Slashdot Mirror


All Five Smartphones Survive Pwn2Own Contest

CWmike writes "Although three of the four browsers that were targets in the PWN2OWN hacking contest quickly fell to a pair of researchers, none of the smartphones were successfully exploited. TippingPoint had offered $10,000 for each exploit on any of the phones, which included the iPhone and the BlackBerry, as well as phones running the Windows Mobile, Symbian and Android operating systems. 'With the mobile devices so limited on memory and processing power, a lot of [researchers'] main exploit techniques are not able to work,' said TippingPoint's Terri Forslof. 'Take, for example, [Charlie] Miller's Safari exploit,' referring to Miller's 10-second hack of a MacBook via an unpatched Safari vulnerability that he'd known about for more than a year. 'People wondered why wouldn't it work on the iPhone, why didn't he go for the $10,000?' she said. 'The vulnerability is absolutely there, but it's a lot tougher to exploit on the iPhone.'" Chrome was the only browser at the contest that was not successfully exploited. We previously discussed day one of the contest, and a summary of day two is available as well.

2 of 144 comments (clear)

  1. Re:Not any tougher on iPhone according TFA by scorp1us · · Score: 0, Troll

    The iPhone does not use Safari. The iPhone uses a rebranded mobile browser from another vendor. This vendor also makes the browser for other smart phones.

    --
    Slashdot's rate-of-post filter: Preventing you from posting too many great ideas at once.
  2. Re:Phones by petehead · · Score: 0, Troll

    A quick Google Pulled up the Phones as: Phones (and associated test platform) * Blackberry(TBA)
    * Android(Dev G1)
    * iPhone(locked 2.0)
    * Nokia/Symbian(N95-1)
    * Windows Mobile (HTC Touch)

    I have the HTC Touch. It has a built in security feature: It will crash whatever you are running to try to exploit it. If anyone here figures out how to exploit it, please tell Microsoft. Not so that they will patch it, but so they can use it as an example to developers for how to code.