Challenge Mac Uncracked and Unhacked after 38 Hours--Challenge Axed by U. Wisconsin's CIO

Dave Schroeder ended the "Hack My Mac" challenge Wednesday morning after safely running for 38 hours since Monday morning. We previously reported that his Mac mini running Mac OS X 10.4.5 with Security Update 2006-001 was hosted at the University of Wisconsin on the internet with the http port open to display the challenge's web page and the ssh port open to provide a route of access. While it drew a lot of attacks, the Mac mini was still unhacked as of early Wednesday morning and no one had claimed to have gotten into it.

Mr. Schroeder posted several notes about the attacks which included several Denial of Service attacks and social engineering attacks. However, in the afternoon, the challenge page had been taken down and replaced with the following notice:

Yesterday we discovered the Mac OSX "challenge" was not an activity authorized by the UW-Madison. Once the test came to the attention of our CIO, she ended it. The site, test.doit.wisc.edu, will be removed from the network tonight. Our primary concern is for security and network access for UW services. We are sorry for any inconvenience this has caused to the community.

It appears that the broad publicity given Dave Schroeder's challenge undertaken in response to the misleading challenge described originally in this ZDNet article carried on CNet, attracted the attention of the UW CIO or there were complaints about it. In any case, the 38-hour challenge proved the point. The Mac mini running Mac OS X 10.4.5 is certainly not "easy pickings" as claimed by the hacker in the misleading challenge described in ZDNet. People using a Mac running Mac OS X 10.4.5 are perfectly safe from external attacks coming through the internet.

However, the concern remains for an "inside job" using the privilege escalation vulnerability reported by the ZDNet article. If the reported challenge is not bogus, 30 minutes to get root control from a regular user account is a real problem, one that needs to be fixed to minimize social engineering attacks like trojan horses or damage from "legal" users on a network. [Bill Fox]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive