Chinese hacking competition cracks Chrome, ESXi, Windows 10, iOS 14, Galaxy 20, Qemu, and more
- Reference: 1604905872
- News link: https://www.theregister.co.uk/2020/11/09/tianfu_cup/
- Source link:
News of the crack came from [1]Tianfu Cup , a hacking contest staged in China over the weekend and modelled on events like "Pwn2Own" where vendors allow teams to take down their wares under controlled conditions.
The targets for the competition included the iPhone 11 running the new iOS 14, and the big four browsers – Chrome, Safari, Firefox and Edge. Cup organisers said 11 of the attacks succeeded.
Many mature and hard targets have been pwned on this year’s contest. 11 out of 16 targets cracked with 23 successful demos:
Chrome, Safari, FireFox
Adobe PDF Reader
Docker-CE, VMware EXSi, Qemu, CentOS 8
iPhone 11 Pro+iOS 14, GalaxyS20
Windows 10 2004
TP-Link, ASUS Router
👍 — TianfuCup (@TianfuCup) [2]November 8, 2020
And that's a little scary because the challenge for ESXi, Qemu and Docker was to get control of the host OS.
The good news is that details of the cracks have not been released. So while VMware has [3]admitted to the crack , it should be able to get its patch done before the it is exploited.
If it gets the patch right: the company last week [4]updated a patch for a critical-rated flaw that allowed a malicious actor residing in the management network who has access to port 427 on an ESXi machine to conduct remote code execution. The first patch did not fix the problem and has been suggested as the cause of a [5]Brazilian ransomware attack .
Other vendors and projects whose code was cracked at the competition appear not to have publicly acknowledged the issue at the time of writing. ®
Get our [6]Tech Resources
[1] http://www.tianfucup.com/
[2] https://twitter.com/TianfuCup/status/1325340353184952321?ref_src=twsrc%5Etfw
[3] https://blogs.vmware.com/security/2020/11/vmware-and-tianfu-cup-2020.html
[4] https://www.vmware.com/security/advisories/VMSA-2020-0023.html
[5] https://www.theregister.com/2020/11/06/brazil_court_ransomware/
[6] https://whitepapers.theregister.com/
Re: They did all that over a weekend for a competition
Usually they have stuff prepared and just need to modify it for the current setup. Or have to rethink if a security hole they previously found was patched in the latest version or altered what they were planning.
They targetted Chrome, Safari, Firefox and Edge
and managed to crack Chrome, Safari and Firefox.
Re: They targetted Chrome, Safari, Firefox and Edge
You do know that Edge is based on Chrome, right? Chromium, to be exact, but let's not get pedantic.
Not all systems break-ins/breakdowns are without greater benefits for .....
...... some core programs are kernel corrupted.
As has been mentioned before here on El Reg, and not so long ago and quite recently*, some vulnerabilities cannot be “fixed” ..... they are important systemic opportunities/abiding future relevant features best embraced and extended and modified, for extinction is neither possible nor adorable and attractive.
* 2020 Thursday 5 November 07:48 ..... [1]Something to bear in mind .....
[1] https://forums.theregister.com/forum/all/2020/11/03/google_project_zero_github_flaw_deadline/#c_4139776
The good news is that details of the cracks have not been released .
Really? Sure about that? We're talking about China's "best" hackers here.
They did all that over a weekend for a competition
What can they do when they really put their mind to it?