|
Only one can remain alive and in this case it has been Google's star browser. iPhone, Safari, Explorer and even the established Firefox have fallen without problems in the hands of the best hackers in the world who meet every year in Canada to try to destroy the most famous systems of the moment and point out their security flaws. However, they have not been able to violate the extremely harsh sandbox mode that protects Chrome, a colossus that has resisted the attacks of the best computer experts on the planet. |
The annual Pwn2Own contest at the CanSecWest security fair in Vancouver provides the perfect environment for the world's best IT security experts to engage in full swing against all sorts of hot gadgets and software. Year after year, they manage to circumvent the security hurdles that the systems under review try to impose, but only a few have the honor of reaching the end of the contest without a single failure.
The first to fall was the successful Apple iPhone, Vincenzo Iozzo and Ralf Philipp Weinmann only needed 20 seconds to make a fool of the most demanded device of the moment. The hackers only made the iPhone (without jailbreak) enter a site previously developed by them, from where they copied the entire SMS database (even the deleted ones) to their servers. They stated that despite efforts by Apple to prevent these gaps, "the way they implemented code signing is too lenient." They won $ 15.000 for this intelligence demonstration and as soon as the apple company fixes the security bug, the details of the access will be displayed.
Charlie Miller, Principal Security Analyst at Independent Security Evaluators, managed to hack Safari on a MacBook Pro with Snow Leopard and no physical access, earning $ 10,000. This old event dog manages to bust a device owned by Apple every year. It seems that he has taken the pulse of the brand. It would not hurt for the company to hire him to see if once and for all they can end the security flaws in their products.
The independent security researcher Peter Vreugdenhil won the same amount for the hack of Internet Explorer 8, which no longer surprises anyone to see one edition and another as well, as he is struck down by any expert who proposes it. To hack IE8 Vreugdenhil claimed to have exploited two vulnerabilities in a four-part attack that bypassed ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention), which are designed to help stop attacks in the browser. As in other attempts, the system was compromised when the browser visited a site that was hosting malicious code. The ruling gave him rights to the computer, which he demonstrated by running the machine's calculator.
Firefox also had to bend the knee to the cunning of Nils, UK head of research for MWR InfoSecurity, who made $ 10,000 off the browser vulnerability that is keeping Microsoft at ease. Nils said he exploited a memory corruption vulnerability and also had to overcome ASLR and DEP thanks to a bug in the Mozilla implementation.
And finally, the only one that has remained standing has been Chrome. So far it is the only browser that remains undefeated, something that it had already achieved during the 2009 edition of this event that takes place in Canada and that seeks to warn users of the vulnerabilities of the programs. “There are flaws in Chrome, but they are very difficult to exploit. They designed a 'sandbox' model, which is very difficult to break, "said Charlie Miller, the famous hacker, who in this edition managed to take control of Safari on a Macbook Pro.
Source: Neoteo and Segu-Info and Z