Feeds

Malware cleans out jailbroken iPhones

Hack tool wriggles through Rickroll worm hole

Remote control for virtualized desktops

Updated Miscreants have developed a hacking tool that attacks jailbroken iPhones.

iPhone-Privacy-A follows hot on the heels of last weekend's Rickrolling worm that changed the wallpaper on vulnerable iPhones to an image of cheesy '80s pop star Rick Astley. The latest hacking threat exploits the same vulnerability in the iPhone as the ikee worm, allowing hackers to connect to any jailbroken iPhone.

Mac-specialist security firm Intego, which was the first to warn of the threat, said the hacker tool is far more dangerous than the Rickrolling worm.

"When connecting to a jailbroken iPhone, this tool allows a hacker to silently copy a treasure trove of user data from a compromised iPhone: e-mail, contacts, SMSs, calendars, photos, music files, videos, as well as any data recorded by any iPhone app," Intego warns. "Unlike the ikee worm, which signals its presence by changing the iPhone's wallpaper, this hacker tool gives no indication that it has invaded an iPhone."

Hackers might install the Privacy-A hacking tool after scanning open wireless Lan networks, in a hotspot or elsewhere, for vulnerable devices that happen to be connected at the time. The tool might also be run by hackers from their iPhones. There's no evidence that such attacks are actually happening, certainly not on a large scale.

Jailbroken iPhones are hacked to allow the installation of software beyond applications that can be download through Apple's App Store. An estimated six to eight per cent of iPhones are jailbroken.

The jailbreaking process can involve installing an SSH (secure shell) remote access service on iPhones. Many users don't bother changing their root passwords from the default after going through this process, a security shortcoming exploited by both the ikee worm and the Privacy-A hacking tool. The latest threat is another reminder that jailbroken iPhone owners need to change passwords to avoid the risk of getting iPwned, or worse. ®

Updated

The initial version of this story implied SSH was installed by default during the jailbreak process. Not so.

"It’s something the user has to select to do either during the jailbreak process or afterwards via Cydia," explained Patrik Runald of Websense Security Labs. "However, by default it’s not installed by any of the jailbreak tools out there today."

Secure remote control for conventional and virtual desktops

More from The Register

next story
Mighty Blighty broadbanders beg: Let us lay cable in BT's, er, ducts
Complain to Ofcom that telco has 'effective monopoly'
BT said to have pulled patent-infringing boxes from DSL network
Take your license demand and stick it in your ASSIA
Yahoo! blames! MONSTER! email! OUTAGE! on! CUT! CABLE! bungle!
Weekend woe for BT as telco struggles to restore service
Fujitsu CTO: We'll be 3D-printing tech execs in 15 years
Fleshy techie disses network neutrality, helmet-less motorcyclists
Ofcom tackles complaint over Premier League footie TV rights
Virgin Media: UK fans pay the most for the fewest matches
FCC: Gonna need y'all to cough up $1.5bn to put broadband in schools
Kids need more fiber, says Wheeler, and you'll pay for it
prev story

Whitepapers

Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.