Posts tagged as:

ie8

iPhone, Firefox, Safari, IE8 Pwned!

by Admin on March 25, 2010

Welcome back!

Google Buzz

The three day Pwn2Own contest at the CanSecWest security show is on.

And at the end of the day, 3 major browsers, Firefox, Safari and IE8 were successfully exploited.

Also a non-jailbroken iPhone was also hacked and its SMS database was stolen.

Vincenzo Iozzo and Ralf Philipp Weinmann redirected an iPhone to a web site they’d set up, crashing its browser and then stealing its entire SMS database (including some erased messages). It is possible, however, to set up a similar attack to work without crashing the browser, hackers claim, and set up different attack payloads. Iozzo and Weinmann won a $15,000 prize for successfully demonstrating the attack. Details about the attack will be released once Apple is notified and the security hole is patched.

A successful remote attack against a MacBook Pro running the latest version of Apple’s MacOS X was done by Charlie Miller – exploiting a unknown security vulnerability in the Safari browser to launch a remote shell and winning himself $10,000 plus the laptop for his work.

Peter Vreugdenhil managed to bypass Windows security features including Data Execution Prevention code via Internet Explorer 8 to take over a PC (running the latest patched version of Windows 7) – and again receiving $10,000 plus the hardware.

CNET provides all details of the hacks here.


Related Posts
Related Websites

{ 1 comment }

Microsoft Releases IE8, Improves Security

by Admin on March 19, 2009

Google Buzz

Microsoft plans to make its Internet Explorer 8 browser available on Thursday, along with a company-commissioned report claiming IE8 is more secure against malware than rival browsers from Mozilla and Google.

Users will be able to download IE8 in 25 languages at 12:00 noon Eastern Daylight Time on Thursday from Microsoft’s IE Web site and its online download center.

Microsoft has been preparing users for IE8 for a good year now, stressing performance improvements, better support for Internet technology standards, the addition of new features to help people keep track of most visited sites and favorite sources of information, and of course, security, as highlights of the new browser.

According to the report Microsoft released Thursday, based on research conducted by NSS Labs, IE8′s Release Candidate 1 was 69 percent effective at catching malware before it did damage to a user’s system. Mozilla Firefox 3.07 came in second with a 30 percent effectiveness rate, with Apple Safari’s 3 in third place with a 24-percent rate and Google’s Chrome 1.0.154 in fourth place with 16 percent effectiveness rate

NSS Labs said in the report that the data was collected from tests conducted in just over 12 days from Feb. 26 through March 10 in its labs in Austin, Texas. During the course of the test, the company said it monitored connectivity to ensure the browsers could access the live malware sites being tested, and performed 141 discrete tests. The margin of error of the tests was 3.76 percent, according to NSS Labs.

Amy Barzdukas, a senior director at Microsoft, acknowledged that it might be a conflict of interest for Microsoft to sponsor a report in which IE8 came out on top in terms of security. However, she encouraged people to “look closely at the results” before making a judgment call on the validity of the report.

IE8 will be included as part of the Windows 7 OS. However, for the first time since adding browser technology to its operating system, Microsoft will give users the ability to turn off IE8 as a feature in the system.


Related Posts
Related Websites

{ 0 comments }