from arstechnica.com
Security researchers have uncovered an active malware campaign in the wild that steals the Apple ID credentials from jailbroken iPhones and iPads.
News of the malware dubbed "unflod," based on the name of a library that's installed on infected devices, first surfaced late last week on a pair of reddit threads here and here. In the posts, readers reported their jailbroken iOS devices recently started experiencing repeated crashes, often after installing jailbroken-specific customizations known as tweaks that were not a part of the official Cydia market, which acts as an alternative to Apple's App Store.
Since then, security researcher Stefan Esser has performed what's called a static analysis on the binary code that the reddit users isolated on compromised devices. In a blog post reporting the results, he said unflod hooks into the SSLWrite function of an infected device's security framework. It then scans it for strings accompanying the Apple ID and password that's transmitted to Apple servers. When the credentials are found, they're transmitted to attacker-controlled servers.
In an e-mail to Ars, Esser said the malicious code works only on 32-bit versions of jailbroken iOS devices. "There is no ARM 64-bit version of the code in the copy of the library we got," he wrote. "This means the malware should never be successful on [the] iPhone 5S/iPad Air or iPad mini 2G."
reddit readers said unflod infections can be detected by opening the SSH/Terminal and searching the folder /Library/MobileSubstrate/DynamicLibraries for the presence of the Unflod.dylib file. Compromised devices may possibly be disinfected by deleting the dynamic library, but since no one so far has been able to figure out how the malicious file is installed in the first place, there's no guarantee it won't somehow subsequently reappear.
"That is why we recommend to restore the device," Esser told Ars. "However, that means people will lose their jailbreak until a new one is released, and the majority of jailbreak users will not do that."
Of course, whichever course of disinfection users of infected devices choose, they should also change their Apple ID password as soon as possible.
The unflod campaign, which was also analyzed by researchers from antivirus provider Sophos, underscores the risks associated with installing unknown apps on jailbroken iPhones.
"I will also again take this moment to point out to anyone concerned that the probability of this coming from a default [Cydia] repository is fairly low," Cydia developer Jay Freeman, aka Saurik, wrote in one reddit comment. "I don't recommend people go adding random URLs to Cydia and downloading random software from untrusted people any more than I recommend opening the .exe files you receive by e-mail on your desktop computer."
Showing posts with label apple id. Show all posts
Showing posts with label apple id. Show all posts
Tuesday, April 22, 2014
Thursday, September 12, 2013
Little Girl Finds Security Flaw in iPhone 5S Fingerprint Scanner
from mashable.com
Apple's new iPhone 5S features the latest in phone-unlocking security: a fingerprint scanner.
The company announced that its Touch ID fingerprint sensor would read fingerprints at a highly detailed level, boasting a capacitive sensor at 170 microns thin and a 500 ppi resolution. It's James Bond-level technology that could revolutionize lock screens.
While some rejoiced at the advancement in phone security, one Reddit user's clever daughter knew there was a simple flaw in this new tech.
Redditor iZeeHunter posted the image Wednesday, along with the caption: "The new iPhone 5S provides unmatched security with its new Fingerprint lock, which makes your personal data even harder to reach!"
Apple should probably hire the little girl pictured, who is wearing a mischievously adorable grin, to examine future products for security breaches.
Apple's new iPhone 5S features the latest in phone-unlocking security: a fingerprint scanner.
The company announced that its Touch ID fingerprint sensor would read fingerprints at a highly detailed level, boasting a capacitive sensor at 170 microns thin and a 500 ppi resolution. It's James Bond-level technology that could revolutionize lock screens.
While some rejoiced at the advancement in phone security, one Reddit user's clever daughter knew there was a simple flaw in this new tech.
![]() |
| "You call that security?" |
Apple should probably hire the little girl pictured, who is wearing a mischievously adorable grin, to examine future products for security breaches.
Wednesday, May 1, 2013
Hackers To Manage Your Apple ID, If Caught From Phishing Bait
from blog.trendmicro.com
Phishers appear to have concentrated their fire on a relatively new target: Apple IDs. In recent days, we’ve seen a spike in phishing sites that try to steal Apple IDs.
Upon looking at the URLS, we noted that there was a consistent pattern to the URLs of these phishing sites. They are under a folder named ~flight. Interestingly, trying to access the folder itself will load the following page:

Technically, the sites were only compromised, but not hacked (as the original content was not modified). It’s possible, however, that the sites may be hacked or defaced if the site stays compromised.
As mentioned earlier, the directory contains pages that spoof the Apple ID login page fairly closely:

We’ve identified a total of 110 compromised sites, all of hosted at the IP address 70.86.13.17, which is registered to an ISP in the Houston area. Almost all of these sites have not been cleaned.

The graph above shows the increase in phishing sites targeting Apple IDs. We’ve seen attacks targeting not only American users, but also British and French users. Some versions of this attack ask not only for the user’s Apple ID login credentials, but also their billing address and other personal and credit card information. It will eventually result in a page that states that access has been restored, but of course the information has been stolen. One can see in the sample page below how it asks for credit card information:

Users may be redirected to these phishing sites via spam messages that state that the user’s account will expire unless their information is subject to an “audit”, which not only gets users to click on the link, it puts them in a mindset willing to give up information.

One way to identify these phishing sites, is that the fake sites do not display any indications that you are at a secure site (like the padlock and “Apple Inc. [US]” part of the toolbar), which you can see in this screenshot of the legitimate site:

The screenshot above is from Chrome, but Internet Explorer and Firefox both have similar ways to indicate secure sites.
For the phishing messages themselves, legitimate messages should generally have matching domains all around – where they were sent from, where any links go to, etcetera. Mere appearance of the email isn’t enough to judge, as very legitimate-looking emails have been used maliciously. We also encourage users to enable the two-factor authentication that Apple ID recently introduced, for added protection.
In case you’re using mobile devices to manage your Apple ID or other parts of your online activities, you may read our ebook about avoiding bad mobile URLs to help protect yourself. We have blocked all sites and messages related to these attacks.
Phishers appear to have concentrated their fire on a relatively new target: Apple IDs. In recent days, we’ve seen a spike in phishing sites that try to steal Apple IDs.
Upon looking at the URLS, we noted that there was a consistent pattern to the URLs of these phishing sites. They are under a folder named ~flight. Interestingly, trying to access the folder itself will load the following page:

Technically, the sites were only compromised, but not hacked (as the original content was not modified). It’s possible, however, that the sites may be hacked or defaced if the site stays compromised.
As mentioned earlier, the directory contains pages that spoof the Apple ID login page fairly closely:

We’ve identified a total of 110 compromised sites, all of hosted at the IP address 70.86.13.17, which is registered to an ISP in the Houston area. Almost all of these sites have not been cleaned.

The graph above shows the increase in phishing sites targeting Apple IDs. We’ve seen attacks targeting not only American users, but also British and French users. Some versions of this attack ask not only for the user’s Apple ID login credentials, but also their billing address and other personal and credit card information. It will eventually result in a page that states that access has been restored, but of course the information has been stolen. One can see in the sample page below how it asks for credit card information:

Users may be redirected to these phishing sites via spam messages that state that the user’s account will expire unless their information is subject to an “audit”, which not only gets users to click on the link, it puts them in a mindset willing to give up information.

One way to identify these phishing sites, is that the fake sites do not display any indications that you are at a secure site (like the padlock and “Apple Inc. [US]” part of the toolbar), which you can see in this screenshot of the legitimate site:

The screenshot above is from Chrome, but Internet Explorer and Firefox both have similar ways to indicate secure sites.
For the phishing messages themselves, legitimate messages should generally have matching domains all around – where they were sent from, where any links go to, etcetera. Mere appearance of the email isn’t enough to judge, as very legitimate-looking emails have been used maliciously. We also encourage users to enable the two-factor authentication that Apple ID recently introduced, for added protection.
In case you’re using mobile devices to manage your Apple ID or other parts of your online activities, you may read our ebook about avoiding bad mobile URLs to help protect yourself. We have blocked all sites and messages related to these attacks.
Subscribe to:
Posts (Atom)

