Tuesday, March 6, 2007

Maynor Reveals Missing Apple Flaws

Via SecurityFocus -

Six months after the security researcher and his colleague Jon Ellch claimed that Mac OS X wireless drivers were vulnerable to attack, Maynor on Wednesday revealed the code he used to exploit one of the native flaws the two researchers found in the platform as well as e-mails showing he notified Apple as to the danger.

Maynor said he found three flaws: one in the driver for the Atheros wireless chip--used in MacBooks, another in the Broadcom wireless chip--the hardware under the hood of many PowerBooks, and a third in the Bluetooth driver (corrected). However, Maynor only showed e-mail messages that he sent and received from his personal .Mac account, which limited the evidence shown at the conference to the Broadcom flaw, he said.

In an e-mail dated August 9 to Apple from the account, Maynor promised the company that his demo at the Black Hat Las Vegas 2006 Conference would not reveal the flaw in the native drivers, but use a third-party card, because the pair of researchers had not fully identified all the platforms affected by the bugs.

------------------------------------------

Shocking?

Not for me....as I have seen demos of wireless drivers crashing all over the place for my own eyes.

No comments:

Post a Comment