Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Hacking the iPhone as easy as sending an SMS

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
HiyaEmerald Eyes Donating Member (106 posts) Send PM | Profile | Ignore Thu Jul-30-09 02:02 PM
Original message
Hacking the iPhone as easy as sending an SMS
Source: International Business Times.

A Mac security expert has discovered a technique that hackers could use to take control of Apple Inc. computers and iPhone's in order to steal data, disproving the long believed theory that Apple products are more secure than PCs.

Charlie Miller, a noted security researcher, discovered the hack a month ago and contacted Apple, but the company has yet to release a software update fixing the security hole. Miller and fellow researcher Collin Mulliner will make the exploit public at today's Black Hat cyber security conference in Las Vegas, where hosts and attendees exchange information on Internet threats.

The hack involves sending a series of SMS messages to hijack the iPhone. At that point, the hacker could make calls, steal data, send text messages, and basically control all functions of the phone. The hacker could even use it to hijack more iPhones.

Earlier this month, the iPhone was shown to not be as safe as users had expected. Forensics expert Jonathan Zdziarski recently bypassed the iPhone 3GS's passcode PIN and backup encryption with relative ease.

Attacks on Apple computers are extremely rare, but security experts believe this will soon change as Macs gain market share on PCs running Microsoft Corp's Windows operating system.

Dai Zovi, who is the co-author of "The Mac Hacker's Handbook," said that once hackers start to put substantial resources into targeting Apple's computers, they will be at least as vulnerable as Windows machines, according to Reuters.

"There is no magic fairy dust protecting Macs," he said.

Miller, co-author of "The Mac Hacker's Handbook," said that the Mac OS will be easier to crack than Windows as it is bigger and less concisely written. This means that there is more room for vulnerabilities and bugs.


Read more: http://www.ibtimes.com/articles/20090730/iphone-hack-sms-virus-macs-apple-black-hat-conference.htm
Printer Friendly | Permalink |  | Top
Common Sense Party Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 02:04 PM
Response to Original message
1. OK, I'll prove I'm a technomoron: What's an SMS?
Printer Friendly | Permalink |  | Top
 
truthisfreedom Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 02:05 PM
Response to Reply #1
2. Text message
Printer Friendly | Permalink |  | Top
 
Common Sense Party Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 02:08 PM
Response to Reply #2
3. Why don't they just call it a text message?
What does the acronym stand for?
Printer Friendly | Permalink |  | Top
 
HiyaEmerald Eyes Donating Member (106 posts) Send PM | Profile | Ignore Thu Jul-30-09 02:10 PM
Response to Reply #3
5. Short Message Service
:hi:
Printer Friendly | Permalink |  | Top
 
Common Sense Party Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 02:14 PM
Response to Reply #5
7. Thank you.
I've never texted in my life; probably never will. An old Fuddy Duddy, and proud of it, I am!
Printer Friendly | Permalink |  | Top
 
HiyaEmerald Eyes Donating Member (106 posts) Send PM | Profile | Ignore Thu Jul-30-09 02:50 PM
Response to Reply #7
11. neither have I
:rofl:
Printer Friendly | Permalink |  | Top
 
Ter Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 01:30 AM
Response to Reply #7
20. It's ok, the overwhelming majority of people who text pronounce
texted "text-ted" (two syllables) rather than the correct way of "texed" (one syllable). That drives me up a wall, along with 90% of the population who thinks you have to dial "1" first on a cell before the area code (on any cell network, you NEVER have to dial 1 first to make a call in the US, NEVER!).

Used in a sentence, "I just texted someone."

End of rant! :)
Printer Friendly | Permalink |  | Top
 
stlsaxman Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 10:00 AM
Response to Reply #20
23. First i've heard of this... so the second "t" is silent when followed by "ed"?
Edited on Fri Jul-31-09 10:05 AM by stlsaxman
on edit: this question is poised without malice. trying to come up with another example without much success.... :shrug:
Printer Friendly | Permalink |  | Top
 
Ter Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 04:03 PM
Response to Reply #23
28. Yes it is, completely silent
Did you know about the never having to press "1" first when making a call anywhere in the US on a cell? Maybe one day I'll start a topic on it in the Lounge. :)
Printer Friendly | Permalink |  | Top
 
truthisfreedom Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 04:40 PM
Response to Reply #20
29. Hmm. I've read that the proper pronuciation has several possibilities, none of which is "texed".
http://www.howjsay.com/index.php?word=texted&submit=Submit

The most common variant seems to be "Tex'd."
Printer Friendly | Permalink |  | Top
 
Fumesucker Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 02:11 PM
Response to Reply #3
6. Short Message Service n/t
Printer Friendly | Permalink |  | Top
 
formercia Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 02:27 PM
Response to Reply #3
9. And it only has three letters
Some people don't speak English.
Printer Friendly | Permalink |  | Top
 
cabluedem Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 06:51 PM
Response to Reply #3
17. 2001: A Space Oddessy's legacy: Three letter abbreviations like HAL. nt
Edited on Thu Jul-30-09 06:53 PM by cabluedem
Printer Friendly | Permalink |  | Top
 
gmoney Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 09:44 AM
Response to Reply #17
22. TLA - three-letter acronym
Been around for years...
Printer Friendly | Permalink |  | Top
 
we can do it Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 03:49 PM
Response to Reply #2
13. Sending Moronic Shit?
Printer Friendly | Permalink |  | Top
 
zonkers Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 05:10 PM
Response to Reply #1
15. wiki is your friend.
Printer Friendly | Permalink |  | Top
 
Common Sense Party Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 10:34 PM
Response to Reply #15
18. So is DU
Printer Friendly | Permalink |  | Top
 
HiyaEmerald Eyes Donating Member (106 posts) Send PM | Profile | Ignore Thu Jul-30-09 02:09 PM
Response to Original message
4. iPhone Security: Latest Hack Not So Scary (another view)
http://community.zdnet.co.uk/blog/0,1000000567,10013351o-2000440756b,00.htm

Thursday 30 July 2009, 4:43 PM

iPhone Security: Latest Hack Not So Scary
Posted by MobileTech

iPhone Security: Latest Hack Not So Scary
Author: Eric Everson, Founder MyMobiSafe.com

To read the headlines, one would think that the “hack of hacks” had emerged on the iPhone. While there are some vulnerabilities within the iPhone OS, this latest scare is not likely to affect the masses.

This attack wherein hundreds (and yes, that is an “s” on the end of hundreds) of SMS control messages must be sent to an individual handset, is a hack that is best demonstrated in a controlled environment. To this avail if any one of these hundreds of SMS messages is removed or otherwise deleted from the handset before all the commands are in place, this entire hack is defunct. This hack works very similarly to the old fashioned DoS (Denial of Service) hacks that have been around for decades, the primary point of differentiation is simply that this one takes place on the iPhone.

The likelihood of your iPhone being subjected to this labor intensive attack today is seemingly implausible. In all reality you are way more likely to destroy your iPhone by dropping it today than by losing it to this latest hack.

One of the more interesting pieces of tomorrow’s mobile security puzzle is embedded in the physical architecture of tomorrow’s handsets. Today, touch-screens are considered relatively new technology, thus they use the same power supply and “sand box” (the brain of the handset) as the rest of the handset. In turn this makes them way more susceptible to attacks as a hacker’s first target is to disable user control via attacking the touch-screen. Differentiating the core operating components for touch-screen technology is one way to keep mobile users in control of their handsets even under the worst attacks.
Printer Friendly | Permalink |  | Top
 
The Stranger Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 02:24 PM
Response to Original message
8. Oh Darn. I clicked on this thinking that the computer people would be having a flame war.
I've seen them before on DU, and they are, for some bizarre reason, the most virulent of all.
Printer Friendly | Permalink |  | Top
 
SkyDaddy7 Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 02:41 PM
Response to Reply #8
10. I know! LOL!
I clicked to see a pc vs mac fight and was disappointed!
:shrug:

I will check back...
Printer Friendly | Permalink |  | Top
 
Abacus Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 04:01 PM
Response to Reply #8
14. That's why I tossed in a rec
:popcorn:
Printer Friendly | Permalink |  | Top
 
tomm2thumbs Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 03:46 PM
Response to Original message
12. *CLICK HERE to download virus for your iPhone* (ahem)
Edited on Thu Jul-30-09 03:48 PM by tomm2thumbs

of course I'm kidding!!

It is true that the more they start integrating the functions of syncing files, instant messaging, security shutdowns, etc, the more hackers will be able to make use of the software. I can't imagine all of the personal data that exists on one's iphone right now - security question answers, lock combinations, school schedules, passwords, notes on bank accounts, etc - people need to be careful.

As a note, if you have a password you need a reminder for, make sure you still have a way of scrambling it so only YOU know what it is by looking at it, but the actual version in your reminder is not the actual password. Like reminder 'passwd=ifeedthecat' means your 'passwd= wifewalksthedog' - if that makes any sense at all. No need in giving people direct access to any actual password text or keys to your personal accounts that you can protect with your brain! (until they hack that as well)

Printer Friendly | Permalink |  | Top
 
cabluedem Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 06:45 PM
Response to Original message
16. Score: Windows Mobile 6=1. IPhone OS=0 nt.
Printer Friendly | Permalink |  | Top
 
Jkid Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jul-30-09 11:05 PM
Response to Reply #16
19. Windows Mobile 6=1. Android OS=1. IPhone OS=0
Fixed
Printer Friendly | Permalink |  | Top
 
cabluedem Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-01-09 01:02 PM
Response to Reply #19
30. Thank you! nt
Printer Friendly | Permalink |  | Top
 
alfredo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 09:42 AM
Response to Original message
21. Word is, there should be a fix posted Saturday
Printer Friendly | Permalink |  | Top
 
JayMusgrove Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 10:11 AM
Response to Reply #21
24. Word from whom? Please!
I like to know sources.
Printer Friendly | Permalink |  | Top
 
alfredo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 11:41 AM
Response to Reply #24
25. Here:
Printer Friendly | Permalink |  | Top
 
alfredo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 03:39 PM
Response to Reply #24
26. Check your software update today or tomorrow if you have an iPod or iPhone
Printer Friendly | Permalink |  | Top
 
alfredo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-31-09 03:41 PM
Response to Original message
27. The patch should be on softwareupdate
Edited on Fri Jul-31-09 03:42 PM by alfredo
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed Apr 24th 2024, 09:20 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC