Your favorite Apple, iPhone, iPad, iOS, Jailbreak, and Cydia site.
Thread: New Baseband Hack at Pwn2Own, But No Unlock (yet)
is a discussion within theiPhone News
forums, a part of theGeneral iPhone
section;A new method of unlocking the iPhone baseband will be revealed at this year's Pwn2Own conference, with a new, and potentially malicious, feature: the ability to turn your phone into
...-
01-18-2011, 11:42 AM #1MMi Staff Writer
- Join Date
- Aug 2009
- Location
- Union Square, Somerville, Mass.
- Posts
- 919
- Thanks
- 6
- Thanked 996 Times in 401 Posts
New Baseband Hack at Pwn2Own, But No Unlock (yet)

A new method of unlocking the iPhone baseband will be revealed at this year's Pwn2Own conference, with a new, and potentially malicious, feature: the ability to turn your phone into a spying device. Ralf Philipp Weinmann, a research associate at the University of Luxembourg, will be discussing a huge bug in the firmware of baseband processors commonly used on iPhones and Android devices at the CanSecWest conference in Vancouver, Canada, which begins March 9. However, there's no update on the arrival of a deployable iPhone unlock, whether or not connected to this exploit.
Weinmann says he has identified some serious security holes in Qualcomm and Infineon firmware for GSM baseband processors. As a demonstration of how his exploit completely defeats the data protection engineered by the manufacturers into this firmware, Weinmann says he will show "how to use the auto-answer feature present in most phones to turn the telephone into a remote listening device."
Baseband hackers and security analysts alike are impressed with the sophistication of the exploit. "[It's] like tipping over a rock that no one ever thought would be tipped over, said a forensic and anti-forensic researcher who is known only as 'the Grugq' to protect his own identity. "There are a lot of bugs hidden" in the baseband firmware, he added. "It is just a matter of actively looking for them." Don Bailey, a security consultant with Isec Partners, calls Weinmann's work "an extremely technical attack," but notes that it's unlikely to turn into a problem for everyday phone users because an attacker would need his own cellular base station. However, he notes that using OpenBTS and as little as $2,000 worth of equipment, anyone can create their own tower: something that used to cost tens of thousands of dollars. "Now it's a completely different game," Bailey says.
Weinmann hacked a non-jailbroken iPhone in last year's Pwn2Own contest and exflitrated the SMS database in about 20 seconds. By loading a web page in Safari, Weinmann triggered an exploit that ran entirely inside the iPhone sandbox using the privileges of a non-root user called 'mobile'. With this exploit, Weinmann said, "I can do anything that 'mobile' can do." Weinmann is also credited with finding the TMSI overflow hole that was patched in iOS 4.2. The expectation is that the details on this exploit will also be kept secret until Apple patches the hole.
Source: PC World
-
The Following 4 Users Say Thank You to Paul Daniel Ash For This Useful Post:
dimplenicko (01-20-2011), LEVMAN (01-19-2011), noob_ipod (01-19-2011), reaves205 (01-18-2011)
-
01-18-2011, 11:45 AM #2Moderator
- Join Date
- Apr 2009
- Location
- Owasso,OK
- Posts
- 28,336
- Thanks
- 801
- Thanked 3,476 Times in 2,051 Posts
Interesting to say the least
Follow me @LoganWesterman
Need Your iPhone Unlock Click HERE
Needs Your iPhone Fixed Pm Me!
Have a question about Jailbreaking Pm Simon, Annie, Or just about any other member on here
-
01-18-2011, 11:53 AM #3iPhone? More like MyPhone
- Join Date
- Sep 2008
- Location
- Mtl, Canada
- Posts
- 188
- Thanks
- 18
- Thanked 4 Times in 4 Posts
nice. like to hear the talk about unlocks after like months of silence
-
01-18-2011, 11:55 AM #4iPhoneaholic
- Join Date
- Sep 2007
- Location
- Killeen, Texas, United States
- Posts
- 362
- Thanks
- 72
- Thanked 30 Times in 24 Posts
wonder if any good will come out of this hack.
-
01-18-2011, 12:06 PM #5iPhone? More like MyPhone
- Join Date
- Mar 2008
- Location
- Baja Mexico
- Posts
- 124
- Thanks
- 13
- Thanked 0 Times in 0 Posts
almost every hack means good for the whole community.
Common Sense Its Not So Common
-
01-18-2011, 12:07 PM #6
Cool. Looking forward to the event.
-
01-18-2011, 12:19 PM #7Drinks the Kool Aid
- Join Date
- Mar 2010
- Location
- New York
- Posts
- 1,323
- Thanks
- 131
- Thanked 350 Times in 198 Posts
Amazing stuff!
-
01-18-2011, 12:36 PM #8Retired Moderator
- Join Date
- Jul 2007
- Location
- Saint Louis, MO
- Posts
- 1,088
- Thanks
- 139
- Thanked 128 Times in 90 Posts
Krazy, with a K
-
01-18-2011, 12:38 PM #9
Nice one!! Creative hacks tho
-
01-18-2011, 12:51 PM #10Livin the iPhone Life
- Join Date
- Sep 2007
- Location
- Utah
- Posts
- 1,947
- Thanks
- 87
- Thanked 116 Times in 100 Posts
Can't wait to see it.

-
01-18-2011, 01:57 PM #11
Very cool stuff. I have wanted to build my own tower for a while. Maybe now I will...
-
The Following User Says Thank You to thechronic For This Useful Post:
Snozberries (01-19-2011)
-
01-18-2011, 02:35 PM #12My iPhone is a Part of Me
- Join Date
- Aug 2008
- Location
- The Patriots Area
- Posts
- 794
- Thanks
- 56
- Thanked 75 Times in 60 Posts
nice cant wait to see

-
01-18-2011, 03:09 PM #13
That weinmann dudes a genius! How did he hack a non-jb iphone?? The potential there is scary to say the least.
-
01-18-2011, 04:14 PM #14
not to be the debbie-downer of the group, but seeing as how this event is happening in early march, we probably won't see an unlock from this guy any sooner than we will from the dev team (since they said they're waiting until 4.3)
-
01-18-2011, 04:15 PM #15
-
01-18-2011, 04:38 PM #16
-
01-18-2011, 05:03 PM #17
-
01-18-2011, 05:08 PM #18My iPhone is a Part of Me
- Join Date
- Jul 2010
- Location
- Oklahoma
- Posts
- 526
- Thanks
- 213
- Thanked 37 Times in 30 Posts
Cool, it's funny how simple glitches can be so destructive
Sent from my iPod touch using ModMyi
-
01-18-2011, 06:38 PM #19
Haven't you guys realized yet that Apple has finally found a way to stop people from unlocking their iPhone 4. Its by releasing updates so frequently. By doing this it scares the hackers to not release the unlocks/untethered jailbreaks.
I don't even have an iPhone anymore and I say just release the ******* **** already. If people are retarded enough to update without waiting then its their own fault.
-
01-18-2011, 07:11 PM #20
Yeahh Totaly agree.. Release the darn thing... one day they are going to patch it wether you like it or not.if its gonna be patched in 4.4 or 4.5 or 5.0 ITS GONNA BE PATCHED...
so releasing the Unlock later or sooner for it not being patched is just a stupid excuse..
We all know for now that 4.3 is going to have the same BB as for 4.2.1... there is not going to be any BB updates till iPhone 5 is released
iPhone 5 or iPhone 4 (S) is at he Horizon already and we all see on many website that its going to have New CPU Hardware and stuf meaning BB Updates...
So Dev Teams release the Unlock...




LinkBack URL
About LinkBacks
Reply With Quote



