The Mac Observer

This is an iPod Observer article.

Jailbroken iPhones Hit with Another Worm

November 23rd, 2009 at 8:49 AM - News by Jeff Gamet

Jailbroken iPhone owners are facing yet another potential security threat now that a new worm is users in the Netherlands. The new threat acts like a botnet and redirects ING online bank customers to a phishing site.

Like previous iPhone worms, this new threat works only on iPhones that have been hacked to support unauthorized third-party applications, have SSH installed, and are still using the default root password. The worm spreads between iPhones that are on the same Wi-Fi network, according to the security research firm F-Secure.

So far, the number of infected iPhones is estimated to be in the hundreds. "It's fairly isolated and specific to Netherlands but it is capable of spreading," said F-Secure research director Mikko Hypponen.

ING Bank is alerting its customers to the potential threat and is reminding them that the threat impacts only jailbroken iPhones.

The first iPhone worm to appear used a similar method to jump from iPhone to iPhone, and initially asked victims for €5. That worm was later changed to offer instructions on protecting jailbroken iPhones.

A second worm appeared shortly after, although it was far less dangerous because it only added a new locked screen graphic showing 80's pop star Rick Astley. A more dangerous worm appeared a few days later that could copy data off of a victim's iPhone.

Since the attacks all impact hacked iPhones, the safest defense is to not jailbreak your handset. For users with jailbroken iPhones, changing the root password should block the attacks as well.

[Thanks to the BBC for the heads up.]

3 Observer Comments

Keep in mind: This worm impacts only jailbroken iPhones. If you aren’t sure how to change your iPhone’s root password, you might not want to hack it.

If you aren’t sure how to change your iPhone’s root password, you might not want to hack it.

Because it’s so hard to use passwd while logged on as root?

The “more dangerous worm” as you call it, links to a story about the iPhone/Privacy.A (so-called by Intego Antivirus) HACKER TOOL.  This may be nitpicking, but iPhone/Privacy.A is not a worm (or virus) that spreads from iPhone to iPhone.  It is a piece of software that is on Mac computers that allows someone to exploit the same vulnerability (open ssh server with default passwords) that the previous worm did, but it is not a worm.  I think it’s safe to assume in most cases that iPhone/Privacy.A (is on someone’s Mac because they installed it there for their OWN nefarious purposes.  An exception might be a bad guy who’s already somehow compromised your Mac for their own use.

Page 1 of 1 pages
Login. Need an account? Register here.



Auto-login on future visits

Show my name in the online users list

Forgot your password?


Post A Comment

Name:

Email: (will not be displayed)

  Your Comments

Remember my personal information

Notify me of follow-up comments?

What is the sum of 2 and 2?

 

Recent Headlines - Updated February 9th

Tue, 8:00 AM
TMO Appearances - TMO’s Bryan Chaffin and the Atomic Love Bombs Perform During Macworld Expo
Mon, 5:37 PM
News - Juniper Readies Software to Improve Cell Carrier Networks
5:17 PM
Macworld Expo - Macworld Expo 2010 Hess Party List Goes Online
4:11 PM
News - Survey: iPad Announcement Increased Awareness, Fails to Convert New Buyers
3:30 PM
TMO Appearances - Dave Hamilton Keeps Your Mac Lean and Clean at Macworld Expo
1:10 PM
TMO Appearances - Mac Geek Gab Live Recording at Macworld Expo
12:39 PM
Deal Brothers - Western Digital 750GB My Passport Essential SE Portable Hard Drive:  $129
11:46 AM
Product News - nova media Intros FoneSync for LG Handsets
11:15 AM
News - Pwnage Tool 3.1.5 Adds iPhone OS 3.1.3 Support
10:35 AM
News - Mobily Adding iPhone Tethering Support in February
10:00 AM
Hot Forum Topic - Apple, Google and the Evolution of the Smartphone Market
9:30 AM
Monday's Mac Gadget - Want to Secure Your Data Across Platforms?  Check out TrueCrypt!
 

The Mac Observer Reader Specials

Apple Stock Quote

  • AAPL: $194.12. Change: 0.00.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal