TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Swedish developer discovers security hole in iPhone

76 pointsby orjanover 11 years ago

9 comments

orjanover 11 years ago
Google Translate didn&#x27;t do a good job, so I cleaned up the translation a bit:<p>A Swedish programmers has discovered a serious security hole in the iPhone. TechWorld&#x27;s news editor gets his phone hacked - and can not do anything about it.<p>A few days ago, TechWorld was contacted by the developer Roman Digerberg, who said he&#x27;d found serious security holes in iOS. Among other things, he asserted that it was possible to send an anonymous text message that appears on the lock screen, even when this is set to not display messages.<p>He also said that it was possible to manipulate the number that denotes the number of voice mail messages, or to just put a red dot in place of the indicator, which the user can not remove. When TechWorld talks to him, he tells us more:<p>How did you discover this? - It was by pure chance. I wrote a program in C# for my GPS tracker, which would facilitate the programming of it. By mistake I sent the text message to my iPhone which then began to beep and display strange messages on screen. Soon, I realized that I had created a monster.<p>What did you do? - I have been in contact with Apple, both via email and phone, but they seem totally uninterested in this. I&#x27;ve been thinking about making the source available online. People will start doing harakiri with each other&#x27;s phones, but why should you care about it when not even Apple does?<p>He also reports that he has received offers from several companies that want to buy the software to use it for advertising, since it is next to impossible to ignore the messages that pop up on the screen.<p>He offers to demonstrate how it works and TechWorld&#x27;s news editor gives him his phone number. Soon, things start to happen in his phone:<p>[image]<p>Apparently there were lots of people who tried to call in the last minute. However, the voicemail does not have any new messages.<p>[image]<p>But it still says that there were 250 missed calls. And it will not disappear, no matter what we do.<p>Roman Digerberg calls us to check that it worked. During our conversation, he sends another message:<p>[image]<p>Indeed a very good call. But maybe not so fun when ad companies get the technology, starting with mass mailings that can not be ignored or turned off.<p>After taking screenshots, he removes everything in seconds.<p>- You can not remove it, only I can remove it, he explains.<p>He is also sending over examples of much nastier things he can do:<p>[image]<p>So what should we make of this? An extra important call that was missed?<p>Or this, which has great potential to cause heart attacks:<p>[image]<p>He explains, without going further into technical details, that it&#x27;s about manipulating classes in the message structure. Other than sending messages that can not be avoided and manipulating figures for the number of messages, he says that he also managed to lock a phone altogether and that a restart was required to get it working again.<p>- Some think that I should start a paid service where you can anonymously send different types of messages. You can imagine what chaos there would be if people sit and sends unwanted and unavoidable messages to each other and make changes in each other&#x27;s phones. That said, I realize that this is a monster, says Roman Digerberg.
评论 #7226608 未加载
评论 #7226168 未加载
评论 #7225490 未加载
patrickasover 11 years ago
It seems to me he is just manipulating the DCS of the SMS being sent. This is standard behavior according to the GSM SMS specs.<p><a href="http://www.etsi.org/deliver/etsi_gts/03/0338/05.00.00_60/gsmts_0338v050000p.pdf" rel="nofollow">http:&#x2F;&#x2F;www.etsi.org&#x2F;deliver&#x2F;etsi_gts&#x2F;03&#x2F;0338&#x2F;05.00.00_60&#x2F;gsm...</a><p>From section 4, &quot;SMS Data Coding Scheme&quot; can be used to control &quot;Voicemail Message Waiting&quot; among other indicators and to send messages of &quot;Class 0&quot; which instruct the phone to shall &quot;display the message immediately and send an acknowledgement to the SC when the message has successfully reached the MS irrespective of whether there is memory available in the SIM or ME.&quot;<p>Admittedly it has been over a decade since I last played with sending such messages to phones, but it did seem to me like a bug in the spec, giving too much control to anyone with access to an sms-c (or any other mean to change the DCS field). Back then all phones I tested had implemented the spec as described.
评论 #7230116 未加载
robinduckettover 11 years ago
Isn&#x27;t this just SMS &quot;Flash&quot; messages? That&#x27;s how I was told the voicemail count worked when the iPhone came out on O2 in the UK all those years ago.<p><a href="http://en.wikipedia.org/wiki/Short_Message_Service#Flash_SMS" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Short_Message_Service#Flash_SMS</a>
评论 #7224874 未加载
评论 #7224793 未加载
评论 #7228636 未加载
评论 #7225907 未加载
评论 #7226018 未加载
x0054over 11 years ago
If Apple does not care about this vulnerability, sell it to the black hat community, let them spam with it. 500 visits a day to the Genius Bar per store will get this issue fixed in a hurry.
orjanover 11 years ago
It appears he is sending a specially formatted SMS message that the iPhone doesn&#x27;t handle correctly.
评论 #7224657 未加载
sergiotapiaover 11 years ago
Why risk legal trouble? Just sell it to black hat organizations and make tons of money with zero repercussions from outdated laws.<p>In this case I&#x27;m not sure those hacking laws apply, but who knows with these legislators. Anyone familiar with Swedish law in this area?
评论 #7227012 未加载
Kiroover 11 years ago
OT but I love how his name is translated. Novel The Black Mountains.
评论 #7224776 未加载
评论 #7227104 未加载
chrisBobover 11 years ago
The important thing that is missing is if this is an iPhone only issue.
badman_tingover 11 years ago
I&#x27;m not sure I agree on the severity, but of course Apple is being dumb by simply not communicating with the guy about it. Jeez.
评论 #7224875 未加载