Feeds

A Mac gets whacked, a second survives

CanSecWest PWN to Own contest beaten

Security for virtualized datacentres

The Safari flaw is approximately the same severity as the recent animated-cursor vulnerability recently fixed by Microsoft and used widely in attacks by groups that appear to operate out of China and Eastern Europe. The flaw was rated critical by Microsoft.

Browser flaws are fairly easy to find, said HD Moore, founder and developer for the Metasploit Project. Moore used data-fuzzing techniques to find a large number of flaws in internet browsers a year ago, releasing them as the Month of Browser Bugs in July 2006.

"It makes it a lot easier to find a flaw," Moore said. "There are so many (similar) bugs in Safari."

Yet, Moore and others gave mixed responses comparing the security of the latest Mac and Windows operating systems. Macaulay favoured Windows Vista for security, but Dai Zovi said the Mac seemed to be the more secure platform, but acknowledged that the reason could be because the operating system has far less marketshare.

"While the Mac does not have problems with widespread malware like Windows, if they had that kind of marketshare they would have similar issues," he said. "But, by the time they do get the marketshare, they should be on a trajectory to have much better security than Windows."

There is still a way to go: Amidst the bustle of cleanup, two security engineers from networking firm Juniper frantically raced to beat the clock and churn out code to reliably exploit a second bug, this time a truly remotely exploitable flaw in the Mac OS X.

The two engineers described the bug as a "really weird" heap overflow in a default service on the Mac. TippingPoint confirmed that the company would pay a second $10,000 bounty for any zero-day flaw that compromised the other system. The two engineers had already decided to give the money to a charity fund at Viriginia Tech, where 32 students and faculty had died last week in the United States' worst school shooting.

Yet, the two engineers, who asked not to be identified, couldn't get the exploit to work. Around 6pm, the conference staff pulled the plug.

After the conference, CanSecWest organiser Dragos Ruiu acknowledged that he may have miscalculated the interest that free MacBooks would generate. Money should have likely been a prize right from the start.

"It is interesting to me that it took a cash prize to bring the flaw out of the woodwork," he said.

For his part, Dai Zovi said the money was not necessarily the object.

"I have a day job in finance, so I'm not hurting," he said. "I think there has been a lot of controversy over Mac vulnerabilities in the last year, and I was hoping to prove something concrete."

This article originally appeared in Security Focus.

Copyright © 2007, SecurityFocus

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.