Home | Sign up for newsletters!

About

Advanced Search

Mobile & Wireless

"Jail broken" iPhones hacked by new virus

iPhones with disabled pre-installed security features at risk

      

BOSTON (Reuters) - Hackers have built a virus that attacks Apple Inc's iPhone by secretly taking control of the devices via their Internet connections, security experts said.


The virus has been detected in the Netherlands and can only attack iPhones whose users have disabled some pre-installed security features, according to analysts monitoring the progress of the virus.

The hackers are trying to use the virus to obtain passwords to banking sites, according to Graham Cluley, a researcher with anti-virus software maker Sophos. When an iPhone user tries to access a bank website, the Duh Worm directs the browser to a look-a-like site controlled by the hackers, Cluley said.

A spokeswoman for ING Group said the Dutch banking giant discovered a criminal network that attempted to steal banking credentials via hacked iPhones. Dutch clients of ING have been targeted, but there was no indication that clients outside the Netherlands have to worry, she said.

ING has not received any reports from clients that their credentials have been lost, but the bank was monitoring client accounts for suspicious transactions, the spokeswoman said.

The only iPhones that are vulnerable to the Duh Worm are "jail broken" phones, where users disable key Apple security features to get around the terms of usage agreement that they are designed to enforce, analysts said.

For example, Apple prevents users from switching service providers to unauthorized carriers and limits users to the approximately 100,000 programs that the company has vetted for installation on the device. There are thousands of unauthorized programs covering areas including Internet phone calls, WiFi access and pornography.

"The vast majority of customers do not jailbreak their iPhones, and for good reason. These hacks not only violate the warranty, they will also cause the iPhone to become unstable and not work reliably," said Apple spokeswoman Natalie Harrison.

Three independent security experts said that it is best for iPhone users not to jail break their devices because the security risks are greater than the benefits.

"They're leaving their back door open. Every one else knows what the key is to open that door," Cluley said.

The ING spokeswoman said: "People who use their iPhones in a regular way have nothing to fear."

The case, which was widely reported by security experts on Monday, is the first in which iPhones have been recruited into a "botnet," or army of infected devices that hackers can control from a central "command and control center."

Early this year an unknown criminal gang built a botnet with millions of PCs using a worm known as Conficker. Security researchers feared that it might wreak havoc on April 1 based on code in the worm's software, but that date passed with little fanfare.

Since then, security researchers say that a limited number of Conficker-infected PCs have been used to spread spam, sell fake anti-virus software and perpetrate identity theft.

Mikko Hypponen, an expert on Conficker and chief research officer for security software maker F-Secure, said that Duh could spread from the Netherlands to other countries.

Like the authors of Conficker, the hackers who wrote Duh are motivated to spread the worm because they too are looking for a payoff from their work, he said.

"It's clearly written to make money. That's a first on the mobile side," Hypponen said.

To be sure, iPhones that have not been jail broken face their own security challenges. Yet so far Apple has been able to stay ahead of the hackers.

In July the company issued a software patch to fix a critical bug uncovered by two researchers that made the device susceptible to secret attacks using the SMS system, which mobile devices use to send text messages.

Apple shares rose 3 percent on Monday to $205.88 on the Nasdaq.

The M2M Switch - turning the wireless business model upside down -- September 1, 2010

Vivendi raises 2010 goals after strong first-half results -- September 1, 2010

FCC cuts off free nationwide broadband potential indefinitely -- September 1, 2010

Shipments of Bluetooth, NFC, UWB, 802.15.4 and Wi-Fi ICs will increase 20% in 2010 -- September 1, 2010

3PAR claims widespread uptake for VMware 'vSphere' service -- August 31, 2010

Related articles:

The M2M Switch - turning the wireless business model upside down -- September 1, 2010
While global telecom operators, systems integrators, and enterprises wrestle with Machine-to-Machine, they may struggle to contain a tide that has only just begun to rise. The power of supply chain automation, ubiquitous connectivity, and pervasive computing are so strong, we may already have traversed a threshold into a radically new paradigm in the communications industry, one in which waves of innovation, new economies of scale, and sheer business logic will prevail. While no crystal ball can show us the future of network evolution, we can revisit milestones of technological progress and shed light on the path ahead.

Vivendi raises 2010 goals after strong first-half results -- September 1, 2010
Europe's largest telecom and entertainment group, Vivendi, raised its profit targets on the back of forecast-beating first-half results and reassured investors on its acquisition strategy, lifting its flagging stock.

Shipments of Bluetooth, NFC, UWB, 802.15.4 and Wi-Fi ICs will increase 20% in 2010 -- September 1, 2010
The market for short range wireless ICs is forecast to expand this year; total shipments of Bluetooth, NFC, UWB, 802.15.4 and Wi-Fi ICs will increase approximately 20% compared to 2009. “Bluetooth ICs still lead the short-range wireless IC market,” says ABI Research industry analyst Celia Bo. “Unit shipments are expected to exceed 58% of the total short-range wireless IC shipments in 2010.

3PAR claims widespread uptake for VMware 'vSphere' service -- August 31, 2010
Today at VMworld 2010, 3PAR announced that cloud computing market leaders in the Infrastructure-as-a-Service (IaaS) and Software-as-a-Service (SaaS) segments have combined the 3PAR InServ Storage Server with VMware vSphere to build cloud infrastructures for their shared, virtualized "utility" service offerings.

M2M Zone Keep up with the latest in Machine-to-Machine Communications:

Read M2M Newsdesk
News, research, show coverage and more, covering the M2M industry.

Visit the M2M Zone
M2M Zone Seminars offer the latest information, directly from industry leaders and experts. The M2M Zone is a fixture at top-shelf trade shows including CeBIT and CTIA Wireless. Learn more about what the M2M Zone offers.


Horizon House Network
Microwave Journal
Wireless & RF News


BVD Electronic Publishing
Hosting & Development

Advertisement

©2010 Telecommunications Online & Horizon House Publications®.

 
Home | NewsGlobe | Events | Contact Us | Register | About Us | Advertise

All rights reserved. Privacy Policy.

Advertisement




Let the news come to you
Sign up for newsletters!