- Pwnie award
The Pwnie Awards recognize both extreme excellence and incompetence in the field of information security. Winners are selected by a committee of security industry luminaries from nominations collected from the information security community. The awards are presented yearly at the BlackHat Security Conference.
__TOC__
= Origins =
The name Pwnie Award is based on the word 'pwn', which is hacker-slang meaning "to compromise" or to "control" based on the previous usage of the word "own" (and it is pronounced similarly). The name "The Pwnie Awards" is meant to sound like The Tony Awards, an awards ceremony for Broadway Threater in New York City.
= History =
The Pwnie Awards were founded in 2007 by
Alexander Sotirov andDino Dai Zovi following discussions regarding Dino's discovery of a [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2175 cross-platform QuickTime vulnerability] and Alexander's discovery of an [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0038 ANI file processing vulnerability] in Internet Explorer.= Categories =
As of 2008, Pwnies are awarded in the following categories:
* Best Client-Side Bug
* Best Server-Side Bug
* Most Innovative Research
* Most Overhyped Bug
* Mass 0wnage, or the bug that has been exploited most frequently in the wild.
* Lamest Vendor Response
* Best Song
* Most Epic Fail
* Lifetime Achievement Award= Previous Winners =
2008
: Best Server-Side Bug: Windows IGMP Kernel Vulnerability ( [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0069 CVE-2008-0069] ): Best Client-Side Bug: Multiple URL protocol handling flaws: Mass 0wnage: An unbelievable number of WordPress vulnerabilities: Most Innovative Research: Lest We Remember: Cold Boot Attacks on Encryption Keys: Lamest Vendor Response: McAfee's "Hacker Safe" certification program: Most Overhyped Bug:
Dan Kaminsky 's DNS Cache Poisoning Vulnerability ( [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447 CVE-2008-1447] ): Best Song: [http://www.youtube.com/watch?v=bHxyHlFZ778 Packin' the K!] by Kaspersky Labs: Most Epic Fail:Debian 's flawed OpenSSL Implementation ( [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0166 CVE-2008-0166] ): Lifetime Achievement Award:Tim Newsham 2007
= External links =
* [http://pwnie-awards.org The Pwnie Awards]
Wikimedia Foundation. 2010.