Interesting how Java was pwned thee times in spite of the lowest reward.
Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.
Pwn2Own owned all major browsers
21–30 of 67 posts
Re: Pwn2Own owned all major browsers
#22woah! whats with the hp site permalink/URI/url formatting? http://h30499.www3.hp.com/
Re: Pwn2Own owned all major browsers
#23Earlier quoted context omitted.
At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari. I was about to make fun of you for suggesting safari has significant usage until I considered mobile.
Safari's desktop share is somewhere between 5.5% and 15.5% depending on whose stats you trust: http://en.wikipedia.org/wiki/Usage_share_of_web_browsers#Sta... Is it crazy to consider that significant?
Re: Pwn2Own owned all major browsers
#24Earlier quoted context omitted.
Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.
Why sit on it? Why not disclose it and have it be your name on that CVE, and not someone else?
Re: Pwn2Own owned all major browsers
#25Re: Pwn2Own owned all major browsers
#26Interesting how Java was pwned thee times in spite of the lowest reward.
A nameless firm (not the one I'm working with now) that happens to be one of Europes largest banks has insainly locked down versions windows, everything disabled, some custom thing that has hooked NT kernel functiosn to check which image is being loaded to be executed.
And then it has Java. A very old, un-patched version running a vendor risk system (yes it is that french one your thinking of).
This means that despite the frankly anoying parinoid security there, you can pwn any of the machines easily. As we see more targeted attacking, remember that Java is heavily used by a lot of rich, often inept due to size, firms.
Re: Pwn2Own owned all major browsers
#27Re: Pwn2Own owned all major browsers
#28"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?
At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari. I was about to make fun of you for suggesting safari has significant usage until I considered mobile.
Source: http://tech.fortune.cnn.com/2013/02/01/apple-android-market-...
Re: Pwn2Own owned all major browsers
#29Interesting how Java was pwned thee times in spite of the lowest reward.
Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.
I've always wondered if it's intelligence agencies, criminal organizations, police organizations, or commercial endeavors that sell services to those three bodies that are paying that kind of money for zero days.
I also don't understand why people give good zero days away for free, if is really the case that there is a market in these types of properties. Anybody have actual insight into this?
Re: Pwn2Own owned all major browsers
#30Earlier quoted context omitted.
Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.
I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward. I've always wondered if it's intelligence agencies, criminal organizations, police organiz…