Remote Exploit Forums

Go Back   Remote Exploit Forums > Archives > BackTrack v2.0 Final


BackTrack v2.0 Final Released 6th of March 2007 Please do not make posts related to BackTrack 2 Beta here!

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-24-2007, 02:44 AM
balding_parrot's Avatar
Administrator
 
Join Date: May 2007
Posts: 3,245
Default Madwifi driver users UPDATE NOW (THAT MEANS ANYONE USING ATHEROS CARDS)

Just stumbled upon this, and as I didn't find it posted, I thought that it needed to be brought to people's attention, just in case you have missed it.

THIS AFFECTS ANYONE WITH AN ATHEROS CHIPSET WIRELESS CARD

Quote:
Announcement
Hi all.
We recently have been made aware of three security-related issues in MadWifi v0.9.3. In response to these reports we've released v0.9.3.1 today (which is similar to v0.9.3 plus the relevant fixes). The release tarballs are available for immediate download from: http://sourceforge.net/project/showf...ckage_id=85233
*We strongly advise all users of MadWifi to upgrade to v0.9.3.1 as soon as possible.*
Thanks to Md Sohail Ahmad of AirTight Networks Inc. for reporting issue 1. We also like to thank the reporter of issues 2 and 3, who has asked to keep his identity private.
The issues are:
1. Remote DoS: insufficient input validation (beacon interval)
The beacon interval information that is gathered while scanning for Access Points is not properly validated. This could be exploited from remote to cause a DoS due to a "division by zero" exception.
See also: http://madwifi.org/ticket/1270
2. Remote DoS: insufficient input validation (Fast Frame parsing)
The code which parses fast frames and 802.3 frames embedded therein does not properly validate the size parameters in such frames. This could be exploited from remote to cause a DoS due to a NULL-pointer dereference.
See also: http://madwifi.org/ticket/1335
3. Local DoS: insufficient input validation (WMM parameters)
A restricted local user could pass invalid data to two ioctl handlers, causing a DoS due to access being made to invalid addresses. Chances are that this issue also might allow read and/or write access to kernel memory; this has not yet been verified.
See also: http://madwifi.org/ticket/1334
Thanks for your attention.
Bye, Mike
So as you can see, if you are a MadWifi user you REALLY need to update your drivers NOW.

Anyone with atheros chipset cards should follow Xploitz instructions on how to update the drivers here
__________________

Any questions you have will get a good answer as long as you have followed the forum rules and show you have tried to help yourself. Your questions are clear and contain as much relevant info as possible, especially error messages, commands you have tried and the output from those commands.

remember: garbage in = garbage out

BackTrack needs your donations, no matter how small.

Please contribute HERE


Last edited by balding_parrot; 07-24-2007 at 03:51 AM.
Reply With Quote
  #2 (permalink)  
Old 07-24-2007, 03:00 AM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,487
Default

Thanks balding_parrot for bringing this to our forums attention. I just updated.

Last edited by -=Xploitz=-; 07-24-2007 at 03:04 AM.
Reply With Quote
  #3 (permalink)  
Old 07-24-2007, 03:07 AM
balding_parrot's Avatar
Administrator
 
Join Date: May 2007
Posts: 3,245
Default

Quote:
Originally Posted by -=Xploitz=- View Post
Thanks balding_parrot. I just updated.
No Problem, your welcome.

I spotted it and thought people should be aware of it.

If I have saved one person from the potential nasties, then my purpose has been done.
__________________

Any questions you have will get a good answer as long as you have followed the forum rules and show you have tried to help yourself. Your questions are clear and contain as much relevant info as possible, especially error messages, commands you have tried and the output from those commands.

remember: garbage in = garbage out

BackTrack needs your donations, no matter how small.

Please contribute HERE


Last edited by balding_parrot; 07-24-2007 at 03:22 AM.
Reply With Quote
  #4 (permalink)  
Old 07-24-2007, 03:13 AM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,487
Talking

Quote:
Originally Posted by balding_parrot View Post

If I have saved one person from the potential nasties, then my purpose has been done.
Well, Im all about preventing the nasties when I'm penetrating As long as my ndiswrapper doesn't break I'm ok!!! Now then...wheres my brewski's at??
Reply With Quote
  #5 (permalink)  
Old 07-24-2007, 04:30 AM
theprez98's Avatar
Super Moderator
 
Join Date: Apr 2007
Location: Maryland
Posts: 2,530
Default

Quote:
Originally Posted by balding_parrot View Post
Just stumbled upon this, and as I didn't find it posted, I thought that it needed to be brought to people's attention, just in case you have missed it.

THIS AFFECTS ANYONE WITH AN ATHEROS CHIPSET WIRELESS CARD

So as you can see, if you are a MadWifi user you REALLY need to update your drivers NOW.

Anyone with atheros chipset cards should follow Xploitz instructions on how to update the drivers here
Can we assume that these new drivers are already patched for injection?
__________________
theprez98
"I want peace on earth and goodwill toward men."
"We are the United States Government. We don't do that sort of thing!"
Reply With Quote
  #6 (permalink)  
Old 07-24-2007, 05:24 AM
balding_parrot's Avatar
Administrator
 
Join Date: May 2007
Posts: 3,245
Default

Quote:
Originally Posted by theprez98 View Post
Can we assume that these new drivers are already patched for injection?
I don't have my atheros card with me at the moment, so cannot confirm this. I did see a post on another forum that said that this version supported injection out of the box, but as I say I cannot confirm it.
I am sure that Xploitz will soon say if they don't, but as I saw a post from him giving instructions saying how to update to them, I assume that he has tested them.

So come on Xploitz, do they support injection or not ?
__________________

Any questions you have will get a good answer as long as you have followed the forum rules and show you have tried to help yourself. Your questions are clear and contain as much relevant info as possible, especially error messages, commands you have tried and the output from those commands.

remember: garbage in = garbage out

BackTrack needs your donations, no matter how small.

Please contribute HERE

Reply With Quote
  #7 (permalink)  
Old 07-24-2007, 06:03 PM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,487
Thumbs up

Quote:
Originally Posted by balding_parrot View Post
I am sure that Xploitz will soon say if they don't, but as I saw a post from him giving instructions saying how to update to them, I assume that he has tested them.

So come on Xploitz, do they support injection or not ?
I assume your referring to my card injecting with these drivers installed and not me injecting. But yes, both me and my card can inject after I installed this new updated driver.
Reply With Quote
  #8 (permalink)  
Old 07-24-2007, 09:05 PM
balding_parrot's Avatar
Administrator
 
Join Date: May 2007
Posts: 3,245
Default

OK COOL so now that is confirmed, UPDATE NOW
__________________

Any questions you have will get a good answer as long as you have followed the forum rules and show you have tried to help yourself. Your questions are clear and contain as much relevant info as possible, especially error messages, commands you have tried and the output from those commands.

remember: garbage in = garbage out

BackTrack needs your donations, no matter how small.

Please contribute HERE

Reply With Quote
  #9 (permalink)  
Old 07-24-2007, 09:20 PM
pureh@te's Avatar
Jenkem Addict
 
Join Date: Mar 2007
Location: /dev/null
Posts: 5,401
Default

this is also documented HERE
MadWifi Multiple Denial of Service Vulnerabilities
2007-07-24
http://www.securityfocus.com/bid/24114

MadWIFI Channel Switch Announcement Information Elements Denial of Service Vulnerability
2007-07-24
http://www.securityfocus.com/bid/23436

MadWIFI Ad-Hoc Mode Denial of Service Vulnerability
2007-07-24
http://www.securityfocus.com/bid/23433

MadWifi Auth Frame IBSS Remote Denial of Service Vulnerability
2007-07-24
http://www.securityfocus.com/bid/23431

MADWiFi IEEE80211_Output.C Unencrypted Data Packet Multiple Vulnerabilities
2007-07-24
http://www.securityfocus.com/bid/23434

MADWiFi Linux Kernel Device Driver Multiple Remote Buffer Overflow Vulnerabilities
2007-03-01
http://www.securityfocus.com/bid/21486

Last edited by pureh@te; 07-24-2007 at 09:23 PM.
Reply With Quote
  #10 (permalink)  
Old 07-24-2007, 09:26 PM
balding_parrot's Avatar
Administrator
 
Join Date: May 2007
Posts: 3,245
Default

Quote:
Originally Posted by purehate View Post
this is also documented HERE
MadWifi Multiple Denial of Service Vulnerabilities
2007-07-24
http://www.securityfocus.com/bid/24114

MadWIFI Channel Switch Announcement Information Elements Denial of Service Vulnerability
2007-07-24
http://www.securityfocus.com/bid/23436

MadWIFI Ad-Hoc Mode Denial of Service Vulnerability
2007-07-24
http://www.securityfocus.com/bid/23433

MadWifi Auth Frame IBSS Remote Denial of Service Vulnerability
2007-07-24
http://www.securityfocus.com/bid/23431

MADWiFi IEEE80211_Output.C Unencrypted Data Packet Multiple Vulnerabilities
2007-07-24
http://www.securityfocus.com/bid/23434

MADWiFi Linux Kernel Device Driver Multiple Remote Buffer Overflow Vulnerabilities
2007-03-01
http://www.securityfocus.com/bid/21486
What more evidence do you need to convince you to UPDATE NOW
__________________

Any questions you have will get a good answer as long as you have followed the forum rules and show you have tried to help yourself. Your questions are clear and contain as much relevant info as possible, especially error messages, commands you have tried and the output from those commands.

remember: garbage in = garbage out

BackTrack needs your donations, no matter how small.

Please contribute HERE

Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:19 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2