Monday, October 15, 2018
Search
  
Submit your own News for
inclusion in our Site.
Click here...
Breaking News
Call of Duty: Black Ops 4 Delivers Biggest Launch Day One Digital Sales in Activision History
Samsung Mobile CEO Confirms New Foldable Phone will Also be a Tablet
Hackers Stole Phone Number and Email Details of 29 Million Facebook Users
TSMC Said to be the Sole Maker of the 7nm Apple A13 Chips
Samsung Chromebook Plus V2 Gets "Always On" LTE Connectivity
Intel Further Reduces Stake in EUV Equipment Maker ASML
Facebook Removes More than 800 Spam Accounts, Pages
Xbox Update Rolling Out Today, Brings Avatars and Dolby Vision Video Streaming
Active Discussions
Which of these DVD media are the best, most durable?
How to back up a PS2 DL game
Copy a protected DVD?
roxio issues with xp pro
Help make DVDInfoPro better with dvdinfomantis!!!
menu making
Optiarc AD-7260S review
cdrw trouble
 Home > News > Mobiles > iPhone ...
Last 7 Days News : SU MO TU WE TH FR SA All News

Monday, July 23, 2007
iPhone Vulnerable to Hackers


Apple 's iPhone may be vulnerable to hackers due to a flaw that allows them to take control of the device, according a report in the New York Times on Monday.

Three researchers working for Independent Security Evaluators, a company that tests its clients' computer security by hacking it, said that they could take control of iPhones through a WiFi connection or by tricking users into going to a Web site that contains malicious code.

The iPhone runs a stripped down and customized version of Mac OS X on an ARM processor. Much of the device's claimed security is reliant on its restrictions against running third party applications. Only Javascipt code can be executed in the Safari web browser, ensuring that all such code executes in a "sandbox" environment. Many of the features of Safari have also been removed, such as the ability to use plug-ins such as Flash. Likewise, many filetypes cannot be downloaded. These actions serve to reduce the attack surface of the device.

"However, there are serious problems with the design and implementation of security on the iPhone," the researchers wrote in their report. "The most glaring is that all processes of interest run with administrative privileges. This implies that a compromise of any application gives an attacker full access to the device. Like the desktop versions of Mac OS X on which its operating system is based, the iPhone also does not utilize widely accepted practices, such as using address randomization or non-executable heaps, to make exploitation more difficult. These weaknesses allow for the easy development of stable exploit code once a vulnerability is discovered," they added.

To demonstrate these security weaknesses, the researchers created an exploit for the Safari browser on the iPhone. They used an unmodified iPhone to surf to a malicious HTML document that they created. "When this page was viewed, the payload of the exploit forced the iPhone to make an outbound connection to a server we controlled. The compromised iPhone then sent personal data including SMS text messages, contact information, call history, and voice mail information over this connection. All of this data was collected automatically and surreptitiously," the researchers said.

"After examination of the filesystem, it is clear that other personal data such as passwords, emails, and browsing history could be obtained from the device. We only retrieved some of the personal data but could just as easily have retrieved any information off the device," they added.

Additionally, the security consultants wrote a second exploit that performs physical actions on the phone. "When we viewed a second HTML page in our iPhone, it ran the second exploit payload which forced it to make a system sound and vibrate the phone for a second. Alternatively, by using other API functions we discovered, the exploit could have dialed phone numbers, sent text messages, or recorded audio (as a bugging device) and transmitted it over the network for later collection by a malicious party," the report concludes.

Apple was notified of these findings, including detailed technical documentation, on July 17th.

The New York Times said an Apple spokeswoman said the company took security "very seriously" and that it was looking into the report submitted by Independent Security Evaluators.


Previous
Next
Nonprofit May Launch $350 Laptop by Christmas        All News        Helios Labs Launches the H2000
Karstadt Stores to Sell iPhone in Germany     Mobiles News      Nokia Starts Global Positioning Service

Get RSS feed Easy Print E-Mail this Message

Related News
TSMC Said to be the Sole Maker of the 7nm Apple A13 Chips
Apple to Buy Dialog's Assets and Staff for $600 million
Apple to Offer Its Original Content For Free on iOS Devices: report
Apple, Amazon Deny Report on Chinese Hardware Attack
ITC Judge Found Apple Infringing Qualcomm's Patent But iPhones Won't Be Banned
iPhone Xs Max Estimated to Cost Apple $20 More in Materials Than Last Year's Smaller iPhone X
Tech Giants Back Federal Privacy Safeguards
Apple Said to Shaves Cost from Displays in iPhones
Qualcomm Says Apple Gave Modem Secrets to Intel
Apple Completes Acquisition of Shazam
Apple macOS Mojave Update Brings Dark Mode, Stacks, New Apps, a Redesigned Mac App Store and More
Apple and Salesforce to Bring Siri to Business Apps

Most Popular News
 
Home | News | All News | Reviews | Articles | Guides | Download | Expert Area | Forum | Site Info
Site best viewed at 1024x768+ - CDRINFO.COM 1998-2018 - All rights reserved -
Privacy policy - Contact Us .