Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, 25 September 2011

Two iOS security breaches and how the hackers got those pictures of you

    Germany’s Federal Office for Information Security discovered a serious security vulnerability in Apple's iOS platform. The security hole allows a malicious user access to the root files of the phone, where they could see personal user information like passwords, call logs, messages, and and your location date if he hasn't done so already. Apple has acknowledged the problem and promises to issue a fix.
Speaking to the Associated Press, Apple spokesperson Bethan Lloyd said Apple is "aware of this reported issue and developing a fix that will be available to customers in an upcoming software update." She did not provide a date as to when the fix would be available.
     In other news, multiple frustrated iPhone 4 owners have complained this week that their device's front-side camera is taking pictures of them when it is supposed to be inactive.
Those photos then show up on the iPhone screen when the user tries to start a FaceTime video call. One angry owner said her FaceTime picture showed her in her office, despite never using the app while at work.


Wednesday, 21 September 2011

iOS vulnerability leaves Skype users open to address book theft


    If you are using Skype for iPhone or iPod Touch, the Address Book on your device can easily be stolen via a simple chat message.

    How does it work?: Javascript commands are entered into the user names Skype account, a chat message is sent to the user who is using the newest version of Skype for iPhone, and a program is loaded onto a web server to receive the Address Book content.

    The report claims there is two oversights that are allowing this to happen so easily:

  • iOS allows address book contents accessible to every app installed
  • Failure by Skype to sanitize potentially dangerous JavaScript commands from the text that gets sent in chat messages
Of course it will be Skype's responsibility to patch the hole as iOS security is currently a complete mess as apple still tries to figure out the hole that made them lose the US Army defense contract.
    Meanwhile any skilled hacker/developer can collect your and your friend's addresses with the simplest app or game imaginable.
Detailed instructions of the hack after the break.


Sunday, 18 September 2011

OS X Lion disappoints again - it's just like having no password at all

    OS X from apple has not seen a great deal of interest during development (if any) and one million downloads on launch day, reported by Apple, so you can expect that number was rounded. For an $30 OS this is certainly a disappointment.
Not only has one of the sites endorsed by Apple, Gizmodo, called it a failure but the cuts in manufacturing quality at Foxconn and security holes haven't certainly brought more popularity:
     Security blog Defense in Depth has found a glaring security flaw in OS X Lion that enables hackers to change the password of any user on a machine running Lion. “[While] non-root users are unable to access the shadow files directly, Lion actually provides non-root users the ability to still view password hash data,” Patrick Dunstan from Defense in Depth explained in a recent blog post. The result is that anyone could use a simple Python script, created by Dunstan himself, to discover a user’s password. It gets worse. Reportedly, OS X Lion does not require its users to enter a password to change the login credentials of the current user. That means typing the command: “dscl localhost -passwd /Search/Users/Roger” will actually prompt you to set a new password for Roger. Hackers could easily take advantage of the known bug if they have local access to the computer and Directory Service access. Disabling automatic log-in, enabling sleep and screensaver passwords and disabling guest accounts are as efficient to keeping your Mac secure as duck-taping the lid. We recommend upgrading to a Linux based OS or Windows.

Friday, 22 July 2011

MAC: Security so bad, even your battery can get hacked

There's your problem, it's a virus!
   Charlie Miller's managed yet again to render several Macbooks, Macbook Pros and Airs useless after gaining total access to their battery's micro-controllers' firmware via a security hole. Evidently, the Li-ion packs for the line of laptops are accessible with passwords he dug up from an 2009 software update. He mentions that someone could "use them to do something really bad," including faulting charge-levels and thermal read-outs to possibly even making them explode. He also thinks hard-to-spot malware could be installed directly within the battery, repeatedly infecting a computer unless removed.
“You could put a whole hard drive in, reinstall the software, flash the BIOS, and every time it would reattack and screw you over. There would be no way to eradicate or detect it other than removing the battery.”

Sunday, 8 May 2011

Apple loses US Army contract, Russian govermnent wants to ban iProducts due to security concerns

    Apple has lost the U.S. Army defense contract in favor of Android for upcoming Army-approved smartphones and tablets, as well as  for apps that will be necessary for missions.
  There have been concerns about security for Android as compared to other mobile OS but most officials deemed Android the most secure, as the Army will be able to use the open source software as they choose, likely beefing up security even more. In terms of stability and connectivity, the OS is leaps and bounds above the competition.
    During combat, the devices will likely have to have satellite  phone-capabilities, meaning round-the-clock data and voice with no lapses. The Army wants every soldier to have one of the future Android devices, to ensure they are connected during missions. A prototype dubbed the Joint Battle Command-Platform is already being tested. Apps will include "critical messaging" for exchanging medevac requests and other emergencies, and A Blue Force Tracker program to make sure soldiers know where friendlies are. Finally, the phones will be able to withstand extreme wear-and-tear  and will likely be similar to the rugged "ToughBooks" created by Panasonic.

Thursday, 7 April 2011

The Apple/iOS user tracking & privacy breaking roundup


    You’ve probably heard by now about the detailed log your iOS device keeps of your movements, but it's about time a roundup o the whole story was made. Now there’s a tool to prevent that plus some more clarity on the issue, which like all freedom on Apple products, requires jailbreaking.
    Apple's location services pinpoint your location using GPS, Cell-ID and Wi-Fi hotspots. Early devices used Google and Skyhook databases to do that, but since iOS 3.2 Apple has been building up their own database - you become their Guinea Pig (read: lab rat).
     A file kept unencrypted on your iProduct holds a record of all your movements from about an year ago and that file is copied to any computer you’ve synced it to and any backups you might have made.
As usual with Apple software, there's no security between anyone and your private data (called consolidated.db), either by copying it from a computer that contains a copy of the file or simply stealing the device itself, can easily extract a log of your whereabouts over the last year.(red more about Steve Jobs's opinion and Android below)

Wednesday, 23 March 2011

iOS and MACos destroyed (again) at Pwn2Own security conference

    The Pwn2Own event, held at the CanSecWest security conference in Vancouver, allows companies to challenge hackers to exploit their software, i.e. operating systems or web browsers.

iOS
    Charlie Miller and Dion Blazakis have managed to yet again hack iOS thanks to a security hole in the mobile version of Safari. They managed to access the contacts and inbox of an iPhone 4 (iOS 4.2.1) by simply loading a web page.
    The vulnerability isn't patched in iOS 4.3 and it looks like ASLR (Address Space Layout Randomization) won't be able to protect you from this one.

MACos
    This year French pen-testing firm VUPEN has hacked Apple’s Safari web browser using a zero-day flaw to win the coveted Pwn2Own hacker challenge.
    The exploited computer was a fully patched MacBook running Mac OS X (64-bit). Co-founder of VUPEN, Chaouki Beckar, lured the Mac to a fake website and managed to bypass the ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) execution procedures that were built into the OS. He then launched a calculator app successfully and wrote files to the machine.

Sunday, 6 February 2011

Tens of thousands of hacked iTunes accounts are now for sale

    Hacked iTunes accounts are available for sale across China at prices starting as low as a few dollars. These hacked account details, include credit card details, were being made available for sale via China's largest retail website, Taobao. An original report in the Global Times claimed around 50.000 hacked accounts were being peddled on Taobao at prices ranging from one to 200 yuan. Thousands of accounts have been sold over the past several months, it said. AFP has confirmed the claims.
    The retailer claimed it takes all reasonable and necessary steps to protect consumers. Hacked iTunes accounts are sold with the admonition to use them for just 24-hours.

    “At this time, we have not received any information from Apple or any other principal related to the iTunes accounts indicating that these products either violate our listing rules or infringe on the IP of others,” the company said, as reported by AFP.

    Well we're probably going to see a lot more Vietnamese books being sold/bought in record numbers but the question at hand is, what really makes iTunes such a good target; what happened to Amazon, Paypal, Ebay?

Friday, 4 February 2011

Apple: Hey! Your bank account just got drained

     An unsuspecting reader of The Register, named Peter, woke up one morning to discover an email informing him of a "£10 Monthly Gift for wqfaqapk445@hotmail.com", an account he'd never heard of.
    The vouchers, sent to a recipient's email address, can be used to purchase music and audio books from the iTunes Music Store. Peter checked his iTunes purchase history, where to his horror he discovered scores of these "Monthly Gift" purchases, all of which had been generated within a short space of time on 19 January, but only one of which generated an email - because Apple really doesn't want to bother you while "you're" spending. He was informed of the theft by an e-mail from Apple, saying his £1,000 gift purchase had been confirmed, sum which didn't alert any of the iTunes security policies (if there are any) for an user that didn't spend more than 5£ a month. Ever.

    Apple describes iTunes Monthly Gifts as a "great way to give a gift that keeps on giving".
"How is it even possible for iTunes to be used as some type of glorified bank account? Why the hell would I want to use iTunes to transfer money to people?
"It is completely unacceptable that Apple has turned iTunes into some type of pseudo-PayPal without the security measures, monitoring and care being taken to run something so important,"
"iTunes isn't just a system for buying a bit of music; it's turned into a banking system that can wipe out your finances and put whole families into financial limbo." Peter concluded.
[UPDATE]

Tuesday, 26 October 2010

October is the iOS security flaw month at the iPhone Fever!

     No, you're not reading an old story. There really is yet another serious iOS security flaw which allows someone to access information on your supposedly password-protected iPhone.
    As the Brazilian fellow in the video above shows, all that you need to do is grab a password-protected iPhone running iOS 4.1, pretend to make an emergency call but dial ### or some other nonsensical number instead, tap the lock button real quick, and tada! You'll have access to the device's contacts, voicemail, call history, voice control and phone features.
    I replicated this trick successfully on  iOS 4.1. When trying this on an iPhone iOS 4.2 Beta 3 I couldn't replicate the security hole. This could mean that Apple is already aware of the flaw and has the fix ready although  this is very similar to the security flaw discovered on the iPhone in 2008 allowed people to easily bypass the lock screen to access mail, contacts and bookmarks. Apple later acknowledged the bug and issued a software update patching the issue.

Sunday, 24 October 2010

Apple personal information free give-away. Snoop it while it's hot!

    Hidden in music files gotten from iTunes is  all the information needed to identify you. You won’t find it disclosed in their published terms of use. It’s nowhere in the support documentation. There’s no mention in the digital receipt. Consumers are largely oblivious to this, but it could have future ramifications as the music industry takes another stab at locking down music files.
    Here’s how it works: Apple knows your private data; before making the song available for download their software embeds into the file either an account name or a transaction number or both. Once downloaded, the file has squirreled away this personal information in a manner where you can’t easily see it, but if someone knows where to look they can. This information doesn’t affect the audio fidelity, but it does permanently attach to the file data which can be used to trace back to the original purchaser which could be used at a later date.
    As usual Apple refused comment on the matter, but there’s ample proof of what’s transpiring. Using simple file comparison tools it’s possible to verify this behavior by purchasing identical songs using different accounts and see if they match. This unfortunately applies to both purchased and free music you might have gotten from the iStore - even if it's DRM free!

iOS 4 - as insecure as ever

Nicolas Seriot, Security Analyst,  created a proof-of-concept
"SpyPhone" app to show how easy it is to snoop on iPhone users.
     Lax security screening at Apple's App Store and a design flaw are putting iPhone users at risk of downloading malicious applications that could steal data and spy on them, a Swiss researcher warns.
     Apple's iPhone app review process is inadequate to stop malicious apps from getting distributed to millions of users, according to Nicolas Seriot, a software engineer and scientific collaborator at the Swiss University of Applied Sciences (HEIG-VD). Once they are downloaded, iPhone apps have unfettered access to a wide range of privacy-invasive information about the user's device, location, activities, interests, and friends, he said in an interview Tuesday.
     In a talk scheduled at the Black Hat DC security conference, Seriot will explain how an innocent-looking app could be designed to harvest personal data and send it to a remote server without the user knowing it.
      The rogue app could be hidden within an innocent-looking app, such as a game. Low-hanging fruit for rogue apps includes the mobile-phone number, address book data, and a notes section of the address book, where some people store bank account and other sensitive information, he said.
"It turns out that the full Address Book is readable without the user's knowledge or consent," Seriot wrote in a white paper (PDF) on the subject.

Tuesday, 29 June 2010

Apple App Store and iTunes Accounts Hacked

     Apple hackers are at large again. One guy, Thuat Nguyen has apparently hacked into iTunes. He did this dastardly deed just to boots the ratings for his book apps that accounted for 42 of the top 50 books by revenue in the Books section of the iTunes App Store. Other developers noticed the lopsided rise in Nguyen’s app and found it very mysterious. Up to $200 from hacked accounts were reportedly used to buy the developer's apps. So far there’s nothing official that’s come out of Apple concerning the hack but word is they’re still investigating. So if you notice a few books added onto your account, try to remember if you bought them, even if they are in Vietnamese.