Vendredi, 11 Mars 2011 06:34
Charlie Miller Hacks iPhone 4; Wins Pwn2Own 2011 Contest Again
Charlie Miller, known for exploiting the Safari browser for the past 3 years has managed to rip apart iPhone 4 security today at the Pwn2Own 2011 hacking contest at Vancouver. This is Miller’s forth consecutive win at the Pwn2Own contests. All the attack required was for the target iPhone to surf to a rigged website. On his first attempt at the drive-by exploit, the iphone browser crashed but once it was relaunched, Miller managed to hijack the entire address book. He partnered with colleague Dion Blazakis to successfully exploit the Apple device using a MobileSafari flaw to swipe the iPhone 4?s address book. After winning, Dion tweeted the following: @0xcharlie @dancaselden and I won the iPhone PWN2OWN. What a pain in the ass — glad it wasn’t iOS 4.3 (vuln still there, tho) Something interesting to note is that the iPhone 4 test device was not running the final iOS 4.3 build (most likely it was GM). But even though it was iOS 4.3, it was exploitable as the vulnerability still exists. After winning and earning $15,000 USD, the device itself, and 20,000 ZDI reward points which immediately qualified them for Silver standing. The Silver standing included a one-time $5,000 USD cash payment, 15% monetary bonus on all ZDI submissions in 2011, 25% reward point bonus on all ZDI submissions in 2011, and paid travel and registration to attend the DEFCON Conference in Las Vegas. It’s nice to see people winning at the Pwn20wn contests as it ends up helping every party in one way or another. What do you think of the news? Let us know in the comments below! As usual, stay tuned for more tech news and info by following us on Twitter and/or subscribing to our RSS feed. [Source: ZDNet] Authors:
Read 1676 times
Published in
News Technologique-Tech News
Last WebBuzz
-
WebBuzz du 04/12/2015: Animation stroboscopique de Scultures: Blooms-Blooms Strobe-Animated Sculptures
Read 13826 times
-
WebBuzz du 03/12/2015: Le challenge mobil 1: 240cm avec Jenson button-Mobil 1 challenge 240 cm with Jenson button
Read 13691 times
-
WebBuzz du 02/12/2015: Carpes et poissons chat à Tchernobyl-Chernobyl catfishes and carps
Read 14720 times
-
WebBuzz du 01/12/2015: La porte des étoiles par le groupe playmid-The Playmid's star gate
Read 15444 times
-
WebBuzz du 30/11/2015: Vie sauvage en artique filmé par drone-Wild life in artic recorded by a drone
Read 14273 times
-
WebBuzz du 27/11/2015: Les migrants de Calais: la réalité-The truth about Calais emigrants
Read 11808 times
-
WebBuzz du 26/11/2015: Un batteur vole la veddette-Best drummer ever
Read 8536 times
-
WebBuzz du 25/11/2015: Une cheminée s'écroule sur une pelleteuse-A chimney collapsed on a excavator
Read 13718 times
-
WebBuzz du 24/11/2015: Un cargo perd son ancre-A freighter loose its anchor
Read 8985 times
-
WebBuzz du 23/11/2015: Destruction du super star destroyer en LEGO-Giant Star Wars LEGO Super Star Destroyer Shattered
Read 8546 times
Accusé de reception
bancaires
bilan
cheval
configuration
Confirmation de lecture
copie
copies
Dolibarr
duplicata
EDF
Excel
exim
facture
factures
Firefox
Google cloud print
hameçonnage
IE6
IE7
impression
informatique
itunes
java
linux
luxembourgeois
mac os
MAJ
micosoft
microsoft
Office
Outlook
phishing
quicktime
rappels
relances
seamonkey
serveurs
spécifique
Sécurité
Tentative
thunderbird
troie
utilisant
V322
Vista
Windows
Windows 7
XP/2000 : Activer le pavé numérique
établissements