First Pwn2Own 2009 Contest Winners Emerge
mellowdonkey writes "Last year's CanSecWest hacking contest winner, Charlie Miller, does it again this year in the 2009 Pwn2Own contest. Charlie was the first to compromise Safari this year to win a brand spankin new Macbook. Nils, the other winner, was able to use three separate zero day exploits to whack IE8, Firefox, and Safari as well. Full detail and pictures are available from the sponsor, TippingPoint, who acquired all of the exploits through their Zero Day Initiative program."
Nils, the other winner, was able to use three separate zero day exploits to whack IE8, Firefox, and Safari as well.
Wow.
'Security' through obscurity
Well, I'm not surprised it didn't take but a few moments for the contest to be won.
Man can make it, man can break it. That's it.
Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
Either these guys are very good.
or something is very wrong with the security features of these Apps
Once or twice meant something, but now it's an institution.
Meaning that somebody is going to try to make a career of breaking the easiest part of the system at this contest.
Meaning that these guys are going to sit on their exploits.
Meaning that this contest, running at a set time once a year, is now meaningless.
Except for advertising potential. You know, keeping your product name in the headlines.
The respective companies should offer a running bounty on exploits on their browsers. Yeah, that would spoil all the pageantry of Pwn20wn, but do we really need another pageant?
Computer memory is just fancy paper, CPUs just fancy pens with fancy erasers; the 'net is just a fancy backyard fence.
I checked the article and there don't appear to be any details. A few of these hacking contests have been a bit overblown so I'd like to know what manner of exploit they used.
If it's another "well you need physical access to the machine and know the admin username and password" then it's no big deal. If it's "we had the user click a link and all hell broke loose" that would be much more interesting.
firefox is firefox, it runs on linux, it can be exploited on linux. NOSCRIPT FTW
IranAir Flight 655 never forget!
The same hole can have different levels of exploitability in different OSes. FF for Windows cannot take advantage of ASLR because Windows XP didn't support it. In Linux it should be enabled by default by now. MacOS X has nothing at all yet.
If all OSes would implement all of OpenBSD security features, even if not perfectly, the amount of exploitable bugs would decrease considerably. The bug is still there, but the black hat is met with a harsh environment totally unlike the green garden that are major OSes.
10 little-endian boys went out to dine, a big-endian carp ate one, and then there were -246.