Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

iPhone Targeted Yet Again

New hacking tool steals personal data off 'jailbroken' iPhones via a wireless network

Nov 11, 2009 | 03:20 PM

By Kelly Jackson Higgins
DarkReading

It has been a tough week for a "jailbroken" iPhone: First a hack changed the smartphone's wallpaper, then a worm spread singer Rick Astley's image as its locked wallpaper, and now a newly released hacking tool can steal personal data.

European researchers discovered the so-called iPhone/Privacy.A malware, which targets jailbroken iPhones and iTouch handsets, via a wireless network. Jailbroken devices are disabled such that the user can run code or apps on the device that aren't "signed" by Apple.

The hacking tool can copy the user's email, contacts, SMS text messages, calendar, photos, music, video, and other data gathered by an iPhone app, according to Intego, the security firm that discovered it, and the victim would have no idea his iPhone was hacked.

The attacker would run the tool on a desktop or laptop machine and be able to identify and break into a jailbroken iPhone or iTouch via WiFi or via the same mobile network. "I haven't seen anything like this before...that's automated to remotely log into the device wirelessly," says Patrik Runald, senior manager of security research for Websense.

But the tool can hack only a limited number of iPhones. It targets a jailbroken iPhone or iTouch that has SSH (Secure Shell) installed and is using the default password that comes with the SSH utility. "You're not at risk unless you have all three" of these factors, Runald says.

Intego says between 6 to 8 percent of all iPhones have been jailbroken. "This hacker tool could easily be installed, for example, on a computer on display in a retail store, which could then scan all iPhones that pass within the reach of its network. Or a hacker could sit in an Internet caf and let his computer scan all iPhones that come within the range of the wifi network in search of data. Hackers could even install this tool on their own iPhones, and use it to scan for jailbroken phones as they go about their daily business," Intego says in its advisory

Websense's Runald says so far the only big threats to the iPhone have been on jailbroken devices. "There are lots of vulnerabilities [found] in the iPhone," he says. "But so far, we've not seen anything [attack-wise] because the model Apple implemented for it is pretty decent. It won't run any unsigned apps on the device."

Of the three attacks this past week, Runald says the iPhoneOS.Ikee worm that was written by an Australian researcher was the most damaging because it spread automatically.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)