White Hat group demonstrates low-level exploit on poor WiFi driver coding.
Never really suprising is it to find the various exploit techniques that groups come out with over the years, from the sniper styled bluetooth phone exploits from a mile away to the daily exploit findings on Windows and Windows software. Today though a group takes things a step further by demonstrating at the Black Hat security conference in Las Vegas a method to exploit a MacBook.
The details of this trick have been withheld for obvious reasons, the performance was based via video demo to help try to ensure that it wouldn't be picked up on by watchers sniffing for details. Also they've managed to find similar flaws in Windows based machines. Given that it's driver based for both systems there might be some attempts to evade things, for now the best bet users will have is to disable wifi when not in use as it operates at a level well below that of the Firewall or AV utilities.
When asked about the Mac as the demonstration model Maynor noted it was based on the "Mac user base aura of smugness on security." then elaborated with the following.
"We're not picking specifically on Macs here, but if you watch those 'Get a Mac' commercials enough, it eventually makes you want to stab one of those users in the eye with a lit cigarette or something," Maynor said. "The main problem here is that device drivers are a funny mix of stuff put together by hardware and software developers, and these guys are often under the gun to produce the code that will power products that the manufacturer is often in a hurry to get to market."
Hopefully WiFi owners will be seeing some heafty updates in the coming weeks, maybe without having a gun to their head only to release yet another exploit in the code. Although if the companies making the device drivers are lagging behind there might be a need to figure out new upgrade paths to avoid being a target.