Site icon WinCert

Firefox and Edge have been exploited at Pwn20wn

<p>Mozilla Firefox and Microsoft Edge web browsers were exploited several times at the Pwn20wn hacking contest&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3460" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;03&sol;hacking-2903156&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"426" &sol;><&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p>The first target was the Firefox browser on which the Fluoroacetate team has managed to exploit a JIT bug and running code at a system level&period; After that&comma; they have managed to take over the PC by pointing Firefox to a website running malicious content&period; For this breaking into the Firefox browser&comma; the Fluoroacetate team consisting of two researchers won a prize of &dollar;50&period;000&period;<&sol;p>&NewLine;<p>Fluoroacetate team was not the only one who managed to hack Firefox&period; Niklas Baumstak also managed to exploit a JIT bug combined with a logic bug to escape the browser&&num;8217&semi;s sandbox&period; Niklas managed to gain full system control using log-in rights&period; For his effort&comma; Niklas won &dollar;40&comma;000&period;<&sol;p>&NewLine;<p>The second target for the Fluoroacetate team at Pwn20wn was Microsoft Edge&period; They had to use a very complex way to exploit the Microsoft Edge browser&period; Using Microsoft Edge on VMWare Workstation client they have accessed their specially crafted web page where they have managed to run malicious code on the underlying hypervisor&period;<&sol;p>&NewLine;<p>For this exploit and efforts&comma; Cama and Zhu from the Fluoroacetate team have won a prize of &dollar;130&comma;000&period;<&sol;p>&NewLine;<p>Microsoft Edge was also exploited by Arthur Gerkis of Exodus Intelligence&period; He managed to exploit a double-free bug to escape Microsoft Edge&&num;8217&semi;s sandbox for what he claimed &dollar;50&comma;000&period;<&sol;p>&NewLine;

Exit mobile version