Jailbroken iPhones fall victim to Australian virus

  • Email a Friend
  • Print Page
Jailbroken iPhones fall victim to Australian virus
"@harbl I asked him that question and he said that he only found out about the Dutch version of the code when people told him about it. His is quite different to that version."
 
Nov 9, 2009 10:37 AM
Tags: apple | hacker | iphone | australia | ashley | towns | ikee

21-year-old hacker claims responsibility.

iPhone users who have jailbroken their handset to install third-party apps have fallen victim to a virus created by an Australian hacker that alters the phone's wallpaper to a picture of singer Rick Astley.

The hacker, Ashley Towns, a 21-year-old from Wollongong, south of Sydney, claimed the virus was a "harmless" practical joke.

click to view full size image

Hacker Ashley Towns, 21, on his MySpace, and, inset, a picture of Rick Astley, the singer Towns placed on people's iPhones.

The virus relied on the iPhone user leaving a default password unchanged after installing the software that allows them to run third-party apps.

It scanned the IP address range an iPhone was on and then a "random" 20 IP ranges from the American Registry for Internet Numbers (ARIN), Towns said.

The virus had spread to hundreds of iPhones nationwide by early yesterday and has since gone global.

It followed a similar virus where a hacker demanded users pay a fee of five dollars for its removal. But Towns was not demanding money from his version.

iPhone users flooded online forums including Whirlpool reporting the virus as early as Friday.

"I woke up this morning to find that the wallpaper on my jailbroken [iPhone] 3GS had been changed to a picture of Rick Astley (some 80's singer?) with the words 'ikee is never going to give you up'," wrote Whirlpool internet forum user sierralpha.

"Same thing is happening to me," wrote another Whirlpool user jmaust72.

Creator Towns said he "wasn't intending" the virus to spread as far as it did.

Towns, who goes by the alias of "ikee" and other variants, said he hacked the iPhones to "have fun". He hoped affected users would also see the "fun" side.

"I guess the immature side of me kicked in at first," Towns said. "And Rick-rolling is always a way for a cheap laugh.

"I wanted to have fun, and I did."

Privacy breached

But some Whirlpool users failed to see the funny side.

"This is a bit of a jerk move,"  wrote Whirlpool user adamiam.

"Like, yes his justification for doing this was that it will prompt people to secure their iPhone, but it's still quite annoying".

Some users had private photos - which had previously been set as their wallpaper - sent to other user's iPhones.

And other affected users claimed the virus had resulted in excess data usage bills.

Towns admitted pictures of loved ones - in one case an iPhone user's child - had been sent to other iPhones infected by the virus.

"That was a flaw in the first variant [and I] didn't quite think things over too much," said Towns.

"I hope no one got anything too private".

Towns also conceded he had "never thought" about whether the virus would cost users in excess download fees - and in turn higher bills.

"It would be weird if it ... started on the 6th [of November] because ... my billing cycle ends on the 6th and I checked my bill today and I am $200 over my cap, which I think is impossible," alleged one Whirlpool user, JoshuaSpence.

"Worried" about legal fallout

At first Towns claimed he was "aware" of the legal implications of creating the virus but was "not concerned" by them.

He later said on Twitter that the media coverage had gotten him "worried".

Towns said his own iPhone had infected over 100 iPhones. But he couldn't say how many iPhones had been infected by other iPhones.

Towns also said he originally intended to have a user's ringtone changed to singer Rick Astley's 1980s hit Never Gonna Give You Up. He said, at the last minute, he couldn't find an audio converter that made that possible.

Apple's caution

Hacks like this have seen Apple respond by cautioning users against installing software that jailbreaks the iPhone's operating system.

"Customers who have installed software that makes these modifications have encountered numerous problems in the operation of their hacked iPhone or iPod touch," states Apple's website.

Apple recently posted a job listing on its website for an "iPhone OS Platform Security Manager" to oversee a team "focused on the platform security of iPhone OS" and ensuring "secure booting and installation of the OS".

It was believed the job was to secure the iPhone from being jailbroken.


 
Comments: 5
Thoughts on this article? Add a comment below.
Daveh
Nov 9, 2009 11:37 AM
Im not sure how this can be called a hack.

This particular attack is one of the oldest in UNIX history. Attempting to access machines visible to the internet VIA multiple root login attempts over SSH.

To blame the Jailbreak is stupid. Within the Jailbreak SSH is 100% optional and the RPM for iPhone carries the standard SSH warning about access via SSH.

It's pure laziness on the part of users. As you have guessed, i have a jailbroken iphone, which i uses SSH for all kinds of service interactions over the net and have had no trouble at all.

Lets call this what it is users doing silly things, without aiming to understand and getting stung. Educate these people and this kind of garbage will stop.
BrettWinterford
Nov 9, 2009 4:09 PM
I agree DaveH, its arguable if words like 'virus' or 'hack' are applicable here.
bengrubb
Nov 9, 2009 4:41 PM
It's a virus in the way that is spreads to other iPhones.

The Apple dictionary defines a virus as...

"A piece of code that is capable of copying itself and *typically* has a detrimental effect, such as corrupting the system or destroying data."

There was code that was inserted into iPhones. It saw system files changed and it meant users had to reinstall the Cydia app if they wanted regain SSH access.

Edited by bengrubb: 9/11/2009 04:44:20 PM
harbl
Nov 10, 2009 2:12 AM
the kid didnt even wrote the "virus"...
He merely stole the Dutch version of code.
http://www.tuaw.com/2009/11/03/dutch-hacker-accesses-jailbroken-iphones-requests-5/

bengrubb
Nov 10, 2009 7:37 AM
@harbl I asked him that question and he said that he only found out about the Dutch version of the code when people told him about it. His is quite different to that version.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
 
Top Stories
TIO website hit by malware
Weekend malware runs one new process per target machine.
 
Microsoft announces Azure launch date
Australia in second wave of country releases.
 
CBA embarks on "database-as-a-service"
Analysis: How the bank intends to save megabucks.
 

Spotlightthe topics we're following

Latest Comments

"I only became aware of it when news arose that they were ditching it. Maybe it just wasn't ..."
by Ace Feb 10, 2010 10:39 AM
 
"With Optus supposedly boosting this service sounds great, record profits on mobile business ..."
by Johnnnny Feb 10, 2010 9:58 AM
 
"Digger and JL - the two biggest back-flippers in history. (Or are they they same person ?) Now ..."
by marklara Feb 10, 2010 9:56 AM
 
"Once we get past cloud computing, it will be full speed ahead to blue sky computing - although ..."
by Ace Feb 10, 2010 9:52 AM
 
"Maxxi if your reading this I am pretty sure the opinion of Google far outweighs the minority ..."
by Mark D Feb 10, 2010 9:46 AM
1) HTC Magic16 plans 2%
2) Nokia N9743 plans 9%
3) Nokia E7149 plans 1%
4) Apple iPhone 3GS 16GB30 plans 11%
5) Apple iPhone 8GB42 plans 5%
1) iiNet32 plans 5%
2) Netspace36 plans 11%
3) TPG Internet19 plans 14%
4) Optus33 plans 1%
5) Telstra BigPond30 plans 2%

Mobiles | Broadband | Credit Cards

iTnews

Polls

What is the sweet spot for Apple's entry 16GB Wi-Fi iPad?




   |   View results
$549
  77%
 
$579
  11%
 
$619
  4%
 
$649
  3%
 
$699
  5%
TOTAL VOTES: 384

Vote