Ngā mahi tinihanga i whakaatuhia ki Pwn2Own 2020 Ubuntu, Windows, macOS me te PouakaMariko

Tukua iho Ko ngā hua o te whakataetae Pwn2Own 2020 e rua ngā rā te roa, i tū i ia tau hei wāhanga o te huihuinga CanSecWest. I tēnei tau, i tū te whakataetae mariko, ā, i whakaaturia ngā whakaekenga ki te ipurangi. I whakaatuhia e te whakataetae ngā tikanga mahi mō te whakamahi i ngā ngoikoretanga kāore i te mōhiotia i mua i roto i Ubuntu Papamahi (matua Linux), Windows, macOS, Safari, VirtualBox, me Adobe Reader. Ko te tapeke o te putea taonga he $270. ko neke atu i te 4 miriona taara).

  • Te Whakanuia o te Mana ā-Rohe i roto i Ubuntu Papamahi mā te whakamahi i te ngoikoretanga o te kernel Linux, e pā ana ki te whakamana hē o ngā uara whakauru (taonga: $30);
  • Whakaaturanga o te puta atu i te taiao manuhiri i VirtualBox me te whakamahi i te waehere me nga mana hypervisor, te whakamahi i nga whakaraeraetanga e rua - te kaha ki te panui i nga raraunga mai i tetahi waahi kei waho o te parepare kua tohatohahia me te hapa i te wa e mahi ana me nga taurangi koretake (he utu 40 mano taara). I waho atu o te whakataetae, i whakaatu ano hoki nga kanohi o te Zero Day Initiative i tetahi atu hack VirtualBox, e taea ai te uru atu ki te punaha manaaki ma te mamingatanga i te taiao manuhiri;


    Taata ataata

  • Te tinihanga i te whakanui ake i te mana o te kernel Safari macOS me te whakahaere i te tātaitai me ngā mana pakiaka. I whakamahia he mekameka o ngā pepeke e ono mō te whakamahi kino (taonga: $70,000);
  • E rua ngā whakaaturanga mō te whakanui ake i ngā mana ā-rohe i roto i Windows mā te whakamahi i ngā ngoikoretanga e arahi ana ki te urunga atu ki tētahi wāhi mahara kua wātea kē (e rua ngā taonga o te $40 ia taonga);
  • Te whiwhi urunga kaiwhakahaere i roto i Windows i te whakatuwheratanga o tētahi tuhinga PDF i hangaia mō te Adobe Reader. I whakamahia e te whakaeke ngā ngoikoretanga o Acrobat me te kernel. Windows, e pā ana ki te uru atu ki ngā wāhi mahara kua wātea kē (taonga: 50 mano tāra).

Kāore anō kia keremehia ngā whakaingoatanga mō te taumanutia o Chrome, Firefox, Edge, Microsoft Hyper-V Client, Microsoft Office me Microsoft. Windows RDP. I nganahia te taumanutia o te VMware Workstation, engari kāore i angitu.
Pērā i tērā tau, kāre ngā kāwai taonga i uru ki ngā hacks o te nuinga o ngā kaupapa puna tuwhera (nginx, OpenSSL, Apache httpd).

Ka wehea, ka taea e taatau te tuhi i te kaupapa o te hacking nga punaha korero o te motuka Tesla. Kaore he ngana ki te tarai i a Tesla i te whakataetae, ahakoa te utu nui o te $700 mano, engari wehe ke i puta nga korero mo te tautuhi i te whakaraeraetanga DoS (CVE-2020-10558) i roto i te Tesla Model 3, e taea ai, i te whakatuwheratanga i tetahi wharangi i hangaia i roto i te kaitirotiro hanga-i roto, ki te whakakore i nga whakamohiotanga mai i te autopilot me te whakararu i te mahi o nga waahanga penei i te te tere tere, te tirotiro, te hau, te punaha whakatere, aha atu.

Taata ataata

Source: opennet.ru

Hokona te manaaki pono mo nga waahi me te tiaki DDoS, nga kaiwhakarato VPS VDS 🔥 Hokona he manaaki paetukutuku pono me te tiakitanga DDoS, ngā tūmau VPS VDS | ProHoster