Menu

Database

Logitech wireless devices vulnerable to MitM attacks

WVE ID: WVE-2005-0032

Type: Vulnerability

Status: Candidate

Classification:
Design Flaw

Description:
Logitech mice and keyboards are vulnerable to MitM (man in the middle) attacks.

Discussion:
The Logitech Cordless iTouch Keyboard, Freedom Pro, Freedom Navigator, and Freedom are susceptible to remote eavsdropping, hijacking, and MitM attacks. These devices operate on a carrier frequency of 27Mhz. When using these devices a user presses the "Connect" button on both the receiver connected to their computer as well as the one on their keyboard or mouse. This initiates a synchronization mechanism whereby the reciever and device find a pair of frequencies to communicate on.

An attacker using radio equipment can monitor the synchronization traffic between a victim's receiver and their keyboard or mouse. From this, the attacker can read keystrokes from a keyboard without the victim's knowledge. Furthermore, an attacker can modify one of the affected devices to enable them to take control of the victim's keyboard or mouse, giving them full access to the victim's console.



Credits
Author: Axel Hammer (alpha01@grafx-design.de) : None

References
BUGTRAQ: http://seclists.org/lists/bugtraq/2001/May/0156.html
CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2001-0737
BID: http://www.securityfocus.com/bid/2738/

Released: 2001-05-16

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Fri Nov 04 15:57:49 -0800 2005

Candidate Date: Fri Nov 04 15:59:08 -0800 2005


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...