Archive notice: This article was originally published on April 2, 2008. Links and embedded videos are preserved as part of the historical record.
During the “Pwn to Own” hacking competition, devices running Mac OS X and Windows were compromised through vulnerabilities in Safari and Flash respectively. Only the open-source system Linux successfully withstood the experts’ attacks. At the event sponsored by security company TippingPoint http://www.tippingpoint.com at the CanSecWest security conference http://cansecwest.com late last week, experts could win laptops if they gained access to files on the systems through zero-day exploits. “An interesting competition, because not everyone has the skills to find zero days,” Mikko Hyppönen, a security specialist at F-Secure http://www.f-secure.com, tells pressetext.de. With OS X Leopard 10.5.2 on a MacBook Air, Vista Ultimate SP1 on a Fujitsu device and Ubuntu Linux 7.10 on a Sony notebook, the three major operating-system names were represented as targets.
All three target systems had been patched to the latest available versions. On the first day of the competition, participants could attack only the operating system itself over the network. The result was quite pleasing for the operating-system manufacturers, as there was initially no successful hacking attempt. “That is a significantly better situation than would have been the case two years ago,” Hyppönen says. Subsequently, however, the attack vectors were expanded. On the second day, attacks involving standard applications and requiring user interaction were also permitted. These included methods exploiting vulnerabilities in email or browser software. For the final day of the competition, the rules were relaxed even further, allowing attacks through third-party applications considered popular by the jury.
The browser proved OS X’s undoing on the second day. A team from Independent Security Evaluators (ISE) http://securityevaluators.com led by Charlie Miller used a vulnerability in Apple’s Safari browser to win the MacBook Air and 10,000 dollars. The security expert said his team had chosen Leopard as what they considered the easiest target. Apple and Safari had already come into ISE’s sights when the security experts announced the discovery of the first iPhone vulnerability in July 2007. On the third day, a team led by Shane Macaulay from security consultancy and software development company Security Objectives http://security-objectives.com used a vulnerability in Adobe Flash for a successful attack on Windows, earning the team 5,000 dollars in addition to the Fujitsu laptop. Linux was not successfully cracked in the specialist competition, which Hyppönen believes can indeed be seen as a sign of better overall operating-system security. “There is still some work to do,” Hyppönen says, however, in view of the two successful attacks.
More detailed information about the two vulnerabilities was initially not made public, but was instead handed over to TippingPoint’s Zero Day Initiative http://zdi.tippingpoint.com which first forwards the details to Apple and Adobe respectively. The security experts who succeeded in the competition have undertaken not to disclose further details about the vulnerabilities to the public until the vendors have completed the corresponding patches.