4 ms·
> By using the frames to target timers responsible for carrying out regularly occurring events such as performing scans for adjacent networks, Beniamini managed
by msgilligan 10y ago
> By using the frames to target timers responsible for carrying out regularly occurring events such as performing scans for adjacent networks, Beniamini managed to overwrite specific regions of device memory with arbitrary shellcode.
This implies that the exploit can happen when the phone is just scanning for list of available networks.
- Neeek 10y ago>Two of the vulnerabilities can be triggered when connecting to networks supporting wireless roaming features; 802.11r Fast BSS Transition (FT), or Cisco’s CCKM roaming. From reading the actual Project Zero post yesterday, the exploit was figured out using the fast BSS transition which I think is for high frequency p2p transmission, i.e. sending a video to your Chromecast. So you still have to be connected to the same network. https://googleprojectzero.blogspot.com.au/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html https://googleprojectzero.blogspot.com.au/2017/04/over-air-e...