Pwn2Own: Hacker busts IE8 on Windows 7 in 2minutes. Dutch researcher bypasses DEP, ASLR to bring down Microsoft's browser.
Two researchers yesterday won $10,000 each at the Pwn2Own hacking contest by bypassing important security measures of Windows 7.
Both Peter Vreugdenhil of the Netherlands and a German researcher who only would give his first name of Nils, found ways to disable DEP (data execution prevention) and ASLR (address space layout randomization), two of Windows 7's most vaunted anti-exploit features. Each faced down the fully-patched 64-bit version of Windows 7 and came out the winner.
Pwn2Own: Hacker busts IE8 on Windows 7 in 2minutes. Dutch researcher bypasses DEP, ASLR to bring down Microsoft's browser.
Two researchers yesterday won $10,000 each at the Pwn2Own hacking contest by bypassing important security measures of Windows 7.
Both Peter Vreugdenhil of the Netherlands and a German researcher who only would give his first name of Nils, found ways to disable DEP (data execution prevention) and ASLR (address space layout randomization), two of Windows 7's most vaunted anti-exploit features. Each faced down the fully-patched 64-bit version of Windows 7 and came out the winner.
System Manufacturer/Model Number tw33k OS Windows 7 Ultimate (x64) SP1 CPU Intel 3770k 4.6GHz Motherboard ASUS Maximus V Formula Memory 8GB (2x 4GB) Crucial Ballistix Graphics Card Sapphire 7950 (1060/1600) Sound Card On Board Realtek HD Audio Monitor(s) Displays 27" Acer B273HU (via HDMI) Screen Resolution 2048 x 1152
Keyboard Microsoft Wireless 5000 Mouse Microsoft Wireless 5000 PSU Corsair AX750 Gold Case Corsair Obsidian 800DW Cooling Corsair H100 (2x AP-121/2x UK-3000 push/pull) Hard Drives Crucial M4 128GB
2TB WD Black
1TB Samsung F3 SATA
1TB WD Elite External
2TB WD USB 3.0 Internet Speed 5mb/s Other Info Logitech z-2300 2.1 speakers
Lamptron FC-5 v2
I agree, JMH. Although news, this is security related.
(I just wish you & I would stop cross-posting each other. I posted the Microsoft response in the similar topic I had started in CanSecWest Pwn2Own Victories.)
System Manufacturer/Model Number tw33k OS Windows 7 Ultimate (x64) SP1 CPU Intel 3770k 4.6GHz Motherboard ASUS Maximus V Formula Memory 8GB (2x 4GB) Crucial Ballistix Graphics Card Sapphire 7950 (1060/1600) Sound Card On Board Realtek HD Audio Monitor(s) Displays 27" Acer B273HU (via HDMI) Screen Resolution 2048 x 1152
Keyboard Microsoft Wireless 5000 Mouse Microsoft Wireless 5000 PSU Corsair AX750 Gold Case Corsair Obsidian 800DW Cooling Corsair H100 (2x AP-121/2x UK-3000 push/pull) Hard Drives Crucial M4 128GB
2TB WD Black
1TB Samsung F3 SATA
1TB WD Elite External
2TB WD USB 3.0 Internet Speed 5mb/s Other Info Logitech z-2300 2.1 speakers
Lamptron FC-5 v2
I agree, JMH. Although news, this is security related.
(I just wish you & I would stop cross-posting each other. I posted the Microsoft response in the similar topic I had started in CanSecWest Pwn2Own Victories.)
Have noticed Corrine - perhaps IM might help with a solution................ [We seem to source the same areas for new information.]