Skip to main content

iPhone will be first mobile device to fall at Pwn2Own 2010

The fourth annual Pwn2Own contest—which takes place at the CanSecWest security conference every year—kicks off next week. Like last year, 2010's contest will offer security experts and hackers the chance to "pwn" a number of mobile platforms in addition to various browser/OS combinations. Though no mobile devices were successfully hacked last year, expectations are high that the iPhone will go down in this year's contest.

"With all the recent research on mobile phone security being presented worldwide, these devices are quickly becoming a ripe target," wrote Aaron Portnoy, security researcher at TippingPoint and Pwn2Own contest organizer. "First to fall: the iPhone."

Mac OS X security expert Charlie Miller, known for his past exploits of Safari and discovery of a possible arbitrary code execution exploit for the iPhone, is also confident that the iPhone will go down this year. "Someone I know quite well says they have an exploit for it and plan on using it," he said recently during a chat with Kapersky Labs' ThreatPost. "From an exploitation perspective, iPhone is no harder than [Mac] OS X now that Snow Leopard has data execution protection," Miller explained.

However, Miller plans to stick to Safari, which he successfully attacked the last two years, netting him thousands in cash and two MacBooks. "There isn't as much exposed code on the iPhone," he said. "The easy to exploit bugs I know about happen to live in the code that Safari has but Mobile Safari doesn't," mostly due to Mobile Safari's lack of support for Java, Flash, and other third-party plugins.

Also, Miller said, "in real life the iPhone is harder because you can't just execute a shell. You have to write your return-oriented payload to do all your dirty work, which can be a pain."

Miller said that attacking Safari this year will be harder than last year, since Snow Leopard has DEP and Safari sandboxes plug-ins in separate processes. However, he noted that Snow Leopard's incomplete support for address space layout randomization still leaves the Safari and Mac OS X combination open to vulnerabilities.

This year, contestants will have a chance to nab a laptop and a $10,000 cash prize for demonstrating exploits for IE8, Firefox 3, and Google Chrome 4 running under Windows 7, or Safari 4 running on Mac OS X 10.6. Contestants that successfully hack an iPhone 3GS, BlackBerry Bold 9700, a Nokia E62, or a Motorola Droid will get to keep the device as well as $15,000 in cash.

Comments

Popular posts from this blog

SEO Optimizing A Website For Improved Value

SEO or search engine optimization is something that every web owner and creator should be aware of. Even if a website owner hires an expert to carry out the online marketing, understanding the very basics and how it really can improve a websites performance and popularity is important. Simply put, optimizing a website is important and is built around keywords that are valuable to a website and to the products or services it is trying to provide. By focusing on main keywords or key phrases for a business, and expanding on them over time, can improve the amount of visitors a website receives, in turn increasing profits or simply improving its popularity if it is an information website. SEO is valuable, and means a way of making a site appear at a higher ranking in search engines such as Google, Yahoo, AOL etc. Using this important type of online marketing can reap great benefits. It takes time to learn and time to complete, and is a constant job to keep a website performing well above co...

PsyberOmni: Unlocking the Potential of Digital Excellence

Are you ready to take your digital presence to the next level? PsyberOmni is not just a digital platform; it’s a movement designed to empower individuals and organizations to thrive in the ever-evolving digital world. With expertly crafted tutorials, engaging blog posts, and a community-oriented approach, PsyberOmni is your go-to source for all things digital. Whether you are an entrepreneur, a student, or simply someone eager to learn, PsyberOmni has something for you. In this blog post, we'll dive deep into what PsyberOmni offers, why it's a game-changer for your digital growth, and how you can leverage the tools and content they provide to enhance your skills and expand your digital capabilities. Let’s explore everything you need to know about PsyberOmni! Why PsyberOmni? - Empowering the Digital Landscape In today's fast-paced world, staying updated with digital skills is crucial. PsyberOmni recognizes this need and offers a platform that brings together educationa...

Email On Deck: A disposable email address that works

Today, Team Inforpioneer brings an interesting Email service for our reader which will definitely help our readers to improve their internet security and will benefit in some other ways.  Here is a short description of this service.  EmailOnDeck.com is the premier site for all things relating to temporary, disposable and throwaway email addresses. We want to help you avoid SPAM, protect your online privacy, and stop you from having to give away your personal email address to every company and person on the internet who insists on you giving it to them. We work hard and will continue to work hard to give you a disposable email address that works with any site or app. We hope to help give you back the control of deciding who you want to give your personal info to. Temporary emails are perfect for any transaction where you want to improve your online privacy. Use them when you buy or sell Bitcoins or trade cryptocurrency, at exchanges, or locally. They can be used for QA tes...