News: 1604905872

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Chinese hacking competition cracks Chrome, ESXi, Windows 10, iOS 14, Galaxy 20, Qemu, and more

(2020/11/09)


VMware has taken the unusual step of warning about an imminent security advisory after a Chinese team successfully popped its flagship product.

News of the crack came from [1]Tianfu Cup , a hacking contest staged in China over the weekend and modelled on events like "Pwn2Own" where vendors allow teams to take down their wares under controlled conditions.

The targets for the competition included the iPhone 11 running the new iOS 14, and the big four browsers – Chrome, Safari, Firefox and Edge. Cup organisers said 11 of the attacks succeeded.

Many mature and hard targets have been pwned on this year’s contest. 11 out of 16 targets cracked with 23 successful demos:

Chrome, Safari, FireFox

Adobe PDF Reader

Docker-CE, VMware EXSi, Qemu, CentOS 8

iPhone 11 Pro+iOS 14, GalaxyS20

Windows 10 2004

TP-Link, ASUS Router

👍 — TianfuCup (@TianfuCup) [2]November 8, 2020

And that's a little scary because the challenge for ESXi, Qemu and Docker was to get control of the host OS.

The good news is that details of the cracks have not been released. So while VMware has [3]admitted to the crack , it should be able to get its patch done before the it is exploited.

If it gets the patch right: the company last week [4]updated a patch for a critical-rated flaw that allowed a malicious actor residing in the management network who has access to port 427 on an ESXi machine to conduct remote code execution. The first patch did not fix the problem and has been suggested as the cause of a [5]Brazilian ransomware attack .

Other vendors and projects whose code was cracked at the competition appear not to have publicly acknowledged the issue at the time of writing. ®

Get our [6]Tech Resources



[1] http://www.tianfucup.com/

[2] https://twitter.com/TianfuCup/status/1325340353184952321?ref_src=twsrc%5Etfw

[3] https://blogs.vmware.com/security/2020/11/vmware-and-tianfu-cup-2020.html

[4] https://www.vmware.com/security/advisories/VMSA-2020-0023.html

[5] https://www.theregister.com/2020/11/06/brazil_court_ransomware/

[6] https://whitepapers.theregister.com/

They did all that over a weekend for a competition

tip pc

What can they do when they really put their mind to it?

Re: They did all that over a weekend for a competition

Anonymous Coward

Usually they have stuff prepared and just need to modify it for the current setup. Or have to rethink if a security hole they previously found was patched in the latest version or altered what they were planning.

They targetted Chrome, Safari, Firefox and Edge

Anonymous Coward

and managed to crack Chrome, Safari and Firefox.

Re: They targetted Chrome, Safari, Firefox and Edge

Alumoi

You do know that Edge is based on Chrome, right? Chromium, to be exact, but let's not get pedantic.

Not all systems break-ins/breakdowns are without greater benefits for .....

amanfromMars 1

...... some core programs are kernel corrupted.

As has been mentioned before here on El Reg, and not so long ago and quite recently*, some vulnerabilities cannot be “fixed” ..... they are important systemic opportunities/abiding future relevant features best embraced and extended and modified, for extinction is neither possible nor adorable and attractive.

* 2020 Thursday 5 November 07:48 ..... [1]Something to bear in mind .....

[1] https://forums.theregister.com/forum/all/2020/11/03/google_project_zero_github_flaw_deadline/#c_4139776

sanmigueelbeer

The good news is that details of the cracks have not been released .

Really? Sure about that? We're talking about China's "best" hackers here.

Take me drunk, I'm home again!