The Pwn2Own contest pays contestants for their exploit code, which leverages software flaws to give the attacker a foothold on the machine being attacked. But because of the iPhone's sandbox architecture, Weinmann and Iozzo actually spent much more time working on their payload software.
To make their attack work, they used a technique called "return-oriented programming," in which they essentially cobble together instructions from different parts of the iPhone's memory. But even with this technique, the iPhone's sandbox restricted what they could do once they had hacked into the machine.
Return-oriented programming has been around for more than a decade, but this attack is the first public demonstration of this technique on the Arm microprocessor, contest organizers say.
Iozzo and Weinmann were selected by lot to be the first to try out their attack at the three-day hacking contest. But Iozzo wasn't actually at the conference when his slot came up. A delayed flight caused him to miss his connection to Vancouver, but a co-worker, Thomas Dullien (better known as Halvar Flake), stood in for him at the contest.
Even though they tested the hack before the contest, Dullien and Weinmann ran into some trouble. "The first try gave us an empty database, but that was probably due to a bug in our database," Weinmann said after winning the prize. A second attempt was successful.
Run in conjunction with the CanSecWest security conference, Pwn2Own has become a closely watched test of exploit-writing skills, where professional hackers routinely show up and demonstrate how easy it would be to break into a computer running the latest software.
The contest provides a high-profile demonstration of just how common exploitable software bugs really are, despite concerted efforts by companies such as Microsoft, Mozilla and Apple to lock down their code.
TippingPoint, a security company that sponsors the contest, runs a program that pays hackers for working exploit code. According to Aaron Portnoy, TippingPoint's security research team lead, software makers have introduced techniques that make it harder to hack their products, but there are still plenty of bugs out there.
CanSecWest and the Pwn2Own contest run through Friday.
Sign up for Computerworld eNewsletters.