PDF exploit in iOS 4
daringfireball.net
daringfireball.net
The fact that a zero-day remote code execution exploit can be triggered so reliably in every iOS 4 and iPad 3.x device that the creators could drop a cute "Slide to Jailbreak" widget on a web page is alarming. With nothing more than a single rogue link and a bit of Objective C, this exploit could easily be used to produce a worm spread by e-mail or SMS to every contact with a link to the same rogue code, hopping from device to device as users tap an innocent link from a friend. In fact, the action of clicking a link could be bypassed entirely by script injection -- resulting in infection should the user merely browse to a page serving the rouge JS. Considering that the exploit is PDF-based, it's likely that it could also be triggered by viewing a document in Mail.
The prospect of iOS worms is very real, and unless Apple begins to take security more seriously (note that this is the second remote code execution exploit accessible from within MobileSafari, and they've yet to even make a peep about this one), I would not be surprised if we begin to see malware on the platform.
[ See the original exploit teardown here: http://digdog.tumblr.com/post/894317027/jailbreak-with-pdf-f... ]
* The teardown you've linked to is (a) pretty superficial and (b) wrong (though I see it's now been corrected) --- here I will annoy you by smugly noting that you've linked to an exploit teardown written by someone who thinks it's likely that the iPhone would have been vulnerable to an Acrobat Reader flaw.
* It is not generally the impression I get from vulnerability researchers that the iPhone does a poorer job of defending against remote code execution vulnerabilities than Android; specifically: the iPhone has much stricter (DEP-style) page protections than OSX, and the iPhone has strict code signing.
Does Apple need to take security seriously? Indubitably. But I don't think you can read tea leaves here. Things like this are going to happen to every phone. Let's see how Apple handles it; that, at least, is a signal we can actually discuss reasonably.
It's not the end of the world, but it would be nice to see companies take browser security more seriously.
I intended the comment to bring a few possibilities to the surface that I've not seen raised elsewhere surrounding an exploit which is otherwise being received by many in the community as a Good Thing.
Thanks for pointing out the error in the (original) write-up I'd linked. Yesterday I found myself telling a friend I thought it unfortunate to see others hopping blame upon Adobe for something they clearly had nothing to do with. If you're aware of a more detailed link to a writeup on the vulnerability in the font file processing, I expect people might be interested to see it.
Not sure relative to OSX (or why that relates to Android), however note that Android makes just as heavy of a use of the ARM's NX bit. Gruber recently subtly implied that Android was more reckless about security -- in a blurb about Android 2.2s V8 JIT engine for JavaScript, Gruber offhandedly mentioned that iOS "couldn't" perform such optimization because it barred executable segements -- implying that it didn't have NX-type uses, and he was simply blindly wrong.
And clearly it isn't quite so universal in iOS. This demonstration makes that amply clear.
RPW and Vince from Zynamics wrote a compiler that transforms the REIL intermediate form Zynamics BinDiff/BinNavi tools generate into synthesized stack frames that continually return through fragments of legitimate basic blocks in signed executable iOS code; I believe they're working with fully general programs built in that form, which is to traditional computer programs what Voltron is to Johnny 5.
Which is to say that the cat is thoroughly out of the bag here. All I can point out is, it's not like Apple is totally slacking on the iPhone.
Imagine something along the lines of:
Clueless user: Wow this jailbreaking site really worked well! Now that it has finished, it's showing a Paypal donation button in my browser. It was really helpful so I'll just go ahead and donate $10 on Paypal, right here in the browser of my newly jailbroken phone...
Author of the crack: [trollface.jpg] (thanks for the Paypal login details!)
Why do you trust anyone to do anything? Why do I trust AT&T not to be recording phone calls for the NSA (oh wait...) or Sony not to install rootkits on my Windows PC (hang on a second...).
At the end of the day, unless it's open-source, the possibility of malicious intent is everywhere. It only takes one disgruntled/incompetent employee.
That said, Gruber's last post on this indicated someone of repute had looked over the exploit, and they hadn't mentioned anything about such nastiness.
That being said I have a rooted/Custom ROM droid phone and I have no clue whether or not it is logging my keyboard or any such thing as I took the easy way of installing the root and rom, but that doesn't stop me from using it and I have to agree that if you want to wear a tinfoil hat that is fine and dandy just don't go against those who choose to go unprotected.
I have no idea about the AT&T 'forward all calls to the NSA', but I'd expect that would be logistically impossible.
ho hum, that sounds like a rootkit definition to me. or what's your beloved corporation's definition of this?
> I have no idea about the AT&T 'forward all calls to the NSA', but I'd expect that would be logistically impossible.
oh please, http://en.wikipedia.org/wiki/Room_641A
Does the 'root' not give you a clue as to the primary requirement of a rootkit?
May as well end here I think.
because the thing was defined as rootkit by original security researcher, EFF, court AND even Sony itself.
May as well end here I think.
hypocrisy at it's best.
[1] http://www.networkworld.com/news/2007/102907-iphone-ipod-tou...
it's not just remote code exploit...it's privilege escalation, and that's no joke
Good thing for crackers, I mean.
IMO, unless you really need an app that lives only in Cydia, it's not worth the hassle. Tethering is cool, but seems like something I would personally need 1% of the time.
Super easy to install and lets you actually patch (well, pseudo patch) this exploit.
I tether too, but only for conferences, which is pretty rare.
I've been playing more with various apps since the iPhone 4 can certainly take the performance hit. SBSettings (swipe status bar to pull down commonly-used options, like toggling 3G/EDGE), LockInfo (put calendar, mail, weather, etc on your lock screen), BiteSMS (SMS replacement with a bunch of features).
It's awesome and scary. I really hope Apple gets a fix out soon.
I think he's inferring (or pointing out the irony) that perhaps it's not the 3rd party ones they need to be so overly concerned with.
I think there is a review of app quality (although you could dispute the criteria they use).
But security? It would be unfeasible to do a proper security audit of every app even if they did have access to the source code. And yet many people are convinced that there is some form of security guarantee.
People attacking AppStore policies in the context of a browser exploit is as relevant as a "malicious app" that reports having access to your contact list, "stealing" your data through a Wallpaper that you manually install and grant access (ie, last weeks "debacle"). THOUGH, one could question why the Mobile Safari process is allowed the ability to become rampant anyway. I particularly appreciate the separation of the Dalvik VM in such scenarios.
Also, I posted two comments this evening. One is at -4, the other is at 10. Why did my overall "karma" move from 92 to 89. Should it not be at 98? Maybe I don't understand it. Oh well, hardly relevant.
"People attacking AppStore policies in the context of a browser exploit is as relevant as a "malicious app" that reports having access to your contact list, "stealing" your data through a Wallpaper that you manually install and grant access (ie, last weeks "debacle")"
AKA, NOT RELEVANT. Hence the sarcasm. Whatever.