SMS bug could leave every iPhone in the world vulnerable, say hackers

Posted Jul 30, 2009 at 8:35AM by Karl B. Listed in: News Tags: Hackers, iPhone, Las Vegas, remote control, SMS
Ó


iPhone - Image 1


A pair of hackers have reportedly spotted an iPhone bug that could completely expose the Apple device to remote control through a hack. Worst of all, it doesn't matter what hardware revision or OS version the iPhone has.

AppleInsider reports that Charlie Miller and Collin Mulliner revealed at a recent Black Hat security conference in Las Vegas that a single unusual text character can confuse the phone and open it up for unscrupulous types to attack.

The only defense is to shut off the phone completely. The problem is that the vulnerability extends to messaging, so the hack could also be used to further propagate itself by sending out more messages of its own.

Another vulnerability could leave the iPhone open to what amounts to a mobile equivalent of a denial of service attack. Through a series of SMS messages, someone can keep the iPhone offline for 10 seconds at a time.

Both Miller and Mulliner said that they already notified Apple about the security flaw about a month ago, but the company hasn't issued a patch for either of the two issues yet. Neither have they made any announcements regarding the release of any such patch.



Related articles:


Via AppleInsider

 
 
 

Comments [refresh]

by Musev - 2009-07-30 03:52
» ..

HAHAHAH serves them right! Iphones are for *****s

by Slade - 2009-07-30 05:51
» Apple knows

about this.

by TheRockness - 2009-07-30 07:21
» You're right! It says it right there in the article!!

They've known about this for over a month and they haven't done anything, in the public eye, to remedy this issue so the hacker/s making it public. Did you READ the article?



If any one gets a txt message from an unknown caller that is just one symbol (like a square) turn your iphone off immediately. It says that in the article too.

by Navani - 2009-07-30 10:20
» That last bit reminds me of Nintendo

When Bushwacker or whomever contacted Nintendo about how people can play burned games on a Wii through an exploit and they didn't respond.. Then he released the letter publicly. Or something like that

by valefour - 2009-07-31 02:24
» well...

....that's why i'm a proud G1 owner. haha....

by TheRockness - 2009-07-31 05:04
» ..

The G2's looking nice.

by TheRockness - 2009-07-31 07:53
» Fixed!

http://www.redmondpie.com/download-iphone-os-3.0.1-firmware/



Just fire up iTunes and update. I'd say that's a pretty fast response.

by wolfey2424 - 2009-08-01 17:52
» wholly fuc|

yeah.. but they didn't do a damn thing about it after a month? See, this is another reason I dislike apple.

Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!