Showing posts with label Web Browser Security. Show all posts
Showing posts with label Web Browser Security. Show all posts

Thursday, 23 April 2015

Microsoft Is Going To Reward Hackers For Bugs In Project Spartan


As with the test version of Internet Explorer 11 , Microsoft also launched a reward program for the test version of the new browser, code-named "Project Spartan", which hackers and researchers are rewarded for reporting vulnerabilities.

The compensation amount varies from 500 to $ 15,000, although Microsoft claims that the reward may also increase depending on the vulnerability and found the quality of the bug message. The program runs from April 22 until June 22nd. In this way, Microsoft hopes to encourage researchers to leaks in Project Spartan to find and report before a final version this summer appears. When IE11 made the rewards program will allow more bugs were logged than with the test version of IE10 was.

Besides the reward program for Microsoft Project Spartan also has the "Online Services Bug Bounty Program" expanded.Thus vulnerabilities in Azure and Sway.com be rewarded in the maximum reward to $ 15,000 was raised. Again, the rewards can be higher depending on the submission.

The highest rewards Microsoft hands out for attacks to bypass security measures in Windows 8.1 and Server 2012 R2.Allows researchers can earn $ 100,000. Also this program is adapted, including "Hyper-V escapes" now come for a reward eligible. According to Microsoft's Jason Shirk play "bug bounties", as the rewards are called, an increasingly important role in finding vulnerabilities and safer software.

Thursday, 2 April 2015

Critical Vulnerability In Google Chrome Patched


Google has released a new version of Google Chrome released that fixes four vulnerabilities, including a critical vulnerability that the underlying operating system in the worst case could be full. Visiting a malicious or hacked website or see getting an infected ad would have been sufficient in this case.

This kind of critical vulnerabilities are rare in Google Chrome. Last year there were only three of these types of leaks reported in Chrome. Critical vulnerabilities allow an attacker to run arbitrary code on the computer can perform, such as installing malware, come because of the sandbox security in the browser rare. In addition to a leak in the browser must also be a leak in the sandbox are found to execute code on the underlying system.

The vulnerability, which consists of various bugs, was reported by an anonymous security researcher. Google rewarded the researcher before with a total of almost $ 30,000. Besides this leak is also a vulnerability patched during the Pwn2Own contest was demonstrated. Researcher Jung Hoon Lee aka "lokihardt" succeeded during the event in order to execute arbitrary code via various vulnerabilities. Update to Chrome 41.0.2272.118 will happen automatically in most cases.

Saturday, 21 March 2015

Also, Google Chrome And Safari Hacked During Competition


After Internet Explorer and Firefox during the Pwn2Own contest in Vancouver also Google Chrome and Safari hacked. The Pwn2Own contest is an annual event organized at the CanSecWest conference where researchers and the safety of popular browsers, and browser plug-ins can be tested. During the first day of the event there were leaks in Adobe Flash Player (3) Adobe Reader (3) Windows (3) Internet Explorer 11 (2) and Firefox (2) demonstrated.

During the second day were 11 Internet Explorer and Firefox again to believe. Additionally died also Google Chrome and Safari on Mac OS X. The attacks on IE11, Chrome and Safari were demonstrated by Jung Hoon Lee aka "lokihardt". The researcher was awarded a total of $ 225,000. Most of it, $ 110,000, Lee received because of his attack on Google Chrome.The researcher also showed also two Windows Leaks which he could execute code with system privileges.

In total there are 21 vulnerabilities demonstrated during the two days for which no security updates are available from the respective vendors. Microsoft leads with five vulnerabilities in Windows and four leaks in IE11 the list. Details on the vulnerabilities found will be made public until the updates are available.