::Trend Micro Threat Resource Center::

Showing posts with label iPad. Show all posts
Showing posts with label iPad. Show all posts

10 November 2011

iOS flaw allows App Store apps download malicious code

Since the App Store's inception, Apple has been carefully examining applications submitted by third-party developers in order to assure its customers a malware-free experience. Approved apps get signed with Apple's cryptographic seal, and only than can they be downloaded and run by iPad and iPhone users.

But well-known Mac hacker and researcher Charlie Miller has discovered a flaw in Apple's restrictions on code signing on iOS devices which would allow attackers to use applications sneaked into the App Store to download and run additional, unsigned code.

To prove his point, Miller created an app called InstaStock that ostensibly lists stock tickers and submitted it to the App Store. The app was approved by Apple and offered to users. But unbeknownst to the company, the app also contained a hidden payload which takes advantage of the aforementioned flaw.

The app was now capable to "phone home" to a server set up by Miller, from which new code - unapproved by Apple - was downloaded and executed without a hitch. This gave him remote shell access to the device and allowed him to do things like making it vibrate, run a video, and most frighteningly, downloading any file present on it to the server.

Miller, who has managed to sneak the InstaStock app into the App Store back in September, has already notified Apple of the flaw on October 14th.

But, as news that he was planning to demonstrate the attack next week at the SysCan conference in Taiwan broke, Apple reacted immediately: not only has his app been removed from the App Store, but he himself has been booted out of the iOS Developer Program since he violated the agreement that forbids developers to “hide, misrepresent or obscure” any part of the submitted apps.

Miller is, understandably, annoyed by the move. “They went out of their way to let researchers in, and now they’re kicking me out for doing research,” he says. “I didn’t have to report this bug. Some bad guy could have found it instead and developed real malware.”

I guess that his upcoming demonstration can't be executed now - unless he has predicted Apple's reaction and uploaded (or asked someone to upload) a second booby-trapped app.

10 June 2011

10 most common iPhone passcodes

The problem of poor passwords is not confined to computer use, and the fact was discovered by an app developer who has added code to capture user passcodes to one of its applications.

"Because Big Brother’s [the app in question] passcode setup screen and lock screen are nearly identical to those of the actual iPhone passcode lock, I figured that the collected information would closely correlate with actual iPhone passcodes," says Daniel Amitay.

It turns out that of the 204,508 recorded passcodes, 15% were one of the most common ten:


Comparing it to the list of most common internet passwords, one can see the similarities. "Most of the top passcodes follow typical formulas, such as four identical digits, moving in a line up/down the pad, repetition," he points out. "5683 is the passcode with the least obvious pattern, but it turns out that it is the number representation of LOVE (5683), once again mimicking a very common internet password: “iloveyou.”

Another pattern that pops out when looking at the list of top 100 most used passcodes is the conspicuous use of numbers that mimic particular decades in the last century - the 1990s and 1980s in particular. Amitay chalks that up to the assumption that most users are between the ages of 11 and 21, as it is very likely that the passcode represents the year of their birth or graduation.

Again, nothing new here - people often use their birth dates (or those of their near and dear) for PINs, passwords and codes, fearing that they would soon forget a random number and choosing one they never could forget.

The conclusion is, once again, that people are predictable and don't think much about security. But the fact that makes Amitay's revelation extremely crucial is that if someone steals or finds a lost iPhone, he has a 15% chance of unlocking the device and accessing the data within before it gets wiped just by trying out the passwords on the aforementioned top 10 list.

06 August 2010

French watchdog warns of iPhone hacker glitch

PARIS — French authorities and experts warned Thursday hackers could gain control of iPhones and other gadgets made by US tech giant Apple through the Internet, plundering users' data and tapping their calls.

"Two vulnerabilities have been discovered" in Apple's operating system for the iPhone, iPad tablet computer and iPod music player, the French government computer security agency CERTA said on its website.

Apple did not immediately respond when asked on Thursday to comment on the alert, which was issued by CERTA following a warning by experts at the computer security firm Vupen Securities.

One of the soft spots is caused by a glitch triggered when a user views data in PDF-formatted documents, they said.

Hackers could lure web users on their Apple devices onto special websites where they could exploit the PDF glitch to gain access to the device remotely, Vupen's chief executive Chaouki Bekrar told AFP on Thursday.

A second soft spot involves a data error in one of the devices' components which could allow hackers to increase their control once they have gained access to the device, he said.

The two glitches combined could allow a hacker "to access all of the information" on the device, including contacts, emails, documents and functions such as the camera, microphone and GPS navigation, CERTA said.

CERTA said the problems affected iPhones running versions 3.1.2 to 4.0.1 of Apple's operating system, iPads with versions 3.2 to 3.2.1 and iPod Touch devices with version 3.1.2 to 4.0.

"Pending corrective measures by Apple, great care is recommended while opening PDF files," for example by only opening files from known senders, the government watchdog warned.

Apple devices "are generally very secure," but "are becoming a popular target for hackers," who could tap users' telephone conversations or send messages from their mailboxes, Bekrar said.

He said the glitches were brought to light by the online service Jailbreakme which allows owners of the gadgets to download applications other than the ones sold by Apple in its official "App Store".

12 June 2010

114,000 IPad 3G Owners' Email Addresses Exposed By AT&T

A group called Goatse Security was able to grab 114,067 personal email addresses of iPad buyers from AT&T's website.

Some of the Email addreses leaked include White House Chief of Staff Rahm Emanuel, New York City Mayer Michael Bloomberg, Diane Sawyer of ABC News, and many CEOs, CFO, and CTO's. A number of the email addresses exposed were even those of DARPA reesarchers and high-ranking military officials.

Each iPad comes with an ICC-ID or an "integrated circuit card identifier." The subscriber's SIM card and ICC-ID are linked to uniquely identify them. Normally this data would not be publicly accessible.

AT&T goofed big time and left a script on their website that allowed anyone to query it. If an ICC-ID was provided to the script, it responded with a the subscriber's email address. This script was intended to be used with AJAX apps, but obviously had no protections built in.

This lack of security allowed researchers to write a simple PHP script that used the iPad browser agent string to grab potentially millions of addresses. This would not have been possible with out all the pictures of iPad's online that helped them to guess the ICC-IDs. Like any exploit group that wants fame, these guys shared the script and corresponding info with many others like them before reporting the gaping security hole to AT&T.

So now Steve Jobs has a bit of a problem. Hundreds of thousands of customer's and potentially millions of email address have been made available to groups that could use them for malicious purposes. Not only that, but the iPad 3G looks rather unappealing now even if it was not Apple that was responsible for the breach.

If you bought an iPad 3G and have an email address that doesn't reveal your identity and a strong password for it, you might be safe. However, now is as good a time as any to change your email password to something stronger. Also, if your email is firstname.lastname@mysite.com or something similar, just be very cautious about who you open PDF's from and the links you click in emails. Its easier than you might think for criminals to target a victim with a specially crafted convincing email that appears to be from co-workers or friends.

References: http://security.goatse.fr/

28 April 2010

New Malware Scheme Targets IPad Owners

iPad owners and all-around Apple fans can take comfort in one fact today: the iPad isn't technically affected by a new problem. However, iPad owners who also own PCs running Windows have been targeted by a fresh scheme meant to create a backdoor and steal important info.

A statement provided by BitDefender warned that people are receiving emails telling them to update their iPad's software. A link then takes them to an authentic-looking site where they can download what's supposed to be an iTunes tweak, and the situation gets hairy.

BitDefender explained that things go downhill as "Backdoor.Bifrose.AADY . . . injects itself in to the explorer.exe process and opens up a backdoor that allows unauthorized access to and control over the affected system."

The explanation continued, "Moreover, Backdoor.Bifrose.AADY attempts to read the keys and serial numbers of the various software installed on the affected computer, while also logging the passwords to the victim's ICQ, Messenger, POP3 mail accounts, and protected storage."

Losing all of that information (along with control of one's computer) is perhaps not the nicest way to celebrate a new gadget purchase. iPad owners should try hard to keep their collective guard up.

27 April 2010

iPad users with PCs threatened by backdoor malware

A malicious spam email campaign has been targeting iPad users who own PCs, says Bitdefender. The message is the following:

The message claims that updates have been released for software installed on their iPad devices, and that they need to update their iTunes software so that they will be able to update their iPad software. An embedded URL is offered and, if clicked on, directs the users to a perfect copy of the legitimate page from where iTunes software updates are usually downloaded.

If they choose to download the offered "update", their PCs will be infected with malicious code that "injects itself in to the explorer.exe processand opens up a backdoor that allows unauthorized access to and control over the affected system."

Not content with that, the malware also tries to get keys and serial numbers of the various software installed on the PC, and records the users' passwords for ICQ, Messenger, POP3 mail accounts, and protected storage.

According to Bitdefender, Mac users are not affected - the target are only PC users.