Live data from Hacker News

Pwn2Own owned all major browsers

h30499.www3.hp.com

21–30 of 67 posts

Re: Pwn2Own owned all major browsers

#21
post #16

Interesting how Java was pwned thee times in spite of the lowest reward.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

Why sit on it? Why not disclose it and have it be your name on that CVE, and not someone else?

Re: Pwn2Own owned all major browsers

#23

Earlier quoted context omitted.

At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari. I was about to make fun of you for suggesting safari has significant usage until I considered mobile.

Safari's desktop share is somewhere between 5.5% and 15.5% depending on whose stats you trust: http://en.wikipedia.org/wiki/Usage_share_of_web_browsers#Sta... Is it crazy to consider that significant?

I personally consider it not major but significant, not just due to market share but also because it's the default browser (and shares its inner components with applications leveraging WebView) on a certain platform. Therefore it's a prime target for establishing a foothold on that platform.

Re: Pwn2Own owned all major browsers

#24
post #21
post #16

Earlier quoted context omitted.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

Why sit on it? Why not disclose it and have it be your name on that CVE, and not someone else?

a cve is not worth that much. (nothing?)

Re: Pwn2Own owned all major browsers

#26

Interesting how Java was pwned thee times in spite of the lowest reward.

We've seen Java bugs in the news lately for use in co-ordinated attacks against large companies.

A nameless firm (not the one I'm working with now) that happens to be one of Europes largest banks has insainly locked down versions windows, everything disabled, some custom thing that has hooked NT kernel functiosn to check which image is being loaded to be executed.

And then it has Java. A very old, un-patched version running a vendor risk system (yes it is that french one your thinking of).

This means that despite the frankly anoying parinoid security there, you can pwn any of the machines easily. As we see more targeted attacking, remember that Java is heavily used by a lot of rich, often inept due to size, firms.

Re: Pwn2Own owned all major browsers

#28

"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?

At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari. I was about to make fun of you for suggesting safari has significant usage until I considered mobile.

Safari actually has 60% of mobile web usage.

Source: http://tech.fortune.cnn.com/2013/02/01/apple-android-market-...

Re: Pwn2Own owned all major browsers

#29
post #16

Interesting how Java was pwned thee times in spite of the lowest reward.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward.

I've always wondered if it's intelligence agencies, criminal organizations, police organizations, or commercial endeavors that sell services to those three bodies that are paying that kind of money for zero days.

I also don't understand why people give good zero days away for free, if is really the case that there is a market in these types of properties. Anybody have actual insight into this?

Re: Pwn2Own owned all major browsers

#30
post #16

Earlier quoted context omitted.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward. I've always wondered if it's intelligence agencies, criminal organizations, police organiz…

Maybe because they don't want people's computers to be abused by people with lots of cash to spare? One can only assume they're getting more than $50k worth of value from the zero day, so something pretty dodgy must be going on
Post reply on HN