The ModMyTM Family of Sites:
ModMyMotoModMyiModMyGphone





 
 
Register or Connect with Facebook

Discuss AppStore Apps | Browse / Search Cydia | MMi Cydia Stats




  Apple, iPhone & iPad Forums, Mods, Guides, News, Themes, Downloads, and more! | ModMyi.com > iPhone > iPhone News
Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 11-04-2009, 10:05 AM
pauldanielash's Avatar
MMi Staff Writer
 
Join Date: Aug 2009
Device + Firmware: iPhone 3.1.2 (7D11)
Operating System: hackintosh OS X 10.6.2 on Intel quad-core
Location: Jamaica Plain, Boston, Mass.
Posts: 321
Thanks: 4
Thanked 185 Times in 85 Posts
Send a message via Skype™ to pauldanielash
Dutch Jailbroken iPhones "Gehackt"

Click the image to open in full size.

A Dutch hacker gained access to a number of jailbroken iPhones that were running ssh with root passwords set to default, and demanded €5 to restore them. He's since returned the money, but the incident highlights a common security issue with jailbroken phones.

It seems likely that the hacker portscanned for ssh on the T-mobile Netherlands network in order to find jailbroken iPhones with SSH running. He then changed their wallpaper to a graphic that mimics an SMS message, reading: "Your iPhone's been hacked because it's really insecure! Please visit doiop.com/iHacked and secure your iPhone right now! Right now, I can access all your files." The website contains a link to a PayPal account, and users were told to send him €5 for instructions on how to regain access to their phones. He also left the following message:
Quote:
"If you don't pay, it's fine by me. But remember, the way I got access to your iPhone can be used by thousands of others—they can send text messages from your number (like I did), use it to call or record your calls, and actually whatever they want, even use it for their hacking activities! I can assure you, I have no intention of harming you or whatever, but, some hackers do! It's just my advice to secure your phone."
He subsequently apologized for asking for the money, and posted the restore instructions on his website.

The exploit is not a complicated one, and a commenter to Ars Technica noted that security researchers have done it in the past, and downloaded users' SMS databases as a "proof of concept" that the security hole exists. A Netherlands-based commenter on tweakers.net provided this pithy explanation that will probably be understandable even by readers who speak no Dutch.

A concern that I have involves problems users have noted after changing their root passwords using the passwd utility, as the Dutch hacker directs his "victims" to do. Users have reported that after changing the password using that method and rebooting, an "Edit home screen" message appears and Springboard crashes, entering a loop and rendering the device unusable. The phone then has to be restored.

Has anyone had success with changing passwords using passwd... and if not, did the reported workaround solve the issue?

image via tweakers.net

Last edited by pauldanielash; 11-04-2009 at 10:09 AM..
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following 3 Users Say Thank You to pauldanielash For This Useful Post:
moochermaulucci (11-04-2009), musicguy303 (11-04-2009), tattoojack (11-05-2009)
  #2  
Old 11-04-2009, 10:13 AM
Cow_King's Avatar
What's Jailbreak?
 
Join Date: Nov 2008
Device + Firmware: iPhone 3GS 32gb 3.01 and 1st gen iPhone 2.2
Operating System: OS X 1.5.7,8 and 1.6.0 Windows XP,Vista and 7
Posts: 22
Thanks: 1
Thanked 3 Times in 3 Posts

well that sucks lol
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #3  
Old 11-04-2009, 10:15 AM
Green Apple
 
Join Date: Apr 2009
Device + Firmware: Itouch 2g 3. 0 jailbroken
Operating System: Windows xp sp3
Posts: 46
Thanks: 2
Thanked 3 Times in 2 Posts

what!!!! Now My S*** Can Get Hacked F***!!!!!!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #4  
Old 11-04-2009, 10:20 AM
Green Apple
 
Join Date: Jun 2009
Device + Firmware: iphone 3gs 3.1.2
Operating System: Mbp 17" snow leopard, windows7
Posts: 42
Thanks: 15
Thanked 1 Time in 1 Post

Well I am changing my password today, just to be sure no one is going to hack into my iPhone

Last edited by petterloco1; 11-04-2009 at 10:24 AM..
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #5  
Old 11-04-2009, 10:22 AM
n00neimp0rtant's Avatar
My iPhone is a Part of Me
 
Join Date: Feb 2008
Device + Firmware: AREN'T YOU PROUD I UPGRAEDED =]
Operating System: OS X 10.6.something
Location: South Park (no, really)
Posts: 769
Thanks: 13
Thanked 69 Times in 50 Posts
Send a message via AIM to n00neimp0rtant

This isn't hacking. This is just using SSH over EDGE. And being a ****.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #6  
Old 11-04-2009, 10:30 AM
ty22's Avatar
iPhone? More like MyPhone
 
Join Date: Dec 2008
Device + Firmware: iPhone 3GS 32GB Black and Palm Pre 1.3.5.1
Operating System: MacBook Air Snow Leopard 10.6.2
Location: Pittsburgh, PA
Posts: 126
Thanks: 7
Thanked 7 Times in 4 Posts

I guess he is a hardcore apple fanboy? Well I'm a mild fanboy but this is crazy.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #7  
Old 11-04-2009, 10:36 AM
Green Apple
 
Join Date: Aug 2008
Posts: 84
Thanks: 7
Thanked 4 Times in 4 Posts
lol

How dum you got to be to pay him lol...
Restore? Change the "APLINE" ...

I doubt any 1 has actualy fallen for this crap cause if you jailbroken your phone than i doubt your a dum ***..
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #8  
Old 11-04-2009, 10:36 AM
What's Jailbreak?
 
Join Date: Oct 2009
Posts: 2
Thanks: 1
Thanked 0 Times in 0 Posts

How do you change your ssh password? sorry me noob. lol
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #9  
Old 11-04-2009, 10:37 AM
pauldanielash's Avatar
MMi Staff Writer
 
Join Date: Aug 2009
Device + Firmware: iPhone 3.1.2 (7D11)
Operating System: hackintosh OS X 10.6.2 on Intel quad-core
Location: Jamaica Plain, Boston, Mass.
Posts: 321
Thanks: 4
Thanked 185 Times in 85 Posts
Send a message via Skype™ to pauldanielash

Quote:
Originally Posted by n00neimp0rtant View Post
This isn't hacking. This is just using SSH over EDGE. And being a ****.
I kind of agree that it's pushing the definition of "hacking," though at least he used port scanning. As much as I dislike the down-defining of hacking as being "any unauthorized access of a device," there's at least some creativity in his exploit, so I'm going with the term the media is using in this case.

It was a **** move to ask for money, but it's good that he returned it. Provided that this leads to more awareness of ssh security, no harm no foul.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #10  
Old 11-04-2009, 10:40 AM
Ticko's Avatar
iPhone? More like MyPhone
 
Join Date: Sep 2008
Device + Firmware: iPhone 3g + 3.0 Jailbroken/Unlocked
Operating System: Linux, Vista x64
Posts: 141
Thanks: 3
Thanked 8 Times in 8 Posts

haha kinda funny actually for people to fall for this...good hole he showed though making people realize to either change their pw or TURN OFF SSH if ur not using it...simple
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #11  
Old 11-04-2009, 10:42 AM
exNavy's Avatar
iPhone? More like MyPhone
 
Join Date: Jun 2007
Device + Firmware: 2G, 3G and 3GS
Operating System: OS X 10.6 intel
Location: Arizona
Posts: 297
Thanks: 18
Thanked 35 Times in 28 Posts

Quote:
Originally Posted by centriod View Post
How do you change your ssh password? sorry me noob. lol
Well you have to have openssh on the phone. It's easier to do if you have mobile terminal installed on the phone as well. You could also do this via terminal on your Mac.

ssh root@10.0.1.9 (or whatever your IP address is)
alpine
passwd

You will now be prompted to enter a new password. You will then be prompted to enter the password again. Your root password is now changed. Remember this when you log in using Fugu or Terminal again. If you forget your password, then you will have to restore the iPhone.

Now enter the following:
passwd mobile

You will now be prompted to enter a new password. You will then be prompted to enter the password again. Your mobile password is now changed.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #12  
Old 11-04-2009, 10:56 AM
xwinger's Avatar
iPhoneaholic
 
Join Date: Jul 2008
Device + Firmware: iPhone 3G 3.1.2 JB (Dead, R.I.P.)
Operating System: 13" Aluminum MacBook 10.6.2, 4GB RAM, 500GB HDD
Location: Calgary, Canada
Posts: 337
Thanks: 34
Thanked 16 Times in 15 Posts

I'll turn off ssh now
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #13  
Old 11-04-2009, 11:02 AM
Fallguy's Avatar
iPhone? More like MyPhone
 
Join Date: Dec 2008
Device + Firmware: iPhone 3G 16GB
Operating System: Win XP
Location: Chicago
Posts: 253
Thanks: 20
Thanked 9 Times in 9 Posts

Thats just wrong . This guy looks like he was actually trying to extort money and then realized his mistake . What a douche .
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #14  
Old 11-04-2009, 11:03 AM
What's Jailbreak?
 
Join Date: Oct 2009
Device + Firmware: iPhone 3G Firmware 3.1(Jailed)
Operating System: Windows XP Pro
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts

Quote:
Originally Posted by sale666 View Post
How dum you got to be to pay him lol...
Restore? Change the "APLINE" ...

I doubt any 1 has actualy fallen for this crap cause if you jailbroken your phone than i doubt your a dum ***..
Exactly, if your smart enough to hack it and jailbreak it, you must know that you can always revert back to the original settings by clicking restore on iTunes. Its just like having the Windows or Mac CD and putting it in your computer and hitting restore. DUH!!!

1 Question, Cant you just turn SSH off and they cant get into your phone, or do you still have to change the password?

-if you do have to change the password, how do I go about doing this without getting the little Springboard error messages??
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #15  
Old 11-04-2009, 11:08 AM
hollow0's Avatar
iPhoneaholic
 
Join Date: Jun 2008
Device + Firmware: iPhone 3G[S] 32gig Sexy White OS 3.1 pwnage
Operating System: OS X SL / Windows 7 Pro, XP Pro
Location: Tampa, FL
Posts: 453
Thanks: 22
Thanked 21 Times in 20 Posts

I had never changed my ssh password but i've always kept it off. I never turn it on because i know someone else could use it..so i was secure in that method. But to be safe one should always change the password and never leave ssh open unless you're planning to use it.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to hollow0 For This Useful Post:
jerru-san0901 (11-04-2009)
Reply

  Apple, iPhone & iPad Forums, Mods, Guides, News, Themes, Downloads, and more! | ModMyi.com > iPhone > iPhone News

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Go to Top
ModMyI

All times are GMT -6. The time now is 09:38 AM. Powered by vBulletin® Version 3.8.4
If you need Dedicated Server Hosting, you should check out SingleHop. | Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0
Copyright © 2007-10 by ModMy, LLC. All rights reserved.

iPhone News / iPhone Forums / Apple News / Apple Forums / iPad News / iPad Forums / Cydia Hosting /
RSS / Contact Us / / Top