iPhone as network-enabled root shell

Welcome to Linux Screw! If you're new here, you may want to subscribe our RSS feed.

apple logoWell known security expert H.D. Moore published entertaining article on how to make your Apple iPhone to be a hacking platform…

Having a network-enabled root shell in my pocket is great, but being able to pop a root shell on someone else’s iPhone is even better. A few things to keep in mind:

Every process runs as root. MobileSafari, MobileMail, even the Calculator, all run with full root privileges. Any security flaw in any iPhone application can lead to a complete system compromise. A rootkit takes on a whole new meaning when the attacker has access to the camera, microphone, contact list, and phone hardware. Couple this with “always-on” internet access over EDGE and you have a perfect spying device.

Read more… 

 
 
» You might also be interested in the following articles:
Quick copy/paste MySQL Replication Manual
Why use SUDO instead of SU?
FAQ: Change forgotten or lost MySQL root password
Quick shell change for user in Unix or Linux
How to restart/stop/start networking in FreeBSD



» Want to stay up to date? Subscribe to our E-MAIL or RSS feed!


4 Responses to “iPhone as network-enabled root shell”


  1. 1 The IT Guy

    You could buy a laptop and use your existing smartphone as a wireless modem. Not as cool as the iPhone trick but probably more practical especially if you need to do more than a simple command.

  2. 2 artiomix

    The IT Guy,

    Actually, having read Moore’s article I was amazed that iPhone’s applications are running with root privileges. It’s unacceptable from security perspective. I guess you agree with me. Now I understand why Apple tries to prevent spreading of third party or community developed applications for iPhone…

  1. 1 iphone » iPhone as network-enabled root shell
  2. 2 iPhone as network-enabled root shell

Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word




Friendly Sites:Who is behind Linux Screw?
Aspiring Sysadmin | GeekyBits³ | Bash Cures Cancer | TOTMS
Linux Operating System | Small Linux Deployments | My SysAd Blog
The Danesh Project | ZEPY | Linux config Wiki | Planet Sysadmin
The Sys Admin | {buhay sysad} | a non-geek's linux notes
Linux HOWTOs, Tutorials & Projects with Adam Palmer | LinuxAlt.Com
My name is Artem Nosulchik (artiomix AT gmail DOT com) and I'm Linux/Unix, Cisco systems engineer. The main idea of Linux Screw is to share relevant knowledge, skills and observations over The Web. Here you can find a lot of information related to different Linux distributions, FreeBSD, IOS as well as a other Open Source around staff. Read more ››