iPhone Gets Owned by Security Vulnerabilities

According to InfoWorld, Charles Miller, Jake Honoroff, and Joshua Mason just found the Apple iPhone’s first security vulnerability.
Research trio claims the iPhone’s data can be stolen and the device can even be turned into a remote surveillance tool
This exploit comes from a vulnerability in iPhone’s Safari and proof-of-concept has been implemented. The result?
The iPhone is owned. “In our proof of concept, this code reads the log of SMS messages, the address book, the call history, and the voicemail data, it then transmits all this information to the attacker.”
So what can be done? Nothing right now as Apple has been notified and they have just a mere 2 weeks before details of the exploit get released at a Black Hat 2007 security conference in Las Vegas.
Technorati Tags: Apple, IPhone, Security Vulnerability, Exploit, JAMM, Just Another Mobile Monday


3 Comments
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.PatrickJ
Jul 25, 2007
The security researchers’ paper on all of this is very good – it’s at: http://www.securityevaluators.com/iphone/exploitingiphone.pdf.
They also detail a second level of exploit where the iPhone can be made to execute system commands, like playing an alert sound or making a call.
Brandon Steili
Jul 25, 2007
FUD ….
It’s a safari vulnerability that affects Windows and OS X:
Is the new vulnerability in the Mac or Windows versions of Safari?
The vulnerability is also present in both the Mac and Windows versions of Safari, though it may or may not be exploitable there.
Source: http://www.securityevaluators.com/iphone/
PatrickJ
Jul 25, 2007
I don’t totally agree. One key security flaw they discuss is that ALL processes on the iPhone run with SuperUser privileges. So, if you manage to exploit a single app like the browser (as they have), you completely own the device. Now I haven’t used a Mac in quite a while, but if the same horrific SuperUser flaw exists on a Mac, then Wow, that ‘Macs can’t be hacked’ theory really looks silly. Then again, that has been looking less and less true anyway.
And actually, with UNIX under its hood, obviously Mac OSX does not share this flaw with the phone device …
Leave a Reply
You must be logged in to post a comment.
Search JAMM »
Our Sponsors
Most Popular »
Thursday, April 19, 2012 22:52 - 0 Comments
Tuesday, April 17, 2012 21:31 - 0 Comments
Thursday, April 12, 2012 11:23 - 0 Comments
Wednesday, April 11, 2012 23:46 - 0 Comments
Tuesday, April 10, 2012 21:25 - 0 Comments
Monday, April 9, 2012 21:24 - 0 Comments
Sunday, April 8, 2012 21:15 - 0 Comments
Sunday, April 8, 2012 0:11 - 0 Comments
Friday, April 6, 2012 9:15 - 0 Comments
Thursday, April 5, 2012 18:36 - 0 Comments
Monday, March 26, 2012 10:21 - 0 Comments
Said tjchan on 2011-12-21 16:38:43
Said Trisha on 2011-12-21 14:43:31
Said michell angulo on 2011-12-16 13:30:37
Said dgoldring on 2011-12-13 19:18:24
Said Craig Lambert on 2011-12-13 11:15:27
Said hotgirllei on 2011-12-02 00:02:48
Said Jeremy on 2011-10-30 08:22:18
Said tjchan on 2011-10-18 08:44:50
From Our Friends »
The Mobile Spoon
Clinton Fitch
Just Another iPad Blog
© 2009 Just Another Mobile Monday . All Rights Reserved. Sign up for entries RSS and for the comments RSS.
JAMM logo by Talon Communications Group |
it's 18.