SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Apple may patch serious SMS vulnerability on iPhone

Apple may patch serious SMS vulnerability on iPhone

By:  Sumner Lemon  On: 01 Jul 2009 For: IDG News Service (Singapore Bureau) (GM) Creator

The iPhone is more secure than MacOS X-based computers, but SMS may be a critical weakness

Apple may be working to fix an iPhone vulnerability that could possibly allow an attacker to remotely install and run unsigned software code with root access to the phone.

The attack in question exploits a weakness in the way iPhones handle text messages received via SMS (Short Message Service), said security researcher Charlie Miller, during a presentation at the SyScan conference in Singapore on Thursday. He didn't provide a detailed description of the SMS vulnerability, citing an agreement with Apple.

Miller, the principal security analyst at Independent Security Evaluators, is an authority on MacOS X security, and is a co-author of The Mac Hacker's Handbook. He and another security researcher, Colin Mulliner, discovered the SMS vulnerability together.

An SMS flaw might allow an attacker to run software code on the phone that is sent by SMS over a mobile operator's network. In Miller’s case, it appears he used the flaw he found to remotely crash an iPhone, a sign that a more serious attack might be possible.

"I don't have a working exploit for it, just a suspicious looking crash," Miller said.

If so, the malicious code could theoretically include commands to monitor the location of the phone using GPS, turn on the phone's microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet, Miller said

Miller reported the vulnerability to Apple, hoping it will get fixed. He plans to discuss the flaw further during a presentation at the Black Hat USA conference in Las Vegas. Despite the SMS vulnerability, the stripped-down version of MacOS X used in the iPhone makes it more secure than computers running the full-blown operating system, Miller said.

For starters, the stripped-down version of the OS presents fewer options for attackers, removing applications and features such as support for Adobe Flash and Java, which they might otherwise be able to exploit for vulnerabilities. In addition, the iPhone includes hardware protection for data stored in memory and the phone is designed to only run software code that has been digitally signed by Apple.

The iPhone also requires applications to run in a sandbox, a security feature that isolates them from other applications and limits their access to the phone's capabilities. But SMS offers a way for attackers to get greater access to the phone's capabilities, Miller said.

"SMS is a great vector to attack the iPhone," he said.

Most often used to send brief text messages between cell phones, SMS can also send binary code to an iPhone, which then processes the code without any user interaction. Each SMS message is limited to 140 bytes, but longer sequences can be sent to the phone as multiple messages that are automatically reassembled.

This feature allows larger programs to be delivered to a phone, Miller said.


Sign up for our Newsletters












Print |  Views: 965   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Sumner Lemon Sumner Lemon is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Zero day: IT's race against the clock
Zero day: IT's race against the clockZero-day exploits are on the rise, and the vulnerability marketplace as well as improvements in enterprise patch management are deemed contributors to this rising security risk.
Does zero-day mean zero response?
Does zero-day mean zero response?The time it takes for a known vulnerability to be exploited by some sort of malware has fallen precipitously in the past three years. From the time that the vulnerability became known, the Slammer worm took six months to hit, Sasser took three weeks, and the Witty worm took two days. One of 2005’s best-known worms, Zotob, started making the rounds six days after the vulnerability was identified.Today, many IT security observers believe that zero-day attacks are imminent – if, in fact, they haven’t already happened.
Hackers jump through holes in Microsoft patch
Hackers jump through holes in Microsoft patchSecurity experts are warning Microsoft Corp. customers about silent Internet attacks that exploit a security flaw in the Internet Explorer Web browser, potentially allowing remote attackers to run malicious code on vulnerable machines.
Why hack a Mac?
by joaquim p. menezes - remember charlie miller? 
blog comments powered by Disqus