AfterDawn: Tech news

Pwn2Own: Chrome, Android, Firefox own; Safari, IE8, iOS, BB get pwned

Written by Andre Yoskowitz @ 11 Mar 2011 3:08 User comments (11)

Pwn2Own: Chrome, Android, Firefox own; Safari, IE8, iOS, BB get pwned Two days into the Pwn2Own hacking challenge, only a few still remain.
So far, hackers have not been able to exploit Mozilla Firefox 3.6, Google Chrome, and the mobile Android OS.

Victims of the contest include Internet Explorer 8, Apple Safari 5, iOS 4 and BlackBerry.

All the security researchers who manage to exploit the browsers or operating systems take home a cash prize of $15,000 and a laptop. If Chrome gets beaten, the researcher takes home $20,000.

Charlie Miller beat the iPhone 4 with iOS and has taken home the prize in 2007, 2009, 2010 and this year.

Firefox fixed 10 security flaws the day before the contest started, and Google fixed 9. Chrome has yet to be defeated since its launch in 2008, while Firefox was beaten in 2009 and 2010.



Security researchers from VUPEN beat Safari 5, rather easily: "We pwned Apple Safari on Mac OS X (x64) at Pwn2Own in 5 seconds."

Tags: Chrome Pwn2Own
Previous Next  

11 user comments

111.3.2011 17:01

So much for the whole Apples can NEVER get a virus B.S.

211.3.2011 17:26
lissenup2
Inactive

Originally posted by jookycola:
So much for the whole Apples can NEVER get a virus B.S.
That was never the case but blinded Apple users firmly believe that it is.


On another note, I gotta change my profession and just hack the world away and get payouts like this for an income.

311.3.2011 17:36

According to the article about Pwn2Own on Ars Technica a new set of rules this year for the competition state that the clients were "frozen" a week before competition started and if a hackers flaw worked on the "frozen" version they would "Own" the hardware.

However, if the hacker wanted the cash the flaw must exist in a fully-patched version, even if it was released the day of Pwn2Own:

http://arstechnica.com/security/news/2011/03/pwn2own-day-one-safari-ie8-fall-chrome-unchallenged.ars

411.3.2011 18:31
lissenup2
Inactive

Originally posted by Pop_Smith:
According to the article about Pwn2Own on Ars Technica a new set of rules this year for the competition state that the clients were "frozen" a week before competition started and if a hackers flaw worked on the "frozen" version they would "Own" the hardware.

However, if the hacker wanted the cash the flaw must exist in a fully-patched version, even if it was released the day of Pwn2Own:

http://arstechnica.com/security/news/2011/03/pwn2own-day-one-safari-ie8-fall-chrome-unchallenged.ars


Oh man.........what you just said was like hieroglyphics to me.

511.3.2011 18:42

Originally posted by Pop_Smith:
According to the article about Pwn2Own on Ars Technica a new set of rules this year for the competition state that the clients were "frozen" a week before competition started and if a hackers flaw worked on the "frozen" version they would "Own" the hardware.

However, if the hacker wanted the cash the flaw must exist in a fully-patched version, even if it was released the day of Pwn2Own:

http://arstechnica.com/security/news/2011/03/pwn2own-day-one-safari-ie8-fall-chrome-unchallenged.ars
Idk about you brother, but I want to the $15k, I don't care about being able to say I "owned" the browser lol

611.3.2011 21:56

Originally posted by lissenup2:
Oh man.........what you just said was like hieroglyphics to me.
Basically, if you hack the browser you get the hardware (the laptop) it was setup on. If your hack also works on the latest version (even if it was released the day of Pwn2Own) you get $15k in cash and the hardware.

Originally posted by DVDBack23:
Idk about you brother, but I want to the $15k, I don't care about being able to say I "owned" the browser lol
For sure, I'm in that same boat. I'd much rather have $15-20k in cash instead of a $1000-$2500 laptop. As I stated above, I believe you get both the hardware and the cash if your hack works on the newest version of the browser.

712.3.2011 01:16

Originally posted by jookycola:
So much for the whole Apples can NEVER get a virus B.S.

While too many devotees imply NO viruses on a Mac, they're still very rare to come by...especially the nasty ones. Of course, if people knew what they were doing with their computers (no matter what OS), they wouldn't need ANY protection other than their good sense.

812.3.2011 03:08

OSX viruses are a bit like OSX software...hard to find and lacking capabilities.

912.3.2011 09:06

Anyone that still uses Safari... Well I wouldn't say they deserve to get hacked, but c'mon, get with the times...

1013.3.2011 23:45

Safari might not be as good as freeware, but at least it is better than Internet Exploiter; they didn't even bother including it in the competition...that would have been like shooting fish in a barrel, with a shotgun.

1114.3.2011 14:32

Originally posted by KillerBug:
Safari might not be as good as freeware, but at least it is better than Internet Exploiter; they didn't even bother including it in the competition...that would have been like shooting fish in a barrel, with a shotgun.

Quote:
Pwn2Own: Chrome, Android, Firefox own; Safari, IE8, iOS, BB get pwned
I think you missed that but, but your comment about how bad it is still stands.
Also any gun will kill a fish in a barrel, even a .22
This message has been edited since its posting. Latest edit was made on 14 Mar 2011 @ 2:34

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive