Feeds

iOS 6.x hack allows personal data export, free calls

Find phone, press buttons in weird sequence, invade privacy, call anyone

Internet Security Threat Report 2014

Hackers can access iPhones running iOS 6.x without passcodes, and will then be able to access and export the address book, send emails and make phone calls.

Jailbreak Nation has discovered the method for doing so and The Reg can confirm the method works after a sequence of swipes and key presses. It worked for us on an iPhone 5 running iOS 6.02, not just iOS 6.1 as Jailbreak Nation suggests.

Once the phone has been hacked in the method described in the video below, we were able to access an iPhone 5's address book, view all details of the contacts listed therein and make calls to them. The Contacts app offers the chance to “Message” contacts by SMS or email and a chance to “Share Contact”, which results in a contact's details being added to an outgoing email as a .VCF file.

This method could therefore be used to acquire a copy of all contacts stored on an iPhone, and to run up a colossal phone bill on the device.

In our test the iPhone's Home button became inert after the hacking procedure was applied, making it impossible to access other apps, so Apple will be spared the blushes that would have come with hackers finding stray iPhones and resetting progress in Angry Birds.

With iOS 6.1 proving to be a buggy mess, news of this latest hole won't make for a happy Friday down Cupertino way. Or weekend, if Mr Cook of Cupertino decides a patch has to be delivered ASAP. ®

Watch Video

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.