Skip to main content

Hacking Chrome? Google Bets $20,000 you can't

Google has donated $20,000 to a yearly hacking competition to be awarded to the first researcher able to crack its Chrome browser. The Mountain View, Calif. company's move marks the first time a browser developer has contributed money to the contest.

The Pwn2Own competition is in its fifth year and is held at the CanSecWest security conference. Participants are tasked with cracking a variety of other browsers too (Apple's Safari, Microsoft's Internet Explorer, and Mozilla's Firefox) on computers supplied by the contest creators running Windows 7. Those that perform a successful crack win the computer it was done on as well as a $15,000 cash prize.

Cracking Chrome will be hard. The browser uses what is called a "sandbox," which isolates system processes. In order for a crack to be successful, first the sandbox must be cracked, and then the exploit code itself executed.

Google is offering a CR-48 netbook as a prize itself in addition to the cash award. The netbook would only be offered as a prize -- the exploit would need to be performed on the other computers offered.

"Kudos to the Google security team for taking the initiative to approach us on this; we're always in favor of rewarding security researchers for the work they too-often do for free," HP TippingPoint security research team manager Aaron Portnoy said. Portnoy's firm runs the Pwn2Own competition.

Another portion of the contest will include hacks to popular mobile OS platforms including BlackBerry OS, iOS, and Android. Like the browser competition, a $15,000 prize and the device itself would be awarded.

Registration for the contest is open until February 15. Instructions and more information can be found from HP TippingPoint's website.

http://www.betanews.com/article/Hacking-Chrome-Google-Bets-20000-you-cant/1296848941

Comments

Popular posts from this blog

[AIX] How to restart network service in AIX environment?

When network service like telnet connection hangs, then it is possible the inetd subsystem is not working properly. # refresh -s inetd 0513-095 The request for subsystem refresh was completed successfully. If the refresh hangs for some time and comes back with 0513-056 time out waiting for command response, then the inetd subsystem may not be working correctly and should then be killed nicely. Run #ps -ef | grep inetd and do a kill -15 on the process ID on the line that has /usr/sbin/inetd. Once inetd has been killed, type startsrc -s inetd. If inetd starts, try to telnet into the machine. If inetd does not start up successfully, or if telnet still hangs indefinitely, run kill -15 on the PID of inetd again. Back up the original /etc/inetd.conf file to a new file name by typing: # mv /etc/inetd.conf /etc/inetd.conf.backup The original template is in /usr/lpp/bos.net/inst_root/etc/. You can copy it by typing: # cp /usr/lpp/bos.net/inst_root/etc/inetd.conf /etc/inetd.conf Run start...

Configure Link based IPMP in Solaris

For long we used Tracking IP based IPMP wherein we track the availability of a gateway on the network using ICMP Echo request. When the gateway IP fails to respond it is considered link is unavailable and NIC fails over to the standby NIC in the IPMP group. The biggest disadvantage here is that we use 3 IP addresses: 1 for the Virtual IP 1 for the active NIC 1 for the Standby NIC and ofcourse the overhead of the ICMP echo requests sent every seconds. This can be overcome using the Link based IPMP configuration where you only need only IP Address and there is no overhead of ICMP messages and the failover delay is lot lesser than that of the tracking method. And the added advantage of a very simple configuration. To configure Link based IPMP, create the hostname.<int name> files for the Active NIC and the standby NIC. For instance here, we use the bge0 and bge3 NICs as the IPMP pair where bge0 is active and bge3 is standby and hence the files hostname.bge0 and hostname.bge3 . To...

Windows Server Backup Step-by-Step Guide for Windows Server 2008

The Windows Server Backup feature provides a basic backup and recovery solution for computers running the Windows Server® 2008 operating system. Windows Server Backup introduces new backup and recovery technology and replaces the previous Windows Backup (Ntbackup.exe) feature that was available with earlier versions of the Windows operating system. What is Windows Server Backup? The Windows Server Backup feature in Windows Server 2008 consists of a Microsoft Management Console (MMC) snap-in and command-line tools that provide a complete solution for your day-to-day backup and recovery needs. You can use four wizards to guide you through running backups and recoveries. You can use Windows Server Backup to back up a full server (all volumes), selected volumes, or the system state. You can recover volumes, folders, files, certain applications, and the system state. And, in case of disasters like hard disk failures, you can perform a system recovery, which will rest...