Researcher finds possible bug in Apple's iPhone
The flaw was found by famed Mac hacker Charlie Miller
IDG News Service - Famed Mac hacker Charlie Miller has found another possible security vulnerability in Apple's iPhone.
Miller, a principal security analyst at Independent Security Evaluators, is known for his prowess in hacking Apple products, winning the CanSecWest security conference hacking contest two years straight.
Miller detailed his latest find -- just discovered a couple of days ago -- on Thursday at the Black Hat Europe security conference. The finding refutes what was a commonly held belief about how an unmodified iPhone works.
Most security researchers thought it wasn't possible to run shellcode on an iPhone. Shellcode is code that can run from a command line, but the iPhone was thought not to allow it for security reasons.
The ability to run shellcode is important, as it would let a hacker do all sorts of malicious actions, such as peeping at a person's text messages or call history of an iPhone from a remote location.
Earlier versions of the iPhone software didn't have many protections to prevent people from tampering with its memory to run other commands, Miller said. But the latest version of the iPhone's software strengthened the overall security of the phone, Miller said.
Miller said he's found a way to trick the iPhone into running code that enables shellcode. To run shellcode, however, an attacker would first need a working exploit for an iPhone, or a way to target some software vulnerability in, for example, the Safari Web browser or the mobile's operating system. Miller said he doesn't have one now.
But if someone did, "this would allow you to run whatever code you want," Miller said in an interview after his presentation.
In 2007, Miller and some of his colleagues did find a vulnerability in mobile Safari that would allow an attacker to control the iPhone. Apple was immediately notified and later issued a patch for the problem.
The significance of Miller's find is that it works with unaltered versions of the iPhone as the devices are sold in stores. Researchers have shown a greater ability to manipulate iPhones that are "jail-broken," the term for phones that have been modified to allow installation of applications not vetted by Apple. Those jail-broken phones have fewer protections on the device's memory, Miller said.
Miller said he isn't sure if Apple is aware of the latest issue. He stopped short of calling the problem a vulnerability, saying instead that Apple engineers may have overlooked the issue. Apple also has never come out publicly and said it is impossible to run shellcode on an iPhone, he said.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- Protecting Point of Sale Systems from Targeted Attack
- If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on...
- From the Frontline - Preventing APT
- Is your company's network secure? Are your endpoints and servers secured? Before you answer, read this case study on a US Military Command...
- Stop Hackers Before They Attack
- Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn...
- The four rules of complete web protection
- As an IT manager you've always known the web is a dangerous place. But with infections growing and the demands on your time... All Cybercrime and Hacking White Papers
- WikiLeaks: How am I Affected?
- The latest WikiLeaks episode has raised questions about how organizations and governments protect their sensitive information. While this incident was isolated, it has...
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn... All Cybercrime and Hacking Webcasts