Tag Archive for: PWN2OWN

Pwn2Own contest highlights renewed hacker focus on kernel issues

Hackers demonstrated 21 new vulnerabilities in attacks against browsers and operating systems during this year’s Pwn2Own hacking contest. The complexity of the exploits, though, shows that hackers have to jump through many hoops to gain full system control.

On Wednesday and Thursday, five contestants — four teams and one independent researcher — demonstrated three successful remote code execution attacks against Safari on OS X, two against Microsoft Edge on Windows, four against Adobe Flash on Windows and one partially successful attack against Google Chrome on Windows. Firefox was not a target in this year’s contest.

To read this article in full or to leave a comment, please click here

Network World Security

All four major browsers take a stomping at Pwn2Own hacking competition

The annual Pwn2Own hacking competition wrapped up its 2015 event in Vancouver with another banner year, paying $ 442,000 for 21 critical bugs in all four major browsers, as well as Windows, Adobe Flash, and Adobe Reader.

The crowning achievement came Thursday as contestant Jung Hoon Lee, aka lokihardt, demonstrated an exploit that felled both the stable and beta versions of Chrome, the Google-developed browser that’s famously hard to compromise. His hack started with a buffer overflow race condition in Chrome. To allow that attack to break past anti-exploit mechanisms such as the sandbox and address space layout randomization, it also targeted an information leak and a race condition in two Windows kernel drivers, an impressive feat that allowed the exploit to achieve full System access.

“With all of this, lokihardt managed to get the single biggest payout of the competition, not to mention the single biggest payout in Pwn2Own history: $ 75,000 USD for the Chrome bug, an extra $ 25,000 for the privilege escalation to SYSTEM, and another $ 10,000 from Google for hitting the beta version for a grand total of $ 110,000,” Pwn2Own organizers wrote in a blog post published Thursday. “To put it another way, lokihardt earned roughly $ 916 a second for his two-minute demonstration.”

Read 2 remaining paragraphs | Comments


Ars Technica » Technology Lab

All major browsers hacked in Pwn2Own contest; hacker gets $225,000 in prize money

“On Thursday, South Korean security researcher and serial browser hacker JungHoon Lee, known online as lokihardt, single-handedly popped Internet Explorer 11 and Google Chrome on Microsoft Windows, as well as Apple Safari on Mac OS X,” Constantin reports.
mac hacker – read more

SSCC 139 – PWN2OWN, browser updates, Target alerts, PCI DSS and phishing [PODCAST]

Is a browser less secure if more people like to hack it? Is it OK to ignore alerts simply because you get too many? Do you back yourself to spot every single phish? And just how smart is the Google Play Store? Chester and Duck dissect these issues with their usual style in this week’s Chet Chat podcast…
Naked Security – Sophos