Stuxnet, RSA and Sony score pwnies

Powered by SC Magazine
 

Stuxnet 0wned, Sony failed, and RSA lamed-out.

It was Sony who stole the Black Hat pwnie awards, with all five pwnie nominations for ‘most epic fail' scooping awards.

A total of nine awards were due to be presented in categories including most innovative research, most epic fail and ‘lamest vendor response'.

The wins were for erasing PS3 jailbreak information after it was published online, failing to protect between 25 to 77 million user account details, LulzSec's ‘sownage' campaign, shutting down their PlayStation Network and laying off a significant number of its network security team.

The pwnie for epic 0wnage, given to the hackers responsible for delivering the ‘most damaging, widely publicised or hilarious 0wnage', went to Stuxnet. The pwnies said: “How many centrifuges did your rootkit destroy? How many national nuclear programs did your worm disrupt? How many zero-day exploits and rootkits for equipment, that no one you have ever heard of, have you written? Exactly.”

Among the bug gongs, the award for Best Privilege Escalation Bug went to Tarjei Mandt for ‘Windows kernel win32k user-mode callback vulnerabilities' (MS11-034) which Microsoft patched in April 2011.

The pwnies said: “In the span of a few months, Tarjei found more than 40 vulnerabilities in the Windows kernel. In his presentation at Infiltrate 2011, he described the details of these vulnerabilities and his kernel exploitation techniques.”

The pwnie award for ‘lamest vendor response' went to RSA for its SecurID token compromise, which the pwnies said the company had ‘basically passed it off as a non-event and advised customers that replacing the tokens is not necessary, until Lockheed-Martin got attacked because of them.”

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, US edition


Stuxnet, RSA and Sony score pwnies
Tags
 
 
 
Top Stories
Matching databases to Linux distros
Reviewed: OS-repository DBMSs, MariaDB vs MySQL.
 
Coalition's NBN cost-benefit study finds in favour of MTM
FTTP costs too much, would take too long.
 
Who'd have picked a BlackBerry for the Internet of Things?
[Blog] BlackBerry has a more secure future in the physical world.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  70%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  12%
 
Denial of service attacks
  6%
 
Insider threats
  10%
TOTAL VOTES: 702

Vote