Pwn2Own 2011 Hacking Competition Claims First Victim--Apple OS X

French Security Specialist Chaouki Bekhar Takes Just Five Seconds To Hack OS X

Out at this year’s Pwn2Own competition–an annual gathering of computer security specialists from all around the globe–the various operating systems of the world go up against the great minds in computer science to see just how long they can hold out against their concerted efforts. And the first victim of the great hacking train was none other than Apple’s own OS X. But the most eye-catching part is just how long it took to hack that system.

French security specialist Chaouki Bekhar took about as long to hack Apple’s vaunted OS X as some do clipping a fingernail: five seconds.

All Bekhar had to do, according to reports, was use a flaw in Apple’s Safari browser and the next thing you know, he had hijacked that book. The word is that he easily foiled the memory protections in OS X Snow Leopard, and followed that up by taking advantage of some poorly-written code in Apple’s Webkit branch, which in turn powers Safari.

Interestingly, it also shares a substantial bit of code with Chrome–which Google offered a $20,000 bounty to see hacked at the conclave–but since Google beefed up the security on Chrome, the same exploit likely wouldn’t be usable to get in through Chrome.

Of course, at this point, some of you are likely wondering, if it takes less time to hack OS X than it takes the average person to make a sandwich, why on earth isn’t Apple getting hacked like nobody’s business? It’s actually, reportedly, a combination of points, including unwillingness to attack OS X machines for more sentimental reasons (they’re perceived, in the hacker community, as being closely related), and the sheer overall lack of Apple hardware, among others, though the recent influx of Macbook Airs may serve to put those numbers up a bit.

Still though, after that bit of news, it’ll be interesting to see where the rest of Pwn2Own goes from there.

Related Stories on TFTS:
  • Facebook Launching New Features Including Verified Accounts & Pseudonym Support

    Facebook Continues to Pimp Its Social Network, Takes Cues from the Competition

  • iPhone Jailbreak-based XRY Software Can Crack the Device’s Security Code

    Security Firm Shows Off Application That Can Crack iOS Security Codes for Law Enforcement & Military Use

  • Newest Kinect Hack Controls Massive Organ

    A New Kinect Hack Hooks Up The Kinect To An Enormous Organ In Australia, Raises The Musical Kinect Hack Stakes

  • UK Regulators Now Investigating Apple's 4G iPad Claims

    Following An Investigation Of Apple's 4G Claims In Australia, The Movement Expands To The UK, Where Investigators Are Also Checking Up

  • Michael Jackson Said To Be Newest Victim Of Sony Hack

    Last Year's Sony Hack Did A Lot Of Damage, But A New & Surprising Victim Of The Hack Has Been Found In Michael Jackson



  • Comments are closed.

    We think you may also like: