Live data from Hacker News

Pwn2Own owned all major browsers

h30499.www3.hp.com

31–40 of 67 posts

Re: Pwn2Own owned all major browsers

#32
post #17
post #6

Earlier quoted context omitted.

Safari is a target in the event, but has not been pwned yet: Wednesday: 1:30 - Java (James Forshaw) PWNED 2:30 - Java (Joshua Drake) PWNED 3:30 - IE 10 (VUPEN Security) PWNED 4:30 - Chrome (Nils & Jon) PWNED 5:30 - Firefox (VUPEN Security) PWNED 5:31 - Java (VUPEN Security) PWNED Thursday: 12pm - Flash (VUPEN Security) 1pm - Adobe Reader (George Hotz) 2pm - IE 10 (Pham Toan) Interestingly enough, last year it was the…

Poor Vupen. Their Safari exploit must have broke.

Or they aren't about to kill the same bug in MobileSafari, since it is worth exponentially more.

https://twitter.com/i0n1c/status/309585202810867712

Re: Pwn2Own owned all major browsers

#33
post #22
post #14

woah! whats with the hp site permalink/URI/url formatting? http://h30499.www3.hp.com/

What's wrong with that? Seems perfectly fine to me.

If I didn't know my computer stuff, I would say it's a virus website.

What's that h30499? www3?

Why not communities.hp.com? (this actually redirects to h30507.www3.hp.com). h30500 asks for httpauth.

It's just ugly, is it not?

Re: Pwn2Own owned all major browsers

#34
post #25

Earlier quoted context omitted.

Maybe not as cash. But on a resume?

I get the impression that dsl is a pretty successful person IRL already.

All the more reason to disclose the 0day.

If not for money or recognition, just plain simply for the users.

Re: Pwn2Own owned all major browsers

#35
post #14

woah! whats with the hp site permalink/URI/url formatting? http://h30499.www3.hp.com/

You know, I've actually seen a pretty useful writeup on why HP urls are so crazy. I wish I knew where to find it, but there was some allegedly logical reason. I think it had to do with the site knowing which server to talk to? I wish I could remember more.

Re: Pwn2Own owned all major browsers

#36
post #16

Earlier quoted context omitted.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward. I've always wondered if it's intelligence agencies, criminal organizations, police organiz…

people have ethics.

Re: Pwn2Own owned all major browsers

#37
post #14

woah! whats with the hp site permalink/URI/url formatting? http://h30499.www3.hp.com/

You know, I've actually seen a pretty useful writeup on why HP urls are so crazy. I wish I knew where to find it, but there was some allegedly logical reason. I think it had to do with the site knowing which server to talk to? I wish I could remember more.

If this is the reason, thats a horrible way to do it. Would love to know whats their thinking behind this.

Re: Pwn2Own owned all major browsers

#38
post #17

Earlier quoted context omitted.

Poor Vupen. Their Safari exploit must have broke.

Or they aren't about to kill the same bug in MobileSafari, since it is worth exponentially more. https://twitter.com/i0n1c/status/309585202810867712

WebKit code execution against Chrome is also likely to work (in modified form, but same basic exploit) against desktop or mobile Safari. Desktop Safari sandbox escape is likely to be completely different from MobileSafari sandbox escape. And in all three cases, the sandbox escape is the harder part.

So that logic does not explain to me why people are going after Chrome but not Safari.

I honestly don't know why it is. In particular, I don't have specific reason to believe Mac Safari's sandbox is more bulletproof than Windows Chrome's, but I guess Safari has the advantage of not being exposed to Windows kernel bugs.

Re: Pwn2Own owned all major browsers

#39

Interesting how Java was pwned thee times in spite of the lowest reward.

We've seen Java bugs in the news lately for use in co-ordinated attacks against large companies. A nameless firm (not the one I'm working with now) that happens to be one of Europes largest banks has insainly locked down versions windows, everything disabled, some custom thing that has hooked NT kernel functiosn to check which image is being loaded to be executed. And then it has Java. A very old, un-patched version…

The federal government agency i deal with has similarly locked down computers but, as you say, java, old versions of browsers, and many unsigned applets.

Re: Pwn2Own owned all major browsers

#40
post #16

Earlier quoted context omitted.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward. I've always wondered if it's intelligence agencies, criminal organizations, police organiz…

"I also don't understand why people give good zero days away for free..."

Quite some hackers are a really special (in a good way) kind of people who are in it only for the intellectual challenge.

Now food for thoughts:

Rudyard Kipling once warned students against an over-concern for money, position or glory, he said: “Some day you will meet a man who cares for none of these things. Then you will know how poor you are..."

Post reply on HN