Giveaway: Bracketron Case If outdoor adventures are in your future this summer, enter to win a Bracketron Sport Case with Mount Strap from MacNN and keep that iPhone, iPod or other electronic device safe from the elements.      
toggle

AAPL Stock: 456.5 ( + 3.53 )

http://www.macnn.com/articles/13/03/29/jailbreak.devs.targeted.reveals.flaw.in.messages.app/

'Pranksters' behind spate of iMessage DoS attacks?

updated 09:45 pm EDT, Fri March 29, 2013

 

Jailbreak devs targeted, reveals flaw in Messages app


A flaw in the Messages application used widely on iOS devices has been revealed through a denial-of-service (DoS) attack on a group of jailbreak app developers. The program is subject to simple "flood" type attacks in which an attacker automatically sends messages incredibly rapidly, effectively rendering an account useless. Grant Paul, who goes by "chpwn" on Twitter and was one of the half-dozen victims in the attacks, said that the problem is that "Apple doesn't limit how fast messages can be sent," thus filling up the inbox and requiring the user to clear notifications and text in order to use the app.

Another, known as iH8sn0w, is well known for his jailbreak tool, reports AppleInsider. "On Wednesday night, my private iMessage handle got flooded," he told TheNextWeb, and discovered that simple "automated flood" messages can render the app practically useless, or complex texts using Unicode characters or are very large in size can cause the app to completely crash, particularly if it tries to render "Zalgo" text. He has since created a proof-of-concept AppleScript that demonstrates how easy it is to create and send recurring messages that would effectively block use of Messages.

Paul was able to find a method of deleting the complex texts that were crippling the app, but noted that the attackers were using disposable, temporary email addresses to send the attacks, leaving no effective way to block future attacks. Apple has been notified of the vulnerabilities but has not yet responded on the issue, however iH8sn0w expressed hope that Apple will begin flaggin excessive messaging at the server level and block attacks from there.







by MacNN Staff

toggle

Comments

  1. mr100percent

    Forum Regular

    Joined: 12-06-99

    Easy fix

    A few simple lines of code on Apple's end can easily fix this; No more than 1 message per person per second can be sent.

    Also, hopefully in the future Apple will add blocking in iOS 7, so you can ban certain people from contacting you.

  1. bjojade

    Fresh-Faced Recruit

    Joined: 06-07-07

    Surprised this wasn't figured out sooner. iMessage is an open gate that once your ID gets figured out can be flooded. Putting a limit of one message per second still means 3600 incoming messages an hour.

    Limits would have to be set in a way to stop the DoS damage, but still allow regular messages through. And an overall blocking mechanism would be great too, to keep out those peskys that try and get through. If blocking could also be implemented with SMS and phone calls, that would be awesome.

    Yes, blocking a specific iMessage account can be thwarted by the spammer creating another account, but that takes time on their end, and if Apple sees a huge number of accounts being created from the same address, they can take action specifically.

    The extra scary thing is that you can randomly enter in phone numbers into iMessage, and it'll tell you if that number has an iMessage account associated with it. Pretty easy to script something like that if you wanted to.

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

HighPoint RocketU 1144CM USB 3.0 PCI-E card

Apple was one of the first -- if not the first -- major computer manufacturers to provide then-fledgling USB support at the expense of ...

Nikon WU-1b wireless adapter, PicturePro app

We’re talking George Jetson here. Nikon’s recent introduction of the D600 full-frameDSLR brought a raft of accessories, one of the mos ...

Digital Treasures Props Power Case for iPad

It's not often an iPad case comes with a manual, even a short one, but it seems like an increasing number of models include some form ...

toggle

Most Commented