Your favorite Apple, iPhone, iPad, iOS, Jailbreak, and Cydia site.
Thread: Malicious Worm Takes Aim at Jailbroken iPhones
is a discussion within theiPhone News
forums, a part of theGeneral iPhone
section;There's a new worm on the radar. And, this time, it's a bit more nefarious than anything Rick Astley could have ever imagined himself. The worm is the first malicious
...-
11-23-2009, 05:39 AM #1MMi Staff Writer
- Join Date
- Aug 2009
- Location
- Valparaiso, Indiana
- Posts
- 2,721
- Thanks
- 17
- Thanked 1,439 Times in 531 Posts
Malicious Worm Takes Aim at Jailbroken iPhones

There's a new worm on the radar. And, this time, it's a bit more nefarious than anything Rick Astley could have ever imagined himself.
According to a boatload of media outlets covering the news today, a second worm to hit the iPhone has been detected by security company F-Secure. And, says TG Daily, for now, the worm has set its sights on people in the Netherlands who use their iPhones for internet banking with Dutch online bank ING Direct.The worm is the first malicious infestation to hit the iPhone, the first merely displaying a picture of 1980's crooner Rick Astley - although music lovers might claim that was pretty malicious as well.
In other words, this worm isn't just for "fun." There is an obvious financial motive behind this newly discovered attack.
The worm attacks jailbroken phones and sneakily redirects bank customers to a cloned, look-alike site prompting one to enter their username and password. Naturally, the bank is now frantically trying to get the word out to customers in a hurried fashion.
Unfortunately, it isn't yet clear just how many iPhones may be infected. Once thought to be merely in the hundreds, it's now more likely that the number has increased into the thousands. As warned by F-Secure, the aforementioned worm can recruit iPhones to a botnet and skip around among phones currently sharing the same wi-fi hotspot.
For now, fending off the worm involves some pretty basic steps. For example, jailbroken phone owners are strongly encouraged to revise their SSH password from the default '"Alpine" to help evade the worm."It's the second iPhone worm ever and the first that's clearly malicious - there's a clear financial motive behind it," says F-Secure research director Mikko Hyponen."It's fairly isolated and specific to Netherlands but it is capable of spreading."
To help spread the word and not the worm, F-Secure is endeavoring to publish as many known details as possible of the worm. You can check out their official blog originating from Lithuania by clicking here.
Image via Mobile CastleLast edited by Michael Essany; 11-23-2009 at 12:40 PM.
-
The Following 6 Users Say Thank You to Michael Essany For This Useful Post:
JailbrokeniPodKing (11-23-2009), LEVMAN (11-23-2009), louort3 (11-23-2009), matthew1111 (11-23-2009), micnchris (11-27-2009), reaves205 (11-23-2009)
-
11-23-2009, 05:51 AM #2iPhone? More like MyPhone
- Join Date
- Dec 2007
- Location
- Zürich
- Posts
- 259
- Thanks
- 21
- Thanked 53 Times in 42 Posts
lucky I dont live in the netherlands!
-
11-23-2009, 05:52 AM #3I'm not a star
- Join Date
- Jul 2007
- Location
- MI, USA
- Posts
- 2,441
- Thanks
- 92
- Thanked 164 Times in 143 Posts
For the love of gawd! n00bs: Change your effing root password!!
@Meesany: You should put info on how to change the default password in the first post, n00bs need to be spoon fed.And it will be like a taco inside a taco within a Taco Bell that's inside a KFC that's within a mall that's inside your dream! Springboard screwy after reboot? Here is the fix
-
The Following User Says Thank You to Imahottguy For This Useful Post:
whereswaldo (11-23-2009)
-
11-23-2009, 05:57 AM #4iPhone? More like MyPhone
- Join Date
- Dec 2007
- Location
- Zürich
- Posts
- 259
- Thanks
- 21
- Thanked 53 Times in 42 Posts
-
11-23-2009, 05:58 AM #5MMi Staff Writer
- Join Date
- Aug 2009
- Location
- Valparaiso, Indiana
- Posts
- 2,721
- Thanks
- 17
- Thanked 1,439 Times in 531 Posts
@Imahottguy Thanks! I've put in a link.
-
-
11-23-2009, 06:01 AM #6iPhone? More like MyPhone
- Join Date
- Sep 2007
- Location
- US/RP
- Posts
- 115
- Thanks
- 12
- Thanked 32 Times in 25 Posts
Got it on...see post...instruction also in cydia...
2nd Worm hit Jailbroken iPhones
Thanks Messany...hope everyone would change their password.Last edited by mixi92; 11-23-2009 at 06:01 AM. Reason: Automerged Doublepost
-
11-23-2009, 06:09 AM #7Livin the iPhone Life
- Join Date
- Sep 2008
- Location
- In a van down by the river
- Posts
- 4,831
- Thanks
- 551
- Thanked 515 Times in 427 Posts
Yet another convincing piece of evidence that Apple can use against jailbreaking in the upcoming hearings. Great.
-
The Following User Says Thank You to CaptainChaos For This Useful Post:
JailbrokeniPodKing (11-23-2009)
-
11-23-2009, 06:34 AM #8
Noob question, But this work if you dont have SSH installed? or is the root and alpine set by default as soon as you jailbreak?
-
11-23-2009, 06:38 AM #9Livin the iPhone Life
- Join Date
- Sep 2008
- Location
- In a van down by the river
- Posts
- 4,831
- Thanks
- 551
- Thanked 515 Times in 427 Posts
If you don't have ssh installed then you don't have to worry about it. The benefits of having it though are why it will always be on my phone.
-
The Following User Says Thank You to CaptainChaos For This Useful Post:
jalexis4192 (11-23-2009)
-
11-23-2009, 06:46 AM #10
It's as simple as this.... if you know how to and have Jailbroken your phone you SHOULD know how to change your root password. Pure laziness and it's there fault to get infected.
-
11-23-2009, 06:49 AM #11
-
11-23-2009, 06:51 AM #12Livin the iPhone Life
- Join Date
- Sep 2008
- Location
- In a van down by the river
- Posts
- 4,831
- Thanks
- 551
- Thanked 515 Times in 427 Posts
True, but if your phone gets stuck at the bootlogo and you don't have ssh then your only option is to restore.
-
11-23-2009, 06:54 AM #13Livin the iPhone Life
- Join Date
- Aug 2008
- Location
- New York
- Posts
- 1,023
- Thanks
- 3
- Thanked 78 Times in 63 Posts
These aren't that complex of "Worms". Any basic programmer can write a walking script that simply:
1) Try SSH to IP
2) Login as root/alpine
3) Replace hosts file with bad one
4) Try SSH to next IP.
-
11-23-2009, 07:39 AM #14My iPhone is a Part of Me
- Join Date
- Sep 2007
- Location
- Foco, Colorado
- Posts
- 993
- Thanks
- 4
- Thanked 36 Times in 28 Posts
MTF. leave other people **** alone.
-
11-23-2009, 07:45 AM #15What's Jailbreak?
- Join Date
- Jun 2009
- Location
- Brooklyn NY
- Posts
- 18
- Thanks
- 1
- Thanked 7 Times in 2 Posts
TO ALL : Please just change the root password and thats it its not that hard just click on this link and it will show you step by step on how to do it ..
How To Change the iPhone’s Root Password | Just Another iPhone Blog
Dont forget to hitt the " thanks " if it helped you .
-
The Following 5 Users Say Thank You to marko911 For This Useful Post:
asidrave (11-23-2009), cbgaines (11-23-2009), darwina (11-23-2009), fidosam (11-23-2009), Michael Essany (11-23-2009)
-
11-23-2009, 07:48 AM #16iPhone? More like MyPhone
- Join Date
- Dec 2007
- Location
- Montreal, QC, Canada
- Posts
- 101
- Thanks
- 21
- Thanked 10 Times in 5 Posts
Its simple to avoid. Just change the password from alpine to whatever you want. Issue resolved. I can't live without ssh so its a no brainer.
-
11-23-2009, 07:48 AM #17
Has anyone had the thought that maybe Apple are behind these "attacks" to scare people away from jailbreaking?

-
11-23-2009, 08:01 AM #18iPhone? More like MyPhone
- Join Date
- Oct 2009
- Location
- Austin Texas
- Posts
- 129
- Thanks
- 14
- Thanked 15 Times in 8 Posts
What is this, the 3rd 'worm' in as many weeks due to this issue?
I cannot believe this is still occurring. Seriously, once I used Cyberduck with SSH, that was the first thing I changed.
I think this is the result of a lot of people simply doing 'cool' things on their phone and do not really understand the ramifications of leaving ANY passwords in default...
I believe this will only get worse as JB becomes more mainstream.
WOW!!
-
11-23-2009, 08:14 AM #19
Isn't it, really, "You are, Number 6"? Oops, I gave it all away.
You know, for us Mac-ies, there are other ways to access files. I use iFuntastic, I ain't 'fraid of no worm!
-
11-23-2009, 08:35 AM #20Developer
- Join Date
- Feb 2008
- Location
- Oakland, Pittsburgh, PA
- Posts
- 1,341
- Thanks
- 25
- Thanked 600 Times in 136 Posts
Oh, the SSH "hacker" sh!t again? Really? This is getting pretty old.
Can I Jailbreak? | Can I Unlock? | Ensure iDevice Downgrades | Download ANY iPhone IPSW | StatusNotifier on iOS 4 | Defeat apps that block jailbroken devices | Quick Reply SMS (and more) FREE
Want to say "Thanks?" Check out my Gigs on Fiverr!




LinkBack URL
About LinkBacks
Reply With Quote


