logo-default
  • HOME
  • ABOUT US
  • LITIGATION SUPPORT SERVICES
  • CYBER SECURITY SERVICES
  • BLOG
Return to previous page
Home Blog Courtroom Digital Forensics

Pwn2Own Toronto 2023 Day 1

Pwn2Own Toronto 2023 Day 1

October 25, 2023 /Posted byadmin / 14 / 0

[ad_1]

Pwn2Own Toronto 2023 Day 1 – organizers awarded $438,750 in prizes

Pierluigi Paganini
October 25, 2023

The Pwn2Own Toronto 2023 hacking contest has begun and during the first day, participants received $438,750 in prizes!

During the Day 1 of the Pwn2Own Toronto 2023 hacking contest, the organization has awarded a total of $438,750 in prizes!

Team Orca of Sea Security received the greatest rewards of the day, the researchers chained two issues using an OOB Read and UAF against the Sonos Era 100. They earned $60,000 and 6 Master of Pwn points.

Researchers from Pentest Limited demonstrated an Improper Input Validation against the Samsung Galaxy S23. They earned $50,000 and 5 Master of Pwn points.

Pwn2Own Toronto 2023

The team STAR Labs SG exploited a permissive list of allowed inputs against the Samsung Galaxy S23 and earned $25,000 and 5 Master of Pwn points.

Pentest Limited also earned $40,000 and 4 Master of Pwn points by executing a 2-bug chain against the My Cloud Pro Series PR4100 using a DoS and server-side request forgery (SSRF).

Team Viettel demonstrated a single-bug attack against the Xiaomi 13 Pro and earned $40,000 and 4 Master of Pwn points.

Team ECQ also earned $40,000 and 4 Master of Pwn points by executing a 3-bug chain using an SSRF and two injection vulnerabilities against the QNAP TS-464.

Binary Factory and Synacktiv demonstrated working attacks against the Synology BC500 and earned $30,000 and 3 Master of Pwn points and $15,000 and 3 Master of Pwn points respectively.

Compass Security also executed a stack overflow attack against the Synology BC500, but the exploit they used was previously known. They still earn $3,750 and 0.75 Master of Pwn points.

Other successful attacks were demonstrated against Canon imageCLASS MF753Cdw and Lexmark CX331adwe.

Below is the leaderboard after Pwn2Own Toronto 2023 Day 1.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Pwn2Own Toronto 2023)





[ad_2]

Seiko “BlackCat” Data Breach: ...
AWS: Security Not a Priority F...

Related posts

Read more

Misinformation and hacktivist campaigns targeting the Philippines skyrocket

April 17, 2024 0
... Continue reading
Read more

PuTTY SSH Client flaw allows of private keys recovery

April 16, 2024 0
... Continue reading
Read more

A renewed espionage campaign targets South Asia with iOS spyware LightSpy

April 16, 2024 0
... Continue reading
Read more

Ransomware group Dark Angels claims the theft of 1TB of data from chipmaker Nexperia 

April 16, 2024 0
... Continue reading
Read more

Blackjack group used ICS malware Fuxnet against Russian targets

April 16, 2024 0
... Continue reading

Add comment Cancel reply

Your email address will not be published. Required fields are marked

Search