November 13, 2006 4:21 PM PST

Broadcom flaw could allow Wi-Fi hijacks

Computer code that could let an attacker hijack Windows PCs via a Wi-Fi connection was published on the Internet over the weekend.

The code exploits a security vulnerability in a driver from chipmaker Broadcom. The software is used to run wireless networking hardware in Microsoft Windows-based computers sold by Hewlett-Packard, Dell, Gateway, eMachines and others, according to advisories sent out by various security groups and companies. Potentially, millions of systems could be affected.

The vulnerability is caused by improper handling of wireless network service names, called service set identifiers, or SSIDs, according to a Symantec alert sent to DeepSight subscribers on Monday. An intruder could craft a long SSID that would trigger the vulnerability and give him complete control over the vulnerable machine, the security company said.

"This is the first of this class of vulnerability to have public exploit availability at the time that the remote kernel vulnerability was reported," Symantec said. People who own vulnerable PCs should disable the affected wireless devices until patches have been made available, it said.

The vulnerability can be exploited over a Wi-Fi network only and not over the Internet, according to the advisory issued by a group of security professionals calling themselves the Zeroday Emergency Response Team, or ZERT. That means that an attacker has to be within Wi-Fi range of the target--typically, 150 feet indoors and 300 feet outdoors.

"If you are near other users with laptops, you are at risk," according to the ZERT alert. "(Microsoft) Windows is exploitable without the existence of an access point or any interaction from the user. The card's background scan of available wireless networks triggers the flaw," the alert read. An access point is another term for a wireless network base station.

Digging out the flaw
An exploit for the vulnerability has been added to the Metasploit Framework security tool, allowing people with only moderate hacking knowledge to carry out attacks. The latest version of Metasploit, popular with both security professionals and miscreants, has the ability to probe for vulnerabilities in wireless software.

The Broadcom flaw was discovered by Jon "Johnny Cache" Ellch, a researcher who has extensively studied the security of wireless networking. Ellch was one of two security researchers who held a much-debated presentation on Wi-Fi security at the Black Hat Briefings security conference this summer.

Broadcom has released a patched driver to its hardware customers, which in turn should provide updates for their affected products, Heather Roberts, a Broadcom spokeswoman, said in an e-mailed statement. "We are in contact with our customers to help speed the deployment of drivers that fix this issue," she said.

After Black Hat, Broadcom embarked upon an audit of its Wi-Fi code, Roberts said. The company has identified and fixed several vulnerabilities and developed tools to find bugs, she said. Those tools are now part of its driver-testing procedures to prevent such security holes in the future, Roberts said.

The Broadcom flaw was made public as part of an initiative titled the "Month of Kernel Bugs," launched by a security researcher who goes by the initials "LMH." As part of the effort, details of a new bug in low-level software will be made public every day. The month started with an Apple Wi-Fi flaw.

It appears very few of Broadcom's customers so far have applied the update. Linksys, which sells products that ship with this driver, has released an updated driver, according to Symantec, which doesn't list any other vendors on its list of available patches.

Computer users can check if they have the vulnerable driver by searching for it on their system. The driver filename is: BCMWL5.SYS. As a workaround, some people suggest installing the fixed Linksys drivers for protection. TechRepublic blogger George Ou has instructions on how to do that.

See more CNET content tagged:
Broadcom Corp., vulnerability, SSID, Black Hat, flaw

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.