Top stories

Journalists Cover Microsoft, Using Macs

It’s not an easy time for Microsoft — with Steve Ballmer having to field questions about being “buffoons” and an “evil empire”  at the shareholder’s meeting (.doc) — so when they get together “the world’s most influential technology pundits and online writers” (nb: we weren’t invited) for Mobius to discuss super-secret mobile tech you’d think [...]

Guide To Black Friday Apple Bargains: Cheap MacBooks, iPods and Accessories Galore

Here’s a guide for finding the best bargains on Apple-related gear during the infamous Black Friday sales on November 27. We’ve compiled a comprehensive list of gear from leaked photos of sales flyers and descriptions of sales.
The bargains include a 2.26 GHz MacBook + $150 gift card at Best Buy for $999.99 ; a 32GB [...]

Review: Voices Is Today’s Best Thing Ever, Grab It Now While It’s Cheap

New on the App Store is Voices from the clever folk at Tap Tap Tap. You can guess what it does.

Open it up, pick a silly voice. Helium is pretty silly. A microphone appears and the app even clears your throat for you (try it, you’ll see what I mean). Now speak your brains, and [...]

Review: Sony Walkman S540 Series Video MP3 Player

Press releases, you will hardly be surprised to hear, are rarely very interesting. But one arrived in my inbox a couple of weeks ago that made me double-take.
“Sony’s S Series Walkman,” it chattered, “is a serious challenger to the iPod Nano.” Gosh, really? Perhaps the Cult had better have a look at one, then, despite [...]

Security Expert Hacks a Mac in Seconds

cmiller.png

Charlie Miller, principal security analyst at Independent Security Evaluators, used a security exploit in Safari 4 to hack into a MacBook in about 10 seconds Wednesday, winning the Pwn2own contest at the CanSecWest security conference for the second year in a row.

The security hole, which Miller said he discovered last year, allows a remote attacker to gain control of a machine by getting the computer user to click on a malicious URL, as Miller demonstrated.

“It’s not easy, but this worked with one click” from the Safari browser, he said.

The contest is sponsored by TippingPoint, which shares details on the exploit with Apple and develops a patch for it. TippingPoint offers $5,000 for each new exploit demonstrated in the major browsers and $10,000 for each successful exploit in the major smartphones.

Miller also discovered an exploit in the mobile version of Safari shortly after the iPhone was launched in 2007. In addition to the $5000 prize for his efforts Wednesday, he gets to keep the MacBook he used to win the contest.

[CNet]

About the author

Lonnie Lazar

Lonnie Lazar is a writer, musician, web designer attorney. He writes about Apple for Cult of Mac and Mac|Life, and about VoIP and telecommunications for Voxilla. Follow Lonnie on Twitter @LonnieLazar, join the Cult of Mac on Facebook, and find Lonnie's photos on Flickr.

Email the author | Read more posts by Lonnie Lazar.

4 comments

    Wasn’t he a Mac security expert?
    Didn’t he prepared before the contest, how others browsers performed in that show?

    Is there a browser that is immune to attacks?

    Ohh! …

    It’s interesting that this can be considered valid in a Beta browser. But useful as now the exploit will be fixed.

    Is it a hack if it needs user input?

    “In seconds!” the breathless bloggers all write… then right there in the article it says that he discovered it last year; reading more about the contest reveals that he worked on the exploit weeks ahead of time and put it through weeks of testing. So no, he didn’t hack a Mac in SECONDS, he took weeks to hack it after a year of studying the security hole.

    And yeah, the exploit relied on someone clicking a suspicious link in an email. Duh.

Buy Inside Steve's Brain Buy from Amazon.com Buy from Barnes & Noble