Войти

Chinese hackers successfully hacked the latest versions of Windows, Ubuntu, iOS and Android

2868
1
0
Image source: naked-science.ru

China hosted the largest national hackathon Tianfu Cup-a competition between teams of experts on attacks on information infrastructure. Using previously unknown vulnerabilities, participants were able to hack almost all the most modern software products.

The winner of the contest received $ 744,500 for successful attacks on Google Chrome and Mozilla Firefox browsers, as well as hacking the iOS operating systems (OS) running the iPhone 11 Pro, and Microsoft Windows 10 2004 running on the Surface Pro 5 tablet. The team has the long name 360 Enterprise Security and Government and (ESG) Vulnerability Research Institute. Its members work for a Chinese company specializing in Internet security, Qihoo 360. In total, this team took two-thirds of the total prize Fund, which was $ 1.2 million.

Qihoo 360 employees were also able to hack the enterprise virtualization software VMWare EXSi, the PDF document viewer Adobe Reader (two successful attacks), the Samsung Galaxy S20 smartphone running Android 10, the QEMU emulation software environment,and the Ubuntu 20 OS. In addition, they easily seized control of the TP-Link wdr7660 router.

Other participants also distinguished themselves — Safari browser, Docker enterprise software management system, and ASUS AX86U router "fell" under their onslaught. In addition, not only specialists from Qihoo 360 successfully coped with the hacking of the above SOFTWARE. Most targets were attacked more than once.

Table of achieved goals

Image source: Tianfu Cup

For example, the iPhone 11 was hacked in two ways, just like the Galaxy S20. And the PDF document viewer from Adobe "distinguished itself" at all — five successful attacks were made on it. A comparable number of new vulnerabilities were found only in the TP-Link router: four.

It is noteworthy that the hackathon organizers chose several more goals as the competition's disciplines, but the participants ignored some of them. The Microsoft Edge browser, the VMware Workstation custom package, and the Exchange Server 2019 system could bring teams another $ 380,000. But for some reason, they didn't waste their energy on them. Perhaps these software products are not of great interest to cybercriminals, or maybe there is simply no time left for them in the competition.

In total, 11 of the 16 goals were achieved, and the most common applications and operating systems were successfully attacked. It goes without saying that the developers of each software product received detailed information about all identified vulnerabilities.

The Tianfu Cup hackathon has been held since 2018. It was organized after the Communist Party banned Chinese cybersecurity specialists from participating in foreign professional competitions. According to its principles, the contest is similar to one of the most prestigious hacker Championships — Pwn2Own. Participants are assigned a goal: for example, to execute code with certain privileges on the attacked device. They must find a previously unknown vulnerability and implement it. For successful completion of the task, points are awarded, and then cash prizes. All detected software errors must be reported to the SOFTWARE creators.

The rights to this material belong to
The material is placed by the copyright holder in the public domain
  • The news mentions
Comments [1]
№1
12.11.2020 19:10
"Всё, что один человек построил, другой завсегда сломать может" (С)
0
Inform
Do you want to leave a comment? Register and/or Log in
ПОДПИСКА НА НОВОСТИ
Ежедневная рассылка новостей ВПК на электронный почтовый ящик
  • Discussion
    Update
  • 17.05 08:15
  • 1279
Корпорация "Иркут" до конца 2018 года поставит ВКС РФ более 30 истребителей Су-30СМ
  • 17.05 08:09
  • 1378
Without carrot and stick. Russia has deprived America of its usual levers of influence
  • 17.05 05:32
  • 3
Более 15 кораблей отрабатывают на учениях борьбу с беспилотниками
  • 17.05 00:47
  • 1
Ответ на https://vpk.name/news/863570_ssha_vstupili_v_shvatku_srazu_na_dvuh_frontah_ih_zhdet_gorkoe_razocharovanie_geopolitikanews_horvatiya.html
  • 16.05 23:43
  • 2725
Как насчёт юмористического раздела?
  • 16.05 20:33
  • 1
Successes in Work: what is the importance of the promotion of the Armed Forces of the Russian Federation in the Zaporozhye direction
  • 16.05 14:19
  • 2
Для космонавтов создали дополнительные конечности
  • 16.05 13:36
  • 49
Продолжается разработка перспективного тяжёлого транспортного самолёта "Слон"
  • 16.05 09:38
  • 1
С американского эсминца "Зумвальт" демонтировали 155-мм артустановку
  • 16.05 08:34
  • 2
The United States entered the fray on two fronts at once. They will be bitterly disappointed (Geopolitika.news, Croatia)
  • 16.05 02:40
  • 0
Почему опыта СВО (на ее нынешней стадии) НЕДОСТАТОЧНО для выводов ("технических", в том числе) на будущее.
  • 16.05 01:11
  • 0
О борьбе тихоокеанского флота с беспилотниками.
  • 16.05 00:25
  • 0
О реальных уроках хода (и промежуточных результатов) СВО.
  • 15.05 18:56
  • 0
Об уроках СВО (на данном этапе ее развития).
  • 15.05 18:24
  • 42
Глава Военного комитета НАТО заявил о необходимости проведения дополнительной мобилизации на Украине