Pwn2Own owned all major browsers
h30499.www3.hp.com
Pwn2Own owned all major browsers
1–10 of 67 posts
Re: Pwn2Own owned all major browsers
#2Re: Pwn2Own owned all major browsers
#3Where's Safari?
Re: Pwn2Own owned all major browsers
#4Re: Pwn2Own owned all major browsers
#5Where's Safari?
Re: Pwn2Own owned all major browsers
#6Where's Safari?
Directly below "Mozilla Firefox on Windows 7 ($60,000)"
Wednesday:
1:30 - Java (James Forshaw) PWNED
2:30 - Java (Joshua Drake) PWNED
3:30 - IE 10 (VUPEN Security) PWNED
4:30 - Chrome (Nils & Jon) PWNED
5:30 - Firefox (VUPEN Security) PWNED
5:31 - Java (VUPEN Security) PWNED
Thursday:
12pm - Flash (VUPEN Security)
1pm - Adobe Reader (George Hotz)
2pm - IE 10 (Pham Toan)
Interestingly enough, last year it was the only target not 0-day pwned (but was in the CVE contest, via CVE-2011-0115 and CVE-2010-0050).Re: Pwn2Own owned all major browsers
#7Re: Pwn2Own owned all major browsers
#8Re: Pwn2Own owned all major browsers
#9I don't really understand the competiton. Do people come to these with just the intention of finding exploits, or do they come with the exploit ready, waiting to collect a reward?
I've linked to a blog post from the Chrome developers that details the exploit that won late 2011 [1]. 'Pinkie Pie', the pseudonym of the person who won it, is pretty infamous in those circles.
[1] http://blog.chromium.org/2012/05/tale-of-two-pwnies-part-1.h...
Re: Pwn2Own owned all major browsers
#10I don't really understand the competiton. Do people come to these with just the intention of finding exploits, or do they come with the exploit ready, waiting to collect a reward?
It's a useful excercise, I think, in that it demonstrates that even the most hardened of codebases still has security bugs and it also serves as a cautionary tale for people who think they don't need multiple layers of defence..