Showing posts with label Pwn2own. Show all posts
Showing posts with label Pwn2own. Show all posts

Tuesday, 19 April 2016

Adobe: Flash Player Security Thwart Hackers


Adobe security measures in recent months have added to Flash Player ensures that hackers could not carry out successful attacks on the media player during a recent hacking contest, as the software company announced.

During the annual Pwn2Own contest hackers are rewarded for demonstrating unknown vulnerabilities in different browsers and Adobe Flash Player. During the last edition of March Flash Player was finally twice successfully hacked , but that number could be higher, says Peleus Uhley of Adobe. In preparation for the hack contest Adobe rolled several updates to enhance the security of Flash Player.

These measures paid off as several attempts to hack Flash Player failed thus said Uhley. Still, Flash Player has been successfully hacked twice. "These victories show that there is always more vendors can do to improve security," he continues. Uhley notes that companies such as Adobe, Microsoft and Google are engaged in a race with hackers.

Adobe invests in his own words than a lot of security and regularly adds features to thwart it. hackers as only goal. "Such measures are increasingly being added. The companies themselves will change on the frontline of this battle and to grow the more expensive." According Uhley help hacking contests like Pwn2Own software companies to develop. "While Pwn2Own each year seems to take the same required innovations and challenges to books every year results," said Uhley.

Saturday, 5 September 2015

HP Will Stop Sponsoring Pwn2Own Mobile Because Of Wassenaar


Computer manufacturer HP has decided the Mobile Pwn2Own competition in Japan not to sponsor this year. If reason be called the export restrictions of the Wassenaar agreement. Mobile Pwn2Own is an annual event which is part of the PacSecWest Conference in Japan.

The event is organized by the Zero Day Initiative (ZDI) of HP and has different categories where researchers feel the test the safety of popular smartphones and tablets. Compromising a mobile phone via Bluetooth, WiFi, USB or Near Field Communication (NFC) last year yielded 75 000 dollars. A successful attack via a mobile web browser HP rewarded with $ 50,000. At the last edition of the Apple iPhone 5S were Samsung Galaxy S5, LG Nexus 5 and Amazon Fire Phone hacked.The vulnerabilities that were used for this purpose had to give researchers at HP. The computer giant then informs the relevant supplier. Only when the problem is patched researchers may share the details of their vulnerability.

Wassenaar agreement

This year, HP will not sponsor the event and organize, let Dragos Ruiu know via Twitter. Ruiu, the organizer of the PacSecWest Conference. The reason is called the Wassenaar agreement. The Wassenaar agreement sets rules on goods, software and information that countries are allowed to export such technologies as "intrusion software" (pdf) are described.These are so-called "dual use" goods that can be used for multiple purposes. So stand surveillance systems on the list, but also weapons like landmines and nuclear materials. It is a voluntary agreement and it is up to countries how they apply the agreement within their own legislation. The way the US government will be implementing the rules could have far-reaching consequences, as warned Google and Microsoft before.

As a solution, said Ruiu which vulnerabilities are found given to Japanese delegates during Pwn2Own Mobile. In this way, the bugs do not need to go back to the United States. Thus Ruiu think to the export restriction bypass. Besides Pwn2Own Mobile will also find the annual Pwn2Own contest in Vancouver instead, which is part of the CanSecWest conference. As far as known HP continues to sponsor this contest and organizing. The PacSecWest Conference takes place on 11 and 12 November in Tokyo.

Sunday, 3 May 2015

Successful Chinese Hacking Team Is Looking For Math Nerds


A Chinese hacking team that in recent years during various competitions hacker vulnerabilities in popular software such as Adobe Flash Player, Windows 8.1, Apple Safari and Mac OS X Mavericks discovered is particularly looking for mathematical geniuses who are also "real geeks" are.

The Keen Team consists of over twenty highly talented hackers, although the leader himself does not mention that. "We call ourselves geeks, not hackers, because we do not want people to think we are invaders who want to destroy things," said the 37-year-old CEO Wang Qi in front of Vice Magazine . It is the first time that Chinese hackers do an interview in English.

Income

The Pwn2Own hacker contests deserved members of Keen Team tens of thousands of dollars. Yet the prize is not their main source of income. The hackers are hired by parties like Microsoft and Google to find vulnerabilities in software. How many employees earn Wang would not say, but he describes the prize of the Pwn2Own hacker contests as a nice pocket money.The CEO pointed Keen Team in 2011, before that he worked for Microsoft.

According to Wang, the standards Keen Team employs more than Microsoft's. "They should be as high as any computer or phone is touched by our research." In finding new hackers main focus is on math. Some of the members are winners of international math competitions. The best students from Chinese schools are also selected.

"You have real nerds need for this kind of work:. Who have no friends and no life but first we need to know your character and morality, you can not use your talents for criminal matters If you have a criminal past, we will not.. take. " Keen Team members are between 20 and 40 years old and all man. "Maybe it's because women do not like playing with hardware. And maybe they can not stand the loneliness," Wang noted.

Method

What exactly are hackers proceed will not tell the CEO, but the core consists of writing programs that automatically search for vulnerabilities, also known as fuzzing. "It's not that we endlessly looking at code and find vulnerabilities in our eyes," Lu Juhui adds. He managed to earn during the recent Pwn2Own contest with his exploits tens of thousands of dollars. Despite the automated portion of the hackers make their hours. Lu works in their own words twelve hours a day.

Thursday, 2 April 2015

Critical Vulnerability In Google Chrome Patched


Google has released a new version of Google Chrome released that fixes four vulnerabilities, including a critical vulnerability that the underlying operating system in the worst case could be full. Visiting a malicious or hacked website or see getting an infected ad would have been sufficient in this case.

This kind of critical vulnerabilities are rare in Google Chrome. Last year there were only three of these types of leaks reported in Chrome. Critical vulnerabilities allow an attacker to run arbitrary code on the computer can perform, such as installing malware, come because of the sandbox security in the browser rare. In addition to a leak in the browser must also be a leak in the sandbox are found to execute code on the underlying system.

The vulnerability, which consists of various bugs, was reported by an anonymous security researcher. Google rewarded the researcher before with a total of almost $ 30,000. Besides this leak is also a vulnerability patched during the Pwn2Own contest was demonstrated. Researcher Jung Hoon Lee aka "lokihardt" succeeded during the event in order to execute arbitrary code via various vulnerabilities. Update to Chrome 41.0.2272.118 will happen automatically in most cases.

Monday, 23 March 2015

Emergency Patches Firefox Remedy Pwn2Own Leak


Mozilla has released in a short time two emergency patches for Firefox that fix critical vulnerabilities that an attacker in the worst case, the computer could take over completely. It involves two vulnerabilities that were demonstrated during the Pwn2Own contest in Vancouver.

During the event, researchers can win cash prizes by showing vulnerabilities in popular browsers and browser plug-ins. In Firefox three vulnerabilities were demonstrated, where it earned two responsible investigators $ 45,000 together. A day after the demonstration had already updated to Mozilla Firefox 36.0.3 done that fixed the first two leaks. A few hours later by Firefox 36.0.4 for the third vulnerability.

Updating to Firefox 36.0.4 possible via the automatic update feature of the browser or Mozilla.org . Besides Firefox succeeded researchers during the event also to Internet Explorer 11 , Safari and Google Chrome hack. In IE11 most vulnerabilities were discovered, namely four. On the same day as Mozilla also came with a Google update for Chrome, but the description is not mentioned in it or this version vulnerabilities have been patched.

Saturday, 21 March 2015

Also, Google Chrome And Safari Hacked During Competition


After Internet Explorer and Firefox during the Pwn2Own contest in Vancouver also Google Chrome and Safari hacked. The Pwn2Own contest is an annual event organized at the CanSecWest conference where researchers and the safety of popular browsers, and browser plug-ins can be tested. During the first day of the event there were leaks in Adobe Flash Player (3) Adobe Reader (3) Windows (3) Internet Explorer 11 (2) and Firefox (2) demonstrated.

During the second day were 11 Internet Explorer and Firefox again to believe. Additionally died also Google Chrome and Safari on Mac OS X. The attacks on IE11, Chrome and Safari were demonstrated by Jung Hoon Lee aka "lokihardt". The researcher was awarded a total of $ 225,000. Most of it, $ 110,000, Lee received because of his attack on Google Chrome.The researcher also showed also two Windows Leaks which he could execute code with system privileges.

In total there are 21 vulnerabilities demonstrated during the two days for which no security updates are available from the respective vendors. Microsoft leads with five vulnerabilities in Windows and four leaks in IE11 the list. Details on the vulnerabilities found will be made public until the updates are available.

Friday, 20 March 2015

Zero-Day Vulnerabilities In Flash, Windows, IE11 And Firefox Shown


During the Pwn2Own contest in Vancouver researchers have multiple zero-day vulnerabilities in Adobe Flash Player, Adobe Reader, Windows, Internet Explorer and Firefox demonstrated. The Pwn2Ownd contest is an annual event organized during the CanSecWest conference where researchers and the safety of popular browsers, and browser plug-ins can be tested.

In total on the first day of the event three vulnerabilities in Adobe Reader, three vulnerabilities in Adobe Flash Player, three vulnerabilities in Windows, two vulnerabilities in Internet Explorer 11 and two leaks in Firefox displayed. Through the vulnerabilities could allow an attacker full control of the computer without user interaction is much here for required. This involves visiting a hacked or malicious Web site or open a malicious PDF file.

None of the demonstrated vulnerabilities A security update is available, so there is zero-day vulnerabilities. However, the Pwn2Own rules state that only details may be shared with the organization. Which will then inform the relevant suppliers. Only after a security update is available researchers may publish details of the vulnerabilities.

In total, the researchers for their leak 317,500 dollars , which researcher Nicolas Joly dragging $ 90,000 knew inside. The Keen Team, consisting of several researchers, however, managed to leak in Adobe Flash Player and Adobe Reader, as well as bugs to earn the rights to increase Windows, totaling $ 140,000. Later today , various researchers are trying to re-hack Firefox and IE but there are now planned attacks on Google Chrome and Apple Safari.

Wednesday, 25 February 2015

Google Expands Chrome Hacking Contest Day


Every year Google organized during a security conference in Canada, a one-day competition in which hackers and researchers were rewarded for demonstrating vulnerabilities in Google Chrome. The Internet giant has now decided to expand the competition. Instead of a one-day hacking contest, researchers can now throughout the year for millions of Pwnium competition qualify.

Last year there was 2.71828 million dollars prize money available for new vulnerabilities. That prize is "infinity". According to Tim Willis of the Google Chrome Security Team has the game for various reasons changed . So researchers had to be physically on site in Canada to demonstrate their vulnerabilities and exploits. In addition, researchers decided to collect their leak to the Pwnium contest. "This is a bad scenario for all parties," said Willis.

Google was told the leak because later allowing users were more risk. Also, other researchers not to Pwnium participated vulnerabilities can find and report. The contest now to let a whole year, researchers found last report bugs directly, which should prevent them from doing the same work. Besides Chrome Chrome OS is also eligible for the new rules, wherein the top beloning now $ 50,000.

Sunday, 15 February 2015

Prize For Hacking Chrome During Pwn2Own


During a hacker contest next month in Vancouver held hackers and researchers can win the grand prize by hacking Google Chrome. Who a vulnerability in Google's browser on Windows 8.1 knows how to find can earn $ 75,000.

This is more than for leaks is offered in other browsers. The game in question is the annual Pwn2Own contest, which takes place during the CanSecWest conference. Every year, researchers and hackers at the event to test the security of browsers.After the prize for Google Chrome follows Internet Explore 11 where a reward of $ 65,000 to be offered. Apple Safari on Mac OS X Yosemite follows with $ 50,000 in the third. Finally provides a successful hack of Mozilla Firefox at $ 30,000.

Besides the four browsers will be tested also the security of Adobe Reader and Adobe Flash Player. A successful attack on both programs make $ 60,000 on. This year, the difficulty for participants is much higher than previous years because the exploits that should be developed with Microsoft's free security tool EMET works.

The Enhanced Mitigation Experience Toolkit (EMET) is precisely designed to neutralize the effect of exploits. As a result, researchers now take two hurdles. Researchers who through their exploits on a Windows computer code with SYSTEM privileges can perform get an extra $ 25,000 reward. In addition, Google will in the case of a Chrome hack pay an additional reward of $ 10,000. Pwn2Own will take place on 18th and 19th March.