On TechRepublic: 12 tech terms that make you sound old
BNET Business Network:
BNET
TechRepublic
ZDNet

July 2nd, 2009

iPhone executes SMS binary code as root

Posted by Jason D. O'Grady @ 1:58 pm

Categories: Security, iPhone, iPhone OS 3.0

Tags: Apple iPhone, SMS, DailyTech, Text Messaging/SMS/MMS, Telephony, Cellular Phones, Smart Phones, Consumer Electronics, Personal Technology, Online Communications

A security flaw has been discovered in the iPhone OS that could allow attackers to gain root access to the iPhone OS and allow them to install and execute malicious programs at will.

Charlie Miller announced the discovery of the vulnerability during a presentation at the SyScan conference in Singapore on Thursday. DailyTech explains:

The iPhone apparently automatically executes binary code sent in SMS messages.  Messages are limited to 140 bytes, but this is little deterrence as longer programs can be broken up into several messages, which the phone automatically reassembles.  While other applications such as the Safari browser on the phone only enjoy access to their sandbox, the SMS system is automatically granted root access, and SMS commands execute as root.

Miller wouldn’t provide specific details nor would he demonstrate the vulnerability stating that he has entered under an agreement with Apple. He’d only say, “SMS is a great vector to attack the iPhone.”

Update: Apple said that it will release a fix by the end July and Miller has agreed to hold off on releasing details of his attack until then. He will present the attack at the Black Hat USA 2009 conference which runs from July 25-30 in Las Vegas. Miller is the author of The Mac Hacker’s Handbook.

Jason D. O'GradyJason D. O'Grady is the editor of PowerPage.org, which has been publishing daily mobile technology news since December 1995. For disclosures on Jason's industry affiliations, click here or to view Jason's full profile click here.

Email Jason D. O'Grady

Subscribe to The Apple Core via Email alerts or RSS.

  • Talkback
  • Most Recent of 36 Talkback(s)
Yes, it could be a problem, IF...
someone knows you have an iPhone, and wants to send it to you.

There are well over 150,000,000 cell phones in the US. Do you think
someone is going to push hundreds of millions of text mes... (Read the rest)
Posted by: msalzberg Posted on: 07/04/09 You are currently: a Guest | | Terms of Use
why people go down the path  onepersonsopinion@... | 07/02/09
You're such a geek LOL grin  T1Oracle | 07/02/09
Don't listen to the voices in your head! happy  BillDem | 07/02/09
No need to worry  honeymonster | 07/02/09
No, iPhone is NOT UNIX based  NonZealot | 07/02/09
Actually, I think the logic is...  rapson | 07/02/09
Good point  NonZealot | 07/02/09
NZ Of course you know Charlie Miller is a Mac User right?  Davewrite | 07/02/09
Running as root is like opening the door  Herrie | 07/02/09
No OS is secure, particularly when running as Root  BillDem | 07/02/09
naw....  JoeMama_z | 07/02/09
Does this mean that iPhone OS is flawed by design?  NonZealot | 07/02/09
Just a flawed feature I think  Herrie | 07/02/09
In other words its a huge oversight and yet another Apple security fail  T1Oracle | 07/02/09
Bingo! Give the man the prize.  BillDem | 07/02/09
One documented security issue  athynz | 07/03/09
No, 96 (this will be 97th) documented security issues  honeymonster | 07/03/09
I think I would get a little suspicious  frgough | 07/02/09
Nothing to see, move along now!  NonZealot | 07/02/09
Whay appologize for Apple  John Zern | 07/02/09
To be on the safe side....  oncall | 07/02/09
Don't forget to move it away from flammable objects  NonZealot | 07/02/09
Hey heres an idea...  oncall | 07/02/09
Here's an idea for a new iPhone app  eMJayy | 07/02/09
ROFL!!  NonZealot | 07/02/09
Alright. Now...  wrenchy | 07/02/09
IT'S A FEATURE!!!!  athynz | 07/03/09
The only documented security issue?  honeymonster | 07/03/09
AntiVirus for your Phone? There is an App for that.  JoeMama_z | 07/02/09
late to the party  voyager529 | 07/02/09
Nothing wrong with root, really  honeymonster | 07/03/09
Why the claims of being *nix makes me laugh  NonZealot | 07/03/09
Oh. Joy.  HypnoToad72 | 07/03/09
I don't know about you...  msalzberg | 07/03/09
Use your imagination  honeymonster | 07/03/09
Yes, it could be a problem, IF...  msalzberg | 07/04/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here