Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Apple's in the eye of flaw finders
Robert Lemos, SecurityFocus 2006-02-07

At the recent ShmooCon hacking conference, one security researcher found out the hard way that such venues can be hostile, when an unknown hacker took control of the researcher's computer, disabling the firewall and starting up a file server.

Comments Mode:
Apple's in the eye of flaw finders 2006-02-07
Anonymous (1 replies)
Apple's in the eye of flaw finders 2006-02-08
Anonymous (1 replies)
Apple's in the eye of flaw finders 2006-02-08
Anonymous (1 replies)
Apple's in the eye of flaw finders 2006-02-08
Alexey Vesnin
Apple's in the eye of flaw finders 2006-02-08
Anonymous (1 replies)
Apple's in the eye of flaw finders 2006-02-08
Anonymous (1 replies)
Don't be foolish 2006-02-08
Anonymous (2 replies)
Re: Don't be foolish 2006-02-08
Anonymous
Re: Don't be foolish 2006-02-08
Anonymous
I had no problems at Shmoocon 2006-02-08
Anonymous (2 replies)
Re: I had no problems at Shmoocon 2006-02-08
Anonymous (3 replies)
Re: Re: I had no problems at Shmoocon 2006-02-08
Anonymous
I think the point is that the story in the *article* is anecdotal. There's no details, no names, no description. While it's certainly necessary to discuss security problems in a scientific manner, the article above doesn't, and smells of a hidden agenda. That's why it's important to disclose full details of an attack (to show its repeatability) if you're going to discuss it publicly at all: otherwise it's very easy to discount your disclosure as FUD, anti-marketing, or attention-seeking. This article does none of that. For all we know, the "Security Researcher" in question works for SCO, or is an 18-year-old with a badge that reads "Security Researcher", or left his laptop on a table while he/she went ot get coffee. Publish the details and then we can all judge independently whether the computer was hardened or not.

And a tip: using the phrase "It's time you asked mummy to get you a new box of crayons" does nothing to further the belief that you should be included amongst "us grown-ups here".

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11375/33089#33089
move along 2006-02-09
Anonymous
Re: I had no problems at Shmoocon 2006-02-08
Anonymous (2 replies)
Re: Re: I had no problems at Shmoocon 2006-02-10
R_U_Trustified?
Apple's in the eye of flaw finders 2006-02-08
Mike Andrews (1 replies)
Apple's in the eye of flaw finders 2006-02-08
Anonymous (2 replies)
do we want security through obscurity? 2006-02-08
assurbanipal (1 replies)
Apple's in the eye of flaw finders 2006-02-08
Scott Barman (www.barman.ws) (2 replies)
Hired Gun 2006-02-08
Anonymous
Long on FUD, short on fact 2006-02-08
Marty
Apple's in the eye of flaw finders 2006-02-09
A Nonny Moose
Apple's in the eye of Finder flaws 2006-02-09
AudioAquatic
How to do what was described... 2006-02-09
Anonymous
Apple's in the eye of flaw finders 2006-02-09
sierradragon
Apple's in the eye of flaw finders 2006-02-10
Anonymous (1 replies)
Apple's in the eye of flaw finders 2006-03-07
Anonymous (2 replies)







 

Privacy Statement
Copyright 2008, SecurityFocus