Internet Explorer 9 Cracked During Annual Hackathon

This version of Wbna46681640 - Breaking News | NBC News Clone was adapted by NBC News Clone to help readers digest key facts more efficiently.

VANCOUVER, British Columbia — Internet Explorer 9 was hacked during day two of the annual Pwn2Own hacking contest held at the CanSecWest security conference here.

VANCOUVER, British Columbia — Internet Explorer 9 was hacked during day two of the annual Pwn2Own hacking contest held at the CanSecWest security conference here.

Yesterday (March 8), researchers from the French security firm Vupen exploited two bugs, an unpatched heap overflow flaw and a memory-corruption vulnerability, to crack Microsoft's IE9 Web browser and run code outside the sandbox, the security feature in place to contain bugs and prevent malicious code from executing on the user's system.

On Wednesday, Vupen kicked off the Pwn2Own festivities by hacking the Google Chrome browser. It was the first time a research team has hacked Chrome during the annual contest.

"It was difficult because the heap overflow vulnerabilities are not very common," Vupen's CEO and chairman, Chaouki Bekrar, told SecurityNewsDaily of the IE 9 hack. "They [the flaws] are rare but they are useful, because you can use the same vulnerability to achieve memory leak and thus bypass ASLR."

(Address Space Layout Randomization, or ASLR, is a security protocol for randomly arranging data areas in a process' address space.)

Bekrar added, "Usually we need three vulnerabilities, one for DEP [Data Execution Prevention], one for ASLR, and one for the sandbox. Here we had one that allowed us to do DEP and ASLR, which is nice."

The attack required the researchers to navigate to a rigged website, where they demonstrated their exploit by making a calculator app show up on the target system.

"We used only a specially crafted Web page," Bekrar said. "There was no user interaction, no downloading, no pop-ups, no message box to accept. It was a 'visit and get pwned' exploit."

Bekrar said the code execution attack also works on old versions like IE6 and the new IE version 10, which is only available for consumer preview.

Vupen researchers performed their proof-of-concept hack on a fully-patched Windows 7 Service Pack 1 machine. It took the team seven weeks to craft the IE 9 exploit.

×
AdBlock Detected!
Please disable it to support our content.

Related Articles

Donald Trump Presidency Updates - Politics and Government | NBC News Clone | Inflation Rates 2025 Analysis - Business and Economy | NBC News Clone | Latest Vaccine Developments - Health and Medicine | NBC News Clone | Ukraine Russia Conflict Updates - World News | NBC News Clone | Openai Chatgpt News - Technology and Innovation | NBC News Clone | 2024 Paris Games Highlights - Sports and Recreation | NBC News Clone | Extreme Weather Events - Weather and Climate | NBC News Clone | Hollywood Updates - Entertainment and Celebrity | NBC News Clone | Government Transparency - Investigations and Analysis | NBC News Clone | Community Stories - Local News and Communities | NBC News Clone