Technology news and Jobs arrow Information Technology News arrow The first iPhone virus – in the wild
The first iPhone virus – in the wild E-mail
by David Heath   
Monday, 09 November 2009
If you have jailbroken your iPhone, enabled SSH and neglected to change the default password, expect to get infected very soon!

The virus, called Ikee, does a fabulous job of rickrolling iPhone users.  Anyone infected will have their background picture changed to a picture of 1980s pop sensation Rick Astley with a message "ikee is never going to give you up."

Ikee seeks out iPhones with SSH enabled but still using the default password (hint: it's alpine).  On non-jailbroken phones, SSH is disabled by default and so such users are unlikely to be affected; this is more likely to infect jailbroken iPhones which have had SSH enabled to permit easy access from other computers.

Sophos' Graham Cluley, writing in his blog says "The worm will not affect users who have not jailbroken their iPhones or who have not installed SSH."  He goes on to say that "SophosLabs is analysing the worm's code, which suggests that at least four variants have been written so far. One of the attributes of the latest variant (labelled the "D" version) is that it tries to hide its presence by using a filepath suggestive of the Cydia application.

"The source code is littered with comments from the author suggesting the worm has been written as an experiment. One of the comments berates affected users for not following instructions when installing SSH, because if they had changed the default password the worm would not have been able to infect them."

It appears that the worm does nothing more than change the background and go looking for other iPhones to infect; but that doesn't make it innocuous.  Such access is well-defined as illegal under Australian law; additionally, the virus is a perfect test-bed for other, more malicious, people to add their own payload.

Amusingly, Cluley's blog seems to expose the identity of the virus writer as a young man from Woollongong.  Readers can look at the blog for details – they won't be written here.

"If you have a jailbroken iPhone, change your SSH passwords now," urges Paul Ducklin, Sophos's Head of Technology, Asia Pacific. "If you don't have a jailbroken iPhone, you probably also ought to change those passwords, since it makes no sense to have poor passwords pre-configured for any operating system service, whether it runs by default or not.

Ironically, it seems that Apple don't want you to do that -- just the sort of operational restriction which led to jailbreaking in the first place."

(The author does not own an iPhone.  Perhaps a reader might like to add instructions on changing the SSH password as a comment to this article)

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter