PDA

View Full Version : iPhone vulnerability announced



asdf
07-24-2007, 07:19 AM
Link (http://news.com.com/8301-10784_3-9748507-7.html)


iPhone vulnerability announced
Posted by Robert Vamosi

Researchers at Independent Security Evaluators have announced at least two exploits that take advantage of the way the Apple iPhone opens a specially crafted Web page in Safari. Exact details of the vulnerability exploited will have to wait until a presentation at the end of next week's Black Hat conference in Las Vegas. However, some general information has been offered here.

In a preliminary draft of the Black Hat presentation, ISE researchers Charlie Miller, Jake Honoroff, and Joshua Mason note that there are "serious problems with the design and implementation of security on the iPhone," and they single out the fact that most processes run with administrative privileges. Also the custom operating system within the iPhone does not use address randomization or non-executable heaps, making it easy for someone to create an exploit once a vulnerability is found. The researchers said they found such a vulnerability within the Safari browser through fuzzing. Although the researchers wrote two exploits on their own, public exploits for these specific vulnerabilities do not exist. Apple was notified on July 17, 2007, and has yet to respond.

'One of the exploits requires the Safari browser to surf to a maliciously coded Web site. Once there, personal data, SMS text files, contact information, call history, passwords, e-mail, browser history, and voice mail information could be obtained by a remote attacker.

A second exploit developed by the researchers caused the iPhone to make a system sound and vibrate for a second after visiting a maliciously coded Web site. The same exploit could also dial a phone number, send a text message, or turn on the microphone to eavesdrop remotely on conversations within the room

Jaxx
07-25-2007, 11:19 AM
where can I get one!!!

CarpeyBiggs
07-25-2007, 11:25 AM
I'm stunned and in disbelief. I'm calling BS on this. We all know anything made by Apple is without flaw or blemish.

Acca, what's going on here? Is this just some scheming cronies of Mr. Gates trying to stir the pot or what?

accadacca
07-25-2007, 07:38 PM
Acca, what's going on here? Is this just some scheming cronies of Mr. Gates trying to stir the pot or what?
Completely agreed. I call blasphemy and I demand a recount. :lol8:

Kent K25
07-25-2007, 08:40 PM
where can I get one!!!

A virus? Or is it an iVirus?

asdf
07-25-2007, 08:42 PM
We all know anything made by Apple is without flaw or blemish.

:roflol:

stefan
07-25-2007, 09:10 PM
where can I get one!!!

A virus? Or is it an iVirus?



While Apple has not officially confirmed it yet, Appleinsider is claiming that the iBeech virus, which infected ipods earlier this year, has now spread to the iPhone.

http://www.appleinsider.com/articles/07/07/24/iPhone_infected_by_iBeech.html

http://math.bu.edu/people/sf/pub/iBeech.gif