Stuxnet, RSA and Sony score pwnies

Powered by SC Magazine
 

Stuxnet 0wned, Sony failed, and RSA lamed-out.

It was Sony who stole the Black Hat pwnie awards, with all five pwnie nominations for ‘most epic fail' scooping awards.

A total of nine awards were due to be presented in categories including most innovative research, most epic fail and ‘lamest vendor response'.

The wins were for erasing PS3 jailbreak information after it was published online, failing to protect between 25 to 77 million user account details, LulzSec's ‘sownage' campaign, shutting down their PlayStation Network and laying off a significant number of its network security team.

The pwnie for epic 0wnage, given to the hackers responsible for delivering the ‘most damaging, widely publicised or hilarious 0wnage', went to Stuxnet. The pwnies said: “How many centrifuges did your rootkit destroy? How many national nuclear programs did your worm disrupt? How many zero-day exploits and rootkits for equipment, that no one you have ever heard of, have you written? Exactly.”

Among the bug gongs, the award for Best Privilege Escalation Bug went to Tarjei Mandt for ‘Windows kernel win32k user-mode callback vulnerabilities' (MS11-034) which Microsoft patched in April 2011.

The pwnies said: “In the span of a few months, Tarjei found more than 40 vulnerabilities in the Windows kernel. In his presentation at Infiltrate 2011, he described the details of these vulnerabilities and his kernel exploitation techniques.”

The pwnie award for ‘lamest vendor response' went to RSA for its SecurID token compromise, which the pwnies said the company had ‘basically passed it off as a non-event and advised customers that replacing the tokens is not necessary, until Lockheed-Martin got attacked because of them.”

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, US edition


Stuxnet, RSA and Sony score pwnies
Tags
 
 
 
Top Stories
Change is the only constant at iiNet
iiNet's Matthew Toohey is trialling IBM's Watson - between preparing for an acquisition and making sure Netflix doesn't swamp the network.
 
Why straight-through processing is the holy grail for banks
Big benefits from stripping away human intervention and digitising processes.
 
CBA sued over frozen millions in IT bribery scandal
Eric Pulier's not-for profit lodges lawsuit in US.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Should Optus make a bid for iiNet?

   |   View results
Yes
  44%
 
No
  56%
TOTAL VOTES: 668

Vote