All the latest UK technology news, reviews and analysis

Researchers hack popular platforms at Pwn2Own contest

by Shaun Nichols

26 Mar 2010

Comment: 1

  • Tweet this
MacBook Pro
Charlie Miller scooped a prize for quickly compromising a MacBook Pro running Safari

Security researchers at the CanSecWest conference have kicked off the annual Pwn2Own security event.

The 2010 edition of the contest challenged attendees to produce working exploits for several PC-based browsers and mobile handsets. In the first day of competition, three of the four targeted systems had been cracked.

Researcher Charlie Miller claimed a prize for the third year in a row by quickly compromising a MacBook Pro running Safari. Miller has delivered similar exploits for Apple notebooks in each of the previous two Pwn2Own events.

Miller presented his exploit after fellow researchers Vincenzo Iosso and Ralf Phillip Weinmann were able to score the first successful exploit of the day by compromising Safari on the iPhone through the use of a specially-crafted text message.

However, Apple was hardly alone in the hacking spotlight. An MWR InfoSecurity researcher who goes by the name 'Nils' was able to exploit the Firefox browser on Windows 7 through a previously unknown vulnerability.

Microsoft saw its latest browser laid to waste as well when researcher Peter Vreugdenhil compromised a fully-patched version of Internet Explorer 8 running on a Windows 7 notebook.

The only browser to survive the first day was Google's Chrome. None of the day-one contestants attempted to run an exploit on the browser.

Further exploits could be revealed in the next two days as the contest is expanded to browsers running on the Windows Vista and XP platforms.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

28%

1%

13%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Software Developer (.Net, VB.Net) – Skipton

Graduate Developer / Software Developer (.Net, VB.Net...

PHP Developer / Web Developer (PHP4/5, Object Orientated PHP)

PHP Developer / Web Developer (PHP4/5, Object Orientated...

Web Games Designer

Web Games Designer – Gibraltar Web Games Designer...

E-commerce Business / Systems Analyst - retail

An exciting opportunity for a Systems / Business Analyst...

To send to more than one email address, simply separate each address with a comma.