Register FAQ/Rules Forum Spy Search Today's Posts Mark Forums Read

Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate.

 
Go Back   Mac Forums > News and Article Discussion > MacRumors.com News Discussion
TouchArcade.com - iPhone Game Reviews and News

Reply
 
Thread Tools Search this Thread  
Old Jul 22, 2007, 08:45 PM   #1
j/k/Andy
macrumors regular
 
Join Date: Jun 2007
Drudge: Flaw Lets Hackers Exploit iPhone

link

FLAW LETS HACKERS EXPLOIT IPHONE, FIRM SAYS
Sun Jul 22 2007 16:03:45 ET

A team of computer security consultants say they have found a flaw in APPLE's popular new iPhone that allows them to take control of the device!

The researchers, working for Independent Security Evaluators, will report on Monday how they could take control of iPhones through a WiFi connection or by tricking users into going to a Web site that contains malicious code.

Developing...

or http://www.drudgereport.com/

Last edited by j/k/Andy : Jul 22, 2007 at 09:07 PM.
j/k/Andy is offline   Reply With Quote
Old Jul 22, 2007, 08:47 PM   #2
chrisdazzo
macrumors regular
 
Join Date: Apr 2006
Location: Fort Collins, CO (CSU)
Send a message via AIM to chrisdazzo Send a message via Skype™ to chrisdazzo
that was the most excited post of the day. CAPS CAPS CAPS!

good thing i don't have an iphone, though, if this IS true.
__________________

Unibody MBP 2.53GHz/4GB/320GB/512MB, BB Storm, WD 1TB & Seagate 1TB HDDs, 23.6" Asus 1080p display
chrisdazzo is offline   Reply With Quote
Old Jul 22, 2007, 08:50 PM   #3
bigmac4ever
macrumors newbie
 
Join Date: Jul 2007
Ouch...Im so very glad I didnt give up my Treo 700 wx for the apple joke of the year.I did come close though.
bigmac4ever is offline   Reply With Quote
Old Jul 22, 2007, 08:51 PM   #4
mkrishnan
Demi-God (Moderator)
 
mkrishnan's Avatar
 
Join Date: Jan 2004
Location: Grand Rapids, MI, USA
Is this the same as or different from the SPI-announced web dialing issue?

It would be overly generous to call the Drudge report article uninformative, and the referenced company's website is shockingly even less informative... nor does this seem to have been carried by anyone other than the Drudge Report as of yet, which seems a bit odd to me....
__________________
Mohan
mkrishnan is offline   Reply With Quote
Old Jul 22, 2007, 08:58 PM   #5
bxlewi1
macrumors newbie
 
Join Date: Oct 2006
Quote:
Originally Posted by mkrishnan View Post
Is this the same as or different from the SPI-announced web dialing issue?

It would be overly generous to call the Drudge report article uninformative, and the referenced company's website is shockingly even less informative... nor does this seem to have been carried by anyone other than the Drudge Report as of yet, which seems a bit odd to me....
Well, it being a Sunday and all - it's not terribly surprising it's nowhere but Drudge (the man never sleeps.)
bxlewi1 is offline   Reply With Quote
Old Jul 22, 2007, 09:02 PM   #6
Dermot81
macrumors member
 
Join Date: Jun 2007
From the few links up at Drudge on the iphone, most have been negative. Pretty biased reporting.
Dermot81 is offline   Reply With Quote
Old Jul 22, 2007, 09:06 PM   #7
j/k/Andy
Thread Starter
macrumors regular
 
Join Date: Jun 2007
it is a classic Drudge flash, short and sweet, but more often then not he gets it nearly right, sorry for the all caps (copy and paste error)
j/k/Andy is offline   Reply With Quote
Old Jul 22, 2007, 09:13 PM   #8
DMK
macrumors newbie
 
Join Date: Jun 2007
Quote:
Originally Posted by Dermot81 View Post
From the few links up at Drudge on the iphone, most have been negative. Pretty biased reporting.
The Drudge Report is biased ?! what a shocker.
DMK is offline   Reply With Quote
Old Jul 22, 2007, 10:08 PM   #9
kkachurak
macrumors regular
 
Join Date: Jun 2007
IMO, the Drudge Report has the same journalistic integrity as a tabloid.
kkachurak is offline   Reply With Quote
Old Jul 22, 2007, 11:20 PM   #10
Littlebit
macrumors newbie
 
Join Date: Jul 2007
The New York Times is reporting about it, as well...

http://www.nytimes.com/2007/07/23/te.../23iphone.html
Littlebit is offline   Reply With Quote
Old Jul 22, 2007, 11:24 PM   #11
MacRumors
macrumors bot
 
Join Date: Apr 2001
Security Firm Reveals iPhone Vulnerability



The NY Times reports that researchers at a security firm Independent Security Evaluators have announced that they have found a vulnerability in the Apple iPhone that allows them to extract personal information and "take control" of the device from a malicious website or WiFi connection:
Quote:
The researchers, working for Independent Security Evaluators, a company that tests its clients’ computer security by hacking it, said that they could take control of iPhones through a WiFi connection or by tricking users into going to a Web site that contains malicious code. The hack, the first reported, allowed them to tap the wealth of personal information the phones contain.
The company has setup a website which provides a video demo of the exploit as well as answers to questions, but does not provide would-be hackers any detailed instructions. Apple has reportedly been notified of findings. A full disclosure of the hack will be released at the Black Hat conference on August 2nd.

According to the site, in their proof of concept, the exploit can read the log of SMS messages, address book, call history, voicemail data and transmit it to the malicious site.

The principal security analyst admits "It's not the end of the world; it's not the end of the iPhone" and it appears it hasn't changed their enjoyment of the iPhone itself. Even the security firm's founder states that while he may more cautious about using a random public WiFi network, "you'd have to pry it out of my cold, dead hands to get [the iPhone] away from me."




Article Link
MacRumors is offline   Reply With Quote
Old Jul 22, 2007, 11:26 PM   #12
dfnj123
macrumors regular
 
Join Date: Jun 2007
looks like apple better come out with a firmware update fast
dfnj123 is offline   Reply With Quote
Old Jul 22, 2007, 11:29 PM   #13
jjarmoc
macrumors newbie
 
Join Date: Apr 2005
Well, this should be fun. I'll be out at blackhat watching this one anxiously, with an iphone in my pocket the whole time.. heh

I'll hold off on judging this until we see some details of what exactly they've found.
jjarmoc is offline   Reply With Quote
Old Jul 22, 2007, 11:29 PM   #14
twoodcc
macrumors 603
 
twoodcc's Avatar
 
Join Date: Feb 2005
Location: Right side of wrong
Send a message via AIM to twoodcc Send a message via MSN to twoodcc
Quote:
Originally Posted by dfnj123 View Post
looks like apple better come out with a firmware update fast
yeah they need to. and i'm sure that they will
__________________
tville pump
Smarter than the average bear
twoodcc is offline   Reply With Quote
Old Jul 22, 2007, 11:31 PM   #15
coumerelli
macrumors 6502
 
Join Date: Apr 2003
Location: state of confusion.
Send a message via AIM to coumerelli
Here's the deal - don't go to random websites that present themselves to you. Simple. I also don't go to dark alleys...at night...by myself....with my iPhone. I just don't. Now, I'm not saying this isn't important, but my parents didn't raise no dummy. It's called caution.
__________________
They say that if you play a Microsoft CD in backwards it plays Satanic music....That's nothing. If you play it forward it installs Windows!!!
coumerelli is offline   Reply With Quote
Old Jul 22, 2007, 11:32 PM   #16
JPyre
macrumors 6502
 
Join Date: Mar 2005
Location: Pistolvania
Send a message via AIM to JPyre
Thank god... this should speed up a much needed update. I want to listen to my music while browsing the web like it's been advertised.
__________________
Dual 2.0GHz G5 Tower, 2.4GHz Black MacBook, 1.5GHz 12" Powerbook, Screenless 667MHz 15" Powerbook, iPhone 3G, Apple ][c with Okidata line printer.
JPyre is offline   Reply With Quote
Old Jul 22, 2007, 11:33 PM   #17
retroneo
macrumors 6502
 
Join Date: Apr 2005
This is great, you can check to see if your girlfriend is cheating on you without even asking! Just SMS her the link to your specially modified site, and then you can see her call history and messages!

or

This is bad, now my girlfriend can check to see if I am cheating on her without even asking! She just SMSes me the link the her specially modified site, and she can see my call history and messages!
retroneo is offline   Reply With Quote
Old Jul 22, 2007, 11:37 PM   #18
nimbuscloud
macrumors regular
 
Join Date: Jul 2007
Quote:
Originally Posted by JPyre View Post
Thank god... this should speed up a much needed update. I want to listen to my music while browsing the web like it's been advertised.
Actually, you can. I'm listening to Depeche Mode while replying to your comment...all from my iPhone.

nimbuscloud is offline   Reply With Quote
Old Jul 22, 2007, 11:38 PM   #19
jjarmoc
macrumors newbie
 
Join Date: Apr 2005
Quote:
Originally Posted by JPyre View Post
Thank god... this should speed up a much needed update. I want to listen to my music while browsing the web like it's been advertised.
Uhhh.. that feature's always worked fine for me.
jjarmoc is offline   Reply With Quote
Old Jul 22, 2007, 11:42 PM   #20
Analog Kid
macrumors 68000
 
Analog Kid's Avatar
 
Join Date: Mar 2003
One of the risks of building this on a full OS X platform. Good news is that any fixes made to the desktop or iPhone should benefit the other...
__________________
"Quick to judge, quick to anger, slow to understand...
Ignorance and Prejudice and Fear walk hand-in-hand."
--Peart
Analog Kid is offline   Reply With Quote
Old Jul 22, 2007, 11:43 PM   #21
anaknipedro
macrumors newbie
 
Join Date: Mar 2006
Location: Utah
Not

I don't believe this. A website crafted to force the iPhone to make unsolicited calls? These guys can't be for real. This is FUD FUD FUD.
anaknipedro is offline   Reply With Quote
Old Jul 23, 2007, 12:01 AM   #22
badtzmaru
macrumors 6502
 
Join Date: Jul 2007
at least we know an iphone update is coming before, or around, august 2!!
badtzmaru is offline   Reply With Quote
Old Jul 23, 2007, 12:02 AM   #23
ErikGrim
macrumors regular
 
Join Date: Jun 2003
Location: Gold Coast, Australia
Send a message via ICQ to ErikGrim Send a message via AIM to ErikGrim Send a message via MSN to ErikGrim
Quote:
Originally Posted by anaknipedro View Post
I don't believe this. A website crafted to force the iPhone to make unsolicited calls? These guys can't be for real. This is FUD FUD FUD.
Why would this be FUD? Unlike the other recent claims of OS X worms and not to mention the whole Month of OS X bugs debacle, these are "ethical" hackers, disclosing the information to Apple FIRST so that they can issue a fix before releasing the information to the general public.

These kind of independent security analyses actually benefit the end user rather than harm them. There's no FUD here at all. Read their FAQ.
ErikGrim is offline   Reply With Quote
Old Jul 23, 2007, 12:04 AM   #24
Lancetx
macrumors 65816
 
Lancetx's Avatar
 
Join Date: Aug 2003
Location: Texas
I'll bet Apple gets a fix out there before this August 2nd conference occurs. I'm not alarmed, as this will get fixed soon enough. In the meantime though, I'll just make sure not to connect to any unknown wi-fi networks.
Lancetx is offline   Reply With Quote
Old Jul 23, 2007, 12:05 AM   #25
badtzmaru
macrumors 6502
 
Join Date: Jul 2007
before anyone says "this is impossible" visit the firm's website and read their preliminary paper (ignore the part about the iphone being released on june 28

http://www.securityevaluators.com/
badtzmaru is offline   Reply With Quote

Reply

Mac Forums > News and Article Discussion > MacRumors.com News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 05:44 PM.

Mac News | Mac Rumors | iPhone Game Reviews | iPhone Apps

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2002-2009, MacRumors.com, LLC