home
August 27, 2008
Posted by Alias420

GreenMyMac discovered and published a security vulnerability for iPhone 2.0.x at MacRumours last night. The security flaw affects iPhone users who use the password protect feature when locking their keypad, but using this very simple trick gives anyone full access to your cell phone’s private information in Mail, SMS, Contacts, and even Safari.

To recreate this exploit yourself, password protect your phone and lock it. Next slide to unlock and do the following:

  1. Tap emergency call.
  2. Double tap the home button.

You should now be in your favorites. Seems like a convenient feature feature at first, but the security problem here is scary. Anyone who picks up your iPhone can make a call to anyone in your favorites and can access their address and for some service providers this will let a stranger access your voice mail.

Let’s go a little further down the rabbit hole now:

  • If you click in a mail address, it will give you full access to the Mail application. All your mail will be exposed.
  • If there’s a URL in your contact (or in a mail message) you can click on it and have full access to Safari.
  • If you click on send text message in a contact, it will give you full access to all your SMS.

Until Apple addresses this security threat, there is an easy work around to secure your personal information.

  1. In ‘Settings’, select ‘General’.
  2. Select ‘Home Button’.
  3. Select either ‘Home’ or ‘iPod’
Share and Enjoy:
  • Digg
  • del.icio.us
  • Reddit
  • Slashdot
  • Technorati
  • Facebook
  • Mixx
  • NewsVine
  • Propeller
  • TwitThis
  • YahooMyWeb

RSS feed | Trackback URI

2 Comments »

Comment by grc
2008-08-28 14:30:24

not much of a real security issue here since most ppl dont even enable password lock. simple solution was stated above to fix this… well limit access not fix. if you really care then use lockdown to lock your phone

 
Comment by grc
2008-08-28 14:36:36

btw, when security issues are exploited… thats when they “become” security issues. theres a few 100 ppl without any knowledge whom will now be able to pick up somebodys phone and start using it… hell tommorrow at work im going to read everybodys text messages maybe send a few of my own to the wrong ppl lol

 
Name (required)
E-mail (required - never shown publicly)
URI
Your Comment (smaller size | larger size)

Subscribe with Bloglines

Recent Posts

Poster: Digitaldaddy

Sun Jan 04, 2009 1:17 am


Poster: LeifErikson

Sun Jan 04, 2009 12:20 am


Poster: LeifErikson

Sat Jan 03, 2009 10:56 pm


Poster: pomz23

Sat Jan 03, 2009 7:25 pm


Poster: rockclimbinpgyro

Sat Jan 03, 2009 6:04 pm


Poster: rockclimbinpgyro

Sat Jan 03, 2009 5:59 pm


Poster: SumoX

Sat Jan 03, 2009 2:59 pm


Poster: Diabloghst

Sat Jan 03, 2009 1:28 pm


Poster: pkmaximum

Sat Jan 03, 2009 12:52 pm


Poster: onyeka77

Sat Jan 03, 2009 9:18 am