Site icon Liquidmatrix Security Digest

Apple Plugs Prize Winning 10K Hole

Somehow, that title sounds very wrong.

Ah well.

Glad to see that Apple has managed to get around to fixing the hole that made Charlie Miller a cool $10,000 (US) at CanSecWest in Vancouver a few weeks ago.

From Network World:

The bug lay in the way WebKit would process certain specially crafted JavaScript commands. In order to exploit the flaw, Miller had to first make the contest organizers visit a special Web site that contained his malicious JavaScript code.

There was one other winner in the CanSecWest PWN 2 OWN contest, which invited hackers to try to break into Windows, Mac and Linux computers. Shane Macaulay, a researcher with the Security Objectives consultancy, hacked into a Vista machine using an Adobe Flash Player bug, which was patched last week.

WebKit is also part of Apple’s Dashboard and Mail software. An Apple spokesman could not say whether users of those products were also at risk from this attack.

Read on.

Article Link

Exit mobile version