Major points:
- You register for which browser + os combination[0]. Then they randomly order the contestants.
- When you are called, you have 30 minutes.
- The user browses to a particular piece of content that you specify. Then no further user interaction is allowed (like clicking a dialog, downloading a file). [1][2]
- The prize money goes to the first successful exploit. Money differs by browser.
[0] Chrome, Firefox, IE, Adobe Reader in IE, Adobe Flash in IE. Safari on OSX. Fully patched OS.
[1] How does one get to specify the content? What if I have a http header that downloads a file?
[2] I remember back in the day, they used to have a fully no interactive version? Like the user was just on the same wireless network?
That makes more sense. Otherwise, this is movie-script-like hacking ability.
Windows-based targets:
1. Google Chrome (64-bit): $75,000 (USD)
2. Microsoft Internet Explorer 11 (64-bit with EPM-enabled): $65,000 (USD)
3. Mozilla Firefox: $30,000 (USD)
4. Adobe Reader running in Internet Explorer 11 (64-bit with EPM-enabled): $60,000 (USD)
5. Adobe Flash (64-bit) running in Internet Explorer 11 (64-bit with EPM-enabled): $60,000 (USD)
Mac OS X-based targets:
1. Apple Safari (64-bit): $50,000 (USD)
It feels like, just the fact that this competition and other bug bounty programs exist, means that the big companies here have gotten over reputation tarnish and know that the patch is worth it.
I'm pretty sure no system ever is going to be as exploitable as Windows.
http://googleonlinesecurity.blogspot.com/2015/02/pwnium-v-ne...
Do you mean that they used to sell the exploits to other hackers at Pwn2Own?
Nohig ethical at all going on here.
http://blog.chromium.org/2015/02/pwnium-v-never-ending-pwniu...