10 ms·
Do people go into Pwn2Own knowing the exploits they will use in advance? I'm not sure I understand the format of such a contest.
by lost_name 12y ago
Do people go into Pwn2Own knowing the exploits they will use in advance? I'm not sure I understand the format of such a contest.
- olliej 12y agoYes, weeks or months of work goes into finding the bugs, and then working out how to exploit them. The continued "hacked in x minutes" crap is nonsense.
- sp332 12y agoYes. It's basically a bug-bounty system, but the bounty includes more prestige :)
- mccr8 12y agoAnd more money.
- Touche 12y agoAnd leaving the exploits in the wild for weeks/months beforehand.
- tptacek 12y agoThis is a valid criticism.
- cssmoo 12y agoPerhaps more worrying, they may have sold them elsewhere first and informed the purchaser that they have until the competition date to use it. Better business if you have to come back after the disclosure date for more holes... Nohig ethical at all going on here.
- rudolf0 12y agoMy understanding is that would violate the rules of the competition. Though of course if a competitor were to do that, odds are no one would find out.
- djrogers 12y agoWould someone willing to sell exploits on the black market really be concerned with "violating the rules of the competition"?
- rudolf0 12y agoWell, presumably they'd want to keep the money from the competition. That's definitely an incentive.
- MichaelGG 12y agoI would imagine it'd be fairly hard to the competition to know and revoke the money. Bad guys are almost certainly exploiting various undisclosed vulnerabilities. The bigger issue, I'd assume, is that by doing this competition, you've now killed that bug you previously sold. So long that was disclosed to the buyer though, I imagine you're all set.
- im2w1l 12y agoOdds are the black market guys find out. I don't know how the market works, but I'd be pretty pissed if I had bought a hole just for it to be patched soon after.
- mccr8 12y agoTo mitigate this problem, Google has recently announced that they are running a similar program year-round: http://blog.chromium.org/2015/02/pwnium-v-never-ending-pwnium.html http://blog.chromium.org/2015/02/pwnium-v-never-ending-pwniu...
- eugeneionesco 12y agoWith very lower rewards, the exploit that nettet $110k would probably be getting less than $50k
- erichurkman 12y agoBut you also minimize the risk that someone else will find and report the vulnerability before you do, negating any & all chance of earning a bounty yourself.
- coderzach 12y agoI was wondering the same thing. It seems like there would be no way to stop someone from having exploits beforehand. And a single person finding exploits in every major browser in one day seems unlikely.
- deleted 12y ago[deleted]
- NathanKP 12y agoIt's basically demo day for browser (and other software) vulnerabilities. Hackers show off their exploits and vendors pay them cash for disclosing them at Pwn2Own instead of selling them on the blackmarket.
- 0xdeadbeefbabe 12y agoThey used to sell the hacker, but since they've stopped Pwn2Own is much more popular.
- Crito 12y agoSurely there are 13th amendment concerns with selling the hacker. Do you mean that they used to sell the exploits to other hackers at Pwn2Own?
- liyanchang 12y agoWas similarly curious. Reading the rules here: http://zerodayinitiative.com/Pwn2Own2015Rules.html http://zerodayinitiative.com/Pwn2Own2015Rules.html Major points: - You register for which browser + os combination[0]. Then they randomly order the contestants. - When you are called, you have 30 minutes. - The user browses to a particular piece of content that you specify. Then no further user interaction is allowed (like clicking a dialog, downloading a file). [1][2] - The prize money goes to the first successful exploit. Money differs by browser. [0] Chrome, Firefox, IE, Adobe Reader in IE, Adobe Flash in IE. Safari on OSX. Fully patched OS. [1] How does one get to specify the content? What if I have a http header that downloads a file? [2] I remember back in the day, they used to have a fully no interactive version? Like the user was just on the same wireless network?
- tptacek 12y agoThe exploits that take down hardened browsers take months to develop. The time limits and race dynamics are theater.
- hnnewguy 12y ago>"The time limits and race dynamics are theater." That makes more sense. Otherwise, this is movie-script-like hacking ability.
- eeeeeeeeeeeee 12y ago"I just need to break the encryption......ok...it's done."
- smackfu 12y agoIt makes a bit more sense in the original context of the contest, where you were doing the attack on the actual hardware you would win. So time limits were so that everyone got a shot, and a race since there was no prize after someone won it.
- 3pt14159 12y agoI was curious, so here are the rewards: Windows-based targets: 1. Google Chrome (64-bit): $75,000 (USD) 2. Microsoft Internet Explorer 11 (64-bit with EPM-enabled): $65,000 (USD) 3. Mozilla Firefox: $30,000 (USD) 4. Adobe Reader running in Internet Explorer 11 (64-bit with EPM-enabled): $60,000 (USD) 5. Adobe Flash (64-bit) running in Internet Explorer 11 (64-bit with EPM-enabled): $60,000 (USD) Mac OS X-based targets: 1. Apple Safari (64-bit): $50,000 (USD)
- ksk 12y agoThey have to exploit the fully patched versions (on the day). Prior to the contest, vendors are free to patch the exploits, if found.