On TV.com: 2009's Most PIRATED TV Show
BNET Business Network:
BNET
TechRepublic
ZDNet

August 3rd, 2006

MacBook wireless hack dismissed (Updated 2x)

Posted by Jason D. O'Grady @ 8:27 am

Categories: Hack, MacBook, Security, WiFi

Tags:

blackhatlogo.gifEarlier today (see below) I posted a story about about two hackers from the Black Hat conference in Las Vegas and how they supposedly demonstrated how to exploit a vulnerability in Apple’s wireless device driver to remotely access and control a MacBook over a network. The story was based, in part, on a blog entry by Brian Krebs at the Washington Post.

As it turns out the hack described does not apply to MacBooks as it relies on third-party wireless hardware rather than the wireless cards supplied by Apple. FTA: "Maynor said the MacBook used in the demonstration was not using the wireless gear that shipped with the computer."

The duo appear to have singled out Apple because of what Maynor called the "Mac user base aura of smugness on security." He goes on to say:

"We’re not picking specifically on Macs here, but if you watch those ‘Get a Mac’ commercials enough, it eventually makes you want to stab one of those users in the eye with a lit cigarette or something"

Um ok, David.

MacBook users can safely go back to what they were doing.

UPDATE 2: The Washington Post has updated their original post with the actual video from the conference.

ORIGINAL POST, AUGUST 3, 2006, 5:00 a.m. PST:

Title: MacBook hacked in less than 60 seconds 

In a session called Device Drivers at the Black Hat conference in Las Vegas Jon "Johnny Cache" Ellch and David Maynor demonstrated how to exploit a vulnerability in a wireless device driver to remotely access and control a MacBook over a network. They did it by targeting a specific security flaw in the MacBook’s wireless "device driver." The hacking duo also claim that the exploit works with at least two Windows powered machines.

According to a blog entry by Brian Krebs at the Washington Post:

One of the dangers of this type of attack is that a machine running a vulnerable wireless device driver could be subverted just by being turned on. The wireless devices in most laptops — and indeed the Macbook targeted in this example — are by default constantly broadcasting their presence to any network within range, and most are configured to automatically connect to any available wireless network.

Because the hack is driver dependent Ellch talked up a new tool he’s developing that can scan and determine the chipset and driver version of a remote wireless device. The tool already recognizes 13 different wireless device drivers and lists their operating system and firmware version.

The good news is that there’s no immediate threat to wireless users. Maynor and Ellch are not releasing the details of their attack to the public and they gave the demo on videotape for fear that a creative hacker in the audience could packet sniff the attack and using it for malicious purposes.

Apple’s wireless device drivers are created by Atheros who also produces drivers for a number of other manufacturers. No word yet on whether the duo will share their hack with manufacturers of vulnerable machines, like Apple.

Jason D. O'GradyJason D. O'Grady is the editor of PowerPage.org, which has been publishing daily mobile technology news since December 1995. For disclosures on Jason's industry affiliations, click here or to view Jason's full profile click here.

Email Jason D. O'Grady

Subscribe to The Apple Core via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 29 Talkback(s)
"Leaned on", eh?
I wonder if Apple prefers rubber truncheons? Or, maybe
electrical devices? Perhaps they like to get started with a nice,
clean gunshot to the knee to get everyone's attention?

Could w... (Read the rest)
Posted by: MTMacPhee Posted on: 08/04/06 You are currently: a Guest | | Terms of Use
It would appear that the lack of exploits ...  ShadeTree | 08/03/06
It would appear that the lack of intelligent discussion emanating  michael_t | 08/03/06
Try to use smaller words that you understand ...  ShadeTree | 08/03/06
They DID NOT hack the Airport Card  V-Train | 08/03/06
Makes for a GREAT headline though!  crash89 | 08/03/06
Since third party network cards don't ....  ShadeTree | 08/03/06
Uh, no  V-Train | 08/03/06
I disagree  crash89 | 08/03/06
Still not right.  Win3.1 | 08/03/06
What if the built in card didn't work?  ShadeTree | 08/03/06
Now you're reaching...  crash89 | 08/03/06
Read bka1959's post and then ....  ShadeTree | 08/03/06
Keep stretching that arm farther... (nt)  el1jones | 08/03/06
Err...  Win3.1 | 08/03/06
It was a USB card  crash89 | 08/03/06
Maybe because the Apple wireless driver ...  ShadeTree | 08/03/06
Apologies  Jason D. O'GradyZDNet Moderator | 08/03/06
You may want to withdraw your ...  ShadeTree | 08/03/06
Please remove the space before ...  ShadeTree | 08/03/06
I accept and understand the apology, thanks...  el1jones | 08/03/06
Not accurate?  NonZealot | 08/03/06
Please watch the video before posting such statements...  el1jones | 08/04/06
And I doubt you read the update  NonZealot | 08/04/06
Blame the correct problem.  m_holley | 08/03/06
Exactly (nt)  el1jones | 08/04/06
Maybe  Qbt | 08/04/06
Apple had leaned on Maynor and Ellch pretty Hard  bka1959 | 08/03/06
Can you imagine  Qbt | 08/04/06
"Leaned on", eh?  MTMacPhee | 08/04/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here