<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iMore &#187; vulnerability</title>
	<atom:link href="http://www.imore.com/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imore.com</link>
	<description>More of everything iPhone and iPad</description>
	<lastBuildDate>Fri, 10 Feb 2012 15:18:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Timestamp security bug leaves your photos vulnerable under iOS 5</title>
		<link>http://www.imore.com/2012/01/04/timestamp-security-bug-leaves-photos-vulnerable-ios-5/</link>
		<comments>http://www.imore.com/2012/01/04/timestamp-security-bug-leaves-photos-vulnerable-ios-5/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 16:48:22 +0000</pubDate>
		<dc:creator>Allyson Kazmucha</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[camera]]></category>
		<category><![CDATA[cnet]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[gallery]]></category>
		<category><![CDATA[ios 5]]></category>
		<category><![CDATA[peekay]]></category>
		<category><![CDATA[security holes]]></category>
		<category><![CDATA[timestamp]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.tipb.com/?p=89812</guid>
		<description><![CDATA[<a href="http://cdn.imore.com/images/stories//2012/01/IMG_1011.png"></a>

A newly discovered timestamp security bug may leave your iOS device photos exposed regardless of whether or not your device is passcode locked. Ade Barkah, a Canadian tech consultant, has]]></description>
			<content:encoded><![CDATA[<p><a href="http://cdn.imore.com/images/stories//2012/01/IMG_1011.png"><img src="http://cdn.imore.com/images/stories//2012/01/IMG_1011-373x560.png" alt="" title="iOS 5 camera toggle homescreen" width="373" height="560" class="aligncenter size-medium wp-image-89814" /></a></p>

<p>A newly discovered timestamp security bug may leave your iOS device photos exposed regardless of whether or not your device is passcode locked. Ade Barkah, a Canadian tech consultant, has figured out that changing the time on your device will leave any photo taken in the &#8220;future&#8221; accessible via the quick camera toggle on the home screen. </p>

<p>The quick toggle is a new feature in <a href="http://www.imore.com/ios">iOS 5</a> that allows you to double tap your home button to access your camera app. From there you can tap into your image gallery. If your device is passcode locked, you will receive a message asking you to unlock your device to view photos. Unless you change the time on your device. Anything taken after that time stamp will be viewable as the phone will assume nothing exists after that point in time.</p>

<blockquote>
  <p>Turns out Apple’s restriction is just a simple filter based on the timestamp when the Camera app was invoked.  You’re allowed to see all images with a timestamp greater than this invocation time.  Yet that leads to an immediate hole: if your iPhone’s clock ever rolls back, then all images with timestamps newer than your iPhone’s clock will be viewable from your locked phone.</p>
</blockquote>

<p>This could be a potential issue for anyone that travels frequently or has a need to change timezones. You can test this by simply changing the time and popping into your quick toggle even when the device is locked. Better get to deleting those inappropriate pictures!</p>

<p>Source: <a href="http://peekay.org/2011/12/31/incorrect-time-setting-could-leak-ios-5-album-pictures/">Peekay.org</a> via <a href="http://news.cnet.com/8301-27080_3-57351461-245/time-stamp-bug-exposes-photos-on-locked-iphone/">CNET</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2012/01/04/timestamp-security-bug-leaves-photos-vulnerable-ios-5/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Skype admits to iPhone app security problem, releasing a fix &#8220;soon&#8221;</title>
		<link>http://www.imore.com/2011/09/21/skype-admits-iphone-app-security-problem-releasing-fix/</link>
		<comments>http://www.imore.com/2011/09/21/skype-admits-iphone-app-security-problem-releasing-fix/#comments</comments>
		<pubDate>Wed, 21 Sep 2011 20:42:37 +0000</pubDate>
		<dc:creator>Andrew Wray</dc:creator>
				<category><![CDATA[App Store Apps]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[skype]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.tipb.com/?p=75681</guid>
		<description><![CDATA[<a href="http://www.imore.com/2010/12/30/skype-iphone-hits-30-adds-video-calling/photo-207/" rel="attachment wp-att-51211"></a>

Skype has stated they are aware of a serious cross-site scripting vulnerability within the chat feature for Skype on the iPhone.  The security hole could allow for malicious JavaScript code]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.imore.com/2010/12/30/skype-iphone-hits-30-adds-video-calling/photo-207/" rel="attachment wp-att-51211"><img src="http://cdn.imore.com/images/stories//2010/12/photo8-266x400.png" alt="Skype for iPhone hits 3.0, adds video calling" title="Skype for iPhone hits 3.0, adds video calling" width="266" height="400" class="aligncenter size-medium wp-image-51211" /></a></p>

<p>Skype has stated they are aware of a serious cross-site scripting vulnerability within the chat feature for Skype on the iPhone.  The security hole could allow for malicious JavaScript code to access to your address book and is known to affect versions 3.0.1 and below.  </p>

<p>Skype reached out to TechCrunch to say they&#8217;re hard at work on getting an update pushed to the App Store.</p>

<blockquote>
  <p>We are working hard to fix this reported issue in our next planned release which we hope to roll out imminently. In the meantime we always recommend people exercise caution in only accepting friend requests from people they know and practice common sense internet security as always.</p>
</blockquote>

<p>The funny thing is, Skype has known about the issue for a while now.  AppSec Consulting security researcher Phil Purviance helped discover the problem and let Skype know about it almost a month ago.  Skype responded saying they would release an update earlier this month, but we&#8217;re nearing the end of September and there&#8217;s no update to be found. </p>

<p>Here&#8217;s hoping Skype gets on this quick and pushes out an update soon, but in the meantime check out the video below detailing how the vulnerability works.</p>

<p>[<a href="https://superevr.com/blog/2011/xss-in-skype-for-ios/">superevr</a>, <a href="http://techcrunch.com/2011/09/20/skype-aware-of-xss-vulnerability-in-ios-apps-working-hard-to-fix-it/">TechCrunch</a>]</p>

<p><span id="more-75681"></span></p>

<p><object width="560" height="315"><param name="movie" value="http://www.youtube.com/v/Ou_Iir2SklI?version=3&amp;hl=en_US"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/Ou_Iir2SklI?version=3&amp;hl=en_US" type="application/x-shockwave-flash" width="560" height="315" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2011/09/21/skype-admits-iphone-app-security-problem-releasing-fix/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Want a Free iPhone and $10,000 Prize? Pwn2Own it!</title>
		<link>http://www.imore.com/2009/02/28/free-iphone-10000-prize-pwn2own/</link>
		<comments>http://www.imore.com/2009/02/28/free-iphone-10000-prize-pwn2own/#comments</comments>
		<pubDate>Sat, 28 Feb 2009 14:21:55 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=7305</guid>
		<description><![CDATA[<a href="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009">Pwn2Own</a> is a hacking contest which in previous years demanded OS exploits on day one, allowed browser vectors on day two (how OS X was compromised last year &#8212; thanks]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2008/11/macbook_stop_jailbreak.jpg" alt="" title="macbook_stop_jailbreak" width="500" height="300" class="aligncenter size-full wp-image-5295" /></p>

<p><a href="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009">Pwn2Own</a> is a hacking contest which in previous years demanded OS exploits on day one, allowed browser vectors on day two (how OS X was compromised last year &#8212; thanks Safari!), and opened the floodgates with 3rd party bugware on day three. First person to successfully hack a machine won it as a prize, along with a nice cash bounty for their troubles.</p>

<p>This year, <a href="http://arstechnica.com/gadgets/news/2009/02/pwn2own-contest-will-target-browsers-and-mobile-devices.ars">Ars Technica</a> says Pwn2Own is doing something a little different: they&#8217;re bringing in the mobiles!</p>

<p>Apple&#8217;s iPhone is front and center on their target list, along with the Google Android G1, and devices from the BlackBerry, Symbian, and Windows Phone families. Pwn the mobile and you not only win it, but $10,000 to boot!</p>

<p>Not a lot of solid info on the rules yet, but we&#8217;ll keep a look out. Any white hats out there eager to try their luck?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2009/02/28/free-iphone-10000-prize-pwn2own/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>ZOMG! Ziphone Dude Crashing iPhones With Malicious Audio Code?</title>
		<link>http://www.imore.com/2008/11/03/zomg-ziphone-dude-crashing-iphones-malicious-audio-code/</link>
		<comments>http://www.imore.com/2008/11/03/zomg-ziphone-dude-crashing-iphones-malicious-audio-code/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 23:11:26 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[ziphone]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=5286</guid>
		<description><![CDATA[<a href="http://www.forbes.com/technology/2008/11/03/apple-iphone-bug-tech-security-cz_tb_1103iphone.html">Forbes.com</a> (via <a href="http://www.tuaw.com/2008/11/03/ziphone-author-demos-iphone-crash-to-forbes/">TUAW</a>) is claiming Ziphone jailbreak author Piergiorgio Zambrini has found a way to crash the iPhone (and other computer systems, according to Zambrini&#8217;s own <a href="http://www.zibri.org/2008_10_26_archive.html#6408091360728069954">website</a>) using]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2008/08/sadpirate.png" alt="" title="sadpirate" width="273" height="336" class="aligncenter size-full wp-image-3641" /></p>

<p><a href="http://www.forbes.com/technology/2008/11/03/apple-iphone-bug-tech-security-cz_tb_1103iphone.html">Forbes.com</a> (via <a href="http://www.tuaw.com/2008/11/03/ziphone-author-demos-iphone-crash-to-forbes/">TUAW</a>) is claiming Ziphone jailbreak author Piergiorgio Zambrini has found a way to crash the iPhone (and other computer systems, according to Zambrini&#8217;s own <a href="http://www.zibri.org/2008_10_26_archive.html#6408091360728069954">website</a>) using specially crafted video files:</p>

<blockquote>The bug Zambrini found is in the audio portion of Apple&#8217;s video format. Knowing the bug exists, someone could write a program that incorporates the bug into a video file and trigger a crash whenever an iPhone attempts to run that file. The bug, which is located in a shared code library that is used across most Apple operating systems and some Linux ones as well, doesn&#8217;t appear to cause any permanent damage, but immediately sends the device into a panic that leads to a lengthy reboot.</blockquote>

<p>Since it crashed the device and not just the app, one security expert quoted feels it&#8217;s a kernal vulnerability that&#8217;s been discovered. Zambrini, who paradoxically claims to have both applied for a job with Apple&#8217;s security team, and that working for Apple is not his goal, is apparently exploring the vulnerability as a way to inject malicious code.</p>

<p>Lovely.</p>

<p>Howsabout next time we be a little more responsible and keep the information confidential, alerting only the OS makers involved, giving them a reasonable amount of time to patch the problem before we put real world end-users at risk by alerting bad guys to potential exploits, b&#8217;okay?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2008/11/03/zomg-ziphone-dude-crashing-iphones-malicious-audio-code/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Flash and Java on the iPhone: Video Dream vs. Security Nightmare Redux</title>
		<link>http://www.imore.com/2008/09/04/flash-and-java-on-the-iphone-video-dream-vs-security-nightmare-redux/</link>
		<comments>http://www.imore.com/2008/09/04/flash-and-java-on-the-iphone-video-dream-vs-security-nightmare-redux/#comments</comments>
		<pubDate>Thu, 04 Sep 2008 13:25:50 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[Editorial]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=4112</guid>
		<description><![CDATA[Last week the <a href="http://www.imore.com/2008/08/27/why-the-uk-was-wrong-to-ban-the-iphone-just-the-internet-ad/">UK ruled</a> that Apple was misrepresenting the iPhone&#8217;s provisioning of &#8220;just the internet&#8221; due to the lack of support for two ubiquitously popular 3rd party plugins: Flash]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.imore.com/images/stories/2008/06/iphone_flash_rumor_smasher.jpg" alt="iPhone SDK: Smashing Flash Rumors" title="iPhone SDK: Smashing Flash Rumors" width="434" height="350" class="aligncenter size-full wp-image-2649" /></p>

<p>Last week the <a href="http://www.imore.com/2008/08/27/why-the-uk-was-wrong-to-ban-the-iphone-just-the-internet-ad/">UK ruled</a> that Apple was misrepresenting the iPhone&#8217;s provisioning of &#8220;just the internet&#8221; due to the lack of support for two ubiquitously popular 3rd party plugins: Flash and Java. We&#8217;ve previously covered the will they/won&#8217;t they <a href="http://www.imore.com/2008/03/25/being-played-flash-music-and-manipulation-wait-a-thon/">drama</a> surrounding development and deployment of <a href="http://www.imore.com/tag/flash/">Flash</a> and <a href="http://www.imore.com/tag/java/">Java</a> pretty much ad nauseum infinitum, as well as some seldom discussed yet surprisingly frightening concerns about Flash and its downright sneaky use of <a href="http://www.imore.com/2008/03/13/flash-on-iphone-video-dream-or-privacy-nightmare/">3rd party advertising cookies</a>.</p>

<p>More recently, however, another issue has come to light. Primarily concerned with Windows Vista security and how it can be circumvented, this issue throws a renewed focus on the danger of 3rd party plugins like Flash and Java, on how they interpret and run code on our machines, and how they provide an increasingly popular attack vector for bad guys (hackers, malware authors, identity thieves, etc.)</p>

<p>How does this all relate to the iPhone, and what about ZOMG! Can has my Flash vidz? Read on to find out!</p>

<p><span id="more-4112"></span></p>

<p>Before we begin, I&#8217;ll just mention again that I&#8217;m a long time (10+ years) web developer who works quite a bit with Flash. I&#8217;ll also add that some coverage of the issues I&#8217;m about to get into has tended towards the sensationalistic. The sky is not falling. We&#8217;re not doomed. Or, at least, not because of anything to do with Flash, Java, or the iPhone.</p>

<p>Caveat&#8217;d enough? Good. </p>

<p>Back in early August at the Black Hat conference, Alexander Sotirov and Mark Dowd presented a paper amusingly titled <em><a href="http://taossa.com/index.php/2008/08/07/impressing-girls-with-vista-memory-protection-bypasses/">How to Impress Girls with Browser Memory Protection Bypasses</a></em>. While Vista security proper is beyond the scope of this blog, as Operating Systems like OS X on the iPhone become increasingly hardened against security exploits, the web browser becomes the path of least resistance for hackers to get at us and our stuff. </p>

<p>The iPhone&#8217;s browser, MobileSafari is currently the closest thing to a desktop-class rendering engine as can be found on a handset. It&#8217;s based on the same WebKit core as Safari for Mac and Windows, and so it&#8217;s not unreasonable to imagine it shares the same advantages (real HTML, CSS, and AJAX) and risks (can be exploited). This could potentially include buffer overruns, cross site scripts, and &#8212; yes &#8212; plugin vulnerabilities.</p>

<p>On a recent episode of the TWiT network&#8217;s popular <a href="http://www.twit.tv/sn159">Security Now! podcast</a>, Steve Gibson summed up the problems with Flash and Java:</p>

<blockquote>Their technologies, especially in the case of Java, Java has, deliberately has readable, writable, and executable memory because of the way it operates. o it&#8217;s a big target.  And so many of these third-party things, which you could pretty much depend upon, you know, Flash player is installed in the high 90 percentile of Windows machines so you can count on it being there.</blockquote>

<p>And what if we could likewise count on their being on the iPhone? What potential problem could that expose?</p>

<blockquote>Certainly after this paper has come out where these guys demonstrate clearly the exploitability of Flash, which is not [Data Execution Prevention] compatible, it&#8217;s like, okay, Adobe, if you want your code in my machine, you make it safe.  Because we&#8217;ve seen a bunch of Flash exploits here in the last few months.  And, you know, this wouldn&#8217;t be possible if Adobe would do the work.  I don&#8217;t care how hard it is, it&#8217;s certainly possible to code around this [...] Basically this is laziness.  In this day and age, for Flash still not to be marked as DEP friendly when it is in a highly vulnerable environment, it&#8217;s not like it&#8217;s something down on your tray, it&#8217;s in your browser.  And we know what a target browsers are just by their very nature.  I mean, in fact, the whole focus of this paper was specifically browser vulnerability. [...] It is very common applications like Silverlight, like Flash, commonly used components, or even Media Player, that are invokable by the browser and still not yet safe, that is really now the main target of exploitation. </blockquote>

<p>We&#8217;ve already seen MobileSafari exploits in the wild (indeed, a TIFF-based vulnerability was one of the first ways people found to <a href="http://www.imore.com/2007/10/16/iphone-and-ipod-touch-jailbreaks-for-111/">jailbreak the iPhone 1.1.1</a> &#8212; just by entering a URL in the browser!)</p>

<p>Again, this is not breakworld stuff. No need to panic and lock your handset in a lead box. Future versions of Flash and Java (and similar plugins) will likely address these issues.</p>

<p>Just remember, for now, that the iPhone is tremendously popular, and thus will be a tremendously popular target for hackers. Apple already has to worry about securing the HTML, CSS, AJAX (Javascript), and Quicktime (which they own and can therefore rapidly address) components of Mobile Safari. Add to that the complications of 3rd party code interpreters with a very real history of not only exploits, but (in the case of Flash) for being bloated and buggy on the Mac (another thing Adobe has chosen not yet to prioritize fixing), and it begins to make more sense why we haven&#8217;t seen Flash or Java on the iPhone, a device that knows who we are (all our date) and where we are (3G aGPS).</p>

<p>But wait, other smartphones run versions of Flash and Java, though, don&#8217;t they? Sure, but I&#8217;d argue that the iPhone isn&#8217;t really a smartphone, it&#8217;s a mobile computer. Full darwin kernal, BSD networking &#8212; pretty much a UNIX box in your pocket. To me, that&#8217;s a far bigger target than Palm OS, the Java Micro Edition inside a Blackberry, and even Windows Mobile (which, despite the name, is a very different animal under the covers than Microsoft&#8217;s desktop OS).</p>

<p>And isn&#8217;t there a battle going on for the Rich Internet Application (RIA, aka WebApp) space? You betcha. Google didn&#8217;t just drop Chrome for no reason. SproutCore, Flash/Air, Silverlight/.Net, Prism, Safari, Java, etc. all want to own what&#8217;s likely the next major computing platform (the web &#8220;cloud&#8221;).</p>

<p>Bottom-line: Both for Apple and for consumers, the advantages for Flash and Java currently do not outweigh the drawbacks, especially as standard web technologies continue to decrease the gap between proprietary plugin capabilities and the open internet (HTML, CSS, AJAX). </p>

<p>That&#8217;s my opinion, at least. What&#8217;s yours?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.imore.com/2008/09/04/flash-and-java-on-the-iphone-video-dream-vs-security-nightmare-redux/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached

Served from: imore.com @ 2012-02-10 10:44:11 -->
