The ModMyTM Family of Sites:
ModMyMotoModMyiModMyGphone





 
 
Register or Connect with Facebook

Discuss AppStore Apps | Browse / Search Cydia | MMi Cydia Stats




  Apple, iPhone & iPad Forums, Mods, Guides, News, Themes, Downloads, and more! | ModMyi.com > iPhone > iPhone News
Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 07-29-2009, 05:18 PM
Cody Overcash's Avatar
Owner / Founder - ModMyi
aka cash7c3
 
Join Date: May 2007
Device + Firmware: iPhone 3g 3.0 beta 4
Operating System: OS X | XP | Sabayon
Location: Denver, CO
Posts: 3,650
Thanks: 290
Thanked 14,928 Times in 516 Posts
Send a message via AIM to Cody Overcash Send a message via MSN to Cody Overcash Send a message via Yahoo to Cody Overcash
Hijacking All iPhones via SMS

Cybersecurity researchers Charlie Miller and Collin Mulliner discovered how to completely hijack any iPhone via SMS. Tomorrow (Thursday) they plan on publicize and reveal the vulnerability at the Black Hat cybersecurity conference in Las Vegas. They will be demonstrating how to send a series of SMS burst to the iPhone which will allow them to take complete control of EVERYTHNIG on the device and then propagate the attack by sending more SMS messages via the hijacked iPhone. According to Miller
Quote:
This is serious. The only thing you can do to prevent it is turn off your phone . . . Someone could pretty quickly take over every iPhone in the world with this.
Since Apple has yet to address this iPhone vulnerability even though Miller and Mulliner notified Apple over a month ago. Miller suggests that if you receive a text message on your iPhone any time after Thursday afternoon containing only a single square character you should turn the device off immediately.

This vulnerability should be heeded and patched by Apple asap (3.1 firmware anyone?). Miller knows his stuff, he was the first one to remotely hjack the iPhone in 2007 via the former bug in iPhone Safari -- old skool, as in jailbreakme.com old skool

via forbes thx steven and jcrod73 for the tip
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following 3 Users Say Thank You to Cody Overcash For This Useful Post:
estes123 (07-30-2009), ipirate (07-30-2009), pacmac (07-29-2009)
  #2  
Old 07-29-2009, 05:24 PM
PhoneLine's Avatar
iPhoneaholic
 
Join Date: Aug 2007
Device + Firmware: iPhone JB + UL / iPhone 3G JB + UL / iPhone 3G-S JB
Operating System: Windows Vista / Windows 7 64 RTM
Location: New York City
Posts: 427
Thanks: 57
Thanked 55 Times in 44 Posts

I read up on it a bit and it seems that it gives the sender of the sms root access. Any chance perhaps those that jailbroke and have changed the root/mobile passwords would be a little safer?

This is not my cup of tea, just since the jailbreakers have more access to the phone then the regular user, I'm thinking maybe there is a way for us to combat this before the apple patch is released?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #3  
Old 07-29-2009, 05:24 PM
dale1v's Avatar
Super Moderator
 
Join Date: Sep 2007
Device + Firmware: iPhone 3GS 32GB (White)
Operating System: OS X Snow Leopard | Windows 7 Professional
Location: Kingston upon Thames, UK
Posts: 3,559
Thanks: 297
Thanked 356 Times in 242 Posts
Send a message via AIM to dale1v Send a message via MSN to dale1v Send a message via Skype™ to dale1v

Errr well that sucks.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #4  
Old 07-29-2009, 05:25 PM
What's Jailbreak?
 
Join Date: Sep 2007
Posts: 19
Thanks: 25
Thanked 2 Times in 2 Posts

I wonder... after turning it off, will rebooting it fix the problem?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #5  
Old 07-29-2009, 05:30 PM
Bernie-Mac's Avatar
Livin the iPhone Life
 
Join Date: Aug 2007
Device + Firmware: Jailbroken White 32GB 3GS
Operating System: Leopard
Location: Las Vegas, NV
Posts: 1,352
Thanks: 142
Thanked 107 Times in 72 Posts
Send a message via AIM to Bernie-Mac

Quote:
Originally Posted by PhoneLine View Post
I read up on it a bit and it seems that it gives the sender of the sms root access. Any chance perhaps those that jailbroke and have changed the root/mobile passwords would be a little safer?

That makes sense. It sounds like it would work and if it does it would be a big "suck it" to all the non-jailbroken jailbreak bashers out there. At least my jailbroken 3GS isnt going to be hacked and used towards world domination
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #6  
Old 07-29-2009, 05:30 PM
PhoneLine's Avatar
iPhoneaholic
 
Join Date: Aug 2007
Device + Firmware: iPhone JB + UL / iPhone 3G JB + UL / iPhone 3G-S JB
Operating System: Windows Vista / Windows 7 64 RTM
Location: New York City
Posts: 427
Thanks: 57
Thanked 55 Times in 44 Posts

Quote:
Originally Posted by kingskid07 View Post
I wonder... after turning it off, will rebooting it fix the problem?
Well, it will probably disconnect their access till they send you another SMS with the flaw again. But if you get the text at 3am and your sleeping, the person can have full access till you notice the message.

Maybe AT&T can block the text from coming through, since they seem to be so good at blocking things. Not a help to those unlocked, but its a start
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #7  
Old 07-29-2009, 05:33 PM
DjPrayz's Avatar
What's Jailbreak?
 
Join Date: Jul 2007
Location: south carolina
Posts: 7
Thanks: 1
Thanked 1 Time in 1 Post

This is not good.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #8  
Old 07-29-2009, 05:34 PM
Sniper366's Avatar
Green Apple
 
Join Date: Dec 2007
Device + Firmware: 3G[S] 16GB waiting for Jailbreak. 2G 8GB Jailbreak, Unlock
Location: Denver
Posts: 53
Thanks: 8
Thanked 6 Times in 4 Posts

can anyone point me to a tutorial or forum regarding changing the root password on a 3GS. so long, alpine!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #9  
Old 07-29-2009, 05:34 PM
Green Apple
 
Join Date: Nov 2008
Device + Firmware: iPhone 2g jailbroken/unlocked on 3.0 and iPod Touch 1st gen Jailbroken on 2.2.1
Posts: 47
Thanks: 0
Thanked 1 Time in 1 Post

LOL I posted this first I should get credit!
http://www.modmyi.com/forums/general...r-hackers.html
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #10  
Old 07-29-2009, 05:40 PM
What's Jailbreak?
 
Join Date: Nov 2008
Posts: 9
Thanks: 1
Thanked 0 Times in 0 Posts

credit? what can you buy with this credit?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #11  
Old 07-29-2009, 05:41 PM
zoolander369's Avatar
Green Apple
 
Join Date: Feb 2008
Device + Firmware: 32gb 3GS
Operating System: Leopard
Location: Atlanta
Posts: 95
Thanks: 6
Thanked 4 Times in 4 Posts

Yikes.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #12  
Old 07-29-2009, 05:42 PM
GregTheWang's Avatar
Livin the iPhone Life
 
Join Date: Mar 2008
Device + Firmware: iPhone 3G 8GB 3.1
Operating System: 10.6.1 MBP
Location: Pennsylvania
Posts: 1,056
Thanks: 23
Thanked 47 Times in 44 Posts
Send a message via AIM to GregTheWang Send a message via MSN to GregTheWang Send a message via Yahoo to GregTheWang

OMGWTFBBQ OUR iPHONES ARE AT RISK. ARM THE NUCLEAR WEAPONS!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to GregTheWang For This Useful Post:
b3nny (07-30-2009)
  #13  
Old 07-29-2009, 05:45 PM
iPhoneaholic
 
Join Date: Oct 2007
Device + Firmware: 32gig 3gs 3.1.2
Operating System: Snow Leopard
Location: Alaska
Posts: 401
Thanks: 19
Thanked 34 Times in 33 Posts

the drug dealers and cell tower destroyers are one step closer!!!!!!!!!!!!!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #14  
Old 07-29-2009, 05:45 PM
JedixJarf's Avatar
Livin the iPhone Life
 
Join Date: Jun 2007
Device + Firmware: iPhone/8gb/1.1.4
Operating System: OS X Leopard
Posts: 1,688
Thanks: 25
Thanked 114 Times in 87 Posts
Send a message via Skype™ to JedixJarf

Quote:
Originally Posted by Sniper366 View Post
can anyone point me to a tutorial or forum regarding changing the root password on a 3GS. so long, alpine!
Just install terminal on your phone or SSH into it and su root, then type passwd and it will prompt you for a new pass.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to JedixJarf For This Useful Post:
SNIP3R (07-30-2009)
  #15  
Old 07-29-2009, 05:47 PM
blkcadi's Avatar
Super Moderator
 
Join Date: Aug 2008
Device + Firmware: 3G-16GB 3.1.2 - black'd
Operating System: Ye ole' Commodore 64
Location: Arizona, Valley of the Sun
Posts: 10,896
Thanks: 698
Thanked 2,801 Times in 2,120 Posts
Send a message via AIM to blkcadi

Scary, just scary. OMG
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
Reply

  Apple, iPhone & iPad Forums, Mods, Guides, News, Themes, Downloads, and more! | ModMyi.com > iPhone > iPhone News

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Go to Top
ModMyI

All times are GMT -6. The time now is 11:27 AM. Powered by vBulletin® Version 3.8.4
If you need Dedicated Server Hosting, you should check out SingleHop. | Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0
Copyright © 2007-10 by ModMy, LLC. All rights reserved.

iPhone News / iPhone Forums / Apple News / Apple Forums / iPad News / iPad Forums / Cydia Hosting /
RSS / Contact Us / / Top