<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; charlie miller</title>
	<atom:link href="http://www.darknet.org.uk/tag/charlie-miller/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Apple Bans Security Researcher Charlie Miller For Exposing iOS Exploit</title>
		<link>http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/</link>
		<comments>http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 12:44:32 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple-security]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking ios]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[ios code signing]]></category>
		<category><![CDATA[ios exploit]]></category>
		<category><![CDATA[ios flaw]]></category>
		<category><![CDATA[ios security]]></category>
		<category><![CDATA[ios vulnerability]]></category>
		<category><![CDATA[security researcher]]></category>
		<category><![CDATA[white hat]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3223</guid>
		<description><![CDATA[The latest wave in the infosec world is that Apple has banned the well known security researcher &#8211; Charlie Miller &#8211; from it&#8217;s developer program for exposing a new iOS exploit. It&#8217;s not really the smartest move as I&#8217;m pretty sure anyone as smart as Charlie Miller still has plenty of options &#8211; use another [...]]]></description>
			<content:encoded><![CDATA[<p>The latest wave in the infosec world is that <a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> has banned the well known security researcher &#8211; <a href="http://www.darknet.org.uk/tag/charlie-miller/">Charlie Miller</a> &#8211; from it&#8217;s developer program for exposing a new iOS exploit.</p>
<p>It&#8217;s not really the smartest move as I&#8217;m pretty sure anyone as smart as Charlie Miller still has plenty of options &#8211; use another person&#8217;s account, sign up another account with a different identity, hack the phone without the developer program access and so on..</p>
<p>Really it&#8217;s quite a harsh move from Apple and it&#8217;s not going to make them any friends in the security industry.</p>
<blockquote><p>Apple has banned well-known security researcher Charlie Miller from its developer program, for creating an apparently benign iOS app that was actually designed to exploit a security flaw he had uncovered in the firmware.</p>
<p>Within hours of talking about the exploit with Forbes&#8217; security reporter Andy Greenberg, who published the details, Miller received an email from Apple: &#8220;This letter serves as notice of termination of the iOS Developer Program License Agreement &#8230; between you and Apple. Effective immediately.&#8221;</p>
<p>Based on Greenberg&#8217;s follow-up story, Apple was clearly within its rights to do so. Miller created a proof-of-concept application to demonstrate the security flaw and how it could be exploited by malicious code. He then hid it inside an apparently legitimate stock ticker program, an action that, according to Apple, &#8220;violated the developer agreement that forbid[s] him to &#8216;hide, misrepresent or obscure&#8217; any part of his app,&#8221; Greenberg wrote.</p>
<p>He quoted Miller, who works for security consultancy Acuvant, &#8220;I&#8217;m mad. I report bugs to them all the time. Being part of the developer program helps me do that. They&#8217;re hurting themselves, and making my life harder.&#8221; </p></blockquote>
<p>In a way though, you have to agree that Miller did violate the very specific developer program agreement by hiding the PoC inside a legitimate application. That probably wasn&#8217;t his smartest idea, but then again it&#8217;s helping Apple and he&#8217;s not doing it in a malicious way to infect people &#8211; he&#8217;s doing it as a security researcher.</p>
<p><a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> should be more proactive on working with people like this, people who are actually fixing bugs in their products for free and improving the user experience.</p>
<p>It&#8217;s the way Apple operates though, secretive, exclusive, domineering etc. If you don&#8217;t do things their way, screw you.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Miller, a former National Security Agency staffer, is a well-known &#8220;white hat&#8221; hacker (he made Network World&#8217;s recent list of &#8220;Security All Stars&#8221;), with expertise in Apple&#8217;s Mac OS X and iOS platforms, including the Safari browser, and in Android. Miller &#8220;has found and reported dozens of bugs to Apple in the last few years,&#8221; Greenberg noted. Miller reported the latest one barely three weeks ago, and it was Greenberg&#8217;s public account of it yesterday, in advance of a planned public presentation by Miller next week, that got the researcher kicked out of the developer program.</p>
<p>The vulnerability is a fascinating exercise in information security sleuthing. Miller uncovered a flaw introduced in Apple&#8217;s restrictions on code signing on iOS devices. Code signing is a process by which only Apple-approved commands run in device memory, according to Greenberg&#8217;s account.</p>
<p>Miller began to suspect a flaw when Apple released iOS 4.3 in March. He realized that to boost the speed of the mobile Safari browser, Apple for the first time had allowed javascript code from a website to run at a deeper level in memory. This entailed creating a security exception, allowing the browser to run unapproved code. According to Greenberg&#8217;s story, Apple created other security restrictions to block untrusted websites from exploiting this exception, so that only the browser could make use of it.</p>
<p>Miller wasn&#8217;t the only one to notice that Apple had done something different with Safari in iOS 4.3, but many didn&#8217;t understand what was actually happening. Various news sites and bloggers claimed that Web apps running outside of Safari, and its new Nitro javascript engine, were slower. Some suggested that Apple was deliberately slowing them down to make Web apps less attractive than native ones. </p></blockquote>
<p>The way in which Miller uncovered the flaw once again shows his technical brilliance &#8211; something which Apple really should be harnessing rather than turning away.</p>
<p>A lot of people noticed changes with iOS 4.3, but couldn&#8217;t actually figure out what was going on. Well that&#8217;s what we know in the public realm anyway, no doubt the bad guys had their eyes on it and were digging in with much more malicious exploits.</p>
<p>It basically seems like a way to bypass any kind of code validation by Apple and execute arbitrary code from an attack server &#8211; dangerous indeed.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/110811-miller-ios-bug-252886.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3223+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;t=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;title=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;title=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;title=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/&amp;title=Apple+Bans+Security+Researcher+Charlie+Miller+For+Exposing+iOS+Exploit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fapple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/apple-bans-security-researcher-charlie-miller-for-exposing-ios-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malicious PDF Files To Exploit iPhone &amp; iPad Zero Day In The Wild</title>
		<link>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/</link>
		<comments>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/#comments</comments>
		<pubDate>Mon, 11 Jul 2011 09:39:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[apple-security]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking ipad]]></category>
		<category><![CDATA[hacking iphone]]></category>
		<category><![CDATA[ipad hacking]]></category>
		<category><![CDATA[ipad jailbreak]]></category>
		<category><![CDATA[ipad2 jailbreak]]></category>
		<category><![CDATA[iphone jailbreak]]></category>
		<category><![CDATA[iphone pdf]]></category>
		<category><![CDATA[jailbreakme]]></category>
		<category><![CDATA[pdf jailbreak]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3144</guid>
		<description><![CDATA[Well everyone has been waiting for a Jailbreak for the iPad 2 with the latest version of iOS &#8211; it happened and only hours later the malformed PDF files that were used in the exploit were circulating the Internet. It&#8217;s not the first time this has happened, last time jailbreakme did the same thing back [...]]]></description>
			<content:encoded><![CDATA[<p>Well everyone has been waiting for a <a href="http://www.darknet.org.uk/tag/jailbreak/" title="Jailbreak">Jailbreak</a> for the iPad 2 with the latest version of iOS &#8211; it happened and only hours later the malformed PDF files that were used in the exploit were circulating the Internet.</p>
<p>It&#8217;s not the first time this has happened, last time <a href="http://www.darknet.org.uk/tag/jailbreakme/" title="jailbreakme">jailbreakme</a> did the same thing back in August 2010 &#8211; <a href="http://www.darknet.org.uk/2010/08/dangerous-iphone-ios-jailbreak-exploit-goes-public/" title="Dangerous iPhone iOS JailBreak Exploit Goes Public">Dangerous iPhone iOS JailBreak Exploit Goes Public</a>.</p>
<p>The exploit is quite a nasty one, and the irony is this time &#8211; only users that have applied the Jailbreak then the additional &#8216;PDF Patcher 2&#8242; software (from Cydia) are safe from this. Users running the vanilla version of iOS are actually at risk.</p>
<blockquote><p>Hours after developers revealed they had exploited bugs in Apple&#8217;s iOS to &#8220;jailbreak&#8221; iPhones and iPads, German government security authorities warned that one of the flaws could be put to malicious use.</p>
<p>Malformed files that exploit the vulnerability have been publicly posted on the Internet. Late Wednesday, Germany&#8217;s Federal Office for Information Security, known by its German-language initials of BSI for &#8220;Bundesamt fuer Sicherheit in der Informationstechnik,&#8221; warned citizens that the iOS bug could be used by criminals to hijack iPhones, iPads and iPod Touches.</p>
<p>&#8220;Even clicking a crafted PDF document or surfing to a website with the PDF documents are sufficient to infect the mobile device with malicious software,&#8221; the BSI said in a translation of the German-language alert .</p>
<p>PDF files that successfully exploit the vulnerability are available on the Web, according to Mikko Hypponen, chief research officer of Helsinki-based antivirus company F-Secure. And those PDFs could be used by miscreants to hack iOS devices simply by luring users to malicious sites, said Andrew Storms, director of security operations at nCircle Security.</p>
<p>iPhone and iPad users steered to a malicious PDF &#8212; via a link embedded in an email, for instance &#8212; would not receive any warning or be required to take additional action. </p></blockquote>
<p>I hope <a href="http://www.darknet.org.uk/category/apple-hacking/" title="Apple">Apple</a> gets their act together and pushes out the patch for this ASAP as I foresee some kind of iPhone/iPad targeted worm coming out of this fairly shortly.</p>
<p>It took them 10 days to patch a similar pair of exploits back in August 2010 so we should be expecting a patch by the end of this week (mid-July sometime).</p>
<p>The worrying part when it comes to business/agencies/government etc &#8211; is that these exploits could be used to target specific individuals of importance. All you need to know is the e-mail address they access on their iPhone/iPad and do a bit of <a href="http://www.darknet.org.uk/category/social-engineering/" title="Social Engineering">social engineering</a> and you&#8217;re in.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>The BSI warning came just hours after a group of developers released an updated version of JailbreakMe, a tool that hacks iOS so iPhone and iPad users can install software not sanctioned by Apple.</p>
<p>Those developers exploited a pair of vulnerabilities, including one in the font parsing of the PDF viewer integrated with the iOS version of Safari, and another that bypassed anti-malware defenses such as ASLR (address space layout randomization). Wednesday, security experts said that the same vulnerabilities, particularly the one exploitable through malicious PDF files, could be used by criminals to hijack Apple&#8217;s popular iPhone and iPad.</p>
<p>&#8220;They&#8217;re certainly a threat, and would be easy to make malicious,&#8221; said Charlie Miller, a noted Mac OS X and iOS vulnerability researcher who works for Denver-based Accuvant.</p>
<p>Miller also speculated that Apple would quickly patch the vulnerabilities, perhaps even faster than last year when it faced a similar situation. In August 2010, Apple patched a pair of bugs used by JailbreakMe 2.0 just 10 days after the tool&#8217;s release. News of JailbreakMe 3.0&#8242;s impending release had leaked several days before Wednesday&#8217;s official launch, noted Miller, and should have given Apple even more warning.</p>
<p>Yesterday&#8217;s BSI alert was similar to one it issued last August after JailbreakMe 2.0 appeared.On Thursday, Apple said it would fix the flaws.</p></blockquote>
<p>Of course the &#8216;developer&#8217; version of iOS 5.0 is already out and I guess someone people are using this, most iPhone/iPad users have been waiting for that major update &#8211; but I&#8217;m guessing Apple will have to push a patch out for this before the 5.x major release.</p>
<p>There&#8217;s another interesting and relevant article on this topic here:</p>
<p><a href="http://www.networkworld.com/news/2011/070811-the-problem-with-doing-and.html?source=nww_rss">The problem with doing &#8211; and not doing &#8211; an iPhone jailbreak</a></p>
<p>It&#8217;ll be interesting to see what comes of this and if any kind of iPhone/iPad chaos is going to occur due to these exploits.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/070711-pdfs-that-exploit-iphone-ipad.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3144+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;t=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Fmalicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Day One At Pwn2Own Takes Out Microsoft Internet Explorer and Apple Safari</title>
		<link>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/</link>
		<comments>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/#comments</comments>
		<pubDate>Thu, 10 Mar 2011 09:39:01 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[chaouki bekrar]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking macbook]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[internet explorer hack]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[return oriented programming]]></category>
		<category><![CDATA[safari]]></category>
		<category><![CDATA[safari-exploit]]></category>
		<category><![CDATA[safari-security]]></category>
		<category><![CDATA[use-after-free flaw]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3063</guid>
		<description><![CDATA[Well it&#8217;s March again and well we love March because it&#8217;s Pwn2Own time! Every year around this time we get some goodies to discuss way back since: 2008 &#8211; Mac owned on 2nd day of Pwn2Own hack contest 2009 &#8211; Charlie Miller Does It Again At PWN2OWN 2010 &#8211; Mozilla Beats Apple &#038; Microsoft to [...]]]></description>
			<content:encoded><![CDATA[<p>Well it&#8217;s March again and well we love March because it&#8217;s <a href="http://www.darknet.org.uk/tag/pwn2own/">Pwn2Own</a> time! Every year around this time we get some goodies to discuss way back since:</p>
<ul>
<li>2008 &#8211; <a href="http://www.darknet.org.uk/2008/03/mac-owned-on-2nd-day-of-pwn2own-hack-contest/">Mac owned on 2nd day of Pwn2Own hack contest</a></li>
<li>2009 &#8211; <a href="http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/">Charlie Miller Does It Again At PWN2OWN</a></li>
<li>2010 &#8211; <a href="http://www.darknet.org.uk/2010/04/mozilla-beats-apple-microsoft-to-pwn2own-patch-for-firefox/">Mozilla Beats Apple &#038; Microsoft to Pwn2Own Patch For Firefox</a></li>
</ul>
<p>It took Microsoft till June last year to fix the Pwn2Own bug &#8211; <a href="http://www.darknet.org.uk/2010/06/microsoft-patches-at-least-34-bugs-including-pwn2own-vulnerability/">Microsoft Patches At Least 34 Bugs Including Pwn2Own Vulnerability</a>.</p>
<p>This time both <a href="http://www.darknet.org.uk/tag/internet-explorer/">Internet Explorer</a> and <a href="http://www.darknet.org.uk/tag/safari/">Safari</a> fell on the first day! </p>
<blockquote><p>Contestants in a high-stakes hacking contest had no trouble toppling the Apple Safari and Microsoft Internet Explorer browsers, proving for a fifth year in a row that no software or application is safe from people with the expertise and motivation to exploit them.</p>
<p>The attacks came on Day One of the Pwn2Own contest, which pays more than $15,000 apiece for exploits that successfully give the attacker full remote access of the targeted machine. Wednesday&#8217;s event saw hackers take complete control of a fully patched Sony Vaio and MacBook Air by compromising IE and Safari respectively. Google&#8217;s Chrome browser was also up for grabs, but no one stepped forward to try hacking it.</p>
<p>“Every browser, every operating system, has its own vulnerabilities,” said Chaouki Bekrar, CEO of Vupen Security and the contestant who successfully hacked Safari. “This is what we wanted to demonstrate – that we can create a very reliable exploit for Apple Mac OS and Safari without even crashing the browser.”</p>
<p>Contest rules forbid him from disclosing most technical details behind the vulnerability, but he was permitted to say that it involved what&#8217;s known as a use-after-free flaw in the Apple browser. He said the exploit used a technique known as return-oriented programming to bypass a security protection known as data execution prevention that is built into many Apple programs.</p></blockquote>
<p>There have been a barrage of patches recently too with Microsoft patching some very serious bugs in the <a href="http://isc.sans.edu/diary.html?storyid=10510&#038;rss">March 2011 Black Tuesday</a>, <a href="http://www.networkworld.com/news/2011/030911-apple-patches-critical-mac-bugs.html?source=nww_rss">Apple patches critical Mac bugs with Java updates</a>, <a href="http://lists.apple.com/archives/security-announce/2011/Mar/msg00004.html">Apple patching 62 bugs in Safari</a> and Jon Oberheide killing his own <a href="http://www.darknet.org.uk/tag/internet-explorer/">Android</a> bug by <a href="http://www.theregister.co.uk/2011/03/07/android_pwn2own_bug_killed/">reporting it to Google</a>.</p>
<p>Also sadly one of the Pwn2Own champions <a href="http://www.darknet.org.uk/tag/geohot/">Geohot</a> wasn&#8217;t present most likely to to the <a href="http://www.darknet.org.uk/2011/01/happy-new-year-geohot-court-orders-seizure-of-ps3-hackers-computers/">shit storm Sony is throwing at him</a>.</p>
<p>It&#8217;ll be interesting to what else comes out of Pwn2Own this year.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>After building the tools from scratch, it took him about two weeks to find the bug and set out to exploit it. The result was an attack that reliably commandeers a Mac when Safari visits a website that hosts the malicious code.</p>
<p>“Just after visiting the webpage with the affected version of Safari, we can, for example, launch the calculator or open a shell or do anything else we want,” he said a minute or two after demonstrating the exploit at the contest, which was attended by members of Apple&#8217;s security team. “We have the same privileges as the user who visited the webpage.”</p>
<p>He said users would have no way of knowing their machines have been compromised. There is no prompt asking for a password. The only way to thwart the attack is to run Safari from an account that has been configured to have limited privileges.</p>
<p>Under competition rules, contestants drew a lottery to determine who was the first to attempt hacking a particular browser. Once a browser was compromised, it was eliminated from the running. Both IE and Safari were hacked on the first try.</p>
<p>“I have an exploit all ready to go, and now it&#8217;s just sitting in my bag,” said Charlie Miller, a three-time Pwn2Own winner, shortly after Bekrar took this year&#8217;s prize. “You&#8217;d think Apple would be concerned about it.”</p>
<p>Miller said he&#8217;s had the working attack for more than nine months now. Even after Apple patched a whopping 62 Safari security bugs just hours before the contest started, Miller&#8217;s exploit still worked, he said.</p></blockquote>
<p><a href="http://www.darknet.org.uk/tag/charlie-miller/">Charlie Miller</a> has a working exploit sitting in his back too after Bekrar already took the prize. It seems like it&#8217;s really quite worth developing a reliable, working 0-day exploit for $15,000!</p>
<p>The new sandbox in IE got pwned pretty easily too, which shows..slapping on some tonka toy security controls isn&#8217;t ever going to stop a dedicated attacker. There was one contestant who stepped up to the plate to take down <a href="http://www.darknet.org.uk/tag/chrome/">Google&#8217;s Chrome</a>, but perhaps the exploit didn&#8217;t work as there&#8217;s no reports on that.</p>
<p>Day two of Pwn2Own will see attacks on Smart-phone platforms &#8211; Windows 7 Mobile, an iPhone 4, a BlackBerry Torch 9800, and a Nexus S running Google&#8217;s Android. There are multiple contestants signed up for each platform!</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/03/10/apple_safari_ie_stomped/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3063+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;t=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fday-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Adobe Scrambling To Fix Another Serious PDF Flaw</title>
		<link>http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/</link>
		<comments>http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/#comments</comments>
		<pubDate>Mon, 09 Aug 2010 09:07:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[adobe pdf 0-day]]></category>
		<category><![CDATA[adobe pdf exploit]]></category>
		<category><![CDATA[adobe pdf security]]></category>
		<category><![CDATA[adobe pdf zero day]]></category>
		<category><![CDATA[application-security]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[CoolType.dll]]></category>
		<category><![CDATA[foxit]]></category>
		<category><![CDATA[foxit pdf reader]]></category>
		<category><![CDATA[hacking pdf]]></category>
		<category><![CDATA[integer overflow]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[pdf exploit]]></category>
		<category><![CDATA[pdf hacking]]></category>
		<category><![CDATA[pdf integer overflow]]></category>
		<category><![CDATA[pdf security]]></category>
		<category><![CDATA[pdf vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2928</guid>
		<description><![CDATA[It was only the start of July when we talked about Adobe Patching PDF Vulnerabilities Being Exploited In The Wild and once again they are suffering a serious vulnerability which allows code execution from a malicious PDF document. This time the vulnerability came out during Black Hat and it seems to be serious as Adobe [...]]]></description>
			<content:encoded><![CDATA[<p>It was only the start of July when we talked about <a href="http://www.darknet.org.uk/2010/07/adobe-patches-pdf-vulnerabilities-being-exploited-in-the-wild/">Adobe Patching PDF Vulnerabilities Being Exploited In The Wild</a> and once again they are suffering a serious vulnerability which allows code execution from a malicious PDF document.</p>
<p>This time the vulnerability came out during Black Hat and it seems to be serious as <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> are rushing out a patch for the issue.</p>
<p>This issue effects Adobe Reader client for Windows, Mac and UNIX based systems. This follows shortly after <a href="http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/">Microsoft pushed out an emergency patch for the .LNK exploit</a>.</p>
<blockquote><p>Adobe is rushing to develop a patch for a vulnerability in Acrobat Reader revealed at the Black Hat security conference. The update&#8211;expected the week of August 16&#8211;will be the third time this year that Adobe has been forced to fix flaws outside of its regularly scheduled quarterly update pattern.</p>
<p>Adobe published a security bulletin announcing the upcoming update for Adobe Reader 9.3.3 for Windows, Mac OS X, and UNIX, and Adobe Acrobat for Windows and Mac, as well as Reader and Acrobat version 8.2.3 for the same platforms to resolve a number of security issues. Adobe noted &#8220;that these updates represent an out-of-band release. Adobe is currently scheduled to release the next quarterly security update for Adobe Reader and Acrobat on October 12, 2010.&#8221;</p>
<p>Microsoft also released an out-of-band patch for the Windows shortcut vulnerability&#8211;only a week ahead of the planned Patch Tuesday updates. The rapid turnaround by Adobe from vulnerability discovery to patch is commendable, but the rise in zero-day exploits forcing both Adobe and Microsoft to frequently provide updates outside of the normal patch release cycle threatens to negate the benefits of having a regularly scheduled patch release system.</p>
<p>The issue being addressed by Adobe is a vulnerability in Adobe Reader which was unveiled at Black Hat by security researcher Charlie Miller. Miller has made a name for himself by repeatedly winning the Pwn2Own contest at the CanSec West security conference. </p></blockquote>
<p><a href="http://www.darknet.org.uk/tag/charlie-miller/">Charlie Miller</a> has rocked it out before at Pwn2Own (more than once) and it was him who unveiled this vulnerability at Black Hat in recent weeks. Adobe have been criticized in the past for not being pro-active enough in their security efforts and coming out with classics like &#8220;Wait until year end for security patches&#8221;. This is also mentioned in another Network World article published at the same time <a href="http://www.networkworld.com/news/2010/080710-adobe-should-be-more-proactive.html?source=nww_rss">here</a>.</p>
<p>At least they are jumping to attention this time and doing something about it. And don&#8217;t be fooled, this is a serious exploit that can lead to arbitrary code execution when a vulnerable user views a maliciously crafted <a href="http://www.darknet.org.uk/tag/pdf/">PDF</a> file containing this exploit.</p>
<blockquote><p>A Secunia advisory related to the Adobe flaw explains &#8220;The vulnerability is caused due to an integer overflow error in CoolType.dll when parsing the &#8220;maxCompositePoints&#8221; field value in the &#8220;maxp&#8221; (Maximum Profile) table of a TrueType font. This can be exploited to corrupt memory via a PDF file containing a specially crafted TrueType font.&#8221;</p>
<p>Summed up in plain English that IT admins and users who are not developers can understand, Secunia adds &#8220;Successful exploitation may allow execution of arbitrary code.&#8221; Bottom line: an attacker could exploit the Adobe Reader flaw to take control of a vulnerable system and install or execute other malicious software.</p>
<p>Interestingly, it is a flaw in the way fonts are rendered in PDF documents that allows the JailbreakMe Web site to circumvent iPhone defenses and alter the core functionality of the smartphone OS. However, according to Miller the flaws are unrelated to one another. Thankfully, Apple is hard at work updating iOS to address that issue. </p></blockquote>
<p>As mentioned in the last paragraph the web based <a href="http://www.darknet.org.uk/tag/jailbreak/">jailbreak</a> for Apples latest iOS is also using a PDF flaw as the base exploit to run the jailbreak.</p>
<p>It seems like PDF is breaking in all kinds of different ways, perhaps time to look for a format? Or at least use other PDF readers as we&#8217;ve suggested before with <a href="http://www.foxitsoftware.com/pdf/reader/">Foxit!</a> Although it has a share of vulnerabilities too they are far fewer and less serious than those in Adobe software. Another option suggestion is <a href="http://www.nuance.com/imaging/products/pdf-reader.asp">Nuance PDF Reader</a>.</p>
<p>Source: <a href="http://www.networkworld.com/news/2010/080610-adobe-scrambles-to-fix-pdf.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Adobe+Scrambling+To+Fix+Another+Serious+PDF+Flaw+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2928+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/&amp;t=Adobe+Scrambling+To+Fix+Another+Serious+PDF+Flaw" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/&amp;title=Adobe+Scrambling+To+Fix+Another+Serious+PDF+Flaw" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/&amp;title=Adobe+Scrambling+To+Fix+Another+Serious+PDF+Flaw" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/&amp;title=Adobe+Scrambling+To+Fix+Another+Serious+PDF+Flaw" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/&amp;title=Adobe+Scrambling+To+Fix+Another+Serious+PDF+Flaw" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F08%2Fadobe-scrambling-to-fix-another-serious-pdf-flaw%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Charlie Miller Does It Again At PWN2OWN</title>
		<link>http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/</link>
		<comments>http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 08:07:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[hacking macs]]></category>
		<category><![CDATA[hacking safari]]></category>
		<category><![CDATA[hacking-competition]]></category>
		<category><![CDATA[hacking-contest]]></category>
		<category><![CDATA[mac exploit]]></category>
		<category><![CDATA[mac-security]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[safari-exploit]]></category>
		<category><![CDATA[tipping point]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1632</guid>
		<description><![CDATA[You right remember in March last year we posted about Charlie Miller at the PWN2OWN contest owning the MacBook Air in under 2 minutes. Guess what? He&#8217;s done it again! This time though he&#8217;s even faster clocking in at under 10 seconds. No one else stood a chance. He walked off with the prize again, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>You right remember in March last year we posted about <a href="http://www.darknet.org.uk/2008/03/mac-owned-on-2nd-day-of-pwn2own-hack-contest/">Charlie Miller at the PWN2OWN contest owning the MacBook Air in under 2 minutes</a>.</p>
<p>Guess what? He&#8217;s done it again! This time though he&#8217;s even faster clocking in at under 10 seconds. No one else stood a chance. He walked off with the prize again, $5000 and the MacBook that he hacked.</p>
<p>Of course he wrote the exploit before hand, but still impressive!</p>
<blockquote><p>Charlie Miller, a security researcher who hacked a Macintosh in two minutes last year at CanSecWest&#8217;s PWN2OWN contest, improved his time today by breaking into another Macintosh in under 10 seconds.</p>
<p>Miller, an analyst at Independent Security Evaluators in Baltimore, walked off with a $5,000 cash prize and the MacBook he hacked.</p>
<p>&#8220;I can&#8217;t talk about the details of the vulnerability, but it was a Mac, fully patched, with Safari, fully patched,&#8221; said Miller on Wednesday, not long after he had won the prize. &#8220;It probably took five or 10 seconds.&#8221; He confirmed that he had researched and written the exploit before he arrived at the challenge.</p></blockquote>
<p>It guess it might be a Safari exploit, but I guess if you keep your ears open you&#8217;ll hear about it soon enough.</p>
<p>I wonder if he&#8217;ll be able to pull the same trick again next year, with his record so far I&#8217;d say it wouldn&#8217;t be a large stretch of imagination.</p>
<blockquote><p>The PWN2OWN rules stated that the researcher could provide a URL that hosted his exploit, replicating the common hacker tactic of enticing users to malicious sites where they are infected with malware. &#8220;I gave them the link, they clicked on it, and that was it,&#8221; said Miller. &#8220;I did a few things to show that I had full control of the Mac.&#8221;</p>
<p>Two weeks ago, Miller predicted that Safari running on the Macintosh would be the first to fall.</p>
<p>PWN2OWN&#8217;s sponsor, 3Com Corp.&#8217;s TippingPoint unit, paid Miller $5,000 for the rights to the vulnerability he exploited and the exploit code he used. As it has at past challenges, it reported the vulnerability to on-site Apple representatives. &#8220;Apple has it, and they&#8217;re working on it,&#8221; added Miller.</p></blockquote>
<p>Interestingly another researcher later broke into a Sony laptop that was running Windows 7 by exploiting a vulnerability in Internet Explorer 8. So Safari and IE8 both fell! </p>
<p>What with all the claims from Microsoft that IE8 is so secure&#8230;I guess that pissed on their bonfire didn&#8217;t it?</p>
<p>This year&#8217;s PWN2OWN also has a section for mobile operating systems, the prize is larger too at $10,000. If you want to join you can have a crack at Windows Mobile, Google&#8217;s Android, Symbian, and the operating systems used by the iPhone and BlackBerry.</p>
<p></p>
<p>Source: <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9129978">Computer World</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Charlie+Miller+Does+It+Again+At+PWN2OWN+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1632+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/&amp;t=Charlie+Miller+Does+It+Again+At+PWN2OWN" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/&amp;title=Charlie+Miller+Does+It+Again+At+PWN2OWN" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/&amp;title=Charlie+Miller+Does+It+Again+At+PWN2OWN" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/&amp;title=Charlie+Miller+Does+It+Again+At+PWN2OWN" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/&amp;title=Charlie+Miller+Does+It+Again+At+PWN2OWN" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F03%2Fcharlie-miller-does-it-again-at-pwn2own%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

