Tianfu Cup 2020 Reveals Zero-Days and Hacks Against Everything

  • Chinese hackers proved that no products are secure enough, even when you only have five minutes to crack them.
  • The teams found 23 exploits against 11 products and received a total of $1.2 million in bounties.
  • iOS 14, Ubuntu, Samsung Galaxy S20, VMWare, Windows 10, Safari, and Chrome were all hacked.

This year’s Chinese international cybersecurity contest known as the “Tianfu Cup” has been concluded, and the results are impressive without a doubt. The hacking teams managed to crack 11 out of the 16 targets that were defined by the organizers of the event, finding 23 zero-day flaws in them.

The products that were targeted include some very widely-used and high-profile software projects and items like the iPhone 11 Pro+iOS 14, the Samsung Galaxy S20, Windows 10 2004, TP-Link and ASUS routers, Chrome, Safari, Firefox, Adobe PDF Reader, CentOS 8, Docker-CE, and VMWare.

That is a very wide scope of targeting against products that are considered mature and secure, so the payouts were equally impressive. The winning team, “Qihoo 360,” has received a total of $744,500 for the hacks they managed to pull out.

Second place paid $258,000 to “AntFinancial Lightyear Security Lab,” the third place had an award of $99,500 (individual researcher), and even the team finishing eighth received a respectable $8,500.

Related: AnyConnect VPN Suffers From Zero-Day Exploit and Cisco Offers Workaround

Notably, the hacking teams only had three rounds of five minutes each to demonstrate the working exploit against the target.

Source: TFC

Because the products are so popular and widely used, Tianfu Cup couldn’t just publicly disclose the vulnerabilities and allow hackers to exploit a huge pool of users. Instead, and per the contest regulations, all of the discovered zero-days were reported to the vendors of the cracked products.

So, fixing patches are expected to arrive in the next days or even weeks.

Source: TFC

In several cases, different teams followed the same path of exploitation to take over a specific product, so the vulnerability was somewhat obvious. In these cases, the payouts were paid in full to each of the hacking teams, as long as there were up to three max.

Source: TFC

The highest paying fee for any discovery this year was $180,000 for the iPhone 11 Pro running iOS 14, where hackers managed to perform a sandbox escape through an RCE. Two hacking teams managed that, but we can’t tell if their methods were entirely different.

Other notable zero-day bounties include a $100k for a Chrome exploit, $60k for a Safari vulnerability, $50k+$80k for two Samsung Galaxy S20 flaws, $40k for a way into Windows 10, $180k for a VMWare break-in, and $40k+$15k for two Ubuntu bugs. Somehow, the Edge browser was spared from the weekend of massacre, being among the very few targets not to fall.

REVIEW OVERVIEW

Latest

How to Get Paramount Plus on TiVo in 2021

As you probably know, TiVo is a bit peculiar platform. However, it started opening up to third-party apps just recently, which is...

How to Get Paramount Plus on a Vizio Smart TV in 2021

Paramount Plus is available on a range of smart TVs, no matter their platform of choice. With that said, it doesn't come...

How to Get Paramount Plus on Android Phones & Tablets in 2021

Paramount Plus has done an excellent job of offering apps across many platforms. As you can already guess, Android is among those platforms –...