Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Hardwarearrow First iPhone Remote Exploit Revealed by White Hats
Ethical Hacker Community Forums
December 03, 2008, 12:33:22 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: First iPhone Remote Exploit Revealed by White Hats  (Read 2833 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: July 24, 2007, 09:40:12 AM »

Quote
Dan Kaplan Jul 23 2007 SC Magazine

In the first true hack of this summer's hottest item, white hat researchers today revealed the Apple iPhone is susceptible to a remote exploit that can give attackers complete control over the device.

A team of consultants at Baltimore-based Independent Security Evaluators today released general details about a buffer overflow vulnerability that could permit malware writers to inject malicious code to steal personal information from a user’s phone, one of the researchers, Jake Honoroff, told SCMagazine.com today. The attack also could be tweaked to drop other malware, for example, a keylogger.

Attackers would attempt to get victims to visit a specially crafted malicious website either through an email link or by controlling a wireless access point, Honoroff, who worked with researchers for 10 days to discover the flaw, said.

As part of the attack, the thieves, who attain administrative privileges, pilfer personal information, which is then sent to a server the attacker operates. The stolen iPhone data can include stored contacts, text messages or passwords, Honoroff said.

"You could make it (the malicious webpage) look totally real, but after a few seconds, their browser would close and all of their information could be stolen," he said.

The Independent Security Evaluators notified Apple about the flaw, and the consulting company is hopeful it will be patched soon. The research team, which included Charlie Miller and Joshua Mason, did not release specific instructions of how to take advantage of the flaw in their disclosure write-up today, and there are no reports of public exploits.

Apple officials would not disclose whether a patch is coming but said the company is investigating the claims.

"We always welcome feedback on how to improve our security," company spokeswoman Lynn Fox told SCMagazine.com today.

The bug is caused by a buffer overflow, a common programming error in which an application attempts to store data beyond its memory capabilities.

To avoid falling victim, users should only visit websites they know and rely on wireless connection points they trust.

If a patch is released, users would download it through the phone's iTunes feature.

Honoroff said the proof-of-concept code shows the iPhone is vulnerable, like any other web-enabled machine. Other researchers have attempted to "unlock" the device over a USB connection, but this marks the first successful break-in over a remote connection, he said.

"The iPhone is a powerful computer and powerful computers are vulnerable to security issues," he said.

Gartner, in a July 10 report, warned enterprises to expect three or four "critical" patches to be released this year for first-generation versions of the iPhone.

"Apple's iPhone was designed and developed first and foremost to appeal to the consumer market," the report said. "Apple didn't include a portfolio of security features and supporting products that are expected by enterprise buyers."

According to the Independent Security Evaluators, although the iPhone restricts third-party applications, it offers the risk of easy exploit because it runs critical processes with administrative privileges and does not use address randomization or non-executable heaps.

Original story:
http://www.scmagazine.com/us/news/article/672808/first-iphone-remote-exploit-revealed

Don
Logged

CISSP, MCSE, CEH, Security+ SME
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #1 on: July 24, 2007, 06:43:36 PM »

w00w00

beat you to it craig and brian!   Grin
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
boney
Jr. Member
**
Offline Offline

Posts: 61



View Profile
« Reply #2 on: July 28, 2007, 01:49:55 PM »

how bout : http://www.iphonehacks.com/
Logged

C|EH

All my life I wanted a computer...
Now I want my life back !
blackazarro
Full Member
***
Offline Offline

Posts: 227



View Profile
« Reply #3 on: August 01, 2007, 04:56:16 AM »


Just two days before revealing the iPhone exploit at Black Hat, Apple release the first patch for the mobile device.

Quote
The patch for the iPhone comes two days before a presentation at the Black Hat Security Briefings by Charles Miller, a researcher with Independent Security Evaluators, which promises to reveal details of a serious flaw in the mobile phone's stripped-down browser. The patch fixes that flaw and four others.

Complete story:

http://www.securityfocus.com/brief/560
Logged

Security+, OSCP, CEH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.048 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.