On TechRepublic: 10 lame phrases to cut from your resume
BNET Business Network:
BNET
TechRepublic
ZDNet

March 6th, 2007

More on Maynor

Posted by Jason D. O'Grady @ 5:49 am

Categories: Airport, Hack, Security, WiFi

Tags:

owned-macbook.pngLast summer, David Maynor announced an exploit for Mac OS X and Apple's AirPort drivers that would allow third party code to be run. The hack was proven to work, but became controversial when a third party wireless card and third party drivers were involved with the exploit.

Maynor since offered an apology for mistakes that he had made and offered a live demonstration of the MacBook Wi-Fi vulnerability at a Black Hat event in DC last month. Maynor also offered to release e-mail exchanges, crash/panic logs, loose notes and the exploit code used in the hack, which allowed third party code to be run over the wireless connection, as a means of clearing is name.

Maynor's first video has been scrutinized and it is now known that the first hack did not involve a third-party wireless card. It appears to be fraudulent. Check this video.

Here's what someone in the know wrote to me:

You can see from that screenshot that there are only 3 interfaces (Built-In Ethernet, FireWire, and Airport) (the bottom thing on the left says daves-computer, it's the shell prompt). There is no third party device.

So that's one "lie" from the video.

Secondly, he explicitly mentioned the IP address at the beginning of the video. Why did he do this? The bug that apple found and he claimed to find was exploited when searching for networks, he didn't have to be connected to one. Which means there was no reason whatsoever for him to list an IP address.

And as you noticed, that IP is for the built-in airport card, which also supports his assertion there was a third party card was a lie.

He also seems to imply that the Mac Book was already connected to the dell (and that's why it had the IP address)

The other issue is if you look at the video in full, you can see that he gets access to the currently logged in user's account. Since the airport drivers run in kernel space, actually getting a hack to run would give him root access. Yet he doesn't since he creates files on the desktop of the logged in user.

So why is him having an IP address important? Well, if his badseed script simply logs in via ssh on the Mac Book, then he'd be able to do everything he said. In order to ssh in, he'd have to have the Mac Book on the network at a predetermined location (and he does).

So I posit that the entire thing is fake and he logged into the Mac Book normally and created a few files via ssh.

It might have been done to promote Errata security for Maynor  and separately to promote Johnny Cache's upcoming book.

I'm not really sure why they did it. Just that so far there is no evidence to support the idea that they actually found an exploit. Especially since they've refused to display publicly the claims they made in the video.

I'm as sick of this story as you probably are, but wanted to pass along this new piece of analysis of the original video. Apple's Airport stack has since been patched. Does anyone even care about this any more?

Jason D. O'GradyJason D. O'Grady is the editor of PowerPage.org, which has been publishing daily mobile technology news since December 1995. For disclosures on Jason's industry affiliations, click here or to view Jason's full profile click here.

Email Jason D. O'Grady

Subscribe to The Apple Core via Email alerts or RSS.

  • Talkback
  • Most Recent of 60 Talkback(s)
Looking forward to it
That's been the whole point here. Not that anyone is right or wrong, or a good person or a bad person, or that Macs are flawed or invulnerable. The point has been that it's difficult to believe extraordinary claims without concrete evidence proving they're true.... (Read the rest)
Posted by: tic swayback Posted on: 03/11/07 You are currently: a Guest | | Terms of Use
No offence Jason, but WTF happened to "Full-disclosure"???  Scrat | 03/06/07
Why not?  tic swayback | 03/06/07
both of your points.  Arm A. Geddon | 03/06/07
It probably..  dmaynor | 03/06/07
You are evil in the eyes of the zealot  NonZealot | 03/07/07
Wasn't it you that said  Rick_K | 03/07/07
It probably has to do with the fact alot of misinformation continue to be s  Rick_K | 03/07/07
Crappy  dmaynor | 03/07/07
You want to stab me in the eye with a lit cigarette or something?  Rick_K | 03/09/07
care to reply about these few links?  Arm A. Geddon | 03/07/07
Ok...  dmaynor | 03/07/07
in your reply?  Arm A. Geddon | 03/08/07
Huh?  dmaynor | 03/08/07
reponce to your "uh?"  Arm A. Geddon | 03/08/07
correction. in response to your "Huh?" (nt)  Arm A. Geddon | 03/08/07
Well...  zkiwi | 03/06/07
Wrong...  dmaynor | 03/06/07
So, why did you say  zkiwi | 03/06/07
Wrong...  dmaynor | 03/07/07
We have paid close attention  frgough | 03/07/07
Then it should be...  dmaynor | 03/07/07
re:dmaynor  frgough | 03/08/07
So, the...  zkiwi | 03/07/07
Wrong...  dmaynor | 03/07/07
In fact...  dmaynor | 03/07/07
The confusion  zkiwi | 03/07/07
To quote you...  zkiwi | 03/07/07
Hey. I'm a Mac user (by choice)  Rick_K | 03/07/07
Once again...  dmaynor | 03/07/07
You're the liar!  Rick_K | 03/09/07
Comment/questions  msalzberg | 03/07/07
re: Wrong...  Arm A. Geddon | 03/07/07
Good God.  Cayble | 03/07/07
In case  zkiwi | 03/07/07
true  Arm A. Geddon | 03/08/07
So tired of that strawman  tic swayback | 03/08/07
You have no cloths tic.  Cayble | 03/08/07
Sigh  tic swayback | 03/08/07
Drifting out of sight  frgough | 03/08/07
Your cracked. You don't even know me.  Cayble | 03/08/07
Say the title of the article real fast 3 times  mrlinux | 03/06/07
moron mayner  Arm A. Geddon | 03/06/07
UUhh..  dmaynor | 03/07/07
Really?  zkiwi | 03/07/07
UUhh..  dmaynor | 03/08/07
You do know  zkiwi | 03/08/07
Drop it! Please!  cakemusic | 03/08/07
There's that strawman again  tic swayback | 03/08/07
There's tic making a real strawman argument again.  Cayble | 03/08/07
Sadly, you're not one of those people  tic swayback | 03/08/07
Yup, their actions speak louder than words  NonZealot | 03/08/07
Well...  zkiwi | 03/08/07
Same old same old  tic swayback | 03/08/07
Be careful tic.  Rick_K | 03/09/07
Fraudulent?  georgeou | 03/09/07
Come on Jihad George...  Rick_K | 03/10/07
Evidence?  tic swayback | 03/10/07
Yes, just emailed him and he gave me permission to disclose  georgeou | 03/10/07
Looking forward to it  tic swayback | 03/11/07
You're misreading...  msalzberg | 03/10/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and