Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Hacker Super Bowl pits Mac OS vs. Linux, Vista

To garner the $20,000 purse, hackers have to win with a zero-day attack that's never been seen before


It's the most anticipated matchup in the hacker world: Linux versus Mac OS X versus Vista. Who will get hacked first?

That's what organizers of the CanSecWest security conference hope to discover this week as they give show attendees a shot at hacking into the three laptops they've put on display here in Vancouver.

The catch? They have to use a brand-new "zero day" attack that nobody has seen before. The prize is $20,000, plus you get to keep the laptop.

Show organizers are calling the contest PWN 2 OWN. Pwn (which rhymes with "own") is a hacker term meaning to take control of a computer.

Though $20,000 sounds like a lot of money, show attendees say that top-quality computer attack code could easily fetch that much, either from the security vendors such as iDefense or Tipping Point who purchase this type of software or from one of the three-letter U.S. government agencies said to be in the market for this type of code as well.

Charlie Miller, best known as one of the Independent Security Evaluators researchers who first hacked the iPhone last year, said he's participating, not for the cash prize, but for the thrill of seeing whether or not he can be first to hack one of the computers. "For me it's the Super Bowl of security research," he said. "I'm a competitive guy."

By late Wednesday -- the first day of the contest, nobody had even tried to hack the three laptops. This wasn't exactly a surprise to the contest's organizers because on day one, attackers were only allowed to use network-based attacks that involved no user interaction. Those type of attacks are extremely rare these days.

Miller said that he will drop his exploit code on the MacBook Air Thursday, once the rules relax a bit and the hackers are allowed to try attacks that require user action such as visiting a malicious Web site or opening an e-mail.

There is a downside to waiting until Thursday, however. The prize money drops in half each day. If no one has claimed the laptops by Friday, the prize bottoms out at $5,000 and organizers will start installing non-standard software on the machines to see if they can be compromised through programs such as Skype.

Last year's contest generated a lot of attention, but it featured only one laptop: a MacBook Pro. It was won by researcher Dino Dai Zovi, who wasn't at the conference, but asked a friend to run his attack on the machine.

With three laptops to chose from, this year, the 2008 contest is a bit of a horse race.

"It will be interesting to see which one goes first," said Aaron Portnoy, a researcher with TippingPoint, the company that has put up the prize money. "We've tried really hard to make sure the attack surface is the same on all of them."


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





BRINGING PERFORMANCE VALIDATION "INTO THE LIFECYCLE"
Today's enterprise apps are complex and ever-changing, which makes delivering high performance difficult. By virtualizing the behavior of application services and data in a VSE, teams can answer this challenge with validation best practices and test tools to ensure solid performance throughout the lifecycle. Register now to attend this webcast! Sponsor: ITKO

»  Click here to view this Webcast
  The Data Protection You've Been Looking For
Enterprise data is of supreme importance. If you can't find it quickly, it's worthless. If you lose it, it's a crisis. This IT Strategy Guide explores how to keep your data safe.

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 
  • Protect Your Data with SSL - Discover how to increase customer confidence in your site with the latest solution in SSL, Extended Validation (EV) SSL ...
  • Need simple, low cost server virtualization? - Do more with less. Support fewer servers. Simplify disaster recovery. Implement proven, easy-to-use server virtualization...
  • Virtually Limitless Virtual Storage - Do you need virtualization space savings of 50% or more with virtually no performance impact? You might be able to get storage...
  • Invisible IT? - The goal of IT is to become an invisible entity within a larger organization. Eliminating visibility and road blocks IT ...
  • It Really Is Easy to be Green - "Green IT" is a popular concept. And IT organizations are learning the influence that IT purchase decisions have on data...
  • Key Strategies For SOA Testing - SOA requires a unique approach to testing. Unless you're willing to reorient your testing procedures and technology now,...

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS  IT EXEC-CONNECT   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist