Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Serious SMS vulnerability on iPhone, fix in progress
Search Topic:
Uniqs:
281
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 02 Jul 2009 »
« (reported) Major Security Flaw in iPhone 3GS  
AuthorAll Replies
-


TearAbite

join:2001-07-25
Rancho Cucamonga, CA
reply to Smokey Bear
Re: Serious SMS vulnerability on iPhone, fix in progress

Simple work-around until the patch is released: "airplane mode" ..


Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire

reply to Smokey Bear
just a ploy to change the code and thwart imminent jailbreak? Of course if I was the film director that would be the story

Otherwise a nasty bug

Cudni
--
"what we know we know the same, what we don't know, we don't know it differently."
Help yourself so God can help you.
Microsoft MVP, 2006 - 2009


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub

InfoWorld | July 02, 2009

Apple is working to fix an iPhone vulnerability that could allow an attacker to remotely install and run unsigned software code with root access to the phone.

The attack in question exploits a weakness in the way iPhones handle text messages received via SMS (Short Message Service).

The SMS vulnerability allows an attacker to run software code on the phone that is sent by SMS over a mobile operator's network. The malicious code could include commands to monitor the location of the phone using GPS, turn on the phone's microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet, security researcher Charlie Miller said

Apple is working to patch the vulnerability and expects to have a fix ready later this month.

Despite the SMS vulnerability, the stripped-down version of MacOS X used in the iPhone makes it more secure than computers running the full-blown operating system, Miller said.

For starters, the stripped-down version of the OS presents fewer options for attackers, removing applications and features such as support for Adobe Flash and Java, which they might otherwise be able to exploit for vulnerabilities. In addition, the iPhone includes hardware protection for data stored in memory and the phone is designed to only run software code that has been digitally signed by Apple.

The iPhone also requires applications to run in a sandbox, a security feature that isolates them from other applications and limits their access to the phone's capabilities. But SMS offers a way for attackers to get greater access to the phone's capabilities, Miller said.

"SMS is a great vector to attack the iPhone," he said.

Most often used to send brief text messages between cell phones, SMS can also send binary code to an iPhone, which then processes the code without any user interaction. Each SMS message is limited to 140 bytes, but longer sequences can be sent to the phone as multiple messages that are automatically reassembled.

This feature allows larger programs to be delivered to a phone, Miller said.

In addition, vulnerabilities found in the iPhone's SMS function give an attacker root access to the handset, Miller said. That's not the case for the iPhone's other applications, such as its browser, where vulnerabilities only give an attacker access to the application's sandbox.

"The iPhone is more secure than OS X, but SMS could be a critical vulnerability," Miller said.
»www.infoworld.com/d/mobilize/app···hone-934
--
Smokey's Security Forums »www.smokey-services.eu/forums/
Smokey's Security Weblog »smokeys.wordpress.com/
Site Member ASAP - Alliance of Security Analysis Professionals
Forums » Up and Running » Security » SecuritySecurity Software Updates - 02 Jul 2009 »
« (reported) Major Security Flaw in iPhone 3GS  


Thursday, 03-Dec 08:03:55 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [162] Comcast Releasing Promised Usage Meter
· [100] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [82] Avast Antivirus Has Gone Mad
· [80] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [62] Broadband Killed The Game Console
· [55] Rogers Unveils The ISP Dream Model
· [47] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [40] AT&T, Verizon Drop 3G Ad Dispute
Most people now reading
· False positive in Avast! or is it real? [Security]
· [TWC] Audio/Video outage in Brooklyn [Time Warner Cable TV/Voice]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]
· Working in a Stairwell and Surrounding High Walls [Home Repair & Improvement]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· LFM Overkill [World of Warcraft]
· Microsoft actively urges IE 6 users to upgrade [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]