TECHZIE.BLOGSPOT.COM

Your TECH GADGET GURU



Apple’s newest iPhone devices have been hacked with a zero-day font vulnerability in the latest iteration of the JailbreakMe.com project.
The JailbreakMe.com exploit allows the automated jailbreaking of iPhone/iPad/iPod Touch devices from a specially created Web site.
It is essentially a drive-by download attack that exploits the way Apple’s mobile operating system processes certain fonts.  Technical details of the vulnerability are not yet know.
It is likely being combined with a second privilege escalation bug to escape the iOS sandbox, much like the first version of the jailbreakexploit.   According to “Comex,” the hacker behind the site, the exploit defeats ASLR (Address Space Layout Randomization), a key anti-exploit mechanism.
Along with the jailbreak exploit, “Comex” also released a patch for the main vulnerability.
“Due to the nature of iOS, this patch can only be installed on a jailbroken device.   Until Apple releases an update, jailbreaking will ironically be the best way to remain secure,” he explained.
On the issue of releasing exploit for zero-day flaws, here’s a note from the site’s FAQ:
I did not create the vulnerabilities, only discover them.  Releasing an exploit demonstrates the flaw, making it easier for others to use it for malice, but they have long been present and exploitable.  Although releasing a jailbreak is certainly not the usual way to report a vulnerability, it still has the effect of making iOS more secure in the long run.



Apple is rushing to fix a security hole found in its iOS mobile software following a stern warning from a German IT security department.
The Associated Press is reporting that Germany’s Federal Office for Information Security found that flaw stems from clicking on an infected PDF file, which “is sufficient to infect the mobile device with malware without the user’s knowledge.” That opens the door for the user’s passwords, emails, text messages, emails and almost anything else stored on the iPhone, iPad or iPod touch in question.
Apple’s response:
Apple Inc. spokeswoman Bethan Lloyd said Thursday the company is “aware of this reported issue and developing a fix that will be available to customers in an upcoming software update.”
Apparently this is damaging on “several versions” of iOS, but not all. The Guardian has cited specifics:
The problem may occur on iPhone 3GS, iPhone 4, iPad, iPad 2 and the iPod Touch with software versions including iOS 4.3.3, and it “cannot be excluded” that other iOS versions – including the iOS 5 due in September – have the same weakness, said the Bonn-based federal bureau.
The security gap was originally uncovered by a group of hackers trying to jailbreak an iPhone. Some third-parties who produce jailbreaking software have already posted patches. However, it appears that this problem, related to PDF files, is different from the recent zero-day font vulnerability found in JailbreakMe.com. That doesn’t necessarily mean they are unrelated, but just different.
Adrian Kingsley-Hughes reports, there is a debate over whether or not jailbroken iPhones and other iOS devices are actually safer or not. But a patch from Apple for this specific problem is still needed immediately.
All of this follows the recent discovery that Apple could also be a target of the AntiSec campaign, adding fuel to the theory that the Cupertino, Calif.-based company could be the “Holy Grail” for hackers.



Apple is rushing to fix a security hole found in its iOS mobile software following a stern warning from a German IT security department.
The Associated Press is reporting that Germany’s Federal Office for Information Security found that flaw stems from clicking on an infected PDF file, which “is sufficient to infect the mobile device with malware without the user’s knowledge.” That opens the door for the user’s passwords, emails, text messages, emails and almost anything else stored on the iPhone, iPad or iPod touch in question.
Apple’s response:
Apple Inc. spokeswoman Bethan Lloyd said Thursday the company is “aware of this reported issue and developing a fix that will be available to customers in an upcoming software update.”
Apparently this is damaging on “several versions” of iOS, but not all. The Guardian has cited specifics:
The problem may occur on iPhone 3GS, iPhone 4, iPad, iPad 2 and the iPod Touch with software versions including iOS 4.3.3, and it “cannot be excluded” that other iOS versions – including the iOS 5 due in September – have the same weakness, said the Bonn-based federal bureau.
The security gap was originally uncovered by a group of hackers trying to jailbreak an iPhone. Some third-parties who produce jailbreaking software have already posted patches. However, it appears that this problem, related to PDF files, is different from the recent zero-day font vulnerability found in JailbreakMe.com. That doesn’t necessarily mean they are unrelated, but just different.
As ZDNet’s Adrian Kingsley-Hughes reports, there is a debate over whether or not jailbroken iPhones and other iOS devices are actually safer or not. But a patch from Apple for this specific problem is still needed immediately.
All of this follows the recent discovery that Apple could also be a target of the AntiSec campaign, adding fuel to the theory that the Cupertino, Calif.-based company could be the “Holy Grail” for hackers.


fundamentally flawed "Find My iPhone"
Here’s the flaw, and it’s stunningly simple.
Let’s say I’m in a bar and I take a call or answer a txt or email on my iPhone, but then I get distracted and leave it somewhere (and don’t say it can’t happen …). Now imagine that it’s a bar in a shady part of town and my iPhone is found by some miscreant before the lock screen kicks in (which I have set to 5 minutes, because anything shorter than that gets tedious). Now here’s the problem … why is this person now able to go into Settings > Location Services and disable MY ability to find MYiPhone without having to enter a password or anything? What’s worse, doing this simple operating INFORMS SAID BAD GUY THAT IT DISABLES MY ABILITY TO FIND MY PHONE!
This is crazy. Disabling Find My iPhone should, at the very least, require the password to be reentered, and better still require logging into MobileMe (or iCloud or whatever it’s going to end up being called). I know that if your hardware falls into the bad guy’s (or gal’s) hands anything is possible, but I don’t expect hiding MY iPhone from ME to be this darn simple.
This is dead easy to fix. To be honest, it’s such a dumb design that I have no idea why it’s not already been fixed.
Hope Apple Hears This!!!!!!!!..


WORKAROUND FIX : by Zdnet
Even if you leave the phone open and not at lock screen you can prevent someone turning off Find My iPhone.
Go to Settings --> General --> Restrictions
You'll be prompted to put in a lock code.
Now select "Location Services".
So now anyone that tries to change settings related to Location Services will need to enter the passcode, even if the phone was open and in apps or whatever.
It works, but I really think that this setting should be default, and perhaps rely on using your MobileMe password for authentication rather than the iPhone passcode



A host of new features gleaned from the iPhone OS 4 SDK, including iChat, secondary camera



In the short span of time since the iPhone OS 4 SDK was released yesterday, several possible features that the iPhone 4 (which is also called the iPhone 4G or iPhone 4th Generation device) might have are now apparent:

1) iChatAgent
2) New MobileMe support
3) IMCore.framework and IMAVCore.framework


iChatAgent - a background process that is already used on the Mac OSX – shows certain APIs and lines of code that will possibly allow for:
i) Bundled Instant Messaging client - iChat
ii) Forward-facing video/web camera

MobileMe - an email/calendar/contacts synchronisation tool that is already available for the iPhone, iPad and Mac – reveals new lines of code that will possible allow for:
i) Note Syncing
ii) Instant messaging Syncing

IMCore.framework and IMAVCore.framework - two coding frameworks that hint at:
i) Forward-facing web camera and back-facing camera support
ii) Screen sharing

So, to summarise, the iPhone 4G device will probably have the following features: bundles Instant Messaging client – iChat, a forward and back-facing camera, note syncing, and screen sharing. The back-facing camera of the iPhone 4G device will purportedly be a 5MP camera with LED flash




Here are also some features that developers think will be available on the iPhone OS 4 and its fully-supported devices: note syncing, 5x digital zoom support, Tap to Focus Video, MMS message character count display, IPv6 support, automatic downscaling of heavy mail attachments, live Web search suggestions in Safari, and playlist creation without iTunes.

Place an Ad