Mac-mini hacked in under 30 minutes:
http://www.zdnet.com.au/news/security/s ... 748,00.htm
So much for Apple security
Moderators: snarkout, Patrick, dann
So much for Apple security
Ego contemno licentia
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
0-day or weak password? You decide!
I'm not at all convinced - I'd never clam the mac is the king of security, but that article at least provided no info at all about what was running on the box or how the hacker gained root. My guess is that the box either had weak passwords and ssh/telnet turned on, or was running unpatched php or something. If macs were that easy to pwn (via unpublished vulnerabilities that you can't stop because they're unpublished, which means that you can't stop them, but I know cuz I'm 1337...LOLOLOLOL..snort...), they'd be owned all the time - spammers do not give a fsck whether they're bombing the world with spam from a mac or spam from a windows machine. Large vector or not, easy pickings would be getting picked off regularly.
I'm not at all convinced - I'd never clam the mac is the king of security, but that article at least provided no info at all about what was running on the box or how the hacker gained root. My guess is that the box either had weak passwords and ssh/telnet turned on, or was running unpatched php or something. If macs were that easy to pwn (via unpublished vulnerabilities that you can't stop because they're unpublished, which means that you can't stop them, but I know cuz I'm 1337...LOLOLOLOL..snort...), they'd be owned all the time - spammers do not give a fsck whether they're bombing the world with spam from a mac or spam from a windows machine. Large vector or not, easy pickings would be getting picked off regularly.
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson
--Spider Robinson
As I figured, this wasn't what it appeared to be. The guy was giving shells away on the box, so at best, what we have here is priv escalation. Not pwnage. Furthermore, the box wasn't actually owned as far as I can tell. A webpage running on it was defaced, but the 1337 script kiddie who "owned" the box via "So0p3r 53|<r3t AND UNPUBLISHED AND UNPATCHED FLAWS" did not, in fact, gain root. Nor did he rm -rf /. Again, while I'm not a major apple fanboy, this article contained half-baked reporting at best, outright misinformation at worst.
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson
--Spider Robinson

