The Tianfu Cup is the most important hacking contest held in China, this year white hat hackers earned $1.88 Million demonstrating vulnerabilities in popular software.
The edition of this year took place on October 16 and 17 in the city of Chengdu, participants had three attempts of 5 minutes to demonstrate their exploits.
TFC 2021 is coming! Oct. 16th-17th, see you again at CHENGDU, CHINA. This year, the total bonus is up to $1.5 Million, with new category and targets, waiting for you to PWN and WIN. https://t.co/XfAxZbttfq pic.twitter.com/zRSpQ6MkIk
— TianfuCup (@TianfuCup) July 15, 2021
The winner is the security firm Kunlun Lab who earned $654,500, below the tweet of the amazing expert @mj0011 CEO of Cyber-Kunlun & Kunlun Lab and former CTO of Qihoo 360 and founder of team 360Vulcan.
New company but still ranked as #1 this year TianfuCup. Almost all targets are fully pwned this time(except Synology). last photo : the empty review room after 0day party pic.twitter.com/TRM37hAYuh
— mj0011 (@mj0011sec) October 17, 2021
This year’s edition included a list of 16 possible targets, participants successfully demonstrated exploits against 13 of them:
One of the exploits demonstrated at the contest immediately attracted the attention of the media, it is a zero-click remote code execution exploit against a fully patched iOS 15 running on the latest iPhone 13. The Chian Pangu won the highest single bonus in the history of this competition for this exploit, $300000.
The iPhone 13 Pro Safari escaped from prison remotely, and Chian Pangu won the highest single bonus of $300000 in history.
— HBS (@HUC_hbs) October 16, 2021@mj0011sec pic.twitter.com/rrCa1cGcnN
Pangu team iPhone 13 Pro IOS 15 Safari remote jailbreak attack video, really fast. @mj0011sec pic.twitter.com/JlO572oia8
— HBS (@HUC_hbs) October 17, 2021
The participants also demonstrated a remote code execution exploit chain against Google Chrome, this is the first time that this kind of exploit was demonstrated at the Tianfu Cup.
First confirmed entry for day1 of TianfuCup, Kunlun Lab @S0rryMybad pwned Google Chrome to get Windows system kernel level privilege with only two bugs. First time since 2015 as I remembered https://t.co/xy1dTzl1GV
— mj0011 (@mj0011sec) October 16, 2021
No exploit was demonstrated against Synology DS220j NAS, Xiaomi Mi 11 smartphone, and an unnamed domestic electric vehicle.
Follow me on Twitter: @securityaffairs and Facebook
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Tianfu Cup 2021)
[adrotate banner=”5″]
[adrotate banner=”13″]