'Pinkie Pie' trips up Chrome, close to $60K at Hack in the Box
It's the second time the pseudonymous hacker has submitted vulnerabilities for Google's top Pwnium award
IDG News Service - It appears the hacker known as "Pinkie Pie" produced the first Chrome vulnerability at the Hack In the Box conference on Wednesday, just ahead of the deadline for the competition this afternoon.
Google security officials said they are in the process of verifying the vulnerability, which if valid, will net Pinkie Pie US$60,000, the top reward for the second Pwnium competition held this year. The reward goes to someone who creates a full Chrome exploit using bugs only in Chrome itself.
Google has allotted a total of $2 million in reward money for the second round of Pwnium, the first of which was held in March at the CanSecWest security conference in Vancouver, British Columbia.
Pinkie Pie is well known for his skills. He secured $60,000 in the first Pwnium competition for stringing together six vulnerabilities in order to break out of Chrome's sandbox, which is a software boundary designed to quarantine malicious behavior within a browser and not allow it to reach the rest of the computer's software.
Pinkie Pie is apparently not at Hack in the Box this week. Instead, a colleague submitted his entry, which was hosted on Google's infrastructure. Google quickly moves to patch problems found with its browser via an auto-update mechanism.
Google is offering such rich rewards for finding vulnerabilities because it has become harder to exploit the browser. It also takes more time to find those vulnerabilities, so Google has allowed security gurus to work on their exploits for two months.
The final results will be announced late Thursday afternoon near the end of the conference.
Send news tips and comments to email@example.com
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts