Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Chrome, Firefox, Explorer, Safari were all hacked at Pwn2Own contest
PC World —IDG News Service ^ | Mar 20, 2015 5:20 AM | Lucian Constantin

Posted on 03/20/2015 2:41:46 PM PDT by Swordmaker

So much for browser security. Researchers who participated in the Pwn2Own hacking contest this week demonstrated remote code execution exploits against the top four browsers, and also hacked the widely used Adobe Reader and Flash Player plug-ins.

On Thursday, South Korean security researcher and serial browser hacker JungHoon Lee, known online as lokihardt, single-handedly popped Internet Explorer 11 and Google Chrome on Microsoft Windows, as well as Apple Safari on Mac OS X.

He walked away with US$225,000 in prize money, not including the value of the brand new laptops on which the exploits are demonstrated and which the winners get to take home.

(Excerpt) Read more at pcworld.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: anotherapplefailure; applecrap; applecrapped; graphixboxen; libsloveapples; osxfail; overpriced
Navigation: use the links below to view more comments.
first previous 1-2021-30 last
To: Swordmaker

IMHO, you’re not pwned if your attacker doesn’t get #. What good is a user account on *nix?


21 posted on 03/20/2015 4:47:07 PM PDT by proxy_user
[ Post Reply | Private Reply | To 15 | View Replies]

To: proxy_user
IMHO, you’re not pwned if your attacker doesn’t get #. What good is a user account on *nix?

I agree. . . however, the challenge on this Pwn2Own contest was to crack into the browsers. They did. Extra credit was given for getting to root or system. That was only accomplished on the Windows machine.

22 posted on 03/20/2015 4:52:31 PM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 21 | View Replies]

To: Swordmaker

Thanks, I may want to try Firefox and see.
I am thinking of a new laptop but I think I will wait until Windows 10 comes out.
Anyone know what the target date for Windows 10 is?


23 posted on 03/20/2015 4:55:24 PM PDT by Captain Peter Blood
[ Post Reply | Private Reply | To 20 | View Replies]

BFL


24 posted on 03/20/2015 4:57:04 PM PDT by Lurkina.n.Learnin (It's a shame nobama truly doesn't care about any of this. Our country, our future, he doesn't care)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Swordmaker

Excuses. Fact OSX has been the first hacked. And it’s not like the Russians and Chinese don’t have guys as smart as NASA. So it doesn’t make the mac more secure by being obscure.


25 posted on 03/20/2015 5:32:56 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 12 | View Replies]

To: for-q-clinton
Excuses. Fact OSX has been the first hacked. And it’s not like the Russians and Chinese don’t have guys as smart as NASA. So it doesn’t make the mac more secure by being obscure.

It is not a timed contest, for-q-clinton. . . it just mattered who got the first choice of which computer to take a stab at. First Shmish! These "hacks" also required the active participation of the user. . . the "referees" had to invoke them on the targeted computer. . . to go download a file and run it. Sorry. Not much of a hack when it is basically a trojan. The "security by obscurity" canard is false. . . and has been shot down by examples such as the Witty Worm and other examples in the Windows world. Sorry, no banana for you.

26 posted on 03/20/2015 6:58:39 PM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 25 | View Replies]

To: freedumb2003; Swordmaker
From the article:

"The final count for vulnerabilities exploited this year stands as follows: five flaws in the Windows OS, four in Internet Explorer 11, three each in Mozilla Firefox, Adobe Reader, and Flash Player, two in Apple Safari and one in Google Chrome. "

To put that in graphic perspective:

(Note the biasing effect of leaving out zero...)

27 posted on 03/20/2015 6:59:12 PM PDT by TXnMA ("Allah": Satan's current alias... "Barack": Allah's current ally...)
[ Post Reply | Private Reply | To 6 | View Replies]

To: for-q-clinton; freedumb2003
Take a look at the facts -- in un-biased graphics -- in #27...
28 posted on 03/20/2015 7:09:03 PM PDT by TXnMA ("Allah": Satan's current alias... "Barack": Allah's current ally...)
[ Post Reply | Private Reply | To 27 | View Replies]

To: Woodman
OK, so I guess the only really important statistic is how long it took to hack each one? I assume they were at current patch level and default settings. It would be interesting to see how each did at full security.

The real point is that nothing is truly safe and browsers are being used all the time and will be hacked. The only truly safe machine is one that is disconnected from the network - trying to protect them will be semi-effective (unless layered behind several points of scrutiny by adept folks) and all take some of the speed away.

29 posted on 03/21/2015 3:44:04 AM PDT by trebb (Where in the the hell has my country gone?)
[ Post Reply | Private Reply | To 4 | View Replies]

To: TXnMA

You get to the OS through the browser.

I didn’t mention the OS - and everyone knows Windows sucks that way — even spawning an entire multibillion $ industry.

My takeaway from the article is all browsers can be hacked — that is about it.


30 posted on 03/21/2015 12:09:01 PM PDT by freedumb2003 (islam: The hands of the Chinese, the mouths of the arabs, the minds of the French.)
[ Post Reply | Private Reply | To 27 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-30 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson