iPhone virus adds botnet powers

Related gallery

Best iPhone travel apps

Best iPhone travel apps

Related video

A closer look at iOS 5

A closer look at iOS 5

In a similar fashion to the relatively benign ikee virus that was recently released, another iPhone virus is targeting jailbroken Australian devices and builds botnet functionality into it, according to computer security firm, Sophos.

Astley%20copy.jpg

New virus worse than Rick Astley attack
(Credit: Whirlpool ID, Batman)

If your iPhone has been jailbroken, change your passwords now, advised Paul Ducklin, Sophos Australia's chief of technology.

Ducklin said the writers of this virus included a program call "Duh", which added malicious capabilities not present in last month's ikee release.

"'Duh' is the bot component," said Ducklin. "When an iPhone is first infected it uses Duh to call home, which by chance happens to be a server located in Lithuania. It dobs in your IP numbers — Wi-Fi, 3G — and the name of phone and makes a unique identifier which will identify your phone the next time you connect," he said.

The virus would replace Apple's default root log-in password, "Alpine", which was automatically used for the SSH program that was exploited by ikee. SSH is used to set up network communication capabilities on a jailbroken iPhone.

The new password installed by this virus was "ohshit", which can be used to remove the threat of further remote attacks on an infected device. Ducklin said to clean up the device by searching the file "directory/private/var/mobile/home", type in "passwd" to initiate the command, and change the password. "Otherwise the buggers can get back in anytime they want," said Ducklin.

Fellow information security boffin, and the first researcher to analyse a sample of it, F-Secure's Mikko Hypponen, wrote today: "The worm is not widespread, but it is much more serious than the first iPhone worm as it seems to try to steal information from the devices."

Ducklin agreed. It was not widespread because it was only a threat to iPhone users that have a jailbroken iPhone, have installed SSH, and have not changed the root log-in password from Apple's "Alpine" default.

On the other hand, while ikee turned off SSH, which would have prevented further attacks of a similar nature, this virus changed the password, meaning that the controller of the server based in Lithuania could gain access to the device.

"That's why I gave out the password," said Ducklin. "It's more malicious because it installs a bot which checks home for instructions. That site's now down but it has the potential to send a file to delete all files on [an infected] phone."

The latest iPhone virus is the third of its kind in the past two months.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

IT Priorities: servers and storage http://t.co/iQ6oT7qe

Accelerator targets 'clean-tech' start-ups http://t.co/8kGTxJGp via @zdnetaustralia

Westpac board goes paperless with iPads http://t.co/kdm26Ewr via @zdnetaustralia

Cloud TVRs stop in wake of TV Now ruling http://t.co/2hLRUvt6 via @zdnetaustralia

RT @WauloK: Two cloud-based TV recording services have been suspended after Optus TV Now. http://t.co/VomMRrRs // @techwebcast Beem is dead.

ZDNet Patch Monday ep137 - Removing the anonymity from Anonymous: http://t.co/E6Tn8vJr

ZDNet Patch Monday ep138 - Anonymous 'crippled': where to for hacktivism?: http://t.co/lbKew6Bo

ZDNet Patch Monday ep139 - War talk dominates AusCERT 2012: http://t.co/rUm22Zjm

ZDNet Patch Monday ep135 - iiNet wards off AFACT, but what next?: http://t.co/0xVdYm6i

ZDNet Patch Monday ep136 - Blackhole crimeware as a service here to stay: http://t.co/evnCUlsX

GoogleTV will revolutionize television once viewers understand it http://t.co/c4lEyb3a

Reading this article is like stepping back in time. If I was Paul Berryman I would hang my head in shame. How embarrassing!!! I can’t b...

51 minutes ago by MikeSkoey on 30 servers to 7: BUPA redoes virtualisation

Phone cloning, maybe, but bill duplication? Tech-heads give verdict
http://t.co/aw5SNigN
#ozpolitics

The registration sticker provided a visual reminder to the driver to renew regardless of what happened to the renewal letter. The experie...

58 minutes ago by dccharron on NSW ditches rego stickers for tech

"xfire: Why is telecommunications being treated different to roads, water and electricity?" Good question, my guess is AUS is far behind...

1 hour ago by ngoctranminh on Five pros and cons of the NBN

“@zdnetaustralia: Is Windows Phone really the third challenger to Android and iOS? http://t.co/Tr7ASra0 ”. It's different but fast and good

Can HP bounce back? http://t.co/TSlWjmrA

Thanks for the response Luke, Given that the quotes are accurate, then the person in charge of the Vic Health App needs to find another j...

1 hour ago by butterflyeffecs on Android fragmentation steers Vic Health

Social business in Australia http://t.co/aBuXFy40 . Australian businesses still laging behind with social business. Time to catch up!

Can Windows Phone bring a new challenge? #WindowsPhone http://t.co/m82nU7hK

Nice analogy. Another factor is whether you can find 50 people with powerful enough weapons. Minassian's argument is essentially that the...

1 hour ago by Mukimu on National Botnet Network coming: Earthwave

RT @digitaltasmania: @ZDNetAustralia #NBN's Tassie upgrade to cost $1.3m http://t.co/1nTbLUJv -Countdown begins for 1st Oppn. MP to misconstrue per unit cost

@ZDNetAustralia #NBN's Tassie upgrade to cost $1.3m http://t.co/1nTbLUJv -Countdown begins for 1st Oppn. MP to misconstrue per unit cost

RT @mosfreshmedia: Start-up accelerator targets cleantech 'Atlassians, BigCommerce' via @zdnetaustralia http://t.co/oho3oQSK @atpinnovations @hamishhawthorn

Can #HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get... http://t.co/dlgAhwxb

Can HP bounce back? http://t.co/qLlHB5FV

It's nice to see Tas finally get some decent internet connectivity, for too long Tas has been stooged on decent internet connectivity but...

1 hour ago by Jingles on NBN's Tassie upgrade to cost $1.3 million

Cloud inefficiency - Bad habits are hard to break: Cloud can save you a lot of money - if you use it effectively... http://t.co/oVoNx2na

by http://t.co/vmlLt4bh: Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development ... http://t.co/EjWWU9O1

Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get ... http://t.co/KDGewBVH

Can HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get ... http://t.co/y2ajlh9V

Three tips for businesses to support connected customers: While the connected home offers benefits to the consum... http://t.co/psgHJelD

#Agedcare 30 servers to 7: BUPA redoes virtualisation: Most IT teams spend 90 per cent of today making sure that... http://t.co/HmVXHRQ7

[plug] #NBN cost-benefit analyses are so 2011 http://t.co/2mRUKI8G @TurnbullMalcolm has forgotten his CBA; sh/would he still do one? #zdnet

Can HP bounce back? http://t.co/LlAUcyYP

Who is Luke Hartsuyker? He must be the Apprentice FUDster. As PaulPC has already said regional consumers want, deserve and are entitled...

2 hours ago by dickster on Regional review highlights NBN, mobile

Three tips for businesses to support connected customers http://t.co/W7Sr3RpD

by http://t.co/vmlLt4bh: Did RIM shelve plans to license BBM?: Research In Motion (RIM) had considered licensing ... http://t.co/z6VlO472

Did RIM shelve plans to license BBM? - ZDNet Australia http://t.co/j042NNOM

Did RIM shelve plans to license BBM? - ZDNet Australia http://t.co/qMNEifi1

Its good to see the NBN keeping up with the latest equipement & letting the people benefit from it. After all thats why it was a trial, ...

2 hours ago by fibretech on NBN's Tassie upgrade to cost $1.3 million

Did RIM shelve plans to license BBM?: Research In Motion (RIM) had considered licensing BlackBerry Messenger (BB... http://t.co/G13GBXl4

Did RIM shelve plans to license BBM? http://t.co/KKPZVPOr

Shadow Minister for Regional Communications Luke Hartsuyker has got it wrong. Regional consumers want improved mobile services AND the NB...

3 hours ago by PaulPC on Regional review highlights NBN, mobile

Just remember that Google haven't broken any laws here, they're just doing what all their other multinational competitiors do; minimise t...

3 hours ago by Pachanga on Much ado about Google's tax

ルイヴィトン バッグ : http://www.lovebagjp.com/ Louis Vuitton bags, Louis Vuitton pretension nose about,Louis Vuitton daydre...

4 hours ago by bundLourb on Reservoir blogs: Fan fakes Tarantino diary

シャネル バッグ : http://www.bagssalejp.org/ Chanel trap,chanel shekels,gucci bags,direct purse,poor recent Louis Vuitton keep...

6 hours ago by bybrinkLync on Reservoir blogs: Fan fakes Tarantino diary

I guess but in both cases, dead body!

15 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

16 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

16 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

17 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

17 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

17 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

18 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

18 hours ago by Beta on Regional review highlights NBN, mobile

This story has been voted 12000 times in the last 24 hours!

21 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar