Safari and IE8 broken in moments at pwn2own

Powered by SC Magazine
 

Contest hacker no-show continues Google Chrome's reign as most-secure browser.

Apple's Safari browser was the first to be broken at this year's pwn2own contest at the CanSecWest conference in Vancouver.

Safari, being run on a fully patched Mac OSX, was exploited by vulnerability research company Vupen. It said on its Twitter feed that it "pwned Apple Safari on Mac OS X (x64) at pwn2own in five seconds. Congrats to all VUPEN team members for their hard work."

It previously commented that Apple had released Safari 5.0.4 and iOS 4.3 a few minutes before the pwn2own contest, yet it was able to break the up-to-date software by successfully exploiting a zero-day flaw. Vupen won $24,000 and a 13-inch MacBook Air.

Shortly afterwards, Stephen Fewer from vulnerability research and consultancy company Harmony, tweeted that he had "just popped ie8 at pwn2own". Fewer received a laptop and $15,000.

Aaron Portnoy, manager of the security research team at Pwn2Own sponsor Tipping Point, pointed out that Fewer had successfully compromised Internet Explorer with a Protected Mode bypass switched on.

According to eWeek, the two contestants who signed up to hack Google Chrome did not show up meaning that it was the most secure browser for the second year running and got to keep its $20,000 prize.

Technical details of the exploits legally belong to TippingPoint under contest rules; they provide information to Microsoft and Apple and give them six months to fix the flaws before publicising them.

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, US edition


 
 
 
Top Stories
Australia passes data retention into law
Mammoth last-ditch effort by Greens, indies knocked back.
 
Turnbull introduces bill to block piracy websites
Takes ownership of legislation from Brandis.
 
ATO to kill off e-Tax
Veteran software to be replaced by more modern myTax.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Xero now includes an inventory function built-in
Mar 26, 2015
Xero has added inventory and other major new features to the latest release of its cloud ...
Apple reveals its new MacBook
Mar 13, 2015
Replacing the MacBook Air as Apple's thinnest laptop, the new MacBook comes packed with features.
Xero has released a new version of its app for the iPad
Mar 6, 2015
iPad-wielding Xero users can now take advantage of a new version of the iOS app for the cloud ...
Microsoft is offering Azure for Disaster Recovery to Australian SMBs
Feb 10, 2015
If you haven't talked to your IT provider about disaster recovery, it might be worth discussing ...
The 2015 Xero Roadshow is on: here are the locations and dates
Feb 6, 2015
The 2015 Xero Roadshow kicked off this week - see where you can attend at locations around ...
Latest Comments
Polls
Do you support the Government's data retention scheme?

   |   View results
Yes
  8%
 
No
  92%
TOTAL VOTES: 1327

Vote