This Pwn2Own didn't test Linux because their goal was to gun after common Desktop platforms. ie: Windows and Mac.
They went after browsers, as that is the most common point of entry.
Still, if any Windows fanatic rants about how awesome DEP and ASLR will protect them; think again!
This contest has proven that Win7 (64bit) with all the latest patches, using either Firefox or IE8; one should NOT rely on DEP/ASLR...And that's on Day 1!
The contest lasts for 3 days. Safari (using OSX), IE8, and Firefox has fallen. Chrome is only left.
Quote: "The winning exploits become intellectual property of the company hosting CanSecWest hence Miller is not allowed to disclose to the public what they are exactly other than the technique used."
This is correct only as it relates to the 'WINNING EXPLOITS.' The others that Mr. Miller has found and decided not to exploit in the competition are owned by him (or anyone else who can find them). He can reveal them publically or keep them to himself (or sell them if he's smart).
He's only required to stay 'mum' on the ones he's used in the competition until the vendors can patch their crappy software. Seems like everyone has taken a hit so most of them will be very busy.
Apple are too busy marketing their iPad to patch anything so maybe it's a good time to work on some hacks for their equipment.
The winning exploits become intellectual property of the company hosting CanSecWest hence Miller is not allowed to disclose to the public what they are exactly other than the technique used.
Instead of releasing the exploit code to the public, keep it locked away. I think people should stump up money for him to get a 30 second ad during a nightly news program and show all of the computers melting down and put the companies on the spot. Doesn't violate any laws and gets their attention just the same.
This Pwn2Own didn't test Linux because their goal was to gun after common Desktop platforms. ie: Windows and Mac.
They went after browsers, as that is the most common point of entry.
Still, if any Windows fanatic rants about how awesome DEP and ASLR will protect them; think again!
This contest has proven that Win7 (64bit) with all the latest patches, using either Firefox or IE8; one should NOT rely on DEP/ASLR...And that's on Day 1!
The contest lasts for 3 days. Safari (using OSX), IE8, and Firefox has fallen. Chrome is only left.
Quote: "The winning exploits become intellectual property of the company hosting CanSecWest hence Miller is not allowed to disclose to the public what they are exactly other than the technique used."
This is correct only as it relates to the 'WINNING EXPLOITS.' The others that Mr. Miller has found and decided not to exploit in the competition are owned by him (or anyone else who can find them). He can reveal them publically or keep them to himself (or sell them if he's smart).
He's only required to stay 'mum' on the ones he's used in the competition until the vendors can patch their crappy software. Seems like everyone has taken a hit so most of them will be very busy.
Apple are too busy marketing their iPad to patch anything so maybe it's a good time to work on some hacks for their equipment.
Rock on Google Chrome!
As far as I can see no Linux desktop has been breached?
The winning exploits become intellectual property of the company hosting CanSecWest hence Miller is not allowed to disclose to the public what they are exactly other than the technique used.
Instead of releasing the exploit code to the public, keep it locked away. I think people should stump up money for him to get a 30 second ad during a nightly news program and show all of the computers melting down and put the companies on the spot. Doesn't violate any laws and gets their attention just the same.