Evad3rs to present at HITBSecConf2013 in Amsterdam

By Cody Lee on Feb 13, 2013

The evad3rs are probably one of the hottest tickets around right now on the mobile security circuit. The four hackers were able to overcome Apple’s highly regarded security systems in iOS 6, to provide us with the evasi0n jailbreak.

Well good news for those of you that will be in Amsterdam between the dates of April 8 – 11. The team will be giving a presentation at the Hack in the Box Security Conference in the country, at the Okura Hotel. More details after the fold… Read More

 

Pod2g, MuscleNerd and others to take part in HITB discussion panel

By Cody Lee on Oct 8, 2012

Hot on the heels of last week’s JailbreakCon convention, another event is set to take place on October 11th featuring some prominent members of the jailbreaking community.

On October 11th, in Kuala Lumpur, Malaysia, MuscleNerd, pod2g and other well-known hackers will take part in a discussion panel at this year’s Hack in the Box conference… Read More

 

iPhone 4S hacked using Safari exploit in Pwn2Own contest

By Cody Lee on Sep 19, 2012

Users of Apple’s iPhone and other iOS devices enjoy a fairly high level of security. In the past five years, the platform has only seen a handful of malware scares, and MIT says it recently crossed a “significant” threshold in security.

But all of that security couldn’t stop the iPhone 4S from getting hacked today at the Pwn2Own contest in Amsterdam. A group of Dutch security researchers gained remote access to the handset in seconds with a Safari exploit… Read More

 

Twitter adds iOS hacker Charlie Miller to its security team

By Cody Lee on Sep 15, 2012

If you are a long-time iDB reader, you’ll likely recognize the name Charlie Miller. The iOS hacker has broken through the security of everything from the iPhone to the App Store.

Well it looks like Miller’s iOS hacking days are over, at least for now. The systems expert announced on Friday that he will be joining Twitter’s security team, starting next week… Read More

 

Predictably, FBI denies involvement in UDID scare

By Christian Zibreg on Sep 4, 2012

If you’ve been anywhere near an electrical outlet today, you already know about the latest privacy scare reportedly involving the hacking group AntiSec publishing a million UDIDs they allegedly lifted from a laptop belonging to an FBI agent. It’s been all over the news and concerned citizens jumped to the rescue by writing a web app to check if your device identifier has been compromised (though I wouldn’t be typing in my UDID into some web form if I were you).

Well, the Federal Bureau of Investigation, also known under the widely popular FBI moniker, issued a public statement related to the scandal. No, the Bureau absolutely had nothing to do with collecting Apple UDIDs. Its agent wasn’t carrying around a file with a whopping twelve million device identifiers, thanks for your question. And of course they refuted the story and denied any wrongdoing. Sometimes, it’s easier to believe in God than to trust the Government, isn’t it? Read More

 

Check if your iOS device has been compromised by the FBI breach

By Christian Zibreg on Sep 4, 2012

Yesterday, news broke that the hacking group AntiSec published a million UDIDs from an alleged trove of twelve million device IDs claimed to have been stolen from a laptop belonging to an FBI agent. Even though the hackers had removed some of the identifiable information from the list, your UDID might be exposed out in the wild, along with 999,999 other IDs posted on the web.

And why would you want to know if your UDID is out there for everyone to see? Good question. Your UDID uniquely identifies your device and expert hackers could use it to glean all sorts of information from other data associated with your UDID.

Yeah, it’s a privacy catastrophe, one that might potentially even lead to identity theft. Perhaps even more important than that, wouldn’t you like to know if your device is on the FBI’s watch list? Read More

 

Hacker group leaks 1 million Apple device IDs from FBI breach

By Cody Lee on Sep 4, 2012

Earlier this year, Apple started rejecting applications that called on unique device identifiers (or UDIDs). The move came amidst privacy and security concerns, as several apps were found to be misusing the information.

Tonight, those concerns multiplied as the hacking group known as AntiSec announced that it had acquired more than 12 million device IDs from a recent FBI hack. And they’ve just released a million of them… Read More

 

New spyware found capable of taking over iPhones

By Cody Lee on Aug 30, 2012

The iPhone receives a fair amount of praise for its security features. The Massachusetts Institute of Technology says that the handset’s encryption is so good, that it’s tough for law enforcement agencies to perform forensics.

But this doesn’t mean it’s impenetrable, as hackers continue to find flaws. In fact, another big one was recently discovered in the form of spyware, which can take over the iPhone and give a user remote access to its contents… Read More

 

Why iOS devices are easier to hack and customize than Android ones

By Cody Lee on Jun 9, 2012

I’ve always tinkered with my devices, regardless of their OS. I remember installing leaked versions of RIM’s OS 6 on my old BlackBerry Bold, and rooting my Android handsets to install the latest ROMs.

But out of all of those experiences, I can honestly say that hacking devices, customizing them and installing tweaks, is much easier to do on iOS than it is on any other platform — even the “open” Android… Read More

 

US Government would’ve paid Comex $250,000 for exclusive use of JailbreakMe

By Christian Zibreg on Mar 23, 2012

Jailbreak community owes a lot to adept hackers who find and exploit weaknesses in the design of iOS mobile operating system, thus allowing Apple’s mobile gadgets to run unsanctioned software. It’s more often than not a neverending cat-and-mouse game between Apple and hackers that at the end benefits jailbreakers the most.

Say you’re an expert hacker who just figured an exploit in one of Apple’s products. You could report your findings directly to Apple and help them plug those holes with a software update.

But did you know you could also hand over this valuable information to an exploit broker who will sell it to a government agency and net you a decent profit, minus the broker’s commission? A U.S. government agency, to be precise… Read More

 

Foxconn corporate servers hacked, classified information compromised

By Cody Lee on Feb 9, 2012

Foxconn, Apple’s largest manufacturing partner, has been back in the media spotlight over the last few weeks. Last month, the New York Times pointed to the company in its report on the poor working conditions in Chinese factories.

Foxconn has since been the target of activists and protestors, but now it’s found itself in the sights of a different breed. It seems that the world’s largest component manufacturer has been hacked by a new group called Swagg Security… Read More

 

iTunes accounts being hacked to steal money from store credit

By Jake Smith on Feb 9, 2012

The amount of customers reporting that their iTunes account have been hacked is growing steadily on Apple’s Support Forum. Customers are reporting that their accounts are being hacked, and the hackers are then using the accounts to purchase gift cards, make purchases on the store, and even using their PayPal accounts.

The Globe and Mail reports customers that have been hacked are growing increasingly frustrated with Apple’s response to the issue… Read More

 

Anonymous Hackers Attack Apple Servers

By Cody Lee on Jul 5, 2011

In case you thought computer hacking died with mid-1990′s thrillers like The Net or Hackers, think again. It seems like we’ve seen an uprise of digital deviants over the last few months.

They’ve taken down Sony’s PSN network, stolen mounds of credit card information, and even infiltrated Arizona’s government network. According to the infamous hacking group known as “Anonymous,” their latest corporate target is Apple… Read More

 

LulzSec’s Leaked Law Enforcement Documents Reveal iPhone App Training

By Cody Lee on Jun 25, 2011

Lulz Security, commonly referred to as LulzSec, has been causing all sorts of chaos around the web for the past few months. The team of hackers is responsible for a number of recent attacks, including posting a fake news story on PBS.com and knocking the CIA’s website offline.

Though their recent attacks have been fairly harmless, their most recent break-in has made a lot of folks nervous. Last Thursday, LulzSec published more than 700 confidential documents stolen from the Arizona Department of Public Safety (DPS).

The 440MB of data included emails, handbooks, images and other sensitive files, some of which revealed the identities of Arizona Law Enforcement. In sifting through the data, Techland uncovered a form particularly interesting to iDB entitled “iPhone apps- used against officers.docRead More

 

iOS 4 Encryption Broken by ElcomSoft

By Cody Lee on May 24, 2011

Up until the Cupertino company launched iOS 4 last year, there wasn’t any real data protection for iDevices. This left much of the government and enterprise market who require top notch security, holding onto their BlackBerry devices.

iOS 4 brought about industry-standard AES-256 encryption. The new protection consisted of encrypted key sets that were either tied to the device or to the iDevice user’s passcode. Up until now, that encryption has been fairly unbreakable… Read More

 

More iPhone Security Issues Exposed, Passwords Cracked in 6 Minutes

By Jeff Benjamin on Feb 10, 2011

It seems like at least once a month we report a story about the iPhone’s security problems, and this latest security revelation is a bit shocking.

Researchers from the German Fraunhofer Institute Secure Information Technology have discovered a way to crack iPhone passwords via jailbreaking in about 6 minutes.

We don’t mean your iPhone’s dinky 4-digit passcode either; we mean everything stored in your keychain; email, VPN, Wi-Fi, the list goes on…

Read More