Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Pwn2Own hack topples Firefox on Windows  (Read 17529 times)

0 Members and 1 Guest are viewing this topic.

Computer Hope Admin

    Topic Starter
  • Administrator


  • Prodigy

    Thanked: 248
    • Yes
    • Yes
    • Yes
    • Computer Hope
  • Certifications: List
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 10
Pwn2Own hack topples Firefox on Windows
« on: March 31, 2010, 04:37:16 PM »
The first day of the CanSecWest Pwn2Own hacker challenge wrapped up here today with a familiar face going after a familiar target.

And, for the second year in a row, a German hacker known simply as “Nils” exploited a previously unknown vulnerability in Mozilla Firefox to take complete control of a 64-bit Windows 7 machine.

Link
Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein

BC_Programmer


    Mastermind
  • Typing is no substitute for thinking.
  • Thanked: 1140
    • Yes
    • Yes
    • BC-Programming.com
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Windows 11
Re: Pwn2Own hack topples Firefox on Windows
« Reply #1 on: April 01, 2010, 07:46:28 AM »
It's interesting to note here that it would appear that the "weak link" in exploiting firefox was firefox itself- simply because firefox was not taking full advantage of some of the features of windows. Could one surmise that this very same technique could work on Firefox running on other platforms?
I was trying to dereference Null Pointers before it was cool.

Computer Hope Admin

    Topic Starter
  • Administrator


  • Prodigy

    Thanked: 248
    • Yes
    • Yes
    • Yes
    • Computer Hope
  • Certifications: List
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 10
Re: Pwn2Own hack topples Firefox on Windows
« Reply #2 on: April 01, 2010, 10:09:55 AM »
It's possible but since no details were posted hard to say. I'd assume that because he went after Safari on MacOS that it may not be the case, however he could of just went for Safari because it's the default browser. I know one thing for sure if I was Microsoft I'd be paying any amount imaginable to get this guy on my staff and make Windows more secure by just having him find holes.
Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein

Quantos



    Guru
  • Veni, Vidi, Vici
  • Thanked: 170
    • Yes
    • Yes
  • Computer: Specs
  • Experience: Guru
  • OS: Linux variant
Re: Pwn2Own hack topples Firefox on Windows
« Reply #3 on: April 01, 2010, 10:12:32 AM »
I know one thing for sure if I was Microsoft I'd be paying any amount imaginable to get this guy on my staff and make Windows more secure by just having him find holes.
Second.
Evil is an exact science.

BC_Programmer


    Mastermind
  • Typing is no substitute for thinking.
  • Thanked: 1140
    • Yes
    • Yes
    • BC-Programming.com
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Windows 11
Re: Pwn2Own hack topples Firefox on Windows
« Reply #4 on: April 01, 2010, 10:15:55 AM »
They already have a lot of security analysts that are at least as good as him, actually. Many of them have blogs.

However it's important to note that the vulnerability is largely firefox's, not Windows; after all, as stated in the article, the biggest stumbling block was in fact mitigating the built in windows protections to prevent exactly what he was trying to do; as well as how ill-fit Firefox is in using those technologies explicitly (relying on Windows' default behaviour, I imagine).
I was trying to dereference Null Pointers before it was cool.

Computer Hope Admin

    Topic Starter
  • Administrator


  • Prodigy

    Thanked: 248
    • Yes
    • Yes
    • Yes
    • Computer Hope
  • Certifications: List
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 10
Re: Pwn2Own hack topples Firefox on Windows
« Reply #5 on: April 01, 2010, 10:17:46 AM »
Yeah that's true. He didn't come through Internet Explorer, and that's saying a lot.
Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: Pwn2Own hack topples Firefox on Windows
« Reply #6 on: April 01, 2010, 12:10:53 PM »
Umm IE8 got creamed as well...
It's always bigger news when it's the Fox...

Story
" Anyone who goes to a psychiatrist should have his head examined. "

Computer Hope Admin

    Topic Starter
  • Administrator


  • Prodigy

    Thanked: 248
    • Yes
    • Yes
    • Yes
    • Computer Hope
  • Certifications: List
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 10
Re: Pwn2Own hack topples Firefox on Windows
« Reply #7 on: April 01, 2010, 12:27:11 PM »
I stand corrected.
Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein

BC_Programmer


    Mastermind
  • Typing is no substitute for thinking.
  • Thanked: 1140
    • Yes
    • Yes
    • BC-Programming.com
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Windows 11
Re: Pwn2Own hack topples Firefox on Windows
« Reply #8 on: April 01, 2010, 12:33:46 PM »
Umm IE8 got creamed as well...
It's always bigger news when it's the Fox...

Story

True, but specifically I was referring to the fact that it was the application(firefox), not the platform(Windows) that had the security problem.

I gave up on Security in IE long ago. It's usable and they certainly are doing better but I think their security analysts must be working elsewhere.
I was trying to dereference Null Pointers before it was cool.

Hdthree



    Starter

    Re: Pwn2Own hack topples Firefox on Windows
    « Reply #9 on: April 01, 2010, 09:52:00 PM »
    This is interesting the only other hacking conference I know of is Defcon are there many others?

    Computer Hope Admin

      Topic Starter
    • Administrator


    • Prodigy

      Thanked: 248
      • Yes
      • Yes
      • Yes
      • Computer Hope
    • Certifications: List
    • Computer: Specs
    • Experience: Guru
    • OS: Windows 10
    Re: Pwn2Own hack topples Firefox on Windows
    « Reply #10 on: April 02, 2010, 12:00:02 AM »
    Another big one is HOPE

    http://thenexthope.org/
    Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
    -Albert Einstein

    rthompson80819



      Specialist

      Thanked: 94
    • Experience: Experienced
    • OS: Windows 7
    Re: Pwn2Own hack topples Firefox on Windows
    « Reply #11 on: April 02, 2010, 12:09:41 AM »
    This is the story you never hear about, although it happens a lot,  hacking Apple products.

    http://blogs.zdnet.com/security/?p=5846&tag=col1;post-5855

    Salmon Trout

    • Guest
    Re: Pwn2Own hack topples Firefox on Windows
    « Reply #12 on: April 02, 2010, 03:32:43 AM »
    could of just went

    [rant]

    Could have just gone, please!!!

    [/rant]

    mr-bisquit

    • Guest
    Re: Pwn2Own hack topples Firefox on Windows
    « Reply #13 on: April 13, 2010, 03:55:24 PM »
    When they can hack through a secured firefox on a hardened BSD system, let me know.

    BC_Programmer


      Mastermind
    • Typing is no substitute for thinking.
    • Thanked: 1140
      • Yes
      • Yes
      • BC-Programming.com
    • Certifications: List
    • Computer: Specs
    • Experience: Beginner
    • OS: Windows 11
    Re: Pwn2Own hack topples Firefox on Windows
    « Reply #14 on: April 13, 2010, 04:52:21 PM »
    When they can hack through a secured firefox on a hardened BSD system, let me know.

    When FreeBSD is used by people without something to prove let me know.
    I was trying to dereference Null Pointers before it was cool.