<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iMore &#187; pwn2own</title>
	<atom:link href="http://www.imore.com/tag/pwn2own/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imore.com</link>
	<description>More of everything iPhone and iPad</description>
	<lastBuildDate>Sun, 27 May 2012 13:54:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>iPhone Pwned at Pwn20wn</title>
		<link>http://www.imore.com/2010/03/25/iphone-pwned-pwn20wn/</link>
		<comments>http://www.imore.com/2010/03/25/iphone-pwned-pwn20wn/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 14:37:47 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[pwn2own]]></category>

		<guid isPermaLink="false">http://www.tipb.com/?p=23956</guid>
		<description><![CDATA[Looks like our iPhone didn't put up much of a fight at the latest <a href="http://www.imore.com/pwn2own">Pwn20own</a> contest in Vancouver, falling on the first day to hacking duo Ralf Philipp Weinmann of]]></description>
			<content:encoded><![CDATA[<p><img src="http://cdn.imore.com/images/stories/2009/07/sadpirate.png" alt="sadpirate" title="sadpirate" width="273" height="336" class="aligncenter size-full wp-image-9720" /></p>

<p>Looks like our iPhone didn't put up much of a fight at the latest <a href="http://www.imore.com/pwn2own">Pwn20own</a> contest in Vancouver, falling on the first day to hacking duo Ralf Philipp Weinmann of the University of Luxembourg, and Vincenzo Iozzo of Zynamics according to <a href="http://news.cnet.com/8301-27080_3-20001126-245.html">CNET</a>.</p>

<p>The team wins $15,000 for their efforts, which took them about 2 weeks to write. The exploit involved getting a user to go to a malicious website whose payload downloads and executes, stealing the contents of the iPhone's SMS database. (Though they said the same attack could be used to get contacts, photos, or any other data).</p>

<blockquote>
  <p>The exploit was written to bypass the digital code signatures used on the iPhone to verify that the code in memory is from Apple, he said. The exploit then looked for chunks in Apple's code that could be pieced together to accomplish the attack, according to Weinmann.</p>
</blockquote>

<p>Bypassing Apple's security was "major issue" and used a process known since 1997 but not exploited on an ARM-based device like the iPhone until now.</p>

<p>The details of how the exploit was done are being kept confidential but will be shared with Apple.</p>

<p>Hacking the iPhone is nothing new, of course, as getting around Apple's security is how <a href="http://www.imore.com/tag/jailbreak/">Jailbreak</a> is achieved (and original iPhone 2G owners may remember one of the earliest Jailbreak techniques involved simply going to a website with Mobile Safari). Apple has been beefing up their security team so while it's not good news for Jailbreakers, future iPhone hardware and software should be harder targets.</p>

<p>Oh, and yes, <a href="http://www.imore.com/tag/charlie-miller/">Charlie Miller</a> won $10,000 for exploiting Mac Safari. Again.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2010/03/25/iphone-pwned-pwn20wn/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Want a Free iPhone and $10,000 Prize? Pwn2Own it!</title>
		<link>http://www.imore.com/2009/02/28/free-iphone-10000-prize-pwn2own/</link>
		<comments>http://www.imore.com/2009/02/28/free-iphone-10000-prize-pwn2own/#comments</comments>
		<pubDate>Sat, 28 Feb 2009 14:21:55 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=7305</guid>
		<description><![CDATA[<a href="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009">Pwn2Own</a> is a hacking contest which in previous years demanded OS exploits on day one, allowed browser vectors on day two (how OS X was compromised last year -- thanks]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2008/11/macbook_stop_jailbreak.jpg" alt="" title="macbook_stop_jailbreak" width="500" height="300" class="aligncenter size-full wp-image-5295" /></p>

<p><a href="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009">Pwn2Own</a> is a hacking contest which in previous years demanded OS exploits on day one, allowed browser vectors on day two (how OS X was compromised last year -- thanks Safari!), and opened the floodgates with 3rd party bugware on day three. First person to successfully hack a machine won it as a prize, along with a nice cash bounty for their troubles.</p>

<p>This year, <a href="http://arstechnica.com/gadgets/news/2009/02/pwn2own-contest-will-target-browsers-and-mobile-devices.ars">Ars Technica</a> says Pwn2Own is doing something a little different: they're bringing in the mobiles!</p>

<p>Apple's iPhone is front and center on their target list, along with the Google Android G1, and devices from the BlackBerry, Symbian, and Windows Phone families. Pwn the mobile and you not only win it, but $10,000 to boot!</p>

<p>Not a lot of solid info on the rules yet, but we'll keep a look out. Any white hats out there eager to try their luck?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/02/28/free-iphone-10000-prize-pwn2own/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

