Hack turns iPhone into spy-phone

US security consultant, Rick Farrow, has used H D Moore's security testing tool, Metasploit, to crack the iPhone, which allows a hacker to control an iPhone remotely.

Farrow demonstrated how he gained root access to the iPhone and installed an application that can record conversations on and near the iPhone, transforming the device into a spy tool. It also allowed him to remotely access recently modified files, locally stored e-mails and view the iPhone's Web browsing history.

"Using a specially crafted Web page utilising an iPhone exploit (now patched) he gained root level shell access to the phone -- which means he could do anything that the iPhone is capable of from his laptop," explained Jarno Niemelä, security researcher for the security vendor, F-Secure.

"This exploit actually involved you doing something with the iPhone, or in this case, I do something with the iPhone to get the exploit to work. This is not at all unusual. Most PCs are actually exploited because people visit a Web site and wind up being exploited," Farrow told US business and technology publication, Fast Company.

Last month, ZDNet Australia's sister site ZDNet.co.uk reported that application hungry iPhone owners were using a similar technique to gain root access to the iPhone thanks to the jailbreakme hack, which exploited an image vulnerability.

According to analysts, Apple's decision to run every application on Safari as root exposes the iPhone to greater risk, and quite possibly repeats a mistake made by Microsoft some years ago.

"It strikes me as strange that Apple took the shift and moved to Unix as their operating system, but don't seem to have learnt the lesson that you don't run everything as root. This was the same lesson which Microsoft had so many issues with when they intertwined Internet Explorer with the Windows operating system, and it's something which they are now digging themselves out of," security analyst, James Turner, Intelligent Business Research Services, told ZDNet Australia.

"I think the inference we can make is that Apple decided that the risk of running applications as root was worth it. There used to be a saying that Windows 95 was Apple 84. Now it seems that Apple want the iPhone to follow a similar path to Internet Explorer. Sure, Apple will get market share, but at what cost to their reputation for security?" he added.

However penetration testers say that Apple's operating platforms are in general still more secure than its competitors and this instance simply highlights the problem of running a desktop operating system on a phone.

"This vulnerability isn't particularly special as it's just exploiting a vulnerability in Safari. Now it is patched, users will get their phones updated by iTunes when they next sync," said Chris Gatford, security expert from penetration testing company, Pure Hacking.

"I think that Apple's operating system on the whole is far more reliable and secure than the other competitors and I am sure some of these kinks will be eventually ironed out," he said.

The potential threat to iPhone users however is not isolated to Apple's phone, explained Farrow.

"This is a problem for any smartphone, for any widely distributed computing device, which will eventually be attacked and exploited," he said.

Although malware threats to mobile phone operating systems are uncommon today, security companies have been keeping a close eye on the sector. According to F-Secure, there are currently 373 known pieces of malware for all mobile phone operating platforms, 364 of which work only for the dominant smartphone operating system, Symbian, which is used in Nokia's phones.

Future threats for mobile phone operating systems, according to F-Secure, include rootkits, self-propagating worms, mobile phone botnets and large-scale profit-oriented malware organisations.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

What is FRAND? http://t.co/5cMeD6TS #ip #frand

Social business success: Burberry http://t.co/dYhBEABN

Social business success: Burberry | ZDNet http://t.co/BpBMXRYw #socbiz

The mining industry run around telling us about wht great employment gererators they are when they are trying to avoid taxation, as soon ...

8 minutes ago by Kevin Cobley on Robotic mining worth its high cost: Rio

Pilot sues Virgin for being iPad Luddite: A pilot allegedly damaged his back carrying a 18kg flight bag full of ... http://t.co/ksT5JJ37

VeriSign Authentication Services provides solutions that allow companies & consumers to engage in communications & commerce online with c...

16 minutes ago by santla on Hackers stole data from VeriSign in 2010

RT @zdnetaustralia: Telstra reveals cause behind compromised BigPond email accounts http://t.co/V5cYJMcN

Robotic mining worth its high cost: Rio - ZDNet Australia http://t.co/SirHOAuw

In defense of the Galaxy Note's stylus http://t.co/GiBQHPjT

Pilot sues Virgin for being iPad Luddite http://t.co/B3lTvulR

Phishing scam causes Telstra email woe http://t.co/kcXa15Tm

by http://t.co/vmlQ0Ecb: Pilot sues Virgin for being iPad Luddite: A pilot allegedly damaged his back carrying a ... http://t.co/aHx5vxkg

Phishing scam causes Telstra email woe:
http://t.co/nNSQWX96

I've delt with developers daily for 2 decades and I am astounded at the arrogance that new grads possess, combined in no fundamentals and...

28 minutes ago by Dr_Truth on IT lumped with 'arrogant, ignorant' grads

Every mobile phone we should have a good mobile security downloaded so that we can be aware of this malwares!!!

32 minutes ago by santla on Google scans Android apps for malware

Oh nice to know about this article!!!

33 minutes ago by santla on Ex-Firefox exec plans Facebook for Android

Its good if they get it!!

34 minutes ago by santla on Will Android get a root store?

Android is good!!! i too have android mobile ..

36 minutes ago by santla on Android features better than iPhone: Woz

ZDNet: Did Google withhold malware protection details from partners? http://t.co/nblEvOYc

Thanks for the artilcle i too have android mobile phone!! and its so good and i have comodo mobile security in my phone

37 minutes ago by santla on Android to be developer platform of choice

Thanks for the artilcle i too have android mobile phone!! and its so good and i have comodo mobile security in my phone

37 minutes ago by santla on Android to be developer platform of choice

Great to know about it. along with this we can have some good mobile security so that we can remain safe with our mobiles tooo such a com...

39 minutes ago by santla on iPhone 4S wins Android, BlackBerry users

Android mobile very cheap and good now a days more than ipad !!!

39 minutes ago by santla on Android closes in on iPad market share

Android mobileare getting lot of malware now a days its better to have some good mobile securities like Comodo Mobile Security !!!

41 minutes ago by santla on Google scans Android apps for malware

RT @zdnetaustralia: Telstra reveals cause behind compromised BigPond email accounts http://t.co/Xbkfy5OK

This has been a serious problem now a days!!!

42 minutes ago by santla on Microsoft settles with alleged botnet host

This has been a serious problem now a days!!!

42 minutes ago by santla on Microsoft settles with alleged botnet host

"I agree that their products have gotten a lot better. How insecure they still are says a lot about how hard this problem really is

43 minutes ago by santla on Has Microsoft fixed its security issues?

Yeah i accept with myron!!

44 minutes ago by santla on Microsoft halts another botnet: Kelihos

the Kelihos botnet has not crawled out of the grave, ... new botnet is being assembled using a variant of the original malware.

45 minutes ago by santla on Antivirus employee named in botnet case

Thanks to know about it the artile was good

46 minutes ago by santla on 2011: security's most spectacular stuff-ups

Thanks to know about it the artile was good

46 minutes ago by santla on 2011: security's most spectacular stuff-ups

Kelihos, according to the researchers, has been found in new variants and they quite resemble the earlier build.

46 minutes ago by santla on Kelihos variants slipped Microsoft's noose

Google's answer to EU as succinct as its privacy policy - ZDNet (blog): Telegraph.co.ukGoogle's answer to EU as ... http://t.co/uA9aOxQD

Beware of hoaxes. Facebook does not donate money based on the number of shares or likes for "sick babies".... http://t.co/MeXFoUbe

Phishing scam causes Telstra email woe http://t.co/BYZTvadN via @zdnetaustralia

Did Google withhold malware protection details from partners? http://t.co/SHGePNhK

Govt caught in internet-security time warp http://t.co/4st8GIcj

Phishing scam causes Telstra email woe: A phishing scam has led to a number of compromised BigPond email account... http://t.co/PXvZo1no

Phishing scam causes Telstra email woe - Communications - News - ZDNet Australia http://t.co/ikFfPLE1

Pilot sues Virgin for being iPad Luddite: A pilot allegedly damaged his back carrying a 18kg flight bag full of ... http://t.co/mjzcTBWi

Pilot sues Virgin for being iPad Luddite - A pilot allegedly damaged his back carrying a 18kg flight bag full of cha... http://t.co/0NcvLleE

3D printer produces new titanium jaw - ZDNet Australia: BBC News3D printer produces new **** http://t.co/Odgv46l8 #3DPrinting #DoYou3D

Why Windows 8 will be DOA:
http://t.co/yq26BIFr

Govt caught in internet-security time warp - ZDNet Australia (blog): http://t.co/a8ARfbg4

Did Google withhold malware protection details from partners? http://t.co/iLlp0Q5E

Robotic mining worth its high cost: Rio http://t.co/5NMJMDR7

Govt caught in internet-security time warp http://t.co/JVv81vzC

Telstra reveals cause behind compromised BigPond email accounts http://t.co/V5cYJMcN

“@scanman: The Apple fanboy problem http://t.co/ZxuB04OS” This article seems a bit strange.

That Bigpond phishing scam last year caused a number of email addresses to be blacklisted. http://t.co/gMvEmLHx

ZDNet App Wrap: 6 February 2012 - ZDNet Australia http://t.co/oWvIL5RD

by http://t.co/vmlQ0Ecb: Govt caught in internet-security time warp: Today is Safer Internet Day, the day when th... http://t.co/H2x7LRRf

Govt caught in internet-security time warp: Today is Safer Internet Day, the day when the government likes to sh... http://t.co/5AcbMvu0

RT @JLLLOW: RT @zdnetaustralia: Govt caught in internet-security time warp: http://t.co/nIj6MGJE

This story has been voted 5 times in the last 24 hours!

3 days ago, Abbott paving a telecoms road to nowhere

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar