Film izle Sinema izle Bayan Azdirici Bayan Azdirici Damla Azdirici Geciktirici Sprey Geciktirici porno sex travesti cialis kiz oyunlari kiz oyunu oyna porno sex porn sex r57.txt c99 shell hackerbox



Community

February 4, 2011

Pwn2Own 2011 – Google offers $20,000 for Chrome Vulnerability

More articles by »
Written by: Jacob Cunningham
Tags: , , , ,
zdi_logo

That’s right $20,000 to any hacker that can successfully comprise a windows 7 machine running it’s Chrome Browser via a security vulnerability written in Google-written code and  sandbox escape.

CanSecWest’s Pwn2Own Contest is an annual event pitting some of the world’s best security analyst and exploit writers against the most popular web browsers and mobile devices. After last years contest, Google’s Chrome Browser was the only browser left unscathed. Given the money and prizes being offered and obvious publicity involved with successfully comprising the Chrome Browser, chances are good that the cross-hairs are already being lined up on this web browser.

Contest sponsor Tippingpoint ZDI says a successful Chrome hack “must include a sandbox escape”,  and be in Google-written code,  in order to win the $20,000. On day 2 and 3 if competitors are unsuccessful, they will be allowed to use exploits written in non-Google code to potentially compromise the browser. If they succeed on days 2 and 3 ZDI will offer $10000 for a sandbox escape and Google will offer $10000 for the Chrome bug.  In order to fully utilize a sandbox escape the exploit may have to be combined with another vulnerability for full system compromise.

On day 1, Google will offer $20,000 USD and the CR-48 if a contestant can pop the browser and escape the sandbox using vulnerabilities purely present in Google-written code. If competitors are unsuccessful, on day 2 and 3 the ZDI will offer $10,000 USD for a sandbox escape in non-Google code and Google will offer $10,000 USD for the Chrome bug. Either way, plugins other than the built-in PDF support are out of scope.

CanSecWest is also offering cash prizes for anyone using unpublished browser security holes to remotely launch code on Windows 7 or Mac OS X machines.

Browser Targets for this Year:

  • Microsoft Internet Explorer
  • Apple Safari
  • Mozilla Firefox
  • Google Chrome

Each browser will be installed on a 64-bit system running the latest version of Windows 7 or Mac OS X.

For mobile devices the attack surface has been increased to allow attack against the cell phones basebands.

Mobile Targets for this Year:

  • Dell Venue Pro – Windows 7
  • IPhone 4 – iOS
  • Blackberry Torch 9800 – Blackberry 6 OS
  • Nexus S – Android

A successful attack against these devices must require less to no user interaction and must compromise useful data from the phone. Anything that would cost the owner of the device money, ie: silently calling long-distance numbers, eavesdropping on conversations, etc, is within scope.

The contest is being held the 9th, 10th, and 11th of March, 2011 in Vancouver, BC during the CanSecWest Conference. For more information, registration, or to follow the contest visit TippingPoint ZDI’s website.

Source: TippingPoint ZDI







About the Author

Jacob Cunningham
I'm an avid technology lover. My first Android device was a G1; I fell in love (except for the battery), next I got a Samsung Captivate; error in judgment on my behalf, now I've moved on to the MyTouch 4G; which I absolutely love. What started with me just needing some kind of phone to use, i.e. free G1, ended with a new addiction.... I also enjoy long walks on the beach and luxurious bubble baths.... Oh wait.





 
 

 
Motorla Mobility

Google closes deal with Motorola, Dennis Woodside takes CEO Role

After China finally gave Google the proverbial thumbs up to go ahead with their acquisition of Motorola Mobility, the only thing left was to finalize the deal. We thought that might take at least till the end of the week. ...
by Stormy Beach
1

 
 
googlerola-img

Google finally gets China’s approval for Motorola Mobility purchase, on one Condition

Some of you may have forgotten all about Google and their acquisition of Motorola Mobility.  I know I did for a while. Even though they announced it last August, it has been held up waiting on China to approve  the purchase. ...
by Stormy Beach
0

 
 
Screen Shot 2012-05-18 at 6.19.43 PM

The ManDroid Show: Free the HTC EVO 4G and One X! Lock Up the iPhone!

Thank you as always for clicking into another episode of The ManDroid Show. Apple, I swear, why do you got to make our lives miserable? Try concentrating on make your out dated phone batter. Enjoy the show! News Topics HTC EVO ...
by David Pena
1

 

 
Jelly Bean

Google to launch multiple Android 5.0 Nexus devices through Google Play Store

I can’t say we were all that surprised to see the Galaxy Nexus show up for direct purchase from Google. The evolution of Android and the whole technology eco system is making for some great changes and new ways of doing b...
by Stormy Beach
2

 
 
OutSPin_Permissions_Final

OutSpin: Why Google will never get it right!

These have been an interesting two weeks (last week writer’s block did win over me) in the Android/Google world: Samsung presented the Galaxy SIII, Google and Oracle were in court waiting for a decision that could change ...
by Fernando Fonseca
6

 
 
Carrier billing

Google announces more direct carrier billing for Play Store Purchases

Many people have struggled with buying applications, games, books, movies and Music via the Play Store on our Android devices. Mostly due to the need for a credit card of some sort attached to your Google account to do so. Pers...
by Stormy Beach
3

 




One Comment


  1. Anonymous

    You guys really need to proof read articles, you’re looking very amateur and I mean it in a respectful way. Not only does the author use the word comprise when he is meaning to write ‘compromise’ but then later on he changes it to ‘compromise’ like it should have been to begin with, but then goes and spells it wrong.

    It just doesn’t do much for your guys professionalism to have writers who can’t properly write. Makes me want to visit a website with a bit more professionalism on board. I’m sure I’m not the only one who has felt like that.



Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


 
sexsikislezbiyensex izledeutschsex.netdeutschporno.net sexpornoporn videoshd sexsex free pornfree Porn videos
kiz oyunlari kiz oyunu oyna porno sex porn sex porno