Results 1 to 1 of 1
-
17th Aug 2011, 05:18 AM #1OPMember
BlackHat : The Pwnies 2011 Security Award Winners
Late news, but i didn't see this news at KWWH. Just share..
The award for the Best Server-Side Bug went to Juliano Rizzo, Thai Duong - Juliano and Thai showed that the ASP.NET framework is vulnerable to a padding oracle attack that can be used to remotely compromise almost any ASP.NET web application, often leading to remote code execution on the server.
The Pwnie for Best Client-Side Bug was awarded to Comex - Comex exploited a vulnerability in the interpreter for Type 1 font programs in the FreeType library used by MobileSafari. This exploit is a great example of programming a weird machine to exploit a modern system. Comex used his control over the interpreter to construct a highly sophisticated ROP payload at runtime and bypass the ASLR protection in iOS. Furthermore, the ROP payload exploited a kernel vulnerability to execute code in the kernel and disable code-signing. The exploit was hosted on jailbreakme.com and was successfully used by thousands of people to jailbreak their iOS devices.
The Best Privilege Escalation Bug went to Tarjei Mandt ? In the span of a few months, Tarjei found more than 40 vulnerabilities in the Windows kernel. In his presentation at Infiltrate 2011, he described the details of these vulnerabilities and his kernel exploitation techniques.
The Most Innovative Research Pwnie went to Piotr Bania - To implement some of the ideas from pax-future.txt is one thing, to implement them through static analysis on Windows, rewriting drivers automagically, and have it all work preserving binary compatibility across a wide range of Windows versions: that?s deserving of respect.
And finally the Lamest Vendor Response was awarded to RSA ? They got hacked, their SecurID tokens were totally compromised, and they basically passed it off as a non-event and advised customers that replacing the tokens is not necessary ? until Lockheed-Martin got attacked because of them.
News http://www.livehacking.com/2011/08/0...award-winners/
http://pwnies.com/winners/botnet Reviewed by botnet on . BlackHat : The Pwnies 2011 Security Award Winners The winners of this year's Pwnie Awards have been given out during the BlackHat USA security conference in Las Vegas. The annual awards ceremony celebrates the achievements and failures of security researchers and the security community. The award for the Best Server-Side Bug went to Juliano Rizzo, Thai Duong - Juliano and Thai showed that the ASP.NET framework is vulnerable to a padding oracle attack that can be used to remotely compromise almost any ASP.NET web application, often leading Rating: 5
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Multi domain giveaway ( 4 domains 4 winners )
By GeeZus in forum Contests & GiveawaysReplies: 55Last Post: 19th May 2012, 04:36 PM -
Is that a Hacking Attack? Kaspersky Internet Security (2011) notify me just
By Arthur in forum Webmaster DiscussionReplies: 0Last Post: 1st Dec 2010, 05:29 PM -
[Selling] SELLING KASPERSKY(Internet Security 2011) KEYS
By buzz in forum Completed TransactionsReplies: 5Last Post: 9th Nov 2010, 01:27 PM -
Hawk's contenst winners
By Mac in forum General DiscussionReplies: 26Last Post: 5th Nov 2010, 01:47 PM -
[Selling] Original License Norton Internet Security 2011 3pc 1year
By prasa in forum Completed TransactionsReplies: 3Last Post: 26th Oct 2010, 10:54 AM
themaCreator - create posts from...
Version 3.47 released. Open older version (or...