Re: AUGD: Hijacking a Macbook in 60 Seconds or Less
Re: AUGD: Hijacking a Macbook in 60 Seconds or Less
- Subject: Re: AUGD: Hijacking a Macbook in 60 Seconds or Less
- From: "Mr. David Stempnakowski" <email@hidden>
- Date: Thu, 3 Aug 2006 17:35:50 +0200
First let me say Matt is right on target. I just completed a Computer Network Attack/Computer Network Defense course and the instructor was a big advocate of Macs. That said, there are exploits for them but you pretty much have to know what you're doing.
Like Matt said, which evidently has been missed, this hack does use the Apple supplied Airport cards which are built in. But Apple doesn't manufacture their own chips for use in these cards - they use third parties. This hack exploits the particular chip set that Apple (and other manufacturers) use. This is why, again like Matt said, this is not Mac specific.
In the article I read on CNet, they said it was not demonstrated live because they didn't want someone sitting in the audience to deconstruct the attack. All you'd have to do is sit out there with a computer and run Kismet (or another wireless packet sniffer) and capture all the packets, then analyze them and figure out how they did it. Very time consuming and requires a lot of knowledge of how packets are constructed and what the payload looks like, etc. Like Matt said (again) it requires some sophistication. I doubt that it's something you'll find in metasploit anytime soon. In other words, not coming to a script kiddie near you any time soon, if ever. I'm not certain, but this may have already been addressed in the latest security update released this week.
I'm guessing they probably could have just as well performed this hack regardless of the peer to peer connection. And it could be done on any laptop using the particular chipset. The fact that it is a Mac just grabs headlines. It doesn't invalidate the exploit. See Matts other post, he does a good job explaining. David Stempnakowski Mac/Solaris System Administrator
There are only 10 types of people in this world... Those who understand binary and those who don't
|
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Augd mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden