Reply
   
 iPhone trojan found - targets jailbroken iPhones 
 
 
  #1 (permalink)  
Old 10-01-2008, 08:17 AM
MacTalk Podcaster

Group: Regulars
Location: With a Wine glass in hand


iPhone trojan found - targets jailbroken iPhones

http://www.ipodhacks.com/article.php?sid=2482

...
Targeting only "jailbroken" iPhones (which have been modified to allow the installation of third-party applications), this trojan masquerades as an update Erica's Utilities and is named "113 prep." Simply running the application causes no harm - it simply prints the word "shoes" to the screen. Uninstalling the application, however, removes certain files from the iPhone's /bin directory, making it impossible for various applications to function correctly.
...

Considering practically everyone reading this forum with an iPhone has 'hacked' it to work, this is an important heads up.
__________________
See wineweek.com.au for rapid tips on which wines are worth buying and drinking.
Follow me on twitter: wineweek or uncyherb
uncyherb is online now
Profile CardPM
Go to the top of the page
Reply With Quote
  #2 (permalink)  
Old 10-01-2008, 08:25 AM
Regular

Group: Regulars
Location: Townsville, Queensland


ha ha ha.
fiark is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #3 (permalink)  
Old 10-01-2008, 08:29 AM
Regular

Group: Regulars
Location: Sydney


We all knew this would happen sooner or later. I'm going down the safe road and getting my iPhone with an official network, when it comes out in Australia. But even then, I guess people could install spyware and viruses on your phone, right?

What really made me laugh was this:

Quote:
It's particularly interesting to note that the author of the trojan is an 11-year-old child who merely toyed with various XML files to create the malicious app. Obviously more savvy developers could exploit jailbroken iPhones to a much greater degree.
__________________
W...W...W...Windows... 386!
Domenic is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #4 (permalink)  
Old 10-01-2008, 08:36 AM
Regular

Group: Regulars
Location: New Hampshire, USA


Quote:
Originally Posted by uncyherb View Post
[Uninstalling the application, however, removes certain files from the iPhone's /bin directory, making it impossible for various applications to function correctly.
(Of course) this trojan only works if it is removed by using the Installer.app, when the uninstall action is triggered. The trojan can be trivially removed, safely, using any ssh connection to the device.
__________________
24" 2.4GHz iMac, 2GHz MBP, (1.66GHz, 250GB mini + Dell 2405FPW + Belkin F1PI241EGau), 16GB 1stG 'Touch
chrism238 is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #5 (permalink)  
Old 10-01-2008, 08:38 AM
Regular

Group: Regulars


its pretty easy - if you're not stupid and read before installing things you'll be fine.

theres sticky's on most iphone hacking sites since the file came out around the 5th. nothing a restore can't fix of course...
__________________
Successful trades: _bren, step_andy, natakim
stevekicks is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #6 (permalink)  
Old 10-01-2008, 08:39 AM
I'm crackin' skulls

Group: Forum Leaders
Location: Melbourne


Quote:
Originally Posted by domzo View Post
But even then, I guess people could install spyware and viruses on your phone, right?
Well, no. It's a trojan - it relies on the user to install it. If you're downloading software from unreliable sources (i.e, not from Erica Sadun even though it purports to be her work) then it's your own damn fault. Not to mention that deleting some system files seems like it'd be easily fixed by a restore.
__________________
MacBook 2.0 GHz Core Duo, iPhone 3G 16GB
criminaldeli.tumblr.com | twitter
tcn33 is online now
Profile CardPM
Go to the top of the page
Reply With Quote
  #7 (permalink)  
Old 10-01-2008, 09:03 AM
Regular

Group: Regulars
Location: Brisbane


Plenty of tutorials on the web about how to get rid of it too.. doesn't look that difficult...
__________________
Successful Trades: krazy1, Astr0b0y, soulman, areal, smdnetau, Huy, Alessiman, step_andy, tibook, mulquemi, BoxDog, Devski, The Keddi, decryption
Rasta is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #8 (permalink)  
Old 10-01-2008, 09:19 AM
Widgeteer

Group: Forum Leaders


Another OS X "virus" non-event.
__________________
Bjango iPhone apps on sale: Darkness and Jobs
Over 12 million widgets and apps downloaded: iSlayer.com (RSS), iPhone apps: Bjango.com (RSS, Twitter)
Record TV easily: IceTV (RSS, IceTV iPhone app)
marc is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #9 (permalink)  
Old 10-01-2008, 11:51 AM
Regular

Group: Regulars
Location: Townsville, Queensland


Quote:
Originally Posted by chrism238 View Post
(Of course) this trojan only works if it is removed by using the Installer.app, when the uninstall action is triggered. The trojan can be trivially removed, safely, using any ssh connection to the device.
Of course everyone with an iphone knows how to remove safely using any ssh connection to the device...

Last edited by fiark; 01-02-2008 at 09:20 PM.
fiark is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #10 (permalink)  
Old 10-01-2008, 11:52 AM
Taking a break

Group: Forum Leaders
Location: Adelaide


Even if it runs rampant on your iPhone... all you've got to do is uninstall it, then re-install the apps it deletes.

<neo> Woah. </neo>
__________________
Read my drivel, be dazzled by my Twitter

Are you some kind of devil trying to keep me from using my time usefully? - Currawong
"You're an enigma wrapped in a ferreo roche" - fulltimecasual
Disko is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #11 (permalink)  
Old 10-01-2008, 11:58 AM
Regular

Group: Regulars
Location: Melbourne


Everybody run and hide the virus's are coming
__________________
Sick of Bullshit? Go here
www.youngausskeptics.com

iBook 14'' 1GB Ram, MBP(santa) 15" 4GB ram, iPod Nano(3G) 4gb, iPod shuffle 512mb, iPod Touch 8gb.
The Fluffy Duck is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #12 (permalink)  
Old 10-01-2008, 01:41 PM
Member

Group: Member


Was going to happen sooner or later, i spose thats theres a downside to everything, including jailbreaking... next there will be a 3rd party Anti Virus
__________________
...
Scratch is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #13 (permalink)  
Old 10-01-2008, 02:10 PM
Regular

Group: Regulars
Location: At a place called Vertigo


Quote:
Originally Posted by Scratch View Post
Was going to happen sooner or later, i spose thats theres a downside to everything, including jailbreaking... next there will be a 3rd party Anti Virus
Calm down, it's not actually anything worth worrying about. Anyone can write an app that deletes files and mislabel it as an app that does something else, which is just about what's happened here, except an app with a use has been modified.
__________________
Q: How many Apple Newtons does it take to change a light bulb? A: Foux! There to eat lemons, axe gravy soup.
'Cooper' - Intel iMac 24"; 3.06Ghz C2D, nVidia 8800GS-T, 2GB, 500GB
'Falcon' iPhone 3G 16GB White
'Pods Yerfunkle' - iPod 5.5G 30GB
'Tiny' - iPod Shuffle 2G 1GB Blue
ford.boy is online now
Profile CardPM
Go to the top of the page
Reply With Quote
 
Reply

Thread Tools

 
Similar Threads
 
Thread Thread Starter Forum Replies Last Post
call people with jailbroken OOB 1.1.2 downgraded to 1.1.1 or jailbroken 1.1.2 altuno iPhone Help and Support 2 02-02-2008 02:45 AM
New Trojan Horse OSX.RSPlug.A targets Macs Currawong News 4 01-11-2007 10:21 AM
Trojan Horse Found On My Imac! adamjc Mac OS X & All Software 22 19-09-2005 11:32 AM
Trojan Horse Found On My Imac! Monkey Mac OS X & All Software 0 01-01-1970 10:00 AM