iPhone

iPhone hacked in less than a month?

By Tom Espiner on 24 July 2007

Tags: apple | exploit | hack | iphone | malicious | os x | safari | sms | text message | web browser

Apple's iPhone has been on the market for less than a month, but already researchers have claimed to have hacked the popular device.

Security researchers from Maryland-based penetration testing firm Independent Security Evaluators (ISE) say they have written two exploits that take advantage of "serious problems with the design and implementation of security on the iPhone". They claim that one of the exploits, for the Safari Web browser on the iPhone, could be used for stealing data.

The researchers used an unmodified iPhone to surf to a malicious HTML document they had created. When this page was viewed, the payload forced the iPhone to make an outbound connection to a server that the researchers controlled. The compromised iPhone then sent personal data including SMS text messages, contact information, call history and voicemail information over the connection.

The second exploit created by the researchers enabled them to perform so-called "physical actions" on the iPhone. Using their iPhone to visit a second malicious Web page, they forced the device to "vibrate for a second".

They also raised the spectre of premium-rate rogue-dialler fraud, and the use of the iPhone as a bugging device. By using other API functions, the researchers claimed the exploit could have "dialled phone numbers, sent text messages or recorded audio as a bugging device, and transmitted it over the network for later collection by a malicious party".

The security researchers claim that the iPhone's "most glaring" security fault is that all major processes run with administrative privileges. This is a problem because a compromise of any application gives an attacker full access to the device.

The number of ways the iPhone can be attacked has been reduced by stripping down OS X. But, as on the desktop version of OS X, iPhone software does not utilise security practices such as address randomisation, which would make exploiting the operating system more difficult, said the researchers.

"These weaknesses allow for the easy development of stable exploit code once a vulnerability is discovered," the researchers wrote in a whitepaper. They said they were unwilling to divulge any more details about the exploits until the Black Hat security conference in Las Vegas in August, because Apple was only notified of their research findings on 17 July.

In response to news of the hack, Apple said: "Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users."

Tom Espiner reported for ZDNet UK from London.

Like this article? Click below to send it to your mobile for free!

arthurdaley
25/07/2007 10:45 AM

Sensationalism at its best. Has there been an iphone problem yet? Reporting speculation. How many Windows problems have there been?

Report offensive content

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • The best smartphone is...

  • Vodafone 3G upgrade delayed to 2009

  • MWg: There's a new phone in town

  • BlackBerry Storm 9500

  • BlackBerry Storm finally official

  • Oi!: Rock out with your tech out

  • 50 significant moments from internet history

  • Megaphone #1: Your monthly dose of mobile

  • OLED, 3D displaying the future

More articles »

Find the right mobile phone

Brand
  • Multiple options can be selected

    Recycle your old mobiles
    • BlackBerry Storm 9500

      BlackBerry Storm 9500

      A BlackBerry without a keyboard may seem like a car without wheels, but if RIM has given us a touchscreen similar to the stunning display we saw on the Bold, then the Storm could be this year's must-have touch-sensitive smartphone.

    • HTC Touch Pro

      HTC Touch Pro

      The Touch Pro is a step in the right direction for HTC. It's still a bit sluggish but overall it performs better than the Diamond, plus the keyboard is a winning touch.

    • HTC Touch 3G

      HTC Touch 3G

      Of the three new smartphones announced by HTC, the Touch 3G looks destined to suffer middle child syndrome. Its spec sheet falls short of the mouth-watering Touch HD, and its price won't be as attractive as the low-end Viva.

    • HTC Touch HD

      HTC Touch HD

      Without a doubt, two of the most highly anticipated and sought after smartphones of 2008 are Apple's iPhone 3G and HTC's Touch Diamond. Have you ever wondered what might happen if you spliced the two together?

    • Palm Treo Pro

      Palm Treo Pro

      Beneath its iPhone-esque exterior lurks a very capable business phone.The Palm Treo Pro may not have the snazzy interface designs of the competition, but this means it performs better in most areas.

    More reviews »

    Membership benefits

    Win prizes and other promotion benefits

    Win prizes and other promotion benefits

    As a CNET.com.au member, you're eligible to enter and win any prizes on our site. Sign up for a free CNET.com.au membership now!