Please help us by taking our survey
troubleshooting/tutorials/security

07/23/2007, 1:00pm, EDT

Monday, July 23rd

iPhone security flaw offers complete control

A new security flaw in Apple's iPhone could allow attackers to access personal information such as SMS text messages and voice mails stored on the device, and could even provide malicious users with a means of recording the iPhone owner or taking photos with the handset's built-in digital camera. The exploit, which was discovered by a group of security researchers who plan to detail the hole at the BlackHat conference in Las Vegas on August 2nd, offers complete unfettered access to the phone with administrator privileges. The experts who discovered the flaw at Independent Security Evaluators are refusing to provide extensive details on the security flaw but said iPhone users need only access a maliciously crafted website or forum post to hand over complete control of their phone to that site's owner.

Attackers gain access to the iPhone in one of three ways: any iPhone that automatically connects to an attacker-controlled wireless access point with the same name and encryption type as a trusted network would be compromised; an improperly configured forum on any website could allow insertion of the exploit; and iPhone users opening a link delivered via email or an SMS message could unknowingly open a hostile website.

ISE researchers have already alerted Apple to the presence of the security flaw, and have offered a patch to the Cupertino-based company to repair the issue. A video is available showing the compromise of an iPhone's security.


Filed under: troubleshooting

, , 19comments, del.icio.us, slashdot, digg, buzz


19 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Give me a break!
0
07/23, 1:23pm, EDT
What the article failed to also say was......

that the aforementioned hacker / attacker would have a better chance of success by simply jumping me on the street, putting a gun to my head, and jacking my iPhone from me.

I mean, come on, all these "ifs and coulds" are enough to make me laugh. I know which networks I am connecting to and I know which websites I am browsing with my iPhone.

If you carelessly jump around the internet and click on any and every link you come accross, then you might need to worry about this. However, just as on your computer, if you are a smart web citizen, you have nothing to worry about.

By the way, I am sure this study / hacker group is being funded by MicroShaft to find this and any other flaw. I mean, who else has enough time to sit around for two weeks without pay and find an exploit... that even if it works in the wild... gets them information that most likely would not reap any financial rewards. I mean, once you get the names and numbers of my infamous friends and family... what are you going to do with them? Sell them for top dollar... or try to blackmail my mother to not post her meatloaf receipe that she emailed me on the net?
Fresh-Faced Recruit
Joined Oct 2006
User is offline
...wow..
0
07/23, 1:48pm, EDT
And people seem to think Testudo doesn't have a point when he asks why people get so defensive when announcements like this are made.

How bad would your world be rocked if you actually WORKED at Apple?
Fresh-Faced Recruit
Joined Jan 2006
User is offline
The question...
0
07/23, 1:56pm, EDT
The question isn't whether vulnerabilities will appear; of course they will. The question is, rather, how quickly can Apple respond and what do they learn from each security hole. If Apple has this patched by the end of the day, it will reflect positively on the iPhone as a product that is secure in the long-run.
Mac Enthusiast
Joined Jan 2001
User is offline
Re: give me a break
0
07/23, 2:17pm, EDT
If you carelessly jump around the internet and click on any and every link you come accross, then you might need to worry about this. However, just as on your computer, if you are a smart web citizen, you have nothing to worry about.

Hey, everyone, stop trying to break the iphone! Its not possible, we all know this. Because every iPhone user knows exactly what he's doing, going, clicking on, etc, and would never fall for such a thing!

Man, how stupid do these hackers have to be to think people would fall for this stuff? I mean, sure, you could consider the vast number of users who unknowingly download and install trojans, malware, spyware, etc, I would think this is a concern. Or those who fall for phishing scams. Or Nigerian treasury protection scams. Or ebay scams.

But these people would never own an iPhone! So its pointless!

Fresh-Faced Recruit
Joined Aug 2001
User is offline
no break for you
0
07/23, 2:18pm, EDT
I don't understand jhawk95 why issues like this are "no big deal". If you look at the past 3 years of Internet Explorer/Windows vulnerabilities, not a SINGLE ONE has been self spreading. Almost all PC malware these days relies on the user to initiate the sequence of events that allows it to infect the machine-e.g. by clicking on a link in an email or by going to a previously "safe" Web site that has since been compromised. That means that unless you are willing to give Internet Explorer and Windows a free pass on worms, this IS a big deal.

Oh and just because you know the Web sites you visit doesn't mean you are safe. What happens if MacNN or some other "known" Web site is hacked so that when you visit it, you get infected? It's happened before to PC users, sometimes with some pretty well known Web pages (a lot of times it's with "blogs" that have not been properly locked down). Attackers simply insert an IFRAME into the existing HTML source so that unsuspecting victims go to the Web page, get infected with some malware using a hole in Internet Explorer (just like this hole in Safari) and boom, instant infection of a lot of people.

Until people like you stop saying "Bah humbug!" to every security vulnerability that Apple has, people are going to target the Mac to prove the naysayers wrong.
Fresh-Faced Recruit
Joined Jul 2006
User is offline
Phishing mails
0
07/23, 2:19pm, EDT
This bears another question. The text of the article includes "and iPhone users opening a link delivered via email or an SMS message could unknowingly open a hostile website."

How does the iPhone's Mail and Safari handle these types of links (those that look like one thing, but go somewhere else)? I mean, in OS X, I don't recall ever being warned of a possible re-directed URL. Do you get any of that in the iPhone?
Fresh-Faced Recruit
Joined Aug 2001
User is offline
Re: phishing mails
0
07/23, 3:19pm, EDT
In MacOS X Mail, if you hover your mouse over the link, it shows you via a tooltip if the link is different than what it says.

On the iPhone, if you "tap-hold" over the link, I think it does the same thing.
Professional Poster
Joined Sep 1999
User is offline
altered?
0
07/23, 3:51pm, EDT
First how do we know this is real? Second how do we know the hackers have not altered the hardware in order to allow their exploit. We've seen this kind of claim before only to find out that the hardware was altered in some way.

These kinds of claims are beginning to numb users way more than they help. We'll have something to worry about when the headline says something like "iPhone has a confirmed vulnerability, by a third party, on a device that has never been in the hands of the hacker." Until then this is nothing more that a scare tactic for hacker's personal gain.

I'll believe this when I see it in the wild. An no I don't believe either the iPhone or the Mac is impossible to hack into. But as long as the device has been in the hands of the hackers, physically, we have no idea what is actually real.

Fresh-Faced Recruit
Joined Apr 2007
User is offline
stuff
0
07/23, 4:54pm, EDT
In MacOS X Mail, if you hover your mouse over the link, it shows you via a tooltip if the link is different than what it says.

Yeah, but wouldn't it be nicer if they could do the comparison for you, and tell you when they're different?

These kinds of claims are beginning to numb users way more than they help.

That's the POINT! If you numb users to this stuff, they stop paying attention, so when some hackers do come up with a way (which might be the case here), people will have no defenses or cares (in their "wake me when its in the wild!" mood, which, really, is just funny, because that's a tad too late to protect you) and devices are exploited with nary a notice from the users.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
more 'hacker' bs
0
07/23, 8:58pm, EDT
you know, I just found a way to hack into your testicles. I wont show you, but I really really do know how. I will demonstrate it in a week or so. I mean it, I really can do it. I have already turned the info over to your scrotum. Really, I can do it.
Fresh-Faced Recruit
Joined Nov 2005
User is offline
additional comments:..1..2..Next
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Turn your laptop into CASH: Sell us your used laptop. Working or not. Get money FAST. Instant online quote. Shipping is FREE.

PowerBookMedic will fix any Apple laptop or iPod: We offer Parts, Hard Drives, Superdrives, Ram Upgrades & Repairs all backed up w/ our 1YR Warranty!

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

Core: Browse a huge selection now. Find exactly what you want today.

Shop Forcore: Largest Selection of Wine Online Lowest Prices on core.

Dual Anime DVD Sale on Now: Dual TV Series anime DVD Box set - save up to 80%, Free ship.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.