Skip to main content

Secondary menu

User menu

  • Join
  • OR
  • Log In

MNN - Mother Nature Network

Thursday, May 23, 2013
SPECIAL FEATURES:
  • Leaderboard
  • Nest
  • TreeHugger
  • Photos
  • Blogs
  • SB 2013
  • Joy of Less

Search form

Social links

Main menu

  • Earth Matters
    • Browse all »
    • Animals
    • Weather
    • Energy
    • Politics
    • Space
    • Translating Uncle Sam
    • Wilderness & Resources
  • Health
    • Browse all »
    • Allergies
    • Fitness & Well-Being
    • Healthy Spaces
  • Lifestyle
    • Browse all »
    • Arts & Culture
    • Travel
    • Natural Beauty & Fashion
    • Recycling
    • Responsible Living
  • Green Tech
    • Browse all »
    • Computers
    • Gadgets & Electronics
    • Research & Innovations
    • Transportation
  • Eco-Biz & Money
    • Browse all »
    • Green Workplace
    • Personal Finance
    • Sustainable Business Practices
  • Food & Drink
    • Browse all »
    • Beverages
    • Healthy Eating
    • Recipes
  • Your Home
    • Browse all »
    • At Home
    • Organic Farming & Gardening
    • Remodeling & Design
  • Family
    • Browse all »
    • Babies & Pregnancy
    • Family Activities
    • Pets
    • Protection & Safety

Breadcrumb Navigation

MNN.COM › Green Tech › Gadgets & Electronics
    x
  • Tweet
  • Email
  • Bookmark and ShareShare
  • Earn Points
    What's this?
iPhone 5 operating system already the victim of hackers
A gap in the mobile browser on the iPhone 4S and iPhone 5 allows 'drive-by' malware to install itself without users even knowing.

By

Ben Weitzenkorn, SecurityNewsDaily
Fri, Sep 21 2012 at 10:28 AM

Related Topics:

iPhone, Apple, Technology
The new iPhone 5 is displayed during an Apple special event at the Yerba Buena Center for the Arts

The new iPhone 5 is displayed during an Apple special event at the Yerba Buena Center for the Arts on Sept. 12. (Photo: Justin Sullivan/Getty Images)

The iPhone 4S, and probably the iPhone 5 as well, are vulnerable to attacks from malicious web pages that can steal the user's pictures, contact information and browsing history and send it all to a remote server.
 
On Sept. 19 at the Mobile Pwn2Own contest at the EUSecWest conference in Amsterdam, a pair of Dutch security researchers successfully exploited a completely patched iPhone 4S.
 
The duo, Daan Keuper and Joost Pol from The Hague-based computer security company Certified Secure, said their proof-of-concept hack works on both iOS 5.1.1 and the version of iOS 6 that was given to developers several months ago.
 
Keuper and Pol said iPads are also vulnerable to this attack. While the two haven't had a chance to test an iPhone 5 running the final build of iOS 6, it is likely also at risk, they told Computerworld.
 
The malicious code — technically, a drive-by download — took only a few weeks to create and can be embedded anywhere on a website to work, Pol said.
 
When placed in a graphic or advertisement on a blog visited by Mobile Safari, the code figures out a workaround for Safari's sandboxing and signing mechanisms.
 
Users don't need to do anything but visit the booby-trapped page for the malware to work. While the attack is able to steal a lot of sensitive data, email and SMS messages are separately encrypted and are not vulnerable to this particular attack.
 
Keuper and Pol wouldn't reveal exactly how their attack works, but told ZDNet that it involved a zero-day exploit, one that's not yet known to most security specialists.
 
They also told ZDNet that they wouldn't do it again.
 
"We shredded it from our machine," Pol said. "The story ends here. ... It's time to look for a new challenge."
 
Despite this chink in the iPhone's armor, Pol said he still thinks the iPhone is more secure than any other mobile device.
 
He said that BlackBerry and Android devices, which that run the same WebKit rendering in their browsers as iOS's Safari, could also be open to this exploit, but haven’t been tested. Pol hopes Apple fixes the exploit soon and that users download the patch as soon as possible.
 
Last year, security researcher Charlie Miller snuck a malicious proof-of-concept app into Apple's iTunes App Store that could also steal data from iPhones.
 
For their successful hack of Mobile Safari, Pol and Keuper together took home $30,000.
 
Related on SecurityNewsDaily:
  • 10 Pros and Cons of Jailbreaking Your iPhone or iPad
  • Email Scammers Prey on iPhone 5 Anticipation
  • 10 Best Mobile Security Software Products
 
This story was originally written for SecurityNewsDaily and was reprinted with permission here. Copyright 2012 SecurityNewsDaily, a TechMediaNetwork company. All rights reserved.

You might also like:

Join the conversation

Comment: 1
Sign in with one of these accounts to add your comment.
Log in or
create an account
  • Sign in using this account:
anonymous
eza Nov 13 2012 at 10:09 AM

i think the iphone should have more stuff to access to and have more things to do on the phone

|
  • Log in or register to post comments
  • Report This Post 

EDITORS' PICKS

tease drones

line

tease book cars

line

tease sunscreen

Advertisement

TODAY'S MOST POPULAR ON

  1. U
  2. Rapping math teacher uses rhyme to make sense of cosine
  3. Drones may become sentinels for U.S. highways
  4. Why can't I have grapefruit while taking certain prescription drugs?
  5. What kind of food should I feed my dog?
  6. Energy-guzzling cities changing weather 1,000 miles away
+ Add this to my site
From our sponsor
Making a difference with the click of a mouse: Tech meets philanthropy at Causes.com
Causes.com and AT&T offer Connect for Good, a program that encourages the telecommunications more...
AT&T: Transforming Business
The Distributed Workplace: AT&T Saves Money and Resources with Telecommuting
AT&T minimizes its environmental impact with telecommuting technology, enabling many of its more...
AT&T: Transforming Business
Do One Thing: AT&T employees lead positive change in the community
The 2012 champions of AT&T's Do One Thing - Rethink Possible employee engagement program more...
AT&T: Transforming Business
John Schinter explains AT&T’s three-pronged approach to energy management
John Schinter, AT&T's Director of Energy, explains that one of AT&T's most more...
AT&T: Transforming Business
Water scarcity 101: AT&T explores the relationship between energy and water
AT&T teams up with the Environmental Defense Fund (EDF) to examine ways to save water in its more...
AT&T: Transforming Business

NEWSLETTER

Mother Nature. Delivered
Advertisement
Advertisement

Footer menu

  • Quick Links
    • Joy of Less
    • About Us
    • Advisory Board
    • Editors' Blog
    • Press
    • Privacy
    • Sitemap
    • Terms of Service
  • MNN Tools
    • Advice
    • Blogs
    • Day in History
    • Eco-glossary
    • Infographics
    • Lists
    • Photos
    • Videos
  • Connect
    • The Nest
    • Contact Us
    • Mixed Greens
    • Newsletters
    • RSS
    • Social
    • TreeHugger
    • Mobile
  • Channels
    • Earth Matters
    • Health
    • Lifestyle
    • Green Tech
    • Eco-Biz & Money
    • Your Home
    • Family
    • State Reports
  • Follow MNN
    • Facebook
    • Twitter
    • Pinterest
    • Tumblr
    • Google+
    • StumbleUpon

Copyright © 2013 MNN Holdings, LLC. All Rights Reserved. Website by GLICK INTERACTIVE | Powered by CIRRACORE

SPONSORS