Google Pixel pwned in 60 seconds
theregister.co.uk
Google Pixel pwned in 60 seconds
1–10 of 41 posts
Re: Google Pixel pwned in 60 seconds
#2Re: Google Pixel pwned in 60 seconds
#3How do these competitions declare a winner? Snippets like "it only took 4 seconds" suggest they use the total exploit running time as the only criteria?
Re: Google Pixel pwned in 60 seconds
#4How do these competitions declare a winner? Snippets like "it only took 4 seconds" suggest they use the total exploit running time as the only criteria?
Generally once a target has been compromised, no other teams are allowed to use the same vulnerabilities. this prevents a team from sharing an exploit/vuln to others who run it again. The downside is that if you've been working on an exploit chain for 6 months but a team runs a similar bug ahead of you, your work is worthless.
Re: Google Pixel pwned in 60 seconds
#5Re: Google Pixel pwned in 60 seconds
#6Re: Google Pixel pwned in 60 seconds
#7Re: Google Pixel pwned in 60 seconds
#8$520,000 in a day. I wonder how many man-hours were spent prior to the competition?
Re: Google Pixel pwned in 60 seconds
#9Apart from the Flash vulnerability, did any of the exploits use Chrome to gain all permissions on the Pixel? That would be scary, because the user would just have to be served Javascript containing malicious code or visit an affected website.
Why isn't Linux or the BSDs usually included in these pawn competitions?