Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Researcher hacks just-launched IE8

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Editorials & Other Articles Donate to DU
 
OhioChick Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Mar-19-09 10:14 PM
Original message
Researcher hacks just-launched IE8
Cracks Microsoft's new browser hours before release; also hacks Safari, Firefox

March 19, 2009 (Computerworld) Just hours before Microsoft Corp. officially launched the final code for Internet Explorer 8, a German researcher yesterday hacked the browser during the PWN2OWN contest to win $5,000 and a Sony Viao laptop.

The researcher, a computer science student from Germany who would only give his first name, Nils, broke into the Sony within minutes by exploiting a previously unknown vulnerability in the new browser, said Terri Forslof, manager of security response at 3Com Corp.'s TippingPoint, the contest sponsor. The laptop was running what Forslof described as a "recent Microsoft internal build" of Windows 7.

Earlier today, Microsoft launched the final version of IE8 for Windows XP, Vista, Server 2003 and Server 2008. A final edition for Windows 7, however, has not been released to the public.

"It was important for Microsoft to see that bug right away," said Forslof today. "There are cases in product development where you might have a vulnerability so critical that makes the call to actually block the release. Microsoft needed to see that and evaluate that vulnerability."

More: http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9130074&intsrc=hm_ts_head
Printer Friendly | Permalink |  | Top
BlooInBloo Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Mar-19-09 10:15 PM
Response to Original message
1. (Hugs his wonderful firefox with bunches of lovely extensions)
Printer Friendly | Permalink |  | Top
 
baldguy Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Mar-19-09 10:51 PM
Response to Original message
2. Guy needs a hobby.
Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Mar-21-09 06:37 PM
Response to Original message
3. Well heck, this doesn't look good. nt
Printer Friendly | Permalink |  | Top
 
vow66 Donating Member (167 posts) Send PM | Profile | Ignore Sat Mar-21-09 08:50 PM
Response to Original message
4. The Pwn2Own trifecta
The Pwn2Own trifecta: Safari, IE 8, and Firefox exploited on day 1
http://www.engadget.com/2009/03/19/the-pwn2own-trifecta-safari-ie-8-and-firefox-exploited-on-day/
That didn't take long. One day into the Pwn2Own hacking competition at CanSecWest and already Apple, Microsoft, and Mozilla have been sent packing to their respective labs to work on security issues in their browsers. In a repeat performance, Charlie Miller pocketed a $5,000 cash prize and a fully-patched MacBook by splitting it wide, and gaining full control of the device after a user clicked on his malicious link.


Safari hole exploited in seconds at security conference
http://news.cnet.com/8301-1009_3-10199652-83.html
The security expert who won $10,000 hacking a MacBook Air in less than two minutes last year won $5,000 on Wednesday by exploiting a hole in Safari in 10 seconds or so.

Charlie Miller, principal security analyst at Independent Security Evaluators, used a MacBook running the latest version of the Mac OS as part of a contest at the CanSecWest security conference called "Pwn2Own," which is hacker slang for gaining control of a computer.


Questions for Pwn2Own hacker Charlie Miller
http://blogs.zdnet.com/security/?p=2941

Why Safari? Why didn’t you go after IE or Safari?

It’s really simple. Safari on the Mac is easier to exploit. The things that Windows do to make it harder (for an exploit to work), Macs don’t do. Hacking into Macs is so much easier. You don’t have to jump through hoops and deal with all the anti-exploit mitigations you’d find in Windows.
It’s more about the operating system than the (target) program. Firefox on Mac is pretty easy too. The underlying OS doesn’t have anti-exploit stuff built into it.







Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Mar-21-09 09:33 PM
Response to Original message
5. "Web security" is an oxymoron.
Not that I blame them for trying. What you have really is an arms race, or maybe a red queen situation. Run like hell to stay in the same place. The only sane thing to do is not put important stuff on the web. The web is for aimless talk, dialog, ranting, etc. Or else use industrial quality encryption end-to-end and screw performance. It's like random sex without condoms otherwise.
Printer Friendly | Permalink |  | Top
 
8 track mind Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Mar-21-09 11:29 PM
Response to Original message
6. Doh!!! n/t
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue May 07th 2024, 10:10 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Editorials & Other Articles Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC