Results 1 to 5 of 5

Thread: Pwn2Own hacking contest 2013 shaping up

  1. #1
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Pwn2Own hacking contest 2013 shaping up

    http://nakedsecurity.sophos.com/2013...alf-a-million/

    So the prize fund for this years pwn 2 own competition has been announced.

    What is interesting is this year they have done away with the point system, and instead assigned an amount per exploit.

    Why is this interesting? Because JAVA is considered so comparatively easy, an exploit is only worth $20k.

    Also IE 9 on Windows 7, is considerably less than Chrome. (IE10 is the same price).

    Safari gets an honerable mention being the only browser targetted on OS X.



    With java having such a low price attributed to its difficulty, it begs the question again, should anyone be running it whilst oracle dither about.
    throw new ArgumentException (String, String, Exception)

  2. #2
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,232
    Thanked
    2,290 times in 1,873 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Pwn2Own hacking contest 2013 shaping up

    For website plugins, probably not.

    Then again, I guess it's not unlike most software - unless you trust the source of the codebase you're running, you probably shouldn't run it. The web's an easy infection vector, because most people think of website as "content", rather than "software" - back when I started out as a web designer that probably wasn't too much of a problem, but given the inexorable drive towards the web as a development and distribution platform (rather than a text-sharing protocol) I'd guess that it's not far off being the majority of software that's now web-delivered and hosted. It makes it a lot easier to slip malicious software onto a system when you don't have to have users download and install it...

  3. #3
    Oh Crumbs.... Biscuit's Avatar
    Join Date
    Feb 2007
    Location
    N. Yorkshire
    Posts
    11,193
    Thanks
    1,394
    Thanked
    1,091 times in 833 posts
    • Biscuit's system
      • Motherboard:
      • MSI B450M Mortar
      • CPU:
      • AMD 2700X (Be Quiet! Dark Rock 3)
      • Memory:
      • 16GB Patriot Viper 2 @ 3466MHz
      • Storage:
      • 500GB WD Black
      • Graphics card(s):
      • Sapphire R9 290X Vapor-X
      • PSU:
      • Seasonic Focus Gold 750W
      • Case:
      • Lian Li PC-V359
      • Operating System:
      • Windows 10 x64
      • Internet:
      • BT Infinity 80/20

    Re: Pwn2Own hacking contest 2013 shaping up

    Does seem bizzare that they would only test safari in OSX, why not test that in windows aswell? Why not test chrome on OSX?

  4. #4
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,232
    Thanked
    2,290 times in 1,873 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Pwn2Own hacking contest 2013 shaping up

    Market penetration? I imagine safari on Windows and Chrome on OS X are fairly small percentages. Makes sense that they'd price according to how widespread an exploit could be.

  5. #5
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Pwn2Own hacking contest 2013 shaping up

    OS X is generally considered to be less secure than windows 8, due to certain issues with key technologies. Apple are really quite new to the secure computing world, instead normally relying on the whole "user privledge" thing.

    When you consider how advanced some of the statistics involved in defeating ASLR are becoming, a lot of these attacks amount to the same thing.

    Break the Browser, this is actually complex, is it via rendering, via script engine, or what?
    Break the sandbox, all browsers now use a sandbox, which in theory is inescapable.
    Break the OS, in theory all OSes do not allow you to do anything beyond the privledge of the user.

    Increasingly the last one isn't needed. For instance the MacDefender was *very* sucessful when you consider how few there are in the wild.

    The rewards are based on the pericieved difficulty of each task, Chrome and IE10on8 are percieved to have the most convoluted and complex security systems.
    throw new ArgumentException (String, String, Exception)

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •