nV News Forums

 
 

nV News Forums (http://www.nvnews.net/vbulletin/index.php)
-   Archived News Items (http://www.nvnews.net/vbulletin/forumdisplay.php?f=67)
-   -   Anatomy of a hack: 6 separate bugs needed to bring down Google browser (http://www.nvnews.net/vbulletin/showthread.php?t=181563)

News 05-22-12 06:40 PM

Anatomy of a hack: 6 separate bugs needed to bring down Google browser
 
http://cdn.arstechnica.net/wp-conten...b15f-intro.jpg After exploiting six different Chrome vulnerabilities, a hacker named Pinkie Pie was able to display this image on his target machine.
Dan Goodin


An exploit that fetched a teenage hacker a $60,000 bounty targeted six different security bugs to break out of the security sandbox fortifying Google's Chrome browser.

The extreme lengths taken in March by a hacker identified only as Pinkie Pie underscore the difficulty of piercing this safety perimeter. Google developers have erected their sandbox to separate Web content from sensitive operating-system functions, such as the ability to read and write files to a hard drive. Such sandboxes are designed to minimize the damage that can be done when attackers identify and exploit buffer overflows and other types of software bugs that inevitably find their way into complex bodies of code.

Pinkie Pie's attack came during Pwnium, a contest that awarded $60,000 prizes to hackers who successfully broke out of the protective barrier by exploiting only vulnerabilities residing in code that is native to the Google browser. The teenager was one of only two contestants to win the top prize. He did it after executing a custom-written Netscape Plugin Application Programming Interface directly on a Dell Inspiron laptop that ran a fully patched version of Chrome on a fully patched version of Microsoft's Windows 7 operating system. Google patched the severest of the vulnerabilities within 24 hours of them being exploited.

Read more | Comments

http://feedads.g.doubleclick.net/~at...AO26JVOYg/0/di
http://feedads.g.doubleclick.net/~at...AO26JVOYg/1/di

http://feeds.feedburner.com/~ff/arst...nY:V_sGLiPBpWU http://feeds.feedburner.com/~ff/arst...nY:F7zBnMyn0Lo http://feeds.feedburner.com/~ff/arst...?d=qj6IDK7rITs http://feeds.feedburner.com/~ff/arst...?d=yIl2AUoC8zA
http://feeds.feedburner.com/~r/arste...~4/obzm8xMbgGk

More...


All times are GMT -5. The time now is 10:30 AM.

Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Copyright 1998 - 2014, nV News.