Safari/Mac OS X first to fall at pwn2own
zdnet.com
zdnet.com
Pwn2Own browser day: March 9th, 2011
Safari 5.0.4 released March 9th
Chrome 10.0.648.127 released March 8th
Firefox 3.6.15 released March 4th
Internet Explorer 8 didn't get a patch this cycle (too cool for school)
Mobile day: March 10th, 2011 iOS 4.3 released March 9th
Nexus S 2.3.3 released Feb 24th
Not sure about WP7 & BB@VUPEN: Anti-pwn2own again: Apple fixed a record of 50 vuln. in Webkit (iTunes), and is preparing the update for Safari / Mac OS X... (1:43 AM Mar 3rd via web)
http://twitter.com/VUPEN/status/43245159776915456
And the trades agree:
Mozilla follows Google, patches Firefox as prep for Pwn2Own
http://www.computerworld.com/s/article/9212479/Mozilla_follo...
etc.
Besides, if most competitors arrive at the competition with carefully-researched exploits available to use, I'm not sure this sort of last-minute patching would make much difference, even if it was intentional.
I'm not sure this sort of last-minute patching would make much difference
Even if the vulnerability is still there, screwing with the way the binary is built and linked could easily make it so they'd have to put it back in a debugger and retune the exploit.
It would be different if the other OS/browsers didn't go down too, but because the Mac is always first to go just means it's the most desirable target.
UPDATE: It's actually a MacBook Air 13", not MBP. The other laptops are ASUS G73SW and Alienware M11x.
Mac's always go down quickly in these contests. The people who make it happen often say that its considerably easier.
edit: Charlie Miller: "It's really simple. Safari on the Mac is easier to exploit. The things that Windows do to make it harder (for an exploit to work), Macs don't do. Hacking into Macs is so much easier." - http://www.zdnet.com/blog/security/questions-for-pwn2own-hac...
Did Safari fall first because it is the least secure, or because it is the hardware everyone wants to win? It really is difficult, if not impossible to tell.
Personally, I'm quite sure that the Windows machines are at this point far more secure, simply because Microsoft takes so much battering by being in the dominant position. But I wouldn't use this as evidence for it.
EDIT: Question about your quote-- later in that article, Miller suggests that there is no "randomization" in OS X, while this year's article says his exploit bypassed ASLR in OS X-- is this a new feature in OS X that wasn't present in 2009?
That's just weak, the prizes were $15,000 even for IE8 and Google was offering $20K.
How many Macbooks can you get for $15K or $20K ?
http://www.computerworld.com/s/article/9207939/Google_bets_2...
The easiest way to get a lot of Macbooks would be to exploit the easy software to hack and just buy them from the store.
I really don't think that these security researchers as prioritizing based on winning a $1200 laptop. Given that this competition is time-based, I'd, again, say that they prioritize based on speed.
Most ASLR bypasses are when someone's found an application that includes one or more images that was compiled without randomization support and thus has a predictable load address and code to use; with OS X you get one for free in every application by default.
10.7 is supposed to have better ASLR, haven't investigated yet though.
In fact he associated the fact of being the most awesome and generating the most media coverage with the fact it would be the first to fall, regardless of how secure or not the computer is.
In fact, they are developed far in advance. The order the browsers fall is determined by the order the challengers get to demonstrate their hacks.
However, a vulnerability on the Mac isn't worth as much (on the black-market) as a vulnerability on Windows. So people keep trying to break Windows. Even if you tried to sell a Mac vulnerability, the people who make botnets wouldn't be interested, as they can buy Windows vulnerabilities instead.
pwn2own is the only show in town where a Mac vulnerability is worth roughly the same as a Windows one.
I suppose being the easiest target couldn't possibly be a reason, could it?
You're one of those people that cause others to label Mac users as zealots suffering from cognitive dissonance, aren't you?
”We had to do everything from scratch. We had to create a debugging tool, create the shellcode and create the ROP (return oriented programming) technique,”
Obviously there is a fair bit of preparation involved.
Day 1: Default install no additional plugins. User goes to link.
Day 2: flash, java, .net, quicktime. User goes to link.
Day 3: popular apps such as acrobat reader ... User goes to link
iirc it's only the last year or two that most of them have been falling on day 1I've tried Chrome, but I just always go back strangely to Safari it just feels right at home.
This is really embarrassing for OS X fans.
Everyone who signs up for this has exploits already in the bag that they've been working on for weeks, it's not like it's hackers showing up and racing each other to discover exploits from scratch (which, incidentally, renders the whole "first to fall"/"browser X pwned in seconds" style of headline asinine)
[1] http://venturebeat.com/2011/02/26/apple-wises-up-by-sharing-...