TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Hackers earn $990k for 63 zero-days exploited at Pwn2Own Toronto

95 点作者 Blue111超过 2 年前

10 条评论

ackbar03超过 2 年前
I remember reading somewhere that hardcore foreign teams stopped going to pwn2own once they realized that they were<p>1) effectively disclosing valuable zero days in a dark room 2) to the tagert manufacturer 3) and the pwn2own organizer who happens to be indirectly sponsored by the NSA<p>In exchange for what is pretty much just kudos and pocket change
评论 #33940661 未加载
评论 #33940519 未加载
评论 #33946760 未加载
bmitc超过 2 年前
Interesting that they didn&#x27;t mention in the summary that exploits were found for both a Samsung Galaxy and a Tesla head unit.<p>What type of knowledge do these people have? Networking? File systems? Linux kernels? How do they get started?
评论 #33941167 未加载
评论 #33941069 未加载
ec109685超过 2 年前
Firecracker shows how low overhead VM’s can be. It feels like more of systems should have a harder boundaries, limiting impact of exploits.
评论 #33941279 未加载
romellem超过 2 年前
Money well spent, just think of the damage these could do if unpatched. These types of events are a great investment for the companies.
rdtwo超过 2 年前
Seems like us probably 1&#x2F;100 of what they could have earned on the market
评论 #33940211 未加载
评论 #33940617 未加载
1B05H1N超过 2 年前
Glad they found those vulns but I imagine one could fetch a lot more on less legitimate markets.
barbarbar超过 2 年前
Is this hacking of a phone they have in their hands and connect it to a computer with a wire?
MichaelZuo超过 2 年前
It seems like the name is bit of a misnomer though. Perhaps Pwn2Sell?
deafpolygon超过 2 年前
Ok, ok, we get it. The Samsung Galaxy is an insecure phone.
thefourthchime超过 2 年前
Not exactly related, but in my opinion, the quality of software has decreased in recent years. This is not unexpected.
评论 #33940128 未加载