Notices



SMS vulnerability on iPhone to be revealed today still isnt patched

Random Community Topics

Post New ThreadReply
 
Thread Tools
  #1  
Old 07-30-2009, 10:27 AM
ICEM/\N's Avatar
ICEM/\N ICEM/\N is offline   Thread Starter  
The Man with the Plan!
Mobile Model: Mogul/Touch/IPHONE3G
Mobile Carrier: Sprint,AT&T,T-Mobile
Mobile OS: 6.5

 
Join Date: April 10th, 2008
Location: Philly, P.A.
Posts: 1,858
Thanks: 0
Thanked 4,700 Times in 1,421 Posts
Downloads: 0
Uploads: 0


View ICEM/\N's Profile   Edit Options Edit Profile Picture View ICEM/\N's Photo Album Add ICEM/\N's to Your Contacts Show Groups Edit Avatar Subscribed Threads Private Messages
SMS vulnerability on iPhone to be revealed today still isnt patched

SMS vulnerability on iPhone to be revealed today, still isn't patched



“ Quote ”

Remember that alleged SMS-based security hole on the iPhone allowing evil-doers to execute arbitrary code and do all sorts of nasty crap like create an army of mobile zombies ready and willing to execute a DoS attack? The guy who found it, security expert Charlie Miller, said that he'd reveal the details of it at Black Hat -- and Black Hat's this week. Sure enough, Miller and his cohorts plan to unleash details of the hack today, and while they claim they informed Apple of the problem over a month ago, Cupertino's yet to make a move. We'd stop short of suggesting iPhone owners all turn off their handsets and take themselves firmly off the grid and into a completely disconnected underground bunker the moment the attack becomes public, but if it's as serious as Miller claims, it definitely bumps up the pressure on Apple to get a fix out on the double -- preferably before 3.1 drops.

(Via Engadget)

“ Quote ”

On Thursday, two researchers plan to reveal an unpatched iPhone bug that could virally infect phones via SMS.


If you receive a text message on your iPhone any time after Thursday afternoon containing only a single square character, Charlie Miller would suggest you turn the device off. Quickly.

That small cipher will likely be your only warning that someone has taken advantage of a bug that Miller and his fellow cybersecurity researcher Collin Mulliner plan to publicize Thursday at the Black Hat cybersecurity conference in Las Vegas. Using a flaw they've found in the iPhone's handling of text messages, the researchers say they'll demonstrate how to send a series of mostly invisible SMS bursts that can give a hacker complete power over any of the smart phone's functions. That includes dialing the phone, visiting Web sites, turning on the device's camera and microphone and, most importantly, sending more text messages to further propagate a mass-gadget hijacking.

Article Controls

EMAIL
PRINT
REPRINT
NEWSLETTER
COMMENTS (7)
SHARE
YAHOO! BUZZ
"This is serious. The only thing you can do to prevent it is turn off your phone," Miller told Forbes. "Someone could pretty quickly take over every iPhone in the world with this."

Though Miller and Mulliner say they notified Apple ( AAPL - news - people ) about the vulnerability more than a month ago, the company hasn't released a patch, and it didn't respond to Forbes' repeated calls seeking comment.

The iPhone SMS bug is just one of a series that the researchers plan to reveal in their talk. They say they've also found a similar texting bug in Windows Mobile that allows complete remote control of Microsoft ( MSFT - news - people )-based devices. Another pair of SMS bugs in the iPhone and Google's ( GOOG - news - people ) Android phones would purportedly allow a hacker to knock a phone off its wireless network for about 10 seconds with a series of text messages. The trick could be repeated again and again to keep the user offline, Miller says. Though Google has patched the Android flaw, this second iPhone bug also remains unpatched, he adds.

The new round of bugs aren't the first that Miller has dug up in the iPhone's code. In 2007, he became the first to remotely hijack the iPhone using a flaw in its browser. But while that vulnerability gave the attacker a similar power over the phone's functions, it required tricking the user into visiting an infected Web site to invisibly download a piece of malicious software. When Miller alerted Apple in July of that year, the company patched the vulnerability before Miller publicized the bug at the Black Hat conference the following month.

(VIA Forbes.com)

Reply With Quote
The Following User Says Thank You to ICEM/\N For This Useful Post:
  #2  
Old 07-30-2009, 12:11 PM
iamdasht19's Avatar
iamdasht19 iamdasht19 is offline    
Member
Mobile Model: TP, TP2, soon Hero
Mobile Carrier: SPJ
Mobile OS: 6.5

 
Join Date: February 7th, 2007
Location: Grand Rapids, MI
Posts: 40,537
Thanks: 0
Thanked 42,425 Times in 15,688 Posts
Downloads: 0
Uploads: 0


View iamdasht19's Profile   Edit Options Edit Profile Picture View iamdasht19's Photo Album Add iamdasht19's to Your Contacts Show Groups Edit Avatar Subscribed Threads Private Messages
Re: SMS vulnerability on iPhone to be revealed today still isnt patched

mmm thats very interesting and will have to watch for that when i have the service on my iphone..... bu i wish they would have said more about the supposed wm one, he just said that there is one but nothing to look ofr or anything like he said with the iphone version...... guess i will have to look into that and thanks for the news share ice.
Reply With Quote
The Following User Says Thank You to iamdasht19 For This Useful Post:
Post New ThreadReply

Tags
iphone, patched, revealed, sms, today, vulnerability


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On


Similar Threads
Thread Thread Starter Forum Replies Last Post
4th Generation iPhone revealed! iamdasht19 Random Community Topics 13 12-21-2009 09:55 PM
iPhone OS 301 update released fixes SMS vulnerability ICEM/\N Random Community Topics 1 08-02-2009 02:52 AM
s2us help slide bar isnt showing up. bonezsz90 General Questions 1 06-24-2008 12:15 AM
Kai´s Today Call, SMS, MMS Counter v.1.3 iamdasht19 WM And PPC Applications 2 04-22-2008 01:25 PM
HOw to post a picture (it isnt that hard people) Tigerz Noob Area 1 12-03-2007 04:53 PM


All times are GMT -5. The time now is 08:25 AM.

Layout Options | Width: Fixed
Contact Us - SPJ Bulletin - Archive - Privacy Statement - Terms of Service - Top