Hacker Cracks Recently Released IE8 Final
It is not just the recently released Internet Explorer 8 (IE8) that has been cracked, Mozilla’s Firefox and Apple’s Safari have succumbed as well, but the thing that drew my attention to IE8 is the fact that Steve Ballmer put a great deal of emphasis on how secure this latest version of the Microsoft develop browser really is.
“Customers have made clear what they want in a Web browser — safety, speed and greater ease of use. With Internet Explorer 8, we are delivering a browser that gets people to the information they need, fast, and provides protection that no other browser can match,” said Microsoft CEO, Steve Ballmer a while back.
The good news is that all this hacking business occurred at the PWN2OWN competition and it was done right in front of Microsoft representatives. A computer science student from Germany (we only know his first name: Nils) was presented with a Sony laptop running on a “recent Microsoft internal build” of Windows 7 which had Internet Explorer 8, Firefox and Chrome installed on it. He managed to successfully hack it by defeating IE8’s built in DEP (Data Execution Prevention) as well as ASLR (Address Space Layout Randomization) security features.
Terri Forslof, manager of security response at 3Com's TippingPoint, sponsor of the PWN2OWN contest comments: “This is the awesome part of PWN2OWN. Microsoft got to stand there and watch it happen. They were right at ground zero. It was important for Microsoft to see that bug right away. They took it back to Microsoft and filed a bug. That's a real success story. Microsoft had the opportunity to talk directly with Nils about the bug, and within five hours they had it reproduced in their labs.”
For his accomplishment, Neils received a $5,000 reward, but by the end of the day he had managed to triple his earnings by hacking into Firefox and Safari (for each successfully hacked browser he received an additional $5,000). On top of that, he also received a Sony Vaio P series laptop. Not bad for a day’s work you might say, but keep in mind that by accepting these cash rewards he has actually sold the vulnerabilities and rights to exploit them to TippingPoint.
Terri Forslof again: “It was insane compared to last year. Nils hit the IE8 vulnerability and everybody thought that was it. Then he comes back and says 'Do you mind if I try my Safari vulnerability? Oh, and by the way, I also have a Firefox bug'. After just two hours, we had four browser vulnerabilities and we'd paid out $20,000.”
The additional $5,000 were paid to Charlie Miller, the defending champion of 2008’s PWN2OWN (when only 2 vulnerabilities were uncovered). Charlie Miller was presented with a Macbook which had Safari and Firefox installed on it – in no time at all he successfully exploited a Safari vulnerability thus winning the $5,000 prize and the Macbook.
“Charlie Miller got the luck of the draw, and had the first time slot for the browser competition. His target- Safari on Mac OS X. Before I could even pull my camera out, it was over within 2 minutes- and Charlie (coincidentally also last year's first winner of the day) is now the proud owner of yet another MacBook, and $5,000 from the Zero Day Initiative,” said Forslof.
The only browser that was left intact at the PWN2OWN competition was Google’s Chrome, version 2.0 of which recently hit Beta (Chrome 2.0 Beta) and which is attempting to become more popular thanks to Chrome Experiments.
Tags: Internet Exporer 8, Safari, Firefox, Chrome, PWN2OWN
“Customers have made clear what they want in a Web browser — safety, speed and greater ease of use. With Internet Explorer 8, we are delivering a browser that gets people to the information they need, fast, and provides protection that no other browser can match,” said Microsoft CEO, Steve Ballmer a while back.
Advertising
The good news is that all this hacking business occurred at the PWN2OWN competition and it was done right in front of Microsoft representatives. A computer science student from Germany (we only know his first name: Nils) was presented with a Sony laptop running on a “recent Microsoft internal build” of Windows 7 which had Internet Explorer 8, Firefox and Chrome installed on it. He managed to successfully hack it by defeating IE8’s built in DEP (Data Execution Prevention) as well as ASLR (Address Space Layout Randomization) security features.
Terri Forslof, manager of security response at 3Com's TippingPoint, sponsor of the PWN2OWN contest comments: “This is the awesome part of PWN2OWN. Microsoft got to stand there and watch it happen. They were right at ground zero. It was important for Microsoft to see that bug right away. They took it back to Microsoft and filed a bug. That's a real success story. Microsoft had the opportunity to talk directly with Nils about the bug, and within five hours they had it reproduced in their labs.”
For his accomplishment, Neils received a $5,000 reward, but by the end of the day he had managed to triple his earnings by hacking into Firefox and Safari (for each successfully hacked browser he received an additional $5,000). On top of that, he also received a Sony Vaio P series laptop. Not bad for a day’s work you might say, but keep in mind that by accepting these cash rewards he has actually sold the vulnerabilities and rights to exploit them to TippingPoint.
Terri Forslof again: “It was insane compared to last year. Nils hit the IE8 vulnerability and everybody thought that was it. Then he comes back and says 'Do you mind if I try my Safari vulnerability? Oh, and by the way, I also have a Firefox bug'. After just two hours, we had four browser vulnerabilities and we'd paid out $20,000.”
The additional $5,000 were paid to Charlie Miller, the defending champion of 2008’s PWN2OWN (when only 2 vulnerabilities were uncovered). Charlie Miller was presented with a Macbook which had Safari and Firefox installed on it – in no time at all he successfully exploited a Safari vulnerability thus winning the $5,000 prize and the Macbook.
“Charlie Miller got the luck of the draw, and had the first time slot for the browser competition. His target- Safari on Mac OS X. Before I could even pull my camera out, it was over within 2 minutes- and Charlie (coincidentally also last year's first winner of the day) is now the proud owner of yet another MacBook, and $5,000 from the Zero Day Initiative,” said Forslof.
The only browser that was left intact at the PWN2OWN competition was Google’s Chrome, version 2.0 of which recently hit Beta (Chrome 2.0 Beta) and which is attempting to become more popular thanks to Chrome Experiments.
Tags: Internet Exporer 8, Safari, Firefox, Chrome, PWN2OWN
I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 10 Feb 2012
With the release of Wolfram|Alpha Pro, the team behind the popular computational knowledge engine took a very big step forwardBy George Norman on 10 Feb 2012
Microsoft has just announced that this February, as part of the Patch Tuesday program, it will roll out a grand total of 9 security bulletins to all customers all over the world.Related News
By George Norman on 17 Jan 2012
With Firefox Sync in the latest version of Firefox, that would be Firefox 9.0, you can keep bookmarks, passwords, preferences, history, and tabs synced across devices. This means that if youBy George Norman on 24 Nov 2011
Today is Thanksgiving in the good old US of A, the day when everyone gives thanks and fills their bellies with lots and lots of food. This means that a lot of people went back home to celebrate Thanksgiving with their families and visit their parents.By George Norman on 06 Dec 2011
Ever wondered why you should leave your default browser behind and move on to something else? If you have been thinking about dropping the browser that comes by default on your Windows-powered computer, then you will be glad to find out thatBy George Norman on 16 Dec 2011
Earlier this week, Mountain View-based search engine giant Google announced that version 16.0 of its Chrome web browser graduated from the Beta to the Stable Channel. I remind you that Google Advertising
Hot Software Updates
Top Downloads
2.
Opera5.
Trillian8.
AIM9.
Skype10.
Ad-Aware12.
Nero13.
Google Earth14.
Picasa15.
Winamp16.
iTunes17.
RealPlayer18.
uTorrent19.
eMule20.
WinRAR21.
BitComet22.
WinZip23.
Shareaza24.
CCleaner25.
Recuva26.
Tweak UI27.
CuteFTP Home29.
Adobe Reader30.
NewsPiperBecome A Fan!
Link To Us!
Hacker Cracks Recently Released IE8 Final
HTML Linking Code
HTML Linking Code





