Jump to content

225,000 iPhones HACKED with Jailbreak Malware

Source: TNW News
Original Source: Palo Alto Networks

 

jailbreak-iOS.jpg

So this is a funny and scary one for me. A malware called KeyRaider was apparently inserted into a build of Cydia, which is a popular iOS Jailbreaking app. The app is designed to help the non-tech savvy tweak their iOS devices.

Researchers estimate ~225,000 VALID Apple IDs were compromised with out the users having any idea. The credentials were then uploaded to a server which the researchers were able to gain access to via, get this...SQL Injection! Yes good ol' easily avoided by database input validation/sanitation, responsible for dozens of major corporate hacks, are you serious why is this still a common attack vector... SQL Injection.

exploits_of_a_mom.png

Apparently only the jailbreakings apps distrubuted from the Weiphone Cydia repositories contained the malware. But this points out a huge issue with Jailbreaking or running any 3rd party software in what's supposed to be closed environment. Similar events have happened with Android ROMs/Rootkits, free/open source encryption software etc...

A while back a popular game hack service allegedly released a hacked version of their own software which would format the drives of users that installed the "stolen" version of their already nefarious software. You can find thousands of video and text/picture guides on how to root/jailbreak devices and crack software for free use. Question is what hidden little bytes of data are you unknowingly giving access to some of your most important information?

Will this stop any of you from rooting, jailbreaking or using cracked software/games. Do you guys ever use checksums to ensure the validity of the 3rd party or open-source software you install?

FX-8350 | Asus Sabertooth 990fx r2.0 | 16 GB (2x8 1600Mhz) Corsair Vengeance | EVGA GeForce GTX 770 SC Dual | Corsair Vengeance C70 | 120GB Samsung EVO SSD, 1TB WD Black | Corsair AX860i | 2x BenQ XL2420TE | Corsair H110 | Logitech G15 | Logitech G500 | Creative Sound Blaster Z | Windows 8.1

Link to comment
Share on other sites

Link to post
Share on other sites

APPLE PRODUCTS CAN GET VIRUSES

HAHAHAHAHAHHAHA

take that people who say apple products cant get viruses >: D 

Link to comment
Share on other sites

Link to post
Share on other sites

Hahaha, sucks to suck.

Want total control over your iphone like all the andriod users? Easy, just download this hack and infect your phone!

Updated 2021 Desktop || 3700x || Asus x570 Tuf Gaming || 32gb Predator 3200mhz || 2080s XC Ultra || MSI 1440p144hz || DT990 + HD660 || GoXLR + ifi Zen Can || Avermedia Livestreamer 513 ||

New Home Dedicated Game Server || Xeon E5 2630Lv3 || 16gb 2333mhz ddr4 ECC || 2tb Sata SSD || 8tb Nas HDD || Radeon 6450 1g display adapter ||

Link to comment
Share on other sites

Link to post
Share on other sites

APPLE PRODUCTS CAN GET VIRUSES

HAHAHAHAHAHHAHA

take that people who say apple products cant get viruses >: D 

If these people had used their Apple products the correct way, this would never have happened. :P

I once had one of these, now I've got this.

Link to comment
Share on other sites

Link to post
Share on other sites

If these people had used their Apple products the correct way, this would never have happened. :P

still got hacked :D

Link to comment
Share on other sites

Link to post
Share on other sites

HAHAAHHAHAHAHAHAHAAH

good thing I went swimming with my iphone 3 weeks ago !

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

APPLE PRODUCTS CAN GET VIRUSES

HAHAHAHAHAHHAHA

take that people who say apple products cant get viruses >: D 

 

True, but it isn't that much of a feat when the end user has done something not vouched by the manufacturer....

Link to comment
Share on other sites

Link to post
Share on other sites

muahahahaha.... *strokes zenfone 2*

That's what they get for shit-talking Android.

ZENFONE BUDDIES UNITE

 

the funny thing is is that apple used to be mostly clean from viruses because they were not the majority of the consumer market. well that has changed

My Rig  

 
PCPartPicker part list: http://ca.pcpartpicker.com/p/kGNksY

 

CPU: Intel Core i7-4770 3.4GHz Quad-Core Processor  ($379.00 @ shopRBC) 

CPU Cooler: RAIJINTEK THEMIS 65.7 CFM Sleeve Bearing CPU Cooler  ($34.99 @ NCIX) 

Motherboard: MSI CSM-H87M-G43 Micro ATX LGA1150 Motherboard  ($78.83 @ DirectCanada) 

Memory: Kingston HyperX 16GB (4 x 4GB) DDR3-1600 Memory  ($139.99 @ Memory Express) 

Storage: Kingston Fury 120GB 2.5" Solid State Drive  ($71.34 @ DirectCanada) 

Storage: Seagate Barracuda 2TB 3.5" 7200RPM Internal Hard Drive  ($92.95 @ Vuugo) 

Video Card: Gigabyte Radeon R9 280X 3GB Video Card  ($298.98 @ Newegg Canada) 

Case: Fractal Design Define R4 w/Window (Black Pearl) ATX Mid Tower Case  ($125.98 @ Newegg Canada) 

Power Supply: Corsair CX 600W 80+ Bronze Certified Semi-Modular ATX Power Supply  ($66.99 @ NCIX) 

Operating System: Microsoft Windows 8.1 - 64-bit (OEM) (64-bit)  ($116.00 @ shopRBC) 

Case Fan: Cougar Turbine 120 (4-Pack) 60.4 CFM 120mm  Fans  ($23.99 @ NCIX) 

Monitor: HP 22xi 60Hz 21.5" Monitor  ($187.11 @ Amazon Canada) 

Monitor: HP 22xi 60Hz 21.5" Monitor  ($187.11 @ Amazon Canada) 

Keyboard: Logitech G710 Wired Gaming Keyboard  ($114.99 @ NCIX) 

Mouse: Razer DeathAdder 2013 Wired Optical Mouse  ($76.99 @ Amazon Canada) 

Headphones: Kingston HyperX Cloud Pro Headset  ($78.98 @ DirectCanada) 

Total: $2074.22

Prices include shipping, taxes, and discounts when availableGenerated by PCPartPicker 2015-04-10 15:33 EDT-0400Build log http://linustechtips.com/main/topic/303263-the-dell-from-hell/#entry4121100 

Phone Compassion Spreadsheet https://docs.google.com/spreadsheets/d/1EN6s426gyxqPloIqT4wQ7Y7yovkkQy_5B3djVN-N-R8/edit#gid=0


Gta V Pc Online Crew http://linustechtips.com/main/topic/344773-unofficial-linus-tech-tips-gta-v-crew-pc/

Link to comment
Share on other sites

Link to post
Share on other sites

You can crash the OS with a single string of digits.

Which has already been fixed. The reason these accounts where hijacked is that users used software that wasn't certified by Apple. Something like this would have never happened with an application downloaded from Apples appstore, since every app and every app update has to be approved by Apple. I'm definitly not saying that iPhones are invincible to malware, but still it's much more unlikely to catch malicious software on iOS than on Android.

I once had one of these, now I've got this.

Link to comment
Share on other sites

Link to post
Share on other sites

I'm definitly not saying that iPhones are invincible to malware, but still it's much more unlikely to catch malicious software on iOS than on Android.

 Android and iOS are both based on operating systems designed in such a way so as to catch malware at multiple levels. iOS is no more adept at finding and preventing malware problems than Android.

Link to comment
Share on other sites

Link to post
Share on other sites

This is why you shouldn't use other, untrusted sources inside of cydia when you have a jailbroken iPhone. This includes piracy repositories

"If a Lobster is a fish because it moves by jumping, then a kangaroo is a bird" - Admiral Paulo de Castro Moreira da Silva

"There is nothing more difficult than fixing something that isn't all the way broken yet." - Author Unknown

Spoiler

Intel Core i7-3960X @ 4.6 GHz - Asus P9X79WS/IPMI - 12GB DDR3-1600 quad-channel - EVGA GTX 1080ti SC - Fractal Design Define R5 - 500GB Crucial MX200 - NH-D15 - Logitech G710+ - Mionix Naos 7000 - Sennheiser PC350 w/Topping VX-1

Link to comment
Share on other sites

Link to post
Share on other sites

if they had bought android. They would never have needed to jailbreak the phone in the first place... so HA!!!!

Glad I'm not getting an iPhone xD

Link to comment
Share on other sites

Link to post
Share on other sites

What's that? Apple is just as vulnerable as everyone else, and not so high and mighty as they think they are?

nelson-muntz-haw-haw.png

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

I don't get it why people say the iphone in general is vulnerable when the post clearly states that they were jailbroken, thus had a modded os on them.
If I buy a nice VW then somehow manage to slap a 800 HP engine in there (something youre NOT intended to do by VW) and then go with 250km/h when suddenly my car falls apart and the brakes malfunction I can't say: This is VWs fault and all VW are really bad cars because my 1 week old one broke down on the second drive.

System:
CPU: I7-3610QM @ 2.3 GHz | Motherboard: something with chips | RAM: 8 Gb of something | GPU: AMD HD 7600M | Case: Something made out of plastic | Storage: Toshiba MQ01ABD075 750GB | PSU: something external | Display(s): something glowing | Cooling: jet engine | Keyboard: hama something | Mouse: Logitech something | Sound: Traktor Kontrol S2 as soundcard, AKG K500 Headphones | Operating System: Windoof 10

Link to comment
Share on other sites

Link to post
Share on other sites

Idk why youd jailbreak an iPhone in the first place, if youre into customisability and being able to tweak anything you want, you probably should have gotten an Android device with a custom ROM instead.

 

Only time I tinkered with my iPhone was when I had the iPhone 4 and jailbroke it to get iOS 7 early, but that was way back.

4690K // 212 EVO // Z97-PRO // Vengeance 16GB // GTX 770 GTX 970 // MX100 128GB // Toshiba 1TB // Air 540 // HX650

Logitech G502 RGB // Corsair K65 RGB (MX Red)

Link to comment
Share on other sites

Link to post
Share on other sites

What's that? Apple is just as vulnerable as everyone else, and not so high and mighty as they think they are?

snip

mah boi NELSON

 

NELSON-vi.gif

4690K // 212 EVO // Z97-PRO // Vengeance 16GB // GTX 770 GTX 970 // MX100 128GB // Toshiba 1TB // Air 540 // HX650

Logitech G502 RGB // Corsair K65 RGB (MX Red)

Link to comment
Share on other sites

Link to post
Share on other sites

 

APPLE PRODUCTS CAN GET VIRUSES

HAHAHAHAHAHHAHA

take that people who say apple products cant get viruses >: D 

 

 

What's that? Apple is just as vulnerable as everyone else, and not so high and mighty as they think they are?

 

 

Well yes. Jailbreaking an iPhone does indeed remove most of the aspects of iOS that are inherent in its superior security over Android.

 

It would be like giving everything in Linux root access and then claiming that it's clearly not more secure than Windows when that inevitably ends badly.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×