madison

Second iPhone worm behaves like botnet

Vivian Yeo ZDNet Asia | November 23, 2009 5:29 AM PST

Summary

A second iPhone exploit has been identified by security vendor F-Secure, which claims the new worm has botnet capability and is more threatening than its predecessor.
A second iPhone exploit has been identified by security vendor F-Secure, which claims the new worm has botnet capability and is more threatening than its predecessor.

Mikko Hyponen, chief research officer at F-Secure, said in a blog post that the new worm, like the first, affects jailbroken iPhones with SSH (secure shell) protocol enabled and unchanged default passwords. The Finnish security company has yet to give a name to the new threat.

Ikee, another threat that was discovered earlier this month, is said to infect vulnerable phones in Australia. When Ikee strikes, it alters the iPhone's wallpaper to an image of Rick Astley with the message "ikee is never going to give you up".

"The worm is not widespread, but it is much more serious than the first iPhone worm as it seems to try to steal information from the devices," Hyponen said about the new worm in the blog post.

For more, read "Second iPhone worm behaves like botnet" on ZDNet Asia.

Talkback Most Recent of 107 Talkback(s)

  • That'll teach them what happens to jailbreakers!
    This only hits those who deliberately climbed
    the fence and ventured into the dangerous
    would outside Apples walled garden.

    Victims of this have nothing on Apple for this.
    The vulnerability was introduced by their own
    (incompetent) actions, but knowingly non-
    sanctioned by Apple.

    The learning: You better stay inside. Trade
    your freedom in for your safety and protection.

    Reminds me of my all-time favorite Pink Floyd
    tune:

    "So, so you think you can tell Heaven from
    Hell,
    blue skies from pain.
    Can you tell a green field from a cold steel
    rail?
    A smile from a veil?
    Do you think you can tell?
    And did they get you to trade your heroes for
    ghosts?
    Hot ashes for trees?
    Hot air for a cool breeze?
    Cold comfort for change?
    And did you exchange a walk on part in the war
    for a lead role in a cage?
    How I wish, how I wish you were here.
    We're just two lost souls swimming in a fish
    bowl, year after year,
    Running over the same old ground.
    What have you found? The same old fears.
    Wish you were here."
    ZDNet Gravatar
    honeymonster
    23rd Nov 2009
  • Morron of the week!
    You won!

    Seriously. it is 110% Apple fault. They illegally lock the iphone in the 1st place.
    ZDNet Gravatar
    Mectron
    23rd Nov 2009
  • ZDNet Gravatar
    jmiller1978
    23rd Nov 2009
    • Flagged
  • iPhone has discovered what MS always knew...
    Apple and many of its users always thought that the viruses for Microsoft was from poor technology? Well not they are learning the hard truth. Its not from poor technology but from being a good popular technology. Apple has just never been good till the iPhone (unless you wanted to browser the internet or edit photos of grandma). So as they wonder into usefulness and popularity, they find themselves falling victim to their own marketing? Is the iPhone a crappy system because it can get viruses? If you listen to Apple fan boys and Apple itself, yes, the iphone is bad.

    If you listen to us tech geeks, you will know the truth. Good usable platform = Popularity = viruses made for you.
    ZDNet Gravatar
    Millystone
    23rd Nov 2009
  • Popularity and viruses
    Here's a race: which platform will get hacked first: iPhone or Android?
    there are millions of (non-jail-broken) iPhones sold, so an attractive
    target now. When there are millions of Androids out there, they will
    become an attractive target. So which will be seriously hacked first?

    By the way: I think "Jail-broken" or "Jailbroken" would be the proper
    spelling, not "jail-breaked" - and very much not "jail-braked." IMHO, of
    course.
    ZDNet Gravatar
    levinson
    23rd Nov 2009
  • No iPhone worm yet.
    No viruses or botnets yet for iPhone, so why all this hype over somethink
    not even invented yet, any platform - it's security can be attacked, we all
    know this and if one is stupid of enough to install software that requires
    you to change the default password and you ignore it and get attacked, it
    is not it was not secure, it is down to human error, not the security as it
    was fine.
    ZDNet Gravatar
    XArt
    23rd Nov 2009
  • @levinson
    Apple are about to release the iPhone to China, last I checked. They've already been hacked multiple times, and Apple has the advantage of being Apple. Everybody loves the shiny. =P

    So no race. iPhone has been hacked, and will be hacked more than Android until Google manages to take over the phone industry from Apple. (which will be never)
    ZDNet Gravatar
    Cyberjester
    29th Nov 2009
  • amen..
    amen to that, as previously advertised, there are not many viruii/trojan written for the apple computer itself because of it's lack of total popularity. anything that has software written on it, is hackable.

    if you build it, they will come. is the saying?

    this is normal. beta testing is (dare i say) open to the public in this platform.

    if you mod it, and add port holes... don't go crying down the river when your 'personal information' is jacked.

    (at this moment, i really feel sorry for those whom store their banking/credit information in those 'secure' apps right about now... oh wait, no i dont?)
    ZDNet Gravatar
    zerosine@...
    23rd Nov 2009
  • There's somethign to that...
    ...but I think it's a bit too simple.

    Certainly, iPhones are the trendiest phones on the scene. But last time I checked, many more people had Nokia or Blackberry phones. So at the very least, you have to factor in usability and media exposure along with popularity.

    Part of the reason this happens, though, is because Apple doesn't take iPhone users seriously. Instead, they force users to "jailbreak" their phones before they can really take control of their phones. iPhones are handheld computers. There's no way around that. What in the world would cause someone to accept a situation where they couldn't administer his or her own computer? That's astonishing on its face.
    ZDNet Gravatar
    bhartman36
    23rd Nov 2009
  • "Apple doesn't take iPhone users seriously."
    You mean the users who install a command shell to circumvent the
    manufacturer's built-in security paradigm, and then don't bother to
    change the password on this brand-new garage door they just put onto
    their mobile computer?

    Well, I don't take them seriously either.
    ZDNet Gravatar
    matthew_maurice
    23rd Nov 2009
  • Not a popularity contest
    This worm came into existence because of the ease of the exploit: scp
    some executables over since you already know the platform, the root
    user's password, and exactly what the file system layout is.

    This worm did not come into existence just because jailbroken iPhones
    are such a huge portion of the smartphone market.

    TL;DR: ikee worm came into existence because there was an easy
    vulnerability to exploit, not because jailbroken iPhones are popular.
    ZDNet Gravatar
    grail@...
    23rd Nov 2009
  • I have to agree
    This guy hits it on the head, and I've said it myself. No OS is safe. There's always someone that can beat any system. My roommate also noted the commercials from Apple of late don't help any; it's like taunting. Welcome Apple fans to most other people's reality.
    ZDNet Gravatar
    mlbslugger
    23rd Nov 2009
  • The Blame is at Apple's Feet, Same as M$!
    It's simple! ....close source Insecurity breeds closed sourced disasters. Linux is the only Secure OS. Made by the NSA itself with the Secure Linux Kernel. That still does not rely on the fallacy that a Micro Kernel or Hybrid System is better.

    That's why Linux is the smart choice for Super Computers (most of any other OS), HPC Clusters (over 90%), Banks, Stock Exchange Servers, DOD, DOE and now the most powerful Super Computer on the Planet. The IBM 1.8 PFLOPS Roadrunner. That will soon grow to 28 PFlops. So tell me who would YOU rather trust Apple, M$ or yourself. Google is only fostering an Open Source development of Linux. They don't even claim to own it, nor does IBM!

    Linux is the ONLY mainstream OS that actually belongs to YOU. The others keep your computer's routes open, so they have remote control of their software and YOU. Thus leaving open doors for not just them, but the criminals out there as well.

    Why do you think Google's future Chrome OS and Android platform is so secure. Because it's not on as many phones? NO!... Because it runs on Open Source SecureLinux Kernel with all applications running as Applets (java is now Open Source as well). Whereas Apple's iPhone OS, OS-X and M$'s Windows applications all run directly on the hardware and operating system. Android and Google's future Chrome OS will be more like a Java OS. Running on top of the SecureLinux Kernel. Where all applications are isolated from the OS!!!

    Google Chrome's main features will be an OS that is first and foremost, on SecureLinux Kernel. That is fully upgradable and most of all, you own it. Along with the power to control it! ...and that neither Apple or Microsoft want you to have!!!!
    ZDNet Gravatar
    i2fun@...
    23rd Nov 2009
  • Down troll, down!
    This is NOT and never was about linux! My God man, stick to the topic at hand. Freaking linux trolls...
    ZDNet Gravatar
    Pete "athynz" Athens
    24th Nov 2009
    • Flagged
  • @i2fun
    ... *sighs* Trolls these days.. At least _try_ and make a decent argument.

    Apples OS is built on Darwin, a BSD variant. The iPhone OS is simply a cutdown version of the normal Apple OS.

    Linux can be hacked, Apple can be hacked, MSFT can be hacked. Only difference between them is:
    With Linux you have to fix it yourself.
    With Apple you have to wait months for a patch.
    With MSFT you get quick patches and a secure dev cycle, but are using the most popular software around so you're going to get hacked anyway.

    *shrugs*

    Oh, and Google reads your emails. =P As if any sane person would use an OS that monitored everything you do..
    ZDNet Gravatar
    Cyberjester
    29th Nov 2009

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity