This year’s edition of the Tianfu Cup hacking competition was very prolific, bug bounty hackers have discovered multiple vulnerabilities in multiple software and applications.
The Tianfu Cup is the most important hacking contest held in China, the total bonus of the contest this year was up to 1 million US dollars.
The third edition of the competition ended today and the winning team earned a total of $744,500.
TFC 2020 has come to the end, all these excellent offensive researchers and their burning 0days makes #TFC 2020 a success! Thank you all for participating and following!
— TianfuCup (@TianfuCup) November 8, 2020pic.twitter.com/MwJLc5M0B4
The participants successfully tested their exploits against the following software:
Many mature and hard targets have been pwned on this year’s contest. 11 out of 16 targets cracked with 23 successful demos:
— TianfuCup (@TianfuCup) November 8, 2020
Chrome, Safari, FireFox
Adobe PDF Reader
Docker-CE, VMware EXSi, Qemu, CentOS 8
iPhone 11 Pro+iOS 14, GalaxyS20
Windows 10 2004
TP-Link, ASUS Router
This year fifteen teams of Chinese hackers took part in the competition, each team had three tries of five minutes to demonstrate a working exploit against a specific target.
Working exploits were already reported to software vendors that will address the vulnerabilities discovered by the experts in the coming weeks.
The team named “360 Enterprise Security and Government and (ESG) Vulnerability Research Institute,” which is part of the Chinese tech giant Qihoo 360, won the competition. The winning team earned $744,500 of the total $1,210,000 jackpot.
Congratulations to all the winning teams, especially to 360 ESG Vulnerability Research Institute – crowned the biggest winner on #TFC 2020 with $744,500 total bonus.
— TianfuCup (@TianfuCup) November 8, 2020
The glory is for your awesome demos on the stage, also for massive research you’ve done off the stage! Well done!
At the second place there is the AntFinancial Lightyear Security Lab followed by the security researcher Pang.
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Tianfu Cup)
[adrotate banner=”5″]
[adrotate banner=”13″]