Live data from Hacker News

Pwn2Own owned all major browsers

h30499.www3.hp.com

61–67 of 67 posts

Re: Pwn2Own owned all major browsers

#61

Earlier quoted context omitted.

WebKit code execution against Chrome is also likely to work (in modified form, but same basic exploit) against desktop or mobile Safari. Desktop Safari sandbox escape is likely to be completely different from MobileSafari sandbox escape. And in all three cases, the sandbox escape is the harder part. So that logic does not explain to me why people are going after Chrome but not Safari. I honestly don't know why it is.…

Yeah, the WebKit exploit will work effectively unmodified on Safari. And the sandbox escape used against Chrome on Windows was a kernel bug in surface that can't be turned of from user-space (or really at all on Win7). Also, they softened the target quite a bit by using 32-bit Win7 for the contest, rather than 64-bit Win8 (or even 64-bit Win7). As for why no one's targeting Safari, I think it's simple market forces a…

Getting sandbox escapes from Mac Safari and iOS Safari requires completely different exploits. The code execution stage of a complete exploit could be shared, but it could also be shared with Chrome. So you'd think the same argument of iOS Safari exploit market value would apply either way.

My theory is that not much research has been done yet on breaking the WebProcess sandbox. Which makes me sad.

Re: Pwn2Own owned all major browsers

#62

Earlier quoted context omitted.

Yeah, the WebKit exploit will work effectively unmodified on Safari. And the sandbox escape used against Chrome on Windows was a kernel bug in surface that can't be turned of from user-space (or really at all on Win7). Also, they softened the target quite a bit by using 32-bit Win7 for the contest, rather than 64-bit Win8 (or even 64-bit Win7). As for why no one's targeting Safari, I think it's simple market forces a…

Getting sandbox escapes from Mac Safari and iOS Safari requires completely different exploits. The code execution stage of a complete exploit could be shared, but it could also be shared with Chrome. So you'd think the same argument of iOS Safari exploit market value would apply either way. My theory is that not much research has been done yet on breaking the WebProcess sandbox. Which makes me sad.

>Getting sandbox escapes from Mac Safari and iOS Safari requires completely different exploits.

You're focusing too narrowly on the sandbox itself. You have to consider the whole stack, and all of the surface exposed from within the sandbox. Consider the Chrome sandbox escape from yesterday, which didn't use anything specific to Chrome. It targeted part of the Windows stack that's guaranteed to be exposed to every process on the system.

Re: Pwn2Own owned all major browsers

#63
post #44

Are any vendors offering no questions asked X$/0day rewards all year long instead of dedicated events? Seems like it would be a decent move. If the going rate is really in the 50k ballpark why can't say Google offer 10-20k per Chrome exploit? Their engineers don't make peanuts and the attacks on the software happen regardless. After a year or two you'd probably have a pretty secure system for a reasonable cost. I don…

> Are any vendors offering no questions asked X$/0day rewards > all year long

Both Mozilla and Google do, but those rewards are in the $3k range.

Re: Pwn2Own owned all major browsers

#64
post #47

Earlier quoted context omitted.

If I didn't know my computer stuff, I would say it's a virus website. What's that h30499? www3? Why not communities.hp.com? (this actually redirects to h30507.www3.hp.com). h30500 asks for httpauth. It's just ugly, is it not?

> If I didn't know my computer stuff, I would say it's a virus website. If you didn't know your computer stuff you wouldn't have ever noticed the URL.

If you're trying to auth, and you get one subdomian vs. another - it's a pain in the ass for all users. That's why other big properties have unified to one domain and subroutes (e.g.: google.com - no more reader.google.com, but www.google.com/reader).

Re: Pwn2Own owned all major browsers

#65
post #16

Earlier quoted context omitted.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

I have a friend who tells me that good (windows) zero days, with remote execution, are worth about $50K on the market that transacts these things, with a contract to increase that value if their is no open disclosure. I.E. If your zero day remains a zero day for another six months, there is an opportunity to see further reward. I've always wondered if it's intelligence agencies, criminal organizations, police organiz…

$50k sounds like a lot, but if you can weather the current storm of every firm and researcher digging into Java and finding all the low hanging fruit, it could be worth $300k+ when nobody else has an undisclosed Java vulnerability.

Usually the way it works is 6 monthly payments, so you get a wire for $8,500 every month that it is not disclosed.

Re: Pwn2Own owned all major browsers

#66
post #50
post #44

Are any vendors offering no questions asked X$/0day rewards all year long instead of dedicated events? Seems like it would be a decent move. If the going rate is really in the 50k ballpark why can't say Google offer 10-20k per Chrome exploit? Their engineers don't make peanuts and the attacks on the software happen regardless. After a year or two you'd probably have a pretty secure system for a reasonable cost. I don…

Google's bug bounty is $3,133.70 (elite). The black market can pay $80k-200k+[1]. Why doesn't Google pay more? Well, like you said, "attacks on the software happen regardless". Their objective is to maximize shareholder value. People adopt browsers for other reasons besides maximum security. You hear about critical vulnerabilities all the time, to the point where you get desensitized to it. I don't think there's been…

The bug bounty is for a security bug with no exploit. That makes it a lot less work for the security researcher. See the release notes on the Google Chrome blog for details of bounties paid.

Google also sponsors Pwn2Own and Pwnium with bigger prizes for bugs with working exploits.

Re: Pwn2Own owned all major browsers

#67
post #49

Earlier quoted context omitted.

Thanks for the link. This is crazy. SquareWheel was right. This is an absolutely brain-dead way of doing this, by a very incompetent IT admin.

And yet that it persists brings to mind all the problems faced by large organizations. An inability to change processes, execute quickly on decisions, disconnect between customers and company operations. Which is why startups can disrupt them. Pretty much everything HP produces seems mediocre and of substandard quality including their printers, ink, devices, services such as their open stack cloud offerring.

Which is only now improving with Meg Whitman.
Post reply on HN