here  Fred Fredrickson | 03/07/06
Care To Take Back That Last Comment Ian?  itanalyst | 03/07/06
The Wisconsin site is still  Jim Blaine - Bellingham WA. | 03/07/06
Conclusion is useless without more info  NonZealot | 03/07/06
Well hopefully  Jim Blaine - Bellingham WA. | 03/07/06
And here is the answer...  Jim Blaine - Bellingham WA. | 03/07/06
How long ago was it...  doctormoriarty | 03/07/06
Firewalls  tic swayback | 03/07/06
History repeating itself  doctormoriarty | 03/07/06
Not the same  NonZealot | 03/07/06
Overconfidence can be an exploitable weakness  doctormoriarty | 03/07/06
What's to prevent?  tic swayback | 03/07/06
Doesn't exist?  doctormoriarty | 03/07/06
2 viruses?  tic swayback | 03/07/06
Publish the method  mergatroid | 03/07/06
What's next...  yyuko@... | 03/07/06
What you ALL are MISSING...  ziembd@... | 03/07/06
I agrue none of it...  nomorems | 03/07/06
Not a serious contest!  An_Axe_to_Grind | 03/07/06
So what you are saying is another Real contest should be done  Boot_Agnostic | 03/07/06
Contests are not terribly useful  tic swayback | 03/07/06
But they are attention getters  Boot_Agnostic | 03/07/06
Compare numbers  DeadFred | 03/07/06
coverage was so journalistically poor  wh0arey0u | 03/07/06
Dear ZD net  s_gamgee | 03/07/06
Who do you trust? [nt]  BlazeEagle | 03/07/06
Leave ZDNet alone[more inside]  BlazeEagle | 03/07/06
Why is it that  RhinoRover | 03/08/06
I dislike Mac  Heretic_Seraphim | 04/07/06
You have never even used it  keydesignz | 04/08/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc