| Windows 7: IE and Safari out at Pwn2Own on day 1 |
10 Mar 2011
|
#1 | | |
IE and Safari out at Pwn2Own on day 1 I really wish they would have tested IE9...but not being released yet means they won't...because pre-release versions of something are just that, unfinished and not ready for prime-time. Making sport of browser security, hackers topple IE, Safari • The Register Quote: Contestants in a high-stakes hacking contest had no trouble toppling the Apple Safari and Microsoft Internet Explorer browsers, proving for a fifth year in a row that no software or application is safe from people with the expertise and motivation to exploit them.
The attacks came on Day One of the Pwn2Own contest, which pays more than $15,000 apiece for exploits that successfully give the attacker full remote access of the targeted machine. Wednesday's event saw hackers take complete control of a fully patched Sony Vaio and MacBook Air by compromising IE and Safari respectively. Google's Chrome browser was also up for grabs, but no one stepped forward to try hacking it. Google's Chrome untouched at Pwn2Own hack match - Computerworld Quote: If Chrome comes out unscathed, as it now appears it will, the browser will have survived three consecutive Pwn2Owns, a record.
Firefox testing was expected to commence today. | My System Specs |
| System Manufacturer/Model Number Self-Built in July 2009 OS Windows 7 Ultimate x64 CPU Intel Q9550 2.83Ghz OC'd to 3.40Ghz Motherboard Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS Memory 8GB G.Skill PI DDR2-800, 4-4-4-12 timings Graphics Card EVGA 1280MB Nvidia GeForce GTX570 Sound Card Realtek ALC899A 8 channel onboard audio Monitor(s) Displays 23" Acer x233H Screen Resolution 1920x1080 Keyboard ABS M1 Mechanical Mouse Logitech G9 Laser Mouse PSU Corsair 620HX modular Case Antec P182 Cooling stock Hard Drives Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS Internet Speed 15/2 cable modem Other Info Windows and Linux enthusiast. Logitech G35 Headset. |
10 Mar 2011
|
#2 | | Windows 7 Ultimate x64 SP1 UK |
I knew there was a good reason why I was using Chrome
Apple need to up their security a lot more, that result is really really poor, IE8 well who's surprised about that one, not me that's for sure.
Hopefully Firefox's security can hold out. | My System Specs | | System Manufacturer/Model Number Acer Aspire 5742 OS Windows 7 Ultimate x64 SP1 CPU Intel Core i3-370M @ 2.4GHz Motherboard Mobile Intel HM55 Express Chipset Memory 6GB 1333MHz DDR3 Graphics Card Intel GMA HD Monitor(s) Displays 15.6" HD Acer CineCrystal LED LCD Screen Resolution 1366×768 Mouse Microsoft Wireless Optical Mouse 3000 PSU 65W Hard Drives 320GB (5400 RPM) SATA Internet Speed 6Mbps Other Info WEI Score: 4.6 |
10 Mar 2011
|
#3 | | |
Do you guys know if they test Opera? I would be really curious to see the results for that one. I don't like the idea that they are just going after FF 3.6, and IE8, instead of the 4 and 9 respectively... Nonetheless, the results should be interesting. | My System Specs | | System Manufacturer/Model Number Dell Studiio 1555 OS Windows 8 Pro CPU Core 2 Duo P8600 2.4 ghz Memory 4GB DDR2 Graphics Card ATI Radeon 4570 512MB Sound Card IDT High Definition Monitor(s) Displays 15.6" Screen Resolution 1920x1080 Hard Drives 250GB 7200 RPM SATA |
10 Mar 2011
|
#4 | | Windows 7 Ultimate x64 SP1 UK |

Quote: Originally Posted by Windows 911 Do you guys know if they test Opera? I would be really curious to see the results for that one. I don't like the idea that they are just going after FF 3.6, and IE8, instead of the 4 and 9 respectively... Nonetheless, the results should be interesting. Because they are aren't released yet, pointless testing development software, wouldn't really be fair plus their usage won't be as wide spread as the stable versions. | My System Specs | | System Manufacturer/Model Number Acer Aspire 5742 OS Windows 7 Ultimate x64 SP1 CPU Intel Core i3-370M @ 2.4GHz Motherboard Mobile Intel HM55 Express Chipset Memory 6GB 1333MHz DDR3 Graphics Card Intel GMA HD Monitor(s) Displays 15.6" HD Acer CineCrystal LED LCD Screen Resolution 1366×768 Mouse Microsoft Wireless Optical Mouse 3000 PSU 65W Hard Drives 320GB (5400 RPM) SATA Internet Speed 6Mbps Other Info WEI Score: 4.6 |
10 Mar 2011
|
#5 | | |
That is quite true, good point. Well, I'll have to wait to see next year.  I just looked up the results for the fall of IE8, they bypassed ASLR, DEP, and the protected mode. Pwn2own said that they never saw that before... And like you said, Apple seriously needs to step up their game. I have read multiple articles that Apple's security is definitely lacking... | My System Specs | | System Manufacturer/Model Number Dell Studiio 1555 OS Windows 8 Pro CPU Core 2 Duo P8600 2.4 ghz Memory 4GB DDR2 Graphics Card ATI Radeon 4570 512MB Sound Card IDT High Definition Monitor(s) Displays 15.6" Screen Resolution 1920x1080 Hard Drives 250GB 7200 RPM SATA |
10 Mar 2011
|
#6 | | Windows 7 x64 Ultimate San Diego |
They can't be trying very hard on Opera given the number of vulnerabilities found in it over the last year :/ http://secunia.com/advisories/search/?search=opera
One always has to queestion the motivations of the participants. EVERYONE wants to bag on IE, but what street cred to you get from poking holes in everyones hero Opera? | My System Specs | | System Manufacturer/Model Number Scratch built OS Windows 7 x64 Ultimate CPU i7 960 Motherboard Asus P6X58D Memory 12 Gig Corsair Dominator Graphics Card Nvidia 480 Sound Card Maudio Delta 44 + breakout box Monitor(s) Displays Dell UltraSharp U2410 24in and Samsung 21 dual monitors Screen Resolution 1920x1200 and 1280x1024 Keyboard Logitech G15 + N52 game pad Mouse Logitech MX518 PSU Corasair TX850 Case Cooler Master HAF Cooling Corsair H50 Hard Drives Primary: Intel X-25M G2 160G SSD
Secondary: Segate baracuda 1.0 TB
HDs in AHCI mode. Internet Speed 15kbs down 4.5kbps up Other Info WEI 7.6
CPU & RAM 7.6
Graphics 7.9
Hard disk 7.7 |
10 Mar 2011
|
#7 | | |

Quote: Originally Posted by Windows 911 That is quite true, good point. Well, I'll have to wait to see next year.  I just looked up the results for the fall of IE8, they bypassed ASLR, DEP, and the protected mode. Pwn2own said that they never saw that before... I honestly don't expect the situation with IE to improve much by next year. Honestly, they were supposed to be better with IE6 (and weren't), IE7 (and weren't), IE8 (well, we all now how secure that has been), and now here comes IE8. 
Quote: Originally Posted by Windows 911 And like you said, Apple seriously needs to step up their game. I have read multiple articles that Apple's security is definitely lacking... Apple doesn't have enough customers for it to really matter. | My System Specs | | System Manufacturer/Model Number Self-Built in July 2009 OS Windows 7 Ultimate x64 CPU Intel Q9550 2.83Ghz OC'd to 3.40Ghz Motherboard Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS Memory 8GB G.Skill PI DDR2-800, 4-4-4-12 timings Graphics Card EVGA 1280MB Nvidia GeForce GTX570 Sound Card Realtek ALC899A 8 channel onboard audio Monitor(s) Displays 23" Acer x233H Screen Resolution 1920x1080 Keyboard ABS M1 Mechanical Mouse Logitech G9 Laser Mouse PSU Corsair 620HX modular Case Antec P182 Cooling stock Hard Drives Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS Internet Speed 15/2 cable modem Other Info Windows and Linux enthusiast. Logitech G35 Headset. |
10 Mar 2011
|
#8 | | W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE Indian Territory |

Quote: Originally Posted by fseal They can't be trying very hard on Opera given the number of vulnerabilities found in it over the last year :/ Search - Advisories - Community
One always has to queestion the motivations of the participants. EVERYONE wants to bag on IE, but what street cred to you get from poking holes in everyones hero Opera? That is a very poor accessment of Opera. If you take the time to check, all of those vulnerabilities have been fixed in the current version. What does make a browse insecure, such as IE has always been in the past, is that a known vulnerability is not fixed, or worse that some are never published so that the users are unaware of them.
Opera has ALWAYS been the most secure browser available. That does not mean that it is perfect, nor that faults will never be found, it means that once a vulnerability is known, Opera fixes it VERY rapidly. | My System Specs | | System Manufacturer/Model Number DIY OS W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE CPU Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3 Motherboard ASRock 890FX Deluxe 4/**A8N-SLI Memory 2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS Graphics Card EVGA GTX460 SC/**EVGA 8800GTS Sound Card Asus Xonar D2X/**Xonar D1 Monitor(s) Displays Acer X233H, Dell E152FPc /**LG M237-WD Screen Resolution 1920x1080 & 1024x768/**1980x1080 Keyboard Logitech Media USB/**Saitek Eclipse Mouse Cordless Trackman Wheel/**Ditto PSU CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000 Case HAF922/**Antec 1040IIB Cooling 3x200mm, 1x140 and 1x120mm/**5x80mm fans Hard Drives WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black Internet Speed 3.3Mbps Other Info SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig) |
10 Mar 2011
|
#9 | | |
I think many of the contestants in Pwn2Own use Opera for their browser. I wonder which one is more secure, Chrome or Opera? I personally like Opera a bit more because of its fantastic Software acceleration and more personal options to choose from. | My System Specs | | System Manufacturer/Model Number Dell Studiio 1555 OS Windows 8 Pro CPU Core 2 Duo P8600 2.4 ghz Memory 4GB DDR2 Graphics Card ATI Radeon 4570 512MB Sound Card IDT High Definition Monitor(s) Displays 15.6" Screen Resolution 1920x1080 Hard Drives 250GB 7200 RPM SATA |
10 Mar 2011
|
#10 | | Windows 7 x64 Ultimate San Diego |
Well yes, of course they are all fixed, but given that they are being found at a steady rate, it's pretty safe to assume that it still has some, in fact probably a lot. Until the discoveries slow down to one or two a year, the software is guaranteed to contain plenty more waiting to be discovered.
Sentences like this "Google's Chrome browser was also up for grabs, but no one stepped forward to try hacking it." speaks voolumes about the fairness of it all.
Given that Safari and Chrome are based on the same base layout engine, it's entirely likely to suffer a lot of the same flaws. Why aren't people going after it? If Google makes it through because no one dared to suffer community retribution for even trying, does it get to claim it survived too?
So again, if Opera makes it through unscathed it's far more likely it's because no one bothered to try very hard... The people that do the hacking as well as the contests are so religeously polarized you can't judge much at all by the outcomes, and that's really a shame | My System Specs | | System Manufacturer/Model Number Scratch built OS Windows 7 x64 Ultimate CPU i7 960 Motherboard Asus P6X58D Memory 12 Gig Corsair Dominator Graphics Card Nvidia 480 Sound Card Maudio Delta 44 + breakout box Monitor(s) Displays Dell UltraSharp U2410 24in and Samsung 21 dual monitors Screen Resolution 1920x1200 and 1280x1024 Keyboard Logitech G15 + N52 game pad Mouse Logitech MX518 PSU Corasair TX850 Case Cooler Master HAF Cooling Corsair H50 Hard Drives Primary: Intel X-25M G2 160G SSD
Secondary: Segate baracuda 1.0 TB
HDs in AHCI mode. Internet Speed 15kbs down 4.5kbps up Other Info WEI 7.6
CPU & RAM 7.6
Graphics 7.9
Hard disk 7.7 IE and Safari out at Pwn2Own on day 1 problems? All times are GMT -5. The time now is 04:25 PM. | |