Georgia Tech trio to reveal iOS test exploit at Black Hat

June 4, 2013 by Nancy Owano, Phys.org weblog
Georgia Tech trio to reveal iOS test exploit at Black Hat

(Phys.org) —Apple's iOS devices such as smartphones are considered relatively secure, so when an Apple customer pays more for an Apple device with iOS there is that reassuring feeling of confidence that the investment is worth it for security sake. Next month at the Black Hat conference, however, three security researchers from Georgia Tech will show that using chargers to power up iOS devices may be a direct path to insecurity. The three, Billy Lau, Yeongjin Jang, and Chengyu Song, will discuss how their proof of concept charger can hack Apple devices easily, in under a minute—and, we might add, hack devices running the latest version of Apple iOS.

They pushed software onto an iOS device using a charger. They will provide more detail at the Black Hat event conference which takes place in Las Vegas from July 27 to August 1.

Technology-watching sites have already, though, posted the web site's overview description of the upcoming talk. The one word that stands out in the summary is "alarming." They wrote that "Apple iOS devices are considered by many to be more secure than other mobile offerings. In evaluating this belief, we investigated the extent to which were considered when performing everyday activities such as charging a device."

That is when the "A" word came in. They said, "The results were alarming: despite the of defense mechanisms in iOS, we successfully injected arbitrary software into current-generation Apple devices running the latest operating system (OS) software."

Their investigation did not need a jailbroken device and it did not need any user interaction.

The charger was built around a single-board computer, the open source BeagleBoard. "We built a malicious charger, called Mactans, using a BeagleBoard," they wrote. They chose BeagleBoard to show how easy it was to construct "malicious" USB chargers. BeagleBoard in a single small package can work with the functionality of a laptop. Its roots are in a group of people including several employees of Texas Instruments who provided a low-cost, fan-less single-board computers based on low-power Texas Instruments processors featuring the ARM Cortex-A series core.

The three pose the question that if they were able to build Mactans in a limited amount of time and with a small budget, what could motivated, better-funded people with bad intentions accomplish?

The authors said they can recommend ways in which users can protect themselves and can suggest security features that Apple can put in place to make attacks by way of chargers more difficult to accomplish.

Andy Greenberg of Forbes spoke to one of the Georgia Tech team, Yeongjin Jang, who said that had been contacted about the exploit.

Explore further: iOS 6.1: Apple updates software for iPhone, iPad

More information: www.forbes.com/sites/andygreen … a-malicious-charger/

Related Stories

Apple granted patent on new augmented reality technology

March 20, 2013

(Phys.org) —Apple Inc. has been granted a patent for an application filed with the U.S. Patent Office in 2010 for "Synchronized, interactive augmented reality displays for multifunction devices." The patent filing describes ...

iOS 5 jailbroken before its release

June 7, 2011

(PhysOrg.com) -- The beta version of iOS has already been jailbroken, which is interesting when you consider that the iOS 5 was only announced 24 hours prior to the jailbreak, at the Apple keynote address at WWDC. The presentation, ...

Recommended for you

Cryptocurrency rivals snap at Bitcoin's heels

January 14, 2018

Bitcoin may be the most famous cryptocurrency but, despite a dizzying rise, it's not the most lucrative one and far from alone in a universe that counts 1,400 rivals, and counting.

Top takeaways from Consumers Electronics Show

January 13, 2018

The 2018 Consumer Electronics Show, which concluded Friday in Las Vegas, drew some 4,000 exhibitors from dozens of countries and more than 170,000 attendees, showcased some of the latest from the technology world.

Finnish firm detects new Intel security flaw

January 12, 2018

A new security flaw has been found in Intel hardware which could enable hackers to access corporate laptops remotely, Finnish cybersecurity specialist F-Secure said on Friday.

0 comments

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.