FEATURED VIDEO
Sponsored By:
SLIDE SHOWS
As if they needed more stress, organizations are facing evolving and increasingly stringent compliance regulations from the Payment Card Industry, as well as Sarbanes-Oxley, HIPAA and others. Here are a few security compliance products that can make the audit process less excruciating.
Here are 10 of the distributor's hottest new offerings winning over solution providers.
New smartphones from Sony, Motorola and the first-ever Twitter-only mobile device -- the TwitterPeek -- headline a busy week for handset makers as the holiday shopping season heats up.
INSIDE CHANNELWEB

Apple Keyboard Firmware Vulnerability Detected By BlackHat Researcher


By Stefanie Hoffman, ChannelWeb

3:52 PM EDT Wed. Aug. 05, 2009
On top of patching the iPhone SMS flaw, Apple has to deal with a keyboard firmware vulnerability that allows hackers to silently log keystrokes to steal passwords and other identifying information.

During the BlackHat conference in Las Vegas, one hacker demonstrated that Apple keyboards contain a flaw that enables cybercrooks to launch key-logging software designed to record keystrokes. Any personal information entered by the users, such as passwords and credit card numbers, can then be swiped by the attackers.

The vulnerability, which stems from a poorly designed firmware upgrade in the keyboard USB buses, enables a rootkit to flourish with a clean reinstallation of the host operating system.

Apple's keyboards contain enough RAM and flash memory -- albeit a small amount -- for hackers to inject key-logging software. Once injected in the Apple keyboard firmware, the key-logging software is almost undetectable by the malware-detection system.

The attack is further enabled by the fact that the keyboard firmware updater is unencrypted and doesn't require validation.

K. Chen, the security researcher who first detected the Apple firmware vulnerability, said that many modern firmware upgrade devices embedded in the keyboards contain cheap microcontrollers that make it difficult to verify cryptographic signatures.

"The security of many of these upgrade mechanisms is very much in question," wrote Chen in a white paper. "For a device as simple in design as a keyboard, it is hard to imagine why a firmware update mechanism is even required. Many other devices have firmware update mechanisms that we believe can also be exploited by attackers for malicious purposes."

During the BlackHat conference, Chen demonstrated how the exploit could be used to obtain passwords, login credentials and other information typed into the system by the user.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
Avnet 0% Lease Promotion
The Avnet Capital Solutions “0% Lease Promotion” has been extended to December 31, 2009! This offering significantly reduces ...
Double Your Money!
Cash Rewards - DOUBLED!
RELATED BLOG >>
Photo
LogLogic takes complex log data and turns it into something manageable.
ADVERTISEMENT




CHANNEL SERVICES >>