Showing posts with label Chrome. Show all posts
Showing posts with label Chrome. Show all posts

Thursday, March 7, 2013

Successfully hacked Chrome, Firefox, IE 10, Java, Win 8


At Pwn2Own hacking  contest was successfully hacked Chrome, Firefox, IE 10, Java, Win 8


The first day of competition Pwn2Own, held each year at the conference CanSecWes, proved fruitful as ever - were demonstrated working industry practices previously unknown vulnerabilities in Chrome, Firefox, IE 10, Windows 8 and Java. In all cases, the attack was carried out in the processing in the browser specially decorated web-pages, the opening of which ended with complete control over the system. When demonstrating the attack relies on the most recent stable releases of browsers and operating systems Windows 7, 8 and Mac OS X Mountain Lion with all available updates in the default configuration.

In accordance with the terms of the tender, the detailed information of all the demonstrated 0-day vulnerabilities will be published only after the release of the manufacturers updates with the removal of these vulnerabilities. Part of the success of this year's Pwn2Own is associated with a significant increase in the amount of remuneration. For example, for the demonstration of hacking Chrome browser will be paid compensation of 100 thousand dollars for hacking IE - 75,000 dollars for hacking Firefox - 60 thousand dollars for hacking Safari - 65 thousand dollars, for breaking through the IE plug-in Adobe Reader XI - 70,000 dollars for breaking plugins for Adobe Flash and Java on 20 thousand dollars. At the same time the competition will be held adjacent Pwnium, which will be offered to break the Chrome OS on the device Samsung Series 5550 Chromebook. The total prize fund will Pwnium 3.14159 million and the maximum amount of compensation - 150 thousand dollars.

Friday, October 12, 2012

Teenager found new critical vulnerability in Chrome


Young hacker Pinkie Pie can become a millionaire, receiving thousands of Google for each working exploit.

Yesterday at a conference Hack in the Box during the contest Pwnium 2 young talent has shown a couple of critical vulnerabilities in Chrome and working exploit for which he was awarded a monetary reward.

Vulnerability of an ID CVE-2012-5112, a detailed description of our issue tracker, tickets 117 715 and 117 736, as well as a blog Chromium. The first bug is associated with an error at rendering SVG-files engine WebKit, and the second bug was found in the system IPC (inter-process data transfer), which allowed to go beyond the sandbox. The result was to make NPAPI-browser plug-in that gets full privileges on the system.

This is the second time that Pinkie Pie earns thousand in the last time he scored in March 2012 for the first competition Pwnium. At the time, he was able to be chained six vulnerabilities to get out of the sandbox and get Chrome to execute arbitrary code on the system. Now, apparently, the exploit uses only two vulnerabilities, but the result is the same.