Advertisement
Guest User

Pwn2Own 2016 Major Changes and Rules v3

a guest
Feb 10th, 2016
1,768
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.67 KB | None | 0 0
  1. Pwn2Own 2016 Major Changes and Rules:
  2.  
  3. => Wassenaar: "Any software or technology that attendees bring or cause to be transferred to Canada for the Contest may be subject to the export controls of attendee's country of residence or travel origin. Attendees are responsible for compliance with any applicable import and export controls as a result of their attendance at the Contest."
  4.  
  5. => Major changes for Pwn2Own 2016:
  6. - Removed target: Firefox
  7. - Added target: VMware Workstation
  8. - No ZDI reward points for all winners but only for the one contestant with the highest total points.
  9. - Contestants have only 3 attempts to browse to the malicious content during a 15 minute time slot.
  10. - Prizes for Chrome and Safari have been reduced by $10,000 each. Prize for SYSTEM EoP was also reduced (by $5,000).
  11.  
  12. => Targets/Prizes/Rules:
  13.  
  14. Microsoft Windows 10 x64 / Mac OS X El Capitan.
  15.  
  16. Google Chrome + Sandbox bypass/escape: $65,000 (USD)
  17. Microsoft Edge + Sandbox bypass/escape: $65,000 (USD)
  18. Adobe Flash running in Microsoft Edge + Sandbox bypass/escape: $60,000 (USD)
  19. Apple Safari (Mac OS X) + Sandbox bypass/escape: $40,000 (USD)
  20. (Optional) Gain SYSTEM or root: +$20,000 (USD)
  21. (Optional) VMware Workstation host-to-guest escape: +$75,000 (USD)
  22.  
  23. - A successful remote attack against these targets must require no user interaction beyond the action required to browse to the malicious content and must occur within the user's session with no reboots, or logoff/logons. For example, having to interact with a dialog in order to successfully complete the exploit or writing a malicious file to the Startup folder is *not* allowed.
  24.  
  25. Full rules: http://zerodayinitiative.com/Pwn2Own2016Rules.html
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement