MacBook: Hacking context [UPDATE] Contest Won

Apr. 21st, 2007 00:30 by fbrunel@gmail.com

The contest "Hack a Mac" has started: anyone taking the control of the MacBook would win the prize: $10000.

The first day did not show any success in hacking the MacBook as the level of difficulty is really high: hackers are only allowed to use SSH. If noone can succeed, they will be allowed to use either of the following methods: Safari, then USB or bluetooth connection.

It is worth noting that the MacBooks are standard configuration, with all security update available applied.

[UPDATE 21 avril 2007]
As nobody won the contest in the previous day, a relaxed set of rules has been adopted.
Hence, the contest has been won by Dino Dai Zovi thanks to a Safari security flaw which is not fixed at the moment. By providing an URL that exposed Safari to a blank page, he did take the control of the MacBook by exploiting a vulnerability issue in the input handling routine.

