This does not surprise Storms.
He said: ' These gaps are difficult to exploit. Last year, it was easy, but it turned out not to be easy to exploit these vulnerabilities, because it required users to browse to the area containing the malicious code and open the file, and the attackers would Put a malicious DLL and a bad file. That's just a few steps '.
HD Moore, head of Rapid7's security staff and creator of the Metasploit toolkit open source toolkit, yesterday announced to businesses that they can turn the exploit of any DLL vulnerability. Which hijacking load becomes more difficult for any hacker by removing WebDAV service on all Windows machines, and blocking outbound ports 139 and 445.
Last year, Moore was one of the first to reveal the new level of DLL load hijacking vulnerability .
However, Microsoft did not patch IE before the Pwn2Own hack contest took place today.
Pwn2Own, which will put security researchers 'against' four browsers, including Microsoft's IE, Apple's Safari, Google's Chrome and Mozilla's Firefox, will take place from November 9 at the CanSecWest conference in Vancouver. Canada. The first security researcher who defeats IE, Safari or Firefox will receive a $ 15,000 prize, and anyone who gets off the Chrome browser will receive a $ 20,000 prize.
Yesterday (March 8), Bryant said that customers' patching should not be interrupted with surprising security updates to create opportunities for the Pwn2Own competition.
Bryant said: ' I don't see any reason to disrupt customers just because of the competition. Going out is a potential interruption, and we won't do this unless a vulnerability is being attacked . '
Microsoft refused to preempt IE before Pwn2Own was not a surprise: The company provided updates for IE in even months, and the latest browser update was released on August 8. 2 past.
Bryant added, in any case, that any holes exploited at Pwn2Own leaked out were not harmful because the errors discovered at this contest will be reported to the vendor. level discreetly.
HP TippingPoint Group, which owns Zero Day Initiative (ZDI) security research program, generously donated Pwn2Own and paid most cash prizes, acquired ownership of the discovered holes in the competition and awarded Leave them to suppliers. ZDI gives developers six months to patch any vulnerabilities they buy before they publish official information.
Both Google and Mozilla have recently patched their browser - Google patched early yesterday - and Apple is expected to update Safari before Pwn2Own starts.
Microsoft updates can be downloaded and installed via Microsoft Update and Windows Update services, as well as through Windows Server Update Services (WSUS).