<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iMore &#187; vulnerabilities</title>
	<atom:link href="http://www.imore.com/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imore.com</link>
	<description>More of everything iPhone and iPad</description>
	<lastBuildDate>Sun, 27 May 2012 07:29:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Infamous Safari Security Cracker Finds Vulnerability-ish in iPhone OS?</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/</link>
		<comments>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 14:04:25 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120</guid>
		<description><![CDATA[Very little code is bullet-proof. Hackers will always find holes. The worst holes will be critical. The worst hacks will be zero-day and found in the wild -- catching companies]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2008/11/macbook_stop_jailbreak.jpg" alt="" title="macbook_stop_jailbreak" width="500" height="300" class="aligncenter size-full wp-image-5295" /></p>

<p>Very little code is bullet-proof. Hackers will always find holes. The worst holes will be critical. The worst hacks will be zero-day and found in the wild -- catching companies and users both by surprise.</p>

<p>Not sure we have any of that here. <a href="http://www.macworld.com/article/140039/2009/04/iphone_vulnerability.html">Macworld</a> does report that, at the Black Hat Europe Security Conference, former NSA number cruncher Charlie Miller -- who has rolled his ability to find exploits in the Mac version of Apple's Safari Browser into tens of thousands of dollars and a couple free MacBooks at the annual <a href="http://www.imore.com/2009/02/28/free-iphone-10000-prize-pwn2own/">Pwn2Own</a> contest -- claims to have:</p>

<blockquote>
  <p>...found a way to trick the iPhone into running code that enables shellcode. To run shellcode on an iPhone, however, an attacker would first need a working exploit for an iPhone, or a way to target some software vulnerability in, for example, the Safari Web browser or the mobile’s operating system. Miller said he doesn’t have one now.</p>
</blockquote>

<p>Miller previously gained attention for a <a href="http://www.imore.com/2007/08/21/interview-with-charlie-miller/">Mobile Safari exploit</a> that made for some quick early jailbreaking and led to Apple patching the problem in firmware 1.0.1.</p>

<p>What's particularly disturbing, however, is that Miller also says he's unsure whether or not Apple knows about the potential vulnerability.</p>

<p>He should know that absolutely dead cold, of course. He should have told Apple <em>long</em> before he made the information public, and only made the information public when Apple had a fix rolled out or ignored his warnings for so long that public pressure could reasonably be considered the only option in getting them to roll out a fix.</p>

<p>Either way, Miller should <em>know</em> that Apple <em>knows</em> because he <em>told</em> them <em>first</em>. Or do we no longer warn people in a house when we see a potential fire starting, but wait and see how much attention and cash we can get for the info first?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>

