SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    All Four Major Browsers Take a Stomping at Pwn2Own Hacking Competition
Date    Saturday March 21 2015, @11:02PM
Author    janrinok
Topic   
from the lynx-FTW dept.
https://soylentnews.org/article.pl?sid=15/03/21/1011222

AnonTechie writes:

The annual Pwn2Own hacking competition wrapped up its 2015 event in Vancouver with another banner year, paying $442,000 for 21 critical bugs in all four major browsers, as well as Windows, Adobe Flash, and Adobe Reader.

The crowning achievement came Thursday as contestant Jung Hoon Lee, aka lokihardt, demonstrated an exploit that felled both the stable and beta versions of Chrome, the Google-developed browser that's famously hard to compromise. His hack started with a buffer overflow race condition in Chrome. To allow that attack to break past anti-exploit mechanisms such as the sandbox and address space layout randomization, it also targeted an information leak and a race condition in two Windows kernel drivers, an impressive feat that allowed the exploit to achieve full System access.

[Related]: http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2015-Day-Two-results/ba-p/6722884#.VQwyVuF7S_Y

Links

  1. "AnonTechie" - https://soylentnews.org/~AnonTechie/
  2. "annual Pwn2Own hacking competition wrapped up its 2015 event in Vancouver" - http://arstechnica.com/security/2015/03/all-four-major-browsers-take-a-stomping-at-pwn2own-hacking-competition/

© Copyright 2023 - SoylentNews, All Rights Reserved

printed from SoylentNews, All Four Major Browsers Take a Stomping at Pwn2Own Hacking Competition on 2023-07-03 09:26:12