Follow Us

Chrome hacking bounty increased to $2 million at Pwnium

Doubles cash on offer from March Pwnium event

Google now will pay up to $2 million for major vulnerabilities in its Chrome browser at a second Pwnium hacking contest this autumn.

Pwn2Own, a rival contest sponsored by HP, will award as much as $200,000 in a mobile-specific challenge slated to run several weeks earlier.

Google's Pwnium 2 will take place at the Hack In The Box security conference on October 10 in Kuala Lumpur, Malaysia.

Like the inaugural Pwnium, which Google sponsored in March at the CanSecWest conference in Vancouver, British Columbia, the upcoming challenge will pit researchers against the then-current version of Chrome. Vulnerability and exploit experts who demonstrate exploits of previously-unknown bugs will be eligible for awards of up to $60,000 for each flaw.

For what Google calls a "full Chrome exploit" - one that successfully hacks Chrome on Windows 7 using only vulnerabilities in Chrome itself - Google will pay $60,000 -- the same amount it handed out at the first Pwnium.

A partial exploit that uses one bug within Chrome and one or more others -- perhaps in Windows -- will earn a researcher $50,000, a 25% increase over the same category in the CanSecWest contest. Finally, Google will pay $40,000 for any "non-Chrome" exploit that doesn't involve the browser, but reveals a flaw in, for example, Windows or Adobe's Flash Player - which is bundled with Chrome.

Google also added a new class of awards for incomplete exploits. "We want to reward people who get 'part way' as we could definitely learn from this work," Chris Evans, a software engineer on the Chrome security team, said. "Our rewards panel will judge any such works as generously as we can."

The company committed up to $2 million total to Pwnium 2, twice the maximum it risked for the original. It's unlikely it will end up paying anywhere near $2 million; in March, it wrote checks totaling $120,000, or 12% of the $1 million limit.

To claim any award except in the "incomplete" category, researchers must not only pinpoint the vulnerability but also provide working exploit code to Google.

Evans repeated what Google had said earlier, that the original Pwn2Own was a success. "We were able to make Chromium significantly stronger based on what we learned," he said, referring to the name of the open source project run by Google that then feeds code into Chrome itself

Both researchers who won $60,000 prizes at the March event -- Sergey Glazunov and someone identified only as "PinkiePie" - also took home the Pwnie Award last month in the "Best Client-Side Bug" category for their Chrome work.

Another hacking contest will take place several weeks before Pwnium 2.

HP's TippingPoint will run a mobile-only version of its annual Pwn2Own in Amsterdam on September 19-20 at the EUSecWest security conference, where hackers will face off against Apple, Nokia, RIM and Samsung smartphones.

TippingPoint's Zero Day Initiative bug-buying programme will host the event, with help from sponsors AT&T and RIM, the struggling maker of the BlackBerry. Prizes total $200,000, a record for Pwn2Own, with the top-dollar award of $100,000 going to the first researcher who demonstrates a hack of cellular baseband, the silicon inside mobile phones that connects them to carrier networks.

Other rewards will be handed out to the first to hack NFC (near-field communication), the communications protocol being promoted for mobile payments, and SMS (short message service), the text-messaging service.




Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Optimise Performance For Global eCommerce

Global is all the rage: eBusiness teams are feverishly building new international initiatives in...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Techworld UK - Technology - Business

Part 2 of your journey to virtualisation

You can still access part 2 of our virtualisation journey - explore how you can improve your servers, storage and networks by developing your infrastructure.

Watch now...
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *