<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; hacking iphone</title>
	<atom:link href="http://www.darknet.org.uk/tag/hacking-iphone/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Malicious PDF Files To Exploit iPhone &amp; iPad Zero Day In The Wild</title>
		<link>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/</link>
		<comments>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/#comments</comments>
		<pubDate>Mon, 11 Jul 2011 09:39:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[apple-security]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking ipad]]></category>
		<category><![CDATA[hacking iphone]]></category>
		<category><![CDATA[ipad hacking]]></category>
		<category><![CDATA[ipad jailbreak]]></category>
		<category><![CDATA[ipad2 jailbreak]]></category>
		<category><![CDATA[iphone jailbreak]]></category>
		<category><![CDATA[iphone pdf]]></category>
		<category><![CDATA[jailbreakme]]></category>
		<category><![CDATA[pdf jailbreak]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3144</guid>
		<description><![CDATA[Well everyone has been waiting for a Jailbreak for the iPad 2 with the latest version of iOS &#8211; it happened and only hours later the malformed PDF files that were used in the exploit were circulating the Internet. It&#8217;s not the first time this has happened, last time jailbreakme did the same thing back [...]]]></description>
			<content:encoded><![CDATA[<p>Well everyone has been waiting for a <a href="http://www.darknet.org.uk/tag/jailbreak/" title="Jailbreak">Jailbreak</a> for the iPad 2 with the latest version of iOS &#8211; it happened and only hours later the malformed PDF files that were used in the exploit were circulating the Internet.</p>
<p>It&#8217;s not the first time this has happened, last time <a href="http://www.darknet.org.uk/tag/jailbreakme/" title="jailbreakme">jailbreakme</a> did the same thing back in August 2010 &#8211; <a href="http://www.darknet.org.uk/2010/08/dangerous-iphone-ios-jailbreak-exploit-goes-public/" title="Dangerous iPhone iOS JailBreak Exploit Goes Public">Dangerous iPhone iOS JailBreak Exploit Goes Public</a>.</p>
<p>The exploit is quite a nasty one, and the irony is this time &#8211; only users that have applied the Jailbreak then the additional &#8216;PDF Patcher 2&#8242; software (from Cydia) are safe from this. Users running the vanilla version of iOS are actually at risk.</p>
<blockquote><p>Hours after developers revealed they had exploited bugs in Apple&#8217;s iOS to &#8220;jailbreak&#8221; iPhones and iPads, German government security authorities warned that one of the flaws could be put to malicious use.</p>
<p>Malformed files that exploit the vulnerability have been publicly posted on the Internet. Late Wednesday, Germany&#8217;s Federal Office for Information Security, known by its German-language initials of BSI for &#8220;Bundesamt fuer Sicherheit in der Informationstechnik,&#8221; warned citizens that the iOS bug could be used by criminals to hijack iPhones, iPads and iPod Touches.</p>
<p>&#8220;Even clicking a crafted PDF document or surfing to a website with the PDF documents are sufficient to infect the mobile device with malicious software,&#8221; the BSI said in a translation of the German-language alert .</p>
<p>PDF files that successfully exploit the vulnerability are available on the Web, according to Mikko Hypponen, chief research officer of Helsinki-based antivirus company F-Secure. And those PDFs could be used by miscreants to hack iOS devices simply by luring users to malicious sites, said Andrew Storms, director of security operations at nCircle Security.</p>
<p>iPhone and iPad users steered to a malicious PDF &#8212; via a link embedded in an email, for instance &#8212; would not receive any warning or be required to take additional action. </p></blockquote>
<p>I hope <a href="http://www.darknet.org.uk/category/apple-hacking/" title="Apple">Apple</a> gets their act together and pushes out the patch for this ASAP as I foresee some kind of iPhone/iPad targeted worm coming out of this fairly shortly.</p>
<p>It took them 10 days to patch a similar pair of exploits back in August 2010 so we should be expecting a patch by the end of this week (mid-July sometime).</p>
<p>The worrying part when it comes to business/agencies/government etc &#8211; is that these exploits could be used to target specific individuals of importance. All you need to know is the e-mail address they access on their iPhone/iPad and do a bit of <a href="http://www.darknet.org.uk/category/social-engineering/" title="Social Engineering">social engineering</a> and you&#8217;re in.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>The BSI warning came just hours after a group of developers released an updated version of JailbreakMe, a tool that hacks iOS so iPhone and iPad users can install software not sanctioned by Apple.</p>
<p>Those developers exploited a pair of vulnerabilities, including one in the font parsing of the PDF viewer integrated with the iOS version of Safari, and another that bypassed anti-malware defenses such as ASLR (address space layout randomization). Wednesday, security experts said that the same vulnerabilities, particularly the one exploitable through malicious PDF files, could be used by criminals to hijack Apple&#8217;s popular iPhone and iPad.</p>
<p>&#8220;They&#8217;re certainly a threat, and would be easy to make malicious,&#8221; said Charlie Miller, a noted Mac OS X and iOS vulnerability researcher who works for Denver-based Accuvant.</p>
<p>Miller also speculated that Apple would quickly patch the vulnerabilities, perhaps even faster than last year when it faced a similar situation. In August 2010, Apple patched a pair of bugs used by JailbreakMe 2.0 just 10 days after the tool&#8217;s release. News of JailbreakMe 3.0&#8242;s impending release had leaked several days before Wednesday&#8217;s official launch, noted Miller, and should have given Apple even more warning.</p>
<p>Yesterday&#8217;s BSI alert was similar to one it issued last August after JailbreakMe 2.0 appeared.On Thursday, Apple said it would fix the flaws.</p></blockquote>
<p>Of course the &#8216;developer&#8217; version of iOS 5.0 is already out and I guess someone people are using this, most iPhone/iPad users have been waiting for that major update &#8211; but I&#8217;m guessing Apple will have to push a patch out for this before the 5.x major release.</p>
<p>There&#8217;s another interesting and relevant article on this topic here:</p>
<p><a href="http://www.networkworld.com/news/2011/070811-the-problem-with-doing-and.html?source=nww_rss">The problem with doing &#8211; and not doing &#8211; an iPhone jailbreak</a></p>
<p>It&#8217;ll be interesting to see what comes of this and if any kind of iPhone/iPad chaos is going to occur due to these exploits.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/070711-pdfs-that-exploit-iphone-ipad.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3144+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;t=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/&amp;title=Malicious+PDF+Files+To+Exploit+iPhone+%26+iPad+Zero+Day+In+The+Wild" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Fmalicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/malicious-pdf-files-to-exploit-iphone-ipad-zero-day-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone Security Flaw &#8211; Using a PIN Won&#8217;t Protect Your Data</title>
		<link>http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/</link>
		<comments>http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 06:59:38 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[apple iphone]]></category>
		<category><![CDATA[apple iphone data]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection flaw]]></category>
		<category><![CDATA[hacking iphone]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone 3gs security]]></category>
		<category><![CDATA[iphone business security]]></category>
		<category><![CDATA[iphone business security framework]]></category>
		<category><![CDATA[iphone data privacy]]></category>
		<category><![CDATA[iphone data protection]]></category>
		<category><![CDATA[iphone data protection flaw]]></category>
		<category><![CDATA[iphone encryption]]></category>
		<category><![CDATA[iphone pin]]></category>
		<category><![CDATA[iphone privacy]]></category>
		<category><![CDATA[iphone race condition]]></category>
		<category><![CDATA[iphone security]]></category>
		<category><![CDATA[iphone security framework]]></category>
		<category><![CDATA[pairing issue]]></category>
		<category><![CDATA[pairing issues]]></category>
		<category><![CDATA[race condition]]></category>
		<category><![CDATA[race conditions]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2703</guid>
		<description><![CDATA[Now it wasn&#8217;t long ago when the first malicious iPhone worm appeared in the wild and well generally since the boom of the device people have looking at the security measures. Huge sales are made to corporates touting the security, privacy and encryption features of the iPhone OS. The latest discovery is that using a [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Now it wasn&#8217;t long ago when the <a href="http://www.darknet.org.uk/2009/11/first-malicious-iphone-worm-in-the-wild/">first malicious iPhone worm</a> appeared in the wild and well generally since the boom of the device people have looking at the security measures.</p>
<p>Huge sales are made to corporates touting the security, privacy and encryption features of the iPhone OS. The latest discovery is that using a PIN on your iPhone 3GS really doesn&#8217;t protect you from anything as long as the person has physical access to your phone.</p>
<p>But then the same thing goes for desktop/laptop computers too, if someone has physical access you&#8217;re done for. </p>
<blockquote><p>Using a four-digit PIN to lock your iPhone doesn&#8217;t really protect your data, security and IT blogger Bernd Marienfeldt has discovered. In an article describing the iPhone&#8217;s business security framework, Marienfeldt has found a &#8220;data protection vulnerability&#8221; in Apple&#8217;s iPhone 3GS.</p>
<p>Marienfeldt, working with security expert Jim Herbeck, has been able to reproduce the vulnerability on at least three non jail-broken iPhone 3GS handsets with different iPhone OS versions installed (including the latest). All tested iPhones were protected with a four-digit PIN.</p>
<p>In Marienfeldt&#8217;s own words:</p>
<p>&#8220;The unprotected iPhone 3GS mounting is &#8220;limited&#8221; to the DCIM folder under Ubuntu < 10.04 LTS, Apple Macintosh, Windows 2000 SP2 and Windows 7. The way Ubuntu Lucid Lynx handles the iPhone 3GS [6,7,8] allows to get more content (please do make sure that the native Ubuntu system is fully up to date, e.g. "apt-get update, "apt-get upgrade" - any virtualization based solution will not work as described). I used the Alternate CD with x86 and AMD64 on different hardware." </p></blockquote>
<p>I guess with phones/embedded system we expected the user data to a little more secure and well we guessed wrongly. With a total of 33.75 million iPhones sold up to Q4 2009 that&#8217;s a staggering amount of vulnerable devices out there.</p>
<p>Another issue is Apple haven&#8217;t as yet worked out what the problem is, they&#8217;ve given some vague mentions of “race conditions” or “a pairing issues” but haven&#8217;t been able to reproduce it so far.</p>
<p>Other people have had varying success in exploiting the flaw, it seems to depend on the actual iPhone itself rather than anything else.</p>
<blockquote><p>Basically, plugging an up-to-date, non jail-broken, PIN-protected iPhone (powered off) into a computer running Ubuntu Lucid Lynx will allow the people to see practically all of the user&#8217;s data&#8211;including music, photos, videos, podcasts, voice recordings, Google safe browsing databases, and game contents. The &#8220;hacker&#8221; has read/write access to the iPhone, and the hack leaves no trace.</p>
<p>According to Marienfeldt, &#8220;The allowed write access could also lead into triggering a buffer overflow.&#8221; A buffer overflow could allow full write access, and full write access could potentially lead to the attacker being able to make phone calls (as far as we know, the attacker can access all of your data but they can&#8217;t make any phone calls&#8230;how reassuring).</p>
<p>Marienfeldt points out that this is especially an issue for corporate/business users, who &#8220;rely on the expectation that their iPhone 3GS&#8217;s whole content is protected by encryption with a passcode based authentication in place to unlock it.&#8221;</p>
<p>Apple has been notified of the flaw, but has yet to correct it (or give a timeline for the correction).</p></blockquote>
<p>I hope Apple can address this phone and give a proper breakdown and explanation of why this happens, there must be some technical explanation for it and why it occurs in their so called &#8216;secure&#8217; implementation.</p>
<p>You can read the original blog post here:</p>
<p><a href="http://marienfeldt.wordpress.com/2010/03/22/iphone-business-security-framework/">iPhone business security framework</a></p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2010/052810-iphone-security-flaw-using-a.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=iPhone+Security+Flaw+%E2%80%93+Using+a+PIN+Won%E2%80%99t+Protect+Your+Data+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2703+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/&amp;t=iPhone+Security+Flaw+%E2%80%93+Using+a+PIN+Won%E2%80%99t+Protect+Your+Data" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/&amp;title=iPhone+Security+Flaw+%E2%80%93+Using+a+PIN+Won%E2%80%99t+Protect+Your+Data" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/&amp;title=iPhone+Security+Flaw+%E2%80%93+Using+a+PIN+Won%E2%80%99t+Protect+Your+Data" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/&amp;title=iPhone+Security+Flaw+%E2%80%93+Using+a+PIN+Won%E2%80%99t+Protect+Your+Data" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/&amp;title=iPhone+Security+Flaw+%E2%80%93+Using+a+PIN+Won%E2%80%99t+Protect+Your+Data" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F06%2Fiphone-security-flaw-using-a-pin-wont-protect-your-data%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/06/iphone-security-flaw-using-a-pin-wont-protect-your-data/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Apple iPhone OS 3.0 Released &#8211; 46 Security Patches</title>
		<link>http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/</link>
		<comments>http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 08:18:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[apple iphone]]></category>
		<category><![CDATA[apple iphone 3.0]]></category>
		<category><![CDATA[apple iphone security]]></category>
		<category><![CDATA[apple software]]></category>
		<category><![CDATA[hacking iphone]]></category>
		<category><![CDATA[iphone 3.0]]></category>
		<category><![CDATA[iphone security]]></category>
		<category><![CDATA[iphone update]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1865</guid>
		<description><![CDATA[With the latest version of the Apple iPhone OS being released last night or this morning (depending where in the World you are) I guess most of the iPhone users amongst you would have already installed the software. Everyone I know using an iPhone has already done it without a hitch, it&#8217;s been long awaited [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>With the latest version of the <a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> iPhone OS being released last night or this morning (depending where in the World you are) I guess most of the iPhone users amongst you would have already installed the software.</p>
<p>Everyone I know using an iPhone has already done it without a hitch, it&#8217;s been long awaited and it&#8217;s definitely an improved over version 2.0.</p>
<p>The new OS also includes patches for 46 previously unpatched security vulnerabilities in the version 2.0 OS.</p>
<blockquote><p>Apple releases iPhone OS 3.0 to much fanfare. In addition to new features, the updated iPhone operating system brings several patches that address serious security issues in the mobile device.</p>
<p>Apple quietly plugged nearly four dozen security holes when it pushed out an upgrade to iPhone OS 3.0 on June 17.</p>
<p>With iPhone OS 3.0, users are getting fixes for several critical flaws, a number of which could be exploited by an attacker to execute arbitrary code. The WebKit and CoreGraphics components were the most vulnerable with 21 and eight vulnerabilities, respectively.</p></blockquote>
<p>There are several serious flaws being fixed in this update, so even if you don&#8217;t need the features please update for the security.</p>
<p>Let anyone else you know using the iPhone to update too.</p>
<p>Apple&#8217;s advisory on the issues can be found <a href="http://support.apple.com/kb/HT3639">here</a>. </p>
<blockquote><p>The Apple iPhone OS 3.0 contains more than 100 new features, some of which were aimed squarely at enterprises. In March, Apple gave about 50,000 individuals who paid to be part of the company&#8217;s developer program access to both the updated SDK (software development kit) and the beta version of the operating system as part of an effort to bring more secure business functionality to the iPhone. </p>
<p>The popularity of the iPhone and other smartphones has brought about an increased interest in properly securing and managing the devices. Along those lines, the <a href="http://www.eweek.com/c/a/Security/Five-iPhone-Security-Tips-for-IT-Departments-334334/">Center for Internet Security just released a benchmark with advice on using the iPhone securely</a>. </p>
<p>&#8220;Phones are small and relatively cheap, and fashionable, so many companies still don&#8217;t realize—or don&#8217;t want to acknowledge—that they can be as serious in terms of breach effects as a laptop or desktop PC,&#8221; Gartner analyst John Girard said. </p></blockquote>
<p>I would take a wild guess though with 100 new features introduced that Apple has also introduced some security vulnerabilities.</p>
<p>I&#8217;d give it a week or so before some issues start to pop up with the new OS.</p>
<p>Companies do need to look at the security of mobile devices seriously, that&#8217;s partially why BlackBerry is so popular as it&#8217;s easy to setup secure communications and lock down the device.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Apple-iPhone-OS-30-Brings-46-Security-Patches-to-Users-172227/?kc=rss">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Apple+iPhone+OS+3.0+Released+%E2%80%93+46+Security+Patches+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1865+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/&amp;t=Apple+iPhone+OS+3.0+Released+%E2%80%93+46+Security+Patches" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/&amp;title=Apple+iPhone+OS+3.0+Released+%E2%80%93+46+Security+Patches" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/&amp;title=Apple+iPhone+OS+3.0+Released+%E2%80%93+46+Security+Patches" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/&amp;title=Apple+iPhone+OS+3.0+Released+%E2%80%93+46+Security+Patches" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/&amp;title=Apple+iPhone+OS+3.0+Released+%E2%80%93+46+Security+Patches" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Fapple-iphone-os-3-0-released-46-security-patches%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/apple-iphone-os-3-0-released-46-security-patches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple iPhone Unlocked Again &#8211; 1.1.2 and 1.1.3 Firmware</title>
		<link>http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/</link>
		<comments>http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/#comments</comments>
		<pubDate>Mon, 18 Feb 2008 09:54:29 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple iphone]]></category>
		<category><![CDATA[geohot]]></category>
		<category><![CDATA[george hotz]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking iphone]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone jailbreak]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[unlock iphone]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/</guid>
		<description><![CDATA[Once again Apple iPhone has been unlocked by a determined youngster, the same who was amongst the first to unlock it last year winning himself a rather nice car and a few 8gb iPhones. It just shows nothing is infallible, all he needed to find was a writable memory address and he was pretty much [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Once again Apple iPhone has been unlocked by a determined youngster, the same <a href="http://www.theregister.co.uk/2007/08/29/hacked_iphone_trade/">who was amongst the first to unlock it</a> last year winning himself a rather nice car and a few 8gb iPhones.</p>
<p>It just shows nothing is infallible, all he needed to find was a writable memory address and he was pretty much done (he used a much higher range of registers than previously).</p>
<blockquote><p>A teen hacker known for his deftness with iPhones has figured out how to unlock models running the latest firmware versions by cracking a protection that has frustrated hackers for weeks.</p>
<p>The breakthrough by George Hotz, aka Geohot, means people who have bought a recent iPhone will once again be able to use it on the phone network of their choice. Apple makes as much as $400 for every handset that&#8217;s activated on an approved network, so its developers have worked hard to prevent the so-called unlocking of iPhones.</p></blockquote>
<p>A very smart young man indeed, just showing 1 person can indeed defeat the security of a huge multi-national billion dollar company.</p>
<p>And he&#8217;s done it twice.</p>
<blockquote><p>The latest salvo was fired late last week, following a 24-hour hacking spree by Geohot that was broken up by only three hours of sleep. It turns out the latest firmware contained modifications to the device&#8217;s memory registers to prevent unlocking. Geohot worked around those changes by finding another, much higher register that was vulnerable.</p>
<p>&#8220;I guess Apple thought big numbers were harder to guess,&#8221; he wrote.</p>
<p>He then found a way to install his custom-built code by exploiting a flaw that allowed him to erase a range of memory addresses where security software is stored.</p></blockquote>
<p>An amazing 27% of iPhones are running on unauthorized networks which means they are cracked. Of course Apple will soon come out with a new firmware update that negates this problem&#8230;.but then the game will just start all over again.</p>
<p>And no one doubt Geohot or someone like him will break it again.</p>
<p>If you want to know how to do it check out step-by-step instructions here from iClarified <a href="http://www.iclarified.com/entry/index.php?enid=649">here</a>.</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2008/02/11/latest_iphone_hack/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Apple+iPhone+Unlocked+Again+%E2%80%93+1.1.2+and+1.1.3+Firmware+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D803+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/&amp;t=Apple+iPhone+Unlocked+Again+%E2%80%93+1.1.2+and+1.1.3+Firmware" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/&amp;title=Apple+iPhone+Unlocked+Again+%E2%80%93+1.1.2+and+1.1.3+Firmware" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/&amp;title=Apple+iPhone+Unlocked+Again+%E2%80%93+1.1.2+and+1.1.3+Firmware" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/&amp;title=Apple+iPhone+Unlocked+Again+%E2%80%93+1.1.2+and+1.1.3+Firmware" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/&amp;title=Apple+iPhone+Unlocked+Again+%E2%80%93+1.1.2+and+1.1.3+Firmware" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F02%2Fapple-iphone-unlocked-again-112-and-113-firmware%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/02/apple-iphone-unlocked-again-112-and-113-firmware/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

