dotlinklogo_hover

MBP Hacked, Safari exploit.

Its been confirmed on electronista that a MacBook Pro was successfully hacked at a competition, when the rules were loosened to allow participants to attack the computer via code sent through malicious websites, instead of directly attacking the computer. Winners were able to gain user level shell access, via an exploit in Safari.

My personal risk assessment is that there really isn't much to worry about, as of now the flaw is a 0day hack, but I expect Apple will be on top of it soon enough. The hack isn't in the wild, its proof of concept. I'm going to continue using Safari, especially since that in order to exploit this hole, you have to navigate to a specific website containing malicious code, one that, isn't actually online as of now. ( Ill try and keep the blog updated pertaining to this ).

If you want to play it safe and it might just be wise, depending on the nature of your security requirements, just hold off using Safari for a day or two till Apple release a patch. Instead, use Camino or Firefox.

Happy Mac'ing!

Labels:

0 Comments. | By Skippy, Sunday, April 22, 2007 5:56 PM | Links to this post

Leave a Reply.