Cov neeg npaj txoj haujlwm no (ZDI) Pwn2Own 2020, yog ib qho kev tshwm sim uas cov neeg koom nrog raug caw tuaj qhia txog cov txheej txheem ua haujlwm rau kev siv cov qhov tsis zoo uas tsis tau paub dua, yuav muaj nyob rau ntawm lub Peb Hlis 18 txog 20 ua ib feem ntawm lub rooj sib tham CanSecWest hauv Vancouver. Tag nrho cov khoom plig rau xyoo 2020 yuav tshaj $ 4 lab, tsis suav nrog Tesla Model 3 tshiab.
Ib yam li xyoo tas los, cov khoom plig tseem ceeb tshaj plaws yog muab rau kev hacking Tesla Model 3 cov ntaub ntawv systems. Qhov khoom plig siab tshaj plaws ntawm $ 500,000 yog rau kev tsim ib qho multi-layered exploit uas tso cai rau kev ua tiav code hla ntau lub tsheb subsystems (pib nkag mus los ntawm Wi-Fi, Bluetooth, lossis lub tuner, ua raws li kev siv qhov tsis muaj zog hauv infotainment subsystem thiab tau txais kev nkag mus tas li rau VCSEC, gateway, lossis Autopilot). Cov khoom plig ntxiv kuj tseem muab rau kev nkag mus rau hauv paus rau infotainment subsystem ($ 50000), kev tswj hwm ntawm CAN Bus ($ 100,000), thiab kev nkag mus rau hauv paus rau Autopilot ib puag ncig ($ 50,000), nce qhov nyiaj them siab tshaj plaws rau $ 700,000.
Cov khoom plig ntawm $ 250,000, $ 300,000, thiab $ 400,000 yog muab rau kev tsim ib qho kev siv tsis raug uas hla kev tiv thaiv ntawm ob lub subsystems. Kuj tseem muaj yim qhov khoom plig txij li $ 35,000 txog $ 200,000 rau kev tswj hwm lub tsheb npav CAN, tawm hauv malware ua haujlwm tom qab reboot, thiab tawm tsam lub modem, tuner, Wi-Fi, Bluetooth, infotainment system, Autopilot, thiab lub smartphone key function. Tag nrho cov khoom plig rau Tesla-related pawg yog $ 2,490,000.
Lwm cov kev xaiv tsa rau Pwn2Own 2020 suav nrog:
- Hacking Chrome, Firefox, Safari thiab Microsoft Edge browsers (ob qho tib si EDGEHTML-based thiab Chromium-based);
- Kev nyiag khoom ntawm cov txheej txheem virtualization Oracle VirtualBox, VMware Workstation, thiab Microsoft Hyper-V Client;
- Kev siv Microsoft Office thiab Adobe Reader;
- Microsoft hack Windows RDP;
- Tsim ib qho kev siv tsis raug rau kev nce qib ntawm txoj cai hauv zos Ubuntu и Windows.
Ib yam li xyoo tas los, cov kernel hacks tsis suav nrog hauv kev xaiv tsa khoom plig. Linux thiab feem ntau cov haujlwm qhib (nginx, OpenSSL, Apache httpd), qhov kev hacking uas nyob rau hauv xyoo dhau los tsuas yog txwv rau qhov kev ua qauv qhia ntawm 0-hnub qhov tsis muaj zog hauv lub kernel hauv 2017. Linux, tso cai rau tus neeg siv hauv zos kom tsa lawv cov cai hauv lub system. Txawm li cas los xij, qhov kev xaiv tsa rau kev tsa cov cai hauv zos tau raug xa rov qab mus rau Ubuntu.
Tau qhov twg los: opennet.ru
