ZDNet

July 20, 2012

Pwn2Own goes mobile: $200,000 prizes for iOS, Android, BlackBerry zero-day attack

Share

pwn2own_mobile
(This was the scene at the very first iPhone hack at the CanSecWest Pwn2Own contest in 2010 when Vicenzo Iozzo teamed up with Ralf Philipp Weinmann to pop Apple’s iPhone device).

Conference organizers at EuSecWest in Amsterdam are dangling $200,000 in cash prizes to security researchers who demonstrate zero-day attacks against the most widely deployed smart phones.

The cash bounty will form part of Mobile Pwn2Own 2012, a special edition of the hacker challenge that pits vulnerability finders and exploit writers against fully patched computers and smart phones.

[SEE: Pwn2Own 2010: iPhone hacked, SMS database hijacked ]

TippingPoint ZDI, which is sponsoring the contest along with ATT and BlackBerry, says the primary goal is to demonstrate the current security posture of the most prevalent mobile technologies in use today; including attacks on mobile web browsers, Near Field Communication (NFC), Short Message Service (SMS), and the cellular baseband.  

follow Ryan Naraine on twitter

The organizers plan to shell out a $100,000 prize for a successful hack of Cellular Baseband and $40,000 each for zero-day exploits against NFC and SMS.   For a mobile web browser hack, Pwn2Own will pay $20,000.

TippingPoint ZDI says each contestant will be allowed to select the device they wish to compromise during a pre-registration process. 

“The only requirement is that it be a current device and running the latest operating system.  The exact OS version, firmware and model numbers will be coordinated with the pre-registered researcher,” the company said. 

Some examples of devices include:

  • BlackBerry Bold 9930
  • Samsung Galaxy SIII
  • Nokia Lumia 900
  • Apple iPhone 4S

For an attack to be deemed successful, it must use a zero-day vulnerability and must require “little or no user interaction.”

To win the prize, hackers must also compromise or exfiltrate useful data from the phone.

“Any attack that can incur cost upon the owner of the device (such as silently calling long-distance numbers, eavesdropping on conversations, and so forth) is within scope,” the company explained.

A special RF isolation enclosure will be provided to facilitate hacks without breaking local laws. 

Mobile platforms have been a staple at previous Pwn2Own contests but, apart from a few hits on Apple’s iPhone and RIM’s BlackBerry, they have emerged mostly unscathed.

Article source: http://www.zdnet.com/pwn2own-goes-mobile-200000-prizes-for-ios-android-blackberry-zero-day-attack-7000001316/

Share





 
 

 
 

Smartphone App Wrap: Travel, TV, Google, and sports

Previous | Next Image 1 of 16 (Image: Google Hangouts) As the pleasant weather finally approaches, we start to think about travel, baseball, golf, music, and enjoying time with family and friends. This collection of apps cove...
by Geek Staff
0

 
 
 

Improve smartphone photos with native editing tools (gallery)

Previous | Next Image 1 of 26 Android: Viewing a photo, getting ready to edit Most people take photos with their smartphones and then share them on social networking sites or via email. I rarely see anyone print photos and th...
by Geek Staff
0

 
 
 

SEA mobile phone sales rise by 8 percent

Southeast Asian consumers are increasingly moving away from feature phones and on to smartphones, which is helping spur sales growth in this region. According to findings from GfK released Friday, the region’s overall mob...
by Geek Staff
0