Reply to topic  [ 3 posts ] 
Hacker Identifies Persistent Keyboard Attack 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:56 pm
Posts: 12030
Reply with quote
Quote:
August 3rd, 2009
Hacker demos persistent Mac keyboard attack
Posted by Ryan Naraine @ 8:55 am

Apple’s sleek $49 Mac keyboards can be hacked and infected with keystroke loggers and impossible-to-detect rootkits, according to a security researcher presenting at this year’s Black Hat/DEFCON conferences.


The researcher, known only as “K. Chen,” found a way to reverse engineer and tamper with the keyboard’s firmware upgrade. With the firmware under control, an attacker can subvert the keyboard by embedding malicious code that allows a rootkit to survive a clean re-installation of the host operating system.

Chen, from the Georgia Institute of Technology, said malicious code embedded into the firmware would be immune to the typical rootkit detection methods which examine the integrity of the filesystem, check for hooks or direct kernel object manipulation, or detect hardware and/or timing discrepancies due to virtualization in the case of a virtual-machine based rootkit.

“Such code could also completely bypass the remote attestation of a Trusted Platform Module, if one were present in the computer. As far as everybody is concerned, our [malicious keyboard] code is simply the user typing commands at the keyboard,” he explained.

Chen said a malicious keyboard can be used to snoop on keystrokes from any machine it is plugged into.

Here’s a technical paper discussing the keyboard firmware attack. In the video below, Chen demonstrates the attack for George Ou.


Source: http://blogs.zdnet.com/security/?p=3851


I imagine Apple keyboards are not alone in this, surely?

Well, in the mean time, I'm going to stop lending my keyboard out to any Tom, Dick or Harry and no mistake.

_________________
www.alexsmall.co.uk

Charlie Brooker wrote:
Windows works for me. But I'd never recommend it to anybody else, ever.


Wed Aug 05, 2009 10:36 pm
Profile
Doesn't have much of a life

Joined: Sat Apr 25, 2009 6:50 am
Posts: 1911
Reply with quote
They may well be alone in offering firmware updates for a keyboard though.


Wed Aug 05, 2009 11:10 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
I think what makes them so easy is that OS X comes with a firmware writing utility for the keyboard built-in. Other "intelligent" keyboards could also be susceptible, but the hacker would need to write a firmware programming routine as well as the code for the keyboard itself...

You would, presumably, need to adjust the code for each keyboard controller as well.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Thu Aug 06, 2009 5:12 am
Profile ICQ
Display posts from previous:  Sort by  
Reply to topic   [ 3 posts ] 

Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.