<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The iPhone Blog &#187; exploits</title>
	<atom:link href="http://www.theiphoneblog.com/tag/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.theiphoneblog.com</link>
	<description>For people who dare to Phone Different.</description>
	<lastBuildDate>Sun, 22 Nov 2009 21:58:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>GSM Encryption Cracked: Know Your Risks</title>
		<link>http://www.theiphoneblog.com/2009/09/12/gsm-encryption-cracked-risks/</link>
		<comments>http://www.theiphoneblog.com/2009/09/12/gsm-encryption-cracked-risks/#comments</comments>
		<pubDate>Sun, 13 Sep 2009 01:43:50 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[cracked]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[gsm]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=11608</guid>
		<description><![CDATA[

The cracking of GSM &#8220;encryption&#8221; has been making the inter-rounds lately, and this week on the Security Now! Podcast, Steve Gibson takes a look at how badly it&#8217;s broken, and what the potential risks are. In simple terms, it means what you say on your iPhone &#8212; or any GSM phone, which includes all phones [...]<p>This is a story by <a href="http://theiphoneblog.com">the iPhone Blog</a>.  This feed is sponsored by <a href="http://store.theiphoneblog.com">The iPhone Blog Store</a>.<br/><br/><a href="http://www.theiphoneblog.com/2009/09/12/gsm-encryption-cracked-risks/">GSM Encryption Cracked: Know Your Risks</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.theiphoneblog.com/images/stories/2009/06/antenna_pointingtoward_pokhara.jpg" alt="antenna_pointingtoward_pokhara" title="antenna_pointingtoward_pokhara" width="300" height="318" class="aligncenter size-full wp-image-9565" /></p>

<p>The cracking of GSM &#8220;encryption&#8221; has been making the <a href="http://www.theregister.co.uk/2009/09/04/gsm_security/">inter-rounds</a> lately, and this week on the Security Now! Podcast, Steve Gibson takes a look at how badly it&#8217;s broken, and what the potential risks are. In simple terms, it means what you say on your iPhone &#8212; or any GSM phone, which includes all phones on AT&amp;T, T-Mobile, Rogers, and almost all phones internationally &#8212; can be intercepted, decrypted, and listened to if a person has several thousand dollars worth of equipment and the motivation to do it. In more complex terms:</p>

<blockquote>
  <p>So again, we&#8217;re now at the hobby level. We&#8217;re at the level where the hobbyist with a couple thousand dollars can &#8211; needs to know nothing about radio and even hardware. And even all of the preprocessing steps for demultiplexing the data and analyzing it and performing spectrum analysis and finding the channels and everything, all of that&#8217;s been done. There&#8217;s even some people have taken &#8211; they&#8217;re not at the GPL licensing, but they are &#8211; so they&#8217;re proprietary licenses, but free, but they&#8217;re open source and free for personal use, where turnkey packages to pull all this data together have been produced. There&#8217;s even one which abstracts this USRP, this Universal Software Radio Peripheral, making it look like a network device so that Wireshark, our favorite packet capture utility, is able to capture GSM packets and decode them and show you all the bits and all the protocols and everything going on in a stream that you capture.</p>
  
  <p>So, I mean, we&#8217;re way far along in making this possible. In my opinion, this GSM Alliance is &#8211; they&#8217;re saying what they have to say politically; but, if they really believe what they&#8217;re saying, that they&#8217;re in serious denial because this is no longer James Bond government-level sci-fi stuff. It would be entirely possible for a company who wanted to do some surveillance of a competitor to equip a van with some of this equipment, spending only tens of thousands of dollars, park it across the street from a competitor, aim their antennas at the competitor&#8217;s building, and spend a day just streaming in, sucking in all of the cellphone traffic that is being transacted by the employees within the building, and then drive the van off and decrypt those conversations offline afterwards and find out what was being said. I mean, it is no longer difficult to do. It&#8217;s entirely possible.</p>
</blockquote>

<p>It should be noted that the GSMA (GSM Alliance) seems to consider this attack <a href="http://www.theregister.co.uk/2009/08/28/mobile_phone_snooping_plan/">theoretical and impractical</a> for now. If you&#8217;re interested in more, check out the audio podcast [<a href="http://media.grc.com/sn/sn-213.mp3">MP3 link</a>] or the <a href="http://www.grc.com/sn/sn-213.htm">transcript</a>.</p>
<p>This is a story by <a href="http://theiphoneblog.com">the iPhone Blog</a>.  This feed is sponsored by <a href="http://store.theiphoneblog.com">The iPhone Blog Store</a>.<br /><br /><a href="http://www.theiphoneblog.com/2009/09/12/gsm-encryption-cracked-risks/">GSM Encryption Cracked: Know Your Risks</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.theiphoneblog.com/2009/09/12/gsm-encryption-cracked-risks/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>TiPb Presents: iPhone Live! #21 &#8211; Google Voiceless</title>
		<link>http://www.theiphoneblog.com/2009/07/30/tipb-presents-iphone-live-21-google-voiceless/</link>
		<comments>http://www.theiphoneblog.com/2009/07/30/tipb-presents-iphone-live-21-google-voiceless/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 15:18:09 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[3.1 beta 3]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[google voice]]></category>
		<category><![CDATA[iphone 3.1]]></category>
		<category><![CDATA[iphone vs palm pre]]></category>
		<category><![CDATA[itablet]]></category>
		<category><![CDATA[verizon]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=10230</guid>
		<description><![CDATA[




    Our podcast feed
    Download Directly
    Subscribe via iTunes


Join Dieter, Chad, and Rene for iPhone 3.1 Beta 3, Google Voice rejection, iTablet and Verizon rumors, Palm/iTunes escalation, SMS exploits, and all the news and how-tos. Listen in!



Featured Accessory


Jabra SP200 Bluetooth Speakerphone for Hands-Free iPhone 3G/3GS Action


News

iPhone [...]<p>This is a story by <a href="http://theiphoneblog.com">the iPhone Blog</a>.  This feed is sponsored by <a href="http://store.theiphoneblog.com">The iPhone Blog Store</a>.<br/><br/><a href="http://www.theiphoneblog.com/2009/07/30/tipb-presents-iphone-live-21-google-voiceless/">TiPb Presents: iPhone Live! #21 &#8211; Google Voiceless</a></p>
]]></description>
			<content:encoded><![CDATA[<p align="center"><img src="http://www.theiphoneblog.com/images/stories/2008/10/iphonelive-podcast1_300.jpg" alt="" width="300" height="300" />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="300" height="27" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#ffffff" /><param name="flashvars" value="playerMode=embedded" /><param name="src" value="http://www.google.com/reader/ui/3247397568-audio-player.swf?audioUrl= http://media.libsyn.com/media/phonedifferent/iphonelive21.mp3" /><param name="wmode" value="window" /><embed type="application/x-shockwave-flash" width="300" height="27" src="http://www.google.com/reader/ui/3247397568-audio-player.swf?audioUrl=http://media.libsyn.com/media/phonedifferent/iphonelive21.mp3" wmode="window" flashvars="playerMode=embedded" bgcolor="#ffffff"></embed></object>
</p>

<ul>
    <li><a href="http://feeds.feedburner.com/PhoneDifferentPodcast">Our podcast feed</a></li>
    <li><a href="http://media.libsyn.com/media/phonedifferent/iphonelive21.mp3">Download Directly</a></li>
    <li><a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=261058960">Subscribe via iTunes</a></li>
</ul>

<p>Join Dieter, Chad, and Rene for iPhone 3.1 Beta 3, Google Voice rejection, iTablet and Verizon rumors, Palm/iTunes escalation, SMS exploits, and all the news and how-tos. Listen in!</p>

<p><span id="more-10230"></span></p>

<h2>Featured Accessory</h2>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/29/review-jabra-sp200-bluetooth-speakerphone-iphone-3g3gss/">Jabra SP200 Bluetooth Speakerphone for Hands-Free iPhone 3G/3GS Action</a></li>
</ul>

<h2>News</h2>

<h3>iPhone 3.1 Watch</h3>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/27/apple-release-iphone-31-beta-3-developers-beta-2-expires-tues-july-28/">Updated: Apple Release iPhone 3.1 Beta 3 to Developers (Beta 2 Expiring Tues, July 28!)</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/25/iphone-31-augmented-reality-apps/">iPhone 3.1: Augmented Reality Apps are a Go!</a></li>
</ul>

<h3>Apps and App Store</h3>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/28/apple-rejects-google-voice-apps/">UPDATED: Apple Rejects Removes all Google Voice Apps for iPhone from iTunes App Store</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/28/gv-mobile-brings-google-voice-iphone-cydia-jailbreak/">GV Mobile Brings Google Voice to iPhone… via Cydia for Jailbreak</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/27/apple-reverses-decision-promo-codes-apps-rated-17/">Apple Reverses Decision, Allows Promo Codes for Apps Rated 17+</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/29/apple-improves-itunes-app-store-search-asks-developers-keywords/">Apple Improves iTunes App Store Search, Asks Developers for Keywords</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/29/quick-app-apple-releases-mobileme-idisk-app-iphone/">Quick App: Apple Releases MobileMe iDisk App for iPhone</a>
<a href="http://www.theiphoneblog.com/2009/07/24/amazons-jeff-bezos-apologizes-kindle-users/">Amazon’s Jeff Bezos Apologizes to Kindle (and iPhone Kindle App) Users</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/23/google-finally-latitude-iphone-users-yeah-webapp/">Google Finally Provides Latitude to iPhone Users — Yeah, it’s a WebApp</a></li>
</ul>

<h3>iTunes &amp; iTablet</h3>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/29/itablet-ship-run/">iTablet: When Will it Ship and What Will it Run?</a> now that <a href="http://www.theiphoneblog.com/2009/07/24/itablet-rumor-du-jour-steves-finally-happy-giant-ipod-touch/">Steve is finally happy with i</a>t, and <a href="http://www.theiphoneblog.com/2009/07/26/rumor-verizon-racing-4g-lte-network-q1-2010-iphone-itablet-launch/">Verizon is racing to get LTE ready</a>&#8230;</li>
<li><a href="http://www.theiphoneblog.com/2009/07/27/apple-record-labels-reignite-album-interest-cocktail/">Apple and Record Labels Trying to Reignite Album Interest with “Cocktail”?</a></li>
</ul>

<h3>Carrier Talk</h3>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/24/att-iphone-exclusivity-eventually/">CEOh-Snap! AT&amp;T Says iPhone Exclusivity Will End… Eventually</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/27/verizon-sees-profit-loss-due-iphone-3gs/">Verizon: iPhone 3GS Cost us Money, Helped Drive Innovation</a>
<a href="http://www.theiphoneblog.com/2009/07/28/rogers-canada-roundup-q2-financial-results-stock-21mbps-hspa-testing/">Rogers Canada Roundup: Q2 Financial Results, Out of Stock, and 21Mbps HSPA+ Testing</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/28/apple-china-unicom-finally-potentially-iphone-deal-possibly/">Apple and China Unicom Finally Maybe Potentially Have an iPhone Deal. Possibly.</a></li>
</ul>

<h3>The Competition</h3>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/23/palm-rehacks-itunes-sync-shows-care-ego-press-pre-users/">Palm Re-Hacks iTunes Sync, Shows They Care More About Ego and Press Than Pre Users</a>, and <a href="http://www.theiphoneblog.com/2009/07/24/yeahbuwhy-palm-spoofs-apple-usb-vendor-id-files-complaint-apple-misuse-usb-vendor-id/">files a complaint against Apple</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/28/roger-mcnamee-iphone/">Palm’s Roger McNamee Wants to Know if You’re Still Using an iPhone?</a></li>
</ul>

<h3>In Other News</h3>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/24/iphone-3gs-hardware-encryption-useless/">iPhone 3GS Hardware Encryption “Useless”?</a></li>
<li><a href="http://www.theiphoneblog.com/2009/07/28/1ghz-arm-mobile-cpu-horizon-iphone/">1GHz ARM Mobile CPU on the Horizon — but is it iPhone Bound?</a></li>
</ul>

<h2>Help and How To</h2>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/27/pro-tips-secure-jailbroken-regular-iphone-hackers/">Pro Tips: How to Secure Your Jailbroken (or Regular) iPhone Against Hackers</a></li>
</ul>

<h2>Forums</h2>

<ul>
<li><a href="http://www.theiphoneblog.com/2009/07/25/forums-14/">From the Forums: iPhone 3.0 Jailbreak Apps, Overheating, 3GS Photos, Battery Tips</a></li>
</ul>

<h3>Credits</h3>

<p>Thanks to the <a href="http://store.theiphoneblog.com">the iPhone Blog Store</a> for sponsoring the podcast, and to everyone who showed up for the live chat!</p>

<p>Our music comes from the following sources:
<ul>
    <li><a href="http://www.sneakmove.com/audio/I%20Called%20You%20-%20iphone%20remix.mp3">I Called You &#8212; iPhone Remix</a> by <a href="http://www.myspace.com/pbl3">Pete Leidy</a></li>
via <a href="http://sneakmove.com/2007/01/winner-is.html">Sneakmove iPhone Ringtone Challenge</a></ul></p>
<p>This is a story by <a href="http://theiphoneblog.com">the iPhone Blog</a>.  This feed is sponsored by <a href="http://store.theiphoneblog.com">The iPhone Blog Store</a>.<br /><br /><a href="http://www.theiphoneblog.com/2009/07/30/tipb-presents-iphone-live-21-google-voiceless/">TiPb Presents: iPhone Live! #21 &#8211; Google Voiceless</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.theiphoneblog.com/2009/07/30/tipb-presents-iphone-live-21-google-voiceless/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Infamous Safari Security Cracker Finds Vulnerability-ish in iPhone OS?</title>
		<link>http://www.theiphoneblog.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/</link>
		<comments>http://www.theiphoneblog.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 14:04:25 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120</guid>
		<description><![CDATA[

Very little code is bullet-proof. Hackers will always find holes. The worst holes will be critical. The worst hacks will be zero-day and found in the wild &#8212; catching companies and users both by surprise.

Not sure we have any of that here. Macworld does report that, at the Black Hat Europe Security Conference, former NSA [...]<p>This is a story by <a href="http://theiphoneblog.com">the iPhone Blog</a>.  This feed is sponsored by <a href="http://store.theiphoneblog.com">The iPhone Blog Store</a>.<br/><br/><a href="http://www.theiphoneblog.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/">Infamous Safari Security Cracker Finds Vulnerability-ish in iPhone OS?</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.theiphoneblog.com/images/stories/2008/11/macbook_stop_jailbreak.jpg" alt="" title="macbook_stop_jailbreak" width="500" height="300" class="aligncenter size-full wp-image-5295" /></p>

<p>Very little code is bullet-proof. Hackers will always find holes. The worst holes will be critical. The worst hacks will be zero-day and found in the wild &#8212; catching companies and users both by surprise.</p>

<p>Not sure we have any of that here. <a href="http://www.macworld.com/article/140039/2009/04/iphone_vulnerability.html">Macworld</a> does report that, at the Black Hat Europe Security Conference, former NSA number cruncher Charlie Miller &#8212; who has rolled his ability to find exploits in the Mac version of Apple&#8217;s Safari Browser into tens of thousands of dollars and a couple free MacBooks at the annual <a href="http://www.theiphoneblog.com/2009/02/28/free-iphone-10000-prize-pwn2own/">Pwn2Own</a> contest &#8212; claims to have:</p>

<blockquote>
  <p>&#8230;found a way to trick the iPhone into running code that enables shellcode. To run shellcode on an iPhone, however, an attacker would first need a working exploit for an iPhone, or a way to target some software vulnerability in, for example, the Safari Web browser or the mobile’s operating system. Miller said he doesn’t have one now.</p>
</blockquote>

<p>Miller previously gained attention for a <a href="http://www.theiphoneblog.com/2007/08/21/interview-with-charlie-miller/">Mobile Safari exploit</a> that made for some quick early jailbreaking and led to Apple patching the problem in firmware 1.0.1.</p>

<p>What&#8217;s particularly disturbing, however, is that Miller also says he&#8217;s unsure whether or not Apple knows about the potential vulnerability.</p>

<p>He should know that absolutely dead cold, of course. He should have told Apple <em>long</em> before he made the information public, and only made the information public when Apple had a fix rolled out or ignored his warnings for so long that public pressure could reasonably be considered the only option in getting them to roll out a fix.</p>

<p>Either way, Miller should <em>know</em> that Apple <em>knows</em> because he <em>told</em> them <em>first</em>. Or do we no longer warn people in a house when we see a potential fire starting, but wait and see how much attention and cash we can get for the info first?</p>
<p>This is a story by <a href="http://theiphoneblog.com">the iPhone Blog</a>.  This feed is sponsored by <a href="http://store.theiphoneblog.com">The iPhone Blog Store</a>.<br /><br /><a href="http://www.theiphoneblog.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/">Infamous Safari Security Cracker Finds Vulnerability-ish in iPhone OS?</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.theiphoneblog.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>

