Hacker project puts spotlight back on Mac security

November 2, 2006, 11:22 AM —  IDG News Service — 

The security of Apple Computer Inc.'s wireless drivers is under scrutiny again, thanks to a new hacker project.

On Wednesday HD Moore posted code that exploits a flaw in the Proxim Wireless Corp. Orinoco wireless cards used by PowerBook and iMac computers built between 1999 and 2003, according to Moore.

Apple said the issue "affects a small percentage of previous generation AirPort enabled Macs and does not affect currently shipping or AirPort Extreme enabled Macs," according to a statement issued Wednesday.

The code was posted on a new blog called the Month of Kernel Bugs. It is modelled on Moore's own Month of Browser Bugs project, which disclosed one new browser vulnerability per day during the month of July.

The kernel bug project was launched with a reference to a controversy over Apple's products, kicked off at the Black Hat USA conference three months ago.

"With all the hype and buzz about the now infamous Apple wireless device driver bugs... hopefully this will bring some light (better said, proof) about the existence of such flaws in the Airport device drivers," wrote the blog's author, a hacker going by the name of LMH.

In August security researchers David Maynor and Jon Ellch claimed to have discovered a flaw that affected Apple's wireless device drivers. They played a video demonstrating how this flaw could be used to run unauthorized code on a Macbook at Black Hat, but their claims have been criticized because their demonstration used a third-party wireless card rather than the one that ships with the Macbook, and because the two hackers have not published the code used in their attack.

Apple later said that Maynor's employer, SecureWorks Inc. had "not shared or demonstrated any code in relation to the Black Hat-demonstrated exploit that is relevant to the hardware and software that we ship."

A month later, Apple patched a number of flaws in its wireless products and soon after announced that it was working with SecureWorks on security issues.

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Free books

Essential JavaFX
Get started building rich Web apps quickly with an introduction to the power of JavaFX key features -- scene node graphs, nodes as components, the coordinate system, layout options, colors and gradients, custom classes with inheritance, animation, binding, and event handlers.Enter now!

The Nomadic Developer
Consulting can be hugely rewarding, but it's easy to fail if you are unprepared. To succeed, you need a mentor who knows the lay of the land. Aaron Erickson is your mentor, and this is your guidebook. Enter now!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace