Hacks ntawm Ubuntu, Windows, macOS thiab VirtualBox tau tshwm sim ntawm Pwn2Own 2020 kev sib tw

Cia cia Cov txiaj ntsig ntawm ob hnub ntawm kev sib tw Pwn2Own 2020, tuav txhua xyoo raws li ib feem ntawm CanSecWest lub rooj sib tham. Xyoo no kev sib tw tau tuav zoo thiab kev tawm tsam tau tshwm sim hauv online. Cov kev sib tw tau nthuav tawm cov txheej txheem ua haujlwm rau kev siv cov kev tsis paub yav dhau los hauv Ubuntu Desktop (Linux kernel), Windows, macOS, Safari, VirtualBox thiab Adobe Reader. Tag nrho cov nyiaj them yog 270 txhiab daus las (tag nrho cov nqi zog yog ntau tshaj 4 lab US dollars).

  • Kev nce hauv cheeb tsam ntawm cov cai hauv Ubuntu Desktop los ntawm kev siv qhov muaj qhov tsis zoo hauv Linux ntsiav cuam tshuam nrog kev txheeb xyuas tsis raug ntawm cov nqi nkag (nqi $ 30);
  • Ua qauv qhia ntawm kev tawm ntawm cov qhua ib puag ncig hauv VirtualBox thiab ua tiav cov cai nrog hypervisor txoj cai, siv ob qhov tsis zoo - muaj peev xwm nyeem cov ntaub ntawv los ntawm thaj chaw sab nraud ntawm kev faib tsis tau thiab qhov ua yuam kev thaum ua haujlwm nrog cov kev hloov pauv tsis tsim nyog (ib qho khoom plig ntawm 40 txhiab nyiaj). Sab nraum qhov kev sib tw, cov neeg sawv cev ntawm Zero Day Initiative kuj ua rau pom lwm qhov VirtualBox hack, uas tso cai rau kev nkag mus rau tus tswv tsev los ntawm kev tswj hwm hauv ib puag ncig qhua;



  • Hacking Safari nrog cov cai nce siab rau macOS ntsiav qib thiab khiav lub tshuab xam zauv raws li hauv paus. Rau kev siv, ib txoj hlua ntawm 6 qhov yuam kev tau siv (nqi 70 txhiab daus las);
  • Ob qhov kev tawm tsam ntawm kev tsim cai hauv zos nce ntxiv hauv Windows los ntawm kev siv cov kev tsis zoo uas ua rau nkag mus rau thaj chaw nco tau tso tseg (ob qho khoom plig ntawm 40 txhiab daus las txhua);
  • Nkag mus rau tus thawj tswj hwm hauv Windows thaum qhib ib daim ntawv tsim tshwj xeeb PDF hauv Adobe Reader. Qhov kev tawm tsam cuam tshuam nrog qhov tsis zoo hauv Acrobat thiab Windows kernel ntsig txog kev nkag mus rau thaj chaw nco tau tso tseg (khoom plig ntawm $ 50).

Nominations rau hacking Chrome, Firefox, Edge, Microsoft Hyper-V Client, Microsoft Office thiab Microsoft Windows RDP tseem tsis tau lees paub. Ib qho kev sim ua rau hack VMware Workstation, tab sis nws ua tsis tiav.
Zoo li xyoo tas los, pawg khoom plig tsis suav nrog hacks ntawm feem ntau ntawm cov haujlwm qhib (nginx, OpenSSL, Apache httpd).

Cais, peb tuaj yeem nco ntsoov lub ntsiab lus ntawm kev nyiag cov ntaub ntawv ntawm Tesla lub tsheb. Tsis muaj kev sim hack Tesla ntawm kev sib tw, txawm tias qhov khoom plig siab tshaj ntawm $ 700 txhiab, tab sis nyias оявилась информация hais txog kev txheeb xyuas qhov tsis zoo ntawm DoS (CVE-2020-10558) hauv Tesla Model 3, uas tso cai rau, thaum qhib nplooj ntawv tsim tshwj xeeb hauv qhov browser built-in, txhawm rau kaw cov ntawv ceeb toom los ntawm autopilot thiab cuam tshuam kev ua haujlwm ntawm cov khoom xws li lub speedometer, browser, cua txias, navigation system, thiab lwm yam.

Tau qhov twg los: opennet.ru

Ntxiv ib saib