IPB

Welcome Guest ( Log In | Register )


 
Reply to this topicStart new topic
> University of Wisconsin MacOS X Hack Challenge
Dogmeat
post Mar 7 2006, 02:33 PM
Post #1


DEATH TO ....something?


Group: Members
Posts: 5,618
Joined: 23-February 06
From: Parker, CO
Member No.: 55



http://apple.slashdot.org/apple/06/03/07/1324256.shtml

Apparently the MacOS box they've set up has been slashdotted to death, but they're basically claiming the ZDNet article that said MacOS X could be h4x0r0r0r0r00reDDDDddd in 30 minutes was false.


--------------------
I r Ur Gawd!
Go to the top of the page
 
+Quote Post
pebkac
post Mar 8 2006, 12:36 PM
Post #2


From Atlantis to Interzone


Group: Global Moderators
Posts: 2,512
Joined: 23-February 06
From: Somewhere in space and time
Member No.: 65



http://test.doit.wisc.edu/

There were no successful access attempts of any kind, including during the 38 hour duration of the test period, nor have their been any claims of success. The host is still the same host and configuration used for the test.

Also:

The ZDnet article, and almost all of the coverage of it, failed to mention a very critical point: anyone who wished it was given a local account on the machine (which could be accessed via ssh). Yes, there are local privilege escalation vulnerabilities; likely some that are "unpublished". But this machine was not hacked from the outside just by being on the Internet. It was hacked from within, by someone who was allowed to have a local account on the box. That is a huge distinction.


--------------------
QUOTE (Spectatrix @ Oct 13 2006, 09:51 PM) *
Holy shit, pebkac, you're awesome!



"Be who you are and say what you feel, because those who mind don't matter and those who matter don't mind." - Theodor Seuss Geisel (AKA Dr. Seuss)

"An idea that is not dangerous is unworthy of being called an idea at all." - Oscar Wilde
Go to the top of the page
 
+Quote Post
Hartmann
post Mar 8 2006, 03:39 PM
Post #3





Group: Admin
Posts: 3,403
Joined: 23-February 06
From: PDX/TXL
Member No.: 35



I like what Molly Wood wrote:

QUOTE
OK, so first there was a Mac OS X hacking contest, and this guy was all, "w00t, I totally hax0rd it in 30 minutes, I am hecka l33t!" And then a University of Wisconsin systems engineer organized a new challenge that was actually a challenge--in the sense that he didn't give anyone a local account on the machine, just like you wouldn't if, you know, it were your Mac. And no one breached that bad boy in some 38 hours of trying. I feel the only appropriate response here is "snap."


--------------------

"There is a level of cowardice lower than that of the conformist: that of the fashionable non-conformist."
Go to the top of the page
 
+Quote Post
impala454
post Mar 8 2006, 03:42 PM
Post #4





Group: Members
Posts: 10,620
Joined: 23-February 06
From: Houston, TX
Member No.: 48



there's a difference between hacking a box that some dude sets up purposely to be more secure, and what an everyday user will have hosing their system up.
Go to the top of the page
 
+Quote Post
pysex
post Mar 8 2006, 03:49 PM
Post #5


I was raised on the dairy, BITCH!


Group: Members
Posts: 3,080
Joined: 23-February 06
From: Cedar Park
Member No.: 49



QUOTE (impala454 @ Mar 8 2006, 03:42 PM)
there's a difference between hacking a box that some dude sets up purposely to be more secure, and what an everyday user will have hosing their system up.

if you turn any kind of remote access off on your mac you're practically invulnerable


--------------------
"Ah, y'know it's funny, these people they go to sleep, they think everything's fine, everything's good. They wake up the next day and they're on fire."
Go to the top of the page
 
+Quote Post
Hartmann
post Mar 8 2006, 04:30 PM
Post #6





Group: Admin
Posts: 3,403
Joined: 23-February 06
From: PDX/TXL
Member No.: 35



QUOTE (impala454 @ Mar 8 2006, 03:42 PM)
there's a difference between hacking a box that some dude sets up purposely to be more secure, and what an everyday user will have hosing their system up.

There's also a difference in giving someone a basic user account, having them up their permissions and someone brute-forcing their way in.


--------------------

"There is a level of cowardice lower than that of the conformist: that of the fashionable non-conformist."
Go to the top of the page
 
+Quote Post
Seeker
post Mar 8 2006, 04:47 PM
Post #7





Group: Members
Posts: 5,275
Joined: 22-February 06
Member No.: 2



So if you get access to the Mac box you can own it, the problem in this case is getting an account. He'd have to try all the default accounts, run brute-force dictionaries on accounts, figure out if any trusted IPs are allowed and spoof them, hijack the session between a legal user and the Mac box, or find a buffer overflow in some service that's running to let him in remotely.

Either way I'm sure it can be done by someone with enough persistance and know-how. The question is, who cares enough to even try?
Go to the top of the page
 
+Quote Post
impala454
post Mar 8 2006, 05:48 PM
Post #8





Group: Members
Posts: 10,620
Joined: 23-February 06
From: Houston, TX
Member No.: 48



QUOTE (pysex @ Mar 8 2006, 03:49 PM)
if you turn any kind of remote access off on your mac you're practically invulnerable

yeah right
Go to the top of the page
 
+Quote Post
impala454
post Mar 8 2006, 05:49 PM
Post #9





Group: Members
Posts: 10,620
Joined: 23-February 06
From: Houston, TX
Member No.: 48



QUOTE (Lancifer @ Mar 8 2006, 04:47 PM)
The question is, who cares enough to even try?

bingo
Go to the top of the page
 
+Quote Post
zetec
post Mar 8 2006, 06:50 PM
Post #10


Retired Funk-bringer


Group: Moderators
Posts: 2,656
Joined: 22-February 06
From: Dallas
Member No.: 14



if you read the zdnet arcticle, the hacker A ) used an unpublished exploit, and B ) the box they set up to h4x0r had no extra security hardening, it was more on a user-level than a server level


get your shit right.


--------------------
WAIT. I'm not finished.
Go to the top of the page
 
+Quote Post
Hartmann
post Mar 8 2006, 07:22 PM
Post #11





Group: Admin
Posts: 3,403
Joined: 23-February 06
From: PDX/TXL
Member No.: 35



QUOTE (zetec @ Mar 8 2006, 06:50 PM)
if you read the zdnet arcticle, the hacker A ) used an unpublished exploit, and B ) the box they set up to h4x0r had no extra security hardening, it was more on a user-level than a server level


get your shit right.

And to top that off it was an exploit in the user permissioning code. What bothers me is that Apple has made no comment on fixing the exploit even though they apparently know what the problem is.


--------------------

"There is a level of cowardice lower than that of the conformist: that of the fashionable non-conformist."
Go to the top of the page
 
+Quote Post
prefix
post Mar 8 2006, 07:33 PM
Post #12





Group: Members
Posts: 290
Joined: 23-February 06
Member No.: 59



QUOTE
Yesterday we discovered the Mac OSX "challenge" was not an activity authorized by the UW-Madison. Once the test came to the attention of our CIO, she ended it. The site, test.doit.wisc.edu, will be removed from the network tonight. Our primary concern is for security and network access for UW services. We are sorry for any inconvenience this has caused to the community.


Hahahaha, that's funny. So this contest wasn't official? Anyway, most people probably didn't even know about the test so the results were probably mediocre anyway.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 20th August 2026 - 12:58 PM
Skin made by: skeedio.com