Jailbroken idevices pwned by charging stations

Powered by SC Magazine
 

USB mode silently comes to life.

Data can be stolen from Windows, Android and Apple devices by unassuming power charging towers.

In an attack demonstrated at the Defcon hacking conference, mobile phone charging units were rigged to pull data from phones plugged into them.

They were laced with different power charging adaptors to make them more appealing.

Some stock phones were safe since they deactivated USB mode when they were powered off, but others were not so lucky.

Many jailbroken and modified devices activated USB functions when  they were plugged in, or simply rebooted.

That gave security researchers Brian Markus, Joseph Mlodzianowski and Robert Rowley the access they needed to pull data, though they instead served victims with a warning.

“If the phone died due to lack of power, in most cases the phone would boot up upon
plugging it in, then expose the data,” Marcus said.

Three hundred and sixty four people fell for the trick. Each was served with a message that warned of the dangers of using public power charging stations.

The researchers were still crunching over the findings, however Markus said specifications that may mean USB modes were silently actived included the platform and version of operating system and root kits and jailbreaks used, whether custom systems like Android ROMs were used, and the drivers loaded on the host.

Markus said the team was to his knowlegde the first to expose the threat, but said he was suspcious “of certain power kiosks”.

“Our goal is to promote security awareness.  While we do have several other variants of this demo that shows what could happen, we demo them in a responsible way.”

Copyright © SC Magazine, Australia


Jailbroken idevices pwned by charging stations
 
 
 
Top Stories
Australia's digital crescendo
Barely unpacked from his move from Amsterdam, Southern Cross Austereo's new digital boss Vijay Solanki is looking for Australia's untapped potential.
 
Turnbull nabs UK govt digital guru as DTO chief
Inaugural CEO to lead change agenda.
 
NBN to offer TV connections through fibre for greenfields
Ditching aerials to come at a cost.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Xerocon is heading to Melbourne!
Jul 1, 2015
We're not saying Xero is our FAVOURITE or anything, but Xero's 2015 Xerocon conference is being ...
New Microsoft Office apps for Android phones
Jun 26, 2015
Microsoft's latest Office apps for Android now work on phones as well as tablets, further ...
Windows 10 UK price revealed, but don't believe everything you hear
Jun 26, 2015
Windows 10 £99 price tag for users in the UK (who presumably don't already have Win 7 Pro ...
Now Xero notifies iOS users of new transactions
Jun 24, 2015
The latest version of Xero's iPhone app includes notifications when new transactions arrive from ...
Your Essential Cloud Toolbox
Jun 22, 2015
When BIT interviewed Receipt Bank country manager Sophie Hossack, we asked for her thoughts on ...
Latest Comments
Polls
Is site blocking effective in stopping piracy?


   |   View results
Yes
  2%
 
No
  86%
 
Somewhat
  12%
TOTAL VOTES: 754

Vote