A specific network name can completely disable Wi-Fi on your iPhone
9to5mac.com
9to5mac.com
This sounds like a significant security bug?
Why do you need my Apple ID?
Apple allows anyone with an Apple ID to install apps they’ve built themselves onto their devices for testing. AltStore uses your Apple ID to communicate with Apple's servers on your behalf and perform the necessary steps to prepare your account for installing apps onto your device.
Do you save or send my Apple ID to anyone besides Apple?
Your Apple ID is never sent to anyone but Apple. AltStore does save your Apple ID so it can refresh apps for you automatically, but it is stored securely in the device’s keychain. AltServer does not save your Apple ID, and requires you to enter your credentials each time.
(Ofcourse, Jailbreak isn't necessarily more secure - you have no idea if they inject a malware into your device during the process.)
printf(theStr);
rather than printf(“%s”, theStr);
Still this bug regularly crops up all over the place, making the % character risky when naming any shared resource.Heh. I do appreciate the subtlety here.
Lessons will be repeated until they are learned.
Don't have a quick way to setup a WiFi with the specific SSID ATM. Would be interested to see if that works.
I'll admit I looked around before writing this and saw that Python's str.format() can be pretty bad. So let's say a reasonably constrained formatting language in a good runtime -- the attacker is limited in what they can see or control, and the formatter can see how many arguments were actually passed so it doesn't tromp off into other memory.
Sorry, how does Rust protect you against injection again?
edit: turns out from the analysis it was CFStringCreateWithFormatAndArguments, so yes, a sprintf-like used incorrectly
https://play.rust-lang.org/?version=stable&mode=debug&editio...
https://play.rust-lang.org/?version=stable&mode=debug&editio...
This nasty printf()-like way of formatting is a giant footgun though. Apple are not the first ones to fall into this trap.
Sure there are safer models for computing. But it has served its purpose for a long time. A small language allowing highly performant programs/operating systems to be written. Plus we got to see the beautiful art form of exploit writing. Sure at what cost (lots), but all hackers can appreciate when a system gets owned. It’s the intentions that come after which bother us all.
Don’t get me wrong, I’m excited for newer languages like rust to come along. However, I learned so much about low level computing from c, and I’m forever grateful.
Hats off to Dennis Ritchie. Thanks for creating a language I met so many other hackers through, and sparking the curiosity of hacking within me.
C was great for its time, now its time to move on and use a sensible language.
Also there are Objective C APIs which take format strings, like +[NSString stringWithFormat:] and the system function NSLog().
Even Swift uses format strings in places. https://developer.apple.com/documentation/swift/string/31267...
If you think that someone targeted would notice their WiFi turned off and turn it back on, they would definitely notice and probably become suspicious of that behavior shown in the video where WiFi automatically turns itself on and off rapidly.
That said, I also find it unlikely this is a planned exploit.