Page 1 of 2 12 LastLast
Results 1 to 10 of 16

Thread: Pwn2Own 2010: Google Chrome is the last man standing

  1. #1
    Skiz's Avatar (_8(I)
    Join Date
    May 2003
    Location
    CO
    Age
    47
    Posts
    22,943
    Pwn2Own 2010: Google Chrome is the last man standing
    Mar 25th 2010 at 9:01AM

    " Pwn2Own 2010 is under way, and after day one of the annual security showdown the results are darn near an exact replica of last year's. Safari was the first to fall, followed by Internet Explorer 8 on Windows 7. Firefox on Windows 7 x64 was also taken down, as was the iPhone's mobile Safari. Google Chrome, however, has yet to succumb.

    Once again, it's Chrome's sandbox which is making things difficult. At last year's Pwn2Own, Charlie Miller had this to say:

    "There are bugs in Chrome but they're very hard to exploit. I have a Chrome vulnerability right now but I don't know how to exploit it. It's really hard. They've got that sandbox model that's hard to get out of. With Chrome, it's a combination of things - you can't execute on the heap, the OS protections in Windows and the Sandbox."

    Miller successfully targeted Safari on OsX using one of 20 exploits he had at the ready -- exploits which he uncovered using a simple 5-line Python script. "Tomorrow, I'm going to describe exactly how I found them, so hopefully that means Apple will replicate what I did and they'll find my 20 [bugs] and probably a lot more," Miller stated.

    The mobile Safari attack was particularly impressive, since running code on the iPhone requires a valid digital signature. By rearranging bits of pre-signed code, Halvar Flake of Zynamics was able to deliver a malicious payload via Safari and force the iPhone to cough up its complete SMS database. Contacts and messages were laid bare -- including deleted ones.

    While most (if not all) of these exploits aren't being used in the wild, it's still an indication of just how scary the landscape of the Internet is right now. How do you stay safe? Google Chrome looks like a good choice, obviously, but there's another option: Opera.

    As one participant put it, "I use Opera, but that's basically because it has a tiny market share and as far as I know, nobody is really interested in creating a drive-by download for Opera."

    Gotta love security by obscurity -- am I right, Apple fans? "

    Source: Pwn2Own 2010: Google Chrome is the last man standing Homepage: http://www.downloadsquad.com/
    Last edited by Skiz; 04-02-2010 at 05:47 AM.

  2. News (Archive)   -   #2
    I'm trying to get in the habit of using sandboxie with whatever browser I'm using at the moment. They say the 64 bit version of ie8 is also very isolated and secure.

  3. News (Archive)   -   #3
    I came a little.

  4. News (Archive)   -   #4
    Poster
    Join Date
    Nov 2008
    Posts
    15
    interesting. wonder if there are any performance penalties in chrome for being so secure

  5. News (Archive)   -   #5
    Actually Chrome is faster than firefox or ie. I will switch when AB+ is available for it.
    Last edited by Sporkk; 04-09-2010 at 10:45 PM.

  6. News (Archive)   -   #6
    Quote Originally Posted by jedispork View Post
    Actually Chrome is faster than firefox or ie.
    Is it faster than Opera 10.50?
    "I just remembered something that happened a long time ago."

  7. News (Archive)   -   #7
    If chome has more optional extensions as firefox,mostly something like ABP and many other excellent ones,I bet chrome will have a large share。
    Now I’m using firefox with noscript,it's much safer!

  8. News (Archive)   -   #8
    I didn't find no script to be worth the hassle. If a site is compromised you can still be attacked through your white list fwir. I like the virtualized security like sandboxie but noscript could still be cool to see whats going on.
    Last edited by Sporkk; 04-20-2010 at 01:14 PM.

  9. News (Archive)   -   #9
    ca_aok's Avatar Poster BT Rep: +1
    Join Date
    Feb 2008
    Posts
    1,547
    I use NoScript... it's annoying to set up your initial whitelist of sites you frequent but afterwards it works quite well. CookieSafe is another decent extension that works just like NoScript does except with cookies rather than scripts.
    Quote Originally Posted by whatcdfan View Post
    u are somewhat fairer then the last occasions but still pal i give a damn to what u said and expect i really dont need anything from u or optimuscrime i get what i want coz u 2 guyes dont own bittorrent and i dont think i portrayed any image i wrote simple english and u are seems to be very good at making assumptions if someone is not a cheater and u assume he's a cheater and write what u wrote and when u are proven wrong who u think will owe an apology then barack obama????

  10. News (Archive)   -   #10
    Quote Originally Posted by ca_aok View Post
    CookieSafe is another decent extension that works just like NoScript does except with cookies rather than scripts.
    I wish there was something like that for Opera... I hate tracking/unnecessary cookies, and disabling them individually doesn't really work.
    "I just remembered something that happened a long time ago."

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •