TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How To Hijack 'Every iPhone In The World'

50 pointsby thinkzigalmost 16 years ago

9 comments

thinkzigalmost 16 years ago
OP here. In short, it sounds like the iPhone SMS infrastructure is susceptible to buffer overflow attacks. Seems the guys who have found it have given Apple a lot of time to fix it with no response so far.
评论 #730746 未加载
评论 #730582 未加载
embeddedradicalalmost 16 years ago
<i>Though Miller and Mulliner say they notified Apple about the vulnerability more than a month ago, the company hasn't released a patch, and it didn't respond to Forbes' repeated calls seeking comment.</i><p>those new android phones are coming out later this year, right?
评论 #730735 未加载
pedalpetealmost 16 years ago
This makes me wonder if the reason we haven't seen major threats on other mobile devices/platforms is due more to the lack of a market penetration vs. a lack of security.<p>It's the old 'Apple doesn't get viruses' argument in reverse. Not as many viruses targeted Macs because it had a smaller user base, so they focused on Windows. Now that Apple has serious traction with a device which is in someways ideally suited to forwarding the virus, they are becoming the focus on an attack.
teejalmost 16 years ago
This was reported earlier in the month. Most blogs' source reference is this Yahoo Tech article, that claims:<p>"Apple is working to fix an iPhone vulnerability that could allow an attacker to remotely install and run unsigned software code with root access to the phone."<p><a href="http://tech.yahoo.com/news/pcworld/20090702/tc_pcworld/applepatchingserioussmsvulnerabilityoniphone" rel="nofollow">http://tech.yahoo.com/news/pcworld/20090702/tc_pcworld/apple...</a><p>No details on if Apple dropped the ball or if they were actually working on it in the first place.<p>My best guess to the vulnerability is the iPhones new MMS capability. They probably had to punch some holes in the sandbox to get MMS media saved on to the phone.
评论 #730539 未加载
jrockwayalmost 16 years ago
Some day, I hope people will stop writing their software in C.
评论 #730854 未加载
jodrellblankalmost 16 years ago
If you have a vulnerability that could result in the takeover of every iPhone in the world, along with a noticable increase in SMS message traffic over carrier networks, and the manufacturer has not fixed it yet...<p>... then you probably shouldn't release it.<p>(Also: Buffer Overflow? Hello? Did someone develop this ten years ago?)
评论 #730639 未加载
评论 #731075 未加载
benatkinalmost 16 years ago
s/every/any/<p>You'd have to be able to send a text message to every iPhone in the world in order to hijack all of them.
评论 #730782 未加载
ynnivalmost 16 years ago
Funny, no one paid much attention when this was posted four weeks ago. People never pay much attention to security until its about to bite them.<p>Ho hum, if you would like to avoid the SMS apocalypse you can hope that Apple releases a security update before the conference, or you can sign up for AT&#38;T's Smart Limits for Wireless Parental Controls ($5/mo) and set your SMS quota to 0 (add your Mom to the whitelist first).
评论 #731437 未加载
migpwralmost 16 years ago
I'm not trying to be the dumbass comment but this better make its way to a celebrity phone somewhere. SOMETHING of real value has to come of this... obviously, other than a more secure SMS infrastructure.