iPhone SMS Vulnerability Found

At the SyScan conference in Singapore, Charlie Miller described a vulnerability in the iPhone’s SMS system, a flaw that Apple iPhone 3G WWDC 2009could “allow an attacker to remotely install and run unsigned software code with root access to the phone.

It’s unlikely that this will be exploited vastly, but it’s still a very serious risk due to the sheer numbers of iPhones out there. According to the security researched said that the attack “exploits a weakness in the way iPhones handle text messages received via SMS (Short Message Service),” however he has made an agreement with Apple to keep the details out of the press so that Apple have a chance to fix it before someone else figures it out and makes matters more serious.

Miller only gave the following information concering the vulnerability: “The SMS vulnerability allows an attacker to run software code on the phone that is sent by SMS over a mobile operator’s network. The malicious code could include commands to monitor the location of the phone using GPS, turn on the phone’s microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet.

Miller will be going into more detail of this at the Black Hat USA expo in Las Vegas later on this years, giving Apple a chance to patch it. Apple have planned to get a fix ready for later this month.

Apple Removes BeautyMeter

After all the complaints that have been directed towards the photo rating app, BeautyMeter, Apple have finally pulled it down.

BeautyMeter

The app is photo sharing platform where you rate others pictures based on appearance, however the company does not directly check each picture and so pictures of underage girls were found on the app and caused a huge uproar against Apple’s approval process, once again.

New Features in iPhone OS 3.1 Beta

Apple released the iPhone OS & SDK 3.1 Beta yesterday. Here’s a list of what people have found to be changed so far:Apple iPhone 3G WWDC 2009

– MMS is now enabled by default (Still not supported by AT&T).
– A “Fraud Protection” toggle is now available in Safari settings.
– Voice Control over Bluetooth is now available, allowing users to Initiate calls and control music playback via Bluetooth headsets.
– iPhone startup and shutdown and app launching times have improved.
– Trimming video clips on the iPhone 3GS now offers the ability to save the edited version as a copy rather than simply overwriting the original file.
– New APIs allow developers of third-party application to access and edit videos.
– iPhone vibrates when rearranging Home screen icons.
– OpenGL and Quartz have seen improvements.

O2 Get Palm Pre in the UK

The official iPhone UK carrier O2, have been reported that they are to be the official carriers for the Palm Pre. O2 has always Palm Prehad a strong smartphone market in the UK and with the iPhone and Pre being sold in the same store it will make things a little more interesting.

It seems this will be true as the O2 owner Telefonica, reportedly secured global rights to the Pre back in March.

O2 owner Telefonica reportedly secured broad global rights to the Pre back in March

Apple Releases iPhone Firmware & SDK 3.1 Beta

Apple today, released the 3.1 beta for the iPhone firmware and SDK; both the SDK and the firmware are available for Apple iPhone 3G WWDC 2009testing and development to paid members of the iPhone developer program. Although this is pre-release software and details should remain under NDA, some details will leak out soon.

Some wonder why Apple have released the 3.1 Beta so close to the release of 3.0 to the public. Some think that it’s not just bug fixes, as Apple would probably release it as 3.0.1 if so. Apple may have worked out the exploit in which the Dev-Team use to jailbrake devices and patched it in this new release, so upgrading is to be taken at your own risk and may stop you from jailbraking until the Dev-Team work it out.

iPhone OS 3.1 Beta

Developers Continue To Fight Piracy

As the iPhone user-base increases, so does the piracy user-base of iDevices. Many developers have been or are now implementing features to stop piracy of their apps. You will have read how BeejiveIM stopped working for pirated copies, now Spokko, the makers of Light Wars have also implemented a feature that stops pirated copies from working.

Spokko Pirate Version

This has only been implemented into the new update but from what I know the original 1.0 release will not stop pirates using it, it’s interesting to see how developers are taking different methods to stop piracy.

Stack v3 Alpha Review Coming Soon

If your an iPhone owner you will of most likely have heard of, or used one of Steve Troughton-Smith’s app’s at some point or at least heard of them. He was the one who worked out how to tether the iPhone months ago.

He currently has 6 projects listed on his official website some of which are App Store approved, others are available via Cydia, however a project he’s been working on a lot recently is the Stack app, which gives the iPhone and dock like Stack feature. The new v3 has a lot of things to look forward to and the early alphas are promising, I’ve got hold of the alpha earlier and will be writing up a full review over the weekend.

Stack v3 Alpha

iPhone 3GS Jailbreak & Unlock Coming Soon

The Dev-Team announced today that the 24Kpwn exploit that the hybrid team used on the iPod Touch 2G, is still Jailbrakeapplicable to the bootrom of the iPhone 3GS, therefore meaning the same sort of technique can be used as current jailbraking tools such as redsn0w.

The good news is also ultrasn0w can used used on the iPhone 3GS, without any modifications.

Apple are still continuing there effort to fix these flaws in the iPhone which allow for jailbraking and it will take a while for the Dev-Team to safely work out the new efforts made by Apple, ready for the new tools.

Ultrasn0w Released!

The Dev-Team today announced the release of the avidly awaited Ultrasn0w soft unlcock for iPhone & iPhone 3G, not the Jailbrake3G S yet, as that’s not been jailbroken.

Follow these instructions to get Ultrasn0w:

  1. Ensure you have upgraded to iPhone OS 3.0
  2. Jailbreak your iPhone 3G using redsn0w or PwnageTool (this will also install Cydia/Icy)
  3. Run Cydia or Icy
  4. Please add the repo repo666.ultrasn0w.com to Cydia or Icy. That last “o” is actually the number zero “0”! If you use the letter “o” you’ll get an error.
  5. Search for ‘ultrasn0w’ in cydia or icy and install ultrasn0w
  6. Reboot your iPhone 3G
  7. T-Mobile USA users should disable 3G before using ultrasn0w
  8. Enjoy