Modified iPhones Are Compromised By New Worm

Nov 25, 2009 by John Messina weblog

(PhysOrg.com) -- Several research security firms have reported a new worm attack against jail broken iPhones, dubbed "Ikee.B or "Duh", this worm searches for personal and banking information.

The worm spreads by using the default password for applications that can be installed on jail broken . Once the iPhone is infected, the worm grabs text messages and searches for banking authorization codes used for at least one bank. The codes are then sent to a central server located in Lithuania.

With cybercriminals becoming savvier, it's only a matter of time before they find ways to infect iPhones that are not jail broken as well as other smartphone devices. Some researchers confirm that worm attacks against are evolving and it's becoming more common for cybercriminals to target personal and financial information stored on portable devices.

Researchers have confirmed that even Bluetooth connections between portable devices can be compromised with malicious code. A Bluetooth outbreak can be easily carried out in shopping malls, airports, or libraries, anywhere a cybercriminal may find potential victims.

The new worm easily infects jail broken iPhones by a weakness introduced into an application called OpenSSH. The application uses the default password 'alpine' that the worm uses to connect to the iPhone remotely. Since there is no shell code and no buffer overflow compromising the iPhone, writing code is fairly simple.

The attacks that have target iPhones this past month, focused on jail broken phones only. In the process of jail breaking a phone, the code that prevents users from loading any application they want is removed, thereby also removing most of the security that prevents from running on the smartphone.

With the evolution of hacking into portable devices growing, it's only a matter of time before phones employing Google's , and everything else will be compromised in one way or another.

More information: iPhone worm Rickrolls Australia

© 2009 PhysOrg.com

Explore further: Gift Guide: Strong photo, video gear options

add to favorites email to friend print save as pdf

Related Stories

iPhone worm Rickrolls Australia

Nov 10, 2009

(PhysOrg.com) -- iPhone users in Australia have been hit during the last few days with a worm called "ikee". The worm replaces the default wallpaper with a difficult to remove picture of British singer Rick ...

The malware attack against mobile phones is mounting

Dec 23, 2004

The security challenges in the mobile environment are similar to the problems we have encountered in the PC world. Open platforms are becoming popular in smartphones, for example the Symbian operating system is used in more ...

Wikipedia launches iPhone application

Aug 20, 2009

Wikipedia said it has released an iPhone application as part of a drive to open the pages of its revered online encyclopedia to the booming ranks of smart phone users.

Skype comes to iPhones on Tuesday

Mar 30, 2009

Skype has confirmed that a free software application enabling iPhone owners to use its Internet telephone service will be available in Apple's online App Store beginning Tuesday.

Recommended for you

Ear-check via phone can ease path to diagnosis

Dec 18, 2014

Ear infections are common in babies and young children. That it is a frequent reason for young children's visit to doctors comes as no consolation for the parents of babies tugging at their ears and crying ...

Gift Guide: Home products come with connectivity

Dec 18, 2014

Do you really need an app to tell you to brush and floss? It seems every household appliance is getting some smarts these days, meaning some connection to a phone app and the broader Internet. But then what?

BlackBerry launches Classic in last-ditch effort

Dec 17, 2014

(AP)—BlackBerry is returning to its roots with a new phone that features a traditional keyboard at a time when rival Apple and Android phones—and most smartphone customers—have embraced touch screens.

Tag Heuer changes tune, now looking at smartwatches

Dec 16, 2014

Barely a few months after dismissing Apple's smartwatch, the new chief executive of luxury Swiss watchmaker Tag Heuer conceded Tuesday that such a hi-tech gadget might after all have a place in his firm's ...

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

Inco
5 / 5 (1) Nov 25, 2009
Its hardly OpenSSH that have a weakness. Looks more like installation bundle takes a few shortcuts.
Regarding Android, yes it is likely it will get worms/viruses in the future though not the same quantity of them.
The reasons for rooting an Android phone is quite small. And applications don't run with full privileges. For iPhone, metasploit.com have for a long time pointed out weaknesses in the security model of the phone. Its security by only allowing Apple to install programs, and just hope those programs don't have flaws.

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.