Dutch Hacker Hack’s Into Jailbroken iPhone’s

A Dutch hacker used a port scanning to identify jailbroken iPhones on T-Mobile Netherlands with SSH running.Jailbroken iPhone HackedJailbroken user’s commonly use SSH to run standard UNIX commands on their iPhone. However, due to the way it’s set up all iPhones have the same default root password that most people don’t change. This means if a user knows a iPhone is close running SSH they can access all of the files on the device.

The Dutch hacker used the unchanged root passwords to hack into the phones, he then sent a SMS alert to the phones that read, ” You iPhone’s been hacked because it’s really insecure! Please visit doiop.com/iHacked and secure your iPhone right now! Right now, I can access all your files.” Once going to the website it directs the user to send €5 to a PayPal account, after which the hacker will e-mail instructions to remove the hack—which most likely involve restoring the iPhone to factory settings.

The hacker doesn’t appear to have malicious intent, other than to glean some extra cash. “If you don’t pay, it’s fine by me,” reads the page mentioned in the message to the hacked iPhone owners. “But remember, the way I got access to your iPhone can be used by thousands of others—they can send text messages from your number (like I did), use it to call or record your calls, and actually whatever they want, even use it for their hacking activities! I can assure you, I have no intention of harming you or whatever, but, some hackers do! It’s just my advice to secure your phone.”

To stop this from happening to you read the article on How To: Change Your iPhone’s SSH Password.

iPhone Dev-Team Release PwnageTool for 3.1

The iPhone Dev-Team has just released there latest jailbreaking tool, PwnageTool for iPhone OS 3.1. At the minute the Jailbrakejailbreak is for Mac only but hopefully a Windows version will be released soon.

Read More

Download (Torrent)

This release starts with PwnageTool 3.1 for Mac OS X – this application supports the iPhone 1st Generation (2G), the iPhone 3G and the iPod touch 1G. NB: THIS DOES NOT SUPPORT THE 3GS OR 2G/3G IPOD TOUCH. redsn0w for Mac OS X and Windows will follow sometime in the near future, please don’t bug us about it – we’ll release when we have something ready.

  1. GOLDEN RULE: If you are using a 3G iPhone with ultrasn0w and rely on ultrasn0w to obtain cellular service, then you should only upgrade to 3.1 with a PwnageTool created .ipsw. – Stay away from Apple’s direct updates as described here and here please get up to speed on the whole subject by reading the information contained in these posts.
  2. If you have an original iPhone (1st generation) then 3.1 unlock works with this PwnageTool release. iPhone 3G users upgrading to 3.1 will need to continue using ultrasn0w with a PwnageTool created 3.1 .ipsw
  3. Please read all parts of this post before downloading and using these tools.
  4. Read items 1, 2 and 3 again and again.
  5. At the bottom of this post are the bittorrent files for the 3.1 capable version of PwnageTool.
  6. This app is suitable for the recent 3.1 release.
  7. This version of PwnageTool will NOT work for the iPhone 3GS.
  8. PwnageTool WILL work for Original iPhone (1st Generation), Original iPod touch (1st Generation) and the iPhone 3G.

Dev-Team Confirm No Need For New Jailbreak Tools For 3.0.1

The iPhone Dev-Team have confirmed that there is no need for them to release new tools for Jailbrakejailbreaking the latest firmware 3.0.1.

They released this information:

The 3.0.1 release is a “branch” from 3.0 that occurs (code-wise) before all the 3.1 betas. The programs redsn0w needs to change for the jailbreak are identical when you compare the 3.0 and 3.0.1 versions. It seems pretty much the only changes Apple made were for the SMS bug, which affects programs that redsn0w doesn’t touch. That’s why you can re-use redsn0w 0.8 on 3.0.1 even though it was written for 3.0.

And since 3.0.1 doesn’t touch the baseband either, ultrasn0w 0.9 works for those needing the soft unlock. Just install it from the repo666.ultrasn0w.com repository using Cydia as usual.

We’ll at some point fix redsn0w to recognize both 3.0 and 3.0.1 IPSW’s, but really that’s the only change that would be made to it. Everything else would be identical, so there’s no need to wait for the “proper” version that recognizes the 3.0.1 IPSW as valid.

So to jailbreak the new firmware just use the old tools and you should have no problems.

Apple Releases iPhone OS 3.0.1

Apple earlier today released the latest iPhone OS, version 3.0.1. This update fixes the major SMS security issue that theyiphone_os_3 have finally fixed.

There hasn’t been many changes in the latest firmware release that have been found other than the SMS fix, feel free to email them in if you find any.

If you want to jailbreak your device it has been reported that in most cases it works fine but maybe wait a while until everything gets checked out.

Ultrasn0w Version 0.9 Released

The Dev-Team have released ultrasn0w version 0.9 today. Its features include:

  • Works on both 3G and 3GS
  • Works on hacktivated devices
  • Works regardless of how you jailbroke your device
  • Doesn’t patch any mach-o binary whatsoever.  (Doesn’t require a separate patch as each new firmware comes out).
  • Doesn’t install any additional daemon
  • Has no race conditions, no popups about “Missing SIM”, no network issues
  • Is almost 7000 times smaller than its nearest competition
  • Is available now via Cydia.  Source repo is http://repo666.ultrasn0w.com (that last “0” in ultrasn0w is a zero!)

Read More

Geohot Releases His Own Soft Unlock For iPhone 3GS

Geohot has released his own unlocking software, like ultrasn0w, for the iPhone 3GS. Playing off the Dev-Team’s namingiPhone 3GS Logo scheme he called it Purplesn0w. The user is required to have a jailbroken device so that the unlock can be downloaded through Cydia, like the Dev-Teams unlock.

Geohot also claims that his unlock is superior to the Dev-Teams unlock:

Wifi fails? Battery fails? Unlock fails? You need purplesn0w, the geohot 3GS unlock solution. Now I know you here a lot about different colors of sn0w, but I’m here to tell you why purplesn0w is the best. First off, what is purplesn0w? It’s a soft unlock for your 3GS that I’d actually use day to day. It’s not a daemon that takes any resources, and it doesn’t add a task to your baseband. It’s very close to a true unlock. All it does is patch three files, CommCenter, lockdownd, and your wildcard activation plist(which you need, activate w at&t sim first, no hacktivation support yet). That’s it, no other files are installed. Props to Oranav for the at+xlog exploit!
A full explanation is coming soon, but I think you clever reversers out there will see what it does, and see why it’s so pristine 🙂 The payload is radically different from other varieties of sn0w. beta as usual, back up first.

Be sure to have legit activated 3GS
Disable 3G if you don’t have it(like T-Mobile).
Add apt.geohot.com to Cydia
Install com.geohot.purplesn0w
Watch for success output in Cydia
Reboot, and enjoy your unlocked iPhone

Read More

ultrasn0w 0.8 Released

ultrasn0w 0.8 has been released today and is now fully working on the 3Gs.Jailbrake

The main 3GS ultrasn0w glitch on hacktivated devices is: need to do Settings->General->Reset->Reset Network settings once.

They have said that stability should be drastically improved for unltrasn0w on the 3GS, for some people however it may take up to 75 seconds after reboot.

To get ultrasn0w 0.8 add http://repo666.ultrasn0w.com/ to your sources.