Google Search

Showing posts with label prize. Show all posts
Showing posts with label prize. Show all posts

Sunday, January 6, 2013

SophosLabs wins coveted Swiss prize

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tareq from SophosLabs Vancouver eating the TobleroneUnfortunately we were passed over by the Nobel Assembly for a prize from their esteemed foundation again this year, but the Swiss weren't so shortsighted.

Adrian Leuenberger from SWITCH-CERT in Switzerland presented a last minute talk titled "Cleaning up the net 2.0 - a success story of cleaning 3,000+ websites" at this year's Virus Bulletin conference in Dallas, Texas.

SWITCH-CERT is the domain registrar for the .ch (Switzerland) and .li (Liechtenstein) top-level domains (TLDs) and recently gained the authority to try to notify and help clean websites within these TLDs.

Adrian shared his processes and procedures for detecting, notifying and remediating affected web sites and talked about how they were able to clean more than 1,000 malicious sites between January and July of 2012.

SWITCH worked together with OFCOM, the Swiss Federal Office of Communications, to implement a process where they are allowed to take domains offline for sites spreading malicious content or hosting phishing sites until they are clean.

Adrian made a plea to the Virus Bulletin audience with a promise... He would send a 4.5 kg (9.92 lb), 80 cm (2.5 ft) long Toblerone chocolate bar to the research lab that could submit the largest list of infected .ch and .li domains.

One of our Vancouver researchers, Onur Komili, heard about the contest from a colleague and being a sucker for chocolate mined our databases for information to provide to SWITCH-CERT.

In the end, we won! To quote Adrian "I can happily announce that Sophos delivered by far the largest list of potentially malicious URLs."

The picture at the top of this post is Tareq Alkhatib enjoying the spoils, while below you can see Onur pondering the how to go about opening a 4.5 kg chocolate bar.

Onur opening up the jumbo Toblerone

I would like to say congratulations to SophosLabs!

We are proud to help the Swiss make their domain space a little bit safer and hope their experiment can be a model for cleaning up the web in other countries.

Thank you to Andrew Ludgate in SophosLabs Vancouver for sharing the photos.

Follow @chetwisniewski

View the original article here

Wednesday, September 5, 2012

Google announces Pwnium 2, raises prize money for Chrome hack to $2m

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

In March this year we wrote about Pwnium, Google's "hack the Chrome browser for money" competition run at the CanSecWest conference.

Two winners took home $60,000 each after crafting devious, multi-stage attacks against the Mountain View browser.

The competition is back, with Pwnium 2 set to take place at the 2012 Hack in the Box conference in Kuala Lumpur, Malaysia.

If you fancy a prize, you've got just under two months to get your exploit ducks in a row - not a terribly long time, if the complexity of the previous winning entries is anything to go by.

There are a few changes from March.

The prize money goes up from $1m to $2m - perhaps a bit of a media stunt by Google, since last time only 12% of the prize money was actually claimed.

The prize categories are adjusted from $20k-$40k-$60k for low-medium-full exploits to $40k-$50k-$60k. As Google explains:

[W]e've compressed the reward levels closer together for Pwnium 2. This is in response to feedback, and reflects that any local account compromise is very serious. We're happy to make the web safer by any means - even rewarding vulnerabilities outside of our immediate control.

The final prize change is that instead of presenting every winner with a Chromebook, Google will present the writer of the best exploit with the Acer laptop used as the standard test platform during the competition.

(That's doesn't seem like much of an endorsement for Google's Chromebook devices - dedicated netbook-type computers that aren't an awful lot more than a walled-off browser lashed to Google's cloud apps. Can't even give the jolly things away.)

What I've referred to as low, by the way, means an exploit that relies entirely on vulnerabilities outside Chrome itself; medium means that some non-Chrome bugs were combined with a Chrome flaw; and full means that only bugs in Chrome were exploited. You need to achieve what Google calls "Win7 local OS user account persistence" for your attack to qualify as an exploit.

Local OS means you're running as a regular application, so you've escaped the limitations of running inside the browser; persistence means you'll keep running even after the browser exits and the computer is rebooted; and user account means you don't need to get all the way to administrator privilege.

Loosely speaking, that means your exploit would be perfect for a drive-by malware attack that would leave the computer infected inconspicuously and indefinitely.

Your exploit, of course, needs to be what is known as zero-day - Chrome and the surrounding OS will be fully patched when the competition opens.

Note to Mac users. Malware with admin privilege can, indeed, do a lot more damage than user-level malware. But even malware running with regular user privileges can be perfectly harmful, on OS X as well as on Windows. The notion that "malware which doesn't prompt for the admin password isn't really malware" is still prevalent amongst Mac fans, and it's a myth. Software which runs as you has the power to do anything you could do yourself, including downloading and running yet more malware; reading and writing files; uploading data to web servers; posting to social networks; and emailing your very own ill-tempered letter of resignation to the Chairman of the Board.

Follow @duckblog
-


View the original article here