Pwn2Own 2017 Offers Big Bounties For Linux, Browser, and Apache Exploits (eweek.com)
Now that TrendMicro owns TippingPoint, there'll be "more targets and more prize money" according to eWeek, and something special for Pwn2Own's 10th anniversary in March.
Slashdot reader darthcamaro writes: For the first time in its ten-year history, the annual Pwn2Own hacking competition is taking direct aim at Linux. Pwn2Own in the past has typically focused mostly on web browsers, running on Windows and macOS. There is a $15,000 reward for security researchers that are able to get a local user kernel exploit on Ubuntu 16.10. The bigger prize though is a massive $200,000 award for exploiting Apache Web Server running on Ubuntu.
"We are nine weeks away," TrendMicro posted Wednesday, pointing out that they're giving out over $1 million in bounties, including the following:
"We are nine weeks away," TrendMicro posted Wednesday, pointing out that they're giving out over $1 million in bounties, including the following:
- $100,000 for escaping a virtualization hypervisor
- $80,000 for a Microsoft Edge or Google Chrome exploit
- $50,000 for an exploit of Adobe Reader, Microsoft Word, Excel or PowerPoint
- $50,000 for an Apple Safari exploit
- $30,000 for a Firefox exploit
- $30,000, $20,000 and $15,000 for privilege-escalating kernel vulnerabilities on Windows, macOS and Linux (respectively)
- $200,000 for an Apache Web Server exploit
Microsoft, Adobe, Google, Apple, and maybe some of the larger linux contributors/users (IBM, Oracle, Amazon) should form a sort of "consortium" and chip in $1M/year each to fund a much more lucrative version of pwn2own. That's chump change to them. With ~$8M in prizes yearly, I dare say we'd eliminate a lot of security flaws.
id rather be poor and look be able to spy on you all ....hhehehehehe
and i have several exploits that work on everything listed enjoy , if the nsa wants to spy so do i...
When paired with mod_php it is child's play.
How about targeting nginx, a superior web server?
APK Hosts File Engine 9.0++ SR-5 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/
Ads rob speed, security (malvertising) & privacy (tracking)
Hosts add speed (hardcodes/adblocks), security (bad sites/poisoned dns), reliability (dns down), & anonymity (dns requestlogs/trackers) natively
Avg. page = big as Doom http://www.theregister.co.uk/2016/04/22/web_page_now_big_as_doom/ & ads = 40%
Hosts != ClarityRay blockable (like inferior wasteful redundant slow usermode addons)
Less power/cpu/ram + IO use vs. DNS/routers/addons/antivirus slowing you + less security issues/complexity
Hosts block more used hostnames & lighten dns load. Firewalls block less used IP in malware.
APK
P.S. - Safe https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/
$1.99 for a working IIS exploit.
#DeleteChrome
APK Hosts File Engine 9.0++ SR-5 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/
Ads & malware rob speed, security & privacy
Hosts add speed (hardcodes/adblocks), security (bad sites/poisoned dns), reliability (dns down), & anonymity (dns requestlogs/trackers) natively
Less power/cpu/ram + IO use vs. DNS/routers/addons/antivirus + less security bugs/complexity
APK
P.S. - Safe https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/
As you all know, first prize is a Cadillac El Dorado. Anybody want to see second prize? Second prize is a set of steak knives. Third prize is you're in prison.
And by the way, all of you now work for the government, comrades.
You are welcome on my lawn.
Having a competition to attack Windows and OSX is fine and all but it's not helpful to anyone trying to run a secure system. I'm looking forward to any number of Linux kernel exploits because it's running on most servers... and my desktop. :)
Anons need not reply. Questions end with a question mark.
APK Hosts File Engine 9.0++ SR-5 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/
Ads & malware rob speed, security & privacy
Hosts add speed (hardcodes/adblocks), security (bad sites/poisoned dns), reliability (dns down), & anonymity (dns requestlogs/trackers) natively
Less power/cpu/ram + IO use vs. DNS/routers/addons/antivirus + less security bugs/complexity
APK
P.S. - Safe https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/
Chrome and Edge the hardest, safari a bit less secure, Firefox at the bottom. at least they're in the competition - they used to be so insecure as to not worth being in the competition
Why is the Safari bounty higher than the Firefox bounty, even though more people are on Firefox? More backing from Apple? More easily exploited target userbase?
See subject: MAKE ME (& I see I ran you DRY of your "downmodpoints" too - hence your unidentifiable ac post)
APK
P.S.=> You little pussy motherfucker... apk
Well, the good news is that Firefox is back! It was banned a few years because it was considered so insecure that there was no challenge in finding a new exploit.
Though, $30,000 for a Windows kernel elevation exploit? It seems like a lot of money, especially since macOS gets you $20,000 and Linux a measly $15,000.
What hosts do addons can't (or as well):
PROTECT vs.:
1.) bad sites (past ads)
2.) fastflux C&C
3.) dynDNS C&C
4.) DGA C&C
5.) DNS down
6.) poisoned dns
7.) trackers (dnsrequestlogs/ads/transparent ISP proxy)
8.) spam/phish payload
9.) dns blocks
10.) slowdown 2 ways: adblocks & hardcodes
11.) Multiplatform
12.) Ez data edit
13.) Efficiency (cpu/ram/I-O)
14.) UBlock no DNS bennys = poor imitation = "sincerest form of flattery"
15.) NoScript tag parses. Hosts block adservers before it cheaper
APK
P.S.=> AB+ 151mb http://cdn.ghacks.net/wp-content/uploads/2014/06/adblocker-memory-consumption.jpg/
UBlock 64MB http://cdn.ghacks.net/wp-content/uploads/2014/06/adblocker-memory-consumption.jpg/
(hosts ~6mb)
ClarityRay defeatable
Don't work http://www.businessinsider.com/google-microsoft-amazon-taboola-pay-adblock-plus-to-stop-blocking-their-ads-2015-2/
SLOWER: http://superuser.com/questions/686041/which-leads-to-faster-browsing-an-ad-blocker-or-an-edited-hosts-file/
See my subject: As you "Run, Forrest: RUN!!!" from a fair challenge I put to trolls like you https://it.slashdot.org/comments.pl?sid=10146371&cid=53715879/ & "your kind" RUNS, every single time, lol...
APK
P.S.=> If all you can do is harass others online? Take your own poor advice, freak... apk