iTnews
  • Home
  • News
  • Technology
  • Security

Hacker with most scalps to win Pwn2Own 2012

By Nicole Kobie on Jan 26, 2012 1:42AM
Hacker with most scalps to win Pwn2Own 2012

Fresh 0days awarded 32 points, working exploits score 10 points.

Hacking is no longer about how fast you do it, but how completely - that's the message coming from changes to a major hacking competition.

One of the most-watched security contests of the year, Pwn2Own targets browsers, offering big prizes to whichever researcher can get through a system first.

This year, the contest has been changed to "more closely reflect the value of the exploits demonstrated," according to contest organisers HP Tipping Point, which said the new version would be a "welcome change both for the competitors as well as the spectators at the event".

Previously, the first researcher to hack a specific browser has won. This year, it's not a race to the finish; there will be only three winners, with their success based on points accumulated over the three day competition.

The contest will award 32 points for a fresh zero-day exploit, but will also announce vulnerabilities at the start of the competition, and award ten points to every working exploit created - showing the importance of patching old flaws, the company said.

"In the past, Pwn2Own has shown the importance of zero-day vulnerabilities and the fact that at any given time you are susceptible to attack regardless of your patch level," Aaron Portnoy, manager of the Security Research Team at HP TippingPoint, told InternetNews.

"What we had been ignoring is the fact that it's really important to actually patch vulnerabilities."

As usual, the contest will target browsers Internet Explorer, Firefox and Chrome on Microsoft's Windows 7 or Safari on Apple's Mac OS Lion. Last year, IE and Safari were both successfully hacked, while Firefox and Chrome were not.

HP is offering US$105,000 in prizes - with US$60,000 plus a laptop to first place - while Google has for the second year running offered an extra US$20,000 per qualifying Chrome bug.

The contest starts on 7 March at CanSecWest in Vancouver, Canada.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © Alphr, Dennis Publishing
Tags:
cansecwestpwn2ownsecurityweb browsers

Partner Content

Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance
Why Genworth Australia embraced low-code software development
Promoted Content Why Genworth Australia embraced low-code software development
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Nicole Kobie
Jan 26 2012
1:42AM
0 Comments

Related Articles

  • Twitter says zero-day bug leaked account data
  • Android apps are invasive and unsafe: study
  • ACSC and CISA detail top malware of 2021
  • Cisco small business routers need urgent patch
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Aussie Broadband nears end of NBN PoI fibre rollout

Aussie Broadband nears end of NBN PoI fibre rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Student details, photos exposed in University of WA data breach

Student details, photos exposed in University of WA data breach

Defence, DEWR drop $160m on Microsoft software, Azure

Defence, DEWR drop $160m on Microsoft software, Azure

Digital Nation

Case Study: Swinburne University overhauls student management system
Case Study: Swinburne University overhauls student management system
Case Study: Multicloud business drivers at MLC Life Insurance
Case Study: Multicloud business drivers at MLC Life Insurance
Personalisation strategies need to be built from the ground up
Personalisation strategies need to be built from the ground up
COVER STORY: Multiple cloud models make security more complex
COVER STORY: Multiple cloud models make security more complex
COVER STORY: What happens when Google changes its algorithm?
COVER STORY: What happens when Google changes its algorithm?
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.