How a wireless keyboard lets hackers take full control of connected computers

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12Lo9D0Se_c_Q9XhPuj8W4SO3hgeU5NKRRptt9xbyQFRhQ@mail.gmail.com>
'There’s a critical vulnerability in a model of Fujitsu wireless
keyboard that makes it easy for hackers to take full control of
connected computers, security researchers warned on Friday. Anyone
using the keyboard model should strongly consider replacing it
immediately.

The Fujitsu Wireless Keyboard Set LX901 uses a proprietary 2.4 GHz
radio communication protocol called WirelessUSB LP from Cypress
Semiconductor. While the keyboard and mouse send input that’s
protected with the time-tested Advanced Encryption Standard, the USB
dongle that accepts the input accepts unencrypted packets as well, as
long as they’re in the proper format.

Researchers with the Germany-based penetration-testing firm SySS
developed a proof-of-concept attack that exploits the insecure design.
Using a small hardware device, they are able to send commands to
vulnerable Fujitsu keyboard receiver dongles that are within range. As
the video below demonstrates, the researchers were able to send input
of their choice that’s automatically funneled to the connected
computer.'

-- source: https://arstechnica.com/information-technology/2019/03/how-a-wireless-keyboard-lets-hackers-take-full-control-of-connected-computers/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.