Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
2014 Pwnie Award Nominations (pwnies.com)
51 points by tptacek on Aug 4, 2014 | hide | past | favorite | 5 comments


They're a joke (literally), of course, but the list of vulnerabilities here is pretty interesting.

Predictions:

* Serverside: Heartbleed

* Clientside: Geohot

* Privilege Escalation: evasi0n

* Most innovative: RPW's hardware memory corruption

* Epic fail: ISC2

* Epic ownage: MtGox


You missed "Lamest Vendor Response". That's a though category. I want OpenCart to "win", but as General Motors' is the only one that required a Congressional inquiry, it's though to beat.


I also want OpenCart to "win": https://github.com/opencart/opencart/pull/1594


Hmm. I hadn't heard of the errata-driven memory corruption paper before: although interesting, it didn't seem terribly novel -- errata being used to adversely affect a machine have been around since the dawn of time.

My personal 'most innovative', I think, would go to the BROP paper. The other exploits are all interesting tricks on modern systems, but the BROP paper is the one that made my jaw really drop in terms of how much they could do with such little information...





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: