Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Apple's Safari browser was the first to be broken at this year's pwn2own contest at the CanSecWest conference in Vancouver.
Safari, being run on a fully patched Mac OSX, was exploited by vulnerability research company Vupen. It said on its Twitter feed that it "pwned Apple Safari on Mac OS X (x64) at pwn2own in five seconds. Congrats to all VUPEN team members for their hard work."
It previously commented that Apple had released Safari 5.0.4 and iOS 4.3 a few minutes before the pwn2own contest, yet it was able to break the up-to-date software by successfully exploiting a zero-day flaw. Vupen won $24,000 and a 13-inch MacBook Air.
Shortly afterwards, Stephen Fewer from vulnerability research and consultancy company Harmony, tweeted that he had "just popped ie8 at pwn2own". Fewer received a laptop and $15,000.
Aaron Portnoy, manager of the security research team at Pwn2Own sponsor Tipping Point, pointed out that Fewer had successfully compromised Internet Explorer with a Protected Mode bypass switched on.
According to eWeek, the two contestants who signed up to hack Google Chrome did not show up meaning that it was the most secure browser for the second year running and got to keep its $20,000 prize.
Technical details of the exploits legally belong to TippingPoint under contest rules; they provide information to Microsoft and Apple and give them six months to fix the flaws before publicising them.
This article originally appeared at scmagazineuk.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.