Go Back  Mac-Forums.com  > General Discussions > Apple Rumors and Reports > Worm effects 'jailbroken' Apple iPhones

Reply
 
LinkBack Thread Tools
Old 11-09-2009, 11:25 AM   #1 (permalink)
cwa107

 
cwa107's Avatar
 
Member Since: Dec 20, 2006
Location: Middletown, PA, USA
Posts: 15,734
cwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond repute
Mac Specs: 15.4 MBP 2.4GHz Penryn C2D, 4GB RAM, 320GB HDD
Worm effects 'jailbroken' Apple iPhones

From BBC News:

Quote:
The first worm to infect the Apple iPhone has been discovered spreading "in the wild" in Australia.

The self-propagating program changes the phone's wallpaper to a picture of 80s singer Rick Astley with the message "ikee is never going to give you up".

The worm, known as ikee, only affects "jail-broken" phones, where a user has removed Apple's protection mechanisms to allow the phone to run any software.

Experts say the worm is not harmful but more malicious variants could follow.
__________________

Community Guidelines
cwa107 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-09-2009, 12:32 PM   #2 (permalink)
mjfleck2000

 
Member Since: Apr 07, 2008
Location: Coeur d' Alene, Idaho
Posts: 6
mjfleck2000 is on a distinguished road
Mac Specs: Macbook, iMac
I read on another site that this exploit occurs when these two conditions are met:

1) a jail-broken iPhone

2) SSS installed with the default password unchanged

"What needs to be stressed, though, is the fact that the ikee worm only affects jailbroken iPhones running the SSH app with the default password, which represents a very small percentage of the total number of iPhones out there." from pcworld.com

Mike
mjfleck2000 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-09-2009, 02:12 PM   #3 (permalink)
cwa107

 
cwa107's Avatar
 
Member Since: Dec 20, 2006
Location: Middletown, PA, USA
Posts: 15,734
cwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond repute
Mac Specs: 15.4 MBP 2.4GHz Penryn C2D, 4GB RAM, 320GB HDD
Interesting. I guess any time there's a blip on the security screen of an Apple product, the media makes all kinds of fuss before they have their facts straight.
__________________

Community Guidelines
cwa107 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-09-2009, 03:17 PM   #4 (permalink)
McBie

 
McBie's Avatar
 
Member Since: Apr 26, 2008
Location: Belgium
Posts: 603
McBie has a spectacular aura about
Mac Specs: MBP 17" - 10.6.2
Quote:
Originally Posted by mjfleck2000 View Post
I read on another site that this exploit occurs when these two conditions are met:

1) a jail-broken iPhone

2) SSS installed with the default password unchanged

"What needs to be stressed, though, is the fact that the ikee worm only affects jailbroken iPhones running the SSH app with the default password, which represents a very small percentage of the total number of iPhones out there." from pcworld.com

Mike
Correct, the 2 conditions above are a pre-requisite for the malware to be successful.
Bad thing is that people only remember 2 words from the whole article and that is .... " iPhone hacked "
What people do not read is that existing security controls needed to be broken first ..... deliberately ... it was only a matter of " when " , not " if ".

Cheers ... McBie
__________________
" Everything should be made as simple as possible, but not one bit simpler. " A. Einstein
McBie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-09-2009, 06:21 PM   #5 (permalink)
cuhnool

 
cuhnool's Avatar
 
Member Since: Jun 02, 2008
Location: Louisville
Posts: 1,343
cuhnool is a jewel in the roughcuhnool is a jewel in the rough
Mac Specs: MacBook 2.1GHz Core 2 Duo | 1GB RAM | OS X 10.6.2 | 250GB External HD | 8GB iPod Touch 1st Gen 3.1.2
Quote:
Originally Posted by cwa107 View Post
Interesting. I guess any time there's a blip on the security screen of an Apple product, the media makes all kinds of fuss before they have their facts straight.
Probably because people don't associate malicious programs with Macs (or Apple, or MACS), so whenever anything is brought up that an Apple device has been infected or has been "hacked", everyone goes bonkers. At least that's what I think.
__________________


thesixtyone -- nothin' better than the blues
cuhnool is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-10-2009, 01:37 PM   #6 (permalink)
wantedinc

 
wantedinc's Avatar
 
Member Since: Oct 21, 2009
Location: melbourne, australia
Posts: 11
wantedinc is on a distinguished road
Mac Specs: Macbook Pro 13", 2.26Ghz Core 2 Duo, 8GB Ram, 500GB WD 7200rpm HDD
I got my iPhone infected by this worm two days ago. It was weird as I didn't expect something like this to hit the iPhones. Oh well, another lesson to look at security!!
__________________
Macbook Pro 13
wantedinc is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-10-2009, 01:47 PM   #7 (permalink)
cwa107

 
cwa107's Avatar
 
Member Since: Dec 20, 2006
Location: Middletown, PA, USA
Posts: 15,734
cwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond reputecwa107 has a reputation beyond repute
Mac Specs: 15.4 MBP 2.4GHz Penryn C2D, 4GB RAM, 320GB HDD
Quote:
Originally Posted by wantedinc View Post
I got my iPhone infected by this worm two days ago. It was weird as I didn't expect something like this to hit the iPhones. Oh well, another lesson to look at security!!
Do note that this wouldn't have happened if you were running the stock software. It's important to note that when you subvert the intent of the OS engineers, you accept a degree of risk. In this case, someone capitalized on sloppy work by the jailbreak author, resulting in a security breach.
__________________

Community Guidelines
cwa107 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-10-2009, 02:07 PM   #8 (permalink)
Jaygray

 
Jaygray's Avatar
 
Member Since: Mar 04, 2008
Posts: 733
Jaygray is a jewel in the roughJaygray is a jewel in the rough
Mac Specs: Macbook 2.2, 4gb RAM, 160gb HD
For anyone whose interested in how to change your password...

Fix for Worm on Jailbroken iPhone/iPod Touch, Change Default OpenSSH Password
Jaygray is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-11-2009, 09:39 AM   #9 (permalink)
wantedinc

 
wantedinc's Avatar
 
Member Since: Oct 21, 2009
Location: melbourne, australia
Posts: 11
wantedinc is on a distinguished road
Mac Specs: Macbook Pro 13", 2.26Ghz Core 2 Duo, 8GB Ram, 500GB WD 7200rpm HDD
Yeah I realize it.. Ive finally upgraded my firmware to 3.1.2, so no more worms(hopefully).

But there are some irresistible things about custom software.
__________________
Macbook Pro 13
wantedinc is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-11-2009, 10:04 AM   #10 (permalink)
McBie

 
McBie's Avatar
 
Member Since: Apr 26, 2008
Location: Belgium
Posts: 603
McBie has a spectacular aura about
Mac Specs: MBP 17" - 10.6.2
Quote:
Originally Posted by cwa107 View Post
Do note that this wouldn't have happened if you were running the stock software. It's important to note that when you subvert the intent of the OS engineers, you accept a degree of risk. In this case, someone capitalized on sloppy work by the jailbreak author, resulting in a security breach.
This is o so true in a lot of cases.
issue being that people do not have a " risk management " mindset when it comes to computing devices ( as a general term ).
Everybody knows you need car insurance and protection against fire, but the risks inherent with your electronic identify are overlooked.

People sacrifice risks for the sake of ' usability ', without thinking.
It happened 50 years ago, it happens today and it will happen again tomorrow.

If people think technology is going to solve their security problems, then they don't understand the technology and they don't understand the problems.
IT Security is more about people and their behavior then it is about machines and their settings.

Just my 2 cents.

Cheers ... McBie
__________________
" Everything should be made as simple as possible, but not one bit simpler. " A. Einstein
McBie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-11-2009, 01:51 PM   #11 (permalink)
ilovemusic

 
ilovemusic's Avatar
 
Member Since: Nov 08, 2009
Location: Scotland!
Posts: 12
ilovemusic is on a distinguished road
I always thought things like this was expected when you jailbreak a device. Maybe if you didn't mess with the iphone OS you wouldn't get problems?
__________________
ilovemusic is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-25-2009, 02:38 PM   #12 (permalink)
DriftNismo

 
DriftNismo's Avatar
 
Member Since: Dec 26, 2008
Location: London, UK
Posts: 157
DriftNismo will become famous soon enough
Mac Specs:  15.4" MacBook Pro w/ 2.4GHz C2D & 2GB, 16GB iPhone 3G, 32GB 1G iPod Touch
Shouldn't be news imo. Phones have always been getting viruses, the iPhone is no different, especially if you compromise the security of the phone by jailbreaking it.

Well, time to change the root password :p.
__________________
 15.4" MacBook Pro [4,1] | Intel Core 2 Duo 2.4GHz | 2GB RAM | Nvidia GeForce 8600M GT 256mb | 200GB HDD | Mac OS X 10.6.2 SnowLeopard 
T-Mobile iPhone 3G 16GB Black | OS 3.1.2 Jailbroken 
DriftNismo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-25-2009, 03:15 PM   #13 (permalink)
baggss

 
baggss's Avatar
 
Member Since: Oct 10, 2004
Location: Margaritaville
Posts: 7,901
baggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond reputebaggss has a reputation beyond repute
Mac Specs: Quad 2.5Ghz PowerMac G5 / 1Ghz iBook G4 / OSX 10.5.8 /iPhone 3G
Quote:
Originally Posted by cwa107 View Post
From BBC News:

BWAHAHAHAHAHAAHAHAH!
__________________


I stopped Twittering, it's stupid..
baggss is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Old 11-26-2009, 07:10 PM   #14 (permalink)
Lex

 
Member Since: Nov 26, 2009
Posts: 34
Lex is an unknown at this point
I got my iPhone 2 weeks after it came out (the first one). It now runs 3.1 software in europe. Never had any issues with it so not impressed of seeing this.

- Lex
Lex is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this post
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump

 
 
 
     
Home Calendar Get New
     

Copyright ©2001-2010 Mac-Forums.com. All Rights Reserved. A division of iNET Interactive.

Other iNET Interactive Sites: Web Hosting Talk | Swish Talk | Hosting Catalog.com| Dev Papers| Deleted Domains| Hot Scripts

Powered by vBulletin
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.