Risk
3/19/2009
02:22 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Safari Hacked... Followed By IE And Firefox

Last year's winner of the CanSecWest security conference's Pwn2Own contest repeats his success in record time.

Just like last year, a Mac running Safari was the first to fall. Then Microsoft Internet Explorer 8, just released officially on Thursday, and Firefox 3 were hacked, leaving only Google's Chrome uncompromised.

At the CanSecWest security conference's Pwn2Own contest in Vancouver, British Columbia, on Wednesday, security researcher Charlie Miller exploited an undisclosed vulnerability in Apple's Safari Web browser, running under Mac OS X. It took him less than two minutes, contest sponsor TippingPoint said, for which he was awarded $5,000, along with the MacBook he hacked. Some accounts indicate Miller's exploit took only seconds.

Miller won a MacBook Air at the 2008 Pwn2Own contest using an undisclosed vulnerability in version 3.1 of Apple's Safari browser.

The TippingPoint Zero Day Initiative offers rewards of $5,000 per browser bug and $10,000 per mobile device bug. The rules are that the first person to run a successful exploit on any of the mobile devices gets to keep that device, with a one-year phone contract. The first person to hack any of the browsers gets to keep the laptop it was running on.

Following Miller's performance, a security researcher who identified himself only as Nils ran a successful exploit against Microsoft IE8 running Windows 7 on a Sony Vaio.

As Terri Forslof, manager of security response for TippingPoint, put it in a blog post, Nils defied "Microsoft's latest built in protection technologies -- DEP (Data Execution Prevention) as well as ASLR (Address Space Layout Randomization) -- to take home the Sony Vaio and $5,000."

Nils then proceeded to hack Safari and Firefox, both under Mac OS X, earning $10,000 more in prize money.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2227
Published: 2014-07-25
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

CVE-2014-5027
Published: 2014-07-25
Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via a query parameter to a diff fragment page.

CVE-2014-5100
Published: 2014-07-25
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new super user account via a request to admin/users/add, (2) insert cross-site scripting (XSS) sequences via the api_key_...

CVE-2014-5101
Published: 2014-07-25
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9) TPL_phone, (10) TPL_pp_email, (11) TPL_authn...

CVE-2014-5102
Published: 2014-07-25
SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.