<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The iPhone Blog &#187; ziphone</title>
	<atom:link href="http://www.theiphoneblog.com/tag/ziphone/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.theiphoneblog.com</link>
	<description>For people who dare to Phone Different.</description>
	<lastBuildDate>Sun, 22 Nov 2009 21:58:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>ZOMG! Ziphone Dude Crashing iPhones With Malicious Audio Code?</title>
		<link>http://www.theiphoneblog.com/2008/11/03/zomg-ziphone-dude-crashing-iphones-malicious-audio-code/</link>
		<comments>http://www.theiphoneblog.com/2008/11/03/zomg-ziphone-dude-crashing-iphones-malicious-audio-code/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 23:11:26 +0000</pubDate>
		<dc:creator>Rene Ritchie</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[ziphone]]></category>

		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=5286</guid>
		<description><![CDATA[

Forbes.com (via TUAW) is claiming Ziphone jailbreak author Piergiorgio Zambrini has found a way to crash the iPhone (and other computer systems, according to Zambrini&#8217;s own website) using specially crafted video files:

The bug Zambrini found is in the audio portion of Apple&#8217;s video format. Knowing the bug exists, someone could write a program that incorporates [...]<p>This is a story by <a href="http://theiphoneblog.com">the iPhone Blog</a>.  This feed is sponsored by <a href="http://store.theiphoneblog.com">The iPhone Blog Store</a>.<br/><br/><a href="http://www.theiphoneblog.com/2008/11/03/zomg-ziphone-dude-crashing-iphones-malicious-audio-code/">ZOMG! Ziphone Dude Crashing iPhones With Malicious Audio Code?</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.theiphoneblog.com/images/stories/2008/08/sadpirate.png" alt="" title="sadpirate" width="273" height="336" class="aligncenter size-full wp-image-3641" /></p>

<p><a href="http://www.forbes.com/technology/2008/11/03/apple-iphone-bug-tech-security-cz_tb_1103iphone.html">Forbes.com</a> (via <a href="http://www.tuaw.com/2008/11/03/ziphone-author-demos-iphone-crash-to-forbes/">TUAW</a>) is claiming Ziphone jailbreak author Piergiorgio Zambrini has found a way to crash the iPhone (and other computer systems, according to Zambrini&#8217;s own <a href="http://www.zibri.org/2008_10_26_archive.html#6408091360728069954">website</a>) using specially crafted video files:</p>

<blockquote>The bug Zambrini found is in the audio portion of Apple&#8217;s video format. Knowing the bug exists, someone could write a program that incorporates the bug into a video file and trigger a crash whenever an iPhone attempts to run that file. The bug, which is located in a shared code library that is used across most Apple operating systems and some Linux ones as well, doesn&#8217;t appear to cause any permanent damage, but immediately sends the device into a panic that leads to a lengthy reboot.</blockquote>

<p>Since it crashed the device and not just the app, one security expert quoted feels it&#8217;s a kernal vulnerability that&#8217;s been discovered. Zambrini, who paradoxically claims to have both applied for a job with Apple&#8217;s security team, and that working for Apple is not his goal, is apparently exploring the vulnerability as a way to inject malicious code.</p>

<p>Lovely.</p>

<p>Howsabout next time we be a little more responsible and keep the information confidential, alerting only the OS makers involved, giving them a reasonable amount of time to patch the problem before we put real world end-users at risk by alerting bad guys to potential exploits, b&#8217;okay?</p>
<p>This is a story by <a href="http://theiphoneblog.com">the iPhone Blog</a>.  This feed is sponsored by <a href="http://store.theiphoneblog.com">The iPhone Blog Store</a>.<br /><br /><a href="http://www.theiphoneblog.com/2008/11/03/zomg-ziphone-dude-crashing-iphones-malicious-audio-code/">ZOMG! Ziphone Dude Crashing iPhones With Malicious Audio Code?</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.theiphoneblog.com/2008/11/03/zomg-ziphone-dude-crashing-iphones-malicious-audio-code/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

