Nah, forget it. Wisc.edu has removed this page. Apparently, they
were concerned with the security of their network *growl*
Go to the test.doit.wisc.edu site, and read their message. Very
silly, but what do you want from paranoid admins who don't know what
they're talking about.
On Mar 8, 2006, at 3:22 AM, Anne Robertson wrote:
Hello everyone,
Here's the piece from MacUser showing what Mac experts think of
the so-called "hack" reported the other day.
OS X 'hack' claim denied 10:57AM
A system administrator at the University of Wisconsin has
described yesterday's report by an Australian website that OS X
had been hacked within 30 minutes as 'woefully inaccurate'.
Dave Schroeder said that rather than hack the machine, all that
the hacker, 'gwerdna', had done was gain escalated privileges on
the target Mac, where he already had a user account. Gwerdna won a
competition to see which user could gain root privileges on the
Mac in the shortest time.
'It's unfortunate that the initial coverage was so
journalistically poor and sensationalistic on what might otherwise
have been an article about an interesting local vulnerability,'
Schroeder said. 'Instead, it chose to leave people with the
impression that a Mac OS X machine can be "hacked" just by doing
nothing more that being on the Internet. That is patently false.'
Schroeder acknowledged that OS X is vulnerable, like any operating
system, but insisted that, 'the general architecture and design
philosophy of Mac OS X, in addition to usage of open source
components for most network-accessible services that receive
intense peer scrutiny from the community, make Mac OS X a very
secure operating system.'
He added that almost all consumer Macs will not give any external
local account access, nor have any ports open, and many will also
be behind personal router/firewall devices.
To test this, Schroeder has setup his own competition, with one
simple objective, to alter the Web page at http://
test.doit.wisc.edu/. The page is hosted on a PowerPC Mac mini
running Mac OS X 10.4.5 with Security Update 2006-001, has two
local accounts and has ssh and http open, which as he points out
is a lot more than most Mac OS X machines will ever have open.
Schroeder said although there have been serious vulnerabilities in
OS X, to date most have relied on typical trojan social
engineering tactics, not genuine vulnerabilities; any
vulnerabilities that are reported to Apple are fixed promptly.
'Apple does a fairly good job with regard to security, and has
greatly improved its reporting processes after pressure from
institutional Mac OS X users: Apple is responsive to security
concerns with Mac OS X, which is one of the most important pieces
of the security picture,' he said.
Simon Aughton
MacUser newsletter 8th March 2006