CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Saturday, July 31st 
Home
Enterprise Software
Enterprise Hardware
Network Security
Compliance
CRM Systems
Data Storage
Chips & Processors
Operating Systems
Communications
World Wide Web
Wireless Tech
Small Business
CIO Issues
Business Briefing
After Hours
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Network Security

Security Flaw Lets Hackers Commandeer iPhone

Security Flaw Lets Hackers Commandeer iPhone
July 23, 2007 9:20AM

Bookmark and Share
In the iPhone hacking demonstration, security researcher Charles Miller used the iPhone's built-in Safari browser to visit a site that transferred code to the iPhone, whereupon the iPhone obediently transmitted text communications, phone contacts, and e-mail addresses. Miller said the exploit could compel Apple's iPhone to do anything.


News has emerged that likely will not be appearing in Apple's iPhone commercials. The iPhone has a security Relevant Products/Services flaw that allows malicious hackers to turn the smartphone into a remote controlled zombie.

The New York Times reported on Monday that a Baltimore-based team of security consultants demonstrated the hack. Independent Security Evaluators (ISE), a company that tests clients' computer systems by trying to break into them, showed the newspaper how to take control of the iPhone remotely.

The attack is delivered through one of at least three ways, according to the researchers. The iPhone could allow a wireless access point, with the same name as a trusted one, to be used to deliver the attack by inserting malicious code in the place of a visited Web page.

A second way is through a forum, which can load an exploit when an iPhone user views a discussion thread. Or a user could be tricked through a link in an e-mail into visiting a fraudulent, "phishing" site that can deliver the malicious code.

"Once you did manage to find a hole," ISE principal security analyst Dr. Charles A. Miller told the Times, "you were in complete control."

Report on iPhone Security

ISE said that it told Apple about the vulnerability and sent a sample patch to fix the problem. A spokesperson for Apple said the company is looking into the issue. Miller will be presenting a full report on the vulnerability at the BlackHat security conference early next month.

In the demonstration to the Times, Miller used the iPhone's built-in Safari Web browser to visit a Web site that transferred code to the device. Afterwards, the iPhone obediently transmitted recent text communications, phone contacts, and e-mail addresses. The researchers said that the exploit could compel the iPhone to do anything, including becoming a spy by recording audio and then sending it to the attacker.

John Girard, a VP at industry research firm Gartner, said that the significance of this reported iPhone bug is that it is the first to be "escalated to a working demonstration." He noted that his company already published a report about vulnerabilities in the iPhone, especially for enterprise Relevant Products/Services environments. For businesses, the report said, the first-generation iPhone does not achieve the level security of devices such as the BlackBerry.

The report found that the "iPhone's primary security defense rests on a restricted configuration that prevents user-installable applications." The report advised businesses to avoid storing enterprise data Relevant Products/Services on the iPhone and to make other efforts to restrict its access until it can be more effectively secured as a business device.

Gartner said it expects Apple to improve iPhone security within the next six months, but that it will have to "open up a level of development tools in the platform Relevant Products/Services." (continued...)

1  |  2  |  Next Page >

 

Tell Us What You Think
Comment:

Name:

Advertisement



 Network Security
1. Keeping Your Computer and Data Safe
2. Sunbelt Software Acquired by GFI
3. Virtual Personal Networks for Security
4. Cyber Command Logo Has a Secret
5. NSA Will Monitor Systems for Attacks


advertisement


 Most Popular Articles
1. A Big Error: Apple Says iPhone Meter Needs Update
2. Sunbelt Software Acquired by GFI
3. Jobs Offers Free Cases, Scolds Media for 'Antennagate'
4. With Palm Deal Complete, HP Moves To Expand webOS
5. EMC Will Acquire Greenplum for Data Storage in the Cloud

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  BlackPad Tablet Expected from RIM
  FCC Approves First LTE 4G Phone
  Google Cries Wolf in China Outage
  Windows 7 Being Retooled for Tablets
  YouTube Videos Can Be 15 Minutes

 Technology Marketplace
Cloud & Virtualization
Rackspace ®: The World's Leader in Hosting & Cloud Computing
 
Communications
Optimize 802.11n performance with Cisco CleanAir technology.
 
Compliance
Stand out from other IS Professionals and increase your earning potential.®.
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Customer Service
Rackspace ® Managed Hosting - Experience Fanatical Support ®
 
Data Storage
Isilon scale-out storage is simple. Simple is smart.
 
Enterprise I.T.
Rackspace ®: The World's Leader in Hosting & Cloud Computing
Stand out from other IS Professionals and increase your earning potential.®.
 
Enterprise Software
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Mobile Gadgets
White Paper Better your mobile work life with an enterprise digital assistant.
 
Mobile Industry News
Better your mobile work life with an enterprise digital assistant
 
Mobile Phones
Better your mobile work life with an enterprise digital assistant
 
Wireless Connectivity
Optimize 802.11n performance with Cisco CleanAir technology.
 
Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Network Security | Compliance | CRM Systems | Data Storage
Chips & Processors | Operating Systems | Communications | World Wide Web | Wireless Tech | Small Business | CIO Issues
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 CIO Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.