On BNET: Apple's insanely great marketing
BNET Business Network:
BNET
TechRepublic
ZDNet

By Eliinor Mills
Posted on ZDNet News: Jul 30, 2009 4:58:50 AM

Researchers have discovered a way to take complete control over an iPhone simply by sending special SMS messages.

An attacker could exploit the hole to make calls, steal data, send text messages, and do more or less anything a person can do on their iPhone, researchers Charlie Miller and Collin Mulliner claimed at the Black Hat security conference in Las Vegas on Wednesday.

The attack is enabled by a serious memory corruption bug in the way the iPhone handles SMS messages, said Miller, a senior security researcher at Independent Security Evaluators. There is no patch, despite the fact Apple was notified of the problem about six weeks ago, he said.

The attack is similar to an SMS attack demonstration CNET News.com wrote about in April in which mobile security firm Trust Digital was able to send an SMS to a phone that opened up a web browser and directed the phone to a malicious website where malware could be downloaded.

In the more recent research, Android-based phones were found to be similarly susceptible to an SMS attack. However, while an attacker could temporarily knock the phone off the cell network, they could not take control, according to Mulliner, who is getting his PhD at the Technical University of Berlin. Google patched the hole last week within a day or two of being notified of the problem, he said.

Meanwhile, a bug in the code written by HTC that controls the user interface on Windows Mobile devices could also be exploited via the SMS messages to create a situation where there are no buttons to push, so the phone cannot be used, said Miller.

For the attack to work, an attacker must send hundreds of SMS control messages, which are different from regular SMS messages, according to Miller. Only the initial SMS may be seen, he said.

The researchers will demonstrate the attack on an Android phone and an iPhone during their presentation on Thursday.

Previous iPhone attacks required an attacker to lure the iPhone user to visit a malicious website or open a malicious file, but this attack requires no effort on the part of the user and requires only that an attacker have the victim's phone number, Miller said.

Once inside a victim's phone, the attacker could then send an SMS to anyone in the victim's address book and spread the attack from phone to phone, he said.

Previously, Miller discovered a hole in the mobile version of Safari shortly after the iPhone was launched in 2007, and earlier this year he won a contest at CanSecWest by exploiting a hole in Safari.


Researchers Collin Mulliner and Charlie Miller plan to demo the attack on an Android phone and an iPhone during their presentation on Thursday.

This article was originally posted on CNET News.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 79 Talkback(s)
Proof Is In The Pudding
I guess we will know when they demonstrate the hack, won't we? (Read the rest)
Posted by: brianpeterson@... Posted on: 08/06/09 You are currently: a Guest | | Terms of Use
I was wondering  jdbukis@... | 07/30/09
really  nessrapp | 07/30/09
Awww... but iPhone is sooooo perfect  trance2tec | 07/30/09
Its SMS jackazs - not iPhone or Apple  VoiceOfLogic | 08/01/09
It is Apple  kguzzi@... | 08/02/09
and Microsoft also  athynz | 08/06/09
Duh!!!!!!  brianpeterson@... | 08/06/09
Dude  athynz | 08/06/09
RE: Researchers take control of iPhone via SMS  Loverock Davidson | 07/30/09
Marketshare or low hanging fruit?  NonZealot | 07/30/09
Other phones have similar bugs  Stuka | 07/30/09
ROFL ROFL ROFL!!!  NonZealot | 07/30/09
And to think....  eMJayy | 07/30/09
Never was an Apple fan but.....  storm14k | 07/30/09
This highlights something important  NonZealot | 07/30/09
WM doesn't have the same bug.  trance2tec | 07/30/09
One ROFL is more than enough  punkpussy | 07/30/09
Neither. Its SMS  VoiceOfLogic | 08/01/09
So THIS is how iPhones can "destroy cell towers"!  kd5auq | 07/30/09
RE: Researchers take control of iPhone via SMS  vermonter | 07/30/09
What should an iPhone owner do?  NonZealot | 07/30/09
Switch???  i8thecat | 07/30/09
Get real...  storm14k | 07/30/09
iPhone can do something no other phone can  NonZealot | 07/30/09
Wrong, YET AGAIN, Non Zealot (aren't you tired of it yet?)  matthew_maurice | 07/30/09
Different bug  eqpc | 07/31/09
Get a clue...  i8thecat | 08/05/09
Real phones?  athynz | 08/06/09
You ate more than just the cat  GuidingLight | 07/30/09
and...  condelirios | 07/30/09
RE: Researchers take control of iPhone via SMS  2karm | 07/30/09
Too bad...  James T. Kirk | 07/30/09
Given the vitriol and invective...  msalzberg | 07/30/09
@msalzberg - I'm with you there  PlayFair | 07/31/09
Anyone who builds themselves up to something they're not  honeymonster | 07/30/09
Ditto. Apple brings this on themselves  trance2tec | 07/30/09
Now you see why Windows is attacked  stevejg61 | 07/31/09
It's only news because it's an iPhone...  i8thecat | 07/30/09
No, it is news because of its DEVASTATING potential!  honeymonster | 07/30/09
I agree that it is definitively newsworthy...  i8thecat | 07/30/09
Newsworthy, when you read the article...  davidfear | 07/30/09
LMAO...  condelirios | 07/30/09
LOL!  GuidingLight | 07/30/09
What will you say when your iPhone is attacked?  Aragorn_z | 07/30/09
Only care because iPhone is popular  kbartels@... | 07/30/09
Always good for something  honeymonster | 07/30/09
What if Apple placed this hole there?  NonZealot | 07/30/09
Doubt Apple made this hole...  Fark | 07/30/09
RE: What if Apple......  bfilipiak@... | 07/30/09
Apple most certainly has that capability  honeymonster | 07/30/09
What does this mean, plz...  sharijune | 07/31/09
What this means  compudog | 08/06/09
RE: Researchers take control of iPhone via SMS  Shelendrea | 07/30/09
Yeah, the "bad guys" will never figure this one out  NonZealot | 07/30/09
6 Weeks?  robbys22 | 07/30/09
Since a company cannot stay in business by  frgough | 07/30/09
I Think You Misunderstood  robbys22 | 07/30/09
This is a nasty bug, but almost as bad  frgough | 07/30/09
Miller is great!  NonZealot | 07/30/09
Good for you.  frgough | 07/30/09
Seriously?  robbys22 | 07/30/09
nah..  condelirios | 07/30/09
Good Point  robbys22 | 07/30/09
Sure, shoot the messenger  honeymonster | 07/30/09
Apple has been too busy with other security patches  NonZealot | 07/30/09
AT&T involved?  odcchaz | 07/31/09
As you have done  GuidingLight | 07/30/09
I'd rather he do that...  storm14k | 07/30/09
Has anyone seen video of this?  matthew_maurice | 07/30/09
Has Anyone Seen Video?  vermonter | 07/31/09
Apple's having a really bad day...  eMJayy | 07/30/09
iphone  norm adams | 07/30/09
I'm getting tired of this 'security' crap  croberts | 07/31/09
Update Available  Macwinux | 07/31/09
Wow...  condelirios | 07/31/09
Mmm Hmmmmm  Macwinux | 07/31/09
The real issue here is...  dnendza | 08/06/09
This is already fixed in firmware 3.0.1  fernande-zdnet | 08/06/09
Proof Is In The Pudding  brianpeterson@... | 08/06/09

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads