ie9 cracked in hacking contest
Last Updated : GMT 09:07:40
Egypt Today, egypt today
Egypt Today, egypt today
Last Updated : GMT 09:07:40
Egypt Today, egypt today

IE9 cracked in hacking contest

Egypt Today, egypt today

Egypt Today, egypt today IE9 cracked in hacking contest

Paris - Arabstoday

Internet Explorer 9 was hacked during day two of the annual Pwn2Own hacking contest held at the CanSecWest security conference in Vancouver. On March 8, researchers from the French security firm Vupen exploited two bugs, an unpatched heap overflow flaw and a memory-corruption vulnerability, to crack Microsoft's IE9 Web browser and run code outside the sandbox, the security feature in place to contain bugs and prevent malicious code from executing on the user's system. On Wednesday, Vupen kicked off the Pwn2Own festivities by hacking the Google Chrome browser. It was the first time a research team has hacked Chrome during the annual contest. "It was difficult because the heap overflow vulnerabilities are not very common," Vupen's CEO and chairman, Chaouki Bekrar, told SecurityNewsDaily of the IE 9 hack. "They [the flaws] are rare but they are useful, because you can use the same vulnerability to achieve memory leak and thus bypass ASLR." (Address Space Layout Randomization , or ASLR, is a security protocol for randomly arranging data areas in a process' address space.) Bekrar added, "Usually we need three vulnerabilities, one for DEP [Data Execution Prevention], one for ASLR, and one for the sandbox. Here we had one that allowed us to do DEP and ASLR, which is nice." The attack required the researchers to navigate to a rigged website, where they demonstrated their exploit by making a calculator app show up on the target system. We used only a specially crafted Web page," Bekrar said. "There was no user interaction, no downloading, no pop-ups, no message box to accept. It was a 'visit and get pwned' exploit." Bekrar said the code execution attack also works on old versions like IE6 and the new Internet Explorer version 10, which is only available for consumer preview. Vupen researchers performed their proof-of-concept hack on a fully-patched Windows 7 Service Pack 1 machine. It took the team seven weeks to craft the IE 9 exploit.

egypttoday
egypttoday

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

ie9 cracked in hacking contest ie9 cracked in hacking contest



GMT 08:02 2015 Tuesday ,15 September

No snow: Californian water source at 500-year low

GMT 15:25 2018 Wednesday ,14 November

Friedrich Merz vows to steal half of AfD voters

GMT 06:53 2017 Saturday ,18 February

G20 foreign ministers vow to fight poverty in Africa

GMT 14:27 2017 Friday ,10 March

Hypercars mingle with station wagons

GMT 13:13 2011 Friday ,16 December

Hyundai i-oniq Concept for Geneva 2012

GMT 11:53 2011 Monday ,26 September

Guerrero: We’ve got Peruvians dreaming

GMT 18:17 2016 Sunday ,18 December

Iraqi warplanes bomb Daesh warehouses

GMT 16:54 2017 Sunday ,15 January

26 killed as Hadi forces push Houthis back

GMT 04:29 2016 Saturday ,25 June

A New Generation of Robots is Ready for the Market

GMT 12:31 2011 Saturday ,26 November

Google working on OnLive rival for Chrome OS
 
 Egypt Today Facebook,egypt today facebook  Egypt Today Twitter,egypt today twitter Egypt Today Rss,egypt today rss  Egypt Today Youtube,egypt today youtube  Egypt Today Youtube,egypt today youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

egypttoday egypttoday egypttoday egypttoday
egypttoday egypttoday egypttoday
egypttoday
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
egypttoday, Egypttoday, Egypttoday