DocuCrunch.com » One browser left standing after hacking contest

One browser left standing after hacking contest

April 6, 2010 by Sam Narisi
Posted in: In this week's e-newsletter, Security

A recent contest that paid researchers to uncover security flaws shed some light on an important question: What’s the most secure Web browser?

Security researchers Peter Vreugdenhil, of the Netherlands, and a German who identified himself only as Nils won a $10,000 prize at the “Pwn2Own” hacking contest by finding ways around IE8′s security features.

The hackers, running a fully patched version of Windows 7, found a way to disable the OS’s data execution prevention (DEP) and address space layout randomization (ASLR), two of the most highly praised security features of Windows 7.

The hack took a total of two minutes to complete. Vreugdenhil said it took him “six or seven days” to figure out how to make the attack work. He explains what he and Nils did here.

Microsoft responded a few days later, saying the security features are an effective way to prevent exploits but can’t possibly “prevent every attack forever.”

Though Microsoft was the big loser at the contest, it certainly wasn’t the only company to see its browser get hacked. Researchers also exploited flaws in Firefox and Safari, ComputerWorld reports.

The only browser researchers targeted that was still standing after the contest: Google’s Chrome. It was second year Chrome made it through the contest unexploited.

In the past, vendors have been quick to push out patches for the flaws uncovered at the contest, so those could be expected within the next few weeks.

  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , , , ,


4 Responses to “One browser left standing after hacking contest”

  1. James Says:

    “Though Microsoft was the big loser at the contest…”

    You might want to do some research and read the full story here, before making silly comments:

    http://www.pcworld.com/businesscenter/article/192419/security_lessons_learned_from_pwn2own_contest.html

    Apple was the big loser this year – the iPhone was hacked in seconds using a Safari exploit, Mac OS also hacked through Safari, and today, they had to release 88 security patched to their “oh, so secure” operating system.

    That right **88** security flaws. If Redmond releases a patch with 15 fixes, it’s the lead story on the national news!

  2. ipad Says:

    Google Chrome? I’ll still stick with Firefox, by far the best.

  3. Jim Says:

    @James – if Redmond releases a patch with 15 fixes, that’s just about every Patch Tuesday. It doens’t make national news.

    What makes M$ the big loser in this, regardless of Apple having problems with Safari, and Firefox also having exploitable flaws – it’s that it was with their latest-and-greatest, “most secure ever” OS, Windows 7, running their latest-and-greatest, “most secure ever” version of IE, IE8, both fully patched.

    … and since they still do have the majority share of the browser “market” and Safari/Apple is a distant third or fourth place contender, it’s a big black eye for Redmond.

    Safari/MacOS may be billed as more secure than Windows/IE, and it may well be true, but that doesn’t mean it’s perfect.

    Another flaw in your logic: you say they released 88 patches, and equate that to 88 security flaws. MacOS is based on BSD, a *nix flavor. It’s a different paradigm than Windows. Those 88 patches may not have been to fix 88 security flaws, but rather to fix one or two – but 88 files had to be patched to fix them. When Microsoft releases a patch they don’t tell you how many files have to be patched to fix a particular flaw addressed by a KB. I’m not saying that there weren’t 88 security flaws, or that there were only two – this was only to illustrate the flaw in your logic.

  4. Chrome browser gaining ground as IE slips | DocuCrunch.com Says:

    [...] browser rapidly gaining popularityOne browser left standing after hacking contestGoogle Cloud Printing: Smart idea or Cloud Cuckoo Land?Simplify the Complexity of your Data [...]


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement