Google Chrome stands alone at PWN2OWN
By Davey Winder in Editorial
Posted in Security, Firefox, Google, Internet, Microsoft, Apple on
Which web browser client is least at risk from hackers? If the PWN2OWN hacking competition is any measure of client security, then the clear winner was Google Chrome.
Of course, not everything is always as straightforward as it seems. And that is certainly the case when it comes to the annual PWN2OWN hacking championships that are run during the CanSecWest security conference. Standard PCs and Macs running default OS installations are used, loaded up with fully patched and current versions of the target software and no additional plug-ins to help the hackers. The rules seems pretty simple: hack the app as quickly as possible, with code execution as a requirement.
First of the web browsers to fall was Apple Safari running on a MacBook which lasted between 5 and 10 seconds in total. Charlie Miller managed to ‘own’ it by exploiting a previously unknown vulnerability and then simply clicking on a malicious URL. He proved to the judges that as a result of the remote code execution he had full control over the Mac.
Next was, perhaps a little surprisingly, Internet Explorer 8. A German chap known only as Nils managed to exploit a new vulnerability in IE8, running on a recent build of Windows 7. Someone who was no doubt surprised would be the main Internet Explorer 8 man at Microsoft, Dean Hachamovitch, who gave his keynote at the Las Vegas Mix 09 conference to launch the public release of IE8 just a few hours later proclaiming that the browser had been engineered to withstand evolving attack methods used by hackers. Oh dear. Nils, mean while, went back to the keyboard and then managed to successfully hack the Firefox browser client as well.
Two bits of good news did emerge from all this though. Firstly that these new vulnerabilities will not remain exploitable for long, indeed Microsoft are said to have already fixed the IE8 one and the patch is likely to roll out real soon now. This courtesy of the competition sponsors, TippingPoint, who pay the winning hackers a cash prize which also buys them the rights to the vulnerability details and exploit code which are immediately passed over to the vendors concerned.
Secondly, the competition did seem to prove one thing: if you want the most secure of the mainstream web browser clients then Google Chrome would appear to be the way to go. During the course of the competition, it remained unhackable it would seem. Safari hacking supremo Charlie Miller did manage to find a vulnerability, but unlike previous vulnerabilities Miller reports that he was unable to exploit this one thanks to the sandboxing and security features of Chrome.
Pingback by - March 26, 2009 on 7:59 pm
[…] Google Chrome is a more secure browser bet after all? Not yet rated Loading […]
Pingback by - April 3, 2009 on 5:21 pm
[…] Its total ****e, there are now hundreds of exploits that are in the public domain, Ms can’t keep up. This is an interesting read.. IT PRO: Blogs: Davey Winder: Google Chrome stands alone at PWN2OWN […]
Comment by - April 23, 2009 on 12:26 pm
I notice firefox didn’t get ‘pwn’d either, so chrome isn’t special or what?
Comment by Sean - April 23, 2009 on 3:16 pm
“…successfully hack the Firefox browser client…” last line of the third last paragraph, firefox was hacked. so chrome is still special, in a way
Pingback by - April 27, 2009 on 3:04 am
[…] contest (forgetting to mention the wee lil fact that Google Chrome actually outlasted it.. - article from ITPro)… NSS Labs recently released a paper that touts putting all the current browsers through […]
Comment by - October 15, 2009 on 9:59 am
The final reason why you should buy genuine, Aussie Uggs is that they will last longer. The merino sheepskin used is of a very high quality that will last you a long time and because the material allows your feet to breathe, they won’t get sweaty causing the fabric to decay.
Trackback by - November 24, 2011 on 5:39 am
Acnezine…
Acnezine reviews for acnezine…
Trackback by - November 26, 2011 on 6:38 am
Buy Wartrol…
wartrol signs and symptoms of genital warts…
Trackback by - December 1, 2011 on 1:48 am
Wartrol Reviews…
wartrol a cure for genital warts…
Trackback by - December 6, 2011 on 4:50 am
car town game cheats…
car town online game…
Trackback by - December 7, 2011 on 5:40 pm
car town cheat engine download…
money cheat for car town…
Trackback by - December 12, 2011 on 8:06 am
… [Trackback] …
[…] Read More: itpro.co.uk/blogs-archive/daveyw/2009/03/22/google-chrome-stands-alone-at-pwn2own/ […] …
Trackback by - February 9, 2012 on 4:00 am
will smith dead rumor…
[…]have one of each and every pair” or even “I experience not at the moment being my mouth area guard, I am specified that our canine […]…
Make a comment
Tag cloud
Archives
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
Most commented posts
- 80 percent of viruses love Windows 7
149 comments
- Has Microsoft gone mental?
- Has the US Army declared war on Windows 7?
- Cuil frozen out: market share drops to next to nothing
- Xbox 360 FAIL
- The 24GB RAM Desktop is born
- Use old version of Windows instead of Linux, says teacher
- Microsoft reveals time-based licensing model
- Windows XP: the invincible OS
- Nexus Two - The Next Generation
Highest Rated Blog Posts
- Why ecommerce fails (100%)
- Google Chrome stands alone at PWN2OWN (100%)
- Betting on Hubdub technology (100%)
- Has Google gone insane as GMail goes back to beta? (100%)
- Chinese whispers as government implicated in UK hack attacks (100%)
- Crimeware toolkit targets 10,000 trusted sites (100%)
- Black Hat risk to migrating VMs (100%)
- Tough on cyber crime, tough on the causes of cyber crime (100%)
- Firefox 3, Beta 4, Enhancements 900, Tested 5 (100%)
- Has the US Army declared war on Windows 7? (100%)

