November 15, 2013

Samsung Galaxy S4 and iPhone 5 Vulnerability Released at Mobile Pwn2Own

The Mobile Pwn2Own contest ended with participating researchers winning $117,500 out of a prize pool of over $300,000.

A team of security researchers from Japanese company Mitsui Bussan Secure Directions hacked into a Samsung Galaxy S4 device by exploiting vulnerabilities in unnamed applications pre-installed on the device by the manufacturer. The Vulnerability allow the attacker to compromise the device in several ways, such as using a drive-by download to install malware on the phone.

In order for the exploiy to be successful, the group lured a user to a malicious website, gained system -level privileges and installed applications that allowed the team to gather information including SMS messages, contacts and browsing history.
A team of Chinese researchers hacked into two iPhone 5 devices running iOS 7.0.3 and iOS 6.1.4 respectively by exploiting vulnerabilities in Safari.

The Japanese team won $40,000 because their attack resulted in a full compromise of the device, and the Chinese team won $27,500 because their attack resulted in theft of data, like session cookies, photos and contacts.

 
Design by Lasantha
DMCA.com