ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Pwn2Own 2010: Bulls-eye on smartphones, browsers

By | February 16, 2010, 7:33am PST

Summary: This year’s CanSecWest Pwn2Own contest are offering up an whopping $60,000 in prizes to entice hackers to exploit vulnerabilities on iPhones, Android, Nokia and BlackBerry smartphones.

The organizers of this year’s CanSecWest Pwn2Own challenge have painted a big bulls-eye on mobile devices, offering up an whopping $60,000 in prizes to entice hackers to exploit vulnerabilities on iPhones, Android, Nokia and BlackBerry smartphones.

At Pwn2Own 2010, which takes place in Vancouver on March 24, 2010, contest sponsors TippingPoint ZDI has set the booty at US$100,000 with two main technology targets — smartphones and Web browsers/OS pairings.


According to ZDI’s Aaron Portnoy, the big focus this year will be on vulnerabilities affecting mobile devices.

The second portion of Pwn2Own 2010 offers bounties for vulnerabilities affecting mobile phones. The increased presence and capabilities of smart phones has brought with it the same security issues and attention traditionally reserved for non hand-held platforms. Vulnerabilities in parsing media, dynamic web content, e-mail, and other client-side issues have been published in the past. Additionally, many of the communication protocols that mobile phones implement are the focus of a burgeoning field of security research (ex: Lackey, Langlois, Bailey).

Portnoy said that $60,000 of the total $100,000 cash prize pool is set aside for the mobile phone portion of the contest, with each target worth $15,000.

He said a  successful hack on these targets must result in code execution with little to no user-interaction. The targets this year are:

  • Apple iPhone 3GS
  • RIM Blackberry Bold 9700
  • A Nokia device running Symbian S60 (likely the E62)
  • A Motorola phone running Android (likely the Droid)

Mobile phones were in play at last year’s contest but there was little activity from hackers. Instead, the security researchers focused mainly on Web browsers, bringing down the three main browsers — Internet Explorer, Firefox and Safari — on the first day.

The remainding $40,000 will be assigned to targets this year that include the latest versions of Microsoft Internet Explorer, Mozilla Firefox, Google Chrome and Apple Safari.

The browsers will be paired with a fully patched operating system. On day one, Portnoy said the following targets will be in play:

  • Microsoft Internet Explorer 8 on Windows 7
  • Mozilla Firefox 3 on Windows 7
  • Google Chrome 4 on Windows 7
  • Apple Safari 4 on MacOS X Snow Leopard

On the second day, older OS versions will be added to the mix:

  • Microsoft Internet Explorer 7 on Windows Vista
  • Mozilla Firefox 3 on Windows Vista
  • Google Chrome 4 on Windows Vista
  • Apple Safari 4 on MacOS X Snow Leopard

The contest will be expanded on Day 3 to include even older OS/browser pairings:

  • Mozilla Firefox 3 on Windows XP
  • Google Chrome 4 on Windows XP
  • Apple Safari 4 on MacOS X Snow Leopard

ALSO READ:

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
20
Comments

Join the conversation!

Just In

RE: Pwn2Own 2010: Bulls-eye on smartphones, browsers
lovedong 13th Sep
Thanks so much for these! replica watches best
0 Votes
+ -
Let's See How Apple Fairs.
mikefarinha 16th Feb 2010
It will be interesting to see how Apple will fair this year. The last two years were not very kind with OS X and Safari.
Thanks so much for these! replica watches best
0 Votes
+ -
Nice!
AzuMao 16th Feb 2010
Let's compare a phone that just came out with one that's already matured over several generations. Great idea!
0 Votes
+ -
@AzuMao: What are you referring to?
PlayFair 16th Feb 2010
Nt
0 Votes
+ -
Android vs iPhone
AzuMao 22nd Feb 2010
0 Votes
+ -
Typo or intentional?
rtk 16th Feb 2010
"Apple Safari 4 on MacOS X Snow Leopard" is listed under "fully patched", "older OS/browser" and "even older OS/browser".

As well, why isn't Fx being tested on anything but MS OS's?
0 Votes
+ -
I was wondering that, too...
olePigeon 22nd Feb 2010
I was wondering that, too. Shouldn't it be Safari 4 on 10.5 and 10.4?
0 Votes
+ -
Hacked in this order
Ron Bergundy Updated - 16th Feb 2010
in computer OS- 1) M$ IE8 on Windoze 7 - 2) Safari Snow Leopard - 3) Firefox on Windoze 7

on phones- 1) Apple iPhone - 2) RIM Blackberry 3) Symbian S60
0 Votes
+ -
Do me a favor
use_what_works_4_U 16th Feb 2010
While you're at the prognostication, tell me what 6 numbers to play in the Lotto this week!

grin
0 Votes
+ -
We'll see this year.

Note Windows fell through 3rd party plug-in Quicktime (an apple product).

Many of the hacks on Windows utilize non-microsoft apps. QuickTime, Adobe Flash and PDF files, Not directly through the OS and browser on there own.

The browser that was most resistant was Chrome even on Windows.

Champion Pwn2Own Charlie Miller had good things to say about windows security.
0 Votes
+ -
Wrong info
Cobra7fac Updated - 16th Feb 2010
Apple will be the first to fall, as it has every year so far.

Also it should be noted that IE8 only fell because it was in beta last year, if they had held off one day the hack that was used would not have worked (when IE8 went live).

Wonder why they are not doing Linux this year.
0 Votes
+ -
Too much work to crack it. nt
T1Oracle 17th Feb 2010
nt
0 Votes
+ -
First to fall always is: OS X
then anything Open Source of course.

Just google "most vulnerable" and see what comes back...

And while you're at it can you explain this: (Why Linux/Unix vulnerabilities always hover at 3x those of Windows?)


========================================================================

The Secunia Weekly Advisory Summary
2009-12-31 - 2010-01-07

This week: 81 advisories

========================================================================
This weeks Secunia Advisories had the following spread across platforms and criticality ratings:

Platforms:
Windows : 10 Secunia Advisories
Unix/Linux : 27 Secunia Advisories
Other : 3 Secunia Advisories
Cross platform : 41 Secunia Advisories

Criticality Ratings:
Extremely Critical : 0 Secunia Advisories
Highly Critical : 11 Secunia Advisories
Moderately Critical : 32 Secunia Advisories
Less Critical : 35 Secunia Advisories
Not Critical : 3 Secunia Advisories

========================================================================

========================================================================

The Secunia Weekly Advisory Summary
2010-01-07 - 2010-01-14

This week: 63 advisories

========================================================================
Platforms:
Windows : 6 Secunia Advisories
Unix/Linux : 27 Secunia Advisories
Other : 2 Secunia Advisories
Cross platform : 28 Secunia Advisories

Criticality Ratings:
Extremely Critical : 1 Secunia Advisory
Highly Critical : 12 Secunia Advisories
Moderately Critical : 14 Secunia Advisories
Less Critical : 35 Secunia Advisories
Not Critical : 1 Secunia Advisory

========================================================================
========================================================================

The Secunia Weekly Advisory Summary
2010-01-14 - 2010-01-21

This week: 54 advisories

========================================================================
Platforms:
Windows : 10 Secunia Advisories
Unix/Linux : 21 Secunia Advisories
Other : 2 Secunia Advisories
Cross platform : 21 Secunia Advisories

Criticality Ratings:
Extremely Critical : 1 Secunia Advisory
Highly Critical : 5 Secunia Advisories
Moderately Critical : 21 Secunia Advisories
Less Critical : 25 Secunia Advisories
Not Critical : 2 Secunia Advisories

========================================================================
========================================================================

The Secunia Weekly Advisory Summary
2010-01-21 - 2010-01-28

This week: 56 advisories

========================================================================
Platforms:
Windows : 2 Secunia Advisories
Unix/Linux : 28 Secunia Advisories
Other : 3 Secunia Advisories
Cross platform : 23 Secunia Advisories

Criticality Ratings:
Extremely Critical : 0 Secunia Advisories
Highly Critical : 6 Secunia Advisories
Moderately Critical : 21 Secunia Advisories
Less Critical : 24 Secunia Advisories
Not Critical : 5 Secunia Advisories

========================================================================

Want more???

Oh, it's like this in February 2010. And it was like that in 2009, and 2008, and 2007.

Care to explain why you Linooze / OS X freaks don't get your heads out of your b....???
0 Votes
+ -
How can you expect to be taken seriously...
webmaster@... Updated - 19th Mar 2010
When your name is a derogatory term. I've told you before wintard is a
portmanteau of "Windows and Retard!"
0 Votes
+ -
"Windoze"? What is that? (nt)
Hallowed are the Ori 17th Feb 2010
nt
0 Votes
+ -
Call a bookie!!!
Hallowed are the Ori 17th Feb 2010
Put a grand on Apple across the board to be the first to fall.

It'll likely be the easiest money you ever make.
why linux os never comes into pic in case of browser wars?!
always windows os !!!!!!
0 Votes
+ -
No Windows Mobile?
bpunk88 22nd Mar 2010
What is with the exclusion of Windows Mobile in the
smartphone arena? Surely it is vulnerable as well and is
in widespread use. What gives!
0 Votes
+ -
Well done! Thank you very much for professional templates and community edition
sesli sohbet sesli chat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix