![]() ![]() |
Mar 7 2006, 02:33 PM
Post
#1
|
|
![]() DEATH TO ....something? Group: Members Posts: 5,618 Joined: 23-February 06 From: Parker, CO Member No.: 55 |
http://apple.slashdot.org/apple/06/03/07/1324256.shtml
Apparently the MacOS box they've set up has been slashdotted to death, but they're basically claiming the ZDNet article that said MacOS X could be h4x0r0r0r0r00reDDDDddd in 30 minutes was false. -------------------- I r Ur Gawd!
|
|
|
|
Mar 8 2006, 12:36 PM
Post
#2
|
|
![]() From Atlantis to Interzone Group: Global Moderators Posts: 2,512 Joined: 23-February 06 From: Somewhere in space and time Member No.: 65 |
http://test.doit.wisc.edu/
There were no successful access attempts of any kind, including during the 38 hour duration of the test period, nor have their been any claims of success. The host is still the same host and configuration used for the test. Also: The ZDnet article, and almost all of the coverage of it, failed to mention a very critical point: anyone who wished it was given a local account on the machine (which could be accessed via ssh). Yes, there are local privilege escalation vulnerabilities; likely some that are "unpublished". But this machine was not hacked from the outside just by being on the Internet. It was hacked from within, by someone who was allowed to have a local account on the box. That is a huge distinction. -------------------- Holy shit, pebkac, you're awesome! "Be who you are and say what you feel, because those who mind don't matter and those who matter don't mind." - Theodor Seuss Geisel (AKA Dr. Seuss) "An idea that is not dangerous is unworthy of being called an idea at all." - Oscar Wilde |
|
|
|
Mar 8 2006, 03:39 PM
Post
#3
|
|
![]() Group: Admin Posts: 3,403 Joined: 23-February 06 From: PDX/TXL Member No.: 35 |
I like what Molly Wood wrote:
QUOTE OK, so first there was a Mac OS X hacking contest, and this guy was all, "w00t, I totally hax0rd it in 30 minutes, I am hecka l33t!" And then a University of Wisconsin systems engineer organized a new challenge that was actually a challenge--in the sense that he didn't give anyone a local account on the machine, just like you wouldn't if, you know, it were your Mac. And no one breached that bad boy in some 38 hours of trying. I feel the only appropriate response here is "snap."
-------------------- "There is a level of cowardice lower than that of the conformist: that of the fashionable non-conformist." |
|
|
|
Mar 8 2006, 03:42 PM
Post
#4
|
|
![]() Group: Members Posts: 10,620 Joined: 23-February 06 From: Houston, TX Member No.: 48 |
there's a difference between hacking a box that some dude sets up purposely to be more secure, and what an everyday user will have hosing their system up.
|
|
|
|
Mar 8 2006, 03:49 PM
Post
#5
|
|
|
I was raised on the dairy, BITCH! Group: Members Posts: 3,080 Joined: 23-February 06 From: Cedar Park Member No.: 49 |
QUOTE (impala454 @ Mar 8 2006, 03:42 PM) there's a difference between hacking a box that some dude sets up purposely to be more secure, and what an everyday user will have hosing their system up. if you turn any kind of remote access off on your mac you're practically invulnerable -------------------- "Ah, y'know it's funny, these people they go to sleep, they think everything's fine, everything's good. They wake up the next day and they're on fire."
|
|
|
|
Mar 8 2006, 04:30 PM
Post
#6
|
|
![]() Group: Admin Posts: 3,403 Joined: 23-February 06 From: PDX/TXL Member No.: 35 |
QUOTE (impala454 @ Mar 8 2006, 03:42 PM) there's a difference between hacking a box that some dude sets up purposely to be more secure, and what an everyday user will have hosing their system up. There's also a difference in giving someone a basic user account, having them up their permissions and someone brute-forcing their way in. -------------------- "There is a level of cowardice lower than that of the conformist: that of the fashionable non-conformist." |
|
|
|
Mar 8 2006, 04:47 PM
Post
#7
|
|
![]() Group: Members Posts: 5,275 Joined: 22-February 06 Member No.: 2 |
So if you get access to the Mac box you can own it, the problem in this case is getting an account. He'd have to try all the default accounts, run brute-force dictionaries on accounts, figure out if any trusted IPs are allowed and spoof them, hijack the session between a legal user and the Mac box, or find a buffer overflow in some service that's running to let him in remotely.
Either way I'm sure it can be done by someone with enough persistance and know-how. The question is, who cares enough to even try? |
|
|
|
Mar 8 2006, 05:48 PM
Post
#8
|
|
![]() Group: Members Posts: 10,620 Joined: 23-February 06 From: Houston, TX Member No.: 48 |
QUOTE (pysex @ Mar 8 2006, 03:49 PM) if you turn any kind of remote access off on your mac you're practically invulnerable yeah right |
|
|
|
Mar 8 2006, 05:49 PM
Post
#9
|
|
![]() Group: Members Posts: 10,620 Joined: 23-February 06 From: Houston, TX Member No.: 48 |
QUOTE (Lancifer @ Mar 8 2006, 04:47 PM) The question is, who cares enough to even try? bingo |
|
|
|
Mar 8 2006, 06:50 PM
Post
#10
|
|
![]() Retired Funk-bringer Group: Moderators Posts: 2,656 Joined: 22-February 06 From: Dallas Member No.: 14 |
if you read the zdnet arcticle, the hacker A ) used an unpublished exploit, and B ) the box they set up to h4x0r had no extra security hardening, it was more on a user-level than a server level
get your shit right. -------------------- WAIT. I'm not finished.
|
|
|
|
Mar 8 2006, 07:22 PM
Post
#11
|
|
![]() Group: Admin Posts: 3,403 Joined: 23-February 06 From: PDX/TXL Member No.: 35 |
QUOTE (zetec @ Mar 8 2006, 06:50 PM) if you read the zdnet arcticle, the hacker A ) used an unpublished exploit, and B ) the box they set up to h4x0r had no extra security hardening, it was more on a user-level than a server level get your shit right. And to top that off it was an exploit in the user permissioning code. What bothers me is that Apple has made no comment on fixing the exploit even though they apparently know what the problem is. -------------------- "There is a level of cowardice lower than that of the conformist: that of the fashionable non-conformist." |
|
|
|
Mar 8 2006, 07:33 PM
Post
#12
|
|
|
Group: Members Posts: 290 Joined: 23-February 06 Member No.: 59 |
QUOTE Yesterday we discovered the Mac OSX "challenge" was not an activity authorized by the UW-Madison. Once the test came to the attention of our CIO, she ended it. The site, test.doit.wisc.edu, will be removed from the network tonight. Our primary concern is for security and network access for UW services. We are sorry for any inconvenience this has caused to the community. Hahahaha, that's funny. So this contest wasn't official? Anyway, most people probably didn't even know about the test so the results were probably mediocre anyway. |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 20th August 2026 - 01:05 PM |