Live data from Hacker News

Pwn2Own owned all major browsers

h30499.www3.hp.com

51–60 of 67 posts

Re: Pwn2Own owned all major browsers

#51

Considering Chrome had a last minuite patch applied http://nakedsecurity.sophos.com/2013/03/06/last-minute-pre-p... It's good to know it still got taken down, because I had a horrible fear they where going to try and advertise they were 100% safe because they weren't exploited.

There's no last minute patch. We push security and stability updates every 2-3 weeks. Just go look at our release history to verify. As for your other claim, it's so absurdly off base that it doesn't warrant an explicit response.

Which is fair enough, I'm in no way going to suggest having a reactive security update schedule is a bad thing.

However the time of the conference could easily give a vendor that had a compatable release cycle a slight edge.

When I read that story (before hearing the results) I was filled with a kind of dread, I am less than impressed about the claims for Chrome OS, in the UK where its advertised it strikes me as Apple during the bad days who simply advocated bad pratice with regards to security (you've bought us, don't worry) type thing.

If you feel that is at all unfair to you, I am sorry, but Google Chrome has been an agressively marketed product in London and I have general contempt for most of the adds (but then I'm not the target market).

I also think its really important to remind people just how unsafe browsers are (all of them) and how people need to be increasingly aware of the impact such security.

Side Note: If your one of the team, thanks, yours has been my favourite browser for years now :)

Re: Pwn2Own owned all major browsers

#52

Earlier quoted context omitted.

Or they aren't about to kill the same bug in MobileSafari, since it is worth exponentially more. https://twitter.com/i0n1c/status/309585202810867712

WebKit code execution against Chrome is also likely to work (in modified form, but same basic exploit) against desktop or mobile Safari. Desktop Safari sandbox escape is likely to be completely different from MobileSafari sandbox escape. And in all three cases, the sandbox escape is the harder part. So that logic does not explain to me why people are going after Chrome but not Safari. I honestly don't know why it is.…

Yeah, the WebKit exploit will work effectively unmodified on Safari. And the sandbox escape used against Chrome on Windows was a kernel bug in surface that can't be turned of from user-space (or really at all on Win7). Also, they softened the target quite a bit by using 32-bit Win7 for the contest, rather than 64-bit Win8 (or even 64-bit Win7).

As for why no one's targeting Safari, I think it's simple market forces at play. The iOS exploit market is established and pays very well, while the core vulnerabilities, expertise, and techniques are all shared with Safari on Mac OSX. And since Safari isn't a soft target (in no small part due to Abhishek's mass slaughter of WebKit security bugs and our bounty program), $65k just doesn't compete with the real-world exploit market.

Re: Pwn2Own owned all major browsers

#53

Earlier quoted context omitted.

We've seen Java bugs in the news lately for use in co-ordinated attacks against large companies. A nameless firm (not the one I'm working with now) that happens to be one of Europes largest banks has insainly locked down versions windows, everything disabled, some custom thing that has hooked NT kernel functiosn to check which image is being loaded to be executed. And then it has Java. A very old, un-patched version…

Do these "insanely locked down" Windows have a browser and does that browser enable Java applets? The 0-days affecting Java lately have all been using Java applets and drive-by exploits. I'm not saying it's not pathetic and lame for Java's security track records but it's not either as if your company was vulnerable to remote exploits in the case Java applets are not allowed in browsers. I'm running Java webapp server…

Guess how they distrabute the Java application.

However I really don't want to go too far into a former clients site details, just to say it was a laughably big gaping hole, that is really quite common in a lot of large enterprises. It was also completely seperate from my domain there)

Re: Pwn2Own owned all major browsers

#54
post #16

Earlier quoted context omitted.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward. I've always wondered if it's intelligence agencies, criminal organizations, police organiz…

>I've always wondered if it's intelligence agencies, criminal organizations, police organizations, or commercial endeavors that sell services to those three bodies that are paying that kind of money for zero days.

According to this article: 3rd party middlemen, small security firms and large defense contractors are the ones paying for 0-days. There's also has a nice price list for Chrome, IOS, etc.

http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...

Re: Pwn2Own owned all major browsers

#55
post #47

Earlier quoted context omitted.

If I didn't know my computer stuff, I would say it's a virus website. What's that h30499? www3? Why not communities.hp.com? (this actually redirects to h30507.www3.hp.com). h30500 asks for httpauth. It's just ugly, is it not?

> If I didn't know my computer stuff, I would say it's a virus website. If you didn't know your computer stuff you wouldn't have ever noticed the URL.

I could be a basic user that knows how to avoid clicking strange links to avoid email viruses.

I could know enough to notice the URL, but not enough to know that the domain hp.com is what really counts.

Re: Pwn2Own owned all major browsers

#57
post #36

Earlier quoted context omitted.

people have ethics.

They also have to eat.

You're assuming that they have to make their living 'hacking'. If instead they have an oil well in the back yard providing a steady paycheck (I live in Texas, and know people just like this), they have plenty time for non-profit endeavors.

Re: Pwn2Own owned all major browsers

#58
post #49

Earlier quoted context omitted.

http://daringfireball.net/linked/2010/03/09/hp-license-plate...

Thanks for the link. This is crazy. SquareWheel was right. This is an absolutely brain-dead way of doing this, by a very incompetent IT admin.

And yet that it persists brings to mind all the problems faced by large organizations. An inability to change processes, execute quickly on decisions, disconnect between customers and company operations. Which is why startups can disrupt them. Pretty much everything HP produces seems mediocre and of substandard quality including their printers, ink, devices, services such as their open stack cloud offerring.

Re: Pwn2Own owned all major browsers

#59
Few silly questions: 1) I got the feeling from this discussion and some other sources that there are a couple of known Windows kernel vulnerabilities that are making these exploitation easier. What about Microsoft? They don't care or are they fixing those bugs?

2) How secure is let's say Firefox + Ubuntu/Fedora, latest updates, default settings. I haven't seen that many exploits for Linux in general. Is it because no one cares about linux or because it is harder and thus more valuable than windows exploits so no one share linux ones?

Re: Pwn2Own owned all major browsers

#60

Earlier quoted context omitted.

They have the exploits ready to go, the challenge is whether they can exploit the target system (which is fully patched) within their time slot. It's a useful excercise, I think, in that it demonstrates that even the most hardened of codebases still has security bugs and it also serves as a cautionary tale for people who think they don't need multiple layers of defence..

"...it demonstrates that even the most hardened of codebases still has security bugs" Browsers the most hardened codebase? I nearly spilled my coffee ; ) Every single browsers out there (including Chrome) was designed with security as an after-thought. As for me I browse the Web from Linux, using a throwaway user account which doesn't have Java installed. And that user account is itself "hardened" (e.g. no login shel…

if you trust linux or theo for security, you're going to have a bad time.
Post reply on HN