Reply to post: Different keystroke injection vulnerabilities

Hackers pop top 'secure' wireless keyboard and mouse kits, gain RCE

Anonymous Coward
Anonymous Coward

Different keystroke injection vulnerabilities

In MouseJack attacks, you send unencrypted data packets to the USB dongle (receiver) even if the targeted wireless keyboard itself only sends encrypted data packets, and you get keystroke injection because the USB dongle accepts and interprets the unencrypted data packets as well (MouseJack keyboard spoofing vulnerability) and sends corresponding USB HID data (keystrokes) to the connected computer system.

The keystroke injection vulnerability shown here is not based on accepting unencrypted data packets but on cryptographic issues concerning AES counter mode used in different wireless desktop sets, like the targeted ones from Cherry, Logitech, and Perixx.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon