Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

WINDOWS

Vista Ultimate SP1 and Ubuntu Shame the Ultra-Hackable Mac OS X 10.5 Leopard

- Apple's OS hacked in just 2 minutes

By: Marius Oiaga, Technology News Editor

Windows Vista Ultimate Service Pack 1 and Ubuntu 7.10 have bested the Apple proprietary platform in terms of security, by shaming the ultra-hackable Mac OS X 10.5 Leopard. There is a constant face-off on the operating system market, not only when it comes down to the install base and audience, but also security-wise. While the general perspective is that Windows operating systems deliver no contest to the security offered by Linux and Mac OS X platforms, the reality might be a tad different than the
claims provided by bulletproof marketing campaigns or fanatic culture. Case in point: the CanSecWest PWN2OWN 2008 hacking contest claimed its first victim, the fully patched Mac OS X 10.5.2 running on the "thinnovative" MacBook Air.

Apple's official description of MacBook Air reads "ultrathin, ultraportable, and ultra unlike anything else." Obviously, the Cupertino-based security company also meant ultra-hackable. And the description of Mac OS X 10.5 Leopard is nothing more than an example of arrogance defying a sad reality, Apple is placing its own customers at risk by advertising Leopard as a panacea for security issues. "Security. Safer by design. Every Mac is secure — right out of the box — thanks to the proven foundation of Mac OS X." It took a team of three security researchers under 2 minutes to hack a fully patched copy of Mac OS X 10.5.2 Leopard running on a MacBook Air machine.

"At 12:38pm local time, the team of Charlie Miller, Jake Honoroff, and Mark Daniel from Independent Security Evaluators have successfully compromised the Apple MacBook Air, winning the laptop and $10,000 from TippingPoint's Zero Day Initiative. They were able to exploit a brand new 0day vulnerability in Apple's Safari web browser. Coincidentally, Apple has just started to ship Safari to some Windows machines, with its iTunes update service. The vulnerability has been acquired by the Zero Day Initiative, and has been responsibly disclosed to Apple who is now working on the issue. Until Apple releases a patch for this issue, neither we nor the contestants will be giving out any additional information about the vulnerability. You can track the vulnerability on the Zero Day Initiative upcoming advisories page under ZDI-CAN-303," reads the official announcement from Tipping Point.

In the CanSecWest PWN2OWN 2008 contest, hackers had a go at three machines: VAIO VGN-TZ37CN running Ubuntu 7.10; Fujitsu U810 running Vista Ultimate SP1 and MacBook Air running OSX 10.5.2. In the first day of the challenge sponsored by TippingPoint's Zero Day Initiative, no computer could be breached, as the organizers only allowed attacks over a network. The second day of the hacking contest allowed attackers to direct CanSecWest organizers to visit webpages or open messages in Leopard's email client. Charlie Miller, the security expert who hacked the iPhone in 2007, owned the MacBook Air box via a zero-day vulnerability that was disclosed only to Apple. It took Miller just 2 minutes to hack OS X Leopard.

"So Dragos [Dragos Rui, the conference's organizer] just announced before lunch that within 10 minutes of opening Day 2 of the pwn2own contest - the Mac has fallen. Wonder what took so long? Just talked with Dragos - the finder is signing with ZDI to get paid - so no vuln details for us. But we DO know that there was no 3rd party software on the box yet so the 0-day is in some inbox software," stated Robert Hensing, Microsoft Security Software Engineer.

MORE RELATED ARTICLES: Vista Ultimate SP1 vs. OS X Leopard 10.5.2 vs. Ubuntu 7.10 New Beta of Windows Server 2008 Supports Vista SP1 and XP SP3 Microsoft Prepares Its Vista SP1 Heavy Guns – Will Linux and Mac OS X Be Hurt? IE8 Beta 1 Does Not Install on Pre-RTM Vista SP1 Vista Sound – Digital vs. Analog Forget XP SP3, Vista SP1 and Windows 7 – Microsoft's Singularity OS Free Download Will Vista SP1 Trample XP SP3, OS X and Linux in Its Way to the Top? Will Vista SP1 Go Where Vista Never Went? Even with XP SP3 and Windows 7? Microsoft Admits “Stealing” from Open Source When Building Windows Server 2008
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


28th March 2008, 08:50 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 3,949 user(s) | Rating: | 5 vote(s) so far | Cast your vote:
Vista Ultimate SP1 and Ubuntu Shame the Ultra-Hackable Mac OS X 10.5 Leopard - USER OPINIONS

Comment #1 by wonderboy52 on 2008-03-28, 13:52 GMT reply to this comment 
who cares about security most people use mac because it aint got as many errors and its interface is better but number one reason because of speed compared to the slow vista which uses about a gig to run.I got a dual core two gig runs well fast with mac but with vista its like a 98 machine.

Comment #2 by ostar on 2008-03-29, 14:33 GMT reply to this comment 
"I got a dual core two gig runs well fast with mac but with vista its like a 98 machine."

That's because you're an idiot.

Comment #3 by clambake on 2008-04-04, 07:09 GMT reply to this comment 
first ... what a stupid title the os wasn't hacked... safari was
secondly the guy who did it was already aware of the security hole
and had prepared 2 weeks in advance for this

and this isnt even a hack but an exploit .


Comment #4 by Webster Phreaky on 2008-04-04, 13:52 GMT reply to this comment 
QUOTE: \\\" I got a dual core two gig runs well fast with mac but with vista ...\\\"

Isn\\\'t it fascinating that these MacTards love to bash Windows, always based on lies and inconsistent claims generated by Apple PR and their Media Hacks, YET they all want or are running Windows on their MacIntel PC wannabe Clones.

Well \\\"wonderboy52\\\", you proved three things:
1) Apple has fools like you pegged right, you bought an OVER PRICED Mac and then paid again for Windows Vista, so you\\\'ve paid THREE TIMES what all of us paid for a more reliable and feature rich HP, Sony or Dell. Who\\\'s the moron?

2) Vista must be better than OS heXed, otherwise why are you running it on your MacIntel PC Clone? At least Vista is more secure than OS X.

3) ostar is right .... wonderboy52 you proved it. But you\\\'re not alone, all your MacTard buddies are too.


go to top


SHARE YOUR OPINION ABOUT Vista Ultimate SP1 and Ubuntu Shame the Ultra-Hackable Mac OS X 10.5 Leopard

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive