Chrome, IE and Firefox Hacked
Written by Alex Armstrong   
Wednesday, 14 March 2012

By the end of the Pwn2Own competition held last week Google Chrome, Microsoft Internet Explorer and Mozilla Firefox were all subject to zero day exploits. In the separate Pwnium competition Chrome was a victim twice over. 

VuPen, the French team that felled Chrome within the first five minutes of the contest (see Chrome Hacked Twice at CanSecWest) were the overall winners of Pwn2Own, collecting the $60,000 prize for having the greatest number of points (123). On the final day of the competition VuPen exposed two vulnerabilities in Internet Explorer 9 that are also claimed to go back as far as IE6 and also to affect future generations of Microsoft's browser.

Relying on work done over the previous six weeks, the VuPen team used an unpatched heap-overflow bug to bypass DEP and ASLR and a separate memory corruption flaw to work around the browser's "Protected Mode" sandbox, the security feature that's meant to contain malicious code and prevent it from executing any commands on system.

browsers

The second prize awarded at the end of Pwn2Own went to the two-man team of Willem Pinckaers and Vincenzo Iozzo whose zero-day attack on Firefox involved a use-after-free problem which evaded DEP and ASLR protections in Windows 7. The same vulnerability was first used to leak information multiple times and was then used a a conduit through which execute prepared code, again through the same vulnerability. Pinckaers and Iozzo won $30,000 for amassing 66 points.

A second prize ($60,000) was also awarded in Google's separate Pwnium contest, organized once it became apparent that the new rules for Pwn2Own meant contestants would not have to reveal the full exploits or even the bugs used. A few hours before the contest closed a teenage hacker known as Pinkie Pie chained two, or possibly, three zero day vulnerabilities in Chrome together to break out of the browser's sandbox and execute code.

Google has already patched both this vulnerability and the earlier one by Russian researcher Sergey Glazunov. 

Google’s Jason Kersey also said the two Pwnium vulnerability submissions are “works of art that deserve wider sharing and recognition" and plans to prepare technical reports on both Pwnium submissions.

 

Related Articles

Chrome Hacked Twice at CanSecWest

Google Offers $1 million for Chrome Hack

 

 

espbook

 

Comments




or email your comment to: comments@i-programmer.info

 

To be informed about new articles on I Programmer, subscribe to the RSS feed, follow us on Google+, Twitter, Linkedin or Facebook or sign up for our weekly newsletter.

 

Banner

 


Google Releases Gemini 2 And Jules Code Agent
18/12/2024

Google has announced an updated version of Gemini, saying that Gemini 2.0 Flash Experimental will "enable even more immersive and interactive applications", along with new coding agents that can take  [ ... ]



Gifts For Geeks 2024
22/11/2024

Are you ready for Thanksgiving, when overeating remorse and a surfeit of being thankful causes the unsettling thought that there are only four weeks till the Xmas break? So here is a mix of weird [ ... ]


More News

Last Updated ( Wednesday, 14 March 2012 )