Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Saturday March 21 2015, @11:02PM   Printer-friendly
from the lynx-FTW dept.

The annual Pwn2Own hacking competition wrapped up its 2015 event in Vancouver with another banner year, paying $442,000 for 21 critical bugs in all four major browsers, as well as Windows, Adobe Flash, and Adobe Reader.

The crowning achievement came Thursday as contestant Jung Hoon Lee, aka lokihardt, demonstrated an exploit that felled both the stable and beta versions of Chrome, the Google-developed browser that's famously hard to compromise. His hack started with a buffer overflow race condition in Chrome. To allow that attack to break past anti-exploit mechanisms such as the sandbox and address space layout randomization, it also targeted an information leak and a race condition in two Windows kernel drivers, an impressive feat that allowed the exploit to achieve full System access.

[Related]: http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2015-Day-Two-results/ba-p/6722884#.VQwyVuF7S_Y

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by bzipitidoo on Sunday March 22 2015, @02:10AM

    by bzipitidoo (4388) on Sunday March 22 2015, @02:10AM (#160928) Journal

    Which 4 browsers did they mean by "major"? 3 of them had to be Firefox, Chrome, and IE. Was the 4th Opera? Maybe SeaMonkey? No, it was Safari.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 3, Touché) by CirclesInSand on Sunday March 22 2015, @02:15AM

    by CirclesInSand (2899) on Sunday March 22 2015, @02:15AM (#160930)

    So Lynx is still secure?

    • (Score: 2) by Appalbarry on Sunday March 22 2015, @03:33AM

      by Appalbarry (66) on Sunday March 22 2015, @03:33AM (#160954) Journal

      Only if you don't install javascript....

    • (Score: 3, Interesting) by jasassin on Sunday March 22 2015, @10:44PM

      by jasassin (3566) <jasassin@gmail.com> on Sunday March 22 2015, @10:44PM (#161282) Homepage Journal

      So Lynx is still secure?

      OpenBSD just removed Lynx from the base install. I tried finding out why, there were at least a few references to security being a reason but no specific exploits listed. Maybe someone here has some better kung fu and can find out why OpenBSD just removed Lynx from the base install?

      --
      jasassin@gmail.com GPG Key ID: 0x663EB663D1E7F223
  • (Score: 1, Informative) by Anonymous Coward on Monday March 23 2015, @10:52AM

    by Anonymous Coward on Monday March 23 2015, @10:52AM (#161411)

    Safari is the default browser on OS X and iOS.

    Opera and SeaMonkey have nothing on that.