Download the Tom's Hardware App from the App Store
The reference for current tech news
Yes No
Ads

iPhone Hacked in 20 Seconds at Pwn2Own

by - source: Tom's Hardware US

Two European researchers have successfully hacked a fully patched iPhone and exfiltrated the device's entire SMS database in 20 seconds.

ZDNet reports that Vincenzo Iozzo and Ralf Philipp Weinmann exploited a previously unknown vulnerability and had the target iPhone visit a Web Site containing malicious code. It took Weinmann, a 32-year-old from the University of Luxembourg, collaborated and Iozzo, a 22-year-old Italian researcher from Zynamic, to find the vulnerability and write the exploit. Once they put everything in place, the hack took just 20 seconds.

"Basically, every page that the user visits on our [rigged] site will grab the SMS database and upload it to a server we control," Weinmann said, according to ZDNet.

Weinmann went on to say that in addition taking the SMS database, the exploit could have taken the phone's contact list (for both phone and email), photographs and iTunes files.

ZDNet cites Weinmann as saying there’s a non-root user called ‘mobile’ with certain user privileges in the iPhone Sandbox.  "With this exploit, I can do anything that ‘mobile’ can do," he said.

Weinmann and Iozzo won $15,000 and got to keep the iPhone.

Share:
29
Comments
X
Submit

Comments
Add your comment
amabhy 03/25/2010 7:35 PM
Hide
-20+

Give people money and prizes and anything can be done.

dman3k 03/25/2010 7:36 PM
Hide
-20+

Apple and security is like Jello and concrete.

Security by obscurity.

jhansonxi 03/25/2010 7:38 PM
Show
restatement3dofted 03/25/2010 7:46 PM
Hide
-20+

jhansonxi :
Windows and security is like a fart and concrete.



Microsoft has absolutely nothing to do with people successfully manipulating an iPhone - it is completely irrelevant. Go troll elsewhere.

Anonymous 03/25/2010 7:48 PM
Hide
-10+

all OS has security issues...

rtfm 03/25/2010 7:52 PM
Hide
-6+

what no link? :p

Jerky_san 03/25/2010 7:54 PM
Hide
-20+

mikewong27 :
all OS has security issues...



Its just as he says.. every OS is made by man.. thus another man can find a flaw and exploit it. Thats just life.. But just like everything else if you build it well enough the cracks will be much harder to notice..

Anonymous 03/25/2010 7:55 PM
Hide
-8+

Misleading title at best. "Once they put everything in place, the hack took just 20 seconds." Like saying, once I built the car, it took 5 seconds for the engine to start when I turned the key. Ah, yeah, lol.

boxa786 03/25/2010 7:55 PM
Hide
-20+

I can understand the apple comment, but why the hatred for windows on an apple article? Dman made no reference in comparing apple vs windows, ROFL, apple fan ftl?

Anonymous 03/25/2010 7:58 PM
Show
ikefu 03/25/2010 8:20 PM
Hide
-4+

It makes you wonder what kind of others things we could get accomplished if we would start offering cash prizes for other technological feats.

eyemaster 03/25/2010 8:36 PM
Hide
-4+

Please fix the first paragraph, I can't really read the structure...

Anonymous 03/25/2010 8:37 PM
Hide
-6+

jkljlk

there are some hack that need brute force computational power, this one is a simple drive by ordeal.... imagine visiting a website on your iPhone and having the contents copied

JohnnyLucky 03/25/2010 8:48 PM
Hide
-4+

Another example demomnstrating there is not privacy on the Internet.

kingssman 03/25/2010 9:20 PM
Hide
-0+

step one, go to infected unsecured dangerous website
step two, click yes to allow ((((hacking of my device)))
step three, claim ZOMG!! I've Been HACKED!!

soldier37 03/25/2010 9:49 PM
Show
jhansonxi 03/25/2010 11:37 PM
Hide
-9+

soldier37 :
Now if they could just hack and redo Obama Care and reverse it Life would be good again!



Please limit yourself to tech-related trolling while on Tom's.

SAL-e 03/26/2010 12:00 PM
Hide
-1+

Wait a minute. Apples lawyers told us that only reason to lock the phone and jail-breaking is illegal was for security reasons.
/sarcasm
So why the iPhone is locked again?!

hoof_hearted 03/26/2010 12:04 PM
Hide
-0+

alpine dottie

eddieroolz 03/26/2010 1:19 AM
Hide
-0+

They get to keep the iPhone, but something tells me that they'll be selling it for some change.

orionantares 03/26/2010 1:31 AM
Hide
-3+

Was this a weakness in the iPhone OS or was this a weakness in it's Safari browser?

tayb 03/26/2010 1:34 AM
Hide
-1+

Apple,

My iPhone is not secure. There is an application that is being exploited.

The application is Safari. Please remove from App Store.

Thanks,

iPhone User

otacon72 03/26/2010 2:20 AM
Show
doc70 03/26/2010 4:15 AM
Hide
-0+

15 sec was the drum roll...
5 sec the exploit


and why keep the iPhone? After proving it's weakness, no piont.

welshmousepk 03/26/2010 4:30 AM
Hide
-5+

' It took Weinmann, a 32-year-old from the University of Luxembourg, collaborated and Iozzo, a 22-year-old Italian researcher from Zynamic, to find the vulnerability and write the exploit. '

is it just me, or does that make no sense?

Anonymous 03/26/2010 6:06 AM
Hide
-0+

That's takes a great deal of talent. God would hate me if I learned to hack an iPhone.

ossie 03/26/2010 6:37 AM
Hide
-4+

20 seconds is already too much for a pre-scripted attack - weak network signal, slow connection, or was the carrier experiencing some traffic jams?
The moral of the story is simple: today's browser architectures, with all the extensions, and "features not bugs" baggage for the eye-candy factor, are fundamentally flawed.

welshmousepk :
' It took Weinmann, a 32-year-old from the University of Luxembourg, collaborated and Iozzo, a 22-year-old Italian researcher from Zynamic, to find the vulnerability and write the exploit. 'is it just me, or does that make no sense?


It doesn't have to... modern "journalism" in not anymore about respecting grammatical or syntactical rules, factuality, ethics, or even common sense... it's more about hype, ratings, and filling the quota. You gotta love those word processors, most offer a word count feature - what simpler metric for quickly quantifying the intellectual effort can you ask for, and get?

r3t4rd 03/26/2010 8:41 AM
Hide
--1+

soldier37 :
Now if they could just hack and redo Obama Care and reverse it Life would be good again!



Amen!!...at least Obama uses a Blackberry.

shahriarhkhan 04/21/2010 10:44 PM
Hide
-0+

Every one having the same problem regarding hiding or locking text messages on iPhones. Recently I downloaded a program from http://faketexts.com/ and it hides the iPhone SMS button and replaces it with a fake one that you can edit. Basically it doesn’t show all the girls I am talking to.

Ads

Best offers

Newsletters


OK
Ads