Stories
Slash Boxes
Comments

News for nerds, stuff that matters

U of Wisconsin's Mac OS X Security Challenge

Posted by Zonk on Tue Mar 07, 2006 09:10 AM
from the they-really-don't-have-anything-better-to-do-over-there dept.
digitalsurgeon writes "The University of Wisconsin [ed: Go Badgers] has launched a Mac OS X Security challenge, in response to a 'woefully misleading ZDnet article'. From the site: 'The challenge is as follows: simply alter the web page on this machine, test.doit.wisc.edu. The machine is a Mac mini (PowerPC) running Mac OS X 10.4.5 with Security Update 2006-001, has two local accounts, and has ssh and http open - a lot more than most Mac OS X machines will ever have open.' Are you up to the task? Can you prove ZDNet wrong, or can you show that Mac OS X can really be hacked in less then 30 minutes? More information about the challenge is at http://test.doit.wisc.edu/ The challenge ends Fri 10 March 2006 10:00 AM CST." Update: 03/07 14:32 GMT by Z : Commentary on the contest and original claim is available at VNUNet

Related Stories

[+] Mac OS X Security Competition Ends in 30 Minutes 388 comments
ninja_assault_kitten writes "ZDnet is running an article on how a Swedish Mac OS X enthusiast held a competition to prove how good security was on his new fully patched Mac Mini was. Unfortunately, 30 minutes after the competition began, a hacker known as 'gwerdna' had broken in and defaced the website, thus winning the contest. According to gwerdna, 'Mac OS X is easy pickings for bug finders. That said, it doesn't have the market share to really interest most serious bug finders.'." It's also worth noting a piece that says all the security news is much ado about nothing, in practical terms. The security contest also allowed people to have local access via SSH, so that had a lot to do with the crack.
[+] IT: Call for Apple Security 'Czar' 254 comments
conq writes "The second security non-incident to hit the Mac platform in as many weeks has been debunked. People are talking a lot about security on the Mac these days, and the result is that a great deal of FUD is being spread around. BusinessWeek's latest Byte of The Apple column suggests that its time for Apple to appoint a security Czar to get out ahead of the FUD before it spreads much more." From the article: "Creating a CSO position may be viewed by some as an admission of weakness. Still, I say it would be a good way for Apple to inoculate itself against the perception -- warranted or not -- that Mac security may be eroding, and get ahead of the curve for any troubles that may be inevitable. That may not be the case, but in matters related to product marketing, it's the public perception, not the reality that really matters. And once you've lost a user's confidence, it's hard to get it back. Just ask Microsoft."
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • Prove it! (Score:5, Funny)

    by Bromskloss (750445) on Tuesday March 07 2006, @09:11AM (#14865906)
    Can you prove ZDNet wrong, or can you show that Mac OS X can really be hacked in less then 30 minutes?

    So guys, what do you say? Should we all mabye prove ZDNet wrong by not breaking into that computer?
  • A Different Test (Score:5, Informative)

    by Paradise Pete (33184) <.listcatcher. .at. .fastmail.fm.> on Tuesday March 07 2006, @09:11AM (#14865907)
    (Last Journal: Tuesday May 03 2005, @09:38PM)
    While I appreciate this test, and expect it to not be breached, it is simply not the same test. The original test was to see if a regular local user could elevate its privileges to admin. The fact that the "proof" was to be done by changing a web page is a red herring. The real story was that someone was (apparently) able to do that.

    This test is of the web server, and of remote cracking without local access. Also, the explanation page says that the original article did not mention that local access was given. Well, perhaps they've updated the article, but it certainly says so now:

    "Participants were given local client access to the target computer and invited to try their luck."
    As I said, I appreciate this test, but I am also concerned about the apparent ability of an ordinary local user to gain admin status.
    • Re:A Different Test by Yahweh Doesn't Exist (Score:3) Tuesday March 07 2006, @09:15AM
      • Re:A Different Test (Score:5, Informative)

        by Tim C (15259) on Tuesday March 07 2006, @09:27AM (#14866019)
        Lots of hosting companies offer ssh access, not to mention that if an account exists on the machine with ssh access, it may be only a matter of time before someone manages to gain access to it.
        [ Parent ]
        • Re:A Different Test by walt-sjc (Score:3) Tuesday March 07 2006, @09:38AM
          • 1 reply beneath your current threshold.
        • Still no comparison (Score:5, Insightful)

          by massysett (910130) on Tuesday March 07 2006, @11:11AM (#14866775)
          (http://www.smileystation.com/)
          Lots of hosting companies offer ssh access, not to mention that if an account exists on the machine with ssh access, it may be only a matter of time before someone manages to gain access to it.

          True, but this test still does not compare to what hosting companies are doing. Web hosting companies are (hopefully) run by professionals who secure the boxes. Web hosting companies run operating systems like RHEL that were designed for server use--Mac OS X on a Mac Mini was designed for home use.

          Most importantly though, hosting companies are not giving ssh to any anonymous joe off the street, which is exactly what happened in this contest. At a minimum, web hosting companies have your credit card number before they offer you ssh. Some will demand additional information, such as a faxed copy of a driver's license. Of course a crook can get a drivers' license and a stolen credit card, but these are additional hoops to jump through that make the process of cracking the machine that much more trouble. Plus, if someone does crack the machine despite his lack of anonymity, the hosting company might be able to track him down.

          This contest as reported on ZDNet was a joke. The guy gave ssh accounts to anyone who asked for them, without demanding any proof of identification. He ran it on an OS that was not designed to be run with untrusted users logged in. Furthermore, the crack was done by an anonymous person using an "undocumented" security hole, which to me calls the credibility of the whole episode into question. In what real-world situtation does anyone allow ssh login to any random, anonymous Joe?

          [ Parent ]
          • Re:Still no comparison (Score:4, Informative)

            by kaffiene (38781) on Tuesday March 07 2006, @07:34PM (#14871394)
            The reality is that a user was able to elevate their permissions to root - that's a security concern and ought to be pointed out as a weakness. It would be a weakness if it happened on Windows or Linux, it doesn't become a non-issue because fan boys think that only web security is important.

            The fact is *all* security gaps are important. If there's a network hack that can only get you a non-priviledged account, but you can then jack that up to root access using this local hole, then that hole was mighty significant. This whole "Mac has no security faults" meme is dangerously delusional. It's significantly more secure than Win32, but at least own up to faults (small as they may be) and get them fixed, don't bury your heads in the sand.
            [ Parent ]
        • Re:A Different Test by ratboy666 (Score:2) Tuesday March 07 2006, @11:21AM
          • 1 reply beneath your current threshold.
        • Virtual Servers? by SuperKendall (Score:2) Tuesday March 07 2006, @11:50AM
    • Re:A Different Test (Score:5, Insightful)

      by mekkab (133181) on Tuesday March 07 2006, @09:20AM (#14865963)
      (http://apl.jhu.edu/~mekkab | Last Journal: Tuesday January 30 2007, @03:45PM)
      I think you can't "see the forest for the trees."

      The original test was equivalent to saying "I'll let a thief into my house. Let's see if he can steal anything!" Most houses don't have everything bolted down to the floor.

      But how often do you allow someone into your machine? For A desktop, not often, perhaps never.

      The biggest risk to most computers is a network based attack; this is the real meat and potatoes and a better test of the security of a machine.
      [ Parent ]
      • Re:A Different Test (Score:5, Insightful)

        by Paradise Pete (33184) <.listcatcher. .at. .fastmail.fm.> on Tuesday March 07 2006, @09:31AM (#14866043)
        (Last Journal: Tuesday May 03 2005, @09:38PM)
        The original test was equivalent to saying "I'll let a thief into my house. Let's see if he can steal anything!"

        I don't think that analogy is quite apt. It's more like locking someone in your basement and they figure out how to gain access to your whole house.

        When I run a third party program I am essentially letting them inside, but as a non-priviledged user I'm confining them to a specific area. But if this ability to elevate privileges turn out to be a fact, then any program I run can have full access.

        Right now we have only this one supposed demonstration of it. What I'd really appreciate seeing is that *original* test repeated. If we can look at this as if it were an experiment, then when someone publishes a result others try to repeat it under the same conditions. They don't conduct a different test with different conditions in order to disprove the original.

        [ Parent ]
        • Re:A Different Test by Paradise Pete (Score:1) Tuesday March 07 2006, @09:42AM
        • Re:A Different Test (Score:5, Funny)

          by Stalyn (662) on Tuesday March 07 2006, @10:17AM (#14866362)
          (http://slashdot.org/~Stalyn/journal | Last Journal: Wednesday September 28 2005, @08:10PM)
          If we can look at this as if it were an experiment, then when someone publishes a result others try to repeat it under the same conditions. They don't conduct a different test with different conditions in order to disprove the original.

          Science never enters the picture here, this is a religious debate.

          [ Parent ]
        • Much better analogy! (Score:5, Interesting)

          by mekkab (133181) on Tuesday March 07 2006, @10:20AM (#14866398)
          (http://apl.jhu.edu/~mekkab | Last Journal: Tuesday January 30 2007, @03:45PM)
          I don't think that analogy is quite apt. It's more like locking someone in your basement and they figure out how to gain access to your whole house.

          Okay- I like that analogy better. I've got deep deadbolts on my outside doors; the door between my basement and house has a cheap handle lock that can be popped with a long, thin screw driver.

          Not to get lost in the analogy details, but I think you'll find most security skews the same way.


          When I run a third party program I am essentially letting them inside, but as a non-priviledged user I'm confining them to a specific area. But if this ability to elevate privileges turn out to be a fact, then any program I run can have full access.


          I think this ability to elevate privs should be analyzed on a case by case basis for all programs; as such if you are concerned about what applications a user can and can't run, remove the ability to run those applications from the machine.

          However with most desktop machines your biggest worry isn't normally* an attack from within; its usually from without.

          *)people on slashdot aren't normal and typically have needs that extended beyond normal users. Feel free to contribute some examples that counter this assertion.
          [ Parent ]
        • Re:A Different Test by xtracto (Score:2) Tuesday March 07 2006, @10:49AM
        • Re:A Different Test by 99BottlesOfBeerInMyF (Score:2) Tuesday March 07 2006, @11:44AM
        • Re:A Different Test by squiggleslash (Score:2) Tuesday March 07 2006, @11:56AM
        • try it for Windows or Linux...Re:A Different Test by javaxman (Score:3) Tuesday March 07 2006, @02:16PM
        • Re:A Different Test by lisaparratt (Score:2) Monday March 13 2006, @04:46AM
        • 2 replies beneath your current threshold.
      • Re:A Different Test by Anonymous Coward (Score:3) Tuesday March 07 2006, @09:37AM
      • Re:A Different Test by neuroticia (Score:1) Tuesday March 07 2006, @10:33AM
      • Re:A Different Test by rolosworld (Score:1) Tuesday March 07 2006, @10:42AM
      • Re:A Different Test by Guido von Guido (Score:2) Tuesday March 07 2006, @10:52AM
      • Re:A Different Test by ZoOnI (Score:1) Tuesday March 07 2006, @12:52PM
      • Re:A Different Test by farble1670 (Score:2) Tuesday March 07 2006, @12:53PM
      • a better analogy by geekee (Score:2) Tuesday March 07 2006, @01:56PM
      • sorry mate by weierstrass (Score:1) Tuesday March 07 2006, @05:47PM
        • Re:sorry mate by mekkab (Score:1) Wednesday March 08 2006, @11:01AM
      • Re:A Different Test by mgblst (Score:1) Tuesday March 07 2006, @10:03AM
      • Re:A Different Test by mekkab (Score:2) Tuesday March 07 2006, @10:12AM
      • 4 replies beneath your current threshold.
    • Re:A Different Test (Score:5, Informative)

      Yes, they updated the article.

      And the whole point isn't that the test "isn't the same". This is how most Mac OS X machines will appear to outside entities on the internet. The original article - and definitely before it was updated - left people with the impression that a Mac OS X machine could be owned in 30 minutes just by being connected to the internet, without the user "doing" anything, and the subsequent coverage of this in most press proves it. None speak to the fact that a local account was given, or even explore the implications. What could have been a useful article was useless, vague sensationalism. I updated the bottom of the page this morning:

      Update

      The ZDnet article has been updated to include the sentence, "Participants were given local client access to the target computer and invited to try their luck." But might it not have been interesting to explore:

      - What are the implications of local account access, and under what conditions might a computer be used in that way?

      - How can such access normally be obtained? Do home users behind firewalls and with no ports open need to worry?
      How can a vendor fix the claimed local privilege escalation vulnerabilities when they are not informed of the issue?

      - What are the moral and ethical implications of knowing about allegedly severe vulnerabilities in products, like the "hacker" they interviewed, and actively choosing to NOT give the vendor an opportunity to fix the problem(s)?

      - How might a Linux or BSD distribution, other commercial UNIXes, or Windows stand up to a similar challenge, where anyone who wishes is given local account access?

      - A discussion about how since much of OS X is closed, this might make it more difficult for the community to discover - and report and fix - potential vulnerabilities in the closed pieces

      ...and things of that nature, instead of leaving people with the impression that any Mac OS X machine connected to the Internet can be taken over in 30 minutes?

      [ Parent ]
      • Re:A Different Test (Score:5, Insightful)

        by jav1231 (539129) on Tuesday March 07 2006, @09:35AM (#14866066)
        Exactly. If you wanted to truly compare OS X to Windows in this scenerio, put a PC on the Net with TS opened and give out the user account information.
        [ Parent ]
      • Thanks for hosting this contest by nule.org (Score:1) Tuesday March 07 2006, @09:40AM
      • Re:A Different Test by Total_Wimp (Score:3) Tuesday March 07 2006, @10:02AM
      • Re:A Different Test by Fnord666 (Score:2) Tuesday March 07 2006, @10:03AM
      • Re:A Different Test by tpgp (Score:3) Tuesday March 07 2006, @10:07AM
        • Re:A Different Test (Score:5, Interesting)

          I say that on the actual site itself:

          Mac OS X is not invulnerable. It, like any other operating system, has security deficiencies in various aspects of the software. Some are technical in nature, and others lend themselves to social engineering trickery. However, the general architecture and design philosophy of Mac OS X, in addition to usage of open source components for most network-accessible services that receive intense peer scrutiny from the community, make Mac OS X a very secure operating system. There have been serious vulnerabilities in Mac OS X that could be taken advantage of; however, most Mac OS X "vulnerabilities" to date have relied on typical trojan social engineering tactics, not genuine vulnerabilities. The recent Safari vulnerability was promptly addressed by Apple, as are any exploits reported to Apple. Apple does a fairly good job with regard to security, and has greatly improved its reporting processes after pressure from institutional Mac OS X users: Apple is responsive to security concerns with Mac OS X, which is one of the most important pieces of the security picture.

          The "Mac OS X hacked under 30 minutes" story doesn't mention that local access was granted to the system. While local privilege escalation exploits can certainly be dangerous - and used in conjunction with things like the above Safari exploit - this isn't very informative with regard to the general security of a Mac OS X machine sitting on the Internet.


          Of course, I'd have no problem with this if the original article had actually talked about it meaningfully in the context of a local privilege escalation and explored the implications; instead, they just made it sound like you could throw a patched OS X box onto the internet and it'd get owned. The average reader would leave with that *distinct* impression, and most of the subsequent coverage of it talked about it exactly in that fashion.

          Mac OS X has had several local privilege escalation vulnerabilities, just as other OSes have had. Apple fixes them when they become known. (Also, and this is another discussion, but what can Apple do if the "hacker's" claims are correct, i.e., that the vulnerability is unknown to Apple? It doesn't prove that Mac OS X is "insecure"; all it "proves" is that open scrutiny is difficult with closed source pieces, and that some people intentionally and knowingly refuse to give vendors a chance to fix problems.)
          [ Parent ]
        • A bigger real threat for OS X by jscotta44 (Score:1) Tuesday March 07 2006, @10:26AM
          • 1 reply beneath your current threshold.
      • Re:A Different Test by AKAImBatman (Score:3) Tuesday March 07 2006, @10:21AM
      • Original Test Was More Interesting (Score:5, Interesting)

        by adam1101 (805240) on Tuesday March 07 2006, @10:36AM (#14866520)
        Actually, I think the original test was more interesting than this one. For years we've read countless +5 Insightful posts that OS X is more secure than Windows because normal users run in restricted accounts by default. That trojans can't do anything to the system unless you're "stupid enough to type in your password". If the original hack was indeed an exploit of an undisclosed buffer overflow, it means that this argument is pretty much moot. There have already been lots of posts in this and the previous article that amounted to saying "a local exploit is no big deal, everybody has them, if you have local (restricted) access you should be expected to be compromised anyway". Are these posters saying that the supposed advantages of restricted user accounts on OS X are very overrated? Are they saying it's no big deal if the next social engineering attack is combined with a buffer overflow exploit, meaning no popups asking for your password?

        If the original hacker Gwerdna (Andrew G?) was right that there are many undisclosed priviledge escalation bugs, that is a case for concern, not something to be dismissed as a mere "local" vulnerability. BSD, Linux and even Windows already have patches for NX [wikipedia.org] to contain buffer offerflows, where is Apple on this?

        I think that, especially if you're an Apple user, it is very important to test the claim that the OS is rifle with local priviledge escalation issues. And that's why I think the first test was much better than this one. I don't expect this U of W box to be hacked anytime soon. But this proves very little. You can even setup a Windows SP2 ISS+Remote Desktop box like this, and I don't think it will be hacked anytime soon either. But if you redo something like the original box (give normal user ssh accounts to anyone) and get hacked very quickly again, it proofs a lot. Namely that the local security measures of OS X that many have come to thrust amount to very little.
        [ Parent ]
      • Re:A Different Test (Score:5, Interesting)

        by ScriptedReplay (908196) on Tuesday March 07 2006, @11:33AM (#14866961)
        *sigh* are you guys hopeless? The point of the original test was not to hack the machine from outside, but from inside. All the noise about Windows getting hacked 4 minutes after it was connected to the net was due to lack of firewalling and vulnerable services - turn on firewalling and the vulnerable services are no longer accessible. What does that prove? nothing - they didn't magically become secure. OSX probably has fewer vulnerable services (active or not) but that was not the point.

        The point is even with proper design of user separation, local security is hard to get right. Every OS has this problem, to various degrees. And if you want a sample of what this type of problems mean, here is one: malware will not be required to ask you for a password to elevate privileges - see? all those 'this is not a virus, it asks for your password and that should set your alarm bells going' argument goes puff! in smoke. This is the same type of issue that plagued non-administrator users in Windows for a long time now. So let me put it this way:
        1. Local privilege escalation is bad - and hard to prevent (see all the attempts done by other OSes - NX, canaries against stack smashing, grsecurity, PAX, load address randomization and so on)
        2. Local privilege escalation to root is really bad. There are precious few places where one should have to look for things that run as root. Most of them are in the default install. And the worst that can happen is a kernel-level exploit, as that would be likely to affect OSX Server as well, which is far more likely to be used in a multiuser setup.


        So, to come back - your test is utterly irrelevant for the type of people that would be interested in the original one. What you are trying to test is the security of the OpenSSH and Apache installs + your setup (yeah, and password strength - expect to be hit by automated dictionary attacks from scripts that couldn't care less about your test). If I had an XServe machine with several users having ssh access I would really want to know whether any of those users really can get root on the machine or not (if they can, XServe has no place in such enviroment). And I would be really worried. As it stands, I still have worries, but at least I know that I have a certain amount of protections in place against such problems (this not being OSX though - no OS names since I'm not interested in 'my OS is more secure than your OS' flames) But this is a real security concern and yet you turn around and say 'but these other things are secure.' Yeah, the article could have sounded misleading for anyone not willing to check the site and see the conditions (but few people would do that anyway) but how are you any better? All this is countering journalistic sensationalism with more of the same, since your box is neither set up as a home user's nor your setting is pertinent to the original multiuser problem.

        To toss in my 2c of an analogy - the original test was to check whether a bank's employees (with access to the bank building) can empty the main safe to which they do not have the combination[*] while yours is to check whether a customer can; all this on a Sunday when the bank is closed.

        And now mods feel free to mod me down - although a more rational answer would be welcome.

        [*] to all those saying 'by dfault root is not even enabled in OSX': bah! 'enabled' pertains to login and privilege escalation couldn't care less about login restrictions; the account is still there. And in fact, the thing that 'get root' means is 'get uid=0 access'
        [ Parent ]
      • Why Dave Schroeder is wrong (and MSFT is right!) by ichin4 (Score:3) Tuesday March 07 2006, @03:58PM
      • 2 replies beneath your current threshold.
    • Re:A Different Test by Kangburra (Score:1) Tuesday March 07 2006, @09:25AM
    • Re:A Different Test (Score:5, Insightful)

      by Fahrvergnuugen (700293) on Tuesday March 07 2006, @09:28AM (#14866020)
      (http://port80ware.com/)

      The problem is that the media presents the original test as though Mac OSX is insecure out of the box. It's very misleading.

      An acquaintance of mine runs a small web hosting company. His original service plan offered SSH accounts to every hosting account. Despite his best efforts to secure the box, it was still rooted by a script kiddie.

      His customer's PC was compromised and the ssh password for his account on the linux server was found by the script kiddie. The shell account had access to GCC. The script kiddie logged in as the non privileged user and used gcc to compile a rootkit. The rest was a walk in the park.

      The OS was Slackware linux. All of the accounts were jailed, and all of the "best practice" measures were taken to harden the box (I can't comment on every detail as I am not a linux system admin).

      My point is that when a malicious user gains shell access to any *nix system, you're in deep trouble.

      My friend has since stopped offering SSH access to his customers.
      [ Parent ]
      • Re:A Different Test by sabin1001 (Score:1) Tuesday March 07 2006, @09:38AM
      • by xiphoris (839465) on Tuesday March 07 2006, @10:02AM (#14866254)
        (http://www.xiphoris.com/)
        The real problem is that tests like this are garbage in the first place.

        In fact, Bruce Schneier [schneier.com] (a respected cryptographer, responsible for Blowfish) addressed the topic thoroughly almost 8 years ago in his column Crypto-Gram. Here's a relevant snippet:

        You see them all the time: "Company X offers $1,000,000 to anyone who can break through their firewall/crack their algorithm/make a fraudulent transaction using their protocol/do whatever." These are cracking contests, and they're supposed to show how strong and secure the target of the contests are. The logic goes something like this: We offered a prize to break the target, and no one did. This means that the target is secure.

        It doesn't.

        Contests are a terrible way to demonstrate security. A product/system/protocol/algorithm that has survived a contest unbroken is not obviously more trustworthy than one that has not been the subject of a contest. The best products/systems/protocols/algorithms available today have not been the subjects of any contests, and probably never will be. Contests generally don't produce useful data. There are three basic reasons why this is so.


        You can read the original here [schneier.com].
        [ Parent ]
      • And yet companies do it by Sycraft-fu (Score:3) Tuesday March 07 2006, @11:06AM
      • Re:A Different Test by massysett (Score:2) Tuesday March 07 2006, @11:19AM
      • Re:A Different Test by asdfghjklqwertyuiop (Score:3) Tuesday March 07 2006, @02:19PM
      • Re:A Different Test (Score:5, Interesting)

        all of the "best practice" measures were taken to harden the box

        No, they weren't. If all the filesystems that customers have write access to are mounted "noexec", then self-compiled binaries don't present a lot of exposure.

        I'm not saying that it's not a good idea to remove GCC, just that its presence isn't an automatic compromise.

        [ Parent ]
      • 1 reply beneath your current threshold.
    • Re:A Different Test by utlemming (Score:3) Tuesday March 07 2006, @09:48AM
    • Re:A Different Test by hcob$ (Score:1) Tuesday March 07 2006, @10:05AM
    • Re:A Different Test by shippo (Score:3) Tuesday March 07 2006, @10:28AM
    • Re:A Different Test by jlarocco (Score:2) Tuesday March 07 2006, @11:29AM
    • Re:A Different Test ?? No kidding. by necro2607 (Score:2) Tuesday March 07 2006, @03:16PM
    • 1 reply beneath your current threshold.
  • DDOS by BJZQ8 (Score:1) Tuesday March 07 2006, @09:12AM
    • 1 reply beneath your current threshold.
  • Hackorama Windows (Score:3, Insightful)

    by CDMA_Demo (841347) on Tuesday March 07 2006, @09:12AM (#14865913)
    (http://alien.dowling.edu/~rohit/wiki)
    I wish someone running windows 2003 professional could start a competition like this.
  • Logs (Score:5, Insightful)

    by Bromskloss (750445) on Tuesday March 07 2006, @09:13AM (#14865918)
    Mabye logs could be published (in real-time) so that we all can see some of what possible challengers are up to. That would be interesting.
  • Kinda funny by faloi (Score:2) Tuesday March 07 2006, @09:14AM
    • 1 reply beneath your current threshold.
  • * yawn * (Score:5, Insightful)

    by Noryungi (70322) on Tuesday March 07 2006, @09:17AM (#14865942)
    (http://www.slack-fr.org/ | Last Journal: Wednesday November 07, @08:25AM)
    I am sorry, but what exactly does this prove? That ZDNet is wrong? That Mac OS X is secure?

    It proves neither: every operating system on the face of this earth has been hacked, cracked, and 0wned. Numerous times. Get over it.

    Instead of inane, immature competitions such as this one, I'd rather have a nice manual (RTNM -- Read The Nice Manual) on how to improve/lock down an OS X machine. Even better, make that two manuals: one for the average joe, with nice color screenshots for every step that has to be taken, and another for people like me, who manage systems for a living. THAT would be a valuable contribution to the field of computer security, instead of this stupid challenge.

  • Possible Danger (Score:5, Insightful)

    by zaguar (881743) on Tuesday March 07 2006, @09:19AM (#14865955)
    Email das@doit.wisc.edu if you feel you have met the requirements, along with the mechanism used. The mechanism will then be reported to Apple and/or the entities responsible for the component(s).

    With virus/spyware becoming a multimillion dollar business, do you really think that the real hackers (sorry for the use of the term) will stay away from this, due to the this very condition. Do you think that the dangerous exploits and cracks that are, for the moment, unknown by Apple, and are hence, very valuable. They will not be willingly sent to Apple for some minor publicity and no material, no, they will be auctioned off in some sleazy IRC channel in Russia.

  • the original post (Score:3, Insightful)

    by rayde (738949) on Tuesday March 07 2006, @09:19AM (#14865957)
    (http://www.xboxtopic.com/)
    here is the original comment [slashdot.org] posted by Dave Schroeder about this challenge pretty much posted right after the 30-minute hack article was posted here. I'm actually quite curious whether the University of Wisconsin has approved this whole thing, as I'm not so sure they really wish to have a machine on their networks in the crosshairs.
  • Does /. win... (Score:3, Funny)

    by CupBeEmpty (720791) on Tuesday March 07 2006, @09:23AM (#14865984)
    (http://vdov.net/)
    ...if the little Mac Mini melts from a good /.'ing?
  • Generic smear campaign (Score:5, Interesting)

    by catwh0re (540371) on Tuesday March 07 2006, @09:24AM (#14865991)
    I've noticed a significant rise in anti-macosx articles recently. To the point where I'm beginning to believe that it is staged. Each article usually has 3 points to make: Mac OSX is not *nix, Max OSX is insecure and "easy" to hack (and not a target due to small install base.) and that Apple are slow with patches to security faults.

    So far each article has been based on unique situations that lack credibility to begin with, give little detail, and take focus away from the fact that it's basically a machine running a collective of industry proven software (such as apache and openssh.)

    Also of note is that Mac OSX currently has an a user base of over 10 million machines. So the argument that it's too small a target is ridiculous. In fact it's a bigger target as it's untouched territory with a bonus of headline making news.

  • Hacked Pixel #F0F8FF (Score:4, Funny)

    by digitaldc (879047) * on Tuesday March 07 2006, @09:24AM (#14865994)
    I hacked in, and in 22 minutes changed one of the pixels from #FFFFFF to #F0F8FF, but it is very hard to tell.
    In fact, nobody even noticed.
  • Dupe! by tpgp (Score:1) Tuesday March 07 2006, @09:24AM
    • 1 reply beneath your current threshold.
  • It is running Apache 1.3.33 by bryankwalton (Score:1) Tuesday March 07 2006, @09:25AM
  • I'm not sure what the value of this is..... by 8127972 (Score:2) Tuesday March 07 2006, @09:26AM
  • over 15 posts! by ikejam (Score:2) Tuesday March 07 2006, @09:26AM
  • The IP (Score:4, Informative)

    by zaguar (881743) on Tuesday March 07 2006, @09:30AM (#14866036)
    The IP of the server under the test. Saves you a ping of the site.

    128.104.16.150

    • Re:The IP by Kadin2048 (Score:2) Tuesday March 07 2006, @09:42AM
    • Re:The IP by cpollett (Score:1) Tuesday March 07 2006, @10:50AM
      • 1 reply beneath your current threshold.
    • Re:The IP by flutkatastrophe (Score:3) Tuesday March 07 2006, @11:25AM
    • Re:The IP by daveschroeder (Score:2) Tuesday March 07 2006, @12:11PM
    • Re:The IP by MirrororriM (Score:1) Tuesday March 07 2006, @01:52PM
    • 1 reply beneath your current threshold.
  • Hint (Score:5, Informative)

    by spike2131 (468840) on Tuesday March 07 2006, @09:31AM (#14866045)
    (http://currierandives.net/)
    One of the user names is "das".... as in http://test.doit.wisc.edu/~das/ [wisc.edu]

    So run that against a dictionary and see if you can get in....
    • Re:Hint by AcornWeb (Score:1) Tuesday March 07 2006, @09:41AM
      • Re:Hint by artemis67 (Score:2) Tuesday March 07 2006, @02:38PM
    • Re:Hint by kajoob (Score:2) Tuesday March 07 2006, @09:57AM
      • Re:Hint by artemis67 (Score:3) Tuesday March 07 2006, @10:23AM
    • by xxxJonBoyxxx (565205) on Tuesday March 07 2006, @10:18AM (#14866379)
      The server appears to be Apache 1.3.3.3, one version behind the current release. The 1.3.3.4 release has a fix for this item, which would be my favorite vector, but I doubt that this server has an application that uses chunked encoding (often used for file uploads).

          *) SECURITY: core: If a request contains both Transfer-Encoding and
                Content-Length headers, remove the Content-Length, mitigating some
                HTTP Request Splitting/Spoofing attacks. This has no impact on
                mod_proxy_http, yet affects any module which supports chunked
                encoding yet fails to prefer T-E: chunked over the Content-Length
                purported value. [Paul Querna, Joe Orton]
      [ Parent ]
    • Doubtful... (Score:4, Funny)

      by TCQuad (537187) on Tuesday March 07 2006, @10:23AM (#14866421)
      While you're right on the "das", it's doubtful that a dictionary crack would fix it. Since "das" is also his U of Wisc NetID (ref. the e-mail address at the bottom of the page [wisc.edu]), it's more likely that the password is the same as his U of Wisc password [wisc.edu].

      So... Anyone up for breaking into the U of Wisc password database?
      [ Parent ]
    • Re:Hint by woodlouse_man (Score:1) Tuesday March 07 2006, @10:26AM
    • Re:Hint by Drizzt Do'Urden (Score:1) Tuesday March 07 2006, @10:53AM
    • 2 replies beneath your current threshold.
  • Here's MY CHALLENGE! by Dystopian Rebel (Score:2) Tuesday March 07 2006, @09:32AM
  • Do over! by LaminatorX (Score:2) Tuesday March 07 2006, @09:32AM
  • Contest? Pffft..... by archeopterix (Score:2) Tuesday March 07 2006, @09:37AM
    • 1 reply beneath your current threshold.
  • In case we missed it.. by MrShaggy (Score:1) Tuesday March 07 2006, @09:45AM
  • Slashdotted/Denial Of Service by cspring007 (Score:1) Tuesday March 07 2006, @09:46AM
  • Contest closes March 10? (Score:3, Interesting)

    by TheSkepticalOptimist (898384) on Tuesday March 07 2006, @09:47AM (#14866158)
    So Mac OSX security only works for 3 days, while someone is closely monitoring all web traffic?

    If this was a legit challenge, then don't close the challenge. Leave it open, so that when you least suspect it, someone has hacked your site.

    But is this challenge stating the security of OSX? Defacing a website is the same as having a Trojan virus installed that wipes out your applications or formats your system? Why not offer a challenge to find out if someone can write a virus that will adversely affect OSX. The delivery is unimportant, as long as there are people happily downloading apps from P2P, opening email attachments, and downloading security updates from email warnings. No OS is truly secure from human ignorance.

    I guarantee that some hacker will deface the website, but I question the legitimacy of imposing a time limit on the challenge. Certainly hackers don't have a time limit when they corrupt Linux or Windows based website servers, so why impose one for Mac. I think someone is closely monitoring the challenge website, ready to counter any possibility of it being hacked in order to solidify the OSX security myth.
    • 1 reply beneath your current threshold.
  • How unfair! (Score:4, Funny)

    by Linux_ho (205887) on Tuesday March 07 2006, @10:03AM (#14866264)
    (http://slashdot.org/)
    They've removed the biggest security hole in an OS X system: The Mac User. The Mac User will set "fluffy" as their password, and attempt to install any interesting-looking screensaver that gets e-mailed to them. Not that any other OS would do much better in the face of such adversity. But it's funny that they would use a test like this to "demonstrate the security" of a desktop OS.
    • Re:How unfair! by zpok (Score:2) Wednesday March 08 2006, @05:17AM
    • 1 reply beneath your current threshold.
  • /.ing by emerrill (Score:2) Tuesday March 07 2006, @10:03AM
  • Sad. by ninja_assault_kitten (Score:1) Tuesday March 07 2006, @10:09AM
    • Re:Sad. by prockcore (Score:2) Tuesday March 07 2006, @10:25AM
    • Re:Sad. by 99BottlesOfBeerInMyF (Score:3) Tuesday March 07 2006, @10:33AM
      • Re:Sad. by ninja_assault_kitten (Score:1) Tuesday March 07 2006, @10:46AM
        • Re:Sad. by ninja_assault_kitten (Score:1) Tuesday March 07 2006, @10:49AM
          • Re:Sad. by 99BottlesOfBeerInMyF (Score:2) Tuesday March 07 2006, @11:18AM
        • Re:Sad. by 99BottlesOfBeerInMyF (Score:2) Tuesday March 07 2006, @11:28AM
          • Re:Sad. by ninja_assault_kitten (Score:1) Tuesday March 07 2006, @11:43AM
            • Re:Sad. by 99BottlesOfBeerInMyF (Score:2) Tuesday March 07 2006, @12:04PM
          • Re:Sad. by 99BottlesOfBeerInMyF (Score:2) Tuesday March 07 2006, @03:33PM
          • 1 reply beneath your current threshold.
  • Busted? by jrmcferren (Score:2) Tuesday March 07 2006, @10:10AM
  • Big deal.. by Mark Gillespie (Score:1) Tuesday March 07 2006, @10:12AM
    • Re:Big deal.. by 99BottlesOfBeerInMyF (Score:2) Tuesday March 07 2006, @10:24AM
  • One of the unusual things about the "hacked" machine was that Fink was installed. This most likely means that the Apple developer tools were installed (although Fink can install precompiled binaries), making it possible for the hacker to bring his own code and compile on the system. Although Apple ships the developer tools on the OS X client install DVD, it is not installed by default, nor is X11.

    Fink lists a catalog of 6359 open source projects [finkproject.org]that can be installed, many of which are tools that could help a hacker exploit a machine or that are exploitable in themselves. Fink is a Debian style package manager for Mac OS X.

  • Don't play this down by kestasjk (Score:2) Tuesday March 07 2006, @10:46AM
  • A more "real-world" test? (Score:3, Interesting)

    by redmoss (108579) on Tuesday March 07 2006, @10:50AM (#14866634)
    (http://yoderhome.com/)
    It seems to me that tests like "remote break-in using ssh" are not as good of a fit to today's common home computing environment. For something like OS X, most home machines probably are not running any services, so it is rather pointless to try to break into them using standard ssh/http attacks.

    I would prefer to see test break-in attempts set up like this:

    an unprivileged "test account" is created on OS X and set up with email, web browser, and other common desktop programs

    the "test account" is set up with several common methods of communicating with the outside world: email, IM, commonly-browsed web sites, webmail, banking sites, etc

    the test account's email address and IM account are made public to the would-be attackers

    someone regularly checks the test account's email and acts like a "gullible user" would, eg click on spam and phishing links, go to hostile web sites, follow dubious instructions received via IM from supposed friends

    the challenge: attacker must be able to do something "bad": control box resources (think spyware), steal critical system information (think remote root), get bank account information (think phishing), whatever

    A few years ago, this was trivial on Windows. I hear they've cleaned up their act to some extent. How well would OS X hold up? How about a standard desktop version of Linux?
  • Data General used to Boast (Score:4, Interesting)

    by Greyfox (87712) on Tuesday March 07 2006, @10:57AM (#14866672)
    (http://www.flying-rhenquest.net/)
    That their B2 secure version of UNIX was so secure that you could safely post the root password on the Internet. I always thought that was rather disingenuous seeing as how pretty much every UNIX I've worked with required additional configuration to enable remote root logins, but root never had much power on those systems even if someone did find a third party server (or telnetd *cough*) with a possible exploit.

    Then IBM bought Data General and that was the last we heard of DG/UX B2 Secure. Pity really. They should have ditched AIX instead. But I digress...

    OSX is pretty damn secure right out of the box, but Apple could do more to make it tighter by default. They've already managed the security versus usability balance far better than Microsoft has managed so far. I think Apple could push a little more over to the security side of the thing without noticably affecting usability. I also think that Apple users would accept slightly less user friendly systems in order to continue to walk around with that air of I-can't-get-spyware-or-virusses smugness that no Windows user will ever understand until they've seriously used an Apple machine for a few days. Apple's selling more than a machine. They're selling the ability to not have to live in fear every time you connect that machine to the Internet. They're selling the ability to not have to run so many third party security applications that the shiny new machine runs like a shiny new machine from 5 years ago. I think that is worth any percieved price premium.

    • 1 reply beneath your current threshold.
  • I'm a student at UW-Madison by herrvinny (Score:2) Tuesday March 07 2006, @11:16AM
  • Can we break into it? by edunbar93 (Score:2) Tuesday March 07 2006, @11:20AM
  • OT: Badgers by merc (Score:1) Tuesday March 07 2006, @11:22AM
    • Re:OT: Badgers by everphilski (Score:2) Tuesday March 07 2006, @11:40AM
  • Just down the street by jafiwam (Score:2) Tuesday March 07 2006, @11:24AM
  • I could easily win the challenge... by ScottSCY (Score:1) Tuesday March 07 2006, @11:25AM
  • Mac Mini Survives Slashdotting (Score:3, Informative)

    by Anonymous Coward on Tuesday March 07 2006, @11:40AM (#14867030)
    I love how the mac mini is surviving the slashdotting no probs. Sure its mostly text, but I've seen similar sites crumble in no time.

    http://test.doit.wisc.edu/ [wisc.edu]

    Chris
  • And yet somehow it still hasn't been compromised by wellvis (Score:1) Tuesday March 07 2006, @12:28PM
  • by podperson (592944) on Tuesday March 07 2006, @12:30PM (#14867560)
    (http://loewald.com/)
    It appears that the original article has been changed since originally posted. It currently reads:

    "On February 22, a Sweden-based Mac enthusiast set his Mac Mini as a server and invited hackers to break through the computer's security and gain root control, which would allow the attacker to take charge of the computer and delete files and folders or install applications.

    "Participants were given local client access to the target computer and invited to try their luck."


    Other related blog entries have noted the update.

    Even so, the article fails to mention that this vulnerability relies on extra work on the part of the system administrator to create the accounts and open ssh.
  • It's running Apache 1.3.33 by Spy der Mann (Score:2) Tuesday March 07 2006, @12:38PM
  • Why encourage hacking? by Control-Z (Score:2) Tuesday March 07 2006, @01:12PM
  • Unscientific by wolfi (Score:1) Tuesday March 07 2006, @01:34PM
    • Right... by jscotta44 (Score:1) Wednesday March 08 2006, @09:38AM
      • Re:Right... by SuperAlgae (Score:1) Wednesday March 08 2006, @06:40PM
        • Agreed! by jscotta44 (Score:1) Wednesday March 08 2006, @10:04PM
  • You need a reward by geekee (Score:2) Tuesday March 07 2006, @03:06PM
  • Simple! by r_jensen11 (Score:1) Tuesday March 07 2006, @05:12PM
    • Re:Simple! by herrvinny (Score:2) Tuesday March 07 2006, @08:11PM
  • Hacked? by darthservo (Score:1) Tuesday March 07 2006, @06:52PM
  • MiniSlashdotting (Score:3, Interesting)

    by EigenHombre (684799) * on Tuesday March 07 2006, @07:38PM (#14871418)
    (http://www.npxdesigns.com/ | Last Journal: Tuesday August 16 2005, @09:40AM)
    Am I the only one who is impressed that a single PowerPC (not multi-core Intel) Mac Mini can survive a slashdotting? (Not to mention the additional DoS attacks -- and with rather zippy response time to boot.)

    - Former Badger, glad I ordered one of those new MacBooks

  • Test Now Closed (Score:3, Interesting)

    by themadplasterer (931983) on Wednesday March 08 2006, @12:07PM (#14876273)
    The test is now closed and there were no sucsessful security breaches. This proves what most of us already knew about Mac OS X .This is take directly from the site http://test.doit.wisc.edu/ [wisc.edu] Mac OS X Security Test Tue 7 March 2006 11:59 PM CST (8 March 2006 0559 GMT) The testing period is now closed. The response has been very strong, and the test has illustrated its point. Traffic to the host spiked at over 30 Mbps. Most of the traffic, aside from casual web visitors, was web exploit scripts, ssh dictionary attacks, and scanning tools such as Nessus. The machine was under intermittent DoS attack. During the two brief periods of denial of service, the host remained up. The test machine was a Mac mini (PowerPC) running Mac OS X 10.4.5 with Security Update 2006-001, had two local accounts, and had ssh and http open with their default configurations. There were no successful access attempts of any kind, including during the 38 hour duration of the test period, nor have their been any claims of success. The host is still the same host and configuration used for the test. Some snippets from 7 March 2006: The site received almost a half a million requests via the web. There were over 4000 login attempts via ssh. The ipfw log grew at 40MB/hour and contains 6 million events logged. Several social engineering attempts were received, including one purporting to be from the government of Sweden, which apparently uses GMail. ;-) More test results and information will be published here at a future date.
  • Sour grapes by Swift2001 (Score:1) Wednesday March 08 2006, @01:17PM
  • Contest Over! Winner Announced (Score:3, Informative)

    by bugnuts (94678) on Wednesday March 08 2006, @05:53PM (#14879260)
    (Last Journal: Friday November 09, @05:49PM)
    Yesterday we discovered the Mac OSX "challenge" was not an activity authorized by the UW-Madison. Once the test came to the attention of our CIO, she ended it. The site, test.doit.wisc.edu, will be removed from the network tonight. Our primary concern is for security and network access for UW services. We are sorry for any inconvenience this has caused to the community.


    The CIO of UW-Madison has managed to get test.doit.wisc.edu website defaced.
  • Last seen message from site by djkuhl (Score:1) Wednesday March 08 2006, @06:59PM
  • Windows Security Challenge! by bananaendian (Score:1) Thursday March 09 2006, @03:51AM
  • UPDATE on the contest (Score:3, Informative)

    by EvilStein (414640) <{spam} {at} {pbp.net}> on Saturday March 11 2006, @02:48AM (#14897049)
    (http://www.pbp.net/)
    Just in case and of you dumb fuck "Macs suck" knuckle draggers are wondering, It's over. U of Wi pulled the plug.

    38 hours and not one successful crack.

    Mr "Mac OS X is so insecure" didn't even manage to get in.

    http://www.technewsworld.com/story/49296.html [technewsworld.com]
  • Re:2 services only ? by Metrathon (Score:1) Tuesday March 07 2006, @11:17AM
  • by TubeSteak (669689) on Tuesday March 07 2006, @01:57PM (#14868544)
    (Last Journal: Saturday February 25 2006, @11:02PM)
    http://apple.slashdot.org/comments.pl?sid=179501&c id=14866581 [slashdot.org]

    by daveschroeder (516195) on Tuesday March 07, @10:44AM (#14866581)
    And yes, this challenge is sanctioned. I'm glad that the University of Wisconsin supports the genuine interests of its faculty, staff, and students, and encourages individual thought, research, discovery, and exploration. That's why it's a great place to be!
    No +1 Informative for you.
    [ Parent ]
  • Re:attack on my system just moments after by rbannon (Score:1) Thursday March 09 2006, @12:13PM
  • 16 replies beneath your current threshold.