Apple iPhone 3GS Gets Hacked in Pwn2Own Contest [Flaw in Safari Mobile Used to Steal SMS Messages From iPhone]

For the fourth consecutive year, the popular Pwn2Own competition was held at the CanSecWest Conference in Vancouver, BC. As part of the competition, a team or an individual is pitted against a device which, in the past, has included a MacBook running the latest version of Mac OS X and a fully-patched Windows 7 PC. The premise is simple – hack the target device remotely and you get to keep it. In addition to walking away with a shiny new device, the winner also receives a generous cash prize for their l33t hacking skills.

iphone 3gs 1This year’s competition included a mobile division with the Apple iPhone 3GS at the top of the list. The first round of competition in the mobile division was over before it even began with the iPhone 3GS giving up the contents of its SMS database in a mere 20 seconds. The winning team was comprised of Vincenzo Iozzo, a researcher at the security software firm Zynamics, and Ralf Philipp Weinmann,a postdoctoral researcher at the University of Luxembourg.The two men collaborated for a mere two weeks and were able to discover the vulnerability and code the exploit in an amazingly short time frame.

During the competition, the duo was able to point the iPhone’s web browser to a rigged website which remotely executed code that was designed to grab the entire contents of the SMS database and upload it to a remote server. According to Weinmann, though their exploit only targeted the SMS database, it could have been expanded to include the contacts list, email database, images, and iTunes music files. Basically, most of the sensitive and personal data on your iPhone could have pwned after visiting this malicious website.

As part of the competition the method for the pwn is turned over to the TippingPoint Zero Day Initiative who sponsors the competition. The exploit is analyzed and reported to the parent company of the device, which in this case is Apple. The details of the exploit will be released to the public once Apple has confirmed that it has patched the iPhone and closed the hole that allowed the exploit.

Source
You may also like:
Latest TFTS Headline News in
(TFTS has 11037 articles in this category)