iPhone hacked and hijacked at Pwn2Own

Software

haxor

Smartphones might have proved to be a tough nut to crack at last year’s CanSecWest Pwn2Own, but the same cannot be said for 2010 as two European hackers were able to gain control of a stock iPhone’s SMS database. The hack, which takes 20 seconds to execute by having the iPhone visit an infected website, allows its SMS messages — including those which had been deleted — to be uploaded to a predetermined server. If that’s not enough to make paranoid iPhone users soil their pants, the same exploit is also said to be able to access to a user’s address book, emails, photos and music all without leaving the iPhone sandbox. Naturally these sort of hacking developments are a bit frightening, but the good news is the hackers will hand their findings to Apple and keep mum on specifics while the Cupertino company does a bit of spackling with its iPhone OS.

Read

41 Comments
  • http://www.vintagefits.com FrankenBerry

    I don’t ever recall there being this type of hack for the BBerry? I would really like to see someone put RIM to the test.

    • ecou

      RIM was also put to the test and again didn’t fail because it’s the most secure smartphone that isn’t specifically made for .mil use. The only other technically more secure devices are ones that cost $4k+

  • Biggles

    Yeah, I don’t get it. These guys LOVE Apple and Jobs so much that they hand over their findings so the Cupertino crew can plug the holes? Meanwhile, people exploit the hell out of Windows and they hate Gates so much they perpetuate invasive techniques. I swear it’s becoming plainly obvious that Apple invests in sabotage and self-protection outside the walls of its offices. Hell, it wouldn’t surprise me at all to find out that they employ teams of hackers to come up with all the crap Microsoft has to deal with, and it’s funded by those ridiculous premiums they charge on their products.

    • Tdot34

      wouldn’t surprise me either… I fully believe the people at Nortons or Symantecs, AVG and all the other virus protection software companies are also the one creating the virus’ so people have a reason to buy their bloated over priced software every year.

      • Skyy_flyer

        Now correct me if I am wrong as I was just told this by a friend, but the free version of AVG actually was saying it was detecting a virus on the first scan just to make people think it was working. Again, I’ve never used AVG so I don’t know, but was just told that AVG did that.

    • Dara

      All of the pwn2own exploits are shared with the developers. This is not a hacking exercise, it’s a security demonstration.

      • badonkadonk

        … And it’s pay for play – they only get the “prize” money by turning over the details of the exploit. If an exploit was demo’d for WM or Android or anything else, they would also have to turn over the exploit to get the dough.

    • angryshortguy

      Ok,

      Put down the crack pipe, put on your aluminum skull cap, and wait for the aliens to abduct you again…

      Punks, thieves, and governments are responsible for the exploits, malware, and virus’s out there.

      MS is just the most profitable target and the OS that these hackers have the most knowledge and experience with.

  • Sith_Apprentice

    CanSecWest DOES test other devices as well. The iPhone was the only that got hacked.

  • kingdongdor

    I guess then its not a smartphone.

  • (The real Jarrett) Jarrett

    Oh, what’s this? Follow you into a dark alley? Okay. Give you my wallet? Okay. OH NO, PLEASE HELP ME I HAVE BEEN ROBBED.

    I swear, if this happens to someone you deserve what you get. You have to be led to the sight to be exploited. Why not just post your user name and password for them while you are at it.

    Can someone please come up with some sort of slick hack that involves someone really taking over an Apple built product. It has only benn 26 years surely someone is clever even to hack my system (phone or otherwise) without me having to do most of the work for them.

    • blah

      Most hacks, even on desktops require some sort of intervention. Whether it’s opening an e-mail, downloading a trojan, visiting a site… etc.

  • red014

    Maybe I’m naive towards famous hackers, but is that McLovin?

    • Bill Murray

      LOL, was totally going to say the same thing.

  • mangenius

    Jarrett are you retarded or just all over Jobs nutsack to pay attention.

    Your claim that its been 26 years without a hack is as equally stupid. First they have been hacked and the reason nobody cares is because their installed base is so small

    • (The real Jarrett) Jarrett

      I know, I know, the are so small. They have a market cap of almost $210 billion. Small beans. They make 35% of total profits from Personal Computer sales. Again, small beans. They own 91% of the market for machines casting $1,000.00 or more. I agree, small beans.

      I couldn’t agree more. Apple having higher prices is what made me money when I owned the stock. You keep living in your bubble that Apple isn’t the big player. There are a host of PC companies that thought the same thing for a long time. You might know some of those companies and even use their products. You may have recently purchased a NetBook from one of these vendros. After the total costs taken by the manufacturer they profited about $20 from that sale. This is how Dell made a profit of $1.4 billion all of last year and Apple made a profit of $3.4 billion last quarter.

      “Take care of your customers and the customers will take care of the business.”

      With that quote which company would you guess is better servicing their customers? I haven’t bought but two Apple products in the past three years. I won’t be buying an iPad, maybe 2nd generation. I will say though that when i do need a new device, whenever that may be it will absolutely be an Apple product. Until another company goes above and beyond (like servicing my old iMac twice out of warranty) then I will gladly shift my bias. Money talks and when you take my money seriously I will spend more for your services.

      • red014

        91% of RETAIL STORE sales above $1K. You realize how many ThinkPads are floating around in corporate America right now? Don’t skew the facts to make your argument. You are also making everyone’s point when you talk about their profits on computers. They charge too much because people like you keep buying them. Do you brag about how much profit oil companies make? They also have higher total profits because they own the largest music store in the world. They are selling something that costs them next to nothing and making a profit on it. Apple dropped the word “computers” from their name because they are no longer just a computer company.

        mangenius never said they were a small company. He said their market share on personal computers is smaller than Microsoft’s. That statement is 100% balls-on accurate. You don’t have to twist the numbers to make that point. If I’m writing a virus to target people, I’m going after the market that gives me a ~90% chance, not a ~10% chance. I’m starting to think that his other statement is true too.

      • Dara

        Further to that, their share of the consumer market is largely irrelevant to this topic.

        Unless somebody can figure out a way to make money from stealing pre-release graphic design work, there’s really not going to be a lot of effort put into hacking Apple boxes.

        99+% of the data that is worth stealing is on Windows, Unix, or Linux/GNU boxes.

        Why would somebody spend hours of their life trying to break into a system for mp3s and lolcats?

      • (The real Jarrett) Jarrett

        They are a business, and as a former shareholder I like their pricing model. Dell would charge you the same if they could, so would HP. If they could figure out how to transform themselves into a vertical growth company they would and drop Microsoft tomorrow. Windows is their herion and they can not survive without it. Apple owns 100% of the Macintosh, iPod and iPhone markets. No one dictates their business but them.

        Microsoft is paid the same amount for a Win 7 license regardless or computer (for the most part). This is great for Microsoft and they stay profitable. This is bad for HP, Dell, Acer, Asus and every other assembler because the have to fight each other on price. All of these companies would love for you to be a brand loyal customer but since you are not they all have to fight over that $15 to $20 profit they are going to make off of your purchase. You wonder why Dell can’t give great customer service? You just tell your boss that you only need to make $20 a week from now on and you let me know what exactly you are able to accomplish. Good luck.

      • red014

        Who exactly are you arguing with? If I said the sky was blue, would you start complaining about cars having 4 wheels?

        He stated the percentage of PC’s running Windows. Your retort was about profits.

        I’ll see your licensing argument and raise you with this: you know, AIDS isn’t a virus, it’s a condition caused by the HIV virus, right? So think about that next time you buy an Apple product.

        You’re a strange guy, Jarrett.

  • Chut Pata

    The so called “un-hackable” IBM mainframes e.g. 390 and AS/400 are also hackable. The reason they are not hacked is because this technology is not taught to school kids, main frames are not easily accessible for experiments, and finally the mainframe programmers can be thoroughly vetted for trust.

    • Sliznut

      nothing connected to the web is unhackable.

  • Plainly Obvious

    Okay, I can’t quite say I’m shocked. I mean, now if these hackers had got into say Android or WinMo or Symbian… okay any non-Apple system, I think it would be safe to say that BGR would just mouth how crappy it is and how that proves how unsafe it is and everything. But since this was a Apple product, that is not the case. BGR=Biased Guys Reporting… Kind of losing faith in this site as every other article is Apple while the ones that aren’t, seem to mouth any company that compete’s with Apple. /end rant /begin downranking.

    • (The real Jarrett) Jarrett

      Not going to downrank you. Just about any site has the same ratio of Apple stories to other stories. Giz goes through it, Engadget goes through it. I like the whole Apple story and it sometimes becomes comical to me just how many articles can be drawn up by “journalists”. There are other exciting things happening in technology, isn’t there?

      • Dara

        “There are other exciting things happening in technology, isn’t there?”

        Somebody who was just browsing this blog might think that Jarrett is asking a rhetorical question here. They’d be wrong, he really doesn’t know.

      • Plainly Obvious

        That’s what I mean (and BGR is really theo nly site I find easy to comment on at work as the work computers seem to despise engadget’s new site). You would think that Apple was the only tech company in the world when it came to cell phones or computers that deserve respect. Just be nice to hear a positive story about some other tech company other than Apple even once or twice a week.

      • (The real Jarrett) Jarrett

        I agree, it would be great to hear about new and exciting things. It just happens that when something new comes to market their is generally one company behind it. I would love to see some other company transform an industry for once. This is the time for some current company to transform the Television market. Please someone do it before Apple. Because once Apple does it the haters of Apple will double.

        Market Caps as of 12:14pm EST

        Microsoft $261+ billion
        Apple $209+ billion
        Google $181+ billion
        HP $125+ billion
        Dell $29+ billion

        Those last two are confusing, Are they not the major contributors to the corporate world? You know, where all that important business is at? It’s sort of like running the governemnt on the taxes paid by the top 1% of wealth. You can do it, for six months. But it takes the other 99% to actually keep it going.

      • Dara

        Well it would be confusing to somebody who knows nothing about the computer market.

        You see, Dell and HP are bit players in a much larger game that you apparently aren’t even aware of. They assemble computers and provide warranties, which is not a lot of added value to anyone except a moron that knows nothing about computers.

        You might want to expand your horizons a bit because the companies selling those netbooks are doing quite well.

        My personal go to brand, Asus, has a market cap of $236 B. Their neighbours, Acer, have a market cap of $254 B. They do all of this despite your imaginary hurdle of Windows licenses.

        Of course, none of that actually matters if we’re talking about technology.

        What does matter is that Asus is able to sell its loyal customers the best of today’s technology at competitive prices. Apple has done quite well for itself in finding a loyal group of customers willing to pay tomorrows prices for yesterdays hardware, but there’s another old saying that is quite apt:

        “A fool and his money are soon parted”

      • Jman

        Ladies & gentlemen, these other “technology” companies (computer resellers) have their woos in the market share because they don’t produce a “OS” to accompany, or compliment, their product; they only package somebody else’s, ie., Microsoft’s; that’s it in a nutshell.

        Not necessarily defending Apple, but until one (or more) of these companies comes up with a OS of their own, then they really won’t amount to any real wealth…kinda like Ford Motor Company vs 7-11.

        Another good example of this line of profit/wealth/survival thinking is what’s ongoing in mobile phone arena. Apple, Google, and Microsoft are the real players because they are competing with OS platforms which consumer’s can compare. The rest, handset mfgr’s, are… Again, Apple is shining because they not only produce an OS to compliment a handset; they produce a handset to compliment their OS. Google is working on their stardom with their complimenting handset–Nexus One.

    • jawman

      ++++++++++++ SO TRUE.

  • (The real Jarrett) Jarrett

    @ Dara,

    Go ahead and stick to drawing and playing games. Leave business to people who like making money.

    http://www.bloomberg.com/apps/quote?ticker=ACEIF%3AUS Acer $8+ billion (us)

    http://www.bloomberg.com/apps/quote?ticker=AKCIF%3AUS Asustek $7+ billion (us)

    I realize my information wouldn’t do it for you (me being uninformed and all) so I enlisted bloomberg to help.

    Try using US currency next time to determine a corporation’s market cap.

  • (The real Jarrett) Jarrett

    @ Dara,,,

    Go ahead and stick to drawing and playing games. Leave business to people who like making money.

    http://www.bloomberg.com/apps/quote?ticker=ACEIF%3AUS Acer $8+ billion (us)

    http://www.bloomberg.com/apps/quote?ticker=AKCIF%3AUS Asustek $7+ billion (us)

    I realize my information wouldn’t do it for you (me being uninformed and all) so I enlisted bloomberg to help.

    Try using US currency next time to determine a corporation’s market cap.

  • (The real Jarrett) Jarrett

    @ Dara,,,

    Go ahead and stick to drawing and playing games. Leave business to people who like making money.

    bloomberg.com/apps/quote?ticker=ACEIF%3AUS Acer $8+ billion (us)

    bloomberg.com/apps/quote?ticker=AKCIF%3AUS Asustek $7+ billion (us)

    You will have to add your own www. to the front of the URL’s. Moderator is very slow today.

    I realize my information wouldn’t do it for you (me being uninformed and all) so I enlisted bloomberg to help.

    Try using US currency next time to determine a corporation’s market cap.

  • (The real Jarrett) Jarrett

    $1.00 (TWD) = $0.03 (USD)

    • Dara

      You know what’s funny? Even when you’re right you get downvoted because people just assume you’re wrong. Congratulations on your reputation.

      That was my mistake with the taiwanese dollars (i.e. trusting wolfram alpha), but like I said… corporate numbers have nothing to do with a discussion about technology and, other than my employer’s numbers, don’t interest me.

      • (The real Jarrett) Jarrett

        Winners always get down ranked.

        “Losers complain about doing their best, winners go home and fuck the prom queen.”

        “Second place is no place, you’re off the team!”

        The second Karate Kid, funny stuff. (2nd quote)

  • Ag

    @
    Biggles

    WOW I wonder how long it took you to think all that, hater,
    now vote me down you fandroids bitches!!!!!

  • skyboxer

    Yes and to thank them for uncovering the security flaw, Apple will kill their accounts.

  • Corey

    Somebody took a bite out of that apple! Right? Right??!

  • Sliznut

    Dear God Jarrett, get the fuck off Steve Jobs’ balls! The man had to have his liver replaced already! He doesn’t need a wang transplant as well!

  • Necan6(

    LOL…IE 8 on Windows 7 hacks in 2 minutes. It’s on this web site. go Windows!!! ROFLMAO!!!!

blog comments powered by Disqus