It's good to know it still got taken down, because I had a horrible fear they where going to try and advertise they were 100% safe because they weren't exploited.
Pwn2Own owned all major browsers
31–40 of 67 posts
Re: Pwn2Own owned all major browsers
#32Earlier quoted context omitted.
Safari is a target in the event, but has not been pwned yet: Wednesday: 1:30 - Java (James Forshaw) PWNED 2:30 - Java (Joshua Drake) PWNED 3:30 - IE 10 (VUPEN Security) PWNED 4:30 - Chrome (Nils & Jon) PWNED 5:30 - Firefox (VUPEN Security) PWNED 5:31 - Java (VUPEN Security) PWNED Thursday: 12pm - Flash (VUPEN Security) 1pm - Adobe Reader (George Hotz) 2pm - IE 10 (Pham Toan) Interestingly enough, last year it was the…
Poor Vupen. Their Safari exploit must have broke.
Re: Pwn2Own owned all major browsers
#33woah! whats with the hp site permalink/URI/url formatting? http://h30499.www3.hp.com/
What's wrong with that? Seems perfectly fine to me.
What's that h30499? www3?
Why not communities.hp.com? (this actually redirects to h30507.www3.hp.com). h30500 asks for httpauth.
It's just ugly, is it not?
Re: Pwn2Own owned all major browsers
#34Re: Pwn2Own owned all major browsers
#35woah! whats with the hp site permalink/URI/url formatting? http://h30499.www3.hp.com/
Re: Pwn2Own owned all major browsers
#36Earlier quoted context omitted.
Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.
I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward. I've always wondered if it's intelligence agencies, criminal organizations, police organiz…
Re: Pwn2Own owned all major browsers
#37woah! whats with the hp site permalink/URI/url formatting? http://h30499.www3.hp.com/
You know, I've actually seen a pretty useful writeup on why HP urls are so crazy. I wish I knew where to find it, but there was some allegedly logical reason. I think it had to do with the site knowing which server to talk to? I wish I could remember more.
Re: Pwn2Own owned all major browsers
#38Earlier quoted context omitted.
Poor Vupen. Their Safari exploit must have broke.
Or they aren't about to kill the same bug in MobileSafari, since it is worth exponentially more. https://twitter.com/i0n1c/status/309585202810867712
So that logic does not explain to me why people are going after Chrome but not Safari.
I honestly don't know why it is. In particular, I don't have specific reason to believe Mac Safari's sandbox is more bulletproof than Windows Chrome's, but I guess Safari has the advantage of not being exposed to Windows kernel bugs.
Re: Pwn2Own owned all major browsers
#39Interesting how Java was pwned thee times in spite of the lowest reward.
We've seen Java bugs in the news lately for use in co-ordinated attacks against large companies. A nameless firm (not the one I'm working with now) that happens to be one of Europes largest banks has insainly locked down versions windows, everything disabled, some custom thing that has hooked NT kernel functiosn to check which image is being loaded to be executed. And then it has Java. A very old, un-patched version…
Re: Pwn2Own owned all major browsers
#40Earlier quoted context omitted.
Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.
I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward. I've always wondered if it's intelligence agencies, criminal organizations, police organiz…
Quite some hackers are a really special (in a good way) kind of people who are in it only for the intellectual challenge.
Now food for thoughts:
Rudyard Kipling once warned students against an over-concern for money, position or glory, he said: “Some day you will meet a man who cares for none of these things. Then you will know how poor you are..."