Apple patching serious SMS vulnerability on iPhone
Apple patching serious SMS vulnerability on iPhone: Via computerworld.
Apple may be working to fix an iPhone vulnerability that could possibly allow an attacker to remotely install and run unsigned software code with root access to the phone.
The theoretical attack in question exploits a weakness in the way iPhones handle text messages received via SMS (Short Message Service), said security researcher Charlie Miller, during a presentation at the SyScan conference in Singapore on Thursday. He didn't provide a detailed technical description of the SMS vulnerability.
Miller, the principal security analyst at Independent Security Evaluators, is an authority on MacOS X security, and is a co-author of The Mac Hacker's Handbook. He and another security researcher, Colin Mulliner, discovered the SMS vulnerability together.
An SMS flaw might allow an attacker to run software code on the phone that is sent by SMS over a mobile operator's network. In Miller's case, it appears he used the flaw he found to remotely crash an iPhone, a sign that a more serious attack might be possible.
"I don't have a working exploit for it, just a suspicious looking crash," Miller said.
If so, the malicious code could theoretically include commands to monitor the location of the phone using GPS, turn on the phone's microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet, Miller said
[...]
"SMS is a great vector to attack the iPhone," he said.
Most often used to send brief text messages between cell phones, SMS can also send binary code to an iPhone, which then processes the code without any user interaction. Each SMS message is limited to 140 bytes, but longer sequences can be sent to the phone as multiple messages that are automatically reassembled.
This feature allows larger programs to be delivered to a phone, Miller said.
In addition, vulnerabilities found in the iPhone's SMS function give an attacker root access to the handset, Miller said. That's not the case for the iPhone's other applications, such as its browser, where vulnerabilities only give an attacker access to the application's sandbox.
"The iPhone is more secure than OS X, but SMS could be a critical vulnerability," Miller said.
Read Original Article:(Via computerworld.)
Recent blog posts
- Sweden Probing Cisco, NASA Hacks
- Jurors: Stop Twittering
- NBC Removes Conan O'Brien From the Web
- EFF Asks Court to Suppress Evidence Illegally Gathered From Password-Protected Phone
- Google Superbowl Ad Explains The Need for Search Privacy
- EFF Fights for Cell Phone Users' Privacy in Thursday Hearing
- Identifying John Doe: It might be easier than you think
- ShmooCon: Inside FarmVille's sinister underbelly
- More Details on the Chinese Attack Against Google (Schneier)
- The top 5 mistakes of privacy awareness programs