IE and Safari out at Pwn2Own on day 1

"Google's Chrome browser was also up for grabs, but no one stepped forward to try hacking it."

Sorry,, wrong answer for me.

Really? Why, specifically? So, what they are saying,, Google Chrome has their browser so locked down that The NSA, CIA, MI5, what ever initials you want to put up there can be 100% garraunteed to never, ever, not once, EVER, FOREVER, be NOT ONE TINY BIT vulnerable?

I call BS.

This doesn't mean that there will never ever be a vulnerability of any kind. But it does seem to clearly indicate that there isn't a known exploit yet to these hackers which can be used to gain administrative access to the host computer which is the whole point of the Pwn2Own contest.

Hackers at Pwn2Own and BlackHat do not pussy foot around and pretend that everything is all perfect and beautiful. They hack, attack and bring systems to their knees. They didn't manage it on either Firefox or Chrome...that says a lot.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Q9550 2.83Ghz OC'd to 3.40Ghz8GB G.Skill PI DDR2-800, 4-4-4-12 timingsEVGA 1280MB Nvidia GeForce GTX570
Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
an doesn't matter, I made my point and I stick by it.

I call BS.
 

My Computer My Computer

At a glance

Win 7 Ultimate 32bitC2D E6600 2.4Ghz4G Kingston KHX5400D2EVGA GTX 570 HD SC (012-P3-1573-KR)
Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
an doesn't matter, I made my point and I stick by it.

I call BS.

Thats fine you are entitled to this opinion. But considering either 20k or 35k was on the line, it seems rather far fetched.

You do realize that hackers come into the contest with known exploits and such. They aren't released from vacuum tubes and just start hammering away at the keyboard until they find something right?? It seems painfully obvious to me that previous to right at this moment, these guys/gals are not equipped with anything to exploit Chrome to the point where the machine is administratively owned.

Edit: i too will bow out at this point as I'm trying to be a jerk towards anybody and I firmly believe that it was not rigged and results are fair.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Q9550 2.83Ghz OC'd to 3.40Ghz8GB G.Skill PI DDR2-800, 4-4-4-12 timingsEVGA 1280MB Nvidia GeForce GTX570
Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
There is the possibility that no one tried, because there are much easier fish to fry, but that doesn't mean that it is not possible, nor that the browser is safe, it just means that no one spent time on it.

The problem is, they say, no one is testing it.

Then it is automatically assumed, "wow, none of these guys are testing it, must be hard to crack"
"These guys would want to be the first to crack it, but, they haven't even tried, that says a lot."

What about,,,

How much time did they spend trying to crack it?
What methods did they use and failed?

Sorry, but you know what they say about Assume ing things.
 

My Computer My Computer

At a glance

Win 7 Ultimate 32bitC2D E6600 2.4Ghz4G Kingston KHX5400D2EVGA GTX 570 HD SC (012-P3-1573-KR)
Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
Nobody ‘Pwns’ Google Chrome at Pwn2Own 2011
Looks like Google will leave from Pwn2Own with same amount of money they came with. Pwn2Own is a competition at the CanSecWest security conference in Vancouver. In order to ‘pwn’ something, the hacker must successfully execute code using a 0-day vulnerability (meaning a vulnerability that has has not been made public, a new one) on the browser running on that machine. IE8, Safari, and Chrome were the three choices at this years conference.
A month ago Google said they would pay $20,000 to the first person that successfully cracked their Chrome Browser, and it looks like no one is up to that task.



Safari was cracked in a mere 5 minutes, and IE8 on the first day of the competition. An interesting note is that Apple released a new version of Safari minutes before the competition started. Anyone who thought they had an edge on the competition had to rethink their plan of attack.



Google Chrome on the other hand is still waiting for anyone to challenge their security. Out of the two contestants that signed up, one didn’t show up, and the other team decided to put their efforts into something else.


Here is the sign up sheet for the conference;
TippingPoint | DVLabs | Announcing Pwn2Own 2011

As mentioned previously, we've upped the ante this time around and the total cash pool allotted for prizes has risen to a whopping $125,000 USD. While HP TippingPoint is funding $105,000 of that, we've partnered with Google who has generously offered up $20,000 to the researcher who can best their Chrome browser. Kudos to the Google security team for taking the initiative to approach us on this; we're always in favor of rewarding security researchers for the work they too-often do for free.
A successful hack of IE, Safari, or Firefox will net the competitor a $15,000 USD cash prize, the laptop itself, and 20,000 ZDI reward points which immediately qualifies them for Silver standing. Benefits of ZDI Silver standing include a one-time $5,000 USD cash payment, 15% monetary bonus on all ZDI submissions in 2011, 25% reward point bonus on all ZDI submissions in 2011 and paid travel and registration to attend the DEFCON Conference in Las Vegas.

As for Chrome, the contest will be a two-part one. On day 1, Google will offer $20,000 USD and the CR-48 if a contestant can pop the browser and escape the sandbox using vulnerabilities purely present in Google-written code. If competitors are unsuccessful, on day 2 and 3 the ZDI will offer $10,000 USD for a sandbox escape in non-Google code and Google will offer $10,000 USD for the Chrome bug. Either way, plugins other than the built-in PDF support are out of scope.

Here is a link that describes the Google bounty
https://www.infosecisland.com/blogview/11569-Google-Bounty-20K-to-Hack-Chrome-at-Pwn2Own.html
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Q9550 2.83Ghz OC'd to 3.40Ghz8GB G.Skill PI DDR2-800, 4-4-4-12 timingsEVGA 1280MB Nvidia GeForce GTX570
Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Nice info pparks1.

They get 15k and ZDI Silver for hacking IE, Safari, or Firefox and 35k for hacking Chrome.
So what was the reason they didn't hack Chrome? :sarc:

Firefox and Chrome are the two safest browsers, so far.
 

My Computer My Computer

At a glance

Windows 7 Ult x64 - SP1/ Windows 8 Pro x64Intel Core i5-3570K 4.6GHz8GB (2X4GB) DDR3 1600 Corsair Vengeance CL8 1.5vSapphire HD 7770 Vapor-X OC 1GB DDR5
Computer type
PC/Desktop
Computer Manufacturer/Model Number
76~2.0
OS
Windows 7 Ult x64 - SP1/ Windows 8 Pro x64
CPU
Intel Core i5-3570K 4.6GHz
Motherboard
Gigabyte GA-Z77X UD3H, f18
Memory
8GB (2X4GB) DDR3 1600 Corsair Vengeance CL8 1.5v
Graphics Card(s)
Sapphire HD 7770 Vapor-X OC 1GB DDR5
Sound Card
Onboard VIA VT2021
Monitor(s) Displays
22" LCD Dell
Screen Resolution
1680x1050
Hard Drives
Samsung 840Pro 128GB SSD,
Seagate Barracuda 500GB SATA2 7200rpm 32MB cache, Seagate Barracuda 1TB SATA2 7200rpm 32MB cache,
PSU
Corsair HX650W
Case
Cooler Master Storm Scout
Cooling
Corsair H80 2x12cm Noctua NF P12 , 2x14cm case fans
Keyboard
Logitech Wave
Mouse
CM Sentinel
Internet Speed
Dismal
Antivirus
Avast
Browser
Opera Next
Other Info
Haswell laptop: HP Envy 17t-j, i7-4700MQ, GeForce 740M 2GB DDR3, 17.3" Full HD 1920x1080, 16GB RAM, Samsung 840 Pro 128GB, 1TB Hitachi 7200 HDD,
Desktop: eSATA ports,
External eSATA Seagate 500GB SATA2 7200rpm,
External WD USB 500GB

My Computer My Computer

At a glance

W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCEPhenom II 1090T w/Noctua NH-D14 /**4400+ X2 w...2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsai...EVGA GTX460 SC/**EVGA 8800GTS
Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
I'm not a chrome user, but I think that PSI was detecting the previous version as insecure and wanted you to get to the newest version. Unfortunately that was the newest version. If you update PSI and scan again, I think you come back clean.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Q9550 2.83Ghz OC'd to 3.40Ghz8GB G.Skill PI DDR2-800, 4-4-4-12 timingsEVGA 1280MB Nvidia GeForce GTX570
Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
There are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. The’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.

I might have this bug and I might be able to get code execution. But now you’r ein a sandbox and you have no permissions to do anything. You need another bug to get out of the sandbox. Now you need two bugs and two exploits. That raises the bar.
Questions for Pwn2Own hacker Charlie Miller | ZDNet (2009)
 

My Computer My Computer

At a glance

Arch Linux 64-bit
OS
Arch Linux 64-bit
I will admit that I didn't read it in detail, but perhaps one of you that feel so safe with Chrome can explain this for me:

PSI says Chrome 10.0.648.127 is insecure. - Programs - Forum - Community

From what I gather from that, it was fixed when PSI was updated.

There are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. The’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.

I might have this bug and I might be able to get code execution. But now you’r ein a sandbox and you have no permissions to do anything. You need another bug to get out of the sandbox. Now you need two bugs and two exploits. That raises the bar.
Questions for Pwn2Own hacker Charlie Miller | ZDNet (2009)

That explains Chrome's Sandbox quite well. Maybe if you took the time to read things liek that, Tepid, you'd understand more and not just call BS at everything.
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel Core i7 4790k8GB Corsair Dominator 1600MHzMSI TwinFrozr GeForce GTX770
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 8.1 Pro x64
CPU
Intel Core i7 4790k
Motherboard
MSI Z97S Krait Edition
Memory
8GB Corsair Dominator 1600MHz
Graphics Card(s)
MSI TwinFrozr GeForce GTX770
Sound Card
ASUS Xonar DX/XD 7.1
Monitor(s) Displays
Dell 24" S2409W + Dell 20" E207WFP
Screen Resolution
1920x1080 + 1680x1050
Hard Drives
1x 120GB OCZ Agility 3, 1x 750GB Western Digital Caviar Black, 1x 1TB Western Digital Caviar Blue
PSU
Corsair HX850 modular
Case
Fractal Design Define R4
Cooling
Corsair H60 w/ twin Corsair SP120 fans
Keyboard
Logitech G510S Keyboard
Mouse
Logitech G500S Laser Mouse
Internet Speed
40Mbps
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Other Info
LG Blu-Ray player
I never said it would be easy.

But flat out assuming certain things, such as,,, "chrome is safe, cause no one is testing it" is an absurd argument.

Try making that claim on anything else. It just doesn't work that way.

Google patched 25 vulnerabilities in Chrome today in one last update before the Pwn2Own hacking contest starts Wednesday in Canada.

I wonder why no one is taking on the challenge then. And 25, is considered safe?
In other words, there is a reason no one is touching it, but it's has ZERO to do with it being safe.
It has more to do with the fact that they plugged a bunch of holes and that's it.

So, it's a facade.

Just cause no one is testing it does not mean it is safest browser.
It just means no one has either had time, nor spent time on finding other holes that did not get discovered and patched yet a day before the event.

Claiming they survive day one (cause again, no one tested it) is a good thing is a fallacy due to that very fact.
 

My Computer My Computer

At a glance

Win 7 Ultimate 32bitC2D E6600 2.4Ghz4G Kingston KHX5400D2EVGA GTX 570 HD SC (012-P3-1573-KR)
Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling

My Computer My Computer

At a glance

Arch Linux 64-bit
OS
Arch Linux 64-bit
This year, the software was frozen last week, preventing the use of last-minute patches to avoid exploitation. Successful exploits of the week-old configuration win the hardware, and if the exploit still exists in the latest software, money is also paid out for the flaw.
Pwn2Own day 2: iPhone, BlackBerry beaten; Chrome, Firefox no-shows

Hmmmm,,,, Are you sure about that?

Google issues last-minute Chrome fixes before Pwn2Own - Computerworld - March 8, 2011 04:09 PM ET


Google issues last-minute Chrome fixes before Pwn2Own | ITworld - March 9, 2011, 11:30 AM

Google issues last-minute Chrome fixes - Bing
 

My Computer My Computer

At a glance

Win 7 Ultimate 32bitC2D E6600 2.4Ghz4G Kingston KHX5400D2EVGA GTX 570 HD SC (012-P3-1573-KR)
Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
Everyone knows the vulnerabilities are there, that's no secret - it's finding a way to exploit these vulnerabilities, and write the exploit, that's the problem because of Chrome's sandbox.
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel Core i7 4790k8GB Corsair Dominator 1600MHzMSI TwinFrozr GeForce GTX770
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 8.1 Pro x64
CPU
Intel Core i7 4790k
Motherboard
MSI Z97S Krait Edition
Memory
8GB Corsair Dominator 1600MHz
Graphics Card(s)
MSI TwinFrozr GeForce GTX770
Sound Card
ASUS Xonar DX/XD 7.1
Monitor(s) Displays
Dell 24" S2409W + Dell 20" E207WFP
Screen Resolution
1920x1080 + 1680x1050
Hard Drives
1x 120GB OCZ Agility 3, 1x 750GB Western Digital Caviar Black, 1x 1TB Western Digital Caviar Blue
PSU
Corsair HX850 modular
Case
Fractal Design Define R4
Cooling
Corsair H60 w/ twin Corsair SP120 fans
Keyboard
Logitech G510S Keyboard
Mouse
Logitech G500S Laser Mouse
Internet Speed
40Mbps
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Other Info
LG Blu-Ray player
This year, the software was frozen last week, preventing the use of last-minute patches to avoid exploitation. Successful exploits of the week-old configuration win the hardware, and if the exploit still exists in the latest software, money is also paid out for the flaw.
Pwn2Own day 2: iPhone, BlackBerry beaten; Chrome, Firefox no-shows

Hmmmm,,,, Are you sure about that?
Yes, pretty sure about that. If you read what malexous posted above, he says exactly the same thing that I am going to explain in a few more words below.

If you followed the past, Pwn20wn competitions, the requirement was to test against the latest version of the software under attack...even if it was released the morning of the show.

This year, the software was frozen the week prior, preventing the use of new patches to avoid exploitation. If you beat the frozen version, you win the hardware prizes of the competition. If you beat the browser on the latest version as of day of the show, you win the money.

As you can see from this link, Apple too included new patches resolving 60 vulnerabilities right before the start of the conference;
Pwn2Own 2011: On cue, Apple drops massive Safari, iOS patches | ZDNet

And this article explains that while Microsoft also had the opportunity to patch IE8 before the show, they elected not to;
Microsoft Releases Zero IE8 Security Updates Before "Pwn2Own" Browser Hacking Contest | News & Opinion | PCMag.com

So, it's not like Google tried to sneak a fast one past everybody. They played by the same rules as everybody else. Everybody else had the same opportunity. And even with patches being allowed, other browsers allowed machine ownership, and some did not.

Everyone knows the vulnerabilities are there, that's no secret - it's finding a way to exploit these vulnerabilities, and write the exploit, that's the problem because of Chrome's sandbox.
Thank you, that is exactly correct. Nobody is saying that Chrome is perfect, but in a competition with money on the line, the hackers dropped Safari and IE8 and gained full access to the machines. They didn't do the same with Firefox and Chrome.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Q9550 2.83Ghz OC'd to 3.40Ghz8GB G.Skill PI DDR2-800, 4-4-4-12 timingsEVGA 1280MB Nvidia GeForce GTX570
Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Pwn2Own 2011: IE8 on Windows 7 hijacked with 3 vulnerabilities

Using three different vulnerabilities and clever exploitation techniques, Irish security researcher Stephen Fewer successfully hacked into a 64-bit Windows 7 (SP1) running Internet Explorer 8 to win this year’s CanSecWest hacker challenge.

Fewer (right), a Metasploit developer who specializes in writing Windows exploits, used two different zero-day bugs in IE to get reliable code execution and then chained a third vulnerability to jump out of the IE Protected Mode sandbox.

Source

A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Back
Top