Vaughan Spa

New iPhone Vulnerability Exposes Data to Linux

AnimalMagnetism

Self Imposed Exile
Apr 21, 2006
3,742
0
36
Toronto
A new report from security expert Bernard Marienfeldt illustrates a fairly big security hole in the way the iPhone secures user data. When plugged into a Windows or OSX box, and iPhone will only display the DCIM pictures folder. But on the newest Lucid Lynx build of Ubuntu Linux, users can get full read access to the phone. If you think setting a security PIN will help, you're wrong - it doesn't seem to do a thing.

This doesn't require the phone to be specially configured, or compromised in any way. Part of the problem is that in order to make syncing easier, the iPhone does not need any software switches to be flipped in order to exchange data with a computer. Another problem that allows this bug is the iPHone's lack of data encryption.

Marienfeldt says that full write access may be easy to gain as well with further investigation. If this is accomplished, an unauthorized party could access phone functions like calls and text messaging. The real lesson here is that maybe enterprise users should think twice about deploying iPhones.

source: http://www.maximumpc.com/article/news/new_iphone_vulnerability_exposes_data_linux



you guys better keep your phones away from Woodie lol ;)
 

AnimalMagnetism

Self Imposed Exile
Apr 21, 2006
3,742
0
36
Toronto
Update 17/05/2010: Apple’s iPhone 3GS broken authentication model:

I uncovered a data protection vulnerability [9], which I could reproduce on 3 other non jail broken 3GS iPhones (MC 131B, MC132B) with different iPhone OS versions installed (3.1.3-7E18 modem firmware 05.12.01 and version 3.1.2 -7D11, modem 05.11.07) , all passcode (4 digits) protected which means the vulnerability bypasses authentication for various data where people most likely rely on data protection through encryption and do not expect that authentication is not in place.

To clarify, the given file access is read and write !

This is what you get via an auto mount without any PIN (passcode 4 digits) request:


The unprotected iPhone 3GS mounting is “limited” to the DCIM folder under Ubuntu < 10.04 LTS, Apple Macintosh, Windows 2000 SP2 and Windows 7. The way Ubuntu Lucid Lynx handles the iPhone 3GS [6,7,8] allows to get more content (please do make sure that the native Ubuntu system is fully up to date, e.g. “apt-get update, “apt-get upgrade” - any virtualization based solution will not work as described). I used the Alternate CD with x86 and AMD64 on different hardware.

The “Libimobiledevice” [6] developers probably done just their best to make some content available under Linux but nevertheless I would still expect that the iPhone 3GS takes ownership and requests an authentication challenge when in the process to be mounted.

source: http://marienfeldt.wordpress.com/2010/03/22/iphone-business-security-framework/



nice security hole
 

WoodPeckr

Protuberant Member
May 29, 2002
47,064
6,196
113
North America
thewoodpecker.net
But on the newest Lucid Lynx build of Ubuntu Linux, users can get full read access to the phone. If you think setting a security PIN will help, you're wrong - it doesn't seem to do a thing.
Simply amazing the stuff Linux can do.....
 

WoodPeckr

Protuberant Member
May 29, 2002
47,064
6,196
113
North America
thewoodpecker.net
What he said!....
 
Toronto Escorts