Risk
3/19/2009
02:22 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Safari Hacked... Followed By IE And Firefox

Last year's winner of the CanSecWest security conference's Pwn2Own contest repeats his success in record time.

Just like last year, a Mac running Safari was the first to fall. Then Microsoft Internet Explorer 8, just released officially on Thursday, and Firefox 3 were hacked, leaving only Google's Chrome uncompromised.

At the CanSecWest security conference's Pwn2Own contest in Vancouver, British Columbia, on Wednesday, security researcher Charlie Miller exploited an undisclosed vulnerability in Apple's Safari Web browser, running under Mac OS X. It took him less than two minutes, contest sponsor TippingPoint said, for which he was awarded $5,000, along with the MacBook he hacked. Some accounts indicate Miller's exploit took only seconds.

Miller won a MacBook Air at the 2008 Pwn2Own contest using an undisclosed vulnerability in version 3.1 of Apple's Safari browser.

The TippingPoint Zero Day Initiative offers rewards of $5,000 per browser bug and $10,000 per mobile device bug. The rules are that the first person to run a successful exploit on any of the mobile devices gets to keep that device, with a one-year phone contract. The first person to hack any of the browsers gets to keep the laptop it was running on.

Following Miller's performance, a security researcher who identified himself only as Nils ran a successful exploit against Microsoft IE8 running Windows 7 on a Sony Vaio.

As Terri Forslof, manager of security response for TippingPoint, put it in a blog post, Nils defied "Microsoft's latest built in protection technologies -- DEP (Data Execution Prevention) as well as ASLR (Address Space Layout Randomization) -- to take home the Sony Vaio and $5,000."

Nils then proceeded to hack Safari and Firefox, both under Mac OS X, earning $10,000 more in prize money.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.