Quantcast

Forums | MacLife

You are not logged in.

  • Index
  •  » In Tech News
  •  » iPhone Executes SMS Binary Code as Root, No Fix 'til Month's End

#1 2009-07-02 4:28 pm

Bat
Flawless Cowboy
Royal Wombat
From: Björk, Björk
Registered: 2001-05-14
Posts: 28541

iPhone Executes SMS Binary Code as Root, No Fix 'til Month's End

Recently, Apple has struggled with the security ramifications of a higher commercial profile, and seeing an increasing number of OS X malware.  Now another security flaw has been found, this time in the iPhone OS.  The flaw allows attackers to gain root access to the iPhone's underlying OS, allowing them to install and execute malicious programs at will.

The iPhone apparently automatically executes binary code sent in SMS messages.  Messages are limited to 140 bytes, but this is little deterrence as longer programs can be broken up into several messages, which the phone automatically reassembles.  While other applications such as the Safari browser on the phone only enjoy access to their sandbox, the SMS system is automatically granted root access, and SMS commands execute as root.

Charlie Miller, during a presentation at the SyScan conference in Singapore on Thursday introduced the vulnerability to the public.  He declined to go into specific details or offer his proof-of-concept code to the public, as he has entered under an agreement with Apple.  Mr. Miller did state, "SMS is a great vector to attack the iPhone."

He went on to describe several examples of how such an attack could prove beneficial to malicious parties.  Among his ideas were to use the phone's GPS technology to track people, to turn on the phone's microphone to snoop on meetings or conversations, and to use groups of the infected phones to form a botnet and launch distributed denial-of-service attacks.

Apple will have a fix ready by the end July, it says. [..]

My bold. http://www.dailytech.com/article.aspx?newsid=15588


If all economists were laid end to end, they would not reach a conclusion - George Bernard Shaw

"Fire up a colortini, sit back, relax, and watch the pictures, now, as they fly through the air."

Offline

 

#2 2009-07-02 5:14 pm

Chickenhawk
Snark Snark Snark Snark
From: Being Snarky
Registered: 2005-06-01
Posts: 5814

Re: iPhone Executes SMS Binary Code as Root, No Fix 'til Month's End

dumb, dumb dumb.


The recent medical controversy over whether vaccinations cause autism reveals a habit of human cognition—thinking anecdotally comes naturally, whereas thinking scientifically does not. -- Michael Shermer

Offline

 

#3 2009-07-02 5:54 pm

ukimalefu
4 8 15 16 23 42
Moderator
From: time loop
Registered: 2002-09-09
Posts: 9351
Website

Re: iPhone Executes SMS Binary Code as Root, No Fix 'til Month's End

Macs are next!!! We're DOOMED!!!

Offline

 
  • Index
  •  » In Tech News
  •  » iPhone Executes SMS Binary Code as Root, No Fix 'til Month's End

Board footer

Powered by PunBB 1.2.6
© Copyright 2002–2005 Rickard Andersson