Johannesburg

Monday

Passing showers. Mostly cloudy. Mild.

15°C
26°C

7 day forecasts

Researchers hijack iPhone

2007-07-24 08:52

New York - Hackers could take control of an iPhone if its owner visits a doctored website or internet hotspot, security researchers reported on Monday.

The vulnerability of the vaunted device, Apple Inc's first cellphone, is only theoretical for now. There are no reports of criminals actually taking advantage of the security glitch to remotely access an iPhone.

But if it were exploited, hijacked iPhones could be very useful to the same gangs that take over personal computers and use them to disseminate spam, said Charlie Miller, principal security analyst at Independent Security Evaluators, which discovered the flaw.

"You could have a million iPhones dialling the company's main line and overwhelm it that way," Miller said.

In addition, hijacked iPhones could be used to send spam by cellphone text message, which computers generally can't. Any personal data on the phones, such as private phone numbers and text messages, would be accessible as well.

The flaw applies not only to the iPhone, which was launched just three weeks ago, but also to Apple computers running Mac OS and the company's Safari web browser, a version of which comes with the iPhone. It does not affect Safari running on Microsoft Corp's Windows systems.

The researchers at Baltimore-based ISE haven't released the specifics of the vulnerability to the public, but have provided details to Apple and supplied the company with a patch, a software update for plugging the hole.

On August 2, Miller will present details of the flaw at the Black Hat USA hacker conference in Las Vegas and online. That will make it easier for criminals to replicate the exploit, but he stressed that it should also be easy for Apple to release a patch to all its users before then. The iPhone and Macintosh computers are configured to receive software updates automatically from Apple.

'We always welcome feedback on our security'

"Hopefully, on August 2, nothing happens: we release the information, everyone's patched and that's it," Miller said.

Apple spokesperson Lynn Fox said Apple is looking into ISE's report, but would not say if there are plans for a patch.

"We always welcome feedback on our security," Fox said.

Miller said the flaw did not necessarily reflect badly on Apple.

"I'm sure that if you put any sort of mobile device that's complex enough in front of me, we'd find pretty much the same thing," he said. At the same time, "the security of the iPhone is not as good as the security of the Mac desktop, and I think that's something they need to work on".

Miller and the rest of the ISE team discovered holes in the security of the iPhone within minutes of getting their hands on their boss's phone.

"He didn't really want to let us do it, but eventually he gave in, and we poked around with it for a few minutes, and already saw some things that could make the programs crash," Miller said.

Their technique, called "fuzzing", involves sending lots of random or improperly formatted data to a device, and noting what causes crashes or other problems that could be openings to sending code that takes over the device.

To protect an iPhone against this and similar future vulnerabilities, the ISE team recommends that users only visit sites they trust, not open websites from e-mails and not use unfamiliar Wi-Fi hotspots.

- AP

inside news24

Weather
Traffic
Lottery
Cpt: 15-21°C Sprinkles early. More sun than clouds. Mild. Pta: 17-27°C Scattered showers. Mostly cloudy. Mild.
Jhb: 15-26°C Passing showers. Mostly cloudy. Mild. Bloem: 13-30°C More sun than clouds. Pleasantly warm.
Dbn: 18-23°C Scattered showers. More clouds than sun. Cool. PE: 16-22°C Sprinkles late. Scattered clouds. Mild.
7 day forecasts...

Jobs - Find your dream job

SENIOR DEVELOPER: JAVA

Western Cape - Cape Town
Quiglies Solutions

Test automation engineer

Western Cape - Cape Town
Quiglies Solutions

Developer

Western Cape - Cape Town
Quiglies Solutions

Cars - Search 1000's of new and used cars

AUDI

2009 Audi A3 2.0 T Sportback Manual - 24000kms
Lava Grey & Tan leather interior
R 275 000

VOLKSWAGEN

Polo 1.6 Trendline 5-dr MY05
2009
R 179,989.00

TOYOTA

Fortuner 3.0 D-4D 4x4 Dsl MY09
2006
R 249,990.00

BMW

318i (E36)
1996
R 40,000.00

Property - Find a new home

WATERVAL EAST

Single Residential R2,400,000

KWAAIWATER

Single Residential R2,500,000

WELBEDACHT

Single Residential R2,600,000

Travel - Look, Book, Go!

Luxury bush escape

Book a five-star stay at Pumba Game Lodge or Richard Branson's Ulusaba Safari Lodge and save R2 000. More details!

Free Games - TOO MUCH NEWS? TAKE A BREAK!

Kalahari.net - shop online today

Great Festive Savings on Books

Up to 30% Off ALL Books. 2.3 million titles on SALE.

Sleek New iPod Range. Order Your's Now!

iPod nano 16GB - Black, Was R2,499.00 Now R2,299.00! Save R200!

Up to 40% off Fabulous Festive Flicks

46 000 DVDs and Blu-Ray on sale now! Pre-order Up and District 9!

Up to 20% off ALL Music

100s of festive new releases now in stock! Now, Bump 25, Bon Jovi & more!

1000s of Festive Toys on Sale

Lots of Toys, free gift wrap, lowest prices on Lego Mindstorm, Ben 10, Hannah Montana & more!

Hot Deal of the Day!

Up to 30% off Books

Ends midnight, 30 November

2.3 million titles on sale! New Stieg Larsson, Jeremy Clarkson, Jamie Oliver & more!

Up to 40% Off Sale on All Books, Toys, CDs, DVDs & Games!