Skip to main content [aditude-amp id="stickyleaderboard" targeting='{"env":"staging","page_type":"article","post_id":635145,"post_type":"story","post_chan":"none","tags":null,"ai":false,"category":"none","all_categories":"business,security,","session":"A"}']

Fail: Chrome, Firefox, and IE all crack during hacking competition

Fail: Chrome, Firefox, and IE all crack during hacking competition

Google, Microsoft, and Mozilla all patched up their browsers before the Pwn2own competition in Vancouver today, but the "hackers" still got in and in some cases were able to grab hold of the whole operating system as a result.

Chrome coffee fail

Chrome, Internet Explorer, and Firefox all fell to the mercy of the hackers today. That is, in a controlled environment.

[aditude-amp id="flyingcarpet" targeting='{"env":"staging","page_type":"article","post_id":635145,"post_type":"story","post_chan":"none","tags":null,"ai":false,"category":"none","all_categories":"business,security,","session":"A"}']

Security firms Vupen and MWR Labs were able to crack the browsers during a condoned bug-hunt today, with one company winning $100,000 for finding a huge hole.

The Pwn2Own competition is an event at the CanSecWest conference in Vancouver. HP’s DVLabs created the competition as part of its Zero Day Initiative: an attempt to get more people to find and report bugs as opposed to exploiting them for personal gains. This year’s Pwn2Own competition turned up a number of interesting hacks, with three major browsers all falling: Firefox, Internet Explorer, and Chrome.

AI Weekly

The must-read newsletter for AI and Big Data industry written by Khari Johnson, Kyle Wiggers, and Seth Colaner.

Included with VentureBeat Insider and VentureBeat VIP memberships.

Vupen, a security research firm based in France, cracked both Firefox and Internet Explorer. It roughly explained the attack in a tweet (warning: A lot of security vocabulary is incoming), “We’ve pwned Firefox using a use-after-free and a brand new technique to bypass ASLR/DEP on Win7 without the need of any ROP.”

The technique involves recalling memory that the browser had previously “freed,” (user-after-free), after which they were able to mess with the technology that protects a computer system from letting bad code execute.

In Internet Explorer’s case, Vupen says it found two separate “zero-days,” or previously unknown holes in a system, and used them to get inside a Microsoft Surface Pro tablet. From there, the company was able grab hold of Windows 8.

The company explained, again, in a tweet, “We’ve pwned MS Surface Pro with two IE10 zero-days to achieve a full Windows 8 compromise with sandbox bypass.”

Lastly, U.K.-based security firm MWR Labs cracked Chrome and also gained full control of the operating system, this time Windows 7. It also “demonstrated a full sandbox bypass exploit.” The company explained in a blog post that it found a zero-day in Chrome “running on a modern Windows-based laptop.” It was able to exploit the vulnerability by performing a very similar attack to what took down Facebook, Microsoft, and a number of other well-known companies: It had the laptop visit a malicious website. From there the website probed Chrome and was able to get control of the area of the browser that executes code “in the context of the sandboxed renderer process,” or the protective area that allows code to run, but restrict it from using any other part of the system but the CPU and memory.

The sandbox cannot, however, protect against any attacks against the kernel, or the root of the operating system, it exists in and that’s exactly what MWR took advantage of. It found a vulnerability in the kernel, exploited it, and gained full access to the Windows 7 system.

[aditude-amp id="medium1" targeting='{"env":"staging","page_type":"article","post_id":635145,"post_type":"story","post_chan":"none","tags":null,"ai":false,"category":"none","all_categories":"business,security,","session":"A"}']

Shabam.

All of these browsers had been previously patched in preparation for the competition, showing just how much can be missed and how valuable these types of bug-finding events are. MWR won $100,000 as a result. Of course, both MWR and Vupen properly disclosed all the documentation of its findings to the appropriate browser security teams.

hat tip ZDNet; Chrome coffee image via yukop/Flickr

VentureBeat's mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Learn More