republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Serious SMS vulnerability on iPhone, fix in progress
Search Topic:
Uniqs:
283
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 02 Jul 2009 »
« (reported) Major Security Flaw in iPhone 3GS  
AuthorAll Replies


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub

Serious SMS vulnerability on iPhone, fix in progress

InfoWorld | July 02, 2009

Apple is working to fix an iPhone vulnerability that could allow an attacker to remotely install and run unsigned software code with root access to the phone.

The attack in question exploits a weakness in the way iPhones handle text messages received via SMS (Short Message Service).

The SMS vulnerability allows an attacker to run software code on the phone that is sent by SMS over a mobile operator's network. The malicious code could include commands to monitor the location of the phone using GPS, turn on the phone's microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet, security researcher Charlie Miller said

Apple is working to patch the vulnerability and expects to have a fix ready later this month.

Despite the SMS vulnerability, the stripped-down version of MacOS X used in the iPhone makes it more secure than computers running the full-blown operating system, Miller said.

For starters, the stripped-down version of the OS presents fewer options for attackers, removing applications and features such as support for Adobe Flash and Java, which they might otherwise be able to exploit for vulnerabilities. In addition, the iPhone includes hardware protection for data stored in memory and the phone is designed to only run software code that has been digitally signed by Apple.

The iPhone also requires applications to run in a sandbox, a security feature that isolates them from other applications and limits their access to the phone's capabilities. But SMS offers a way for attackers to get greater access to the phone's capabilities, Miller said.

"SMS is a great vector to attack the iPhone," he said.

Most often used to send brief text messages between cell phones, SMS can also send binary code to an iPhone, which then processes the code without any user interaction. Each SMS message is limited to 140 bytes, but longer sequences can be sent to the phone as multiple messages that are automatically reassembled.

This feature allows larger programs to be delivered to a phone, Miller said.

In addition, vulnerabilities found in the iPhone's SMS function give an attacker root access to the handset, Miller said. That's not the case for the iPhone's other applications, such as its browser, where vulnerabilities only give an attacker access to the application's sandbox.

"The iPhone is more secure than OS X, but SMS could be a critical vulnerability," Miller said.
»www.infoworld.com/d/mobilize/app···hone-934
--
Smokey's Security Forums »www.smokey-services.eu/forums/
Smokey's Security Weblog »smokeys.wordpress.com/
Site Member ASAP - Alliance of Security Analysis Professionals


Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire

just a ploy to change the code and thwart imminent jailbreak? Of course if I was the film director that would be the story

Otherwise a nasty bug

Cudni
--
"what we know we know the same, what we don't know, we don't know it differently."
Help yourself so God can help you.
Microsoft MVP, 2006 - 2009


TearAbite

join:2001-07-25
Rancho Cucamonga, CA
reply to Smokey Bear
Simple work-around until the patch is released: "airplane mode" ..
-
Forums » Up and Running » Security » SecuritySecurity Software Updates - 02 Jul 2009 »
« (reported) Major Security Flaw in iPhone 3GS  


Thursday, 10-Dec 12:27:34 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [127] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [74] AT&T Hints At Usage-Based iPhone Data Pricing
· [72] Mediacom Unveils 105 Mbps Pricing
· [67] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [66] Sprint Poised For A Turnaround?
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· New Mediacom Email [Mediacom]
· Cross Server Dungeon Experience [World of Warcraft]
· malware has been found hidden inside an Ubuntu screensaver [Security]
· Will Gearscore die now? [World of Warcraft]
· 60GB would only last us two days! [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· Icecrown 5-man strats [World of Warcraft]
· Battered Hilt Delimma [World of Warcraft]
· PTMP backhauls in rural area [Wireless Service Providers]