On TV.com: 2009's Most PIRATED TV Show
BNET Business Network:
BNET
TechRepublic
ZDNet

March 1st, 2007

Maynor demos MacBook Wi-Fi hijack, admits mistakes

Posted by Ryan Naraine @ 9:02 am

Categories: Apple, Exploit code, Hackers, Metasploit, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Wi-Fi security, Zero-day attacks

Tags: Black Hat, Apple Computer Inc., Apple MacBook, Wi-Fi, E-mail, Ryan Naraine

In Focus » See more posts on: Apple Security, Black Hat

Looking to put to rest one of the most bizarre vulnerability disclosure disputes in recent memory, hacker David Maynor offered an apology for mistakes made, provided a live demo of the controversial MacBook Wi-Fi takeover and promised to release e-mail exchanges, crash/panic logs and exploit code to clear his tarnished name.David Maynor with MacBook

Maynor kicked off a presentation at the Black Hat DC 2007 with a demo of the attack against a MacBook running Mac OSX 10.4.6, proving that he was able to crash the machine via a device driver flaw in Apple's AirPort Atheros.

He then ran the exploit against a fully patched MacBook to prove that Apple did fix the exact issue he reported, even if the company opted not to credit him, his co-presenter Jon "Johnny Cache" Ellch or his then employer [SecureWorks].

"I screwed up a bit [at last year's Black Hat in Las Vegas]. I probably shouldn't have used an Apple machine in the video demo and I definitely should not have discussed it a journalist ahead of time," Maynor said in an interview after his demo.


 
  Black Hat Gallery: Hackers discuss weaknesses in Wi-Fi drivers, RFID proximity devices and hardware-based forensics. Images in our gallery.  

 

"I made mistakes, I screwed up. You can blame me for a lot of things but don't say we didn't find this and give all the information to Apple.

"They claimed we had nothing to do with their patches but I'll release all the crash and panic logs that we gave to them. You can look at it and decide for yourself," Maynor said. "I'll give you crash/panic logs if you want."

The only difference from the 10.4.6 and 10.4.8 machines is the changes to the Airport code," he said, offering examples of e-mail exchanges he had with Apple's security response team discussing the severity of the threat. For legal reasons, Maynor said he could not share e-mails sent from his SecureWorks address.

He said the code, logs, e-mail exchanges will be published on the Errata Security blog.

Here are the slides from Maynor's presentation (PPT). 

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 200 Talkback(s)
Yes.
wink (Read the rest)
Posted by: Cayble Posted on: 07/20/07 You are currently: a Guest | | Terms of Use
What a joke  frgough | 03/01/07
And your point IS????  andrej770 | 03/01/07
That's OK  frgough | 03/01/07
His point is . . .  brian ansorge | 03/01/07
and your point?  Arm A. Geddon | 03/01/07
Maybe  Rick_K | 03/01/07
Henceforth, let the one-eyed smiley be the symbol for all Mac users  YinToYourYang-22527499 | 03/01/07
Your kind is beyond hope.  Cayble | 03/01/07
HWta I don't understand  Lettuce.Pickles | 03/06/07
What a Joke - Author or programmer?  palo905@... | 03/06/07
Oh boy - here we go.  ejhonda | 03/01/07
Ah the irony  tic swayback | 03/01/07
jumping the gun  code_Warrior | 03/01/07
It's real simple  Rick_K | 03/01/07
and so...  Badgered | 03/01/07
I just don't get it  tic swayback | 03/01/07
These people are  Prime Detailer | 03/01/07
Plus, the other givaway is  John Zern | 03/01/07
Nice try  Cayble | 03/01/07
It's all still true  tic swayback | 03/02/07
You went so far as to call Maynor a liar.  ShadeTree | 03/02/07
Did I?  tic swayback | 03/02/07
Well, we know the truth about Apple now dont we. Your next.  Cayble | 03/02/07
Do we?  tic swayback | 03/03/07
Ok, hang tight, Ill get what you ask for.  Cayble | 03/02/07
This is you. Live with it. Read on tic  Cayble | 03/02/07
Thank you so much!!  tic swayback | 03/03/07
hmm  Badgered | 03/05/07
Don't read to selectively, what he says is...  Cayble | 03/07/07
That's how I remember it  tic swayback | 03/05/07
Don't apologize, I don't care you think Apple is a Weasel  Cayble | 03/09/07
Don't apologize, I don't care you think Apple is a Weasel  Cayble | 03/09/07
Don't apologize, I don't care you think Apple is a Weasel  Cayble | 03/09/07
and your point is?  Arm A. Geddon | 03/01/07
Actually, he / she did...  Scrat | 03/02/07
have to disagree  Arm A. Geddon | 03/02/07
And your point is that he is an idiot because you call him one - NT  raycote | 03/02/07
Entertaining posts, all of them.  ejhonda | 03/02/07
Zero credibility  tic swayback | 03/01/07
now now tic...we must wait for George  Monkey_MCSE | 03/01/07
I gues  Rick_K | 03/01/07
My Guess  mrlinux | 03/01/07
Could be  Rick_K | 03/01/07
Those emails he is releasing now are legit  georgeou | 03/01/07
Yee-hah  frgough | 03/01/07
Go Ou Go  YinToYourYang-22527499 | 03/01/07
Message has been deleted.  Rick_K | 03/01/07
Personal attacks like that don't belong here  georgeou | 03/01/07
You know.....  xuniL_z | 03/01/07
re: Apple zealot's tone here is scary man  Arm A. Geddon | 03/01/07
The Rotten Apple need  Mectron | 03/01/07
The Wackos are out to play in force (APPLE JACKS)  Cayble | 03/01/07
so did you light your cigarette yet? (nt)  Arm A. Geddon | 03/01/07
The Apple guy  Mectron | 03/01/07
Date stamped  jimothy@... | 03/01/07
Sounds like you're ignorant about date stamp technology  georgeou | 03/01/07
As the other guy implied  zkiwi | 03/02/07
Those emails he is releasing now is legit....  mrlinux | 03/02/07
Zero credibility just about says it!  ShadeTree | 03/01/07
Where's that proof? I'll look at it  tic swayback | 03/01/07
Sorry Tic, but your busted  Scrat | 03/02/07
No, it wasn't  tic swayback | 03/02/07
Revisionist history!  ShadeTree | 03/02/07
If...  zkiwi | 03/02/07
Rose colored glasses  tic swayback | 03/02/07
Apple colored Glasses, are so shameful  Cayble | 03/02/07
Once again, you lack proof  tic swayback | 03/03/07
Denial?  zkiwi | 03/08/07
Re: Zero credibility  tick tock | 03/01/07
Exactly  tic swayback | 03/01/07
Wow, that sure is a nice admission  georgeou | 03/01/07
George...  zkiwi | 03/01/07
Isn't it classic?  NonZealot | 03/01/07
the guy claimed to have spilled milk..but woun't let anyone in to see...  doctorSpoc | 03/01/07
Don't waste your time  tic swayback | 03/02/07
and while Apple was saying that he didn't spill the milk  Badgered | 03/02/07
Sigh  tic swayback | 03/01/07
Idiot? More personal attacks from someone proven completely wrong  georgeou | 03/01/07
Pot, Kettle, Black  Robert Crocker | 03/02/07
Sorry, you deserve nothing  tic swayback | 03/02/07
Tsk, tsk, tsk!  ShadeTree | 03/02/07
My conditions have not been met  tic swayback | 03/02/07
So, Shadetree  zkiwi | 03/02/07
Crocker, you are a Crock. In case you didnt notice, that was personal.  Cayble | 03/02/07
GOOD LORD IN HEAVEN!! THE POT CALLS THE KETTLE BLACK!!  Cayble | 03/01/07
Where is your proof?  tic swayback | 03/02/07
in agreement with tic...  Monkey_MCSE | 03/02/07
Ok, I understand, you cant read..I wont make fun, but you should learn.  Cayble | 03/02/07
Still no proof?  tic swayback | 03/03/07
Look at the zealots in a tizzy!!  NonZealot | 03/01/07
and the farce himself speaks  Monkey_MCSE | 03/01/07
"Ou Koolaid"  brian ansorge | 03/01/07
Zealots in a tizzy!!  Rick_K | 03/01/07
idiot # 3  Arm A. Geddon | 03/01/07
POT CALLING THE KETTLE BLACK AGAIN  Cayble | 03/01/07
a little angry are we?  Arm A. Geddon | 03/01/07
Ha! You have no idea.  Cayble | 03/02/07
Winners?  tic swayback | 03/03/07
Yes.  Cayble | 07/20/07
Why does having an Opinion make you a Zelot?  Atilla the Snail | 03/01/07
See. You are not a Zelot  John Zern | 03/01/07
It Doesn't... Unless....  Mr_Wizard | 03/01/07
I guess you are new to this debate.  Cayble | 03/02/07
HE CRASHED AN APPLE COMPUTER WITH WI FI  BALTHOR | 03/01/07
Crashing versus "owning"  tic swayback | 03/01/07
That was the whole premise  samcurry | 03/01/07
Apples Versus Oranges...  Cayble | 03/01/07
Ooopsy  tic swayback | 03/02/07
That dog don't hunt.  ShadeTree | 03/02/07
Why should he do anything?  zkiwi | 03/02/07
So you cant read either.  Cayble | 03/02/07
No  zkiwi | 03/03/07
what is there to admit?  Monkey_MCSE | 03/02/07
Why?  tic swayback | 03/02/07
And the answer is  TonyMcS | 03/01/07
Wow, you really sound bitter  tic swayback | 03/01/07
"and the answer is . . . "  brian ansorge | 03/01/07
idiot #4  Arm A. Geddon | 03/01/07
You have serious mental issues  Cayble | 03/01/07
grab a brain  Arm A. Geddon | 03/01/07
You are nothing more then a grade school name caller. Read this if you dare  Cayble | 03/02/07
and you haven't called people names?  Arm A. Geddon | 03/03/07
One jerk claimed there has never been an Apple virus  Cayble | 03/01/07
Swiss Cheese  Mectron | 03/01/07
Swiss Cheese of the Brain  Jesster | 03/02/07
crash vs. own  dmaynor | 03/01/07
excuses, excuses, excuses.  Arm A. Geddon | 03/01/07
If it gives you the ability  zkiwi | 03/01/07
a few links for you  Arm A. Geddon | 03/01/07
?  Robert Crocker | 03/02/07
Obvious questions  tic swayback | 03/02/07
Vicious orchestrated assault on MacBook wireless researchers  Arm A. Geddon | 03/01/07
Please  Mectron | 03/01/07
Ummm..remind me to get my tuition back  Cayble | 03/02/07
re: tuition  Arm A. Geddon | 03/03/07
the story as it first appeared...  Arm A. Geddon | 03/03/07
oops  Arm A. Geddon | 03/03/07
Message from future  jimothy@... | 03/01/07
And you're completely ignorant of digital time stamps  georgeou | 03/01/07
Re: Timestamp  gtdavies33@... | 03/01/07
I said digital cryptographic time stamps  georgeou | 03/02/07
super secret digital timestamps?  g_ludlow | 03/02/07
Ever heard of setting the date/time back on your computer  mrlinux | 03/02/07
Ever heard of the timestamp on mail is provided ...  ShadeTree | 03/02/07
And, if you had a clue...  zkiwi | 03/02/07
Maybe because his contract with Secureworks ...  ShadeTree | 03/02/07
Actually the sending mail server sets the time  mrlinux | 03/02/07
So  zkiwi | 03/02/07
Re Timestamp  gtdavies33@... | 03/02/07
If that makes you feel better  jimothy@... | 03/02/07
Relevance?  sdbryan@... | 03/03/07
Hijacked or Crashed  gtdavies33@... | 03/01/07
The claim was...  Rick_K | 03/02/07
Here's the link to the original story...  msalzberg | 03/03/07
Good Lord  Mr. Big | 03/01/07
funny thing is that the vast majority of responses are windows users...  doctorSpoc | 03/01/07
They're not obsessed. They swear!!!  tic swayback | 03/02/07
Say....  James T. Kirk | 03/02/07
My time comes in brief flashes  tic swayback | 03/02/07
Simple  James T. Kirk | 03/02/07
Fair enough  tic swayback | 03/02/07
Hypochrite!  ShadeTree | 03/02/07
Prove it  tic swayback | 03/02/07
The reason we care is because Apple...  ShadeTree | 03/02/07
then by all means shade...  Monkey_MCSE | 03/02/07
Pot, Kettle, Black  tic swayback | 03/02/07
It makes him  Rick_K | 03/02/07
Ah. Sounds like tic is actually waking up.  Cayble | 03/02/07
You still haven't proven my arguments wrong  tic swayback | 03/03/07
Just so as you know  zkiwi | 03/03/07
You are just plain Ill informed, really Ill informed.  Cayble | 03/04/07
You only have one problem  zkiwi | 03/04/07
what Apple said....  bkwatch | 03/04/07
Can you find the word "gullible" in your dictionary?  tic swayback | 03/04/07
Nice post  NonZealot | 03/04/07
What a pile of really poor excuses. An absolute disgrace.  Cayble | 03/10/07
thoughts on choices and zealotry...  jjarman | 03/06/07
Who Cares?  mag008 | 03/02/07
Irony?  jerry@... | 03/02/07
WEEEEEE!!!! Look at all the Mac zealots!!!  NonZealot | 03/02/07
Sorry  zkiwi | 03/02/07
It's a shame  NonZealot | 03/03/07
Humour?  zkiwi | 03/03/07
HELLO MICROSOFT ZEALOT!!!  nix_hed | 03/03/07
DOH!  nix_hed | 03/03/07
Same old same old  tic swayback | 03/03/07
Broadcom or Atheros  bkwatch | 03/03/07
hrrmm..  dmaynor | 03/05/07
drivers  bkwatch | 03/05/07
Nope...  dmaynor | 03/05/07
Hrm.  dmaynor | 03/05/07
And...  zkiwi | 03/05/07
Wrong...  dmaynor | 03/07/07
On reflection  zkiwi | 03/07/07
You've been PWNED!!  NonZealot | 03/07/07
No  zkiwi | 03/07/07
Oh come on...  dmaynor | 03/07/07
Here's one for you  zkiwi | 03/07/07
Oh come on...  dmaynor | 03/07/07
Correct me if I'm wrong  SikosisZDNet | 03/06/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here