The ModMyTM Family of Sites:
ModMyMotoModMyiModMyGphone





 
 
Register or Connect with Facebook

Discuss AppStore Apps | Browse / Search Cydia | MMi Cydia Stats




  Apple, iPhone & iPad Forums, Mods, Guides, News, Themes, Downloads, and more! | ModMyi.com > iPhone > iPhone News
Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 09-13-2009, 08:59 PM
Kyle Matthews's Avatar
Owner / Founder - ModMyi
aka poetic_folly
 
Join Date: May 2007
Device + Firmware: iPhone 3G[S] | 3.0 | Jailbroke
Operating System: OS X Leopard 10.6.2
Location: Tampa, FL. Used to be Seattle.
Posts: 8,415
Thanks: 311
Thanked 2,685 Times in 863 Posts
Send a message via AIM to Kyle Matthews
iPhone Security Hole Discovered - View iPhone Passwords

Click the image to open in full size.

Just submitted to Apple as a bug, rpetrich (developer of the ActionMenu packages in Cydia) discovered an interesting security bug in the iPhone firmware.

If a password is inputted in a field, shake to undo, and you will be able to see the character you are deleting. Simply repeat this for every character, and you have the password.

Obviously this isn't an issue that would be useful for those with a criminal bent, as you'd have to be within grabbing distance of someone who input their password, DIDN'T navigate off the page, and then left their iPhone... but a security bug none-the-less. EDIT: rpetrich lets us know, this also works in any apps that save passwords (such as most Twitter apps) - making this bug much more severe.

EDIT AGAIN: This seems to have been fixed in FW 3.1. Which is NOT a good enough reason to upgrade yet, heh - wait for the jailbreak.

EDIT 3: The guys over at NeoWin made up a video showing this bug:



You can submit security bugs to Apple here.

rpetrich's Twitter
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following 2 Users Say Thank You to Kyle Matthews For This Useful Post:
black_orchid (09-14-2009), Kiserai (09-13-2009)
  #2  
Old 09-13-2009, 09:04 PM
Melech518's Avatar
The King
 
Join Date: Feb 2009
Device + Firmware: iPhone 3G 3.1.2 Sn0wediPhone 3G S⃣ 3.1.2 Sn0wed
Operating System: Macbook Pro, iMac, & MacMini OSX 10.6.2
Location: The iPhone Hospital
Posts: 3,975
Thanks: 83
Thanked 871 Times in 437 Posts
Send a message via AIM to Melech518 Send a message via Yahoo to Melech518

What about the ones who have auto-fill turned on? Doesnt that remember passwords hence the bug would work for someone to steal your password if they had your device?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following 3 Users Say Thank You to Melech518 For This Useful Post:
Kiserai (09-13-2009), mafo5000 (09-13-2009), nitehawkz (11-17-2009)
  #3  
Old 09-13-2009, 09:28 PM
FURBY8704's Avatar
Green Apple
 
Join Date: Sep 2007
Device + Firmware: Iphone 3G FW 3.1.2
Operating System: OSX 10.6.2 & WINDOWS 7 ULTIMATE
Location: South Central LA
Posts: 67
Thanks: 13
Thanked 2 Times in 2 Posts

oh my oh my now thats scary =S

which FW s this for??...3.1??

Last edited by FURBY8704; 09-13-2009 at 09:36 PM..
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #4  
Old 09-13-2009, 09:57 PM
What's Jailbreak?
 
Join Date: Feb 2009
Device + Firmware: 16 GB iPhone 3G 3.1 JB
Operating System: OS X 10.6
Location: SF
Posts: 27
Thanks: 0
Thanked 0 Times in 0 Posts

Hmmm tried it on my phone in Safari but doesn't seem to happen to me. Maybe I'm doing it wrong? On iPhone 3G 3.1
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #5  
Old 09-13-2009, 10:01 PM
ifonemaniac's Avatar
iPhone? More like MyPhone
 
Join Date: Sep 2008
Device + Firmware: iPhone Jailbroken+Unlocked
Operating System: Windows 7 also Hackintosh (10.5.2) also cocks
Location: U.S.
Posts: 145
Thanks: 34
Thanked 20 Times in 15 Posts

its not a defect...its a feature..
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #6  
Old 09-13-2009, 10:41 PM
TheOrioles33's Avatar
My iPhone is a Part of Me
 
Join Date: Jul 2007
Device + Firmware: iPhone 3Gs - 32GB
Operating System: XP/Win7/Snow Leopard
Posts: 587
Thanks: 30
Thanked 39 Times in 32 Posts

Quote:
Originally Posted by RandyC View Post
Hmmm tried it on my phone in Safari but doesn't seem to happen to me. Maybe I'm doing it wrong? On iPhone 3G 3.1
It's been fixed for for 3.1. You're good.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #7  
Old 09-13-2009, 10:59 PM
sucram6791's Avatar
Green Apple
 
Join Date: Mar 2008
Device + Firmware: iPhone 3G S 32 GB White
Operating System: Os X
Location: House
Posts: 55
Thanks: 36
Thanked 3 Times in 2 Posts

ya this didnt happen to me in the youtube app
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #8  
Old 09-13-2009, 11:01 PM
Green Apple
 
Join Date: Aug 2009
Device + Firmware: iphone 3.0.1
Operating System: SnowLeopard
Posts: 51
Thanks: 5
Thanked 2 Times in 2 Posts

all i wanna know is "will i ever be able to jailbreak 3.1 or not??"
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #9  
Old 09-13-2009, 11:11 PM
Melech518's Avatar
The King
 
Join Date: Feb 2009
Device + Firmware: iPhone 3G 3.1.2 Sn0wediPhone 3G S⃣ 3.1.2 Sn0wed
Operating System: Macbook Pro, iMac, & MacMini OSX 10.6.2
Location: The iPhone Hospital
Posts: 3,975
Thanks: 83
Thanked 871 Times in 437 Posts
Send a message via AIM to Melech518 Send a message via Yahoo to Melech518

Quote:
Originally Posted by mrguy View Post
all i wanna know is "will i ever be able to jailbreak 3.1 or not??"
Don't hijack this thread. It has absolutely nothing to do with a jailbeak...
Visit http://blog.iphone-dev.org/ for info on a jailbreak
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #10  
Old 09-13-2009, 11:44 PM
Green Apple
 
Join Date: Jul 2009
Device + Firmware: iPhone 3gs w/ Dev Team Jailbreak (Current Firmware)
Operating System: MacBook Pro Intel OSX - (Current Version)
Location: On the Internet ツ
Posts: 41
Thanks: 1
Thanked 2 Times in 2 Posts

if you are trying to do it yourself to see if it works, you have to wait a bit after you type your password or after you start to delete each character or else when u shake to undo, it will undo the whole password or all of the deletes you did to get to the other characters (if that makes sense) ... this bug def works so an easy fix would be not to auto save passwords or keep your phone tight in your hands when inputting a pw
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #11  
Old 09-13-2009, 11:53 PM
StealthBravo's Avatar
Super Moderator
 
Join Date: Jan 2008
Device + Firmware: iPhone 3GS
Operating System: OS X
Location: TX
Posts: 12,216
Thanks: 25
Thanked 2,309 Times in 1,152 Posts
Send a message via AIM to StealthBravo Send a message via MSN to StealthBravo

It works and is amazing.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #12  
Old 09-14-2009, 12:19 AM
Melech518's Avatar
The King
 
Join Date: Feb 2009
Device + Firmware: iPhone 3G 3.1.2 Sn0wediPhone 3G S⃣ 3.1.2 Sn0wed
Operating System: Macbook Pro, iMac, & MacMini OSX 10.6.2
Location: The iPhone Hospital
Posts: 3,975
Thanks: 83
Thanked 871 Times in 437 Posts
Send a message via AIM to Melech518 Send a message via Yahoo to Melech518

^Remind me to keep my phones away from you
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #13  
Old 09-14-2009, 12:28 AM
StealthBravo's Avatar
Super Moderator
 
Join Date: Jan 2008
Device + Firmware: iPhone 3GS
Operating System: OS X
Location: TX
Posts: 12,216
Thanks: 25
Thanked 2,309 Times in 1,152 Posts
Send a message via AIM to StealthBravo Send a message via MSN to StealthBravo

good idea. But there are easier ways to get your passwords
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #14  
Old 09-14-2009, 12:35 AM
angiepangie's Avatar
Livin the iPhone Life
 
Join Date: Jun 2009
Device + Firmware: 3G 3.1.2 Pwned and Ultrasn0wed :)
Operating System: Windows Vista & 7
Location: The Golden State :)
Posts: 3,618
Thanks: 18
Thanked 198 Times in 189 Posts
Send a message via AIM to angiepangie

Quote:
Originally Posted by Melech518 View Post
Don't hijack this thread. It has absolutely nothing to do with a jailbeak...
Visit Dev-Team Blog for info on a jailbreak
Please don't
I'm going crazy with the "When is 3.1 jailbreak out?" posts...
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #15  
Old 09-14-2009, 12:38 AM
StealthBravo's Avatar
Super Moderator
 
Join Date: Jan 2008
Device + Firmware: iPhone 3GS
Operating System: OS X
Location: TX
Posts: 12,216
Thanks: 25
Thanked 2,309 Times in 1,152 Posts
Send a message via AIM to StealthBravo Send a message via MSN to StealthBravo

Someone leaked the 3.1 jailbreak on the dev teams blog several hours ago. Wow that must be annoying to deal with those guys posting it every 30 minutes. Dev-Team Blog


Did you erase it angiepangie?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
Reply

  Apple, iPhone & iPad Forums, Mods, Guides, News, Themes, Downloads, and more! | ModMyi.com > iPhone > iPhone News

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Go to Top
ModMyI

All times are GMT -6. The time now is 10:53 AM. Powered by vBulletin® Version 3.8.4
If you need Dedicated Server Hosting, you should check out SingleHop. | Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0
Copyright © 2007-10 by ModMy, LLC. All rights reserved.

iPhone News / iPhone Forums / Apple News / Apple Forums / iPad News / iPad Forums / Cydia Hosting /
RSS / Contact Us / / Top