TECHZIE.BLOGSPOT.COM

Your TECH GADGET GURU



Apple’s newest iPhone devices have been hacked with a zero-day font vulnerability in the latest iteration of the JailbreakMe.com project.
The JailbreakMe.com exploit allows the automated jailbreaking of iPhone/iPad/iPod Touch devices from a specially created Web site.
It is essentially a drive-by download attack that exploits the way Apple’s mobile operating system processes certain fonts.  Technical details of the vulnerability are not yet know.
It is likely being combined with a second privilege escalation bug to escape the iOS sandbox, much like the first version of the jailbreakexploit.   According to “Comex,” the hacker behind the site, the exploit defeats ASLR (Address Space Layout Randomization), a key anti-exploit mechanism.
Along with the jailbreak exploit, “Comex” also released a patch for the main vulnerability.
“Due to the nature of iOS, this patch can only be installed on a jailbroken device.   Until Apple releases an update, jailbreaking will ironically be the best way to remain secure,” he explained.
On the issue of releasing exploit for zero-day flaws, here’s a note from the site’s FAQ:
I did not create the vulnerabilities, only discover them.  Releasing an exploit demonstrates the flaw, making it easier for others to use it for malice, but they have long been present and exploitable.  Although releasing a jailbreak is certainly not the usual way to report a vulnerability, it still has the effect of making iOS more secure in the long run.



Apple is rushing to fix a security hole found in its iOS mobile software following a stern warning from a German IT security department.
The Associated Press is reporting that Germany’s Federal Office for Information Security found that flaw stems from clicking on an infected PDF file, which “is sufficient to infect the mobile device with malware without the user’s knowledge.” That opens the door for the user’s passwords, emails, text messages, emails and almost anything else stored on the iPhone, iPad or iPod touch in question.
Apple’s response:
Apple Inc. spokeswoman Bethan Lloyd said Thursday the company is “aware of this reported issue and developing a fix that will be available to customers in an upcoming software update.”
Apparently this is damaging on “several versions” of iOS, but not all. The Guardian has cited specifics:
The problem may occur on iPhone 3GS, iPhone 4, iPad, iPad 2 and the iPod Touch with software versions including iOS 4.3.3, and it “cannot be excluded” that other iOS versions – including the iOS 5 due in September – have the same weakness, said the Bonn-based federal bureau.
The security gap was originally uncovered by a group of hackers trying to jailbreak an iPhone. Some third-parties who produce jailbreaking software have already posted patches. However, it appears that this problem, related to PDF files, is different from the recent zero-day font vulnerability found in JailbreakMe.com. That doesn’t necessarily mean they are unrelated, but just different.
Adrian Kingsley-Hughes reports, there is a debate over whether or not jailbroken iPhones and other iOS devices are actually safer or not. But a patch from Apple for this specific problem is still needed immediately.
All of this follows the recent discovery that Apple could also be a target of the AntiSec campaign, adding fuel to the theory that the Cupertino, Calif.-based company could be the “Holy Grail” for hackers.



Apple is rushing to fix a security hole found in its iOS mobile software following a stern warning from a German IT security department.
The Associated Press is reporting that Germany’s Federal Office for Information Security found that flaw stems from clicking on an infected PDF file, which “is sufficient to infect the mobile device with malware without the user’s knowledge.” That opens the door for the user’s passwords, emails, text messages, emails and almost anything else stored on the iPhone, iPad or iPod touch in question.
Apple’s response:
Apple Inc. spokeswoman Bethan Lloyd said Thursday the company is “aware of this reported issue and developing a fix that will be available to customers in an upcoming software update.”
Apparently this is damaging on “several versions” of iOS, but not all. The Guardian has cited specifics:
The problem may occur on iPhone 3GS, iPhone 4, iPad, iPad 2 and the iPod Touch with software versions including iOS 4.3.3, and it “cannot be excluded” that other iOS versions – including the iOS 5 due in September – have the same weakness, said the Bonn-based federal bureau.
The security gap was originally uncovered by a group of hackers trying to jailbreak an iPhone. Some third-parties who produce jailbreaking software have already posted patches. However, it appears that this problem, related to PDF files, is different from the recent zero-day font vulnerability found in JailbreakMe.com. That doesn’t necessarily mean they are unrelated, but just different.
As ZDNet’s Adrian Kingsley-Hughes reports, there is a debate over whether or not jailbroken iPhones and other iOS devices are actually safer or not. But a patch from Apple for this specific problem is still needed immediately.
All of this follows the recent discovery that Apple could also be a target of the AntiSec campaign, adding fuel to the theory that the Cupertino, Calif.-based company could be the “Holy Grail” for hackers.


fundamentally flawed "Find My iPhone"
Here’s the flaw, and it’s stunningly simple.
Let’s say I’m in a bar and I take a call or answer a txt or email on my iPhone, but then I get distracted and leave it somewhere (and don’t say it can’t happen …). Now imagine that it’s a bar in a shady part of town and my iPhone is found by some miscreant before the lock screen kicks in (which I have set to 5 minutes, because anything shorter than that gets tedious). Now here’s the problem … why is this person now able to go into Settings > Location Services and disable MY ability to find MYiPhone without having to enter a password or anything? What’s worse, doing this simple operating INFORMS SAID BAD GUY THAT IT DISABLES MY ABILITY TO FIND MY PHONE!
This is crazy. Disabling Find My iPhone should, at the very least, require the password to be reentered, and better still require logging into MobileMe (or iCloud or whatever it’s going to end up being called). I know that if your hardware falls into the bad guy’s (or gal’s) hands anything is possible, but I don’t expect hiding MY iPhone from ME to be this darn simple.
This is dead easy to fix. To be honest, it’s such a dumb design that I have no idea why it’s not already been fixed.
Hope Apple Hears This!!!!!!!!..


WORKAROUND FIX : by Zdnet
Even if you leave the phone open and not at lock screen you can prevent someone turning off Find My iPhone.
Go to Settings --> General --> Restrictions
You'll be prompted to put in a lock code.
Now select "Location Services".
So now anyone that tries to change settings related to Location Services will need to enter the passcode, even if the phone was open and in apps or whatever.
It works, but I really think that this setting should be default, and perhaps rely on using your MobileMe password for authentication rather than the iPhone passcode

While it is evident the iPhone 5, expected earlier this year, has been delayed, new reports say the device is in its final testing stages, and is even being carried around by a few Apple and carrier officials. For now, it seems a September launch is on the cards.


In the meanwhile, there are reports of the iPhone 4 becoming available in its unlocked form in the U.S., at Apple Stores, something that should interest more than just U.S. citizens. Both 16GB and 32GB models should be available in black and white.Other reports indicate the iPhone 5 will be retaining the same 5MP camera sensor as the iPhone 4, despite rumours of an 8MP offering instead.

 

The iPhone 4G seems to have been spotted in the wild, and as far as knock-offs go, this one looks quite authentic, with several parties finding the evidence credible and going so far as to say “it is incredibly likely” the new iPhone will look like the device in the pictures. The device seems remarkably similar to the phone in the images posted on February 20th by a Chinese Tweep, who claimed his photos were taken at a Chinese “testbed” for Apple
. Found in an iPhone 3G case in a San Jose watering hole, the device has been observed to have a front-facing camera, a higher-res back-facing camera with flash, an 80GB hard drive, a 960x640 resolution screen, MicroSIM support, a “radio transparent” ceramic enclosure, and a “decidely new OS” which apparently does not boot anymore. Some seem to think this is device is still on a testbed frame, and that the final-release device will not have such visible and “un-Apple-like" seams on the side. The new owner is looking to sell the device. Find some more pictures in the gallery below.

Images courtesy: Engadget and Weiphone
sources : digit






Place an Ad