Skip to main content

iPhone will be first mobile device to fall at Pwn2Own 2010

The fourth annual Pwn2Own contest—which takes place at the CanSecWest security conference every year—kicks off next week. Like last year, 2010's contest will offer security experts and hackers the chance to "pwn" a number of mobile platforms in addition to various browser/OS combinations. Though no mobile devices were successfully hacked last year, expectations are high that the iPhone will go down in this year's contest.

"With all the recent research on mobile phone security being presented worldwide, these devices are quickly becoming a ripe target," wrote Aaron Portnoy, security researcher at TippingPoint and Pwn2Own contest organizer. "First to fall: the iPhone."

Mac OS X security expert Charlie Miller, known for his past exploits of Safari and discovery of a possible arbitrary code execution exploit for the iPhone, is also confident that the iPhone will go down this year. "Someone I know quite well says they have an exploit for it and plan on using it," he said recently during a chat with Kapersky Labs' ThreatPost. "From an exploitation perspective, iPhone is no harder than [Mac] OS X now that Snow Leopard has data execution protection," Miller explained.

However, Miller plans to stick to Safari, which he successfully attacked the last two years, netting him thousands in cash and two MacBooks. "There isn't as much exposed code on the iPhone," he said. "The easy to exploit bugs I know about happen to live in the code that Safari has but Mobile Safari doesn't," mostly due to Mobile Safari's lack of support for Java, Flash, and other third-party plugins.

Also, Miller said, "in real life the iPhone is harder because you can't just execute a shell. You have to write your return-oriented payload to do all your dirty work, which can be a pain."

Miller said that attacking Safari this year will be harder than last year, since Snow Leopard has DEP and Safari sandboxes plug-ins in separate processes. However, he noted that Snow Leopard's incomplete support for address space layout randomization still leaves the Safari and Mac OS X combination open to vulnerabilities.

This year, contestants will have a chance to nab a laptop and a $10,000 cash prize for demonstrating exploits for IE8, Firefox 3, and Google Chrome 4 running under Windows 7, or Safari 4 running on Mac OS X 10.6. Contestants that successfully hack an iPhone 3GS, BlackBerry Bold 9700, a Nokia E62, or a Motorola Droid will get to keep the device as well as $15,000 in cash.

Comments

Popular posts from this blog

Email On Deck: A disposable email address that works

Today, Team Inforpioneer brings an interesting Email service for our reader which will definitely help our readers to improve their internet security and will benefit in some other ways.  Here is a short description of this service.  EmailOnDeck.com is the premier site for all things relating to temporary, disposable and throwaway email addresses. We want to help you avoid SPAM, protect your online privacy, and stop you from having to give away your personal email address to every company and person on the internet who insists on you giving it to them. We work hard and will continue to work hard to give you a disposable email address that works with any site or app. We hope to help give you back the control of deciding who you want to give your personal info to. Temporary emails are perfect for any transaction where you want to improve your online privacy. Use them when you buy or sell Bitcoins or trade cryptocurrency, at exchanges, or locally. They can be used for QA tes...

SEO Optimizing A Website For Improved Value

SEO or search engine optimization is something that every web owner and creator should be aware of. Even if a website owner hires an expert to carry out the online marketing, understanding the very basics and how it really can improve a websites performance and popularity is important. Simply put, optimizing a website is important and is built around keywords that are valuable to a website and to the products or services it is trying to provide. By focusing on main keywords or key phrases for a business, and expanding on them over time, can improve the amount of visitors a website receives, in turn increasing profits or simply improving its popularity if it is an information website. SEO is valuable, and means a way of making a site appear at a higher ranking in search engines such as Google, Yahoo, AOL etc. Using this important type of online marketing can reap great benefits. It takes time to learn and time to complete, and is a constant job to keep a website performing well above co...

Dr. Elmi Zulkarnain Osman. The Award Winning Trainer With The Right Humour.

Dr. Elmi Zulkarnain Osman – an award-winning educator, a popular corporate trainer and a highly paid Malay English Language Coach started his career as a teacher in a government school in Singapore before becoming a lecturer in a government-based institute. Throughout his career with the Singapore Public Service, Dr. Elmi has already been acknowledged as an accomplished public speaker and a motivational speaker known for his high energy delivery and humorous approach. He is also well known in the grassroots circle as an experienced Chief Facilitator and an accomplished Forum Moderator. Upon completing his PhD in Educational Leadership with Trident University International in 2018, he and a few like-minded friends decided to set up Elemantra Training Consultancy. A consultancy that has been delivering their promise to deliver an “enriching experience every time”. As the CEO and Principal Trainer at Elemantra Consultancy, Dr. Elmi is very much known for his exceptional communication ...