Pwn2Own organizadores ofrecerán a los participantes piratear sistemas de ICS

a partir de 2020, a separate nomination for components of industrial control systems will appear in the Pwn2Own ethical hacker competition. Pwn2Own organizadores darán a los participantes una tarea de cortar los sistemas de ICS.

UNAt the Miami Summit in January, expertos tratarán de romper ocho productos que se presentan en cinco categorías. The prize fund of this part of the competition will be more than $250 mil.

“Starting next January, Pwn2Own grows again by adding a third competition at the S4 conference in Miami South Beach on January 21–23, 2020. This contest focuses on Industrial Control Systems (ICS) and associated protocols”, — write Pwn2Own organizers.

In the nominationManagement Servers“, participants will have to attack Iconics Genesis64 y Inductive Automation Ignition SCADA platforms available on the test network from their laptop.

The organizers suggested several levels of possible hacker performance. Así, a forced shutdown of a system or its transfer to a denial of service condition is estimated at $5,000, and an exploit for unauthorized disclosure of information will bring a specialist twice as much. The maximum bonus of $20 thousand will receive an ethical hacker who will achieve remote code execution within any of the programs.

Adicionalmente, contestants will be able to try to compromise the Triangle MicroWorks SCADA Data Gateway solicitud, presented in the “DNP3 Gateways” category. For hacking a communication program, ethical hackers can get from $5 a $20 mil, as well as up to 20 Master of Pwn points, taken into account when determining the absolute winner.

“We’ve had discussions for years about running a Pwn2Own for ICS, but there are many challenges to holding such a contest. To overcome these issues, we worked with multiple people and companies within the ICS industry to ensure we have the right products and categories to create a meaningful test of the security of these products and protocols”, — report organizers.

For servers using the Open Platform Communications (OPC) specification, a separate category will be provided for Pwn2Own 2020. Participants will be asked to call DoS, to obtain the disclosure of confidential information or to remotely execute their code on Unified Automation ANSI C Demo Server y OPC Foundation OPC UA .NET Standard platforms.

LEER  El malware se convierte en discordia mensajero puerta trasera y fuerzas para robar datos

In the categoryEngineering Workstationsthere is only one product. For remote launch of a third-party script in the development environment of Rockwell Automation Studio 5000, information security specialists will be able to get $20 mil.

For the nomination “Human-Machine Interface”, the organizers prepared a confrontation of competing products of the two largest market players. Ethical hackers will be able to remotely execute their code on Schneider Electric y FactoryTalk View SE EcoStruxure Operator Terminal Expert workstations from Rockwell Automation. For participants who try to hack the latest system, additional bonuses are provided for putting it into a denial of service condition or unauthorized disclosure of information, as well as a separate bonus for an exploit that is resistant to restarting the program.

leer también: Los investigadores encontraron vulnerabilidades en eRosary rosarios inteligentes de los desarrolladores del Vaticano

The last Pwn2Own took place in March this year and brought its participants more than half a million dollars. The triumph of the competition was the fluoroacetate equipo, who managed to hack the on-board system of the Tesla Model 3 and received the electric car as a prize for the competition.

Pwn2Own recalls that the goal is always to get these bugs fixed before attackers actively exploit them.

[Total:0    Promedio:0/5]

Acerca de Trojan Killer

Trojan Killer llevar portátil en su dispositivo de memoria. Asegúrese de que usted es capaz de ayudar a su PC resistir cualquier amenaza cibernética donde quiera que vaya.

también puedes ver

MageCart en la plataforma de nube Heroku

Los investigadores encontraron Varios MageCart Web skimmers En Heroku Cloud Platform

Investigadores de Malwarebytes informaron sobre la búsqueda de varios skimmers MageCart web en la plataforma de nube Heroku …

Android Spyware CallerSpy

máscaras spyware CallerSpy como una aplicación de chat Android

expertos de Trend Micro descubrieron que el malware CallerSpy, que enmascara como una aplicación de chat y Android, …

Deja una respuesta