James Horsman and Zach Hanley: How to Find an RCE and Win $20K at Pwn2Own
A talk about how basic vulnerabilities still go unnoticed in enterprise software. The speakers share their first experience competing at Pwn2Own and explain how a simple approach combined with a “hacker mindset” helped them discover a command injection RCE affecting nearly all Lexmark printers.
They discuss why the vulnerability remained undetected for so long, how static analysis tools failed to catch it, and demonstrate proof-of-concept exploits — including an example of credential extraction.
They discuss why the vulnerability remained undetected for so long, how static analysis tools failed to catch it, and demonstrate proof-of-concept exploits — including an example of credential extraction.