Apple iPhone
Researchers have uncovered more problems with the design and implementation of security on the iPhone
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Remote control flaw found in iPhone

Attackers could take complete control of the platform

Iain Thomson, vnunet.com 23 Jul 2007
ADVERTISEMENT

A team of security researchers in the US claims to have found a flaw in Apple's iPhone that could allow a hacker to take complete control of the device via Wi-Fi.

Independent Security Evaluators, headed by a former professor at Johns Hopkins University, found the hole last week, developed a patch and alerted Apple to the problem. 

"There are serious problems with the design and implementation of security on the iPhone," said the company in a Security Evaluation paper (PDF) on the flaw. 

"The most glaring is that all processes of interest run with administrative privileges. This implies that a compromise of any application gives an attacker full access to the device."

The exploit uses a web page with malware built in that can access the phone via the Safari browser.

This can either be used to force the phone to send personal information stored in its files or to take control of the device and make it place outgoing calls to other numbers.

"Unfortunately, once an iPhone application is breached by an attacker, very little prevents the attacker from obtaining complete control of the system," the team said.

"Additionally, no address randomisation is used in by the operating system. This means that each time a process runs, the stack, heap and executable code is located at precisely the same spot in memory. This helps attackers write reliable exploit code."

Experts have already warned that the phone may be as insecure as a PC because of its powerful operating system, and problems have already been reported with the dialler software

Matt Bancroft, vice president at mobile device management company Mformation, said: "All mobile phones are becoming more powerful, and the iPhone is really a sophisticated mini computer. 

"As we get more powerful mobile devices, it is inevitable that we will get more security issues and threats to mobile devices.

"The key is to manage the device once it is in the hands of the user. Being able to update or patch the security and applications over the air in an ever-changing environment is the way forward."

Apple iPhone'One of the most sophisticated' scams in recent times  16 Jul 2007
Apple iPhoneHacker shows how to bypass AT&T sign-up  09 Jul 2007
Apple iPhoneRetrieval of passwords could allow installation of custom apps  04 Jul 2007

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
EXCEPTIONAL .NET (ASP / VB / C#) DEVELOPER – SURREY HEDGE FUND My client is a CASH RICH leading Microsoft Technology focused Hedge Fund currently experiencing unrivalled success – they need to bring on fresh ... more >
| JAM Recruitment
Position: Software Developer – Modelling / Simulations Salary: £27-37,000 Location: Luton, Bedford, Milton Keynes Apply to: a.ross@jamrecruitment.co.uk This is an excellent chance to join one of the UK’s leading Defence businesses operating at the forefront ... more >
| JAM Recruitment
Position: Software Engineer – C/C++/GUI/UML Salary: £30-40,000 Location: Leicester Apply to: a.ross@jamjobs.co.uk This is a fabulous opportunity to join a globally recognised organisation working as part of a team taking innovative and cutting edge solutions ... more >
| JAM Recruitment
Position: Embedded Software / Systems Engineer Salary: £25-40,000 Location: Barrow, Cumbria, Carlisle, Lake District Apply to: a.ross@jamrecruitment.co.uk (inc salary expectations, availability and notice period) This is an exciting opportunity to join one of the UKs ... more >
More job opportunities