NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 CIO BlackBerry News and Tips
 CIO Research and Analysis
 CIO Microsoft
 CIO Insider
 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Develop Your External Leadership Skills

A collection of essays from CIO Executive Council members on understanding and developing the external-facing leadership competencies of "customer focus," "commercial orientation" and "market knowledge." CIOs from Best Buy, Universal Orlando Resort, Direct Energy and others describe how they have learned to anticipate customer needs, become market savvy and identify and enable commercial opportunities.

The CIO Paradox: Is IT Set Up to Fail? - FREE Webcast Jan. 19th

CIOs run what may well be the toughest function in the business, with end-to-end responsibilities across multiple levels of infrastructure, data management, processes and people. Yet you spend inordinate amounts of time justifying your existence. Join your fellow CIOs in this town-hall-style CIO Executive Council teleconference on rethinking IT governance, re-educating CEOs on IT value and enabling the profession to attack and defeat this "CIO Paradox."

Characteristics of Transformational Leaders - FREE Webcast Jan. 7th

Leaders come in all shapes, sizes and personalities. However, most great leaders share key traits which allow them to transform their organizations. Learn about some of these traits, how they manifest themselves in the workplace and how you can work towards adding them to your repertoire. Our seminar leader is Larry Bonfante, CIO of the U.S. Tennis Association.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
 

Jailbreaking Puts IPhone Owners At Risk, Says Researcher

Jailbroken iPhones are much easier to hijack, security researcher Charlie Miller said today, and the proof is in the ikee worm that has infected some Australian phones.

 

November 09, 2009Computerworld

Jailbroken iPhones are much easier to hijack, a noted security researcher said today, and the proof is in the worm that has infected some Australian phones.

The worm, known as "ikee," has been billed as the first iPhone worm, a title that Charlie Miller, famous for hacking iPhones and Macs, said is accurate. "I'd say it was a worm," said Miller. "It spreads, and it executes remote code, so it's a worm." Miller also agreed that it was the first, saying that although he and others have crafted exploits that compromise the iPhone, they have never been wrapped into a worm.

Miller, formerly with the National Security Agency and now an analyst with Baltimore-based Independent Security Evaluators (ISE), was one of three researchers who uncovered the first iPhone vulnerability in July 2007, just weeks after Apple debuted the smartphone. He's also known for successfully hacking Macs two years running at the annual "Pwn2own" contest, and is the co-author of The Mac Hacker's Handbook .

The ikee worm was released last Wednesday by Ashley Towns, a 21-year-old unemployed programmer from Wollogong, Australia, who told the IDG News Service that he intended it as a prank, and as a lesson to users who jailbroke their iPhones.

Miller, however, said that the lesson is more than the one Towns maintained: that users should change the default password of the SSH (secure shell) Unix utility. Towns' worm accessed others' iPhones using that default password, then changed their devices' wallpaper. SSH lets users connect to their iPhone remotely over the Internet over a encrypted channel.

"A year ago, I didn't think that jailbroken iPhones were less secure than those that weren't jailbroken," said Miller. "But I've changed my mind."

By jailbreaking an iPhone -- the term describes the process of modifying a device so its owner can download and install unauthorized software -- people leave themselves open to attacks that an unaltered iPhone would easily deflect, said Miller.

"The obvious reason why they're less secure is that you get extra software on the iPhone when you jailbreak," noted Miller, referring to the tools necessary to both hack the smartphone and install applications not approved by Apple. "But there are other, less-obvious reasons, too."

Among the latter is the fact that by design, a jailbroken iPhone allows software to run as "root," the Unix-based user account allowed to access the entire operating system. That gives hackers automatic access to everything on the iPhone, something not possible on a standard iPhone without an existing vulnerability and a working exploit.

 
 
Loading...
RELATED
 
WHITE PAPERS

Don't Sacrifice Speed

Learn how to ensure custom content is obtained in a fast manner and doesn't drive your customers away.
 

How Web Site Performance Impacts Shopper Behavior

A new study identified two seconds as the new threshold for acceptable Web page response times. Exceed two seconds, and youre liable to lose the shopper...
 

Is an energy-wasting data center draining your bottom line?

This white paper looks at two key ways that data center managers can improve end-to-end energy efficiency: by changing the voltage of power distribution and by taking advantage of new, high-efficiency, multi-mode uninterruptible power systems (UPSs).
 

Which UPS is Right for the Job

This white paper describes how various UPS topologies work and looks at the impact of operating mode on five key factors of UPS performance.
 

Maximize PC Energy & Cost Savings in a Windows 7 World

This desktop upgrade presents organizations with a unique opportunity to reduce energy waste.
 

Secrets to Shrinking Your Storage

Realize great capital and operational savings by leveraging Microsoft® Windows® 2008 Hyper-V™.
 

WEBCASTS

A Holistic Approach to Compliance Makes Business Sense

Too often, companies consider compliance a check-box project rather than a strategic process. IT management has tre...
 

Top to Bottom Performance Management Excellence at the City of Chicago

In this featured City of Chicago case study, learn how the City's performance management efforts leveraged BIRT Per...
 

Virtualize with Microsoft and NetApp Increase Application Uptime with Windows Server 2008 R2 Hyper-V and NetApp

View this on-demand Webcast to learn how the City of Frisco, one of America's fastest-growing cities, cut capital e...
 

Virtualize SharePoint and SQL Server Now - Maximize Efficiency and Availability with Hyper-V R2 and NetApp

Maximize Efficiency and Availability with Hyper-V R2 and NetApp
 

Unleashing the Power of Customer Data

To hear how companies use feedback from their clients to develop business strategy, watch our video.
 

Does Your Network Let Customers Drive Your Business?

It's no secret that customers exert greater influence over business decisions than at any time in history. But for ...
 

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Build your 1st app FREE with Force.com

Five CIO challenges addressed by better change management

Read about how to add efficiencies with Microsoft Virtualization.

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Secure & simplify your data center w/Juniper Networks.

Gartner ITxpo Panel Webcast: Real-world Early Adoption of Windows 7.

Masters of Virtualization and Cloud Computing - Daily News

Stay informed with custom newsletters from Tech Dispenser

AT&T Synaptic Storage as a Service. Expand on demand

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

Ready to virtualize tier one applications? Check your virtualization maturity.

Upgrading to VMware vSphere with vWire

Top 10 Lessons Learned for Corporate 3G Mobile Broadband Deployments

CRM Built for IT: The Executive Guide to Selecting CRM that Meets IT Needs

ROI of Application Delivery Controllers

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

White Paper: Right-Sizing Your Power Infrastructure

Mobile Security: The Essential Ingredient for Today's Enterprise

White Paper: 5 Best Practices for Smartphone Support

Efficiency goes up. Costs come down.

Maximizing efficiencies with unified communications.

Verint Systems. Discover the Power of Intelligence in Action"

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Forrester Webcast - Managing Desktop Support Costs

Be Prepared for Windows 7. Register for this Webcast Series.

Top Five CIO Challenges

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion.

Trend Micro ranked #1 against real-world malware. Read more.

See how AT&T can help protect your network.

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community

Removing Barriers To Better Server Virtualization Efficiency

4G Revisited. The Continued Evolution of Wireless Mobility.

What's Next for Enterprise Resource Planning?

Gartner Magic Quadrant, Application Delivery Controllers 2009

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Cut Costs & Green Your IT Operations with PC Power Management

Webcast: Unleashing the Power of Customer Data

SharePoint - Unchecked growth of content is unsustainable.

White Paper: Legacy Tools: Not Built for the Helpdesk