Download the Tom's Hardware App from the App Store
The reference for current tech news
Yes No

iPhone Hacked in 20 Seconds at Pwn2Own

by - source: Tom's Hardware US

Two European researchers have successfully hacked a fully patched iPhone and exfiltrated the device's entire SMS database in 20 seconds.

ZDNet reports that Vincenzo Iozzo and Ralf Philipp Weinmann exploited a previously unknown vulnerability and had the target iPhone visit a Web Site containing malicious code. It took Weinmann, a 32-year-old from the University of Luxembourg, collaborated and Iozzo, a 22-year-old Italian researcher from Zynamic, to find the vulnerability and write the exploit. Once they put everything in place, the hack took just 20 seconds.

"Basically, every page that the user visits on our [rigged] site will grab the SMS database and upload it to a server we control," Weinmann said, according to ZDNet.

Weinmann went on to say that in addition taking the SMS database, the exploit could have taken the phone's contact list (for both phone and email), photographs and iTunes files.

ZDNet cites Weinmann as saying there’s a non-root user called ‘mobile’ with certain user privileges in the iPhone Sandbox.  "With this exploit, I can do anything that ‘mobile’ can do," he said.

Weinmann and Iozzo won $15,000 and got to keep the iPhone.

Share:
3
Comments
Read more
X
Submit

Comments
Add your comment
redkachina 26/03/2010 01:20
Hide
-0+

that's hacking for you..really talented people..

Matan Eldan 27/03/2010 14:32
Hide
-1+

And the military want to achieve tech info from apple.
sure... lol

shahriarhkhan 21/04/2010 23:53
Hide
-0+

Every one having the same problem regarding hiding or locking text messages on iPhones. Recently I downloaded a program from http://faketexts.com/ and it hides the iPhone SMS button and replaces it with a fake one that you can edit. Basically it doesn’t show all the girls I am talking to.

Best offers

Newsletters


OK