Jack Writes: You were informed, in one of our previous articles, about the Swedish so-called “Hack-My-Mac” competition, during which a fully patched Mac mini was allegedly cracked in less than 30 minutes. Intrigued by this whole story, a university systems engineer set up his own contest. However, the results were quite different.
Thus, the engineer said that even after 4,000 log-in attempts and two denial-of-service attacks, his Mac mini remained untouched, according to Gregg Keizer for InformationWeek.
Dave Schroeder, a senior systems engineer at the University of Wisconsin, launched his contest Monday by setting up a fully-patched Mac mini hosting a Web page, and challenging attackers to have at it.
Schroeder said that the Swedish attack contest -- in which an attacker claimed he had cracked the Mac in under 30 minutes -- was deceptive. "This machine was not hacked from the outside just by being on the Internet," Schroeder wrote on his Web site. "It was hacked from within, by someone who was allowed to have a local account on the box. That is a huge distinction.
"It [left] people with the impression that a Mac OS X machine can be 'hacked' just by doing nothing more that being on the Internet. That is patently false."
For his challenge, Schroeder connected a PowerPC Mac mini to the Internet. The machine ran Mac OS X 10.4.5 with the latest security updates. The Mac had two local accounts, and Schroeder left both SHH and HTTP open.
The mini garnered attention and lots of traffic, said Schroeder, who logged 4,000 attempts. The machine weathered two DoS attacks, various Web exploit scripts, SSH dictionary attacks, and untold probes by scanning tools, he added.
"There were no successful access attempts of any kind during the 38 hour duration of the test," he crowed.
The Mac OS X is not invulnerable, he said, but it is "very secure."
"Apple is responsive to security concerns with Mac OS X," said Schroeder. "[That's] one of the most important pieces of the security picture."
What do you think? Was the first contest, the Swedish one, just an attempt to discredit the most secure OS currently on the market, by either a Mac-hater or somebody from the competition? To me, this doesn’t seem at all farfetched.
Source: Click Here