Pwn2Own 2010 – Attack’s on browser’s and mobile devices

The  Pwn2Own contest is back this year and is looking the new winner. The competition starts at 24th of March 2010. in Vancouver. The winner is the person that will successfully hack an application or a  platform and the prize will be $100,000 USD and keep the target that exploit.

In the first day the attackers will try to exploit one of the below web-browsers:

  • Microsoft Internet Explorer 8 on Windows 7
  • Mozilla Firefox 3 on Windows 7
  • Google Chrome 4 on Windows 7
  • Apple Safari 4 on MacOS X Snow Leopard
  • Second day will be:

  • Microsoft Internet Explorer 7 on Windows Vista
  • Mozilla Firefox 3 on Windows Vista
  • Google Chrome 4 on Windows Vista
  • Apple Safari 4 on MacOS X Snow Leopard
  • Third and last day:

  • Microsoft Internet Explorer 7 on Windows XP
  • Mozilla Firefox 3 on Windows XP
  • Google Chrome 4 on Windows XP
  • Apple Safari 4 on MacOS X Snow Leopard
  • Also except of web-browsers this year the attackers have the chance to exploit one of the four mobile-devices:

  • Apple iPhone 3GS
  • RIM Blackberry Bold 9700
  • A Nokia device running Symbian S60 (likely the E62)
  • A Motorola phone running Android (likely the Droid)
  • Although last year noone have managed to exploit a mobile device, this year the expectations are high that the iPhone will go down. For every successful exploit the winner will keep the device and take $15,000.

    Aaron Portnoy,security researcher at TippingPoint and Pwn2Own said: “”With all the recent research on mobile phone security being presented worldwide, these devices are quickly becoming a ripe target,First to fall: the iPhone”.

    Miller, the winner of 2008 and 2009 contest which he managed to exploit Safari web browser, this year will stick on Safari to win again the contest. However, Miller said “in real life the iPhone is harder because you can’t just execute a shell. You have to write your return-oriented payload to do all your dirty work, which can be a pain.” We will expect from Miller this year to break the Iphone through Mobile Safari.

    Happy exploiting :)
    References:

    http://arstechnica.com/security/

    http://blogs.zdnet.com/security/?p=5709&tag=content;col1

    http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010

    http://blogs.zdnet.com/hardware/?p=7367

    Leave a Reply