<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iMore &#187; charlie miller</title>
	<atom:link href="http://www.imore.com/tag/charlie-miller/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imore.com</link>
	<description>More of everything iPhone and iPad</description>
	<lastBuildDate>Fri, 10 Feb 2012 08:57:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Charlie Miller to Demonstrate iPhone SMS Hack at Black Hat Conference Today</title>
		<link>http://www.imore.com/2009/07/30/charlie-miller-demonstrate-iphone-sms-hack-black-hat-conference-today/</link>
		<comments>http://www.imore.com/2009/07/30/charlie-miller-demonstrate-iphone-sms-hack-black-hat-conference-today/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 11:46:01 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[sms]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=10240</guid>
		<description><![CDATA[<a href="http://www.imore.com/images/stories/2009/07/hacking-into-iphone-sms.png"></a>

UPDATE: Some folks are telling is that this is an iPhone 2.2.1 exploit already patched in 3.0. We&#8217;ll wait for an update from Black Hat before we exhale, however&#8230;

<a href="http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/">Almost </a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.imore.com/images/stories/2009/07/hacking-into-iphone-sms.png"><img src="http://www.imore.com/images/stories/2009/07/hacking-into-iphone-sms-266x400.png" alt="hacking-into-iphone-sms" title="hacking-into-iphone-sms" width="266" height="400" class="aligncenter size-medium wp-image-9714" /></a></p>

<p>UPDATE: Some folks are telling is that this is an iPhone 2.2.1 exploit already patched in 3.0. We&#8217;ll wait for an update from Black Hat before we exhale, however&#8230;</p>

<p><a href="http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/">Almost a month ago</a> we linked to an Engadget report on <a href="http://www.imore.com/tag/charlie-miller">Charlie Miller</a> and his SMS exploit for the iPhone. Well, today is the day he intends to show it off at the <a href="https://www.blackhat.com/html/bh-usa-09/bh-usa-09-speakers.html#Miller">Black Hat conference</a>. </p>

<p>Thanks to some last minute <a href="http://www.wired.com/gadgetlab/2009/07/sms-hijack-iphone">media</a> <a href="http://www.forbes.com/2009/07/28/hackers-iphone-apple-technology-security-hackers.html">attention</a>, however, the general iPhone user base seems to be getting a tad nervous. And rightly so. We&#8217;ve said it before and we&#8217;ll say it again, in an ideal world, NSA expert come iHacker Charlie, who&#8217;s claim to current fame is using Mac exploits to win Pwn2own contests and free laptops, would work with companies like Apple and Microsoft (yes, it looks like <a href="http://www.wmexperts.com/ihacker-charlie-says-winmo-risk-too">Windows Mobile has an exploit as well</a>), and those companies would patch the exploits as immediately as possible, before any &#8220;research&#8221; was publicly disclosed and any bad guys decided to use them as attack vectors.</p>

<p>TiPb will update post-Miller&#8217;s Black Hack disclosure, and hopefully Apple will roll the security fix into a quick 3.0.2 firmware release, or hurry 3.1 out of the gate.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/07/30/charlie-miller-demonstrate-iphone-sms-hack-black-hat-conference-today/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>Jailbroken iPhones &#8211; Security Risk?</title>
		<link>http://www.imore.com/2009/07/03/jailbroken-iphones-security-risk/</link>
		<comments>http://www.imore.com/2009/07/03/jailbroken-iphones-security-risk/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 15:53:29 +0000</pubDate>
		<dc:creator>Jeremy Sikora</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9719</guid>
		<description><![CDATA[Turns out that if you jailbreak your iPhone you remove most of the Apple&#8217;s security protections &#8212; 80% to be exact &#8212; and are vulnerable to attacks. At least according]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2009/07/sadpirate.png" alt="sadpirate" title="sadpirate" width="273" height="336" class="aligncenter size-full wp-image-9720" /></p>

<p>Turns out that if you jailbreak your iPhone you remove most of the Apple&#8217;s security protections &#8212; 80% to be exact &#8212; and are vulnerable to attacks. At least according to <a href="http://www.imore.com/tag/charlie-miller/">Charlie Miller</a>:</p>

<blockquote>
  <p>“If you care about security, don’t use a jailbroken iPhone,” </p>
</blockquote>

<p>Miller, speaking at SyScan in Singapore, believes that by jailbreaking you open your device some major risks. The operating system on an iPhone is basically a watered down version of Mac OS X. For those of you who are unfamiliar with Macs, Mac OS X is the latest OS that Apple computers run. Macs are generally known for pretty risk-free machines with a few exceptions. Those exceptions being Java, Adobe Flash, and PDF files. The major risk on the iPhone is opening your device up to any application available on Cydia/Icy. iPhones will generally only run applications that are digitally signed by Apple, this is not the case when jailbroken. So if you don&#8217;t know what you are installing, there is a possibility you can be in for a world of hurt.</p>

<p>Of course just a few hours ago Rene told you about the huge <a href="http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/">vulnerability within the iPhone&#8217;s SMS application</a> that Charlie found, so nothing is completely safe.</p>

<p>Does this scare you away from jailbreaking your iPhone? Perhaps you are thinking about doing a restore and going legit from now on? Let us know if this warning from Charlie sways you to avoid the jailbreaking life!</p>

<p>[<em>Via <a href="http://www.macworld.com/article/141506/2009/07/jailbreak_security.html">Macworld</a></em>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/07/03/jailbroken-iphones-security-risk/feed/</wfw:commentRss>
		<slash:comments>47</slash:comments>
		</item>
		<item>
		<title>iHacker Charlie Discloses iPhone SMS Security Vulnerability</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/</link>
		<comments>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 11:12:25 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[black hat]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hackery]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sms]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713</guid>
		<description><![CDATA[<a href="http://www.imore.com/images/stories/2009/07/hacking-into-iphone-sms.png"></a>

In an ideal world, Mac and iPhone hacker <a href="http://www.imore.com/tag/charlie-miller">Charlie Miller</a> would discover vulnerabilities, inform Apple, and Apple would then patch them before they had any chance of being exploited &#8220;in]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.imore.com/images/stories/2009/07/hacking-into-iphone-sms.png"><img src="http://www.imore.com/images/stories/2009/07/hacking-into-iphone-sms-266x400.png" alt="hacking-into-iphone-sms" title="hacking-into-iphone-sms" width="266" height="400" class="aligncenter size-medium wp-image-9714" /></a></p>

<p>In an ideal world, Mac and iPhone hacker <a href="http://www.imore.com/tag/charlie-miller">Charlie Miller</a> would discover vulnerabilities, inform Apple, and Apple would then patch them before they had any chance of being exploited &#8220;in the wild&#8221;.</p>

<p>Miller, however, prefers to keep them to himself so he can win MacBooks and detail them at Black Hat conferences. The good of the hacker obviously outweighs the good of the users, every one. So be it.</p>

<p>Miller&#8217;s latest iPhone-related find was disclosed at SyScan in Signapore: </p>

<blockquote>
  <p>a hole that would let attackers &#8220;run software code on the phone that is sent by SMS over a mobile operator&#8217;s network in order to monitor the location of the phone using GPS, turn on the phone&#8217;s microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet.&#8221; </p>
</blockquote>

<p>Apple, for their part, is hoping to have this patched before Miller&#8217;s upcoming Black Hat gig.</p>

<p>We hope so too.</p>

<p>[via <a href="http://www.engadget.com/2009/07/02/apple-patching-nasty-iphone-sms-vulnerability/">Engadget</a>. Thanks Travis for the tip!]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Infamous Safari Security Cracker Finds Vulnerability-ish in iPhone OS?</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/</link>
		<comments>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 14:04:25 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120</guid>
		<description><![CDATA[Very little code is bullet-proof. Hackers will always find holes. The worst holes will be critical. The worst hacks will be zero-day and found in the wild &#8212; catching companies]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2008/11/macbook_stop_jailbreak.jpg" alt="" title="macbook_stop_jailbreak" width="500" height="300" class="aligncenter size-full wp-image-5295" /></p>

<p>Very little code is bullet-proof. Hackers will always find holes. The worst holes will be critical. The worst hacks will be zero-day and found in the wild &#8212; catching companies and users both by surprise.</p>

<p>Not sure we have any of that here. <a href="http://www.macworld.com/article/140039/2009/04/iphone_vulnerability.html">Macworld</a> does report that, at the Black Hat Europe Security Conference, former NSA number cruncher Charlie Miller &#8212; who has rolled his ability to find exploits in the Mac version of Apple&#8217;s Safari Browser into tens of thousands of dollars and a couple free MacBooks at the annual <a href="http://www.imore.com/2009/02/28/free-iphone-10000-prize-pwn2own/">Pwn2Own</a> contest &#8212; claims to have:</p>

<blockquote>
  <p>&#8230;found a way to trick the iPhone into running code that enables shellcode. To run shellcode on an iPhone, however, an attacker would first need a working exploit for an iPhone, or a way to target some software vulnerability in, for example, the Safari Web browser or the mobile’s operating system. Miller said he doesn’t have one now.</p>
</blockquote>

<p>Miller previously gained attention for a <a href="http://www.imore.com/2007/08/21/interview-with-charlie-miller/">Mobile Safari exploit</a> that made for some quick early jailbreaking and led to Apple patching the problem in firmware 1.0.1.</p>

<p>What&#8217;s particularly disturbing, however, is that Miller also says he&#8217;s unsure whether or not Apple knows about the potential vulnerability.</p>

<p>He should know that absolutely dead cold, of course. He should have told Apple <em>long</em> before he made the information public, and only made the information public when Apple had a fix rolled out or ignored his warnings for so long that public pressure could reasonably be considered the only option in getting them to roll out a fix.</p>

<p>Either way, Miller should <em>know</em> that Apple <em>knows</em> because he <em>told</em> them <em>first</em>. Or do we no longer warn people in a house when we see a potential fire starting, but wait and see how much attention and cash we can get for the info first?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached

Served from: imore.com @ 2012-02-10 07:08:56 -->
