-
11-11-2009, 12:37 PM #1MMi Staff Writer
- Join Date
- Aug 2009
- Location
- Union Square, Somerville, Mass.
- Posts
- 919
- Thanks
- 6
- Thanked 996 Times in 401 Posts
Malware Allows Access to Jailbroken iPhones

Well, we all knew this was coming.
The Macintosh security firm Intego reports that they have identified malware that will allow hackers to access data on jailbroken iPhones running OpenSSH with the default root password 'alpine.' Unjailbroken iPhones, devices not running sshd, and devices with unique root passwords are not vulnerable to this exploit. Though Intego currently categorizes the risk of the malware as "low," users should act to secure their phones.
The tool - which Intego identifies as "iPhone/Privacy.A" - works by being installed onto a "Mac, PC, Unix or Linux" computer - or another iPhone - and then scanning the computer's network to find ssh services.
When a vulnerable iPhone is found, the hacker can then download all personal data stored on the device: "e-mail, contacts, SMSs, calendars, photos, music files, videos, as well as any data recorded by any iPhone app."This hacker tool could easily be installed, for example, on a computer on display in a retail store, which could then scan all iPhones that pass within the reach of its network. Or, a hacker could sit in an Internet café and let his computer scan all iPhones that come within the range of the wifi network in search of data. Hackers could even install this tool on their own iPhones, and use it to scan for jailbroken phones as they go about their daily business.
Intego recommends its own VirusBarrier X5 software to identify and eradicate the software on a Mac, but notes there is no detection tool for other computer platforms, or for the iPhone itself. Users of jailbroken phones should not enable ssh except when needed, and should change their root passwords:- install and run "Mobile Terminal"
- type su root at the shell prompt and tap enter
- type passwd and tap enter
- enter alpine for your old password
- enter new password
- enter new password again to confirm
image via IntegoLast edited by Paul Daniel Ash; 11-11-2009 at 02:22 PM. Reason: h/t jedized and TooSlo for corrections to password commands
-
The Following 9 Users Say Thank You to Paul Daniel Ash For This Useful Post:
amybest222 (11-11-2009), CaryDude (11-11-2009), grantskier (11-11-2009), jailbait28 (11-11-2009), johndoe25 (11-11-2009), LEVMAN (11-11-2009), lonewolf045 (12-02-2009), MJedi (11-11-2009), MuseFan288 (11-11-2009)
-
11-11-2009, 12:51 PM #2
as soon as the news came up with the "virus" from that guy changing the background and demanding paypal money, I knew someone was gonna come out with something like this... good think I never run OpenSSH
-
11-11-2009, 12:52 PM #3iPhoneaholic
- Join Date
- Jun 2008
- Location
- Close then you know
- Posts
- 366
- Thanks
- 5
- Thanked 17 Times in 15 Posts
Another one whats up with that wow
-
11-11-2009, 12:54 PM #4What's Jailbreak?
- Join Date
- Sep 2009
- Location
- Salt Lake City, UT
- Posts
- 13
- Thanks
- 3
- Thanked 0 Times in 0 Posts
can i change my password in cyberduck?
-
11-11-2009, 12:55 PM #5Green Apple
- Join Date
- Jul 2009
- Location
- Bronx, New York, United States
- Posts
- 38
- Thanks
- 17
- Thanked 0 Times in 0 Posts
how do i know if im Jailbroken Iphone is open ssh
-
11-11-2009, 12:55 PM #6
wow that sucks.. im glad i did changed password since the first gen iphone to 3Gs. i usually use openssh to mod my iphone with winscp and all that. just change the password and u will be fine. i hope so
have a nice day
-
11-11-2009, 12:58 PM #7Super Duper Moderator
- Join Date
- Aug 2008
- Location
- Valley of the Sun, Arizona
- Posts
- 23,538
- Thanks
- 2,822
- Thanked 7,443 Times in 4,768 Posts
^if you installed it, it is there. If not your fine.

-
11-11-2009, 01:00 PM #8
-
11-11-2009, 01:10 PM #9iPhone? More like MyPhone
- Join Date
- Feb 2009
- Location
- Kansas
- Posts
- 126
- Thanks
- 39
- Thanked 8 Times in 8 Posts
who leaves a default password anyway
-
11-11-2009, 01:14 PM #10
I think i've been breached...I can't change the password it won't let me type in alpine
-
11-11-2009, 01:25 PM #11
I think Apple's hacking us so that they can get less jailbreakers, lol.
-
11-11-2009, 01:26 PM #12What's Jailbreak?
- Join Date
- Mar 2009
- Location
- Florida, USA
- Posts
- 3
- Thanks
- 0
- Thanked 0 Times in 0 Posts
Please revise your steps to change the password using mobile terminal. They are wrong. That will
only change the
password for user 'mobile' and still leave the hacker access to the user 'root' giving them full control of the device STILL.
-
11-11-2009, 01:28 PM #13
im a hardcore idiot when it comes to this ...how do i go about changing my password in winSCP?
-
11-11-2009, 01:36 PM #14
openshh is not even a dependency for any packages, I don't understand why so many newbies hve it installed. if you have no idea how to use it, uninstall it. if you do actually use it, you have three options. You can either consider an alternative, like USB-file transfer with diskaid or netalk which will work for mac. if you do like the ability to do over the air transfer then either change your shh password with mobileterminal or disable shh via sbsettings. if you dot have openshh installed, don't worry about getting a "virus." charlie miller may be an ultimate hacker, but some of things he says are just plan excagerated.
Wanna-be coder/iphone user since '08
-
11-11-2009, 01:41 PM #15iPhoneaholic
- Join Date
- Jul 2009
- Location
- Bellevue, WA
- Posts
- 407
- Thanks
- 40
- Thanked 43 Times in 38 Posts
That's why you log in using SU.
Now, I might be a little rusty since it's been a while.
Open Terminal and type in "su"
This should prompt you to use your credentials to log in.
Follow the steps below while still having SU privileges and it SHOULD change that password.
At least that's how I've been doing it when playing around on my HTC, and if I recall, the commands are spot on with the iPhones.
-
11-11-2009, 01:44 PM #16The Basketball Guru
- Join Date
- Oct 2009
- Location
- NYC
- Posts
- 833
- Thanks
- 53
- Thanked 153 Times in 100 Posts
I un-installed all SSH stuff I had on my iphone but it still showing up in my SBsettings. Does that mean its still on my phone or its jus there for no reason?
-
11-11-2009, 01:44 PM #17iPhoneaholic
- Join Date
- Jul 2009
- Location
- Bellevue, WA
- Posts
- 407
- Thanks
- 40
- Thanked 43 Times in 38 Posts
-
11-11-2009, 01:45 PM #18Super Moderator
- Join Date
- Jan 2008
- Location
- Austin, TX
- Posts
- 8,261
- Thanks
- 819
- Thanked 1,665 Times in 1,156 Posts
-
11-11-2009, 01:49 PM #19Retired Moderator
- Join Date
- Sep 2007
- Location
- In my own little world
- Posts
- 10,357
- Thanks
- 349
- Thanked 1,174 Times in 728 Posts
Dear Apple,
You can stop releasing bugs to try and scare people to quit jail breaking. It doesn't work.
~The Community.Screw #Winning, I'm #Juanning
iMac 27" i5 quad 2.8Ghz (1TB), MacBook Pro 17" 2.6, iPhone 4s
-
11-11-2009, 01:52 PM #20What's Jailbreak?
- Join Date
- Oct 2009
- Location
- Philadelphia
- Posts
- 16
- Thanks
- 1
- Thanked 2 Times in 1 Post
You can change it even quicker if you have mobileterminal installed, just type in the command "passwd" and you can just change it simply from there.



LinkBack URL
About LinkBacks
Reply With Quote


