Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Mobile Bug Bounty: $300K For New Exploits

Mobile Pwn2Own contest's prize money may be too far below the zero-day vulnerability market rate to net meaningful submissions.

Lost Smartphone? 6 Free Tracking Apps
Lost Smartphone? 6 Free Tracking Apps
(click image for larger view)
Bug hunters hoarding zero-day vulnerabilities for mobile devices: Give us your exploits.

That's the pitch for the second annual Mobile Pwn2Own, a two-day competition run by HP's Zero Day Initiative (ZDI), that begins Nov.13 at the PacSec Applied Security Conference in Tokyo.

"HP and its sponsors are offering over $300,000 (USD) in cash and prizes to researchers who successfully compromise selected mobile targets from particular categories," said HP DVLabs security researcher Brian Gorenc in a related announcement. "Contestants will be judged on their ability to uncover new vulnerabilities and develop cutting edge exploit techniques to compromise some of the most popular mobile devices."

Prizes -- awarded to the first contestant who demonstrates a successful compromise using an unpublished zero-day vulnerability -- are $40,000 for a mobile application or operating system; $50,000 for short distance and/or physical attacks against Bluetooth, Wi-Fi, USB or near field communications (NFC); $70,000 for a mobile message service hack -- against SMS, MMS or the Commercial Mobile Alert System (CMAS); and $100,000 for a hack of a baseband processor, which sends and receives signals from cell towers.

"A successful attack against these devices must require little or no user interaction," said Gorenc. "The contestant must demonstrate remote code execution by bypassing sandboxes -- if applicable -- and exfiltrating sensitive information, silently calling long-distance numbers or eavesdropping on conversations."

[ Learn more about Apple's fingerprint-based authentication. See iPhone 5s Fingerprint Scanner: 9 Security Facts. ]

Successful contestants will also be required to fully detail their exploits. "When you've successfully demonstrated your exploit and 'pwned' the targeted device, you need to provide ZDI with a fully functioning exploit and a whitepaper detailing all of the vulnerabilities and techniques utilized in your attack," said Gorenc.

Contestants can choose among nine device targets: Apple iPad Mini or iPhone 5 (running iOS); BlackBerry Z10 (running BlackBerry 10); Google Nexus 4, 7 or 10 (running Android); Microsoft Surface RT (running Windows RT); Nokia Lumia 1020 (running Windows Phone); and Samsung Galaxy S4 (running Android).

Google, meanwhile, will add a $10,000 "top-up reward" for any successful attacks against Chrome on Android, running on either a Google Nexus 4 or Samsung Galaxy S4. Google may also award multiple prizes in the mobile Web browser hacking category if different participants unveil unique attacks against either of those devices.

But will the prize money be sufficient to draw the latest and greatest exploits? Chaouki Bekrar, CEO and head researcher for firm Vupen Security, which sells exploits to trusted countries and government agencies, said many Mobile Pwn2Own prizes are below the market rate. "Prices are too low for giving full exploit + sandbox bypass," Bekrar tweeted Thursday. But the "price for NFC/USB is good," he noted.

Bekrar's comments reflect how demand for exploits has driven up the prices that governments and other third parties are willing to pay to bug hunters. The Bangkok-based vulnerability broker known as the GrugQ, for example, last year said that he won't bother brokering a deal for a bug that's worth less than $250,000. But that's almost the entire amount of prize money being offered in this year's Mobile Pwn2Own contest.

HP's pitch, however, seems aimed not at giving the going rate, but rather dangling related kudos in front of independent security researchers. Or in the words of HP's Gorenc: "The contest focuses on hardening the mobile attack surface through great research and responsible disclosure."

The contest also offers publicity to independent bug hunters and exploit sellers such as Vupen. Indeed, the French firm saw large amounts of accompanying publicity in March, when it demonstrated a number of vulnerabilities -- including an exploit of the then-latest version of Adobe Flash -- at the seventh annual Pwn2Own in Vancouver, which is a sister contest to Mobile Pwn2Own. After the two-day contest wrapped, thanks to also demonstrating brand-new exploits against Microsoft Internet Explorer 10 and Mozilla Firefox, Vupen walked away with $250,000 in prize money.

Learn more about mobile security by attending the Interop conference track on Mobility in New York from Sept. 30 to Oct. 4.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19040
PUBLISHED: 2019-11-17
KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '"sampling":{"value":"<script>' substring.
CVE-2019-19041
PUBLISHED: 2019-11-17
An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgrade package before processing it. As a result, official upgrade packages can be modified to inject an arbitrary Bash script that will be executed by th...
CVE-2019-19012
PUBLISHED: 2019-11-17
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or ...
CVE-2019-19022
PUBLISHED: 2019-11-17
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git r...
CVE-2019-19035
PUBLISHED: 2019-11-17
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.