Monthly Archives: November 2009

APPLE-SA-2009-11-09-1 Security Update 2009-006 – Mac OS X v10.6.2 & 10.5.8

0
Filed under Apple Updates, Hardening, News, Vulnerabilities
Tagged as , , ,

Along with this Snow Leopard update to 10.6.2, Apple also released a security update for OS X 10.5.8 client and server. The update includes numerous security updates and some feature enhancements, Apple also pulled support for Intel Atom processor which breaks Hackintosh Netbooks.

The update is available via Software Update and Apple’s support downloads site.

iPhone SSH worms making the rounds

0
Filed under Exploits, News, Vulnerabilities
Tagged as , , , , , ,

updated 9.11.09

More variants of iPhone malware are showing up, some claiming to gather personal data from phones. Don’t be surprised with the source code for ikee circulating that more nefarious malware will be coming soon.

JailBroken phone w/ alpine default pswd = pwned phone or a honeypot ;)

iPhone ikee Virus

iPhone ikee Virus

In the past week or so at least four variants of simple worms that look for default ssh passwords on Jail Broken iPhones and replace the backgrounds screens have turned up. The one in the Netherlands is asking users to paypal 5 € to have it fixed.

JD has an interview with the Australian writer ikee and two versions of the source code are available for research purposes. This variant scans a list of subnets for exploitable iPhones and pwns them replacing the background image with a custom one.

Affected users are iPhone users that have JailBroken their phones and NOT changed their default ssh password of alpine. Take a look here at Saurik’s page with detailed instructions on changing your ssh password.