Protect yourself from SSH-based iPhone worms
The internet has been ablaze with reports of jailbroken iPhones being infested with worms. The exploit takes advantage of unwitting jailbreakers who install OpenSSH on their iPhones via Cydia without taking into account all of the impacts on security. The most notable, and now famous, hole in this theory is that every iPhone ships with the same default password for both the all-powerful "root" user as well as the more-restricted "mobile" user.Not surprisingly, Apple has officially commented on the situation noting that "the worm affects only a very specific set of iPhone users who have jail broken[sic] their iPhones and hacked it with unauthorized software." It is pretty clear from Apple's statement their feelings on the jailbreak community and its effects on the iPhone and iPod touch.
Luckily, if you need to have OpenSSH installed on your iPhone (who doesn't want a remotely-accessible, full UNIX terminal in their pocket?), there is a pretty simple solution to this problem that will prevent this breed of infestation from ever reaching your iPhone.
- Remember, this only affects jailbroken iPhone owners who have installed OpenSSH...
- Begin by installing MobileTerminal via Cydia (alternately, you can login via SSH from Terminal.app or a Cygwin-equipped Windows PC).
- Type "login", you will be asked for a login name which should be "root" then a password which should be "alpine".
- Type "passwd" then tap return, you will be asked to type the new password. Tap return and type the new password again.
In addition to changing the user passwords for your iPhone, another good security measure is to use one of the jailbreak apps like BossPrefs or SBSettings to have a toggle that will disable SSH when not in use. Obviously, having SSH disabled (or not installed) is the best defense against worms of this sort. Got any other iPhone security tips? Let us know in the comments!
Share
Categories
The internet has been ablaze with reports of jailbroken iPhones being infested with worms. The exploit takes advantage of unwitting...
Add a Comment
Here isanothrr good reference.
http://iphoneyap.com/showthread.php?t=621
Here is also a very good and simple way (for everyone) to protect your iPhone:
http://www.citrusblog.net/?p=183
Or, maybe, just maybe... DON'T JAILBREAK YOUR IPHONE.
And mainstream sites shouldn't be talking about this sort of crap.
For those that have never jailbroken, it should be stated that right after the jailbreak process it actually tells you REMEMBER to CHANGE THE PASSWORD. And Cydia has a FAQ about how to do it. I recall seeing it first thing after doing it on my last phone (though that phone is gone and I have not done it since with new phones). And these warnings and FAQ's were listed way before all this hit the news.
November 24 2009 at 8:52 AM Report abuse Permalink rate up rate down ReplyPeople who say "just don't jailbreak your phone - problem solved!" are probably a bit naive to what jailbreaking actually means. For me it means opening up my device, that I have bought, to a whole host of new applications and tweaks that make my iPhone experience all the more enjoyable.
I also think that people who slate others for not changing the default password are being a bit pretentious and elitist. Some tutorials for changing things like application icons and wallpapers require you to have SSH access into your iphone so you can transfer files/images and so on. People who might be a bit uninitiated to the realm of SSH and Unix probably don't know that there is a passwd command to change the default password.
The easiest solution for me was to change the password and only use SSH when I need it (using SBSettings to toggle SSH to off for the rest of the time)
Odd. I thought the reason that viruses where not written for the Mac where because of "security through obscurity". I never realized, but there must be more jail broken iPhones then Mac computers, to make writing a virus worth while.
November 23 2009 at 11:35 PM Report abuse Permalink rate up rate down ReplyYou can unlock the phone without installing cydia. Just use blackra1n. Install snow and uninstall blackra1n. I did it. The only problem I've run into is not being able to use Youtube.
November 23 2009 at 10:33 PM Report abuse Permalink rate up rate down Reply"The most notable, and now famous, hole in this theory is that every iPhone ships with the same default password"
Huh? Hole in what theory?
I have an app called Toggle SSH. Free on Cydia, just turn ssh off.
November 23 2009 at 8:42 PM Report abuse Permalink rate up rate down ReplyHowever when your SSH is on you are vulnerable. This doesn't solve the root of the problem, no pun intended.
November 23 2009 at 9:22 PM Report abuse Permalink rate up rate down ReplyGranted, but why would I ever turn SSH on? I keep it off.
November 23 2009 at 10:53 PM Report abuse Permalink rate up rate down ReplyI have seen a lot of comments with this...
Just don't jailbreak. Simple. Easy.
Well how usefull. Such quality input. How much of your life is now forfilled by typing that comment.
Let me just say that there is a percentage of iPhone owners that are stuck in a must unlock situation.
My case for example is I have moved from the UK to Australia. I still want to use the iPhone that I legitimately own. Oh but here is a thought, I simply cant do that for some unknown reason!
Hot Apps on TUAW
Deals of the Day
more deals- Refurb Apple MacBook Air Laptops: 12" 64GB SSD for $699 + free shipping
- JVC Motion Sensing Clock Radio with Dual iPod Docks for $55 + free shipping
- Apple iPhone Headset with Mic for $4 + $2 s&h
- miFrame Picture Frame Dock for iPad for $64 + $8 s&h
- Refurb Apple iPod nano 8GB MP3 Player for $99 + free shipping, 16GB for $119
- Hannspree Apple-Shaped 28" 1080p LCD HDTV for $270 + free shipping
Software Updates
more updates- EFI Firmware Update brings Lion Internet Recovery to 2010-model Macs
- OS X Lion 10.7.3 released with Safari 5.1.3, Wi-Fi bug fix
- Aperture updated to 3.2.2, addresses Photo Stream issue
- Apple updates Keynote to address Lion issues
- Google Search app gets new look on iPad
- Apple releases Apple TV Software Update 4.4.3



25 Comments