Pwn2Own owned all major browsers
11–20 of 67 posts
Re: Pwn2Own owned all major browsers
#12I don't really understand the competiton. Do people come to these with just the intention of finding exploits, or do they come with the exploit ready, waiting to collect a reward?
In general, skilled crackers/reverse engineers/security experts will look for new bugs -- and when found, can either a) Tell the vendor, b) Tell the world, c) Sell the exploit to the highest bidder, or d) Use the exploit for nefarious purposes themselves.
In general some combination of a) and b) or c) is the most common -- these events is a way to compensate people to do a) and b) -- and provide some incentive to avoid c) (and d)).
Re: Pwn2Own owned all major browsers
#13I don't really understand the competiton. Do people come to these with just the intention of finding exploits, or do they come with the exploit ready, waiting to collect a reward?
They have the exploits ready to go, the challenge is whether they can exploit the target system (which is fully patched) within their time slot. It's a useful excercise, I think, in that it demonstrates that even the most hardened of codebases still has security bugs and it also serves as a cautionary tale for people who think they don't need multiple layers of defence..
Re: Pwn2Own owned all major browsers
#14Re: Pwn2Own owned all major browsers
#15"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?
Re: Pwn2Own owned all major browsers
#16Interesting how Java was pwned thee times in spite of the lowest reward.
Re: Pwn2Own owned all major browsers
#17Earlier quoted context omitted.
Directly below "Mozilla Firefox on Windows 7 ($60,000)"
Safari is a target in the event, but has not been pwned yet: Wednesday: 1:30 - Java (James Forshaw) PWNED 2:30 - Java (Joshua Drake) PWNED 3:30 - IE 10 (VUPEN Security) PWNED 4:30 - Chrome (Nils & Jon) PWNED 5:30 - Firefox (VUPEN Security) PWNED 5:31 - Java (VUPEN Security) PWNED Thursday: 12pm - Flash (VUPEN Security) 1pm - Adobe Reader (George Hotz) 2pm - IE 10 (Pham Toan) Interestingly enough, last year it was the…
Re: Pwn2Own owned all major browsers
#18"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?
I was about to make fun of you for suggesting safari has significant usage until I considered mobile.
Re: Pwn2Own owned all major browsers
#19"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?
At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari. I was about to make fun of you for suggesting safari has significant usage until I considered mobile.
Re: Pwn2Own owned all major browsers
#20"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?
At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari. I was about to make fun of you for suggesting safari has significant usage until I considered mobile.
http://en.wikipedia.org/wiki/Usage_share_of_web_browsers#Sta...
Is it crazy to consider that significant?