View Full Version : Two iPhone wireless vulnerabilities exploited


shluke
07-23-2007, 03:11 PM
This isn't a console but there isn't a forum for the iPhone..


Here is an article I found..

Researchers at Independent Security Evaluators (http://www.securityevaluators.com/) have announced at least two vulnerabilities in the way the Apple iPhone opens a specially crafted Web page in Safari. Exact details of the vulnerabilities will have to wait until a presentation at the end of next week's Black Hat (http://www.blackhat.com/html/bh-usa-07/bh-usa-07-index.html) conference in Las Vegas. However, some general information has been offered here (http://www.securityevaluators.com/iphone/).


In a preliminary draft of the Black Hat presentation (http://www.securityevaluators.com/iphone/exploitingiphone.pdf), ISE researchers Charlie Miller, Jake Honoroff, and Joshua Mason note that there are "serious problems with the design and implementation of security on the iPhone," and they single out the fact that most processes run with administrative privileges. Also the custom operating system within the iPhone does not use address randomization or non-executable heaps, making it easy for someone to create an exploit once a vulnerability is found. Although the researchers have exploited two such vulnerabilities on their own, public exploits for these specific vulnerabilities do not exist. Apple was notified on July 17, 2007, and has yet to respond.

One of the exploits requires the Safari browser to surf to a maliciously coded Web site. Once there, personal data, SMS text files, contact information, call history, passwords, e-mail, browser history, and voice mail information could be obtained by a remote attacker.

A second exploit developed by the researchers caused the iPhone to make a system sound and vibrate for a second after visiting a maliciously coded Web site. The same exploit could also dial a phone number, send a text message, or turn on the microphone to eavesdrop remotely on conversations within the room.

CharlieBlix
07-23-2007, 05:26 PM
So the people who make the "unhackable" computers made a hackable phone... sweet.

Ploogle
09-21-2007, 03:03 PM
So the people who make the "unhackable" computers made a hackable phone... sweet.

LOL. Ya. Next thing you know, there'll be an Apple gaming console. And an iHaxxor: the first number-crunching Mac. :P

Virtue
10-11-2007, 08:41 PM
1.1 firmware was realeased and now they have a hack for that 2, also the same thing for the ipod touch.

TheUnderling133
11-07-2007, 02:52 PM
I like macs.

Bauer22
11-07-2007, 06:08 PM
LOL. Ya. Next thing you know, there'll be an Apple gaming console. :P

Too late. They beat you to that in 1995.http://en.wikipedia.org/wiki/Apple_Pippin