Jump to content
Nytro

Plug-in pwning challenge brings Pwn2Own prizes to $US560K

Recommended Posts

Plug-in pwning challenge brings Pwn2Own prizes to $US560K

From: InfoSec News <alerts () infosecnews org>

Date: Tue, 22 Jan 2013 00:19:44 -0600 (CST)


Plug-in pwning challenge brings Pwn2Own prizes to $US560k • The Register

By Iain Thomson in San Francisco

The organizers of the Pwn2Own hacking competition held at the annual CanSecWest security conference have upped the prize pool to $US560,000 and will now be offering prizes for hacking web plug-ins from Adobe and Oracle. The contest, which dropped mobile phone hacking last year, has added web plug-in hacking to the prize pool.

Contestants get $70,000 apiece for cracking Adobe Reader and Flash, and $20,000 for getting past Java. Based on the latter's recent parlous performance in the security arena that price discount seems justified.

"We've added browser plug-ins as a reflection of their increasing popularity as an attack vector," said Brian Gorenc, manager of vulnerability research at Pwn2Own sponsors HP DVLabs.

"We want to demonstrate new hacking areas and design new mitigation techniques."

For the more traditional hacks against browsers, a working Chrome exploit for Windows 7 will net $100,000, with the same again for an IE10 hack in Windows 8 or $75,000 for breaking IE9 in Windows 7. A Safari exploit in OSX Mountain Lion is worth $65,000 and Firefox on Windows 7 just $60,000, and all hacks must be completed in a 30 minute time frame.

Sursa: Information Security News: Plug-in pwning challenge brings Pwn2Own prizes to $US560K

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...