On TV.com: Dollhouse CANCELED, What Went Wrong?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Aug 2, 2006 10:17:00 PM

LAS VEGAS--Flaws in the software that runs wireless-networking hardware could let an attacker break into a PC over Wi-Fi, security researchers warned Wednesday.

An attacker could gain complete control over a laptop by sending malformed network traffic to a vulnerable computer, David Maynor, a senior researcher at security service provider SecureWorks, said in a presentation at the Black Hat security event here.

Maynor, along with researcher Jon "Johnny Cache" Ellch, showed a video of a successful attack on an Apple Computer MacBook. However, the attack is possible also on other computers, both laptops and desktops, and not just MacBooks, the researchers said.

Click here to Play

Video: Breaking into a MacBook
Flawed Wi-Fi drivers can expose PCs

"These driver flaws are pretty common," Maynor said. Researchers are starting to find those bugs as they shift their focus from hunting for operating system flaws to exploitable errors in drivers and in applications, he said. The reason for the shift is that operating systems are becoming increasingly more secure, he added.

There is no immediate threat to the millions of laptop-toting wireless users. Maynor and Ellch are not releasing the details of their attack, and they deliberately did not show a live demonstration to prevent anyone from copying their attack.

"People who should be worrying about this are the hardware and software makers, so this doesn't make it into the mainstream," Maynor said.

Wi-Fi researchers at Black Hat

Consumers should be streetwise when using their laptop by not connecting to networks they aren't sure they can trust and by disabling the wireless radio when it is not needed, Maynor said. "There is no need to run out and rip your wireless card out of your laptop, but you should take precautions," he said.

With their Black Hat talk, Maynor and Cache hope to wake up makers of buggy drivers. "We want to educate developers and hardware makers about this threat before it becomes a wide-scale issue," Maynor said. "We're not talking about something that people don't know about, but a lot of people don't know the severity."

Driver flaws have been getting more attention recently. Microsoft, for example, is readying tools for driver developers to scan their code for common vulnerabilities. According to a recent experiment by Intel flaws in driver software may be worrisome and a potentially serious threat, but there is no need for alarm yet.

To launch an attack using the Wi-Fi driver flaws, the would-be intruder needs to be within about 100 feet, or 30 meters, of its target--the typical reach of a Wi-Fi signal. However, new wireless technologies are extending this range significantly and could increase the threat, so new bugs will likely be found, Maynor said.

To facilitate an attack, the researchers found a way to remotely identify the wireless driver that a particular computer is running, Maynor said. Then malicious data traffic needs to be crafted and sent to the vulnerable PC. A flaw in the way that computer processes the data subsequently causes the compromise, he said.

Coincidentally, Intel late last week issued fixes for flaws in software that controls its popular Centrino wireless hardware. These patches are not related to the Black Hat research, Maynor said. The researchers have worked with hardware and software makers on the issue of Wi-Fi drivers, but not with Intel, he said.

Black Hat runs until Thursday.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 21 Talkback(s)
They may have but they don't ship with any adapters.
I have 2 each Linksys, Buffalo, D-Link, Netgear and Belkin USB adapters on my desk this very minute. None have Mac drivers.

But enough of this nonsense! Read it and weep "Apple"oligist -- (Read the rest)
Posted by: ShadeTree Posted on: 08/03/06 You are currently: a Guest | | Terms of Use
So even with--  Grayson Peddie | 08/02/06
The rest of the story...  crash89 | 08/03/06
It may sound sensational to you ...  ShadeTree | 08/03/06
Not rationalization  ITGuy04 | 08/03/06
They used a third party piece of hardware but ...  ShadeTree | 08/03/06
You're wrong.  crash89 | 08/03/06
I am not wrong!  ShadeTree | 08/03/06
You made my point..  crash89 | 08/03/06
No your point was that it was 3rd party so ...  ShadeTree | 08/03/06
Read my post original again....  crash89 | 08/03/06
You can't buy a Macbook without Airport  j.m.galvin | 08/03/06
Yes, seems redundant.  olePigeon | 08/03/06
Or unless the integrated one failed ...  ShadeTree | 08/03/06
Yes and No.  olePigeon | 08/03/06
Actually since it is a driver vulnerability ...  ShadeTree | 08/03/06
Better Tell Belkin and/or RALink  ITGuy04 | 08/03/06
They may have but they don't ship with any adapters.  ShadeTree | 08/03/06
You sound extremely defensive!!  NonZealot | 08/03/06
Breaking into cars  Prognosticator | 08/03/06
Big deal-  Nradv | 08/03/06
Apple had leaned on Maynor and Ellch pretty hard  bka1959 | 08/03/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline