Article Details
Scrape Timestamp (UTC): 2024-10-24 14:02:56.192
Original Article Text
Click to Toggle View
Samsung Galaxy S24 and Sonos Era hacked on Pwn2Own Ireland Day 2. On the second day of Pwn2Own Ireland 2024, competing white hat hackers showcased an impressive 51 zero-day vulnerabilities, earning a total of $358,625 in cash prizes. Pwn2Own is a hacking contest where security researchers compete to exploit software and mobile hardware devices to earn the coveted title of "Master of Pwn" and $1,000,000 in cash and prizes. On day 2 of Pwn2Own, the Viettel Cyber Security team maintained a strong lead in the race for the "Master of Pwn" title, with standout performances across several categories. Pham Tuan Son and ExLuck from ANHTUD kicked off the day by exploiting a Canon imageCLASS MF656Cdw printer using a stack-based buffer overflow, securing $10,000 and 2 Master of Pwn points. Ken Gannon from NCC Group chained five bugs, including a path traversal, to exploit the Samsung Galaxy S24, gaining a $50,000 payout and 5 points. His exploit allowed him to install an app and gain shell access to the popular Android device. Dungdm from Viettel Cyber Security took control of a Sonos Era 300 smart speaker using a Use-After-Free (UAF) vulnerability. His successful exploit added $30,000 to his team's earnings and 6 Master of Pwn points. Team Cluck's duo Chris Anastasio and Fabius Watson chained two vulnerabilities, including a CRLF injection, to compromise the QNAP TS-464 NAS, earning $20,000 and 4 points in the process. Corentin BAYET of Reverse Tactics earned $41,750 and 8.5 points despite one of the three bugs in his chain being a repeat from earlier rounds while targeting the QNAP QHora-322 router. Collisions and fails Day 2 also had several collisions, meaning the same exploit was used by other researchers, as well as unsuccessful attempts to hack the devices in the allotted time. Tenable and Synactiv received reduced payouts and fewer points due to collisions when hacking the Lorex 2K and Synology BeeStation devices, respectively. Also, DEVCORE, Rapid7, and Neodyme encountered difficulties in executing their exploits within the time limits, resulting in several failed attempts across devices like the Sonos Era 300 and Lexmark CX331adwe printer. Despite the setbacks, the Pwn2Own competition remains intense, only having reached halfway, with two days remaining for participants to climb higher in the rankings. At this point, researchers have exploited a total of 103 zero-day vulnerabilities, 52 on day one, and earned $847,875 in prizes.
Daily Brief Summary
On day two of Pwn2Own Ireland 2024, hackers disclosed 51 zero-day vulnerabilities.
Competitors vied for the "Master of Pwn" title and a share of $1,000,000 in cash and prizes, totaling $358,625 for the day.
Viettel Cyber Security's team led the competition, with notable achievements in multiple categories.
Key exploits included a Canon printer hack by ANHTUD team members, and a Samsung Galaxy S24 hack by NCC Group's Ken Gannon.
Dungdm of Viettel Cyber team managed to take control of a Sonos Era 300 using a Use-After-Free vulnerability.
Attempts to exploit other devices like the Sonos Era 300, and the Lexmark CX331adwe printer faced challenges, with several failed attempts.
The competition will continue for two more days, with researchers aiming to increase their standings.
After two days, the event has awarded $847,875 for exploiting 103 zero-day vulnerabilities.