PDA

View Full Version : Pinkie Pie Earns $60K At Pwn2Own With Three Chromium 0-Day Exploits



wraggster
March 11th, 2012, 20:44
Hot on the hooves of Sergey Glazunov's (http://it.slashdot.org/story/12/03/07/2352220/chrome-hacked-in-5-minutes-at-pwn2own) hack 5-minutes into Pwn2Own, an image of an axe-wielding pink pony (http://arstechnica.com/business/news/2012/03/googles-chrome-browser-on-friday.ars) was the mark of success for a hacker with the handle of Pinkie Pie (http://www.zdnet.com/blog/security/teenager-hacks-google-chrome-with-three-0day-vulnerabilities/10649). Pinkie Pie subtly tweaked Chromium's sandbox design by chaining together three zero-day vulnerabilities (http://www.wired.com/threatlevel/2012/03/zero-days-for-chrome/), thereby widening his appeal to $60K in prize money, another shot at a job opportunity at the Googleplex, and instantly making Google's $1M Pwnium contest about 20% cooler (http://www.equestriadaily.com/2012/03/pinkie-pie-hacks-google.html). (Let the record show that Slashdot was six years (http://slashdot.org/story/06/03/31/1644225/slashdot-design-changes-for-wider-appeal) ahead of this particular curve (http://tech.slashdot.org/story/11/07/28/0124213/better-copyright-through-fair-use-and-ponies), and that April Fool's Day is less than a month away.)

http://tech.slashdot.org/story/12/03/11/0138248/pinkie-pie-earns-60k-at-pwn2own-with-three-chromium-0-day-exploits