Apple comments on iPhone virus, security firm warns against jailbreaking
Apple has responded to the currently circulating iPhone worm that is enabling hackers to steal information from users with jailbroken iPhones, spokesperson Natalie Harrison said: "The worm affects only a very specific set of iPhone users who have jailbroken their iPhones and hacked it with unauthorized software.”
"As we've said before, the vast majority of customers do not jailbreak their iPhones, and for good reason. These hacks not only violate the warranty, they will also cause the iPhone to become unstable and not work reliably," she notes, as reported by The Loop.
Anti-virus vendor, Intego today published its own statement on the matter: “We would like to stress that users who jailbreak their iPhones are exposing themselves to known vulnerabilities that are being exploited by code that is circulating in the wild. If users install ssh, they should change the default password, which is widely known. While the number of iPhones attacked may be minimal, the amount of personal data that can be compromised, and the ability of this new worm to create a botnet, strongly suggests that iPhone users should stick with their stock configurations and not jailbreak their devices.”
Intego calls the new malware iBotnet.A, describing it as “by far the most sophisticated iPhone malware yet: it is not only a worm, capable of spreading across a network, but also hijacks iPhones or iPod touches for use in a botnet.”
This worm starts by searching its local network, as well as a number of IP address ranges, for available devices to infect. The address ranges it scans include those of ISPs in the Netherlands, Portugal, Hungary, Australia, and if an appropriately unprotected iPhone is found, the worm can copy itself to these devices.
When active on an iPhone, the iBotnet worm changes the root password for the device (from “alpine” to “ohshit”), in order to prevent users from later changing that password themselves. It then connects to a server in Lithuania, from which it downloads new files and data, and to which it sends data recovered from the infected iPhone.
The worm sends both network information about the iPhone and SMSs to the remote server. It is capable of downloading data, including executables that it uses to run and carry out its actions, as well as new files, providing botnet capabilities to infected devices.
The worm also gives each infected iPhone a unique identifier; this to be able to reconnect easily to any iPhones on which valuable information is found, but also to ensure that only infected iPhones can connect to the server. Finally, it changes an entry in the iPhones /etc/hosts file for a Dutch bank web site, to lead Dutch users who connect to this bank site to a bogus site, presumable to harvest user names and passwords.
Latest Stories on 9 to 5 Mac
- Apple releases two updates to get you ready for Aperture 3
- Apple unleashes iPhone/iPad SDK 3.2 beta 2
- Apple patents the 3D Apple Store - Alice in Avatar-land
- Surprise: Warner admits iTunes sales slow on price hikes
- Apple ships Aperture 3: 64-bit, Snow Leopard/Intel only, 200 features, $199/£169 (demo available)
- What's coming to the Apple Store this morning?
- Apple Store Down. Can we has Core i7 MacBook Pros?



Delicious
Digg
StumbleUpon
Reddit
Facebook
Google
Yahoo
Comments (15)
As if Miss Harrison really cares (apart from her big fat wallet?). Solid proof that it is these very leeches that write these damn viruses! Well they've found the perfect (jail-broken) market then?
Thanks for layering on the stupid to a thickness previously unseen ever before.
You appear to have forgotten to include a point to your comment, not to mention any grammatical or literal sense. Do you actually know what question marks are for? Oh, and Apple are the people who make the phone, not the viruses.
Complex stuff, I know.
Are you psychotic or just an idiot? Maybe you're 12. Please, never vote and don't speak in public. You're an embarrassment to the species.
For the past 15 years, the good advice for people exposing sshd to the internet is
Those that make SSH available and do not heed all of the above advice are always put into the category of "complete idiots".
Amen to those rules.
What? No paranoid rants about Apple creating the worm?
Only from you howie.
Totally agreed 100%! They "Apple" is capable to do that..
Turn SSH off when not in use. Problem solved.
Take a look at your Internet-facing port 22 access attempts some time. You'll notice port 22 attempts hundreds of times a day.
Enabling an improperly-configured SSH server on the internet for any period of time is a significant security risk. Malware can be installed through a weak ssh configuration in less than 1 second.
sorry i'm a noob. how do i check if i've got ssh turned on?
did you install the ssh app? do you use ssh? if the answer's no, then it will not be on. otherwise, just uninstall it or just use sbsettings to switch it off
Herve Leger womens fashions at ShopStyle. Shop popular stores to find Herve Leger womens fashions on sale - all in one place. Create and share looks based
Herve Leger
Cheap Herve Leger
Jewelry,Necklaces,Jewelry Necklaces,Links of London Necklaces,online sales a variety of world famous such as Links of London etc,with competitive price.
Links of London , the leading British contemporary jeweller was founded in 1990 by jewellery designer Annoushka Ducas and her husband John Ayton.cheap Links of London jewelry at online linksgif UK store, including Links of London Necklaces, Links of London Charms, Links of London Earrings. Links of London Silver Sweetie Bracelet Medium
Links of London Charm
Links of London
Herve Leger womens fashions at ShopStyle. Shop popular stores to find Herve Leger womens fashions on sale - all in one place. Create and share looks based Herve Leger Cheap Herve Leger Jewelry,Necklaces,Jewelry Necklaces,Links of London Necklaces,online sales a variety of world famous such as Links of London etc,with competitive price. Links of London , the leading British contemporary jeweller was founded in 1990 by jewellery designer Annoushka Ducas and her husband John Ayton.cheap Links of London jewelry at online linksgif UK store, including Links of London Necklaces, Links of London Charms, Links of London Earrings. Links of London Silver Sweetie Bracelet Medium Links of London Charm Links of London