Your favorite Apple, iPhone, iPad, iOS, Jailbreak, and Cydia site.
Thread: 2nd Worm hit Jailbroken iPhones
11-23-2009, 06:45 AM #1
2nd Worm hit Jailbroken iPhones
Just read this from BBC news >>>
New iPhone worm can act like botnet say experts
A second worm to hit the iPhone has been unearthed by security company F-Secure.
It is specifically targetting people in the Netherlands who are using their iPhones for internet banking with Dutch online bank ING Direct.
It redirects the bank's customers to a look-a-like site with a log-in screen.
The worm attacks "jail-broken" phones - a modification which enables the user to run non-Apple approved software on their handset.
The handsets at risk also have SSH (secure shell) installed.
SSH is a file-transfer program that enables users to remotely connect to their phones. It comes with a default password, "alpine" which should be changed.
Users who have installed SSH and not changed the password are especially at risk.
The new worm is more serious than the first because it can behave like a botnet, warns F-Secure.
This enables the phone to be accessed or controlled remotely without the permission of its owner.
"It's the second iPhone worm ever and the first that's clearly malicious - there's a clear financial motive behind it," F-Secure research director Mikko Hypponen told the BBC.
"It's fairly isolated and specific to Netherlands but it is capable of spreading."
He added although the number of infected phones was thought to be in the hundreds rather than thousands, the worm could jump from phone to phone among owners using the same wi-fi hotspot.
A spokesperson for ING Direct said that a warning was going to be put on the bank's official website.
"We are also briefing call centre personnel," she added. "It's important to remember that the worm only affects jail-broken phones and it is only aimed at customers in the Netherlands."
The first iPhone worm, called ikee, was harmless. Users with infected phones found their wallpaper replaced with a picture of 1980s popstar Rick Astley.
It also targeted jail-broken phones which were SSH enabled.
Its creator Ashley Towns said he wrote the ikee program in order to raise the issue of iPhone security.
So, if your a Jailbroken iPhone owner, have installed SSH you can easily change your password. The instruction can be found on cydia, and is as follows;
0: Install MobileTerminal Package
1: Run MobileTerminal
This program will be on your SpringBoard are called "Terminal".
2: Obtain Administrator Access
Run "su root" and provide the root password. The default password as provided by Apple is "alpine".
Here I also run "cd" only to shorten the otherwise very long prompt.
iPhone:~ mobile$ su root
iPhone:/var/mobile root# cd
3: Change the root Password
Run "passwd" and type in your new password twice. Please note that your keypresses will not be displayed on the terminal screen (for security).
iPhone:~ root# passwd
Changing password for root.
Retype new password:
4: Change the mobile Password
This is the regular user account on the device. Run "passwd mobile" and repeat as directed above.
iPhone:~ root# passwd mobile
Changing password for mobile.
Retype new password:
5: Close MobileTerminal
Congratulations! Your job is done!
Sorry too long of a post.
Be safe everyone and lets keep the community informed & safe as well.
Last edited by mixi92; 11-23-2009 at 06:54 AM.
11-23-2009, 03:39 PM #2
BBC News - New iPhone worm can act like botnet say experts
Everyone should have changed their default p/word by now - if you haven't, do it now!
11-23-2009, 04:12 PM #3
Thanks for the 411. Took me about 4 minutes to do the whole thing.
11-23-2009, 06:52 PM #4
mobile terminal crashes every time. I already reinstalled it several time.
Do I need to worry if I do not have openSSH intalled?
11-24-2009, 09:53 AM #5