Monday

iPhone security 101



Since I got an iPod Touch (the iPhone is not available in Belgium), I'm fascinated by all related news. I love the interface and functionality. I'm doing a paper on the threats of mobile devices. So this was a good excuse to buy one. ;-)

After getting access to an iPhone Unix shell, you can observe that every process runs as root. This is why the jailbreak process succeed, as the exploitation of the libtiff vulnerability through MobileSafari provided unlimited privileges on the device. Any future security flaw in any iPhone application can lead to a similar complete system compromise.

Full article @ RaDaJo blog

0 comments: