« MacBook Air Cracked First in Security Derby | Main | Curiosity Wouldn't Be Such a Bad Trait for a Legislator »

March 31, 2008

Vista Compromised to Get at a Nice Laptop

“Hacker Shane Macaulay (with the help of friends Derek Callaway and Alexander Sotirov) of Security Objectives was able to compromise and gain control of the Windows Vista laptop via a previously undiscovered flaw in the latest version of Adobe’s Flash software, allowing him to claim the Fujitsu laptop and the $5,000 cash prize. Just like the Safari flaw that Apple was informed of, the zero-day vulnerability that Shane exploited was responsibly disclosed to Adobe, which is already reportedly readying an update that fixes the vulnerability.”

“Microsoft’s Internet Explorer team should see this as a great accomplishment considering how poor IE6’s security record has been. It looks like Vista’s IE7 stood up to the challenge. Nevertheless, Vista’s fall on the last day left the Sony Vaio laptop running Ubuntu as the ultimate winner—Linux was the last OS left standing.”

Readers in the comments claim any of the three targeted machines could have gone down over the Flash exploit that claimed Vista, leaving the Mac as the only machine taken out by software that came out of the box.

Were any points really proven? No. Except, perhaps, a point assorted advocates (and zealots) alternately embrace or dance around, depending on whether it suits them:

Comparing the relative security of operating systems based on ‘sploit-counting nitpickery is just stupid. Who among average users doesn’t have Flash installed on their machine? On what planet have we not seen 13 Firefox 2 point releases come and go, only one of which addressed nothing more serious than a vulnerability of “high” criticality, all the rest of which had at least one “severe” vulnerability?

The problem with contests like this is that the people who don’t know any better than to run into the street yelling “My OS is the securest!!11!!! lolz losedowz luserz!” will continue to not know any better.

(Link)

Previously: MacBook Air Cracked First in Security Derby

E-mail   0 Comments    Digg This    add to del.icio.us

Posted by mhall at 2:07 PM | Add Comment

Leave a comment











Type the characters you see in the picture above.

 




JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Avaya Article: How to Feed Data into the Avaya Event Processor
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: Developing a Software Policy for Your Organization
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Win a Lenovo ThinkPad X300 Notebook in the Intel Resource Center Scavenger Hunt
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Enterprise Search--Do You Know What's Out There?
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES