Slashdot Mirror


Less Than a Minute to Hijack a MacBook's Wireless

Kadin2048 writes "As reported by Ars Technica and the Washington Post, two hackers have found an exploitable vulnerability in the wireless drivers used by Apple's MacBook. Machines are vulnerable if they have wireless enabled and are set to connect to any available wireless network, fairly close to their default state, and the exploit allows an attacker to gain "total access" -— apparently a remote root. Although the demo, performed via video at the BlackHat conference, takes aim at what one of the hackers calls the "Mac userbase aura of smugness on security," Windows users shouldn't get too smug themselves: according to the Post article, "the two have found at least two similar flaws in device drivers for wireless cards either designed for or embedded in machines running the Windows OS." Ultimately, it may be the attacks against embedded devices which are the most threatening, since those devices are the hardest to upgrade. Currently there have not been any reports of this vulnerability 'in the wild.'" According to this story at ITwire.com, they were able to exploit Linux and Windows machines, too. (Thanks to Josh Fink.)

16 of 390 comments (clear)

  1. Mac Users by Ramble · · Score: 5, Funny

    And in the background we hear 1000 Mac users screaming in horror...

    --
    "Oh boy"
    1. Re:Mac Users by cbiltcliffe · · Score: 5, Funny

      What, you mean all of them? Come on! I'm sure a few of them wouldn't have read this story!

      (For the humour challenged among you, this is a joke. I know there are a lot more than 1000 Mac users. Only stupid mods mod jokes as trolls and flamebait.)

      --
      "City hall" in German is "Rathaus" Kinda explains a few things......
    2. Re:Mac Users by Anonymous Coward · · Score: 0, Funny

      Wow! I didn't know there were that many Mac users.

  2. That's ridiculous by Spy+Handler · · Score: 4, Funny

    My Powerbooks is safe. Apple is so much more secure than ^.#$ pwned u n00b wahaha

    1. Re:That's ridiculous by Ohreally_factor · · Score: 4, Funny

      Dammit! I was hoping that the fact that I was still on a G4 PB would preserve my smugness! I guess this means I'm going to have to install an cat5 into the bathroom with a port next to the throne.

      C'mon, don't tell me you've never taken your laptop to the "reading room".

      --
      It's not offtopic, dumbass. It's orthogonal.
    2. Re:That's ridiculous by Mister+Whirly · · Score: 5, Funny

      "How do you know exactly? Viruses, trojans, and rootkits should be undetectable."

      With "undetectable rootkit detection software", duh....
      Unless the rootkit has an "undetectable rootkit detection software" detector and tries to disable it, then you need "undetectable rootkit detection software detector detector software" to disable the rootkit's detector - no big deal..

      --
      "But this one goes to 11!"
    3. Re:That's ridiculous by Anonymous+Freak · · Score: 2, Funny

      Nah, I wouldn't abuse my Mac that way. I use my PC notebook on the throne.

      --
      Another non-functioning site was "uncertainty.microsoft.com."
      The purpose of that site was not known.
  3. But... by jo_ham · · Score: 3, Funny

    Does this exploit run on Linu......

    never mind.

  4. A Mac Exploit by KodeSlut · · Score: 5, Funny

    My reality has been shattered. Macintosh computers have been found to be less than perfect! Time to install WinXP.

    --
    - i'll get me coat! -
  5. Linux Wireless by hyfe · · Score: 5, Funny
    Does this exploit run on Linu......
    Nobody knows, they couldn't get wireless up and running on it.

    Requests for testing have been sent to the guy in California who were rumoured to have gotten it running though.

    --
    "" How about taking the safety labels off everything, and let the stupidity-problem solve itself? """
  6. Re:3rd party by Anonymous Coward · · Score: 1, Funny

    "What's next? Writing the exploitable drivers yourself?"

    LOL - that would be part of the definition of the open source movement wouldn't it?

  7. Re:Smug Mac users? by Billosaur · · Score: 2, Funny

    Many will begin by saying "This is not a virus" or noting you need proximity to take advantage of this flaw.

    Well, they would be saying that, if someone hadn't gone and corrupted their MacBooks via wireless exploit...

    --
    GetOuttaMySpace - The Anti-Social Network
  8. Re:Third party wireless card? by phaxkolumbo · · Score: 3, Funny
    why would anyone use a third-party card?

    Because someone is running a pirated version of OS X on a "beige" PC?

  9. Re:Actually, your Powerbook probably IS safe! by elrous0 · · Score: 4, Funny
    Thank God, for a second there I thought my status symbol might be fading.

    It was bad enough when all this "oil crisis" nonsense ruined my H2 Hummer for me. Overnight I became "guy who's supporting terrorism." It was so much better when I was just "guy with a small penis."

    -Eric

    --
    SJW: Someone who has run out of real oppression, and has to fake it.
  10. Ha! I've done even better! by Quiet_Desperation · · Score: 2, Funny

    I disintegrated a car with my mind!

    I have it on video!

    Of course, I weakened the car's frame with a blowtorch... and the car was packed with explosives... and there was the whole "lit fuse" thing... but still! I disintegrated a car with my mind. Some anonymous guy with a video says so!

  11. Re:Uh by i_am_profiled · · Score: 3, Funny

    This is exactly what the orignal smug comment was aimed at.

    Should be modded +5 Shining Example.