Tag Archive for: PWN2OWN

Trend Micro Offers More Than US$500000 at Mobile Pwn2Own 2017 – satPRnews (press release)

Trend Micro Offers More Than US$ 500000 at Mobile Pwn2Own 2017
satPRnews (press release)
DALLAS–(BUSINESS WIRE)–In the continued effort to thwart malicious attacks against consumers and enterprises, Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global leader in cybersecurity solutions, today announced the Zero Day Initiative's Mobile …

and more »

zero day – read more

White-hat hackers take down MacBook Pro at Pwn2own conference

Two hackers participating in the annual Pwn2own Security Conference managed to hack a MacBook Pro last Wednesday. First, they targeted Safari, then they gained access to Mac OS, and finally, they were able to hijack their way into the MacBook Pro Touch Bar.
mac hacker – read more

Virtual machine escape fetches $105,000 at Pwn2Own hacking contest [updated]

Enlarge (credit: Heather Katsoulis)

Contestants at this year’s Pwn2Own hacking competition in Vancouver just pulled off an unusually impressive feat: they compromised Microsoft’s heavily fortified Edge browser in a way that escapes a VMware Workstation virtual machine it runs in. The hack fetched a prize of $ 105,000, the highest awarded so far over the past three days.

According to a Friday morning tweet from the contest’s organizers, members of Qihoo 360’s security team carried out the hack by exploiting a heap overflow bug in Edge, a type confusion flaw in the Windows kernel and an uninitialized buffer vulnerability in VMware, contest organizers reported Friday morning on Twitter. The result was a “complete virtual machine escape.”

“We used a JavaScript engine bug within Microsoft Edge to achieve the code execution inside the Edge sandbox, and we used a Windows 10 kernel bug to escape from it and fully compromise the guest machine,” Qihoo 360 Executive Director Zheng Zheng wrote in an e-mail. “Then we exploited a hardware simulation bug within VMware to escape from the guest operating system to the host one. All started from and only by a controlled a website.”

Read 7 remaining paragraphs | Comments

Technology Lab – Ars Technica

Adobe Reader, Edge, Safari, and Ubuntu fall during first day at Pwn2Own – CIO


CIO

Adobe Reader, Edge, Safari, and Ubuntu fall during first day at Pwn2Own
CIO
It's organized and sponsored by the Zero Day Initiative (ZDI), an exploit acquisition program operated by Trend Micro after its acquisition of TippingPoint. This year the contest has a prize pool of US$ 1 million for exploits in five categories: virtual

and more »

zero day – read more