The first day of Pwn2Own 2015, the hacking competition held in Vancouver, Canada, offered big prizes to contestants and headaches to software makers: competing teams managed to successfully exploit fresh vulnerabilities in Adobe Flash and Reader, Microsoft Windows, Internet Explorer, and Mozilla Firefox.
The Pwn2Own competition, organized for eight consecutive years by HP's Zero Day Initiative (ZDI) and Google's Project Zero, attracts security researchers from all over the world. Participants must explain how they achieved their attacks, and of course, if they are worthy, there are many millions of dollars to be rewarded.
On Wednesday, security researcher Nicolas Joly came in and presented and walked away $90,000 richer. The researcher managed to combine a use-after-free (UAF) remote-code execution vulnerability with a sandbox escape directory traversal vulnerability in Adobe Flash to execute arbitrary code on the computer, earning $30,000. The remaining $60,000 was earned by also attacking Adobe Reader, managing to execute arbitrary code remotely.
“It’s the kind of attack where you come to Vancouver for a vacation and leave with cash,” said Joly, revealing that he had written the final part of the exploit for Reader on the plane, on his way to the conference.
Hacking teams Tencent PCMgr and KeenTeam also shared $140,000 in Wednesday's competition - winning $30,000 for taking control of Reader with an integer overflow, and $25,000 for a system-level exploit to execute code on Windows via a bug in the kernel's handling of TrueType fonts.
They also managed to earn another $60,000 by exploiting a heap overflow bug in Flash for remote code execution. They then managed to escalate their system-level privileges through another TrueType font flaw in the kernel and earned another $25,000.
But the star of the day was researcher Mariusz Mlynski, who in 0.512 seconds managed to exploit a cross-origin vulnerability in Firefox to attack a logical flaw in Windows. This allowed him to escalate privileges and execute code remotely, earning him $55,000.
Meanwhile, the new 360Vulcan team cracked 64-bit Internet Explorer 11 using an uninitialized memory vulnerability that allowed them to execute code for a $32,500 bounty.
The Pwn2Own continues today, with contestants targeting Apple's Safari, Google Chrome, and Internet Explorer. The makers of the vulnerable software are expected to announce full details once their products are patched.
