Go Back   Wireless and Wifi Forums > Cellular Communications > US Networks > alt.cellular.cingular
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-04-2009, 07:56 PM
News
Guest
 
Posts: n/a
Default jailbroken iPhones compromised, $5 ransom demanded

Yesterday, a “Your iPhone’s been hacked because it’s really insecure!
Please visit doiop.com/iHacked and secure your phone right now!” message
popped up on the screens of a large number of automatically exploited
Dutch iPhone users, demanding $4.95 for instructions on how to secure
their iPhones and remove the message from appearing at startup.

Through a combination of port scanning and OS fingerprinting of
T-Mobile’s 3G IP range, a Dutch teenager has for the first time
automatically exploited a known security vulnerability introduced on
jailbroken iPhones - the SSH daemon which unless modified remains
running with default users root and mobile, using the same password on
each and every device.

Here’s what he demanded, and how he changed his attitude following the
suspension of his PayPal and the spamvertised URL:

The now taken offline site was featuring the following message:

“Dear iPhone user,

Your iPhone is not secure. That’s the reason your visiting this
page, isn’t it? Well you can pay me $4,95 at my paypal account
PureInfinity92@mailinator.com, and I’ll mail you very easy instructions
on how to secure your iPhone. You can also contact me at
PureInfinity92@gmail.com

If you don’t pay, it’s fine by me. But remember, the way I got
access to your iPhone can be used by thousands of others. And they can
send text messages from your number (like I did..), use it to call (or
record your calls), and actually whatever they want, even use it for
their hacking activities! I can assure you, I have no intention of
harming you or whatever, but, some hackers do! It’s just my advise to
secure your phone (: Have a nice day!”

Following the media coverage, active discussions across popular Dutch IT
forums, and the timely shut down of his PayPal account, the
opportunistic and unethical pen-tester quickly changed his attitude and
posted an apology followed by step-by-step guide on changing the default
SSH password, which he was originally offering for a fee.

Why is this automatic exploitation not a surprise?

* Go through related posts: iBotnet: Researchers find signs of
zombie Macs; iPhone’s anti-phishing protection offers inconsistent
results; Snow Leopard’s malware protection only scans for two Trojans;
New Mac OS X DNS changer spreads through social engineering

The exploitability of the default SSH root login combined with the ease
of OS fingerprinting an iPhone’s, and the descriptive and well known 3G
IP ranges for certain service providers, has already been discussed as
an opportunity for automatically exploiting jailbroken iPhones running
the SSH daemon with default passwords.



http://blogs.zdnet.com/security/?p=4805&tag=nl.e550

Reply With Quote
  #2 (permalink)  
Old 11-04-2009, 08:08 PM
nospam
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded

In article <nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.net> , News
<News@Group.Name> wrote:

> Through a combination of port scanning and OS fingerprinting of
> T-Mobile’s 3G IP range, a Dutch teenager has for the first time
> automatically exploited a known security vulnerability introduced on
> jailbroken iPhones - the SSH daemon which unless modified remains
> running with default users root and mobile, using the same password on
> each and every device.


it's only there if the user jailbreaks, installs ssh and leaves it
running.

Reply With Quote
  #3 (permalink)  
Old 11-04-2009, 10:21 PM
DevilsPGD
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded

In message <041120091508018998%nospam@nospam.invalid> nospam
<nospam@nospam.invalid> was claimed to have wrote:

>In article <nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.net> , News
><News@Group.Name> wrote:
>
>> Through a combination of port scanning and OS fingerprinting of
>> T-Mobile’s 3G IP range, a Dutch teenager has for the first time
>> automatically exploited a known security vulnerability introduced on
>> jailbroken iPhones - the SSH daemon which unless modified remains
>> running with default users root and mobile, using the same password on
>> each and every device.

>
>it's only there if the user jailbreaks, installs ssh and leaves it
>running.


AND fails to set a password.

Imagine that, SSH left with unprotected root access on a default port
causes devices to get compromised!

In other news, a bank vault was cleaned out by thieves today, the bank
reports that they have no idea how it happened, but they intend to have
a lock installed on the vault's door immediately.

Reply With Quote
  #4 (permalink)  
Old 11-06-2009, 02:25 AM
Larry
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded

News <News@Group.Name> wrote in
news:nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.ne t:

> If you don't pay, it's fine by me. But remember, the way I got
> access to your iPhone can be used by thousands of others. And they can
> send text messages from your number (like I did..), use it to call (or
> record your calls), and actually whatever they want, even use it for
> their hacking activities! I can assure you, I have no intention of
> harming you or whatever, but, some hackers do! It's just my advise to
> secure your phone (: Have a nice day!"
>
>


This is all nonsense. Everyone, well, all the fanbois, know iPhone is
perfect in every way and can't get a virus or trojan at all, just like all
of Apple's products. It's immune! Only Micro$oft and Linux devices can
get attacked.

Just ignore this message and put your little blonde heads back in the
Koolaid. It's a fake! It must be! iPhones are perfect!

right?

--
Larry


Reply With Quote
  #5 (permalink)  
Old 11-06-2009, 02:45 AM
Malcolm
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded

On 2009-11-05 21:25:33 -0500, Larry <noone@home.com> said:

> News <News@Group.Name> wrote in
> news:nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.ne t:
>
>> If you don't pay, it's fine by me. But remember, the way I got
>> access to your iPhone can be used by thousands of others. And they can
>> send text messages from your number (like I did..), use it to call (or
>> record your calls), and actually whatever they want, even use it for
>> their hacking activities! I can assure you, I have no intention of
>> harming you or whatever, but, some hackers do! It's just my advise to
>> secure your phone (: Have a nice day!"
>>
>>

>
> This is all nonsense. Everyone, well, all the fanbois, know iPhone is
> perfect in every way and can't get a virus or trojan at all, just like all
> of Apple's products. It's immune! Only Micro$oft and Linux devices can
> get attacked.
>
> Just ignore this message and put your little blonde heads back in the
> Koolaid. It's a fake! It must be! iPhones are perfect!
>
> right?


Exactly. Those who though the iPhone perfect, didn't jailbreak them,
so were not affected.


Reply With Quote
  #6 (permalink)  
Old 11-06-2009, 02:37 PM
George Kerby
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded




On 11/5/09 8:25 PM, in article Xns9CBAD9F652BBAnoonehomecom@74.209.131.13,
"Larry" <noone@home.com> wrote:

> News <News@Group.Name> wrote in
> news:nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.ne t:
>
>> If you don't pay, it's fine by me. But remember, the way I got
>> access to your iPhone can be used by thousands of others. And they can
>> send text messages from your number (like I did..), use it to call (or
>> record your calls), and actually whatever they want, even use it for
>> their hacking activities! I can assure you, I have no intention of
>> harming you or whatever, but, some hackers do! It's just my advise to
>> secure your phone (: Have a nice day!"
>>
>>

>
> This is all nonsense. Everyone, well, all the fanbois, know iPhone is
> perfect in every way and can't get a virus or trojan at all, just like all
> of Apple's products. It's immune! Only Micro$oft and Linux devices can
> get attacked.
>

You DID get your flu shots, did you not?!?


Reply With Quote
  #7 (permalink)  
Old 11-06-2009, 03:30 PM
Larry
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded

George Kerby <ghost_topper@hotmail.com> wrote in
news:C71990DB.37EE2%ghost_topper@hotmail.com:

>
>
>
> On 11/5/09 8:25 PM, in article
> Xns9CBAD9F652BBAnoonehomecom@74.209.131.13, "Larry" <noone@home.com>
> wrote:
>
>> News <News@Group.Name> wrote in
>> news:nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.ne t:
>>
>>> If you don't pay, it's fine by me. But remember, the way I got
>>> access to your iPhone can be used by thousands of others. And they
>>> can send text messages from your number (like I did..), use it to
>>> call (or record your calls), and actually whatever they want, even
>>> use it for their hacking activities! I can assure you, I have no
>>> intention of harming you or whatever, but, some hackers do! It's
>>> just my advise to secure your phone (: Have a nice day!"
>>>
>>>

>>
>> This is all nonsense. Everyone, well, all the fanbois, know iPhone
>> is perfect in every way and can't get a virus or trojan at all, just
>> like all of Apple's products. It's immune! Only Micro$oft and Linux
>> devices can get attacked.
>>

> You DID get your flu shots, did you not?!?
>
>


Sorry, I don't "do" doctors. Haven't paid one in over 42 years!


--
Larry


Reply With Quote
  #8 (permalink)  
Old 11-06-2009, 06:23 PM
George Kerby
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded




On 11/6/09 9:30 AM, in article Xns9CBB6AF08BE30noonehomecom@74.209.131.13,
"Larry" <noone@home.com> wrote:

> George Kerby <ghost_topper@hotmail.com> wrote in
> news:C71990DB.37EE2%ghost_topper@hotmail.com:
>
>>
>>
>>
>> On 11/5/09 8:25 PM, in article
>> Xns9CBAD9F652BBAnoonehomecom@74.209.131.13, "Larry" <noone@home.com>
>> wrote:
>>
>>> News <News@Group.Name> wrote in
>>> news:nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.ne t:
>>>
>>>> If you don't pay, it's fine by me. But remember, the way I got
>>>> access to your iPhone can be used by thousands of others. And they
>>>> can send text messages from your number (like I did..), use it to
>>>> call (or record your calls), and actually whatever they want, even
>>>> use it for their hacking activities! I can assure you, I have no
>>>> intention of harming you or whatever, but, some hackers do! It's
>>>> just my advise to secure your phone (: Have a nice day!"
>>>>
>>>>
>>>
>>> This is all nonsense. Everyone, well, all the fanbois, know iPhone
>>> is perfect in every way and can't get a virus or trojan at all, just
>>> like all of Apple's products. It's immune! Only Micro$oft and Linux
>>> devices can get attacked.
>>>

>> You DID get your flu shots, did you not?!?
>>
>>

>
> Sorry, I don't "do" doctors. Haven't paid one in over 42 years!
>

But, the question is:

What do you pay the waitresses at the Waffle House to "do" them?


Reply With Quote
  #9 (permalink)  
Old 11-06-2009, 09:05 PM
News
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded

George Kerby wrote:
>
>
> On 11/6/09 9:30 AM, in article Xns9CBB6AF08BE30noonehomecom@74.209.131.13,
> "Larry" <noone@home.com> wrote:
>
>> George Kerby <ghost_topper@hotmail.com> wrote in
>> news:C71990DB.37EE2%ghost_topper@hotmail.com:
>>
>>>
>>>
>>> On 11/5/09 8:25 PM, in article
>>> Xns9CBAD9F652BBAnoonehomecom@74.209.131.13, "Larry" <noone@home.com>
>>> wrote:
>>>
>>>> News <News@Group.Name> wrote in
>>>> news:nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.ne t:
>>>>
>>>>> If you don't pay, it's fine by me. But remember, the way I got
>>>>> access to your iPhone can be used by thousands of others. And they
>>>>> can send text messages from your number (like I did..), use it to
>>>>> call (or record your calls), and actually whatever they want, even
>>>>> use it for their hacking activities! I can assure you, I have no
>>>>> intention of harming you or whatever, but, some hackers do! It's
>>>>> just my advise to secure your phone (: Have a nice day!"
>>>>>
>>>>>
>>>> This is all nonsense. Everyone, well, all the fanbois, know iPhone
>>>> is perfect in every way and can't get a virus or trojan at all, just
>>>> like all of Apple's products. It's immune! Only Micro$oft and Linux
>>>> devices can get attacked.
>>>>
>>> You DID get your flu shots, did you not?!?
>>>
>>>

>> Sorry, I don't "do" doctors. Haven't paid one in over 42 years!
>>

> But, the question is:
>
> What do you pay the waitresses at the Waffle House to "do" them?
>



....and to complete his thought, can George watch?

Reply With Quote
  #10 (permalink)  
Old 11-06-2009, 09:14 PM
John Doe
Guest
 
Posts: n/a
Default Are you Dutch? (was Re: jailbroken iPhones compromised, $5 ransom demanded)

News <News Group.Name> wrote:

> Yesterday, a "Your iPhone's been hacked because it's really
> insecure! Please visit doiop.com/iHacked and secure your phone
> right now!" message popped up on the screens of a large number
> of automatically exploited Dutch iPhone users, demanding $4.95
> for instructions on how to secure their iPhones and remove the
> message from appearing at startup.


No such message has appeared on my jailbroken iPhone.













>
> Through a combination of port scanning and OS fingerprinting of
> T-Mobile's 3G IP range, a Dutch teenager has for the first time
> automatically exploited a known security vulnerability introduced on
> jailbroken iPhones - the SSH daemon which unless modified remains
> running with default users root and mobile, using the same password on
> each and every device.
>
> Here's what he demanded, and how he changed his attitude following the
> suspension of his PayPal and the spamvertised URL:
>
> The now taken offline site was featuring the following message:
>
> "Dear iPhone user,
>
> Your iPhone is not secure. That's the reason your visiting this
> page, isn't it? Well you can pay me $4,95 at my paypal account
> PureInfinity92 mailinator.com, and I'll mail you very easy instructions
> on how to secure your iPhone. You can also contact me at
> PureInfinity92 gmail.com
>
> If you don't pay, it's fine by me. But remember, the way I got
> access to your iPhone can be used by thousands of others. And they can
> send text messages from your number (like I did..), use it to call (or
> record your calls), and actually whatever they want, even use it for
> their hacking activities! I can assure you, I have no intention of
> harming you or whatever, but, some hackers do! It's just my advise to
> secure your phone (: Have a nice day!"
>
> Following the media coverage, active discussions across popular Dutch IT
> forums, and the timely shut down of his PayPal account, the
> opportunistic and unethical pen-tester quickly changed his attitude and
> posted an apology followed by step-by-step guide on changing the default
> SSH password, which he was originally offering for a fee.
>
> Why is this automatic exploitation not a surprise?
>
> * Go through related posts: iBotnet: Researchers find signs of
> zombie Macs; iPhone's anti-phishing protection offers inconsistent
> results; Snow Leopard's malware protection only scans for two Trojans;
> New Mac OS X DNS changer spreads through social engineering
>
> The exploitability of the default SSH root login combined with the ease
> of OS fingerprinting an iPhone's, and the descriptive and well known 3G
> IP ranges for certain service providers, has already been discussed as
> an opportunity for automatically exploiting jailbroken iPhones running
> the SSH daemon with default passwords.
>
>
>
> http://blogs.zdnet.com/security/?p=4805&tag=nl.e550
>
>


--




















> Path: news.astraweb.com!border5.newsrouter.astraweb.com! news.glorb.com!news2.glorb.com!npeer03.iad.highwin ds-media.com!news.highwinds-media.com!feed-me.highwinds-media.com!Xl.tags.giganews.com!border1.nntp.dca.gi ganews.com!nntp.giganews.com!local2.nntp.dca.gigan ews.com!nntp.speakeasy.net!news.speakeasy.net.POST ED!not-for-mail
> NNTP-Posting-Date: Wed, 04 Nov 2009 13:56:36 -0600
> Date: Wed, 04 Nov 2009 14:56:38 -0500
> From: News <News Group.Name>
> Organization: <undiscernible>
> User-Agent: Thunderbird 2.0.0.23 (Windows/20090812)
> MIME-Version: 1.0
> Newsgroups: alt.cellular.attws,alt.cellular.cingular,misc.phon e.mobile.iphone
> Subject: jailbroken iPhones compromised, $5 ransom demanded
> Content-Type: text/plain; charset=windows-1252; format=flowed
> Content-Transfer-Encoding: 8bit
> Message-ID: <nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d speakeasy.net>
> Lines: 56
> X-Usenet-Provider: http://www.giganews.com
> NNTP-Posting-Host: 216.254.112.65
> X-Trace: sv3-r6yk7s+IFgXGwOdVSgAl6OSxN9UR2yP3Mi3JiV60yjwwcR1jc4 ttbqY/255DHTbVJCtWtqmrREbaAUI!agX4r5H1+LvuF+fu63reMg+vZh np/Nto4JD9Byr6GTcIjdeZM3jw0vYNhr1R5J+ZMb+d3RDsx+Nm!i4 SP8rlre5HX1QG42gGJwezdwvaekzC5
> X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
> X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
> X-Postfilter: 1.3.40
>


Reply With Quote
  #11 (permalink)  
Old 11-07-2009, 01:27 AM
George Kerby
Guest
 
Posts: n/a
Default Re: jailbroken iPhones compromised, $5 ransom demanded




On 11/6/09 3:05 PM, in article
3fGdnXtnXJ09EmnXnZ2dnUVZ_s1i4p2d@speakeasy.net, "News" <News@Group.Name>
wrote:

> George Kerby wrote:
>>
>>
>> On 11/6/09 9:30 AM, in article Xns9CBB6AF08BE30noonehomecom@74.209.131.13,
>> "Larry" <noone@home.com> wrote:
>>
>>> George Kerby <ghost_topper@hotmail.com> wrote in
>>> news:C71990DB.37EE2%ghost_topper@hotmail.com:
>>>
>>>>
>>>>
>>>> On 11/5/09 8:25 PM, in article
>>>> Xns9CBAD9F652BBAnoonehomecom@74.209.131.13, "Larry" <noone@home.com>
>>>> wrote:
>>>>
>>>>> News <News@Group.Name> wrote in
>>>>> news:nMGdnYwwFNrpQWzXnZ2dnUVZ_jJi4p2d@speakeasy.ne t:
>>>>>
>>>>>> If you don't pay, it's fine by me. But remember, the way I got
>>>>>> access to your iPhone can be used by thousands of others. And they
>>>>>> can send text messages from your number (like I did..), use it to
>>>>>> call (or record your calls), and actually whatever they want, even
>>>>>> use it for their hacking activities! I can assure you, I have no
>>>>>> intention of harming you or whatever, but, some hackers do! It's
>>>>>> just my advise to secure your phone (: Have a nice day!"
>>>>>>
>>>>>>
>>>>> This is all nonsense. Everyone, well, all the fanbois, know iPhone
>>>>> is perfect in every way and can't get a virus or trojan at all, just
>>>>> like all of Apple's products. It's immune! Only Micro$oft and Linux
>>>>> devices can get attacked.
>>>>>
>>>> You DID get your flu shots, did you not?!?
>>>>
>>>>
>>> Sorry, I don't "do" doctors. Haven't paid one in over 42 years!
>>>

>> But, the question is:
>>
>> What do you pay the waitresses at the Waffle House to "do" them?
>>

>
>
> ...and to complete his thought, can George watch?
>

And the Prodigal Son come to the aid of daddy...


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Apple building 5 to 6 million new iPhones David Moyer alt.cellular.nokia 18 11-17-2009 11:02 AM
Apple building 5 to 6 million new iPhones David Moyer alt.cellular.attws 11 10-30-2009 02:59 PM
'Exploding' iPhones investigated News alt.internet.wireless 11 08-31-2009 12:21 PM
'Exploding' iPhones investigated News alt.cellular.attws 11 08-31-2009 12:21 PM
'Exploding' iPhones investigated News alt.cellular.cingular 11 08-31-2009 12:21 PM


All times are GMT. The time now is 11:49 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45