IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Public Teleconferences
Join CIO Executive Council members and participate in the following live teleconferences:

* Planning for Succession:
Models for IT Leadership Development, June 23
* Change Leadership at General Growth Properties: A
Pathways Leadership Development Seminar, June 25
* Managing Change: Centralizing Your IT Organization
July 29

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 

News

 

With Vista Breached, Linux Unbeaten in Hacking Contest

 

March 29, 2008 — IDG News Service —

The MacBook Air went first; a tiny Fujitsu laptop running Vista was hacked on the last day of the contest; but it was Linux, running on a Sony Vaio, that remained undefeated as conference organizers ended a three-way computer hacking challenge Friday at the CanSecWest conference.

MacBook Air Hacked in Two Minutes at CanSecWest

Earlier this week, contest sponsors had put three laptops up for grabs to anyone who could hack into one of the systems and run their own software. A US$20,000 cash prize sweetened the deal, but the payout was halved each day as contest rules were relaxed and it became easier to penetrate the computers.

On day two, Independent Security Evaluators' Charlie Miller took the Mac after hitting it with a still-undisclosed exploit that targeted the Safari Web browser. After about two minutes work, Thursday, Miller took home $10,000, courtesy of 3Com's TippingPoint division, in addition to his new laptop.

It took two days of work, but Shane Macaulay, finally cracked the Vista box on Friday, with a little help from his friends.

Macaulay, who was a co-winner of last year's hacking contest, needed a few hacking tricks courtesy of VMware researcher Alexander Sotirov to make his bug work. That's because Macaulay hadn't been expecting to attack the Service Pack 1 version of Vista, which comes with additional security measures. He also got a little help from co-worker Derek Callaway.

Under contest rules, Macaulay and Miller aren't allowed to divulge specific details about their bugs until they are patched, but Macaulay said the flaw that he exploited was a cross-platform bug that took advantage of Java to circumvent Vista's security.

"The flaw is in something else, but the inherent nature of Java allowed us to get around the protections that Microsoft had in place," he said in an interview shortly after he claimed his prize Friday. "This could affect Linux or Mac OS X."

Macaulay said he chose to work on Vista because he had done contract work for Microsoft in the past and was more familiar with its products.

Although several attendees tried to crack the Linux box, nobody could pull it off, said Terri Forslof, a manager of security response with TippingPoint. "I was surprised that it didn't go," she said.

Some of the show's 400 attendees had found bugs in the Linux operating system, she said, but many of them didn't want to put the work into developing the exploit code that would be required to win the contest.

 
 
 
 
 
 
Loading...
 
 
ABCs
 

How To Do Nearly Anything

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

White Paper: How Visualization Can Fix Business Software Problems

Oxford International Modernizes Vehicle Order Management System

Create and Run Any Application On-Demand

A New Generation of Software as-a-Service (SaaS) Solutions

Master Data Management: The Approach Determines the Results

Enhancing Online Sales and Support

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

Wireless Wars - Exchange Hosting is the Neutral Zone

webMethods Business Process Management Suite

Key challenges facing today's IT service and support

Heinz Uses a Wireless, Automated, Auditing process on BlackBerry® devices

BPM Done Right: 15 Ways to Succeed Where Others have Failed

Tuning ERP and the Supply Chain for Profitable Growth

Taking Control of Software Licensing

Simple, Economical Server Virtualization for Any Size Company

White Paper: HP Application Modernization Services

Establishing a Strategy for Global Distributed Development

Write an RFP for Master Data Management: 10 Common Mistakes to Avoid

Building Compliance and Security into an Application Delivery Framework

Witness Oracle's Commitment to On Demand Customers

Making Adaptive Networks a Reality

Cost-Effective Data Center 1U Server Solutions

Automate Business Processes - Try a Free Mashup Composer

Read Forrester's advice for deploying an enterprise mobile solution

Do the math-calculate the impact of mobile device deployment on your bottom line

Webcast: Transformation of Application Development

Run Desktop and CRM Applications Side by Side with Salesforce & Google

User Interface as a Service - Visual Force

The Combined Power of Salesforce and Google Apps

Implementing Knowledge Management

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

Renowned Engineering Institution Chooses AMD Processor-Based Servers

Worst Practices in Business Intelligence

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

BlackBerry Solution Increases Customer Service For Corporate Real Estate Company

White Paper: Learn how to succeed with BPM

Citrix XenServer FREE trial

Mitigating Risk with Security Assessments

White Paper: IDC Analysts Discuss Open Text

BPM At The Crossroads Webcast" Tackling the "Hard Issues" to Drive Success

Top 10 Questions to Ask when Choosing a Secure File Transfer Solution

LIVE Webcast - The Mainframe is Dead...Long Live the Mainframe?

Putting Windows Server and Citrix to Work in the Enterprise

Consider the ROI of Unified Communications for your contact center

EVALUATING THE BUSINESS IMPACT OF ORACLE ON DEMAND

Network Immunity Manager Video

Microsoft System Center - Designed For Big

Choose a mobile device platform with familiar programs and simplified management

Improve device management - Microsoft® System Center Mobile Device Manager

Explore the interactive whitepaper: Rightsizing Blades for the mid-market