LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > LinuxQuestions.org > Linux - News
User Name
Password
Linux - News This forum is for original Linux News. If you'd like to write content for LQ, feel free to contact us.
All threads in the forum need to be approved before they will appear.

Notices

Reply
 
LinkBack Search this Thread
Old 03-29-2008, 08:45 AM   #1
DragonSlayer48DX
Registered User
 
Registered: Dec 2006
Posts: 1,454
Blog Entries: 1

Rep: Reputation: 74
Cool Vista, MacBook Out--Only Linux Left in Hacking Contest


The MacBook Air went first; a tiny Fujitsu laptop running Vista was hacked on the last day of the contest; but it was Linux, running on a Sony Vaio, that remained undefeated as conference organizers ended a three-way computer hacking challenge Friday at the CanSecWest conference.

Read story.
 
Old 03-29-2008, 10:31 AM   #2
Simon Bridge
Guru
 
Registered: Oct 2003
Location: Waiheke NZ
Distribution: Ubuntu 10.04
Posts: 9,196

Rep: Reputation: 190Reputation: 190
This comment is a tad disingenious:
Quote:
Some of the show's 400 attendees had found bugs in the Linux operating system, she said, but many of them didn't want to put the work into developing the exploit code that would be required to win the contest.
The mac went via safari, and vista via java.
We really need to know more about how the boxes are set up.
http://www.pcworld.com/article/id,14...1/article.html
Quote:
Nobody was able to hack into the systems on the first day of the contest when contestants were only allowed to attack the computers over the network, but on Thursday the rules were relaxed so that attackers could direct contest organizers using the computers to do things like visit Web sites or open e-mail messages.
... thus, it's amazing the linux box wasn't hacked. Maybe nobody wanted it?

http://www.pcworld.com/article/id,14...1/article.html
... bin more detail. Not so much "nobody was able to " on day one, and more "nobody even tried".

Last edited by Simon Bridge; 03-29-2008 at 10:41 AM.
 
Old 03-29-2008, 11:31 AM   #3
mickeyboa
Senior Member
 
Registered: May 2004
Location: Indianapolis, Indiana
Distribution: FC-KDE, 32 and 64 bit
Posts: 1,321

Rep: Reputation: 55
Come on Simon Bridge, now your trying to be a wise A__, heh heh!!
 
Old 03-29-2008, 11:33 AM   #4
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Lubuntu
Posts: 19,068
Blog Entries: 4

Rep: Reputation: 385Reputation: 385Reputation: 385Reputation: 385
Day one only allowed remote attacks over the network. As in, they would have had to pretty much brute force their way in. The systems only started to fall when the contest organisers were told to visit websites, probably why the Apple went first as there was a vulnerability only patched a few days ago.

It's a real world test - as far as that's possible in a contest. In reality, a cracer would be more likely to set up a website to have people give them info than spend time crafting a remote exploit which may get patched as they're writing the crack.
 
Old 03-29-2008, 12:33 PM   #5
DragonSlayer48DX
Registered User
 
Registered: Dec 2006
Posts: 1,454
Blog Entries: 1

Original Poster
Rep: Reputation: 74
Quote:
Originally Posted by XavierP View Post
The systems only started to fall when the contest organisers were told to visit websites, probably why the Apple went first as there was a vulnerability only patched a few days ago.
Maybe, but then again~

Quote:
The catch? They have to use a brand-new 'zero day' attack that nobody has seen before.
http://www.pcworld.com/article/id,14...1/article.html

What I assumed from this and other articles is that they had to find their own bugs in the OSes, then write the exploits.

Cheers
 
Old 03-29-2008, 12:57 PM   #6
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Lubuntu
Posts: 19,068
Blog Entries: 4

Rep: Reputation: 385Reputation: 385Reputation: 385Reputation: 385
Good point. I guess it's hard to craft a new exploit remotely if you can't get into the system!
 
Old 03-29-2008, 06:13 PM   #7
Simon Bridge
Guru
 
Registered: Oct 2003
Location: Waiheke NZ
Distribution: Ubuntu 10.04
Posts: 9,196

Rep: Reputation: 190Reputation: 190
The systems were supposed to be default installs, a flaw in any installed package was counted as a flaw in the OS. Another surprise for the linux end with all it's extra packages.

However, one could craft an exploit by having another default install handy. The trick is, it had to be new, so you also needed to know which exploits had been tried already.

Whatever, I did post the links off to BADVista.
 
Old 03-29-2008, 10:45 PM   #8
DragonSlayer48DX
Registered User
 
Registered: Dec 2006
Posts: 1,454
Blog Entries: 1

Original Poster
Rep: Reputation: 74
Quote:
Originally Posted by Simon Bridge View Post
The systems were supposed to be default installs...
Exactly, and the Vista hacker assumed that to mean 'original version', when in fact, he was given sp1 with new security enhancements. That's why it took so long to break it, but he still managed to do so.

Quote:
a flaw in any installed package was counted as a flaw in the OS. Another surprise for the linux end with all it's extra packages.
Why is that such a surprise? From your own previous post~

Quote:
This comment is a tad disingenious:
Quote:
Some of the show's 400 attendees had found bugs in the Linux operating system, she said, but many of them didn't want to put the work into developing the exploit code that would be required to win the contest.
I researched Linux for a long time before I decided to switch, and the one aspect that kept popping up is that it can be hacked, but it's not worth the effort. In other words, it takes too much work for so little gain, considering you can't really do much once you're in. (Unless the logged-in user is running as root). I thought that was intentionally incorporated into the design of the system. Am I wrong?

Quote:
Whatever, I did post the links off to BADVista.
Now, that's worth reading!

Cheers

Last edited by DragonSlayer48DX; 03-29-2008 at 10:46 PM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
This Linux vs Vista vs Leopard contest LinuxNoob75 General 3 02-11-2008 10:52 PM
LXer: Vista, Leopard, Linux to compete in hack contest LXer Syndicated Linux News 0 02-11-2008 07:00 AM
Linux on a macbook/macbook pro... any experiences/problems, or is it even necessary? enigma_0Z Linux - Laptop and Netbook 13 09-14-2007 10:29 PM
Netcat in the Hat - Hacking Contest ddonzal Linux - News 0 09-06-2006 11:49 PM
Hari's Little Contest#1: Linux Troll Essay Contest vharishankar General 32 07-01-2006 12:52 AM


All times are GMT -5. The time now is 05:10 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration