Jump to content

Recommended Posts

Posted

'According to sources at the conference, Miller used an exploit against the Safari browser that ships standard with Mac OS X. Details of the vulnerability and the attack vector are now the property of TippingPoint’s ZDI (Zero Day Initiative), the sponsor of the Pwn2Own challenge'

 

 

More like Safari sucks.

Posted

TippingPoint | DVLabs | PWN to OWN: Final Day's Results and Wrap Up

 

The vista and the ubuntu machine are still standing. The rules have been further relaxed.

 

we are now opening up the the scope of the targets beyond just default installed applications on those laptops; any popular 3rd party application (as deemed "popular" by the judges) can now be installed on the laptops for a prize of $5,000 upon a successful compromise

 

I'm expecting the Vista machine wont last long under these circumstances.

Posted
can't open that article ( at least not from work ) but was curious as to how they set up each machine do they configure firewalls and other mechanisms before they allow them to try to gain access to each machine or is it just a base line pre installed image that each machine already came with ?
Posted

@gecko They're as shipped by the vendor:

 

The Cash Prizes

All machines will be fully patched and in a default configuration. Simply put, if the vendor shipped it on the box and it's enabled, it's in scope.

 

 

Day 1: March 26th: Remote pre-auth

All laptops will be open only for Remotely exploitable Pre-Auth vulnerabilities which require no user interaction. First one to pwn it, receives the laptop and a $20,000 cash prize.

The pwned machine(s) will be taken out of the contest at that time.

 

Day 2: March 27th: Default client-side apps

The attack surfaces increases to also include any default installed client-side applications which can be exploited by following a link through email, vendor supplied IM client or visiting a malicious website. First one to pwn it receives the laptop and a $10,000 cash prize.

The pwned machine(s) will be taken out of the contest at that time.

 

Day 3: March 28th: Third Party apps

Assuming the laptops are still standing, we will finally add some popular 3rd party client applications to the scope. That list will be made available at CanSecWest, and will be also posted here on the blog. First to pwn it receives the laptop and a $5,000 cash prize.

 

*To accommodate any individuals who may not have gotten a chance to take a stab at the machines, we'll provide the opportunity onsite for folks to submit their vulns through the normal ZDI process if they'd like to be compensated for their discovery.

 

The awards ceremony will take place at the end of the day on the 28th. More details and daily results from the contest will be posted here on our blog. Please feel free to ask questions in the Comments section of this posting and we will try to answer them in a timely manner.

 

Update - see our main blog index for the most recent daily updates from the contest.

Posted

Be interesting to see who wins between vista and linux today.

 

Vista was compromised.

 

So at the end of the last day of the contest, only the Sony VAIO laptop running Ubuntu was left standing.

 

Cue MS apologist: It's more secure because no-one uses it, its adobe's fault etc.....

Posted (edited)

Edited: a 2006 article is used to try and prove something. What, I don't know!

 

I mean- imagine a hardware vendor having hardware issues?

Edited by kingswood
Posted
D'oh, I just clicked on the link at the bottom of the original story about the hack - didn't see the date. Whoops. Oh poop. Whatever.

 

I guess Zdnet don't carry so many OSX security stories :D

Posted

Vista hacked was on Day 3, but through Adobe Flash

 

Clearly Apple were the losers here, with Microsoft second and Linux the winner. I don't have much sympathy for Apple really, as Safari is appalling, but as for Microsoft I do have a degree of sympathy. Although security of the OS has been beefed up, it's weakened by an application that probably 90% of all users have installed as it's widely used across the web.

 

Would of been interesting if they put Windows XP SP2 or indeed SP3 to see how (in practice) this competes with Vista in the real world security wise :)

Posted
Although security of the OS has been beefed up, it's weakened by an application that probably 90% of all users have installed as it's widely used across the web

 

lol, @ the MS shill response.

Posted
lol, @ the MS shill response.

 

That's a bit harsh. It has been a matter of debate the extent to which the OS developer can be held responsible for the quality of OEM bundled software.

 

In this case it is half and half between Adobe and Microsoft. Although it was Adobe 's software that contained the exploited vulnerability, it was Microsoft's Active X technology framework that makes it possible for the cracker to own the own the box.

Posted (edited)
Oh well, back to the drawing board. Tomorrow's another day etc etc... ;)

 

Really. Linux was tested against the same criteria.

 

In this case it is half and half between Adobe and Microsoft. Although it was Adobe 's software that contained the exploited vulnerability, it was Microsoft's Active X technology framework that makes it possible for the cracker to own the own the box.

 

That's not really half and half if linux isn't vulnerable !

Edited by CyberNerd
Posted

No operating system is devoid of exploitative code- not even Linux with all it's great stability and power (hence so many patches). But patching- and plugging security holes- is a Good Thing ™. What this event showed is that Apple and Microsoft have a long way to go before they can hold up a crown- and it shows only that *on this occasion* Linux stayed safe.

 

I *like* that OS X was "hacked" in this way. Safari isn't as bad as MS supporters believe, and yet still has a long way to go before it can be considered as seasoned and safe as it should be. With exploits like this being revealed Apple will have to react before it becomes common knowledge; likewise Microsoft have every right to now send a few fiery darts Adobe's direction for releasing hole-ridden code (if it is indeed "hole ridden" and not just in need of a patch).

 

When all is said and done we should all be aware of the need for security- no matter the OS.

 

What this competition does *not* prove- and you would have to be silly to think it does- is that any one OS came out the secure "victor". On the day Linux stood against the hacks attempted against the system. On another day this may not be the case.

 

Paul

Posted
What this competition does *not* prove- and you would have to be silly to think it does- is that any one OS came out the secure "victor". On the day Linux stood against the hacks attempted against the system. On another day this may not be the case.

 

Absolutely I agree! Any OS is breakable, just some easier than others :) I think the Adobe flaw was a combination of Flash and Windows itself (as mentioned by ITWombat), but nevertheless, it goes to show MS needs to work closer with developers so they harden their software too.

Posted
Really. Linux was tested against the same criteria.

 

I don't disagree with you here, Linux was glorious on the day. I meant MS need to go back to the drawing board and work closer with developers (as I mentioned above) :)

Posted

It is one thing for out of the box sessions like this, but it is more fun to watch the competitions against hardened machines.

 

InfoSec used to do a session each year of it, but I didn't see it at all last year. I won't be attending this year, but it is always a good session to look for.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...