Search: Options

Winner mocks OS X hacking contest

By Munir Kotadia
Special to CNET News.com
Published: March 6, 2006, 6:38 PM PST

A clarification was made to this story. Read below for details.

update Gaining root access to a Mac is "easy pickings," according to an individual who won an OS X hacking challenge last month by gaining root control of a machine using an unpublished security vulnerability.

On Feb. 22, the Sweden-based Mac enthusiast set up his Mac Mini as a server and invited hackers to break through the computer's security and gain root control, which would allow the attacker to take charge of the computer and delete files and folders or install applications.

Participants were given local client access to the target computer and invited to try their luck.

Within hours of going live, the "rm-my-mac" competition was over. The challenger posted this message on his Web site: "This sucks. Six hours later, this poor little Mac was owned, and this page got defaced."

The hacker who won the challenge, who asked ZDNet Australia to identify him only as "Gwerdna," said he gained root control of the Mac in less than 30 minutes.

"It probably took about 20 or 30 minutes to get root on the box. Initially, I tried looking around the box for certain misconfigurations and other obvious things, but then I decided to use some unpublished exploits--of which there are a lot for Mac OS X," Gwerdna told ZDNet Australia.

According to Gwerdna, the hacked Mac could have been better protected, but it would not have stopped him because he exploited a vulnerability that has not yet been made public or patched by Apple Computer.

"The rm-my-mac challenge was set up similar to how you would have a Mac acting as a server--with various remote services running and local access to users...There are various Mac OS X-hardening guides out there that could have been used to harden the machine, however, it wouldn't have stopped the vulnerability I used to gain access. There are only limited things you can do with unknown and unpublished vulnerabilities. One is to use additional hardening patches--good examples for Linux are the PaX patch and the Grsecurity patches. They provide numerous hardening options on the system and implement nonexecutable memory, which prevent memory-based corruption exploits," Gwerdna said.

Gwerdna concluded that OS X contains "easy pickings" when it comes to vulnerabilities that could allow hackers to break into Apple's operating system.

"Mac OS X is easy pickings for bug finders. That said, it doesn't have the market share to really interest most serious bug finders," Gwerdna added.

Apple's OS X has come under fire in recent weeks with the appearance of two viruses and a number of serious security flaws, which have since been patched by the Mac maker.

In January, security researcher Neil Archibald, who has already been credited with finding numerous vulnerabilities in OS X, told ZDNet Australia that he knows of numerous security vulnerabilities in Apple's operating system that could be exploited by attackers.

"The only thing which has kept Mac OS X relatively safe up until now is the fact that the market share is significantly lower than that of Microsoft Windows or the more common Unix platforms...If this situation was to change, in my opinion, things could be a lot worse on Mac OS X than they currently are on other operating systems," Archibald said at the time.

An Apple Australia representative said on Monday that the company was unable to comment at this stage. Representatives at Apple's Cupertino, Calif., headquarters could not be reached for comment.

Munir Kotadia of ZDNet Australia reported from Sydney.

 

Clarification: The story has been updated to clarify that participants were given local client access to the target computer.

TrackBack

See links from elsewhere to this story.
 302 comments
Post a comment

TalkBack

Privilege Escalation

Pablo Vogel 
Mar 11, 2006, 7:17 PM PST

Defense Mechanisms. Why your posts are being deleted.

Chrisnwokc 
Mar 9, 2006, 9:45 AM PST

20 more to go :)

Shoppingkart 
Mar 9, 2006, 6:54 AM PST

Ty. when's the last time

City_Of_LA 
Mar 9, 2006, 6:06 AM PST

Whatever Cnet's value!

Shoppingkart 
Mar 9, 2006, 6:03 AM PST

LOL! Hide the beer! The folks are home!

MacDuff 
Mar 8, 2006, 3:46 PM PST

see this, it's funny

Goose 
Mar 8, 2006, 9:27 AM PST

Denial may not be a river, but it's pretty deep...

LarryFugate 
Mar 8, 2006, 7:35 AM PST

c|net makes me ashamed of being a journalist

Xiaxua 
Mar 8, 2006, 6:26 AM PST

Inconsequential as a Tennis Match

tundraboy 
Mar 7, 2006, 6:01 PM PST

Example of better reporting

Thrudheim 
Mar 7, 2006, 6:01 PM PST

Interesting

Tom Canham 
Mar 7, 2006, 5:10 PM PST

Get a life

sandman979 
Mar 7, 2006, 4:07 PM PST

Read the story, people.

Seaspray0 
Mar 7, 2006, 12:30 PM PST

The best piece of info is at the bottom of the story.

aemarques 
Mar 7, 2006, 11:05 AM PST

Poor Journalism

Awesomebase 
Mar 7, 2006, 11:05 AM PST

Gwerdna=

DeusExMachina 
Mar 7, 2006, 10:40 AM PST

To Err is Human

itispals 
Mar 7, 2006, 10:27 AM PST

First find the story, then alter the facts

Swift2 
Mar 7, 2006, 9:16 AM PST

Accusations of Fanboyism

djemerson 
Mar 7, 2006, 8:11 AM PST

Earl Benser. Could you please comment on this

City_Of_LA 
Mar 7, 2006, 6:47 AM PST

Better know what you are talking about

dduck123 
Mar 7, 2006, 6:04 AM PST

advertisement
advertisement

Deal of the day

Creative Zen Micro Photo for $164
Here's a nice rebate deal, good through the weekend, on this highly rated 8GB MP3 player, which, for its size, has a decent photo viewer. Read more...


Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 11:58 AM PDT
View as:
10 'most beautiful' cell phones SanDisk unveils 8GB music player Photos: ZAP cars scream green  Automaker aims to bring clean cars to the masses Photo: SanDisk's 8GB music player  Scientists try to create new universe How to succeed in the gadget biz Photo: Samsung's 70-inch LCD  Old records go in, CDs come out Net's new porn trend: Nearly nude kids Samsung strives for LCD record 'Tetris'-style magnets recall game fun of yore Google welcomes Writely sign-ups AOL fires three over release of user search data Contest for Mac users' wildest (software) fantasies
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Top picks from News.com readers

Readers who read Winner mocks OS X hacking contest also read...

More Info

Privacy policy | Terms of use | About CNET Networks | Jobs | How to advertise | Partnership opportunities
Copyright ©1995-2006 CNET Networks, Inc. All rights reserved.