“If you want to grab the attention of a roomful of hackers, one sure fire way to do it is to show them a new method for remotely circumventing the security of an Apple Macbook computer to seize total control over the machine. That’s exactly what hackers Jon “Johnny Cache” Ellch and David Maynor plan to show today in their Black Hat presentation on hacking the low-level computer code that powers many internal and external wireless cards on the market today,” Brian Krebs reports for The Washington Post.
Krebs reports, “The video shows Ellch and Maynor targeting a specific security flaw in the Macbook’s wireless ‘device driver,’ the software that allows the internal wireless card to communicate with the underlying OS X operating system. While those device driver flaws are particular to the Macbook — and presently not publicly disclosed — Maynor said the two have found at least two similar flaws in device drivers for wireless cards either designed for or embedded in machines running the Windows OS. Still, the presenters said they ultimately decided to run the demo against a Mac due to what Maynor called the ‘Mac user base aura of smugness on security.'”
“‘We’re not picking specifically on Macs here, but if you watch those ‘Get a Mac’ commercials enough, it eventually makes you want to stab one of those users in the eye with a lit cigarette or something,’ Maynor said. ‘The main problem here is that device drivers are a funny mix of stuff put together by hardware and software developers, and these guys are often under the gun to produce the code that will power products that the manufacturer is often in a hurry to get to market,'” Krebs reports.
Krebs reports, “Maynor said he and his colleague opted in favor of a videotaped demonstration versus a live one because of the possibility that someone in the audience could intercept the traffic sent to a potentially live target and deconstruct the attack — possibly to use the exploit in the wild against other Macbook users.
“Apple — like many computer manufacturers — outsources the development of its wireless device drivers to third parties. In Apple’s case, the developer in question is Atheros, a company that devises drivers for a number of different wireless cards, each designed with drivers specific to the operating systems on which they will be used,” Krebs reports. “Maynor and Ellch also found two different device driver flaws for wireless products aimed at Windows systems. This is notable because it points out a security loophole in the way that Microsoft has traditionally processed device drivers.”
Krebs reports, “Maynor said he and Ellch have been in contact with Apple, Microsoft and other companies responsible for vetting the device drivers that power the embedded or third-party wireless card devices meant for those systems, and that both companies are working with wireless card vendors and original equipment manufacturers (OEMs) to remedy the problems. Assuming the wireless device driver makers affected by these flaws fix the problems, it may be an uphill battle for those vendors to find an easy way for users to upgrade that software.”
Krebs reports, “I should note here that while the bad guys may or may not have known about these security weaknesses for some time, there is not a single shred of evidence that these flaws have been exploited ‘in the wild’ (as security companies like to say). That said, it might not be terrible idea to take advantage of the button your laptop that allows you to turn off the machine’s constant search for wireless networks when you’re not actively trying to go online.”
Full article here.
MacDailyNews Take: Those “Get a Mac” commercials are really getting under some people’s skin. Good.
Related MacDailyNews articles:
Symantec researcher: At this time, there are no file-infecting viruses that can infect Mac OS X – July 13, 2006
Sophos: Apple Mac OS X’s security record unscathed; Windows Vista malware just a matter of time – July 07, 2006
Sophos Security: Dump Windows, Get a Mac – July 05, 2006
Apple: ‘Get a Mac. Say ‘Buh-Bye’ to viruses’ – June 01, 2006
Apple Macs and viruses: Fact vs. FUD – May 26, 2006
Videotaped. Sounds fishy to me.
holy shit
my smugness just took a big hit in the groin
But if those commercials prompt a round of Mac attacks that actually do work, then not so good.
What goes around comes around!
External coders are no excuse!!!
At work Apple!!!
hmmm … my guess is that apple will fix this pronto and we’ll still be able to bask in a (realtively) ‘sploit free world, while M$ aficionados continue to fester in their digital petri dishes.
Bet this will garner a boatload of attention. Maybe Apple should do its own programing for wireless.
Good. When Apple releases the patch for this tomorrow I can resume being smug.
You know, it shouldn’t be long before one of these guys that likes to publish malicious operating system exploits finds themselves in big legal trouble.
They want to ‘stab in the eye’? C’mon. We’re hovering near encitement to violence with statements like that. Combine that with the public demonstration of a malicious hack? Gettin’ dicey, no?
La di dahdi. This is not an OS X flaw — it is a driver flaw. I love the people who will turn this around and go “OS X has flAWWSSS!” like Chicken Little. It’s so fun to watch idiots get spun up.
No it’s all good. Mac OS X is much more secure, but Apple needs to identify these types of problems and fix them. For Apple it is a controllable situation. For MS, it is not.
What sounds like bad news here (if true) is actually GREAT news!
Please, let guys like this help Apple fix such problems BEFORE they get loose in the wild, not AFTER!
The truth is that flaws exist in ALL systems, Mac, Windows, and beyond–and always will. The difference lies in how the company responsible for those flaws addresses them.
If these are REAL, lets hope Apple (and even MonkeySoft) fixes them quickly. Regrettably, we ALL suffer when hackers do their thing.
Yikes!
no normal user is going to make any distinction between a flaw that originates in OS X vs. a third-party driver. If somebody hijacks a MacBook, it’s going to reflect very poorly on Apple.
It’s really good that folks like this are out there, though. If the story is to be believed, then they will disclose their findings to both Apple and MS in the hopes of plugging this security hole in the future.
Nothing as complex as Mac OS X– or Windows XP is going to be without flaws. However, when comparing security vulnerabilities between the two the difference is huge. I’d liken it to the difference between a a girl who has slept only with one BF and a toothless $10 crack whore. Guess which is which.
I remember reading about a security analyst going to a convention and having his Mac pwned. Seems as though this explains it.
I downloaded a patch for my iMac but it still wants a cigarette.
Bring it, Krebs!
Still, if someone were to somehow do this on a grand scale, the score would still be Windows – 144,000+ to Mac – 1. Like golf, the lower the score, the better. Mac still wins and is a more secure system to use than Windows could ever hope to be.
“This is not an OS X flaw — it is a driver flaw”
It ships on the OS X discs, is updated by Apple on software update. It’s part of the OS.
Lets be realistic. What are the odds somebody will actually seize control of your mac with a specific security flaw known by VERY few people. Propably same as getting hit by a lightning while under a shark attack in the mediterranean.
re:”But if those commercials prompt a round of Mac attacks that actually do work, then not so good”
The idea that there is some genius hacker out of there who has not heard of OSX and will suddenly strike is silly.
That does not mean that a real attack cannot happen, but if security through obscurity were valid, then how could the first 8500 copies of Windows Vista be attacked by several viruses within 8 hours of release.
Yes, that was a Beta version, but the difference is the underlying structure of an operating system that is the main determining factor.
OSX becomes stronger when faced with challenges, unlike others that keep getting new variants of old viruses. That fact tells you everything you need to know about the inherent weakness of the “other” operating system.
Could these guys be right in this case? Of course, but look at history.
You know, even if the Mac has 100 viruses by September, I’ll STILL be smug.
I’d be more worried that the hacker is in my house…
All your Mac’s belong to us!
Ok, just the wireless ones, including bluetooth
and the ones running exploitable anti-virus software and other apps installed via admin password,
and the ones that doubleclick on anything we send them
and especially the ones that simply give us a admin password to install our gimmick software (weeee!!!)
and the ones who install APE “haxies” and other OS modifications (bingo!)
and the ones who run Microsoft code of any sort (oh yes come to poppa!)
and the one’s who don’t update via Software Update regulary really makes our job easy
and most of all a kudo’s goes to those who don’t even monitor their system, clone their boot drive or change their IP address occassionally so we can easily find them again to run something new.
http://www.net-security.org/
(scroll down and mouse over the Apple Logo on the left.)
This public service announcement brought to you by the Mac friendly l33t h@XXor
My other “box” is a 1,000,000 node cluser Windows Zombie (yea I wish)
“‘We’re not picking specifically on Macs here, but if you watch those ‘Get a Mac’ commercials enough, it eventually makes you want to stab one of those users in the eye with a lit cigarette or something,’ Maynor said.
You want to stab me in the eye because the commercials rub it in your face that you made a bad choice by wasting your hard earned money on a Windows run PC.
Gotta say, it’s not the operating system that has the weekness, it’s the drivers.
Well, let’s see here. Hmmmmm….. Apple just released a security update. This little “demonstration” was videotaped before the security update was released by Apple, most likely. Perhaps this update addresses the yet-to-be demonstrated flaw? Wouldn’t be surprised if Apple beat ’em to the punch.
And for those of you who will choose to remain smug as a bug in your rug – all it will take is one verifiable, replicatable, transmittable virus that does actual damage to another Mac without any user interaction and the windows community (and media, for that matter) will HOWL and HOWL and HOWL with glee. So sad, but true. Then again, they’ve been howling at even the weakest attempts, trying to make them seem way more than they are, which is all they’ve had lately to howl about. Still sad. Okay, and I’m feeling pretty smug, too.
The other Apple sites have already reported a patch is available at Apple. They are also talking about WWDC.
MDN, wake the fuck up! Less than a week to go ’til WWDC and all I am getting here is stories about MSN offering crappy cancelled TV shows.
I am a bit skeptical about a video demo of a Mac exploit by guys that admittedly have an unusual emotional dislike for Apple. Real techs are far more neutral and professional. One step further, a real professional would never disclose this… period.
I think they are just trying for some sort of hostage/ransom money from Apple. They know that Microsoft won’t pay because an entire industry is based on fixing flaws and viruses.
My guess is that they made a cheap fake video, and are just trying to build up hype, producing an income from lies and public gullibility.
If it is true, I’ll bet that it is another “if you have the user’s password…” you can…. blah, blah, blah….
I’ll stick with Apple’s security programming department’s 20 successful years over a couple of dead-beats with Mac-envy.
did todays security update fix this exploit?
Last time someone bragged about hijacking a Mac in 60 seconds they cheated by using a local account already on the machine. One of the universities I.T. managers put up a Mac Mini and challenged the hacker community to break in, and nobody could do it after 72 hours. It’s really a different situation when you’re no where in site of the machine and only have what you think is an I.P. that could get you in. So far no one has proved they can hack a Mac legitimately.
“The other Apple sites have already reported a patch is available at Apple.”
Two questions:
1. WHAT other sites? I just visited a dozen or so and have seen nothing.
2. Where on the Apple site is the patch available?
Put up or shut up, Ray!
http://www.macrumors.com/pages/2006/08/20060801170509.shtml
but does it fix this exploit? i dont know.
I’ll still take a Mac and an obscure security problem as opposed to Windows which is seemingly afflicted in a similar way plus has hundres of thousands of other problems and counting. No problems is a mighty high horse to be on but if I was smug before this isn’t really gonna level the playing field too much.
The very fact that they are demo-ing this via videotape in front of a room full of people means:
A. They can rig the “demo” any way they please to get the results they want (they admit they have an axe to grind) just like the “hack OSX within 30 seconds” scammers did last year- disabling security features on the Mac, allowing local access etc.
B. No one in the room can challenge what they did, cause they have no way of knowing what they really did.
These guys are cowards and media whores, big time.
Anyone know if yesterday’s security updates stops this apparent hack?
We’re all waiting for the list of sites that have already showcased the patch for this flaw, Ray.
Come on, Ray. You were awfully unforgiving of MDN for (supposedly) being behind the times in this issue, so where are YOU now?
BWAAAAHHHHHHHHHHHHAAAAAAAAAAAAAAAAAAHHHABWAHHHHHHHHHHHHHHHHHHWAAAAAAAAAAAAAAAAAAAHHHHHHHHHHHHHH
misery love company
If these guys are trying to make a point (about “smugness”) and the only way they can do is through a device driver flaw, that only proves the point about the inherent security superiority of Mac OS X. If the demo goes on to show that the “bad guy” has to be within wireless range of the target Mac, I’m really going to laugh…
Another example of the benefits of outsourcing.
to: Where ARE You, Ray?
see my post above (macrumors.com)
Apple just released another Security Update (available via Software Update) and I along with “Steven” and “Well…” are asking if this new update fixes the wireless driver exploit.
I’m sure this is the update that Ray is talking about.
Man if you can do this on OSX, just immagine what you could do to a windows box with a wireless card
” width=”19″ height=”19″ alt=”smile” style=”border:0;” />
BRING IT!!!!!!!!!!
Finally, macs get some respect in the haxx0r world, we’re not being ignored as the ugly stepsister anymore, joy! Now that haXX0rs are actually starting to target Macs… it’s good… security through obscurity is no more!!!
Yep, now we’ll all see for sure that “obscurity” has absolutely nothing to do with OS X’s vastly superior security.
I think this is crap. Take a video?
I am not saying it can’t happen, I am sure it will someday, but this smells like a big steamy pile.
G-Spank: “For Apple it is a controllable situation. For MS, it is not.”
Can you, or anybody, explain why this would be?
So far no one has proved they can hack a Mac legitimately.
HAHAHAHAHA!!
See this and read carefully, Dave Schroeder “rm my Mac” was successful.
The most popular was probably the local ‘passwd’ exploit (a zero day based exploit) reported on 03.02.06, which was used to hack the system of Dave Schroeder during the “rm-my-mac” competition.
http://www.net-security.org/article.php?id=933&p=1
Dave Schroeder’s site
http://rm-my-mac.wideopenbsd.org/
Mac OS X still has a bunch of fundamental security vulnerabilities. – Dave Schroeder
Bibliotech –
Because Apple can keep up with 1 security flaw every 5 years. M$ can’t keep up with 100,000’s of thousands every year.
Bibliotech, because Microsoft has invested itself in legacy technology that ties them hand and foot to a fundamentally insecure OS. Apple, on the other hand, walked away from OS9 (and it’s earlier bretheren) to embrace BSD Unix, a mature and inherenlty secure OS. Vista is just a 64 bit shell on top of pieces of 16 bit and 32 bit code sewn together. Why do you think MS is having so many problems getting Vista released? Why do you think so many features have been dropped? You can’t make a silk purse from a sow’s ear.
For those of you ignorant about security (I’m going with ‘most’ at this point), the reason they chose to do video rather than a live demonstration is because anyone with a laptop in the audience could sniff the demonstration attack and it would be out in the wild in no time.
All you have to do is fire up Ethereal and sniff on your wireless card. They run their demo. The attack packets used get sniffed by Ethereal. Now you have the needed information to deconstruct the attack.
Showing a video demonstration is a lot more responsible than running a live one. Oh, and the security patch was available late last night (I updated shortly after midnight) and the presentation is being given today, so don’t count on it being fixed. The quick and dirty solution to this for the paranoid (and what I’ll be using at Defcon this week) is to disable your internal wireless and use a USB dongle wireless adapter
I went to the web site showing Mac OSX weaknesses. Yes, It looks like Mac OSX is not PERFECT. IT has some weaknesses.
OK, what does that really mean. Hmmm lets see at June of 2006 :
Windows virsus=114,000 Mac viruses = 0
Windows weaknesses 150,000 PLUS Mac weaknesses = less than 100
So, sure, I would live to use a Windows machine cause 114,000 is almost equal to 0 and 150,000 potential– Oh wait do not forget the 114,000 already found = 264,000 to a Mac 100. Yep, Windows is really better. . . . . . Duhhhh?
Later dude, I have a life to live.
” width=”19″ height=”19″ alt=”grin” style=”border:0;” />
N.
Okay, thanks for the answers, folks.
Next questions, from one who is just a consumer level user, not a power user:
I’m sitting at a local cafe using my wi-fi. I get up to order another espresso over mint-chocolate ice cream and someone jacks into my laptop. What, exactly, does that person get? Access to my iPhotos? Address book? I’m not clear on the danger here.
Also, what do I do about it when I sit down and, lo and behold, my laptop seems to be moving my mouse or opening my apps without me? Hold the power button down to shut down?
All this shows is that it is unsafe to own a portable computer with wireless.
I thought that was already obvious.
First of all, in order to implement this attack you have to have proximity to the subject which, you have to admit, is a whole lot more risky than attacking over telnet or ftp.
Second, Why is correct in that sniffing the data packets is stupid simple to do. What’s even crazier is the amount of clear text that is contained in those packets. If you’ve ever sniffed your own traffic you’ll find your email account user name and password right there in clear text.
Realistically, however, your Mac on your home wireless network wouldn’t be the target of an attack like this. What’s more probable is if you were on a school campus or some other public space with unencrypted wifi. Furthermore, encryption itself won’t stop a determined attacker but the amount of packets he/she has to collect increases exponentially. Correct me if I’m wrong but as I recall with 128 bit WEP you’re looking at needing somewhere around 2 – 3 million packets. That requires time.
The news of this flaw isn’t earth shattering in my opinion. We have so few details about what else is need to take control of the computer that it’s a bit hard to get too worked up. So, IMHO, take this news with a grain of salt and if your really spooked turn off your airport card when you’re not using it.
To Bibliotech:
I’m sitting at a local cafe using my wi-fi. I get up to order another espresso over mint-chocolate ice cream and someone jacks into my laptop. What, exactly, does that person get? Access to my iPhotos? Address book? I’m not clear on the danger here.
Well, they can get access to any personal information you may have on your laptop. Financial records, for instance. Or they could sniff your passwords through various means (keystroke recorder, packet sniffer, etc). Do you use the same passwords for logging into an email account or instant messaging that you do for your online financial institutions? While your password is typically encrypted on financial sites, it is sent plain text via apps like MSN Messenger.
Also, what do I do about it when I sit down and, lo and behold, my laptop seems to be moving my mouse or opening my apps without me? Hold the power button down to shut down?
This is rarely the case. The only time you’ll see this scenario is if someone logged into your laptop with Remote Desktop and was stupid about how they chose to access it. Remote Desktop allows you to take control of the user’s screen or just be logged in without you knowing (unless you know what to look for). For the most part, you won’t know you’ve been compromised.
Thanks, Why.
I guess I’m pretty safe, for now, as I use a G4 Titanium and rarely take it out anymore. It’s basically my desktop. Still, I guess we all need to be more careful out there. Pisser.
At least I don’t use a Windows machine, though. What you described above happened to a friend recently on his PC at home. He found someone else had been using his computer for their own purposes. Had to wipe the hard drive, change all passwords to everything, all that. He’s not an idiot, either. He had set up protection, or so he thought. He’s looking at an iMac down the road after years of my bugging him to go Mac.
Videotaped, not live. Based on the adapter, not then OS. That sets my BS alarms ringing like a red alert on the Enterprise.
Now, MacBooks use the same wirelss as a host of Windows PC’s namely Intel’s wireless chipset.
I expct this is harder (if not impossible) to do to a PPC Mac, limiting the damage to Intel Macs.
Still, it smells really fishy to me.
Oh, and l33t h@XXor, I doubnt you could hack your way out of a paper sack with a fully functioning chainsaw that your daddy started for you….
Sorry, but this whole story is not for real. If you watch the video carefully, you see that the guy doesn’t use the built-in WiFi drivers but sticks a PCExpress card with a third party WiFi driver into the MacBook! He also has to manually mount it to the access point, using Terminal, not the standard way for Mac users. Who knows what he has installed on that Mac to make this work. Very suspicious…
What the video shows is a guy plugging in a 3rd party wireless card into a Mac that already has it’s own wifi card.. and accessing the mac without telling us what security settings the mac had. Additionally.. he just accessed the User/Desktop….
It took 58 comments on this site to someone finally writing something useful…
Give me a f***** break. This is complete bullshit. You get a Mac, which has its own AirPort card, you plug a third party driver, you acess the machine to write a script and all you get is user level acess, what a publicity stunt! “We’re going after macs because their ads annoys us, bla, bla, bla.” Wannabe hackers, truly script kiddies lammers…
http://macslash.org/article.pl?sid=06/08/02/2118257&mode=thread
what’s a lammer, is that someone who midwifes for sheep?
I watched the video over on CNET, and this is totally stupid. All the “fear” amount to nothing. If this is the best “hackers” can do against Mac OS X, I feel “smug” all over…
But I have a question. How did this guy stick a “third-party wireless card” into a black MacBook? The MacBook does not have slot/port to accept such a device, does it? My conclusion, it was all fake.
Here the side of the MacBook where that guy stuck that “wireless card” on the video (conveniently hidden from the camera angle)
http://www.apple.com/macbook/design.html
Where did that card go, exactly? These idiots can’t even create a decent fake video… I doubt they really know anything worthwhile about computer security.
>ken1w
‘Where did that card go, exactly?’
its a usb wireless card, readily avialable im afraid if you look closely when he shows the card you can see the usb connector, so this dosent prove fakeness.
but even if this is real its a very narrow attack path, most mac users have apple cards which they specifically avoid attacking, if theyd used a pc as the victim no one would have cared. nothing to see move along….
Here’s a succinct summary:
They found a 3rd party wireless adapter has shoddy drivers, and it has nothing to do with original computer hardware or the OS it is running.
Instead of calling out Atheros for their crappy drivers, they decided to create this farce of a demonstration.
This video ‘exploit’ does indeed look to be B.S., but FYI there is a way to cut down on the success rate of any possible exploit similar to thsi one:
Go to System Preferences > Network > select “Airport” from the Show Menu > press the Options button > and do the following …
a] Where it says “If no recent networks are found”, choose “Ask before joining an open network” in the dropdown menu (this is just so you always know what’s going on).
b] Where it says “Require an administrator password to:”, click the boxes for “Change wireless networks” and “Create Computer-to-Computer networks” (if these boxes are checked, then it should be impossible for anyone to take control through the wireless driver regardless of whether the wireless is an APcard or an external card – unless they know your password of course).
That should do it, but if you want to be even safer …
Go back to the frame where you pressed the Option button; up where it says “By default, join:” choose “Preferred networks” from the dropdown menu, NOT “Automatic”. When you are looking for a wireless network you aren’t familiar with, you can go back in and change it back. Yet, if you leave Automatic as the default, the Mac will sniff around indiscriminately for a network where ever you go with it, and thus potentially making it known to hackers, and that could make you more vulnerable. It takes a bit of the ‘Magic Mac’ experience away, but if you’re that concerned about the problem then I guess that’s the price you pay. Like they say, even paranoids have something to worry about.
“Disconnect from wireless network when I log off”. That one too is useful.
heres the viDeo .. Third party wireless card by the way
http://news.com.com/1606-2_3-6101573.html?tag=ne.video.6060109
Wireless of any kind is a security joke – regardless of platform.
Best to turn OFF all network ports you don’t absolutely need.
Stories like this one don’t give ordinary people any valuable takeaway: most people don’t realize it’s a vulnerability in the Atheros wireless device driver, and can also be similarly exploited on Windows and Linux. They just think we’ve got some issue
of unknown practical severity on “MacBooks” (oops, it also affects MacBook Pro and any other Intel Mac that uses the Atheros chipset, not to mention any other platform in the planet using this chipset). What does that mean?
It means we have a feeding frenzy for misinformation (deliberately obscuring the whole truth of an issue), with Apple as the latest victim.
Now we have a bunch of people telling everyone to disable the MacBook’s ability to automatically connect to access points. Whether or not that is a good issue anyway is beside the point: the end result is that people think there’s some kind of problem with just “MacBooks” because of the way the story was presented.
Frankly it amazes me that some of these people are even writers, because it took me about 45 seconds to understand from the presentation that this could affect any platform and any OS, but that they CHOSE to use Mac OS X on a MacBook. Much of the coverage doesn’t reflect this, and the sensationalistic headlines certainly don’t.
The reason MacBook was chosen has nothing to do with the Mac or OS X. It has to do with the fact if the hack was shown on any PC the reaction would have been “Dh’o”, who cares, one more: no news. But stick it Mac or Apple with it and it makes the news. So much so for “Macs not interesting” “Apple not on the radar” etc.
This very silly story – as it has been presented – is the evidence that Macs and OS X are very much in the radar of crackers and malware writers. Very much so. Obscure my ass.
That nothing yet has surfaced is one more evidence that OS X is very secure.