Hacker Super Bowl Pits Mac OS Vs. Linux, Vista

By Robert McMillan

Thu, March 27, 2008 — IDG News Service —

It's the most anticipated matchup in the hacker world: Linux versus Mac OS X versus Vista. Who will get hacked first?

That's what organizers of the CanSecWest security conference hope to discover this week as they give show attendees a shot at hacking into the three laptops they've put on display here in Vancouver.

The catch? They have to use a brand-new 'zero day' attack that nobody has seen before. The prize? US$20,000, plus you get to keep the laptop.

Show organizers are calling the contest PWN 2 OWN. Pwn (which rhymes with own) is a hacker term meaning to take control of a computer.

$20,000 may sound like a lot of money, but show attendees say that top-quality computer attack code could easily fetch that much, either from the security vendors like iDefense or Tipping Point who purchase this type of software, or from one of the three-letter U.S. government agencies said to be in the market for this type of code as well.

Charlie Miller, best known as one of the Independent Security Evaluators researchers who first hacked the iPhone last year, said he's participating, not for the cash prize, but for the thrill of seeing whether or not he can be first to hack one of the computers. "For me it's the Super Bowl of security research," he said. "I'm a competitive guy."

By late Wednesday -- the first day of the contest, nobody had even tried to hack the three laptops. This wasn't exactly a surprise to the contest's organizers because on day one attackers were only allowed to use network-based attacks that involved no user interaction. Those type of attacks are extremely rare these days.

Miller said that he will drop his exploit code on the MacBook Air Thursday, once the rules relax a bit and the hackers are allowed to try attacks that require user action such as visiting a malicious Web site or opening an e-mail.

There is a downside to waiting until Thursday, however. The prize money drops in half each day. If no one has claimed the laptops by Friday, the prize bottoms out at $5,000 and organizers will start installing non-standard software on the machines to see if they can be compromised through programs such as Skype.

Last year's contest generated a lot of attention, but it featured only one laptop: a MacBook Pro. It was won by researcher Dino Dai Zovi, who wasn't at the conference, but asked a friend to run his attack on the machine. Dai Zovi showed up in person at CanSecWest this year, however, making him another prime candidate to win the prize.


Loading...
Applications MarketSpace
Service Level Reporting and Communication
Service level reporting is the most visible output and often the most time-consuming activity in SLM. Learn more »
Lower IT Costs with Oracle Database 11g Release 2
Learn how upgrading to Oracle Database 11g Release 2 can transform your business, budgets, and service levels Learn more »
Managing Your SAP System
Learn how to more effectively manage your SAP system. Learn more »
 
SPONSORED LINKS
 

White Paper: 4 Customer Service Myths

White Paper: Improve Agility with Operational Responsiveness

Removing the Barriers to IT Governance: How On-Demand Software Changes the Game

Cloud Computing--Latest Buzzword or a Glimpse of the Future?

A Balanced Approach to an Application Development Platform

Adobe® LiveCycle®solutions for intuitive user experience

10 Ways Excel Drives More Value from Your SAP Investment

What's New in SOA Suite 11g?

Unleash the Power of Java with Oracle JRockit Real Time

SOA Best Practices and Design Patterns

Application Grid: Ideal Platform for IT Consolidation

Ready to virtualize tier one applications? Check your virtualization maturity.

Learn how to provide complete Business Service Management.

Increase ROI of Your Application Portfolio

See how AT&T can help protect your network.

Top Five CIO Challenges

Streamline IT Costs. Boost Performance with WAN Optimization.

Want to know how you can maximize employee productivity?

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A new fleet of PCs with a total ROI in 10 months. Find your ROI.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

White Paper: Managed Security for a Not-So-Secure World

SharePoint - Unchecked growth of content is unsustainable.

Focus Under Pressure: Why IT Governance Becomes Mission-Critical in a Down Economy

Should Your Email Live In The Cloud? A Comparative Cost Analysis

Adobe® LiveCycle® solutions for business process automation

Architecting Business Intelligence Applications for Change: The Open Solution

Increase UPS efficiency without sacrificing protection.

Unlocking the Mainframe: Modernizing Legacy System to SOA

State of the Data Integration Market

Enhance Customer Loyalty through Higher Responsiveness

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Four steps to populate your CMDB.

"Enterprise-Proven" is the Prerequisite for Enterprise SaaS Portal Solutions

Join us at the US-Brazil IT-BPO Summit, on November 10th in New York.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion

Read the RSA report: Security for Business Innovation

Webcast: Looking to the Cloud for Email and Collaboration Services

64-page prescriptive guide to security, compliance, and IT operations.

Keep your IT expertise up to date. Join the Intel Premier IT Professionals.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

Interactive Q&A helps you discover key ways to maximize IT assets.

 
 
RESOURCE CENTER