Added on 20 Mar 2009(2063 Views)
It is not just the recently released Internet Explorer 8 (IE8) that has been cracked, Mozilla’s Firefox and Apple’s Safari have succumbed as well, but the thing that drew my attention to IE8 is the fact that Steve Ballmer put a great deal of emphasis on how secure this latest version of the Microsoft develop browser really is.“Customers have made clear what they want in a Web browser — safety, speed and greater ease of use. With Internet Explorer 8, we are delivering a browser that gets people to the information they need, fast, and provides protection that no other browser can match,” said Microsoft CEO, Steve Ballmer a while back.
The good news is that all this hacking business occurred at the PWN2OWN competition and it was done right in front of Microsoft representatives. A computer science student from Germany (we only know his first name: Nils) was presented with a Sonly laptop running on a “recent Microsoft internal build” of Windows 7 which had Internet Explorer 8, Firefox and Chrome installed on it. He managed to successfully hack it by defeating IE8’s built in DEP (Data Execution Prevention) as well as ASLR (Address Space Layout Randomization) security features.
Terri Forslof, manager of security response at 3Com's TippingPoint, sponsor of the PWN2OWN contest comments: “This is the awesome part of PWN2OWN. Microsoft got to stand there and watch it happen. They were right at ground zero. It was important for Microsoft to see that bug right away. They took it back to Microsoft and filed a bug. That's a real success story. Microsoft had the opportunity to talk directly with Nils about the bug, and within five hours they had it reproduced in their labs.”
For his accomplishment, Neils received a $5,000 reward, but by the end of the day he had managed to triple his earnings by hacking into Firefox and Safari (for each successfully hacked browser he received an additional $5,000). On top of that, he also received a Sony Vaio P series laptop. Not bad for a day’s work you might say, but keep in mind that by accepting these cash rewards he has actually sold the vulnerabilities and rights to exploit them to TippingPoint.
Terri Forslof again: “It was insane compared to last year. Nils hit the IE8 vulnerability and everybody thought that was it. Then he comes back and says 'Do you mind if I try my Safari vulnerability? Oh, and by the way, I also have a Firefox bug'. After just two hours, we had four browser vulnerabilities and we'd paid out $20,000.”
The additional $5,000 were paid to Charlie Miller, the defending champion of 2008’s PWN2OWN (when only 2 vulnerabilities were uncovered). Charlie Miller was presented with a Macbook which had Safari and Firefox installed on it – in no time at all he successfully exploited a Safari vulnerability thus winning the $5,000 prize and the Macbook.
“Charlie Miller got the luck of the draw, and had the first time slot for the browser competition. His target- Safari on Mac OS X. Before I could even pull my camera out, it was over within 2 minutes- and Charlie (coincidentally also last year's first winner of the day) is now the proud owner of yet another MacBook, and $5,000 from the Zero Day Initiative,” said Forslof.
The only browser that was left intact at the PWN2OWN competition was Google’s Chrome, version 2.0 of which recently hit Beta (Chrome 2.0 Beta) and which is attempting to become more popular thanks to Chrome Experiments.
Don't forget to:
RSSTags: Internet Exporer 8, Safari, Firefox, Chrome, PWN2OWN
Link to this article:
Comments
Ian - 23 Mar 2009 15:33
You have some adware on your computer that is opening the internet explorer windows. It's not a problem with Firefox. You need to use a spyware scanner remover or a decent anti-virus program to get rid of the spyware. Or if you want to be safe, save all your data and format and reload windows. If you want to be even safer, format and load Linux;)
Russ - 22 Mar 2009 23:46
I use firefox 3.0.7. I want to know why this browser pops up internet explorer every few minutes as I'm surfing!! I'm browsing sites with firefox and up pops a copy of explorer with an ad similar to what I'm looking at in firefox. Can anyone tell me how to turn this off???
Add comment:
Software News
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
New Labs Feature for Gmail: Green Robot!
The software developers at Google have announced the release of a new Gmail Labs offering called Green Robot! This new offering is meant to improve the Gmail Chat user experience by letting the ...
20 Nov 2009
Opera Mobile 10 Beta for Windows Mobile Is Out Also
Opera Software, the company that we all know for making the innovative and feature rich Opera web browser, has released Opera Mobile 10 Beta for Windows Mobile-powered devices. This release follows in the...
19 Nov 2009
Beta Testing is Over, Stable Version of Trillian for iPhone Released
The focus so far has been on desktop version of this multiprotocol instant messaging software application, Trillian Astra (version 4.1). Today is time to switch focus away from the desktop version and onto something a bit more...
19 Nov 2009
Recommended Tools
Registry Booster 2010 Enhanced, deeper and faster error scan performance. Now also in 5 languages! Free Scan
Driver Scanner 2009
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2009
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



