Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Pwn2Own: Down go all the browsers
ZDNet ^ | 3/8/13 | Steven J Vaughn-Nichols

Posted on 03/08/2013 7:25:20 AM PST by illiac

Summary: In the first day of the Pwn2Own cracking contest, Microsoft's Internet Explorer 10, Google's Chrome and Mozilla's Firefox web browsers have all gone down in flames.

Steven J. Vaughan-Nichols

By Steven J. Vaughan-Nichols for Networking | March 7, 2013 -- 18:20 GMT (10:20 PST)

In the eternal war between crackers and security professionals, the hackers have won the latest battle. ZDI_Twitter_AvatarIn ZDI's Pwn2Own hacker competition one browser after another fell. At the CanSecWest conference in Vancouver, Canada, the HP Zero Day Initiative's (ZDI) annual Pwn2Own competition has ended its first day of competition and Microsoft's Internet Explorer (IE) 10, Google's Chrome and Mozilla's Firefox Web browsers have all been cracked. In addition, Java—can anyone be surprised at this?--was also cracked multiple times.

Vupen Security, the French security and hacking company, cracked IE 10. Vupen reported, via Twitter, that they "pwned MS Surface Pro with two IE10 zero-days to achieve a full Windows 8 compromise with sandbox bypass."

Mind you, no one else had anything to boast about on this day. Google, which had just fixed numerous security bugs in the Chrome Web browser prior to Pwn2Own, saw Chrome go down as well. MWR Labs, a branch of UK-based MWR InfoSecurity, took down Chrome 25 on Windows 7 by exploiting multiple "zero-day," or unpatched, browser vulnerabilities.

(Excerpt) Read more at zdnet.com ...


TOPICS: Chit/Chat; Computers/Internet; Science
KEYWORDS: browsers; computers
Navigation: use the links below to view more comments.
first previous 1-2021-26 last
To: illiac
A good example of how adding features that appeal to large numbers of end users, and flashy visual designs, are more important to software vendors than security. The market for browsers demands new features, not security, so that is what we get.

It is certainly possible to write browsers that are nearly impossible to attack, but there is little market for them.

21 posted on 03/08/2013 8:24:11 AM PST by freeandfreezing
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin
Where was the image actually stored?
22 posted on 03/08/2013 9:35:41 AM PST by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 8 | View Replies]

To: illiac
Firefox 19.0.2 was released less than 24 hours after this announcement to fix this flaw.

Pretty fast.

23 posted on 03/08/2013 11:23:07 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

I have no idea. Found it using Bing.


24 posted on 03/08/2013 12:07:31 PM PST by BenLurkin (This is not a statement of fact. It is either opinion or satire; or both)
[ Post Reply | Private Reply | To 22 | View Replies]

To: illiac

No way...Impossible for OSX to go down. At least that’s what we’ve been told by the macbots and apple zealots.

Of course they were saying that even after OSX was the first to lose 3 years in a row!

Oh well, who ever takes security advice from a macbot is an idiot anyway.


25 posted on 03/09/2013 12:30:51 PM PST by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 1 | View Replies]

To: illiac

Odd this year they didn’t test safari?

Also it’s amazing that they are saying adobe is the most secure platform this year! Wow they have really turned it around.


26 posted on 03/09/2013 12:34:30 PM PST by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-26 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson