Page 1 of 1

Hackers Can Crack iPhones Remotely.

Posted: Tue Jun 16, 2009 2:26 pm
by Libra Monkee
/. wrote:Two researchers have found a way to run unauthorized code on an iPhone remotely. This is different than 'jailbreaking,' which requires physical access to the device. Normally applications have to be signed cryptographically by Apple in order to run. But Charles Miller of Independent Security Evaluators and Vincenzo Iozzo from the University of Milan found more than one instance in which Apple failed to prevent unauthorized data from executing. This means that a program can be loaded into memory as a non-executable block of data, after which the attacker can essentially flip a programmatic switch and make the data executable. The trick is significant, say Miller and Iozzo, because it provides a way to do something on a device after making use of a remote exploit. Details will be presented next month at the Black Hat Conference in Las Vegas." The attack was developed on version 2.0 of the iPhone software, and the researchers don't know if it will work when 3.0 is released.
Would you like to know more?

I wish I was going to Black Hat.

Who took a bite out of Apple?

Re: Hackers Can Crack iPhones Remotely.

Posted: Wed Jun 17, 2009 8:54 am
by Sabre
Wow, sucks to be Apple with this coming out. Hopefully the researches did the right thing and reported it to Apple. If they didn't, boo on them.... if they did and Apple doesn't do something about it, boo on them!

Re: Hackers Can Crack iPhones Remotely.

Posted: Tue Jun 23, 2009 9:17 am
by ElZorro
Charlie is a good guy, can't imagine that he didn't disclose first. My guess is its a vulnerability in a browser library, thats how they broke in the first summer the phone was out.

Re: Hackers Can Crack iPhones Remotely.

Posted: Tue Jun 23, 2009 9:58 am
by complacent
ElZorro wrote:Charlie is a good guy, can't imagine that he didn't disclose first. My guess is its a vulnerability in a browser library, thats how they broke in the first summer the phone was out.
I don't know about the 'sploit personally, but I agree about Charlie.