Whole Network Emerging Tech Fixed-Mobile Co... Mobile RFID Ultrawideband Wi-Fi WiMax/WiBro

 

Mac Hack Part III: Macs Were Vulnerable After All...

Filed in archive Wi-Fi by jeff goldman on September 21, 2006

Mac Hack Part III: Macs Were Vulnerable After All...

Macworld's Jim Dalrymple reports that Apple today released a Security and AirPort update for Mac OS X to fix vulnerabilities in the company's wireless drivers.


According to Apple, the vulnerabilities were found in an internal audit of the software drivers, but are not open to any known exploits.


"The internal audit came as a result of claims by a senior researcher at SecureWorks that said he had revealed a vulnerability in Apple's MacBook wireless software driver that would allow him to take control of the machine," Dalrymple writes. "SecureWorks later clarified its position and said it had used a third-party driver and not Apple's driver."


Apple spokesman Anuj Nayar says SecureWorks never demonstrated any vulnerabilities in the Mac drivers. "They did not supply us with any information to allow us to identify a specific problem, so we initiated an internal audit," he says.


Still, Dalrymple's description of the vulnerability sounds a lot like the one SecureWorks found: "Two separate stack buffer overflows exist in the AirPort wireless driver's handling of malformed frames," he writes. "An attackerlinks in local proximity may be able to trigger an overflow by injecting a maliciously crafted frame into a wireless network. When the AirPort is on, this could lead to arbitrary code execution with system privileges."


SecureWorks wouldn't comment for Dalrymple's article, but something tells me this isn't anywhere NEAR the end of the story...


UPDATE: Wi-Fi Planet's Eric Griffith has an excellent summary of the issues here.







Permalink: Mac Hack Part III: Macs Were Vulnerable After All...
Tags: SecureWorks  Mac  Apple  exploit  security  buffer  overflow  wireless  WiFi  WiFi  Black  Hat  MacBook  vulnerab 

Trackback: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/37049





RSSrss   | See all blog subscribe options
Google google   |   What is RSS?
Yahoo! yahoo
Addthis Subscribe using any feed reader!
Bloglines Bloglines
Newsletter
Grouptivity

Use the search to look for other interesting posts



 
  • Advertise with us

  • Learn more about our advertising options or email advertising - at - creative-weblogging.com or give us a call at +1 (650) 331 4900.
  • Marketplace



  • Testimonials

  • 'I would highly recommend you to this well written and informative site.'
Subscribe to this blog on your phone




  • Other blogs in the same channel in the Creative Weblogging Network







 

Tagcloud: 4G 700 MHz Bluetooth Emerging Tech Fixed-Mobile Convergence Mobile RFID Sponsored Posts Ultrawideband Wi-Fi WiMax/WiBro WirelessHD