Safari and IE8 broken in moments at pwn2own

Powered by SC Magazine
 

Contest hacker no-show continues Google Chrome's reign as most-secure browser.

Apple's Safari browser was the first to be broken at this year's pwn2own contest at the CanSecWest conference in Vancouver.

Safari, being run on a fully patched Mac OSX, was exploited by vulnerability research company Vupen. It said on its Twitter feed that it "pwned Apple Safari on Mac OS X (x64) at pwn2own in five seconds. Congrats to all VUPEN team members for their hard work."

It previously commented that Apple had released Safari 5.0.4 and iOS 4.3 a few minutes before the pwn2own contest, yet it was able to break the up-to-date software by successfully exploiting a zero-day flaw. Vupen won $24,000 and a 13-inch MacBook Air.

Shortly afterwards, Stephen Fewer from vulnerability research and consultancy company Harmony, tweeted that he had "just popped ie8 at pwn2own". Fewer received a laptop and $15,000.

Aaron Portnoy, manager of the security research team at Pwn2Own sponsor Tipping Point, pointed out that Fewer had successfully compromised Internet Explorer with a Protected Mode bypass switched on.

According to eWeek, the two contestants who signed up to hack Google Chrome did not show up meaning that it was the most secure browser for the second year running and got to keep its $20,000 prize.

Technical details of the exploits legally belong to TippingPoint under contest rules; they provide information to Microsoft and Apple and give them six months to fix the flaws before publicising them.

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, US edition


 
 
 
Top Stories
Australia's digital crescendo
Barely unpacked from his move from Amsterdam, Southern Cross Austereo's new digital boss Vijay Solanki is looking for Australia's untapped potential.
 
Turnbull nabs UK govt digital guru as DTO chief
Inaugural CEO to lead change agenda.
 
NBN to offer TV connections through fibre for greenfields
Ditching aerials to come at a cost.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Xerocon is heading to Melbourne!
Jul 1, 2015
We're not saying Xero is our FAVOURITE or anything, but Xero's 2015 Xerocon conference is being ...
New Microsoft Office apps for Android phones
Jun 26, 2015
Microsoft's latest Office apps for Android now work on phones as well as tablets, further ...
Windows 10 UK price revealed, but don't believe everything you hear
Jun 26, 2015
Windows 10 £99 price tag for users in the UK (who presumably don't already have Win 7 Pro ...
Now Xero notifies iOS users of new transactions
Jun 24, 2015
The latest version of Xero's iPhone app includes notifications when new transactions arrive from ...
Your Essential Cloud Toolbox
Jun 22, 2015
When BIT interviewed Receipt Bank country manager Sophie Hossack, we asked for her thoughts on ...
Latest Comments
Polls
Is site blocking effective in stopping piracy?


   |   View results
Yes
  2%
 
No
  86%
 
Somewhat
  12%
TOTAL VOTES: 723

Vote