IPad 2 JailBreakMe (3.0) now available
jailbreakme.com
jailbreakme.com
I was blown away. How is this even possible? Did they find another userland exploit that allows you to write to the boot loader? I am very, very impressed.
"Q: Do the holes discovered by @comex put my device at risk? A: Yes. We recommend installing PDF Patcher 2 in Cydia once you’re jailbroken to eliminate this risk (any firmware version)."
Did you know the PDF spec includes its own LISP-like language? As well as basically anything else you can imagine. It is surely impossible to write a secure, conformant PDF reader.
If I ran any kind of super-sensitive organisation I'd include an outright ban on PDF renderers in my security policy. If anyone really needed to look at PDFs, I'd require them to be rendered down to TIFs or something on a "cleanroom" machine, preferably running some sort of locked-down linux build.
This talk has all the shocking details: http://www.youtube.com/watch?v=54XYqsf4JEY
The spec is huge, and the insecurity comes from having to faithfully implement all its utterly insane features, like embedding flash files, executing javascript, rendering external assets, and so on.
The challenge is to decide which subset of those features you want to deliberately ignore.
Most of the esoteric ones are likely critical to obscure, in-house business applications created years ago by corporate coders lacking in sense. Adobe Reader obviously implements everything, and its the reference implementation, so it is installed in most businesses.
Unfortunately, business is the area most in need of security.
In summary: OMGWTFPDF!
This is one of the reasons pdf.js is so important: it reduces the attack surface of the browser.
That's been my personal approach, such as it is, to the need to deal with some PDF files from third parties. I look for the environment that does no more than render the static page content.
Somewhat akin to using NoScript in the browser. I only execute when I need to, and then from a source for whom I have some trust.
I recently had to clean up some business systems belonging to a relative whose employee ran an infected PDF. By avoiding execution, I was able to examine the PDF and show them how it was indeed the source of their problems.
Unfortunately, these "business users" still have limited will to learn the techniques to avoid such problems. I've made some impression, but the Adobe PDF format is still a time bomb ticking away in the midst of their organization.
I'll mention that, for casual browsing, I use an extension that redirects PDF URL's to Google's Document Viewer (while not signed in to Google). Again, I get (usually) the static view without having to trust or execute the file on my own system. Thanks, Goog!
(Note that I don't do the latter with documents containing sensitive/personal information.)
Watch Julia Wolf's talk "OMG WTF PDF" to learn more. http://www.youtube.com/watch?v=54XYqsf4JEY
And the thing is, the html spec doesnt include js. It specifies a way of marking it up. Thats not the same thing. The core pdf spec actually contains features so powerful, you could almost make a lisp machine out of them. See the video for details.
The only way to be safe from these is usually to root/jailbreak your system and then patch it up using your newly acquired powers to close the hole before anyone else gets cheeky.
Will be interesting to see if any virus-makers will decide to exploit this before Apple patches it up in a later iOS release.
Visited the site with my iPhone. Pressed Install. No confirmation or anything.
Now I have a Cydia app on my phone that I can move but not delete. Was that all it took to jailbreak my phone? (It took like 10 seconds)
Edit: Figured out the problem. Looks like the MobileTerminal in the CYdia repo doesn't work for iOS 4.0 onwards. The following is a working version from the author of the app:
For those who fancy doing some analysis, here's the curl command with the required ipad UA string:
curl -A "Mozilla/5.0 (iPad; U; CPU OS 4_3 like Mac OS X; en-us) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8F190 Safari/6533.18.5" http://www.jailbreakme.com
EDIT: here's the b64 pdf: http://pastebin.com/69tnPMdVthe PDF is very invalid, because it never needs to masquerade as a real document, it doesn't have to pretend to implement the PDF spec correctly. This makes it somewhat resistant to analysis, it doesn't even have the required '%%EOF' marker so many tools choke on it immediately.
EDIT: There's an unterminated stream object in there which doesn't have a type, and it also has a declared length of 61 bytes and an actual length of well over 400. I think we have a winner... Unfortunately iOS shellcode analysis is waaaay over my head so I'll have to do something useful instead.
It doesn't make that much more sense to me, but atleast you can see some commands.
bunch of random gibberish?
It must be using some other encoding, only if we knew which!
http://digdog.tumblr.com/post/894317027/jailbreak-with-pdf-f...
[1] http://www.iphonedownloadblog.com/2011/07/02/jailbreakme-ipa...
The leak prompted quick action, lest Apple close the bus sized hole.
Seems that results for the bigboss repository aren't being returned in Cydia, and the repo backend isn't responding to requests. http://apt.thebigboss.org/onepackage.php?bundleid=pdfpatch2
Anyone else thinking the bigboss repo (only source of the pdf patcher 2, as far as I can tell) is being kept down on purpose?
No, it's down due to an insane traffic load. It'll be up as soon as either a) traffic gets less insane (not likely to happen soon) or b) BigBoss adds more capacity. I'd also suggest to just keep trying: it'll likely work to install just that if you just keep trying to download it (eventually).
Edit: I've put up a copy of it here, you can install this with "dpkg -i" on the device (via SSH): http://dl.dropbox.com/u/3177211/pdfpatch2_1_iphoneos-arm.deb
It really makes me appreciate the Apple App Store, to be honest.
It is this final step that was failing intermittently on my servers due to the insane load (~300x usual sales on this package, ~125x traffic load overall). Please give it a try now, I have verified that it is up.
// track jailbreaks!
_gaq.push(['_trackEvent', 'jailbreak', 'jailbreak']);
timeout = setTimeout(function() {
_gaq.push(['_trackEvent', 'failed', 'failure']);
goto('failure');
}, 5000);http://www.rakkhis.com/2010/08/can-chrome-learn-from-iphone-...
Ive not bothered to update yet. iPad 1