Another iPhone worm has been spotted in the wild.
Unlike the previous exploitation, which merely changed a jailbroken iPhone's wallpaper to a picture of Rick Astley of "Rickrolling" fame, this new threat allows hackers to steal sensitive information.
According to security firm Sophos, which wrote about the exploitation after a Dutch ISP spotted it late last week, the worm attacks jailbroken iPhone and iPod Touch devices only.
The worm "uses command-and-control, like a traditional PC botnet," Sophos wrote in a blog post on Saturday to warn users about the exploit. "It configures two startup scripts, one to execute the worm on boot-up, and the other to create a connection to a Lithuanian server to upload stolen data and cede control to the bot master."
Jailbreaking, which has been around for about two years, is a hack that enables iPhone and iPod Touch users to download applications unavailable through Apple's App Store.
Sophos wrote that the worm attacks users on several ISPs, including UPC in the Netherlands, Optus in Australia, and T-Mobile in several countries worldwide. Worse, the worm spreads faster on a Wi-Fi connection than a 3G connection. Users with affected devices might notice extremely short battery life while on Wi-Fi. According to Sophos, that's mainly due to the worm engaging in "so much network activity."
When a device is infected, it's assigned a unique number so that the attackers can easily pinpoint a single device. It also looks for authentication systems that use SMS, better known as mTANs. mTANs are frequently used by banks that send an SMS message with a password to mobile phones, allowing people to log in to their online accounts, Sophos wrote.
In essence, this threat is serious.
Sophos recommends that people with infected iPhones and iPod Touch devices restore them back to Apple's most recent firmware update. For now, there is no other way to fix the problem.
Don Reisinger is a technology columnist who has written about everything from HDTVs to computers to Flowbee Haircut Systems. Don is a member of the CNET Blog Network, and posts at The Digital Home. He is not an employee of CNET. Disclosure.
Well, this hacker has quite the sense of humor.
Reports started spreading this weekend that iPhone users in Australia had been falling victim to "ikee," a worm that replaces default wallpaper with a picture of Rick Astley, the British pop singer whose song "Never Gonna Give You Up" has gained eternal infamy thanks to the mainstreaming of the "Rickrolling" prank craze. The photo is accompanied by the message "ikee is never gonna give you up," and it's apparently quite difficult to remove. According to security firm Sophos, this is the first worm detected that targets the iPhone.
The vulnerability is pretty specific: the phones must be jailbroken in order to be affected, and it appears to spread by searching an infected phone's contacts to find other jailbroken-phone users who have installed the Unix software SSH (secure shell) but haven't yet changed their passwords from Apple's default root password, "alpine."
Sophos says that it has not heard of any occurrences of the worm outside Australia, and that while it doesn't appear to do anything worse than irritate and embarrass affected users, that it highlights the vulnerabilities that jailbroken phones face.
- prev
- 1
- next





