Switch to Linear ModeSwitch to Hybrid ModeSwitch to Threaded Mode
Printer Friendly View | Email this page | Register Now to start posting!
BaLtO
BaLtO's Avatar
Moderator


Join Date: Apr 2007
Posts: 2,577
Trade rep: 0 (0%)
Infractions: 0/0 (0)
Chrome withstand the first day of the CanSecWest contest BaLtO Mar 22nd, 09, 06:38 AM #1

"During a contest at the CanSecWest event, security researchers competed to exploit vulnerabilities in web browsers. Firefox, Safari, and Internet Explorer were all successfully compromised, but Chrome was able to withstand the first day of the competition."

Quote:
A recent contest at CanSecWest, an event that brings together some of the most skilled experts in the security community, has demonstrated that the three most popular browser are susceptible to security bugs despite the vigilance and engineering prowess of their creators. Firefox, Safari, and Internet Explorer were all exploited during the Pwn2Own competition that took place at the conference. Google's Chrome browser, however, was the only one left standing—a victory that security researchers attribute to its innovative sandbox feature
Chrome only browser left standing after day one of Pwn2Own - Ars Technica


sg.png
techniqu Registered User


Join Date: Aug 2008
Posts: 589
Trade rep: 0 (0%)
Infractions: 0/0 (0)
techniqu Mar 22nd, 09, 08:53 AM #2
are they sure it's because of this feature and not because IE, Safari, and Firefox have been around longer?
us.png
-Zero- Leg**dary Hero


Join Date: Jul 2008
Posts: 492
Trade rep: 0 (0%)
Infractions: 0/0 (0)
-Zero- Mar 22nd, 09, 09:38 AM #3
First of all, Internet Explorer has a sandbox as well. So it's completely wrong to say that Chrome's sandbox is an 'innovative new feature'.

Microsoft IE came out with that first.

But the problem is that IE's sandbox mode only works if UAC is on. And we do not know what OS they were using for the test, and neither do we know if UAC had been turned off as well. If they were using Windows XP, then of course IE would fall quickly since XP does not have UAC to trigger sandbox mode aka Protected Mode in IE.

But the fact that Safari fell first in seconds: now THAT's something to put the Apple fanboys in their place.
sg.png
BaLtO
BaLtO's Avatar
Moderator


Join Date: Apr 2007
Posts: 2,577
Trade rep: 0 (0%)
Infractions: 0/0 (0)
BaLtO Mar 22nd, 09, 09:57 AM #4
Quote:
Fresh from winning the PWN2OWN contest yesterday, Charlie Miller has been interviewed by ZDNet. He talks about how Mac OS X is a very simple operating system to exploit due to the lack of any form of anti-exploit features. He also explains that the underlying operating system is much more important in creating a successful exploit than the bowser, why Chrome is so hard to hack, and many other things.

...

Miller repeated his claim that Mac OS X is easy to exploit. He makes a clear distinction between the browser and the underlying operating system, stating that for example while Firefox on Windows is very hard to crack, Firefox on Mac OS X is easy, because Mac OS X lacks all the anti-exploit features Windows has built-in. "The things that Windows do to make it harder [for an exploit to work], Macs don't do," Miller says, "Hacking into Macs is so much easier. You don't have to jump through hoops and deal with all the anti-exploit mitigations you'd find in Windows."

...

When it comes to Chrome, Miller is positive about the sandboxing technology in the browser, explaining that you need two bugs in order to create a Chrome exploit; a bug in the browser, and a bug that gets you past the sandboxing. "There are bugs in Chrome but they're very hard to exploit. I have a Chrome vulnerability right now but I don't know how to exploit it," he states, "It's really hard. They've got that sandbox model that's hard to get out of. With Chrome, it's a combination of things - you can't execute on the heap, the OS protections in Windows, and the Sandbox."
Miller on Mac OS X, Chrome, Firefox, Economics
sg.png
babybearbear
babybearbear's Avatar
Registered User


Join Date: Jan 2009
Posts: 3,288
Trade rep: 0 (0%)
Infractions: 0/0 (0)
babybearbear Mar 22nd, 09, 02:15 PM #5
Quote:
Originally Posted by -Zero- View Post
First of all, Internet Explorer has a sandbox as well. So it's completely wrong to say that Chrome's sandbox is an 'innovative new feature'.

Microsoft IE came out with that first.

But the problem is that IE's sandbox mode only works if UAC is on. And we do not know what OS they were using for the test, and neither do we know if UAC had been turned off as well. If they were using Windows XP, then of course IE would fall quickly since XP does not have UAC to trigger sandbox mode aka Protected Mode in IE.

But the fact that Safari fell first in seconds: now THAT's something to put the Apple fanboys in their place.
A LOT of people still using XP, that means IE sandbox is not working for LOTS OF PEOPLE?
sg.png
Bonn
Bonn's Avatar
Over the Cable


Join Date: Feb 2007
Location: West of Singapore
Posts: 1,949
Trade rep: 4 (100%)
Infractions: 0/0 (0)
Bonn Mar 22nd, 09, 02:23 PM #6
That's why better to use Chrome now. lols...
Cheong arh...Hoot dah....
sg.png
babybearbear
babybearbear's Avatar
Registered User


Join Date: Jan 2009
Posts: 3,288
Trade rep: 0 (0%)
Infractions: 0/0 (0)
babybearbear Mar 22nd, 09, 02:31 PM #7
Quote:
Originally Posted by Bonn View Post
That's why better to use Chrome now. lols...
I'm still waiting for the Mac version.
sg.png
lwj5 Slacking In Progress


Join Date: Dec 2006
Location: SG Duh
Posts: 4,326
Trade rep: 0 (0%)
Infractions: 0/0 (0)
lwj5 Mar 22nd, 09, 09:29 PM #8
smart guy bout the econs part
__________________Com Specs__________________________________________________Gadgets / ETCs__________________
Gigabyte GA-965P-DQ6 Mobo ---------------------------------------------------------------------------------------------------------------- PS2
CPU C2D E6600 @ 2.88GHz ------------------------------------------------------------------------------------------------------------------- Nitendo Wii
MSI 7900GTO 512MB GDDR3
2 X 1GB Geil Ultra Ram PC2-6400/800MHz 4-4-4-12 @ 2.13V (Dual Channel)
500GB Seagate SATAII HDD 16MB
Seventeam ST-460EAG-05F 460W PSU
Leadtek PCI DTV2000-H TV/FM Tuner
Sonic Gear EVO 550KFX

sg.png
Soon
Soon's Avatar
Pokemon Trainer


Join Date: Nov 2004
Location: Tampines
Posts: 7,275
Trade rep: 47 (100%)
Infractions: 0/0 (0)
Soon Mar 22nd, 09, 10:04 PM #9
When I see Chrome, my first impression was VIA S3 Chrome... -__-
Anyway, sure or not...? Were the security researchers from google? lolx
sg.png
Thread Tools Display Modes
Linear Mode Linear Mode