• Follow us on Twitter
  • RSS
We are back, with a new look ... but same old love of all things Apple. close

  • News
  • Stories
    • Opinions
    • Learning
    • Reviews
  • Write to us

Blog - Latest News

Malicious worm targets jailbroke iPhone

0 Comments/ in News / by Jimmy Liew
24 November, 2009

iphone-jailbreak

There is no OS out there in the market that is not vulnerable to attacks – either virus, trojan, worms or hacks. Most of the time, the vulnerabilities are inherent in the OS (think Windows 98), and other times – because of ignorance. So no surprise that not one but two worms sprung out for the iPhone in the last few weeks. First it was just a mild, funny RickRolling of the infected iPhone’s Home screen. But recently, a much more vicious worm that will do much worse is spreading.

In a F-Secure report, it says the worm connects to a server in Lithuania and although not wide-spread, it is trying to steal information from the infected devices:

This one connects to a web-based command & control center running at 92.61.38.16 in Lithuania.

However, thankfully, these worms attack only jailbroke iPhones that also installed OpenSSH and has enabled SSH. However, by default, the root password to access via SSH is the same on all iPhones and since this fact is overlooked by most users who jailbreak their iPhone, it was like having a big NEON sign that says “I am OPEN!”.

So the first thing to do if you have jailbroke your iPhone is to close that open door1.

  1. Begin by installing MobileTerminal via Cydia (alternately, you can login via SSH from Terminal.app or a Cygwin-equipped Windows PC).
  2. Type “login”, you will be asked for a login name which should be “root” then a password which should be “alpine”.
  3. Type “passwd” then tap return, you will be asked to type the new password. Tap return and type the new password again.
  4. Repeat this same process for the “mobile” user by replacing “root” with “mobile” in step 2

Lastly, please take note that Apple doesn’t encourage iPhone users to jailbreak their phones as that might leave them susceptible to similar vulnerabilities and they won’t be responsible for any problems resulting from the jailbreaking. Likewise, we don’t post any stories promoting jailbreaking here.

1 instructions from TUAW

Share this if you liked it:
  • Reddit
  • Tweet
  • Share this:
Tags: iphone, jailbreak
← MacGraPhoto Apps Bundle – 7 apps at 84% discount
1Password Pro for iPhone free till 1 December →
Related Posts
$250k in-app purchase?
About that “one minute” sync update
Copy/Cut & Paste in iPhone 3.0?
iPhone OS 3.0 Software Update – 18 June 1am
Comments

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

*

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Mac Book  B 006  300x250

Have something new?

Got a tip? Launching a new app? Or maybe an exclusive... Let us know.
Email us

Related posts

  1. Setting up MMS for StarHub and M1 iPhone users
  2. PwnageTool and QuickPwn plays catch up with 2.2
  3. NewsBits – Updates for Office, Wired Mythbusters and an MTV
  4. SingTel reveals iPhone replacement due to water-damaged
  5. iPhone exclusivity in Canada to end

Latest Tweets

  • Want something like Kinect on your Mac - check out Leapmotion http://t.co/s7cebZe8 http://t.co/TRpS0M4y
    21 May, 2012 - 11:04 pm
  • RT @theloop: Samsung's bullshit Galaxy pre-order numbers http://t.co/wMXcMxG3
    18 May, 2012 - 10:47 pm
  • Probably not as epic as Diablo 3 but this might come close ... looking forward to Infinity Blade: Dungeons! http://t.co/2bpgGkyx
    18 May, 2012 - 1:20 pm

Popular Posts

  1. Setting up MMS for StarHub and M1 iPhone users
  2. Setting up Tethering on Starhub and M1
  3. Getting into the US iTunes Store with iTunes Gift Card

Archives

Categories

© Copyright - iHeartApple - Wordpress Theme by Kriesi.at