Pwn2Own hacking contest winds down after paying a record $480K
Google, Mozilla rush out fixes for flaws revealed by researchers
Computerworld - A day after researchers hacked Chrome and Firefox at the Pwn2Own contest, Google and Mozilla patched their browsers Thursday.
The contest also wound down yesterday after hackers had earned a record $480,000 over two days.
The update to Chrome 25 came about 24 hours after two researchers from U.K. firm MWR InfoSecurity exploited multiple bugs in the browser and Windows 7. In exchange for their attack code and vulnerabilities, Nils -- a German who goes only by his first name -- and Jon Butler were awarded $100,000 by Pwn2Own organizer HP TippingPoint and its Zero Day Initiative (ZDI) bug bounty program.
The quick turn-around nearly matched last year's, when Google patched several Chrome vulnerabilities in under 24 hours after researchers unveiled them at a company-sponsored contest.
Mozilla also patched its Firefox browser on Thursday, closing a hole unveiled by a team from Vupen, a French vulnerability research and exploit-selling company. The team's exploit resulted in a cash prize of $60,000, the laptop used to host Firefox and other fringe benefits.
"We received the technical details on Wednesday evening and within less than 24 hours diagnosed the issue, built a patch, validated the fix and the resulting builds, and deployed the patch to users," said Michael Coates, Mozilla's director of security assurance, in a Thursday blog.
Mozilla had been expecting to patch Firefox, and had prepped for what it calls a "chemspill," or emergency update, before Pwn2Own began.
Firefox 19.0.2, like Chrome 25, has already been pushed to users, most of whom receive it automatically through the browser's in-the-background update mechanism.
The other browser hacked Wednesday at Pwn2Own, Microsoft's Internet Explorer 10 (IE10), has not yet been patched. It's possible, but very unlikely given Microsoft's practices, that a fix will be included in March 12's Patch Tuesday.
On Twitter, Vupen's CEO and head of research, Chaouki Bekrar, said that the exploit his team deployed works against IE10 both on the "classic" desktop in Windows 8 as well as the browser for the tile-based user interface (UI) dubbed "Modern" by Microsoft but still referred to as "Metro" by most outsiders.
On Thursday, Pwn2Own continued with the Vupen team researchers successfully exploiting the Adobe Flash Player browser plug-in. George Hotz, a 23-year-old best known for "jailbreaking" the iPhone and the Sony PlayStation 3 -- and now being sued by Sony for the latter -- later brought down Adobe Reader. Vupen and Hotz each received $70,000 for their Adobe vulnerabilities and hacks.
Oracle's Java was also hacked yesterday by Ben Murphy, making a total of four exploits of the under-assault software that's plagued users with a rash of "out-of-band," or emergency, updates this year. Murphy, like each of the others who cracked Java, earned $20,000.
- The 20 Best iPhone/iPad Games of 2013 So Far
- 9 Steps to Build Your Personal Brand (and Your Career)
- 7 Consumer Technologies Coming to an Enterprise Near You
- 11 Signs Your IT Project is Doomed
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Harness IT -- An Introduction to Business Intelligence Solutions Learn the key selection criteria required to provide your organization with the capability to address structured data, unstructured data and mobile demands so...
- Business Intelligence Shows its Smarts Today's Business Intelligence (BI) tools provide a new way to think about data with self-service capabilities and user-friendly analytics that can be used...
- Proactive Planning for Big Data Big data is less about the terabytes and more about the query tools and business intelligence needed to make sense of massive amounts...
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- Becoming An Analytics Driven Organization Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in... All Cybercrime and Hacking White Papers | Webcasts