Miller does it again: MacBook pwn’d in seconds
Ah the rights and rituals of spring are upon us—animals giving birth in the mud and hackers frolicking playfully in rented spaces in Vancouver. Breath deeply the very stuff of life.
ZDNet reports that Charlie Miller has once again won the CanSecWest Pwn2own contest by being the first person to hack a fully patched MacBook, taking home the Apple portable and $10,000 for his trouble.
“It took a couple of seconds,” said Miller. “They clicked on the link and I took control of the machine,” referring to the Safari based exploit he used to bring home the bacon.
As per the rules and past practice, TippingPoint’s Zero Day Initiative has acquired the exclusive rights to the vulnerability and will coordinate disclosure and the patch release process with Apple. Technically speaking, that means the firm should wait until the mothership releases a patch, though Miller et al bludgeoned the company (and its millions of users) with the threat and then release of the actual exploit into the wild when they felt the Mac maker’s response was too slow.
Own or rent Macheads the Movie right now!
Filed under: Mac



[...] And, the show stopper that’s been addressed? A fix for one of the flaws exploited during this year’s CanSecWest Pwn2Own hacker contest. [...]