Logitech Wireless USB Dongles Vulnerable To New Hijacking Flaws

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12JN6fconP69htb1ZY9CZhZ4KpCXmn74jMNBpHAT1+p7zA@mail.gmail.com>
'A security researcher has publicly disclosed new vulnerabilities in
the USB dongles (receivers) used by Logitech wireless keyboards, mice,
and presentation clickers. New submitter raikoseagle shares a report:

The vulnerabilities allow attackers to sniff on keyboard traffic, but
also inject keystrokes (even into dongles not connected to a wireless
keyboard) and take over the computer to which a dongle has been
connected. When encryption is used to protect the connection between
the dongle and its paired device, the vulnerabilities also allow
attackers to recover the encryption key. Furthermore, if the USB
dongle uses a "key blacklist" to prevent the paired device from
injecting keystrokes, the vulnerabilities allow the bypassing of this
security protection system. Marcus Mengs, the researcher who
discovered these vulnerabilities, said he notified Logitech about his
findings, and the vendor plans to patch some of the reported issues,
but not all.'

-- source: https://it.slashdot.org/story/19/07/09/182246

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.