Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Google Will Pay $1 Million For Chrome Hacks


Recommended Posts

Posted

what sort of hacks constitute an actual hack, could you take a hex editor, adjust the exe for Chrome and then use said loop hole or do you have to leave the executable in tact as is ???

 

Or is this more network hacking ie they have there own little network and they have to do something on the remote computer that has Chrome ?

Posted
what sort of hacks constitute an actual hack, could you take a hex editor, adjust the exe for Chrome and then use said loop hole or do you have to leave the executable in tact as is ???

 

Or is this more network hacking ie they have there own little network and they have to do something on the remote computer that has Chrome ?

 

I think it'd be exploits they're looking for and not hacks.

 

If you change the .EXE it wouldn't be chrome anymore.

Posted
Pwn2Own is normally for using a browser exploit - buffer overflows etc. - to break out of the sandbox and start executing arbitrary code on the machine. I think they normally just open Calculator or Notepad to demonstrate that they can do it, but any such exploit would have the potential to introduce viruses, keyloggers, blah blah blah...
Posted
it's that important an event in security circles.

 

A large scale network security event, designed to expose vulnerabilities in browsers, in a time where more and more is being done online.

 

Of course it's a big deal.

 

 

No-one want's to be the company that allows users personal details to be intercepted/hacked due to security flaws.

  • 2 weeks later...
Posted
Thanks - not tried doing anything like that before - sounds interesting though.

Must be quite difficult...

 

It was a rare event. To date, there are no known reports of a zero-day attack ever hitting Chrome in the wild, and at the previous three years' contests, Chrome escaped unscathed, even as Internet Explorer, Firefox, and Safari were brought down by exploits that allowed the attackers to take complete control of the machine running the software. The chief reason: Chrome's security sandbox—which isolates web content inside a highly restricted perimeter that's separated from the rest of the operating system—makes it harder to write reliable attacks.

 

A contestant in the second contest, which Google has dubbed "Pwnium," was also able to bypass the Chrome sandbox so he could execute any code of his choosing on the underlying machine. Sergey Glazunov wasn't on site to discuss the hack. Google has said only that for him to win the top $60,000 reward, his exploit was required to bypass the sandbox using code native to Chrome.

 

Bekrar told Ars that his team's attack exploited what's known as a use-after-free bug to bypass DEP, or data execution prevention, and ASLR, or address space layout randomization. Both mitigations are designed to prevent hackers from executing malicious code even when they locate vulnerabilities. He said it exploited a second vulnerability that allows code to break out of the sandbox. He declined to detail the vulnerable component, except to say it was found in the "default" installation of the Google browser.

 

That detail led several observers to speculate that an Adobe Flash plugin was the means Vupen used to access more sensitive parts of the operating system. While Chrome runs the media player add-on in its own sandbox, the perimeter is considerably more porous than it is with other components, security researchers say. Core functionality in Flash, for instance, requires the app be able to control web cams and microphones, access system state, and connect to display monitors and other connected devices. (Source)

Posted

How Google set a trap for Pwn2Own exploit team « ZDNet

 

As you know, Google launched an alternative to Pwn2Own to ensure it got the full rights to any sandbox exploitation so when the VUPEN team announced it would arrive here with a Chrome zero-day, the Google Chrome security team decided to set a trap.

 

Google could figure out very easily if a certain exploit technique was being used. Even more, if an attack targeted third-party (er, Adobe Flash Player) code, they could pinpoint the technique.

 

In this case, the Google Chrome security knew that the Flash Player plugin sandbox is significantly weaker and that an exploit against Chrome’s Flash Player would have to go through a certain path.

 

Having figured out that Vupen used that technique (from the May video), Google decided to add a specific protection for Flash.

 

On March 5, the protection was added to Google Chrome 17.0.963.65. When the protection triggers, it generates a very unique signature — 0xABAD1DEA — which is hexidecimal that spells out "a bad idea". The protection was meant to make the browser resilient to certain attacks but in a bit of cat-and-mouse, it was left in there to see if anyone would find it and make a public comment.

 

The VUPEN team arrived at CanSecWest and during testing of its exploits for Pwn2Own, they stumbled into the exception.

  • 2 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...