Programmers Claim to Find Common Vulnerability in Mac, Windows Laptops
August 2nd, 2006 at 3:00 PM - News by Brad Cook
Jon "Johnny Cache" Ellch and David Maynor on Wednesday at the Black Hat 2006 conference in Las Vegas demonstrated a common wireless security flaw in Windows and Mac laptops. During their presentation, a video of which is on Brian Krebsi blog on the Washington Post Web site, they wirelessly connected a MacBook to a Dell and used the latter to take over control of the former. Mr. Maynor noted, however, that the flaw he exploited is a third party one that affects both Windows and Mac laptops; it is not inherent to Mac OS X.
Mr. Maynor told Mr. Krebs that they opted for a video version of their demonstration "because of the possibility that someone in the audience could intercept the traffic sent to a potentially live target and deconstruct the attack -- possibly to use the exploit in the wild against other MacBook users," the columnist wrote.
Mr. Maynor and Mr. Ellch said that the exploit doesnit require the laptop in question to be connected to a network. It simply has to have its wireless card turned on. In the video, Mr. Maynor turned the Dell laptop into a computer-to-computer wireless access point and then connected the MacBook to it via a third-party wireless card, not Appleis AirPort Extreme technology, although he told Mr. Krebs that the flaw exists there, too. He then took over the Mac, creating and deleting files on the desktop to show that he had access to it.
While Mr. Maynor was bothered by what he called the "Mac user base aura of smugness on security," he told Mr. Krebs that they hadnit set out to pick on Macs specifically. He said that he and Mr. Ellch have been in contact with Apple, Microsoft and third party wireless card vendors on fixes for the problem. He told Mr. Krebs that "had leaned on [them] pretty hard not to make this an issue about the Mac drivers -- mainly because Apple had not fixed the problem yet."
Recent Headlines - Updated February 10th
- Tue, 9:09 PM
- Games - Gameloft’s GT Racing Motor Academy Arrives at App Store
- 6:27 PM
- iPad - Apple Job Posting Hints at a Camera in Future iPads
- 6:22 PM
- Product News - Apple Releases Digital Camera RAW Compatibility Update 3.0
- 6:18 PM
- Product News - Apple Updates iLife ‘09 with Aperture 3 Support, Slideshow Performance
- 4:53 PM
- News - Google Introduces “Buzz” Social Information Sharing Service
- 4:19 PM
- Just a Thought - iPad: A Reason For Being
- 3:28 PM
- News - Google Lowers Nexus One “Equipment Recovery Fee” to $150
- 2:27 PM
- Deal Brothers - Refurbished 13” MacBook 2.13GHz Intel Core 2 Duo: $749
- 1:31 PM
- Jeff Gamet's Blog - Macworld Expo: It’s Our Show, Not Apple’s
- 10:38 AM
- Quick Look Review - Texas Tea for the iPhone and iPod touch
- 10:25 AM
- News - Apple Rolls Out Aperture 3 Video Tutorials
- 10:00 AM
- Hot Forum Topic - Backing Up Your iPhoto Library
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
RamJet Memory: Mac Pro 8GB Kit $275.99, Mac Pro 4GB Kits $145.99! Sale on MacBook and MacBook Pro 8GB kits $459.99! MacBook, MacBook Pro, iMac Mac mini 4GB Kits for $113.99! 1TB SATA Hard Drives for $109.99! Click here- If you own a car, you need CarMD! Catch problems, estimate repairs and more. Now for Mac. $98.99 at www.CarMD.com Save $10 with code TMO1.
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.




