Please help us by taking our survey
macnn/ipodnn

02/07/2008, 11:25am, EST

Thursday, February 7th

iPhone denial-of-service bug surfaces

An exploit for Apple's iPhone has surfaced that can crash the device when unsuspecting users visit a maliciously crafted Web page. SecurityFocus notes that successful attacks cause a kernel panic, crashing the iPhone which could ultimately lead to remote code execution. The firm states that iPhone firmware version 1.1.2 and 1.1.3 are both affected, and suggest that other versions may also be vulnerable.

Apple Mobile Safari 0 is vulnerable to the denial-of-service attack, which results from a failure to handle exceptional conditions. The security hole is currently unpatched, leaving iPhone owners vulnerable to potential attacks until Apple issues a security update.


Filed under: iPhone, security
Other story tags: exploit

, , 7comments, del.icio.us, slashdot, digg, buzz


7 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
yay!
0
02/07, 11:42am, EST
Yaaaay, proper jailbreakme.com exploit for 1.1.3, here we come!
Fresh-Faced Recruit
Joined Apr 1999
User is offline
The Sky Is Falling!!!!!
0
02/07, 12:15pm, EST
The Sky is Falling! The Sky is Falling!!

Here we go again! IF you visit a site, and IF you puch the one key and the off button at the same time, and IF you stand on your head and shout "I'm the kinkg of the world"..... then someone might take over your iPhone.

Give us a site where this happens and tell us how many people have been affected by this or SHUT UP already!
Fresh-Faced Recruit
Joined Oct 2006
User is offline
old stuff
0
02/07, 12:32pm, EST
We've seen this stuff on 24 of January, first time the bug was discovered. The only news is "security experts" somehow got their hands on a locked iPhone, patched it to 1.1.3 and confirmed the bug works there as well.

Just don't ask them why they couldn't provide a proof of concept exploit that is actually able to take over iPhone, not crash it.
Fresh-Faced Recruit
Joined Jan 2006
User is offline
maliciously crafted...
0
02/07, 12:33pm, EST
Just exactly what kind of pages are "maliciously crafted" as if we didn't know! If you choose to trawl the underbelly of the internet you're bound to find something unpleasant. It's classic parental advice..."Stay on the well lit streets"! I'm guessing the material found on such web-sites looks pretty good on the iPhone's screen. Does touching work?
Forum Regular
Joined Oct 1999
User is offline
not a denial of service
0
02/07, 12:41pm, EST
A denial of service is an ongoing attack that "denies service"; i.e. it prevents you from using something until the attack ceases. This does not do that, and it is therefore not a denial of service. It is a crash.

"DoS" may *sound* cool, but it shouldn't be applied willy-nilly.
Fresh-Faced Recruit
Joined Mar 2004
User is offline
good to know...
0
02/07, 12:46pm, EST
This article is actually pretty straight forward; DOS bug that can cause your iPhone to crash when visiting a malicious site, currently un-patched. No hype. No sensationalism. We've seen worse reporting.
Fresh-Faced Recruit
Joined Feb 2000
User is offline
Re: not a DOS
0
02/07, 3:53pm, EST
A denial of service is an ongoing attack that "denies service"; i.e. it prevents you from using something until the attack ceases. This does not do that, and it is therefore not a denial of service. It is a crash.

Actually, that's just one way to create a Denial of Service. By definition, a DOS attack/exploit is just that, an attack/exploit that makes the device unresponsive.

The classic way is to pound a system with network traffic so valid traffic is unable to get through. But you can also create a DOS scenario by causing a computer to eat up CPU cycles, or just crash the system. If you've ever had a runaway process that makes the whole system virtually unusable, that's a DOS (though it may not be an attack).

By crashing the phone (or computer, server, car, etc), you are, in affect, denying service of the device.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

Buy from the Apple Store The Apple Store: Get great deals on the iPod video, iPod Radio Remote, Refurbished iPods starting at $79, iPod shuffle or iPod nano with free engraving, other iPod accessories for the road, or education discounts on iPods.

Convert PDF to Word: Easily Convert PDF to Word Doc, Excel, and More. Fast and Accurate. No Registration Trial

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

NewsGator Enterprise RSS: Improve Corporate Communication via Web 2.0, RSS, and Social Computing.

Get an IT Degree Online: Get solid credentials. Take your hobby to the next level. Adult Programs. Affordable.


Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.