{"id":37054,"date":"2019-10-31T22:15:30","date_gmt":"2019-10-31T19:15:30","guid":{"rendered":"https:\/\/prohoster.info\/blog\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti\/"},"modified":"2019-10-31T22:15:30","modified_gmt":"2019-10-31T19:15:30","slug":"pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti","title":{"rendered":"Pwnie Awards 2019: The Most Significant Vulnerabilities and Security Failures","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>At the recent Black Hat USA conference in Las Vegas <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnies.com\/\">took place<\/a><\/noindex> the awards ceremony <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnies.com\">Pwnie Awards 2019<\/a><\/noindex>, during which the most notable vulnerabilities and absurd failures in the field of computer security were highlighted. The Pwnie Awards are considered the equivalent of the Oscars and the Golden Raspberries in the field of computer security and have been held annually since 2007. <\/p>\n<p>Key <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnies.com\/winners\/\">Winners<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnies.com\/nominations\">nominations<\/a><\/noindex>: <\/p>\n<ul>\n<li class=\"l\"> <b>Best Server Error<\/b>. Awarded for identifying and exploiting the most technically complex and interesting error in a network service. Winners include researchers who  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.blackhat.com\/us-19\/briefings\/schedule\/#infiltrating-corporate-intranet-like-nsa---pre-auth-rce-on-leading-ssl-vpns-15545\">discovered<\/a><\/noindex> a vulnerability in the VPN provider Pulse Secure, whose VPN service is used by Twitter, Uber, Microsoft, SLA, SpaceX, Akamai, Intel, IBM, VMware, the U.S. Navy, and the Department of Homeland Security (DHS), as well as probably half of the Fortune 500 companies. Researchers found a backdoor that allows an unauthenticated attacker to change any user's password. They demonstrated the ability to exploit this issue to gain root access to the VPN server, which only has the HTTPS port open;\n<p>Notable non-winning candidates include: <\/p>\n<ul>\n<li class=\"l\"> An exploit found pre-authentication <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/orangetw\/awesome-jenkins-rce-2019\">vulnerability<\/a><\/noindex> in the Jenkins continuous integration system, allowing code execution on the server. This vulnerability is actively used by bots to conduct cryptocurrency mining on servers;\n<li class=\"l\"> A critical <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50819\">vulnerability<\/a><\/noindex> vulnerability in the Exim mail server, allowing code execution on the server with root privileges;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/sec-consult.com\/en\/blog\/2018\/10\/millions-of-xiongmai-video-surveillance-devices-can-be-hacked-via-cloud-feature-xmeye-p2p-cloud\/\">Vulnerabilities<\/a><\/noindex> in Xiongmai XMeye P2P IP cameras, allowing full control of the device. The cameras were shipped with an engineering password and did not use digital signature verification during firmware updates;\n<li class=\"l\"> A critical <noindex><a rel=\"nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0708\">vulnerability<\/a><\/noindex> in the implementation of the RDP protocol in Windows, allowing remote code execution;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50177\">The vulnerability<\/a><\/noindex> in WordPress, related to uploading PHP code disguised as an image. This issue allows arbitrary code execution on the server with publisher (Author) privileges;\n<\/ul>\n<li class=\"l\"> <b>Best Client Software Error<\/b>. The winner is a trivially exploitable vulnerability <noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-6223\">vulnerability<\/a><\/noindex> in Apple's FaceTime group calling system, which allows the group call initiator to forcibly accept a call on the recipient's side (for example, for eavesdropping).\n<p>The following were also nominated for the award: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50679\">The vulnerability<\/a><\/noindex> in WhatsApp, allowing for code execution via a specially crafted voice call;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id=899689\">The vulnerability<\/a><\/noindex> in the Skia graphics library used in the Chrome browser, which can lead to memory corruption due to floating-point operation errors during certain geometric transformations;\n<\/ul>\n<li class=\"l\"> <b>The best vulnerability leading to privilege escalation<\/b>. The award is given for the discovery of <noindex><a rel=\"nofollow\" href=\"https:\/\/googleprojectzero.blogspot.com\/2019\/01\/voucherswap-exploiting-mig-reference.html\">a vulnerability<\/a><\/noindex> in the iOS kernel, which can be exploited through ipc_voucher, accessible via the Safari browser.\n<p>The following were also nominated for the award: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0859\">The vulnerability<\/a><\/noindex> in Windows, allowing full system control through manipulation of the CreateWindowEx function (win32k.sys). The issue was identified during the analysis of malware that exploited the vulnerability before it was patched;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50130\">The vulnerability<\/a><\/noindex> in runc and LXC, affecting Docker and other container isolation systems, enabling an attacker-controlled isolated container to modify the runc executable and gain root privileges on the host system;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.zecops.com\/vulnerabilities\/exploit-of-cve-2019-7286\/\">The vulnerability<\/a><\/noindex> in iOS (CFPrefsDaemon), allowing bypassing of isolation modes and execution of code with root privileges;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-9568\">The vulnerability<\/a><\/noindex> in the Linux TCP stack used in Android, allowing local users to elevate their privileges on the device;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49931\">Vulnerabilities<\/a><\/noindex> in systemd-journald, allowing root access;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/usn.ubuntu.com\/4077-1\/\">The vulnerability<\/a><\/noindex> in the tmpreaper utility for cleaning \/tmp, enabling a user to retain their file in any part of the filesystem;\n<\/ul>\n<li class=\"l\"> <b>The best cryptographic attack<\/b>. Awarded for the discovery of the most significant vulnerabilities in real systems, protocols, and encryption algorithms. The award is given for the discovery of <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50493\">vulnerabilities<\/a><\/noindex> in the WPA3 wireless network protection technology and in EAP-pwd, allowing for the reconstruction of the connection password and access to the wireless network without knowledge of the password.\n<p>Other nominees for the award included: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=48597\">Element.getAnimations()<\/a><\/noindex> attacks on PGP and S\/MIME encryption in email clients;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.f-secure.com\/cold-boot-attacks\/\">The use of<\/a><\/noindex> the cold boot method to gain access to the contents of encrypted Bitlocker partitions;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50213\">The vulnerability<\/a><\/noindex> in OpenSSL, allowing for differentiation between situations where incorrect padding and incorrect MAC are obtained. The issue arises from improper handling of zero bytes in padding oracle;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/sec-consult.com\/en\/blog\/2018\/11\/my-name-is-johann-wolfgang-von-goethe-i-can-prove-it\/\">Issues<\/a><\/noindex> with identification cards used in Germany, utilizing SAML;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.chromium.org\/chromium-os\/u2f-ecdsa-vulnerability\">The Problem<\/a><\/noindex> with random number entropy in the implementation supporting U2F tokens in ChromeOS;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/monocypher.org\/quality-assurance\/disclosures\">The vulnerability<\/a><\/noindex> In Monocypher, which recognized valid zero EdDSA signatures.\n<\/ul>\n<li class=\"l\"> <b>The most innovative research.<\/b>  The award was given to the developer of the technique <noindex><a rel=\"nofollow\" href=\"https:\/\/gamozolabs.github.io\/fuzzing\/2018\/10\/14\/vectorized_emulation.html\">Vectorized Emulation<\/a><\/noindex>, using AVX-512 vector instructions to emulate program execution, allowing for a significant increase in fuzz testing speed (up to 40-120 billion instructions per second). This technique enables 8 64-bit or 16 32-bit virtual machines to run in parallel on each CPU core with instructions for application fuzz testing.\n<p>The following were nominated for the award: <\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mimecast.com\/blog\/2019\/06\/exploit-using-microsoft-excel-power-query-for-remote-dde-execution-discovered\/\">The vulnerability<\/a><\/noindex> in Power Query technology from MS Excel, which organizes code execution and circumvents application isolation methods when opening specially formatted spreadsheets;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50446\">Element.getAnimations()<\/a><\/noindex> tricking the autopilot of Tesla cars to provoke them into oncoming traffic;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/sec-consult.com\/en\/blog\/2019\/02\/reverse-engineering-architecture-pinout-plc\/\">Work<\/a><\/noindex> on reverse engineering the Siemens S7-1200 ASIC chip;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/arxiv.org\/abs\/1808.10250\">SonarSnoop<\/a><\/noindex> \u2014 Finger movement tracking technology for unlocking phone codes, based on sonar principles \u2014 the smartphone's top and bottom speakers generate inaudible vibrations, while built-in microphones capture them to analyze the presence of reflected vibrations from the hand;\n<li class=\"l\"> \t<noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50260\">Development<\/a><\/noindex> in the NSA's reverse engineering toolkit Ghidra;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@massarelli\/safe-self-attentive-function-embedding-d80abbfea794\">SAFE<\/a><\/noindex> \u2014 Technique for determining the use of identical function codes across multiple executable files based on binary assembly analysis;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/vulmon.com\/vulnerabilitydetails?qid=CVE-2019-11098&#038;scoretype=cvssv2\">Creating<\/a><\/noindex> a method to bypass the Intel Boot Guard mechanism to load modified UEFI firmwares without signature verification.\n<\/ul>\n<li class=\"l\"> <b>The lamest vendor response<\/b> (Lamest Vendor Response). A nomination for the most inadequate reaction to a report of a vulnerability in their own product. The winners were the developers of the BitFi crypto wallet, who loudly claimed the extreme security of their product, which turned out to be illusory, harassing researchers identifying vulnerabilities and failing to pay the promised bounties for revealing issues;\n<p>Among the candidates for the award were also considered: <\/p>\n<ul>\n<li class=\"l\"> A security researcher accused the director of Atrient of assault in order to force him to delete the report on a vulnerability he had identified, but the director denies the incident and security cameras did not record this assault;\n<li class=\"l\"> The Zoom company delayed fixing a critical <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/bugbountywriteup\/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5\">a vulnerability<\/a><\/noindex> in its conferencing system and only fixed the issue after public exposure. The vulnerability allowed an external attacker to access data from web cameras of macOS users when opening a specially crafted page in the browser (Zoom launched an HTTP server on the client-side, accepting commands from a local application).\n<li class=\"l\"> The inability to fix for more than 10 years <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51006\">the issue<\/a><\/noindex> with OpenPGP cryptographic key servers, justifying that the code is written in a specific OCaml language and remains without support.\n<\/ul>\n<p><b>The most inflated announcement of a vulnerability<\/b>. Awarded for the most pompous and grandiose coverage of an issue on the internet and in the media, especially if the vulnerability turns out to be practically exploitable. The award was given to Bloomberg for <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49393\">the statement<\/a><\/noindex> about the identification of spy chips on Super Micro boards, which was not confirmed, and the source indicated completely <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49417\">different information<\/a><\/noindex>.<\/p>\n<p>The nominations mention: <\/p>\n<ul>\n<li class=\"l\"> A vulnerability in libssh, which <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49453\">affected<\/a><\/noindex> individual server applications (libssh is hardly used for servers), but was presented by NCC Group as a vulnerability allowing attacks on any OpenSSH server.\n<li class=\"l\"> An attack using DICOM images. The essence is that one can prepare an executable file for Windows that looks like a valid DICOM image. This file can be uploaded to a medical device and executed.\n<li class=\"l\"> The vulnerability <noindex><a rel=\"nofollow\" href=\"https:\/\/thrangrycat.com\/\">Thrangrycat<\/a><\/noindex>, allowing bypassing the secure boot mechanism on Cisco devices. The vulnerability is categorized as inflated issues since it requires root privileges for the attack, but if the attacker has already gained root access, what security can be discussed? The vulnerability simultaneously won in the category of the most underrated issues, as it allows the injection of a permanent backdoor into Flash;\n<\/ul>\n<li class=\"l\"> <b>The biggest fail<\/b> (Most Epic FAIL). The award goes to Bloomberg for a series of sensational articles with eye-catching headlines, fabricated facts, withholding sources, spiraling into conspiracy theories, using terms like \u201ccyber weapon,\u201d and inappropriate generalizations. Other nominees include:\n<ul>\n<li class=\"l\"> The Shadowhammer attack on the firmware update service of Asus;\n<li class=\"l\"> The hack of the BitFi wallet, marketed as \u201cunhackable\u201d;\n<li class=\"l\"> Data leaks and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49366\">access tokens<\/a><\/noindex> in Facebook.\n<\/ul>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51267\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0430 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0435\u0439 \u0432 \u041b\u0430\u0441 \u0412\u0435\u0433\u0430\u0441\u0435 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Black Hat USA \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0430\u0441\u044c \u0446\u0435\u0440\u0435\u043c\u043e\u043d\u0438\u044f \u0432\u0440\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u043c\u0438\u0438 Pwnie Awards 2019, \u0432 \u0440\u0430\u043c\u043a\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u044b \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u0430\u0431\u0441\u0443\u0440\u0434\u043d\u044b\u0435 \u043f\u0440\u043e\u0432\u0430\u043b\u044b \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. Pwnie Awards \u0441\u0447\u0438\u0442\u0430\u0435\u0442\u0441\u044f \u0430\u043d\u0430\u043b\u043e\u0433\u043e\u043c \u041e\u0441\u043a\u0430\u0440\u0430 \u0438 \u0417\u043e\u043b\u043e\u0442\u043e\u0439 \u043c\u0430\u043b\u0438\u043d\u044b \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438 \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u0442\u0441\u044f \u0435\u0436\u0435\u0433\u043e\u0434\u043d\u043e, \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 2007 \u0433\u043e\u0434\u0430. \u041e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u043f\u043e\u0431\u0435\u0434\u0438\u0442\u0435\u043b\u0438 \u0438 \u043d\u043e\u043c\u0438\u043d\u0430\u0446\u0438\u0438: \u041b\u0443\u0447\u0448\u0430\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u0430\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37054","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0430 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0435\u0439 \u0432 \u041b\u0430\u0441 \u0412\u0435\u0433\u0430\u0441\u0435 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Black Hat USA \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0430\u0441\u044c \u0446\u0435\u0440\u0435\u043c\u043e\u043d\u0438\u044f \u0432\u0440\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u043c\u0438\u0438 Pwnie.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Pwnie Awards 2019: \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043f\u0440\u043e\u0432\u0430\u043b\u044b \u0432 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0430 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0435\u0439 \u0432 \u041b\u0430\u0441 \u0412\u0435\u0433\u0430\u0441\u0435 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Black Hat USA \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0430\u0441\u044c \u0446\u0435\u0440\u0435\u043c\u043e\u043d\u0438\u044f \u0432\u0440\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u043c\u0438\u0438 Pwnie.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:15:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:15:30+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Pwnie Awards 2019: Major vulnerabilities and security failures | ProHoster","description":"At the recently held Black Hat USA conference in Las Vegas, the Pwnie Awards ceremony took place.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Pwnie Awards 2019: \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043f\u0440\u043e\u0432\u0430\u043b\u044b \u0432 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 | ProHoster","og:description":"\u041d\u0430 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0435\u0439 \u0432 \u041b\u0430\u0441 \u0412\u0435\u0433\u0430\u0441\u0435 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Black Hat USA \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0430\u0441\u044c \u0446\u0435\u0440\u0435\u043c\u043e\u043d\u0438\u044f \u0432\u0440\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u043c\u0438\u0438 Pwnie.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/pwnie-awards-2019-naibolee-sushhestvennye-uyazvimosti-i-provaly-v-bezopasnosti","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:15:30+00:00","article:modified_time":"2019-10-31T19:15:30+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37054","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 05:53:22","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:34:24","updated":"2026-01-22 05:53:22","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=37054"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37054\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=37054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=37054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=37054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}