{"id":623,"date":"2009-07-31T15:15:51","date_gmt":"2009-07-31T08:15:51","guid":{"rendered":"http:\/\/deepquest.code511.com\/blog\/?p=623"},"modified":"2009-07-31T15:24:37","modified_gmt":"2009-07-31T08:24:37","slug":"623","status":"publish","type":"post","link":"https:\/\/deepquest.code511.com\/blog\/2009\/07\/623\/","title":{"rendered":"Hackers Can Launch iPhone Attack Via SMS"},"content":{"rendered":"<p>Security experts at the Black Hat conference said Thursday that hackers can break into an iPhone to intercept text messages, deliver spam and deliver malware.<\/p>\n<p>Charlie Miller, Independent Security Evaluators researcher, and Collin Mulliner, a Ph.D. student at the University of Berlin, demonstrated during a Black Hat presentation that hackers can break into an iPhone via the SMS protocol to launch a denial-of-service (DOS) attack or take control of a victim&#8217;s phone.<\/p>\n<p><!--more--><\/p>\n<p><span id=\"articleBody\">&#8220;Its lots of fun to kick friends off the network, but it&#8217;s even more fun to own their phone,&#8221; Miller said, who demonstrated the exploits on both the iPhone and Android.<\/span><\/p>\n<p>The hack is enabled by memory issues in the way the iPhone handles the SMS protocol, Miller said. Miller demonstrated Thursday that the attack can be used to launch a <a href=\"http:\/\/www.crn.com\/encyclopedia\/defineterm.jhtml?term=DOS&amp;x=&amp;y=\">DOS<\/a> attack, which could be used to shut off an iPhone, deface text or otherwise reconfigure the keys.<\/p>\n<p>The DOS hack is launched by flooding the iPhone with hundreds of SMS control messages, which allows hackers to keep their victims off the network indefinitely.<\/p>\n<p>A similar SMS hack can be conducted on the <a href=\"http:\/\/www.crn.com\/encyclopedia\/defineterm.jhtml?term=Google&amp;x=&amp;y=\">Google<\/a> Android and the Windows Mobile platforms.<\/p>\n<p>&#8220;Basically what happens, you send a bad SMS, you can&#8217;t use your phone,&#8221; Miller said. &#8220;Literally the phone is working, you just can&#8217;t press any of the buttons.&#8221;<\/p>\n<p>And unlike previous types of mobile attacks, which required a <a href=\"http:\/\/www.crn.com\/encyclopedia\/defineterm.jhtml?term=hacker&amp;x=&amp;y=\">hacker<\/a> to entice users to open a malicious Web site, iPhone users could become infected with no intervention.<\/p>\n<p>These kinds of attacks will likely be used to send spam, researchers said. &#8220;It could be used in a spam game,&#8221; said Mikko Hypponen, chief research officer for Finland-based F-Secure. &#8220;SMS is cheap but it&#8217;s not free.&#8221;<\/p>\n<p>Unless you hack into someone&#8217;s phone, that is. One of the biggest impediments to launching spam campaigns via SMS is that it costs money to send a text. However, hackers who can break into a victim&#8217;s phone can launch an attack that could send out millions of spam text messages free of charge.<\/p>\n<p>Miller, however, found a way to test the SMS <a href=\"http:\/\/www.crn.com\/encyclopedia\/defineterm.jhtml?term=exploit&amp;x=&amp;y=\">exploit<\/a> while incurring minimal costs. &#8220;We paid for 100, and we got the effects of half a million,&#8221; he said.<\/p>\n<p>Perhaps even more menacing, researchers said, is the possibility of launching a malware attack via SMS. An attack could be used to distribute <a href=\"http:\/\/www.crn.com\/encyclopedia\/defineterm.jhtml?term=malware&amp;x=&amp;y=\">malware<\/a> once the hacker is able to penetrate the victim&#8217;s phone, which would spread to everyone on the victim&#8217;s contact list. Mobile Trojans could be used to steal information or make the mobile phone into a remote spying device, Hypponen said.<\/p>\n<p>from <a href=\"http:\/\/www.crn.com\/security\/218900203;jsessionid=P23XY0KZ5HIKIQSNDLOSKH0CJUNN2JVN\">Channel Web<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security experts at the Black Hat conference said Thursday that hackers can break into an iPhone to intercept text messages, deliver spam and deliver malware.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4,18,3],"tags":[40,15],"class_list":["post-623","post","type-post","status-publish","format-standard","hentry","category-apple","category-iphone-apple","category-security","tag-ddos","tag-iphone"],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/s4bBYZ-623","jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/comments?post=623"}],"version-history":[{"count":3,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/623\/revisions"}],"predecessor-version":[{"id":626,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/623\/revisions\/626"}],"wp:attachment":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/media?parent=623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/categories?post=623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/tags?post=623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}