Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Ubuntu survives pwn2own contest


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Ubuntu survives pwn2own contest
Reply
 
Thread Tools
Old 29-03-2008, 20:09   #1
cf.geek
 
brundles's Avatar
 
Join Date: Jan 2006
Location: Berkshire
Posts: 890
brundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud of
Ubuntu survives pwn2own contest

At the risk of putting the cat among the pigeons, I thought some folk here might find the results of the CanSecWest pwn2own contest interesting.

After 3 days of attempting to crack "off-the-shelf" laptops (although with more vulnerabilities each day), the Ubuntu laptop remains unhacked. To be fair, the Vista laptop nearly made it through and it did take the inclusion of some Adobe software to succeed though.

More details at http://dvlabs.tippingpoint.com/blog/...wn-to-own-2008
__________________
brundles is online now   Reply With Quote
Old 29-03-2008, 23:27   #2
.NET 2.0 Developer
 
AntiSilence's Avatar
 
Join Date: Jul 2006
Location: Sutton-In-Ashfield
Age: 30
Services: Software & Web Application Development
Posts: 2,245
AntiSilence is just so famous around these partsAntiSilence is just so famous around these partsAntiSilence is just so famous around these parts
AntiSilence is just so famous around these parts
Re: Ubuntu survives pwn2own contest

I have no problem with Linux and agree that it's a really secure OS. I have tried it (well, only a couple of them anyway lol) and it's just not the OS for me.

Interesting to see the Apple OS get hacked pretty quickly.
__________________
AntiSilence is offline   Reply With Quote
Old 30-03-2008, 11:07   #3
pop`s
 
xpod's Avatar
 
Join Date: Jan 2007
Location: Not in Scotland:-(
Age: 38
Services: 3 for £30........ahem
Posts: 1,193
xpod has entered a golden reputation era
xpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation era
Re: Ubuntu survives pwn2own contest

Quote:
At the risk of putting the cat among the pigeons
I knew there was a reason i opted not to post this anywhere yesterday

Apparently some cynics,obviously forgetting about the $10,000, reckon the MBA was only compromised first because it was the most desirable and expensive machine there.....
If only they`d changed that default Ubuntu scheme things might have been soooo different eh.
__________________
Life is like an ashtray......full of little doubts.
xpod is offline   Reply With Quote
Old 30-03-2008, 12:54   #4
Rather fruity
 
Join Date: Jun 2003
Posts: 6,042
Shaun is a king among kingsShaun is a king among kings
Shaun is a king among kingsShaun is a king among kingsShaun is a king among kingsShaun is a king among kingsShaun is a king among kingsShaun is a king among kingsShaun is a king among kingsShaun is a king among kingsShaun is a king among kingsShaun is a king among kings
Re: Ubuntu survives pwn2own contest

Can't get Ubuntu to run on this x64 lappy. Never could on my dell desktop either, not even the live CD.
Shaun is offline   Reply With Quote
Old 30-03-2008, 13:01   #5
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,029
Stuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star member
Stuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star memberStuart C is a twin star member
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: Ubuntu survives pwn2own contest

Quote:
Originally Posted by xpod View Post
I knew there was a reason i opted not to post this anywhere yesterday

Apparently some cynics,obviously forgetting about the $10,000, reckon the MBA was only compromised first because it was the most desirable and expensive machine there.....
If only they`d changed that default Ubuntu scheme things might have been soooo different eh.
What would have balanced things out is having the same make/model of laptop running each os, just one laptop running each os.
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 30-03-2008, 18:32   #6
.NET 2.0 Developer
 
AntiSilence's Avatar
 
Join Date: Jul 2006
Location: Sutton-In-Ashfield
Age: 30
Services: Software & Web Application Development
Posts: 2,245
AntiSilence is just so famous around these partsAntiSilence is just so famous around these partsAntiSilence is just so famous around these parts
AntiSilence is just so famous around these parts
Re: Ubuntu survives pwn2own contest

Quote:
Originally Posted by Shaun View Post
Can't get Ubuntu to run on this x64 lappy. Never could on my dell desktop either, not even the live CD.
When I tried Ubuntu, it wouldn't let me use 1280x1024 for my monitor resolution, the max it would let me set was 1024x768 which looks awful on my TFT.
__________________
AntiSilence is offline   Reply With Quote
Old 30-03-2008, 20:53   #7
pop`s
 
xpod's Avatar
 
Join Date: Jan 2007
Location: Not in Scotland:-(
Age: 38
Services: 3 for £30........ahem
Posts: 1,193
xpod has entered a golden reputation era
xpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation era
Re: Ubuntu survives pwn2own contest

Quote:
When I tried Ubuntu, it wouldn't let me use 1280x1024 for my monitor resolution, the max it would let me set was 1024x768 which looks awful on my TFT.
Drivers??
Currently have both 19" & 22" screens working fine here @ 1440x900 & 1680x1050 respectively.
__________________
Life is like an ashtray......full of little doubts.
xpod is offline   Reply With Quote
Old 30-03-2008, 20:56   #8
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 30
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 7,467
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Re: Ubuntu survives pwn2own contest

Quote:
Originally Posted by Stuart C View Post
What would have balanced things out is having the same make/model of laptop running each os, just one laptop running each os.
Agreed, doing that makes it entirely about the OS and not about the underlying hardware.
__________________
Formerly known as 'Raistlin'
For Clarity: Bold = Moderating Decision/Comment :: Normal = My Opinion/Comment
Rob M is online now   Reply With Quote
Old 31-03-2008, 01:09   #9
.NET 2.0 Developer
 
AntiSilence's Avatar
 
Join Date: Jul 2006
Location: Sutton-In-Ashfield
Age: 30
Services: Software & Web Application Development
Posts: 2,245
AntiSilence is just so famous around these partsAntiSilence is just so famous around these partsAntiSilence is just so famous around these parts
AntiSilence is just so famous around these parts
Re: Ubuntu survives pwn2own contest

Quote:
Originally Posted by xpod View Post
Drivers??
Currently have both 19" & 22" screens working fine here @ 1440x900 & 1680x1050 respectively.
Most likely, it was the standard drivers that came with the OS. Didn't find much on the nvidia site about Linux drivers, and even if I had, I wouldn't have known what to do with them! LOL
__________________
AntiSilence is offline   Reply With Quote
Old 31-03-2008, 11:52   #10
pop`s
 
xpod's Avatar
 
Join Date: Jan 2007
Location: Not in Scotland:-(
Age: 38
Services: 3 for £30........ahem
Posts: 1,193
xpod has entered a golden reputation era
xpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation era
Re: Ubuntu survives pwn2own contest

Quote:
Most likely, it was the standard drivers that came with the OS. Didn't find much on the nvidia site about Linux drivers, and even if I had, I wouldn't have known what to do with them! LOL
You would indeed struggle getting the higher resolutions with the included NV driver but the Restricted Drivers Manager should have informed you about the option of installing the accelerated Nvidia driver,depending how long ago you tried the thing that is
Thats one of the easier method anyway.

As far as the the last OS standing was concerned......Mr Macaulays having none of it
Quote:
Plenty of commentators have made hay of the MacBook Pro being the first to exit the race, and Linux zealots are sure to conclude the contest results prove the superiority of that platform. Maybe. But that's not how it looks to Macaulay, who says with a few hours of tweaking, his exploit will also work on OS X and Linux.
http://www.theregister.co.uk/2008/03...left_standing/
__________________
Life is like an ashtray......full of little doubts.
xpod is offline   Reply With Quote
Old 31-03-2008, 12:22   #11
cf.geek
 
brundles's Avatar
 
Join Date: Jan 2006
Location: Berkshire
Posts: 890
brundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud ofbrundles has much to be proud of
Re: Ubuntu survives pwn2own contest

Wasn't his exploit based on Safari though? I know that Apple ported it to Windows recently but wasn't aware it ran on Linux too.
__________________
brundles is online now   Reply With Quote
Old 31-03-2008, 12:52   #12
pop`s
 
xpod's Avatar
 
Join Date: Jan 2007
Location: Not in Scotland:-(
Age: 38
Services: 3 for £30........ahem
Posts: 1,193
xpod has entered a golden reputation era
xpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation eraxpod has entered a golden reputation era
Re: Ubuntu survives pwn2own contest

Quote:
Wasn't his exploit based on Safari though? I know that Apple ported it to Windows recently but wasn't aware it ran on Linux too.
Charlie Miller did the MBA with the Safari exploit on day one while
Macaulays(& Co) was the Flash exploit on day 2.
http://www.theregister.co.uk/2008/03...left_standing/
__________________
Life is like an ashtray......full of little doubts.
xpod is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 11:38.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)