News
Articles
Blog
All Keywords
From
To
Search
Filter
View
Poll

Security hole in SSH of jailbroken iPhones; we now go to stage 3

by crispin . Original by Lionel - 24/11/2009 00:24:00 CET - Source: BBC

It was not difficult it to predict, and now it has happened. A new Trojan horse aiming at the jailbroken iPhones prevails in the Netherlands. It still uses the same fault, that of SSH installed on a iPhone during or after a jailbreak and of which the password of the administrator was left at the default setting and not changed.
This time, one passes clearly to the following stage. This Trojan horse will redirect the customers of Dutch banks towards a phishing site that seems identical on all points and thus will get hold of their identifiers and passwords. The substitution of site being done on the level of the network layer, the anti-phishing systems of Safari are bypassed. 
We remind to you that to be infected by one of these Trojan horses, one should satisfy the following conditions:

  • To have a jailbroken iPhone 
  • To have installed SSH and have kept the default password
  • To be connected to a Wi-Fi network on which there is also an iPhone already infected.

It is of course simple enough to modify the SSH password to be secure from this risk, as long as that which you put in is not too trivial.

Printer Friendly
Tip a friend
List View
Daily View
Full View
Previous
Next
Delicious Digg Facebook Technorati Reddit Blogmarks ShareThis