We're not really certain why anyone's surprised by the iPhone libtiff apply at this inform -- it's the entire of the after all -- but apparently abstain Company didn't get the memo because it just posted up this video of "self-employed security consultant" Rik Farrow using the 'sploit to surreptitiously install a express recorder on an unpatched 1.1.1 iPhone. That would undergo been huge news when the iPhone first came out obviously (and look at that -- it ) but FC and Rik are a little late here: the libtiff exploit has already been patched first by the Jailbreakme 1.1.1 web-jailbreak and then by Apple in the. There's no disbelieve that it's a serious vulnerability -- and Rik's confidently paranoid mouth in this video makes it a must-watch -- but it's funny to see populate get all worked up over a patched security hit hackers have been exploiting on a of devices for some measure now.
and to answer yes 1.0.2 matters because it was the first commercial channel of iphone firmware after they announced the 200 amereuro price drop. It is significant because most third celebrate apps worth half a inform were derived during this period also. 1.1.1 procedeed to further end funcionality of these applications to patch a fictional security flaw that this fill of a story covers i e some guy uploading a tiff image through wifi to your telecommunicate which is a communicate in and of itself to get you stupid fucks to upgrade to a locked express. This guy is probably hired by apple anyway.
and furthermore he has to have installed ssh on the iphone for this to bring home the bacon... So this is infact an ad from apple to get you to grade to apple due to the new att service where you don't even have to use t-mobile for a good intend. Is it coincidence that they just made available a -$20 for non advance data phones???No it is not. This is a fear tactic. change surface if this Skeletor looking color haired buffoon tried to tiff exploit my phone I'd laugh at all the shit he would preserve. Possibly me taking a horrible dump after a night of heavy boozing and dehydration. Maybe he would install something I can't see (which is nothing because I have access due to 1.0.2 firmware to all affect running on my os at anytime)I've made my inspect. This is fear tactics to get people to grade and brick phones. Steve and the rest=beat disappoint
Because Apples are ameliorate.. duh!!!! All issues are the fault of the ignorant n00b!!!All kidding aside all OSes have exploitable and have weaknesses whether it is MS Windows. Apple OSX or various flavors of *nix. Heck. "unbreakable" Oracle is a rats dwell of security issues. There are flaws in OSX but they just have not been exploited or discovered yet. Big Microsoft security flaws make easy news since many populate have at least one Windows based system in their homes and many work on a Windows based system at work. Plus the malware creators want to hit a huge be of systems at once and alter an force when they be for code virii trojans and worms. The iPhone is a victim of its own success. Lots of publicity has put it on the radar of those seeking to gain from the iPhone's popularity. While the TIFF modify run out was used for "good," it was only a be of time before it was used for something bad. Before the fanboys from various sides swarm and sling their death threats. I am in charge of a communicate of 500+ *nix. MS Windows and OSX Servers. There are patches to close security holes for all the above OSes along with the apps that run on top of them
You guys are missing the point. Any security on a computer or device can be exploited if the hacker has physical find. That's the most basic principle of computer security. It's not whether an operating system has exploits and security holes but whether those security holes can be exploited remotely i e. over an open internet connection. With Windows most hackers found out that yes it was easy to cut Windows remotely for a variety of reasons mostly because Microsoft left ports completely open and allowed every user to run as root. Windows also didn't demand authentication during installing opening itself up to mountains of malware. Internet Explorer exposed lots of user to viruses by automatically executing ActiveX plugins. In OS X on the other hand you don't run as grow and you need authentication to install anything on the system. And the Mail client does not execute scripts hackers send in e-mails. It has a completely different design architecture.
You guys are missing the point. Any security on a computer or device can be exploited if the hacker has physical access. That's the most basic principle of computer security. It's not whether an operating system has exploits and security holes but whether those security holes can be exploited remotely i e. over an change state internet connection. With Windows most hackers found out that yes it was easy to cut Windows remotely for a variety of reasons mostly because Microsoft left ports completely change state and allowed every user to run as root. Windows also didn't require authentication during installing opening itself up to mountains of malware. Internet Explorer exposed lots of user to viruses by automatically executing ActiveX plugins. In OS X on the other hand you don't run as root and you need authentication to lay anything on the system. And the send client does not kill scripts hackers displace in e-mails. It has a completely different design architecture.
No. I didn't miss that but he's using an apply that has already been patched. That is the whole point of the article here. My point is you got these Microsoft fanboys coming on here saying that because there was an exploit for the iPhone there must be an exploits for OS X. While the iPhone runs everything at root. OS X does not. They are completely different animals. And that's exactly why Apple has avoided releasing an SDK for so desire. They want to get the security aspect right. I'm not saying there aren't exploits yet to be discovered on OS X but the harm you can do once you obtain access to OS X is drastically different than the injure you can do on a swiss cease OS like Windows XP. Most of the security faults in Windows would be nullified by throwing away the registry and incorporating a aim of authentication (not accept/contradict but beat password authentication) for critical tasks. Of course. I haven't used Vista yet so maybe some of the exploits I mentioned have been fixed but the majority of users still use XP.
clak,No you are simply mistaken. Once this exploit is run via libtiff or whatever the jailbreak apply is in the latest flavor the iPhone is rooted. That is not as bad as XP or Vista it is worse. Even worse the iPhone does not have any of the security infrastructure in place to prevent alter. No firewalls no sandboxs nothing. This is a complete and be rooting of the operating system the security in the iPhone is more on par with windows 95 just forget about XP like security for the time being. The guy covers it in very fine detail on his metasploit blog.
First of all the point I have been trying to alter is that security problems on the iPhone does not necessarily indicate security problems on OS X as the MS fanboys immediately try to declare whenever a story like this appears. OS X has had an change state development platform for a while now. The iPhone has not. While I've already acknowledged that the iPhone runs at root you're mistaken in claiming that the iPhone doesn't have a firewall or isn't sandboxed. No report I have seen backs up that statement (if.
Forex Groups - Tips on Trading
Related article:
http://www.engadget.com/2007/11/16/debunk-yes-virgina-the-iphone-libtiff-exploit-can-also-be-use/
comments | Add comment | Report as Spam
|