

Pwn2Own 2023 day one, all major operating systems and Tesla Model 3 hacked | Tec...
source link: https://www.techspot.com/news/98050-pwn2own-2023-day-one-all-major-operating-systems.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Pwn2Own 2023 day one, all major operating systems and Tesla Model 3 hacked
Nothing can survive financially motivated hackers these days
By Alfonso Maruccia Today 8:08 PM
In context: Pwn2Own is an annual hacking contest held at Vancouver's CanSecWest security conference. The event usually hosts high-profile coders and researchers who can demonstrate their skills by finding and exploiting security vulnerabilities in popular software platforms and technology products.
Trend Micro's Zero Day Initiative (ZDI) announced Pwn2Own 2023's first-round winners. Five participants earned $375,000 in prize money from an over $1 million pool by hacking widely popular operating systems, software programs, and a Tesla Model 3 car. The hackers found 12 zero-day vulnerabilities in all.
Offensive security firm Synacktiv compromised a Tesla Model 3 with a TOCTOU (time-of-check to time-of-use) attack in the Automotive category, then escaped access privileges on macOS. The team won the most money, pocketing $140,000, and the hacked Tesla. Its victories put it first on the leaderboard with 14 "Master of Pwn" points for the day.
The STAR Labs team won $115,000 and 11.5 MoP points with a zero-day exploit chain targeting Microsoft SharePoint and successfully hacking the Ubuntu Desktop operating system with a previously known exploit. It will enter Day Two of the competition in second place.
That wraps up the first day of #P2OVancouver 2023! We awarded $375,000 (and a Tesla Model 3!) for 12 zero-days during the first day of the contest. Stay tuned for day two of the contest tomorrow! #Pwn2Own pic.twitter.com/UTvzqxmi8E
— Zero Day Initiative (@thezdi) March 22, 2023
The third spot goes to individual security researcher Abdul Aziz Hariri. Hariri earned $50,000 and 5 MoP points by demonstrating an exploit in Adobe Reader that allowed him to abuse multiple "failed" patches, escape the program's sandbox, and bypass a banned API list on macOS.
Fourth and fifth on the leaderboard are Qrious Security researcher Bien Pham and individual hacker Marcin Wiazowski. Pham won $40,000 by hacking Oracle's VM VirtualBox through an OOB Read and a stacked-based buffer overflow. Wiazowski successfully elevated user privileges under Windows 11 with an improper input validation zero-day flaw worth $30,000. Unfortunately, Pham's four and Wiazowski's three Master of Pwn points leave the pair with a large gap to reach first or second overall.
Zero Day Initiative will disclose the details of the zero-day vulnerabilities demoed during Pwn2Own 2023 to their respective software vendors. Developers will have 90 days to release security patches. The organization will publicly disclose the flaws after this deadline, regardless of the patch status.
During its three-day schedule, Pwn2Own 2023 will host demonstrations for targeted attacks in categories such as enterprise applications and communication, local privilege escalation, server, virtualization, and automotive. In 2022, the Vancouver hack fest awarded $1,155,000 to security researchers.
Recommend
-
67
博客园 博客园用户登录...
-
62
-
55
README.md Pwn2Own 2018: Safari + macOS Safari RCE, sandbox escape, and LPE to kernel for macOS 10.13.3. Usage Install nasm and tornado:...
-
29
移动安全已经变得越发重要,因此也成为了黑客们关注的重点。在刚刚结束的Pwn2OwnTokyo2018上,一群黑客相继对不同的手机发起了猛攻,最终,小米6五次挑战中均被攻破,此外iPhoneX和三星S9也未能幸免于黑客攻击。
-
18
-
44
On the first day of Pwn2Own 2019 hackers poked holes in Apple Safari, VMware Workstation and Oracle VirtualBox. Hackers took down Apple Safari, VMware Workstation, and Oracle VirtualBox on Wednesday, the...
-
34
Browsers Firefox and Edge take a beating on day two of the Pwn2Own competition. Hackers took down the Mozilla Firefox and Microsoft Edge browsers on Thursday at Pawn2Own, the annual hacking conference he...
-
33
*本文中涉及到的相关漏洞已报送厂商并得到修复,本文仅限技术研究与讨论,严禁用于非法用途,否则产生的一切后果自行承担。*本文原创作者:Tasfa,本文属FreeBuf原创奖励计划,未经许可禁止转载 0x01 前言这...
-
33
语音播放文章内容 由深声科技提供技术支持 您的浏览器不支持 audio 元素。 自2007年以来,Pwn2Own便鼓励参赛者...
-
3
Windows 11 and Teams got hacked several times during the first day of Pwn2Own 2022...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK