Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Hack My Mac, Please
Search Topic:
view: topics flat text 
Post a:

Comments on news posted 2006-03-08 13:11:00: Last week a Mac hacking competition made headlines after a hacker claims he got root on a Mac-mini in less than 30 minutes. ..

page: 1 · 2 · 3 · 4 · 5 · 6
AuthorAll Replies

wirelesswoes

join:2004-02-12
Hialeah, FL
With unix underneath the skin

Duh!


MarkyD
Premium
join:2002-08-20
Oklahoma City, OK
clubs:
I just love...

BBR's new spelling of "Mac" is fantastic. Now everyone is going to call it a "Mack."


Shamayim
I already have a Messiah.
Premium
join:2002-09-23
At least it's not MACK.


oliphant
I Have 8 Boobies
Premium
join:2004-11-26
Corona, CA
So these would me Macking competitions?

...sorry.


kamm

join:2001-02-14
Brooklyn, NY
·T-Mobile US

ROFL

You gotta love these news, huh? I can see as Macalots will arrive and claim "see, las one was exception" and such idiocies.
As long as Macs enjoy lower market share than statistical error margin, they can enjoy being fairly hacker-free, due mto the fact that very few people 'in the know' give a shit about such a rare platform.


kamm

join:2001-02-14
Brooklyn, NY
reply to Shamayim
Re: I just love...

said by Shamayim See Profile :

At least it's not MACK.
:D:D:D


pokesph
It Is Almost Fast
Premium
join:2001-06-25
Sacramento, CA
clubs:
·Comcast

reply to wirelesswoes
Re: With unix underneath the skin

the article said something about 4000+ ssh login attempts over the 38 hour test period... thats nothing new, one of our web facing server see 1500 - 4000 'attempts' a day routinely:

--------------------- pam_unix Begin ------------------------
sshd:
Invalid Users:
Unknown Account: 1739 Time(s)
Authentication Failures:
mail (222.40.20.164 ): 12 Time(s)
ftp (chlastna.kh-net.cz ): 7 Time(s)
news (chlastna.kh-net.cz ): 2 Time(s)
root (86.34.189.98 ): 4 Time(s)
apache (chlastna.kh-net.cz ): 7 Time(s)
unknown (chlastna.kh-net.cz ): 283 Time(s)
operator (222.40.20.164 ): 7 Time(s)
ftp (222.40.20.164 ): 6 Time(s)
mail (chlastna.kh-net.cz ): 2 Time(s)
mysql (chlastna.kh-net.cz ): 13 Time(s)
unknown (222.40.20.164 ): 1456 Time(s)
root (chlastna.kh-net.cz ): 92 Time(s)
root (222.40.20.164 ): 169 Time(s)
nobody (chlastna.kh-net.cz ): 3 Time(s)
games (chlastna.kh-net.cz ): 2 Time(s)
adm (chlastna.kh-net.cz ): 2 Time(s)

---------------------- pam_unix End -------------------------
and
 --------------------- pam_unix Begin ------------------------

sshd:
Invalid Users:
Unknown Account: 42987 Time(s)
Authentication Failures:
apache (130.70-85-94.reverse.theplanet.com ): 224 Time(s)
mysql (130.70-85-94.reverse.theplanet.com ): 67 Time(s)
root (130.70-85-94.reverse.theplanet.com ): 224 Time(s)
mail (130.70-85-94.reverse.theplanet.com ): 224 Time(s)
unknown (130.70-85-94.reverse.theplanet.com ): 42987 Time(s)
squid (130.70-85-94.reverse.theplanet.com ): 224 Time(s)
root (218.14.157.80 ): 43 Time(s)

---------------------- pam_unix End -------------------------

of couse none of those got in either..

--
Webmaster Steve
- - - - - - - - - - - -
»ppnhosting.com
»sphenterprizes.com
»pokemonpalace.net


Shamayim
I already have a Messiah.
Premium
join:2002-09-23

reply to kamm
Re: ROFL

I bet there are plenty who would like to be first for the bragging rights. It just ain't happening though
--
"tick...tick...tick..." »www.jtf.org/

iSEPIC

join:2001-04-17
Las Vegas, NV
Why did it go down early?

I am curious, this machine was supposed to stay up for a week. Why did they bring it down after only 38 hours, anyone know?


MxxCon

join:1999-11-19
Brooklyn, NY
clubs:
indeed. yesterday that page said it was going to run until Friday March 10th.
--
[Sig removed by Administrator: Signature can not exceed 20GB]

jrbianch

join:2005-10-20
Wylie, TX
They reached their 2GB/Month limit.


MxxCon

join:1999-11-19
Brooklyn, NY
clubs:

 This test doesn't show OSX is secure!

that machine had just 2 services open.
all this test showed was that during 36hours of testing, they were not aware of any break-ins using SSH or WWW.

BUT WHAT ABOUT ALL THE OTHER SERVICES?!

for all we know NFS or apple remote desktop or SMB or whatever could be full of holes!

if they want to say that OSX is secure, enable all default services, disable firewall and let people work at it for more than a day and a half.
--
[Sig removed by Administrator: Signature can not exceed 20GB]


volntn
The Volunteer
Premium
join:2002-01-05
Cleveland, TN
clubs:
This article says it all.

»www.macnn.com/articles/06/02/28/···r.winxp/


MxxCon

join:1999-11-19
Brooklyn, NY
clubs:

reply to pokesph
needless server load

said by pokesph See Profile :

the article said something about 4000+ ssh login attempts over the 38 hour test period... thats nothing new, one of our web facing server see 1500 - 4000 'attempts' a day routinely
of couse none of those got in either..
move ssh to any other port and those wild logins will drop to 0.:)
--
[Sig removed by Administrator: Signature can not exceed 20GB]

Shark_615

join:2006-01-17
Pickering, ON
Why

Something is not adding up here...

Why did he bin his "project" 3 days early if all was going well?

How is he supposed to remain creditable if he can't even stick to his proposal?


BellBoy
Obama racist? Then Bush is Hitler.
Premium
join:2001-02-20
Los Angeles, CA
clubs:
Humble Pie Anyone?

I guess it can be said to the Windows Mac-bashers that so quickly jumped on the "30-min" story: eat it.


Primis1

join:2005-06-13
Coldwater, MI

reply to Shark_615
Re: Why

quote:
Why did he bin his "project" 3 days early if all was going well? How is he supposed to remain creditable if he can't even stick to his proposal?
Bingo, that's what I've stated elsewhere here.

One of several things happened:

a) He started seeing something he didn't like and shut down the competition early before something could happen,

or b) Someone else told him to cut it short by 3 days, so he did.

Given the fact that he shut it down right around the time it began getting actual pub, it's suspicious. And it basically compromises any point he was trying to make by him not sticking to his own parameters.

If someone wants a valid point made with this, run a real test with static set parameters and give people a go at it. Until then, this guy's done nothing but waste everyone's time.

Primis1

join:2005-06-13
Coldwater, MI

reply to BellBoy
Re: Humble Pie Anyone?

Then why'd he close down the contest 3 days early, and only a day and a half in (only about 10 hours after it began getting real pub anywhere)?

The only point he proved is that he has no clue what he's doing, or that his confidence in his security was severely shaken by something so he bailed on it...


BuriedCaesar
It's Not Polite To Stare.

join:2004-03-27
Richardson, TX
·AT&T U-Verse
·AT&T Yahoo

reply to kamm
Re: ROFL

There you go again with a vague "market share" reference... so I'll say my piece again.

"Market share" is a specious phrase, easily thrown around without context or meaning, as you so deftly have demonstrated. In what context are you using "market share"? Do you mean actual, in-use machines? Machines that logged on to the internet today, or last week, or last month? Numbers of PCs sold over time? During a specific period in time? How about PCs in use that are tracked when they visit some company's website so they can make a buck selling that data to news outlets that then report that, erroneously, as "fact"?

And there are lots of ways to determine a statistical margin of error, but then that depends on the data set you're using (and usually a definition of the referencing term, such as your favorite phrase "market share").

This seems to me to be just a clever attempt to dismiss and deflect attention from what was presented by this second effort to refute the original, flawed "contest." Did you perhaps not RTFA?

And you say the Mac is a "rare platform"? Interesting notion. How did the original story garner such immediate attention if "nobody cares"? Why is this follow-up even being reported here, then? I suspect there are several millions of Mac users out there who would disagree with you about how "rare" this platform really is.

Clearly there are some high emotions tied up in this whole thing - I'm sure other comments in this thread will bear that out. And we both know this won't be going away any time soon. Soon enough there will be another attempt to show that Macs are just as vulnerable as their previously hapless PC cousins, or not - whether you care about it, or not.
--
That was preposterous! Utter Nonsense! Totally unsupportable drivel! You can't be serious!....Um, what did you say?

Shark_615

join:2006-01-17
Pickering, ON

reply to BellBoy
Re: Humble Pie Anyone?

Don't be daft.

First off the first Mac was hacked because of a security vulnerability.

Second although a local luser acct was needed such access could easily be gained through social engineering.

So the point still stands. OSX is vulnerable.
Forums » Hack My Mac, Pleasepage: 1 · 2 · 3 · 4 · 5 · 6


Wednesday, 02-Dec 01:22:12 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF