Security hole in SSH of jailbroken iPhones; we now go to stage 3
It was not difficult it to predict, and now it has happened. A new Trojan horse aiming at the jailbroken iPhones prevails in the Netherlands. It still uses the same fault, that of SSH installed on a iPhone during or after a jailbreak and of which the password of the administrator was left at the default setting and not changed.
This time, one passes clearly to the following stage. This Trojan horse will redirect the customers of Dutch banks towards a phishing site that seems identical on all points and thus will get hold of their identifiers and passwords. The substitution of site being done on the level of the network layer, the anti-phishing systems of Safari are bypassed.
We remind to you that to be infected by one of these Trojan horses, one should satisfy the following conditions:
- To have a jailbroken iPhone
- To have installed SSH and have kept the default password
- To be connected to a Wi-Fi network on which there is also an iPhone already infected.
It is of course simple enough to modify the SSH password to be secure from this risk, as long as that which you put in is not too trivial.