The iPhone's inherent security problems
Moore acknowledged that he's looking at the Bluetooth vulnerability. "The Bluetooth SDP vulnerability is the only issue I
am focusing on," he said Friday.
He also hinted that locating vulnerable iPhones wouldn't be a problem. "The Bluetooth MAC (media address control) address is always one less than the Wi-Fi interface's MAC address," he said. "Because the iPhone is always probing for or is connected to its list of known access points, the presence of the iPhone and its Bluetooth MAC address can be determining by using a standard Wi-Fi sniffer.
"Once the Bluetooth MAC address is obtained, the SDP issue can be exploited by anyone within range of the Bluetooth chip, or within range of the attacker's antenna, which can be up to a mile away in some cases," he said.
If Moore manages to craft an exploit and add it to Metasploit, it's probable that criminal hackers will quickly follow. "Once we see something in Metasploit, we know it's likely we'll see it used in attacks," Alfred Huger, vice president of engineering with Symantec's security response group, said in a July interview.
Jarno Neimela, a senior researcher with F-Secure, a Helsinki-based security vendor, also hit the alarm button, but for a different reason. In a posting to his company's blog Friday, Neimela pointed out that there's no security software available for the iPhone, thanks to Apple's decision to keep the device's inner workings a secret.
"The amount of technical information [available about the iPhone] makes it likely that sooner or later someone will create a worm or some other malware," Neimela said. "This will create an interesting problem for the security field as the iPhone is currently a closed system, and it's not feasible to provide antivirus or other third-party security solutions for it.
"So if someone were able to create a rapidly spreading worm on the iPhone, protecting users against it would be problematic."
Although iPhone owners will be automatically notified in the next week that the new patches are ready to download and install, a large number of those who have modified or unlocked their phones will probably forgo the fixes as the 1.1.1 update apparently also disables unlocked phones and wipes unauthorized third-party applications that have been added with various hacks.
Talkback
E-mail
Printer Friendly
Reprints




