Safari falls in 10 seconds at hacking contest
By Stuart Turton
Posted on 19 Mar 2009 at 10:47
A security researcher has won $5,000 by hacking a Mac in under 10 seconds, exploiting a hole in Safari.
Charlie Miller, a security analyst wtih Independent Security Evaluators, was competing in the annual CanSecWest's PWN2OWN contest - which offers cash prizes for the quickest hacks.
The competition allows contestants to provide a URL hosting their exploit. Though Miller was forbidden from revealing the details of his hack for fear it would be replicated, he did reveal that the URL exploited a hole in a fully patched version of Safari allowing him to take control of a full patched MacBook.
The second machine to fall was a Sony laptop running Windows 7, which was exploited through a vulnerability in the recently released Internet Explorer 8.
The contest is organised by TippingPoint, which is offering $5,000 for each new vulnerability found in a browser and $10,000 for each successful exploit in the major smartphones. Details of the exploits are shared with the affected companies.
Miller also won the competition last year after breaking into a MacBook Air in under two minutes, a feat which bagged him $10,000.
From around the web
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Is Microsoft mismanaging Windows on ARM?
- Dealing with spam surrogates
- Why 3G broadband can be better and cheaper than ADSL
- Is Twitter bad for business?
- Publishing your email address isn't a security disaster
- Why you'll need a fax machine to develop iOS apps
- Learning to adapt to the mobile web
- Why you shouldn't use WPS on your Wi-Fi network
- Disabled users suffer when software breaks the rules
advertisement
