Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Focus on Apple
Re: Hijacking a Macbook in 60 Seconds or Less Aug 12 2006 07:02AM
Nicolas RUFF (nicolas ruff gmail com) (2 replies)
>> http://blog.washingtonpost.com/securityfix/2006/08/hijacking_a_macbook_i
n_60_seco.html
>> What do you think about this?
> Roughly this: http://daringfireball.net/2006/08/krebs_followup

Hello,

I have been watching the video. At 2'05", we can see a dump of the
"ifconfig" command. I made the following screenshot:
http://www.flickr.com/photo_zoom.gne?id=213004107&size=o

For me, it's pretty clear that:
- The first interface (en0) is down. This is the wired interface.
- The second interface (en1) is up and running with the following
configuration :
IP = 192.168.1.50
ETHER = 00:17:f2:41:31:6d

This prefix has been assigned to:

00-17-F2 (hex) Apple Computer
0017F2 (base 16) Apple Computer
1 Infinite Loop MS:35GPO
Cupertino CA 95014
UNITED STATES

- There is a third interface, which has an oddly long MAC address
beginning with 00:16:cb ...

00-16-CB (hex) Apple Computer
0016CB (base 16) Apple Computer
1 Infinite Loop MS:35GPO
Cupertino CA 95014
UNITED STATES

And that's all because we can see the "dave" prompt below.

So my theory is: they ran the demo against the built-in Apple wifi card!

What do you think ?

Regards,
- Nicolas RUFF

[ reply ]
Re: Hijacking a Macbook in 60 Seconds or Less Aug 14 2006 10:54AM
Simon Slavin (s slavin lancaster ac uk)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 13 2006 07:20PM
Massimo Marino (fwa266m mac com)







 

Privacy Statement
Copyright 2008, SecurityFocus