How to hack an iPhone using SMS

happygeek 1 Tallied Votes 591 Views Share

There are two things you can be sure of about the annual Las Vegas Black Hat security conference: nobody will use the free wifi as they are all too , and someone will demonstrate an exploit that will scare the living bejesus out of you. The latter has just happened for iPhone users.

One well known discoverer of such things, Charlie Miller from Independent Security Evaluators, has revealed how a vulnerability can give savvy attackers the ability to gain complete control over your iPhone without any action on the part of the victim. Yep, this is the mother of all mobile remote hijack exploits by the look of it. Using nothing more complicated than a specially constructed text message, Miller says that malicious code can be executed in order to crash the device at the lesser evil end of the scale or take complete control for the more malicious attacker. It is even possible to use the attack to send text messages on to everyone in the victim's contacts list so spreading the hijack quickly to many more handsets.

Miller has been able to demonstrate the vulnerability courtesy of weaknesses in the iPhone CommCenter service that has responsibility for SMS and wireless functionality. Amazingly this runs as root but is not limited by any kind of application sandbox, so Miller realised it was ripe for use as a remote control hacking vector. All that is required is a slight modification of the data that arrives on the iPhone with the SMS text message itself. So far Miller and his team have managed to write software that can exploit the weakness on four different mobile networks in Germany and AT&T in the USA.

Apple has yet to publicly respond to news of the vulnerability, although it has known about it for weeks now. Given its track record on fixing security problems I am not hopeful of a speedy resolution.

In the meantime iPhone users are being urged to keep an eye open for any text message which arrives containing a single square character. Miller reckons this is a giveaway to the exploit and users should immediately turn off their handset if they notice such a message to prevent falling victim to it.

Dani AI

Generated

gave a solid summary of the Black Hat 2009 SMS story. Important update and context: Apple issued iPhone OS 3.0.1 on July 31, 2009 to address the SMS parsing flaw and that update closed the immediate attack vector; the patch was distributed through iTunes. (wired.com)

Technical synopsis (high level only): the problem was a memory‑corruption bug in the SMS handling code that could be reached by specially crafted message data. Researchers showed a controlled demonstration at Black Hat that illustrated denial‑of‑service and, in certain lab conditions, the potential for remote code execution; the work also highlighted how SMS decoding and multipart reassembly create an attack surface on mobile stacks. Those findings were covered in contemporary writeups and conference material. (arstechnica.com)

Practical, non‑exploit guidance that remains useful today: ensure any affected device is running a patched OS (the 2009 fix was iPhone OS 3.0.1; modern devices should run the latest supported iOS), avoid removing platform protections (for example, jailbreaking reduces built‑in defenses), and keep regular, verified backups before applying updates. If a legacy device showed unexplained service loss or strange messages at the time, the standard recovery steps were to power it down, apply the official update via iTunes, and if concerns remained perform a full restore from a clean backup and rotate account credentials. For managed fleets, enforce timely updates and SMS/spam controls at the carrier or gateway level. (arstechnica.com)

Historical note: the issue is well documented in the conference talks and media coverage from summer 2009; it was fixed rapidly and is mainly of historical interest now unless a device was left unpatched. For those wishing to review the technical background without reproducing exploit code, the vendor advisories and the recorded talks provide the appropriate level of detail. (learn.microsoft.com)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.