Results 1 to 10 of 10

Thread: Pwn2Own Hacker Challenge

  1. #1

  2. #2
    AK47 Pew Pew Maplassie's Avatar
    Join Date
    Feb 2009
    Location
    on the Drag Strip
    Posts
    10,775

    Default

    Dammit no mention of Angelina Jolie

  3. #3

    Default

    lol...I bet MS, FF and Apple were wishing they had these guys on their team of developers
    This user has a spatula. We don't know why but we are afraid!

  4. #4

    Default

    That is quite hectic... taking full control of a windows 7 machine using a Fire Fox vulnerability... that is something else. Glad I switched to Opera Unfortunately I still have IE can never win...

  5. #5

    Default

    lol these guys are pro

  6. #6
    tpex's Avatar
    Join Date
    Feb 2009
    Location
    The 031
    Posts
    4,438

    Default

    Can somebody post for us poor souls left with just local?

    Quote Originally Posted by SirGuppie View Post
    That is quite hectic... taking full control of a windows 7 machine using a Fire Fox vulnerability... that is something else. Glad I switched to Opera Unfortunately I still have IE can never win...
    They fixed the exploit 2 days ago, 1 day after it was found out.....

  7. #7

    Default

    For tpex


    VANCOUVER, BC — Jumping through a series of anti-exploit roadblocks, Dutch hacker Peter Vreugdenhil pulled off an impressive CanSecWest Pwn2Own victory here, hacking into a fully patched 64-bit Windows 7 machine using a pair of Internet Explorer vulnerabilities.


    Vreugdenhil, an independent researcher who specializes in finding and exploiting client-side vulnerabilities, used several tricks to bypass ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention), two significant security protections built into the Windows platform.

    [ ALSO SEE: Pwn2Own MacBook attack: Charlie Miller hacks Safari again ]

    “I started with a bypass for ALSR which gave me the base address for one of the modules loaded into IE. I used that knowledge to do the DEP bypass,” he added.

    Vreugdenhil, who won a $10,000 cash prize and a new Windows machine, said he uses fuzzing techniques to find software vulnerabilities. “I specifically looking through my fuzzing logs for a bug like this because I could use it to do the ASLR bypass, he said.

    After finding the IE 8 vulnerability, Vreugdenhil said it took about two weeks to write an exploit to get around the ASLR+DEP mitigations.

    [ ALSO SEE: Pwn2Own 2010: iPhone hacked, SMS database hijacked ]

    Members of Microsoft’s IE team were on hand to witness Vreugdenhil’s exploit. A company spokesman said they were not yet aware of the details of the vulnerability but will activate its security response process once the information is collected from the contest organizers.

    TippingPoint Zero Day Initiative (ZDI), the company sponsoring the hacker challenge, is expected to send the flaw details to all the affected vendors on Friday March 26, 2010.

  8. #8
    tpex's Avatar
    Join Date
    Feb 2009
    Location
    The 031
    Posts
    4,438

    Default

    thanks



    10 words

  9. #9
    McGuywer's Avatar
    Join Date
    Jun 2009
    Location
    Pretoria, Suid Afrika
    Posts
    1,196

    Default

    With enough motivation and resources, anything is possible...

  10. #10

    Default

    Interesting

    Google Chrome was not hacked 2 years in a row

    http://blogs.forbes.com/firewall/201...hon-unscathed/

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •