Logitech SPOTLIGHT: Wireless Remote Code Execution after one-time physicall access
Автор: TheMaMe82
Загружено: 2019-06-28
Просмотров: 2669
Описание:
encryption key could be extracted from receiver in less than 1 second
encryption key could be used by an attacker to inject keystrokes remotely via RF (as often as the attacker likes)
encryption key can't be changed by user, once exposed
the receiver accepts many keyboard keys for injection, but alpha keys (A-Z) are blacklisted
blacklisting could be bypassed, using proper shortcuts on Microsoft Operating Systems
Mitigation:
don't give anyone access to the receiver of this presentation clicker (no sharing)
use Bluetooth mode instead of the receiver (no known vulnerability, yet)
Note: R500 presentation clicker is affected by the same vulnerability CVE-2019-13054
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: