toggle

AAPL Stock: 493.42 ( + 0.25 )

iPhone security slammed at Black Hat

updated 08:00 pm EDT, Fri August 3, 2007

iPhone security slammed


Charles Miller, who first discovered an iPhone vulnerability that was patched by Apple in the iPhone 1.0.1 update, slammed the iPhone's general platform security during a presentation at the Black Hat conference in Las Vegas this week. Saying that his hack was not an isolated incident, Miller labeled Apple's security practices as poor, claiming that they have left the entire OS X platform (both the Mac and the iPhone) vulnerable.

A report in ChannelWeb quotes Miller: "Before they released the patch, I couldn't really say that much because I didn't want to give anyone enough to replicate the exploit. It was really frustrating, because a lot of people leapt to Apple's defense without really knowing the details. Everyone said, 'Oh, everyone gets bugs,' and 'Apple's good on security,' and 'They're better than Microsoft.' When you look at the details of this bug, though, the reality is that Apple's been negligent, I think."

He said that the most problematic Apple practice, from a security standpoint, is the regular inclusion in the OS X platform of older, outdated versions of open source code. Hackers can look at what flaws have been patched in newer releases, then write exploits based on the pre-existing vulnerabilities. Other security experts defended Apple's track record, however, noting that the company has patched serious flaws in a matter of days where Microsoft took several weeks for similar vulnerabilities.

Specifically, the vulnerability reported by Miller was one where viewing a maliciously crafted web page may lead to arbitrary code execution. Apple's description of the flaw is as follows: "Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions."

Via the exploit, attackers could gain access to the iPhone in one of three ways: any iPhone that automatically connects to an attacker-controlled wireless access point with the same name and encryption type as a trusted network would be compromised; an improperly configured forum on any website could allow insertion of the exploit; and iPhone users opening a link delivered via email or an SMS message could unknowingly open a hostile website.

Apple was under pressure to fix the security problem with the iPhone in a matter of days before briefings begin at the Black Hat 2007 conference


by MacNN Staff

TAGS :

 Apple
toggle

Comments

  1. rvhernandez

    Fresh-Faced Recruit

    Joined: Apr 2005

    0

    CM can suckit!

    Somebody just wants their name in the news...

  1. Loert

    Junior Member

    Joined: Nov 1999

    0

    Uhh, yeah right

    Yeah, OS X has terrible security, which explains why in the 6 years I've been running it, I've never had a virus, I've never been exploited, I've never had arbitrary code executed, never had my credentials stolen, and never had antivirus program running. You call me a naive but until some can actually wreck the platform, than I don't have S*** to worry about, do I? I get so tired of hearing about the lack of security of OS X when it's the most secure environment. Why? THERE ARE NO THREATS!!!! If it's so bad, put something out in the wild and prove it. My windows machine is under constant attack, bots, spyware, and whatever the h*** else is out there.

  1. LtCarter47

    Fresh-Faced Recruit

    Joined: Dec 2004

    0

    RE: uhh, yeah right

    amen loert, amen.

  1. ClevelandAdv

    Fresh-Faced Recruit

    Joined: Jul 2004

    0

    The list of if's..

    ..in this exploit are long. While it may be possible, what is the motivation to go through all this to control an iphone temporarily? Just because I could buy a new Ferrari and crash it into a brick wall - does not mean I will, what is the motivation? Sitting in Starbbucks trying to create a botnet out of one or two iphones is an idiotic idea.

  1. e:leaf

    Fresh-Faced Recruit

    Joined: Mar 2006

    0

    OS X is so bad

    at security that I have yet to catch a bug. That OS X may have vulnerabilities I don't deny. I'm sure it does. But the over dramatic characterization is simply mind boggling, and is, frankly, getting old. When something is let loose in the wild, I'll pay these media whores some creedence. Until then, keep your yap shut.

  1. Feathers

    Grizzled Veteran

    Joined: Oct 1999

    0

    macnn slammed on macnn

    ...yet gain a total dog of a story biting the hand that feeds! Should read Apple promptly plugs potential threat to one month old new technology platform!

  1. maybesew

    Fresh-Faced Recruit

    Joined: Apr 2007

    0

    the headline is retarded

    i read that headline and was expecting some big panel discussion or ANYTHING involving the conference. Instead its just one man's opinion, albeit a hacker at black hat, but i mean that is some seriously sensationalizing there.

    I know all these sites are fighting for page views, but shouldnt you earn then my having quality legitimate stories over a long period of time, instead of trying to grab page views with bullshit like this

  1. dogzilla

    Grizzled Veteran

    Joined: Sep 1999

    0

    heh

    Look, I don't want to be alarmist, but please put this into context.

    1) " what is the motivation to go through all this to control an iphone temporarily?" Same as it would be for zombie nets. Your phone is a computer with a web browser. It can be directed to automatically open an ad site, it can be directed to go to a page that looks like AT&T asking you to enter your credit card info for revalidation, it can be directed to send every email address in your contact list to a spammer's database, or it can just be crashed beyond repair because some kid hates iphones.

    2) "Until then, keep your yap shut" - speak fer yourself, bub. I'd rather know about potential issues on a mission-critical piece of kit like my iPhone *before* they become an issue. MacNN could have been more levelheaded and responsible about the posting, but this is MacNN and not some responsible news site.

    3) "Instead its just one man's opinion" - You're right that it's only one man's opinion, but it's the opinion of a responsible security analyst with a doctorate who found a hugely serious issue on the iPhone and who by the way used to work for the NSA. I think if you don't take what he says seriously with his credentials, then you're just dangerously close-minded about Apple security and therefore irrelevant to any worthwhile discussion about security.

  1. Haywire

    Fresh-Faced Recruit

    Joined: Nov 2001

    0

    heh heh

    NSA? Is that them people who found out about those guys that took over the airliners with intent to meet their 70 virgins each? Or maybe they didn't find those guys out.

  1. smezjj

    Fresh-Faced Recruit

    Joined: Dec 2001

    0

    Tired of this s***...

    Does this guy have nothing better to do than slam an OS just because it's made by Apple? If you ask me, he is just shooting his lame a** mouth off because he is a Microsoft crony. I have nothing against Microsoft... I use their software when deemed fit, but if you are going to bad mouth an OS, how about choosing your own?! I can't tell you how many flaws are in VISTA!

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

10 Most Read

Recent Reviews

Logitech Cube

The world of mice could often be described charitably as stagnant: it's an endless sea of ergonomic shapes that assume you're sitting ...

NewerTech and Targus USB Hubs For Gifts

A useful holiday present to resolve an ongoing frustration is a multi-port hub. Whether as a stocking stuffer, Chanukah present, or an ...

X-Rite ColorMunki Photo

Color calibration is the art of tweaking your monitor so that the colors represented on screen better match real life and your printer ...

toggle

Most Commented

10 Most Discussed