Showing posts with label iPhone. Show all posts
Showing posts with label iPhone. Show all posts

Fring Brings VoIP to Hacked iPhones

Fring, the company founded by Avi Shechter, the former co–CEO of ICQ and VP at AOL, has announced that it released a test version of its popular application which brings Skype, as well as MSN, Google Talk and AIM to Apple's iPhone.

"This special pre-release version of fring, developed in conjunction with the Holon Institute of Technology academic research labs is a direct response to iPhone users kicking our behind to get fring for their COOOOOL devices," the company said on its website.

"Part of the objective here (besides getting you all excited with fring for iPhone) is to get feedback prior to release of the full-feature version and create a truly superb user experience for iPhone users," Fring says.

The fring application is only available to those who jailbroke their iPhones or iPod Touches. The application is not endorsed by Apple which is against VoIP applications for its gadgets. This is the case because access to free calls could dramatically cut into the profit margins of the carriers licensed to supply the handset, and everything Apple does is about large profit margins (like its Mac desktop computers). Also, application runs in the background, which is forbidden by Apple.

Of course, the iPod Touch does not have a microphone so you need the Touchmods dock connector microphone.

Fring, also co-founded by Boaz Zilberman and Alex Nerst, is headquartered in Israel, and has representation in Italy, UK and Germany. In February, BusinessWeek reported that more than 100,000 new users from 160 countries were downloading, installing, and registering to use fring each month.

About the security content of the iPhone 1.1.1 Update



The Apple Product Security website:

"For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security"

For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key."

To learn about other Security Updates, see "Apple Security Updates."

iPhone v1.1.1 Update

Bluetooth

Impact: An attacker within Bluetooth range may be able to cause an unexpected application termination or arbitrary code execution

Description: An input validation issue exists in the iPhone's Bluetooth server. By sending maliciously-crafted Service Discovery Protocol (SDP) packets to an iPhone with Bluetooth enabled, an attacker may trigger the issue, which may lead to unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of SDP packets. Credit to Kevin Mahaffey and John Hering of Flexilis Mobile Security for reporting this issue.

Mail

Impact: Checking email over untrusted networks may lead to information disclosure via a man-in-the-middle attack

Description: When Mail is configured to use SSL for incoming and outgoing connections, it does not warn the user when the identity of the mail server has changed or cannot be trusted. An attacker capable of intercepting the connection may be able to impersonate the user's mail server and obtain the user's email credentials or other sensitive information. This update addresses the issue by properly warning when the identity of the remote mail server has changed.

Mail

Impact: Following a telephone ("tel:") link in Mail will dial a phone number without confirmation

Description: Mail supports telephone ("tel:") links to dial phone numbers. By enticing a user to follow a telephone link in a mail message, an attacker can cause iPhone to place a call without user confirmation. This update addresses the issue by providing a confirmation window before dialing a phone number via a telephone link in Mail. Credit to Andi Baritchi of McAfee for reporting this issue.

Safari

Impact: Visiting a malicious website may lead to the disclosure of URL contents

Description: A design issue in Safari allows a web page to read the URL that is currently being viewed in its parent window. By enticing a user to visit a maliciously crafted web page, an attacker may be able to obtain the URL of an unrelated page. This update addresses the issue through an improved cross-domain security check. Credit to Michal Zalewski of Google Inc. and Secunia Research for reporting this issue.

Safari

Impact: Visiting a malicious website may lead to unintended dialing or dialing a different number than expected

Description: Safari supports telephone ("tel:") links to dial phone numbers. When a telephone link is selected, Safari will confirm that the number should be dialed. A maliciously crafted telephone link may cause a different number to be displayed during confirmation than the one actually dialed. Exiting Safari during the confirmation process may result in unintentional confirmation. This update addresses the issue by properly displaying the number that will be dialed, and requiring confirmation for telephone links. Credit to Billy Hoffman and Bryan Sullivan of HP Security Labs (formerly SPI Labs) and Eduardo Tang for reporting this issue.

Safari

Impact: Visiting a malicious website may lead to cross-site scripting

Description: A cross-site scripting vulnerability exists in Safari that allows malicious websites to set JavaScript window properties of websites served from a different domain. By enticing a user to visit a maliciously crafted website, an attacker can trigger the issue, resulting in getting or setting the window status and location of pages served from other websites. This update addresses the issue by providing improved access controls on these properties. Credit to Michal Zalewski of Google Inc. for reporting this issue.

Safari

Impact: Disabling JavaScript does not take effect until Safari is restarted

Description: Safari can be configured to enable or disable JavaScript. This preference does not take effect until the next time Safari is restarted. This usually occurs when the iPhone is restarted. This may mislead users into believing that JavaScript is disabled when it is not. This update addresses the issue by applying the new preference prior to loading new web pages.

Safari

Impact: Visiting a malicious website may result in cross-site scripting

Description: A cross-site scripting issue in Safari allows a maliciously crafted website to bypass the same-origin policy using "frame" tags. By enticing a user to visit a maliciously crafted web page, an attacker can trigger the issue, which may lead to the execution of JavaScript in the context of another site. This update addresses the issue by disallowing JavaScript as an "iframe" source, and limiting JavaScript in frame tags to the same access as the site from which it was served. Credit to Michal Zalewski of Google Inc. and Secunia Research for reporting this issue.

Safari
Impact: Visiting a malicious website may result in cross-site scripting

Description: A cross-site scripting issue in Safari allows JavaScript events to be associated with the wrong frame. By enticing a user to visit a maliciously crafted web page, an attacker may cause the execution of JavaScript in the context of another site. This update addresses the issue by associating JavaScript events to the correct source frame.

Safari

Impact: JavaScript on websites may access or manipulate the contents of documents served over HTTPS

Description: An issue in Safari allows content served over HTTP to alter or access content served over HTTPS in the same domain. By enticing a user to visit a maliciously crafted web page, an attacker may cause the execution of JavaScript in the context of HTTPS web pages in that domain. This update addresses the issue by limiting access between JavaScript executing in HTTP and HTTPS frames. Credit to Keigo Yamazaki of LAC Co., Ltd. (Little eArth Corporation Co., Ltd.) for reporting this issue.

Installation note:
This update is only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an internet connection and have installed the latest version of iTunes from www.apple.com/itunes

iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting "Don't install" will present the option the next time you connect your iPhone.

The automatic update process may take up to a week depending on the day that iTunes checks for updates. You may manually obtain the update via the "Check for Update" button within iTunes. After doing this, the update can be applied when your iPhone is docked to your computer.

To check that the iPhone has been updated:

Navigate to Settings >>General>>About.
The Version after applying this update will be 1.1.1 (3A109a)

Source [securitylab.ru]

Part 2: How to Crack the iPhone

The Second part of the How to Crack the iPhone series:

- Start iTunes. (tested with 7.4.2, might not work with future versions)

- Connect the iPhone, and long-press both the home key and the switch on top for around 30 seconds, until a triangle warning sign appears asking you to connect the iPhone to iTunes.

- On iTunes, click on system restore and flash the device with the latest 1.0 firmware, which as of today is 1.0.2. (might not work with future firmwares, specially the 1.1 series available today on the iPod Touch)

- Wait several minutes (around 5-10 minutes) until the iPhone restarts and iTunes shows it again.

- Kill iTunes and the iTunes helper application.

- Get iNdependence (tested with 1.2.1a) and run it. (more info at the FiveForty.net website)

- Read the README file and download the 1.0.2 firmware from the link on such file. (90MB)

- Click on Activate and wait for some minutes (5-10 minutes). If it takes longer, you can safely kill iNdependence and run it again.

- Get Installer.app App Tapp Beta (tested with v3.1)

- Select firmware 1.0.2 and install it. Again, if this takes more than 5-10 minutes, kill the application and start over.

- From the recently Installer application on the iPhone, install the BSD subsystem, OpenSSH, SummerBoard, and everything else that you want.

- Have fun!

How to Crack the iPhone in 10 steps

Get a Windows machine with administrator rights. Windows iTunes will not see the iPhone’s USB connection.

1. Install iTunes 7.3.0.54. Get it from Apple.

2. Install UltraEdit 32.

3. Download Phone Activation Server v1.0.

4. Using notepad or any other text editor, edit the file “c:\ windows\ system32\ drivers\ etc\ hosts” and add the following line:

127.0.0.1 albert.apple.com

5. Backup the file iTunes.exe on C:\Program Files\iTunes.

6. Edit iTunes.exe using UltraEdit32. Press CTRL-G, enter “2048912“, write “33 C0 C3“. Then Offset 257074, enter “28“. Finally offset “257013“, enter “33 C9 B1“. Save the file and close UltraEdit32.

7. Make sure nothing is running and using the port 80. (e.g. no HTTP server running)

8. Start the Phone Activation Server v1.0 application.

9. Plug the iPhone and start iTunes.

10. iPhone will activate after some seconds and will show some message like “Invalid SIM card”. Slide it to continue and have fun!

How To: Activate the Voicemail Button in Non-AT&T Unlocked iPhones

If you have successfully unlocked your iPhone, you may have discovered already that the voicemail button doesn't do anything at all. It won't give you visual voicemail, but you can easily get the voicemail button to work using any carrier following these steps:
1. First, take note of what your voicemail number is with your current provider (for example, in Spain the Vodafone voicemail number is 177).
2. Click on the phone button in your iPhone.
3. Click on the keypad tab.
4. Tap the following code:

*5005*86*xxx#

The xxx is the voicemail number, in our example it will read: *5005*86*177#

5. Tap call.
6. After a second, the code will have been set.
7. Tap now on the voicemail button and it will automatically call your usual voicemail service.

Unlock iPhone Free Software

The free software iPhone unlock—the only one that counts— has been finally achieved by the iPhone Dev Team and it has been independently tested. Everyone can now unlock their iPhones for free. The unlock was not achieved by GeoHot, who was credited with the first hardware unlocks.

Gizmodo's software mirror: Download iUnlock here (this is the only original iUnlock file.)

Gizmodo's source code mirror: Download iUnlock Source here