Security News Low-cost wireless keyboards open to keystroke sniffing and injection attacks

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Bastille Networks researcher Marc Newlin has discovered a set of security vulnerabilities in low-cost wireless keyboards that could be exploited to collect all passwords, security questions, sensitive personal, bank account and payment card info users input through them.
keysniffer2.jpg

The problem with the vulnerable keyboards is that they don’t encrypt the keystroke data before they transmit it wirelessly to the USB dongle, and that’s because their manufacturers opted to use unencrypted radio communication protocols.

“Wireless keyboards commonly communicate using proprietary protocols operating in the 2.4GHz ISM band. In contrast to Bluetooth, there is no industry standard to follow, leaving each vendor to implement their own security scheme,” Newlin explained how the problem arose.

Aside from eavesdropping on the victim’s keystrokes, an attacker can also inject malicious keystroke commands into the victim’s computer, allowing him to perform actions like installing malware or exfiltrating data.

Full Article. Low-cost wireless keyboards open to keystroke sniffing and injection attacks - Help Net Security
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Do we really need to surprise? Security is somewhat least in priority for improving some products and unfortunately it exist on cheaper products because of lack in awareness.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top