A New iPhone Worm is Here, And This Time it’s Malicious. | Information Technology / Computer Talk | Forum


Please consider registering

sp_LogInOut Log In sp_Registration Register

Register | Lost password?
Advanced Search

— Forum Scope —

— Match —

— Forum Options —

Minimum search word length is 3 characters - maximum search word length is 84 characters

sp_Feed Topic RSS sp_TopicIcon
A New iPhone Worm is Here, And This Time it’s Malicious.
November 27, 2009
2:02 pm
Forum Posts: 4297
Member Since:
April 9, 2009
sp_UserOfflineSmall Offline

A couple of weeks ago, the first iPhone worm appeared, spreading on jailbroken devices with the SSH application installed (vulnerability being the fact that many users haven’t changed the default root password). As far as worms go, this one was quite benign, merely “rickrolling” users; i.e., changing the background image on the device to an image of Rick Astley.

Now, according to early reports of strange activity by Dutch ISP XS4ALL, and later confirmed by Sophos, there’s a new worm in the wild, and this one is far more malicious.

The new worm is called “Duh” or “Ikee.B”, and it uses the exact same vulnerability as the first one. The fix is thus identical – change the root password in the SSH application to something other than the default, which is “alpine”.

Failing to do so might result in very serious consequences. According to Sophos, Ikee.B is “designed to connect to a server in Lithuania and to follow orders from remote hackers.” It can find vulnerable iPhones on a wide range of IP addresses, including IPs in several different countries, for example the Netherlands, Portugal, Australia (Australia), Austria, and Hungary. Furthermore, it changes the root password on the iPhone to “ohshit” (as discovered by Paul Ducklin, head of technology in Sophos Asia Pacific.)

Users who haven’t jailbroken their iPhone or haven’t installed the SSH application are not affected by this vulnerability.

Forum Timezone: America/Los_Angeles

Most Users Ever Online: 288

Currently Online:
46 Guest(s)

Currently Browsing this Page:
1 Guest(s)

Top Posters:

greeney2: 10275

bionic: 9870

Lashmar: 5289

tigger: 4576

rath: 4297

DIss0n80r: 4161

sandra: 3858

frrostedman: 3815

Wing-Zero: 3278

Tairaa: 2842

Member Stats:

Guest Posters: 2

Members: 24663

Moderators: 0

Admins: 2

Forum Stats:

Groups: 8

Forums: 31

Topics: 8966

Posts: 124108

Newest Members:

john peter, German, Cajun, erica, kode, doninbran21, MYSTIFY, kregg, donel clark, Codetrader

Administrators: John Greenewald: 634, blackvault: 1776