English

Hello 

Create Profile

Creating your profile will enable you to submit photos and stories to get published on News24.


Please provide a username for your profile page:

This username must be unique, cannot be edited and will be used in the URL to your profile page across the entire 24.com network.

Settings

Location Settings

News24 allows you to edit the display of certain components based on a location. If you wish to personalise the page based on your preferences, please select a location for each component and click "Submit" in order for the changes to take affect.









Facebook Sign-In

Hi News addict,

Join the News24 Community to be involved in breaking the news.

Log in with Facebook to comment and personalise news, weather and listings.

 
 

Researchers hijack iPhone

2007-07-24 08:52
line

New York - Hackers could take control of an iPhone if its owner visits a doctored website or internet hotspot, security researchers reported on Monday.

The vulnerability of the vaunted device, Apple Inc's first cellphone, is only theoretical for now. There are no reports of criminals actually taking advantage of the security glitch to remotely access an iPhone.

But if it were exploited, hijacked iPhones could be very useful to the same gangs that take over personal computers and use them to disseminate spam, said Charlie Miller, principal security analyst at Independent Security Evaluators, which discovered the flaw.

"You could have a million iPhones dialling the company's main line and overwhelm it that way," Miller said.

In addition, hijacked iPhones could be used to send spam by cellphone text message, which computers generally can't. Any personal data on the phones, such as private phone numbers and text messages, would be accessible as well.

The flaw applies not only to the iPhone, which was launched just three weeks ago, but also to Apple computers running Mac OS and the company's Safari web browser, a version of which comes with the iPhone. It does not affect Safari running on Microsoft Corp's Windows systems.

The researchers at Baltimore-based ISE haven't released the specifics of the vulnerability to the public, but have provided details to Apple and supplied the company with a patch, a software update for plugging the hole.

On August 2, Miller will present details of the flaw at the Black Hat USA hacker conference in Las Vegas and online. That will make it easier for criminals to replicate the exploit, but he stressed that it should also be easy for Apple to release a patch to all its users before then. The iPhone and Macintosh computers are configured to receive software updates automatically from Apple.

'We always welcome feedback on our security'

"Hopefully, on August 2, nothing happens: we release the information, everyone's patched and that's it," Miller said.

Apple spokesperson Lynn Fox said Apple is looking into ISE's report, but would not say if there are plans for a patch.

"We always welcome feedback on our security," Fox said.

Miller said the flaw did not necessarily reflect badly on Apple.

"I'm sure that if you put any sort of mobile device that's complex enough in front of me, we'd find pretty much the same thing," he said. At the same time, "the security of the iPhone is not as good as the security of the Mac desktop, and I think that's something they need to work on".

Miller and the rest of the ISE team discovered holes in the security of the iPhone within minutes of getting their hands on their boss's phone.

"He didn't really want to let us do it, but eventually he gave in, and we poked around with it for a few minutes, and already saw some things that could make the programs crash," Miller said.

Their technique, called "fuzzing", involves sending lots of random or improperly formatted data to a device, and noting what causes crashes or other problems that could be openings to sending code that takes over the device.

To protect an iPhone against this and similar future vulnerabilities, the ISE team recommends that users only visit sites they trust, not open websites from e-mails and not use unfamiliar Wi-Fi hotspots.

- AP

Read News24’s Comments Policy

Comment on this story
0 comments
Comments have been closed for this article.

inside news24

 

140
1
1 of 10

Latest comment in Sci-Tech

skootzie says... Scientists thrive on the unknown, on the ignorance because it keeps them employed ;-) - imagine there was nothing to discover; imagine if we already knew all the answers - what a boring world that would be. Read the article...

 
Traffic
Lottery
 
  • Wednesday Ladysmith - 22:09 PM
    Road name: N11 Both Ways
    ROADWORK - two sets of stop / go controls just south of the R68 Dundee exit - expect waiting times of up to 20 minutes between Ladysmith and Newcastle (ends March 2013)
  • Saturday Pretoria - 08:07 AM
    Road name: N1 Both Ways
    ROADWORKS - lane closures on both carriageways for long term roadworks between the N4 Witbank Highway Interchange and the Zambesi Drive exit - EXPECT DELAYS (until Jan 2013)
 
More traffic reports...
 

Jobs [change area]

Cars[change area]

VOLKSWAGEN

CitiGolf 1.4i 5-dr MY04
2005
R 62,900.00

CADILLAC

BLS 2.0T AT
2007
R 179,995.00

VOLKSWAGEN

CitiGolf 1.4i 5-dr MY04
2007
R 71,995.00

Property [change area]

Vulintaba Country Estate, Upper Drakensberg

A lifestyle estate beyond compare. Home Package Options From R990 000

HOUSES FOR SALE IN Polokwane

Houses R 6 500 000

Travel - Look, Book, Go!

Casa Rex, Vilanculos

Spend 5 nights in at the magical Mozambican resort of Casa Rex from R7983 per person sharing. Includes accommodation, return flights, taxes and transfers. Book now!

Kalahari.com - shop online today

Legos

Let your child construct his own fun with only his imagination limiting his creations. Buy now.

iPad

Update the way you socialize, work and play with the latest iPad models. Buy now.

Max Payne 3

Seeking Redemption from the past, Max hopes to enter his last fight and finally put his demons to rest. Buy now.

Sins of the Father

Foul play in New York City sets the tone. Boundaries pushed, Loyalties tested and secrets unravelled in Jeffrey Archer’s, Sins of the Father. Buy now.

Nikon Camera Range

Capture and preserve your life’s precious memories with the Nikon Camera Range. Buy now.

OLX Free Classifieds [change area]

pool table

For Sale, Toys - Games - Hobbies in South Africa, Gauteng, Johannesburg. Date May 6

Lexus: IS

Vehicles, Cars in South Africa, Gauteng, Johannesburg. Date May 7

stylish bachelor furnished in sandton from 1st of june

Real Estate, Houses - Apartments for Rent in South Africa, Gauteng, Johannesburg. Date May 7

BlackBerry Curve 3G 9300

Keep it together Text. Email. Social. With all the different ways to...

From R1949.00

I'm shopping for:

Horoscopes
Aquarius
Aquarius

You’re friendly by nature and you don’t really have to go too out of your way to befriend the people you work with. Just be your...read more

There are new stories on the homepage. Click here to see them.