No. 1 Story

ACCC clears Optus to scrap HFC network and use NBN instead

The ACCC has cleared, provisionally, the proposed deal between Optus and NBN Co under which Optus is to be paid around $800m to shut down its HFC network and transfer customers onto the NBN. read more

Related Articles

Adoption of cloud computing has reached a tipping point  - but don’t expect legacy...
In yet another blow to the Facebook IPO this week, following the withdrawal of...
Recruitment technology and social media have played a significant role in growing business in...
Those elusive pocket monsters, the Pokémon are becoming more numerous.  Nintendo announce two new...
Sony has released a Music Unlimited app for iPhone and iPod touch. Sony's Music Unlimited...

iPhone open to SMS attack

Your IT - Mobility

Security researcher Charlie Miller has been digging again, and this time he's found a way to trick the iPhone into running code received as SMS messages.

Miller has become well known in the Mac security sphere, in part due to his repeated success an the PWN2OWN competitions run at the CanSecWest conferences.

Now he has revealed that it is possible to use maliciously formed SMSes to install and run code on an iPhone.

While SMS messages are limited to 140 bytes, there is provision for longer messages to be split into the required number of SMSes and then reassembled by the receiving handset.

Miller's technique allows an attacker to install and run code with root access on an iPhone.

The problem - at least until Apple delivers a patch - is that there is apparently no way of stopping an iPhone from receiving SMSes apart from putting it into airplane mode, which disables the radio completely and makes the handset useless as a phone.

Apart from is PWN2OWN success, Miller has also drawn attention with his "no more free bugs" stance, pointing out that since the identification of security flaws clearly has commercial value for the software companies concerned, otherwise they wouldn't employ people to work on such issues.

(There's also an underground market for such information, as working exploits can be used to plant malware on computers and related devices, which are then used to make dirty money.)