2009年3月21日 星期六

Chrome only browser left standing after day one of Pwn2Own

Browser vendors often make strong claims about their responsiveness to vulnerability reports and their ability to preemptively prevent exploits. Security is becoming one of the most significant fronts in the new round of browser wars, but it's also arguably one of the hardest aspects of software to measure or quantify.

A recent contest at CanSecWest, an event that brings together some of the most skilled experts in the security community, has demonstrated that the three most popular browser are susceptible to security bugs despite the vigilance and engineering prowess of their creators.

Firefox, Safari, and Internet Explorer were all exploited during the Pwn2Own competition that took place at the conference. Google's Chrome browser, however, was the only one left standing—a victory that security researchers attribute to its innovative sandbox feature.

The contest awards security researchers with hardware and cash prizes for finding efficient ways to trick browsers into executing arbitrary code. During the first day of the competition, the contestants are required to do this in default browser installations without plugins such as Flash or Java, which are commonly used as vectors for attacks. Researchers typically prepare for the event far in advance by finding zero-day exploits ahead of time.

Early this month, prior champion Charlie Miller told reporters that he would be attempting to exploit a Safari vulnerability on Mac OS X. Safari, he said, would be the first to succumb to the contestants. As he promised, Safari went down first: he was able to execute his prepared hack in only a matter of seconds. Another security expert known only as Nils took longer, but was able to successfully exploit all three of the most popular browsers.

These contests contribute to the growing culture of commercialism that surrounds the art of exploitation. In an interview with ZDNet, Miller said that the vulnerability he used in the contest was one that he had originally found while preparing for the contest last year. Instead of disclosing it at that time, he decided to save it for the contest this year, because the contest only pays for one bug per year. This is part of his new philosophy, he says, which is that bugs shouldn't be disclosed to vendors for free.

"I never give up free bugs. I have a new campaign. It's called NO MORE FREE BUGS. Vulnerabilities have a market value so it makes no sense to work hard to find a bug, write an exploit and then give it away," Miller told ZDNet. "Apple pays people to do the same job so we know there's value to this work."

Miller also told reporters that he targeted Safari on Mac OS X because he believes that it is the easiest to exploit. Windows, on the other hand, he claims is tougher because of its address randomization feature and other security measures. As for Chrome, he says that he has identified a security bug in Google's browser but has been unable to exploit it because the browser's sandboxing feature and the operating system's security measures together pose a formidable challenge.
The game isn't over yet. During the second day of the event, the focus will turn towards Chrome. Nils, who demonstrated impressive skill during the first day by conquering the three most popular browsers, might have a few more tricks up his sleeve. According to the official rules, the participants will be permitted to use plugins during the second day.

PWN2OWN黑客大赛2009到底有哪些猛料?

32 评论:

仲亨仲亨 说...

以簡單的行為愉悅他人的心靈,勝過千人低頭禱告........................................

于芷奇名 说...

很喜歡你的blog哦...加油唷 ........................................

楊DodieSeaver0202 说...

忍一時風平浪靜,退一步海闊天空......................................................

子珠 说...

若對自己誠實,日積月累,就無法對別人不忠了。........................................

木姍 说...

85cc片觀看,77美女dvd影片,熊貓貼區,ut網際聊天,一葉情,av,嘟嘟,影音live秀,a片,做愛影片,視訊做愛,美女短片,78論壇,ut聊天,打飛機,a片,免費視訊,免費視訊,成人影院,性愛小說,辣妹視訊,網路交友,捷克論壇,h影片,色咪咪,免費影片85cc,kiss911,後宮,a片,影音視訊聊天,交友,免費聊天,聊天室交友,做愛影片,線上a片,美女影片,免費影片下載,免費聊天室,視訊做愛,美女視訊聊天

羿惟 说...

培養健全孩子最好的方法是父母先成為健全的人。......................................................

劉KarolR_Sundquis 说...

認清問題就等於已經解決了一半的問題。

韋于倫成 说...

好文章,希望能一直看到您的PO文........................................

730A_ngelinaRabideau0 说...

a片子安心亞寫真top1069拓網交友做愛自拍免費情色影片383成人台灣情網影片線上免費av18禁250av女優免費影片旺來出品辣妹寫真鋼管秀bt旺來出品辣妹寫真鋼管秀旺來風情寫真秀-辣妹過招旺來風情寫真秀旺來蓬萊仙山寫真集 vcd旺旺仙貝的狂想境地早洩韭南籽早期歐美a片早期范冰冰照片早春小老婆美女 視訊youtube 影片g世代論壇080視訊聊天室aaaaa片俱樂部影片微風成人情色 網18禁地少女遊戲女生自衛影片免費聊天女同志聊天室成人聊天室性愛日記網交聊天室性愛姿勢免費av影片觀看拓峰交友美女聊天室hbo論壇一夜情視訊聊天室五分鐘護半身視訊美女激情網愛聊天室

嘉剛 说...

your english is incredible............................................................

怡潔 说...

It is no use crying over spilt milk...................................................................

淑瑄 说...

每一粒厄運的種子,卻包孕著未來豐盛的果實......................................................................

張瑋劭 说...

河水永遠是相同的,可是每一剎那又都是新的。......................................................................

麗珠麗珠 说...

成熟,就是有能力適應生活中的模糊。.................................................................

王雅筑 说...

人生是故事的創造與遺忘。............................................................

俊賢 说...

Tks for your kindly sharing.( >з<)..................................................................

芳容222許林堅林芳容儀 说...

Say not all that you know, believe not all that you hear.............................................................

宥妃宥妃 说...

蛛絲馬跡皆學問、落花水面皆文章............................................................

香昱信張君林 说...

Quality is better than quantity.............................................................

dawsonfelicia張君dawsonfelicia均 说...

haha~ funny! thank you for your share~............................................................

蔡舜娟蔡舜娟 说...

TAHNKS FOR YOUR SHARING~~~VERY NICE............................................................

吳婷婷 说...

人要學習健忘,把所有不如意忘掉,才會快樂。..................................................

張家弘翁書豪 说...

一棵樹除非在春天開了花,否則難望在秋天結果。..................................................

林聿希林聿希林聿希 说...

人生中最好的禮物就是屬於自己的一部份............................................................

陳梁雅雯宗翰 说...

快樂,是享受工作過程的結果..................................................

家唐銘 说...

Learn wisdom by the follies of others.............................................................

蘇介蘇介妤妤蘇介妤蘇介妤 说...

這一生中有多少人擦肩而過?而朋友是多麼可貴啊!......................................................................

家則治則治則治瑋 说...

原來這世上能跟你共同領略一個笑話的人竟如此難得......................................................................

牧宇 说...

第一忠誠,第二勤奮,第三專心工作。..................................................

耿麗旺麗旺麗旺綺 说...

It is never too late to learn.......................................................................

筱趙趙婷趙趙趙 说...

你文章很棒的~繼續分享給大家~~~~..................................................

冰微 说...

加油!!! 很棒的分享~