• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

Virtual machine escape fetches $105,000 at Pwn2Own hacking contest

March 28, 2017 by Mengqi He Leave a Comment

Pwn2Own 2017 contest, an annually computer hacking contest, has ended in March 17. During the three-day contest, Google Chrome remained unscratched; Mozilla Firefox fell once; Apple’s Safari was taken down fourth and numbers of flaws were found from its new-developed Touch Bar; Two exploits were found on both Adobe Reader and Flash Player. One impressive thing on this contest was that two teams,360 Security and Tencent Security both from China successfully completed virtual machine escapes on the third day. Virtual machines are usually used to create an isolated environment that poses no threat to the host operating system in case of compromise. One of the main goals of hypervisors is to create a barrier between the guest OS running inside the VM and the host OS that the hypervisor runs. It prevents one user’s data and OS from being accessed by others sharing the same physical server. However, the success of VM escape meant that hackers were able to break out a VM and interact with and execute code on the host OS. 360 Security completed the VM escape by exploiting a heap overflow bug in Microsoft Edge, a type confusion in the Windows kernel, and an uninitialized buffer in VMware Workstation. The code demonstration took only 90 seconds. On the other hand, Tencent Security completed the guest-to-host by using a three-bug chain involving a Windows kernel UAF, a Workstation infoleak, and an uninitialized buffer in VMware Workstation. Finally, the 360 Security team won the most number of points and were crowned Master of Pwn for this year, and Tecent Security was the second. All the exploits found in this contest had to be shared with the contest’s organizer and the vendors, and these exploits will be kept confidential until vulnerabilities have been patched.

Link: https://arstechnica.com/security/2017/03/hack-that-escapes-vm-by-exploiting-edge-browser-fetches-105000-at-pwn2own/

Filed Under: Week 10 Tagged With:

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (35)
  • Week 01 (2)
  • Week 02 (14)
  • Week 03 (13)
  • Week 04 (10)
  • Week 05 (7)
  • Week 06 (29)
  • Week 07 (8)
  • Week 08 (1)
  • Week 09 (6)
  • Week 10 (12)
  • Week 11 (7)
  • Week 12 (4)
  • Week 13 (6)
  • Week 14 (18)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in