Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » iPhone: risks of running unauthenticated code
Search Topic:
Uniqs:
149
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Report: 41 Percent of Personal Computing Software Is Pirated »
« Can using Spywareblaster and MVPS Hosts file slow you down?  
AuthorAll Replies


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub

iPhone: risks of running unauthenticated code

SANS | 2009-11-08

Couple of days ago there were a lot of discussions about an attack on iPhone users in the Netherlands where the attacker installed a backdoor that asked the iPhone owner to pay 5 EUR to get rid of the Trojan.

The attack was aimed exclusively against jailbroken (hacked) iPhones – these phones allow the user to run unofficial code and bypass Apple's official App Store. In other words – it allows users to run (often) pirated programs.

One of the problems with most jailbroken iPhones is that they run various services, including SSH among the others. The installation of SSH service is terribly insecure and, besides allowing remote root login, also leaves a default password on most jailbroken iPhones. This "vulnerability" was used by the hacked in the Netherlands and the same thing is exploited by the worm named iKee that was published today.

The worm is actually very, very simple. After execution it will scan certain IP addresses (you can see the list on the screenshot above). All IP addresses belong to 3G customers in Australia and are hardcoded in the worm. If an IP address is reachable, the worm uses a Cydia application to try to login to the IP address as root – it presumes that it is an iPhone since only 3G networks are scanned.

If the login was successful, the worm will copy several files (including itself) to the vulnerable iPhone, will kill SSH (so the phone can't be infected again or by a different attacker) and will change the background as well.

While this is maybe the first iPhone worm that was actually detected in the wild, and while it is very simple, it definitely highlights the risks of running unauthenticated code, something that a lot of people using hacked/jailbroken iPhones are not aware of. Similarly as not running a pirated version of an operating system on your machine, one should not try to evade security mechanisms implemented in phones, especially since they can contain a lot of sensitive personal information.
»isc.sans.org/diary.html?storyid=7549
--
Smokey's Security Forums »www.smokey-services.eu/forums/
Smokey's Security Weblog »smokeys.wordpress.com/
Official Jetico Inc. Support Forums »www.smokey-services.eu/


TearAbite

join:2001-07-25
Rancho Cucamonga, CA
·surpasshosting
·Charter Pipeline

Pretty much the same risk on any system - change the default password!

So IF you jailbreak your phone and IF you install the jailbroke-app SSH, change the default SSH password.

Again - never leave default passwords.. common sense..
--

Don't hate OS X users because of YOUR poor choice in operating systems.
-
Forums » Up and Running » Security » SecurityReport: 41 Percent of Personal Computing Software Is Pirated »
« Can using Spywareblaster and MVPS Hosts file slow you down?  


Saturday, 05-Dec 00:53:07 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [79] The Bandwidth Hog Does Not Exist
· [74] Sprint Defuses GPS Privacy Media Bomb
· [70] Baltimore To Ban Lazy Cable Installs
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Farewell [Bell Canada]
· Google takes aim at browser redirection [Security]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· DNS options, what are YOU using? [TekSavvy]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· Using AirMax to provide triple play services? [Wireless Service Providers]