5% Off Powermat

Join The Community

Showing posts with label Password. Show all posts
Showing posts with label Password. Show all posts
Wednesday, June 2, 2010

Let's Bypass the iPhone Passcode without Restoring

Let's Bypass the iPhone Passcode without Restoring

Ok, So I have stumbled on a few 3GS's in the past months since the release that are stuck on disabled screens. All options have been exhausted except for a full restore, which inadvertently would put the 3GS on 3.1 making it a locked phone, no good! There has been talk by Nervegas (Jonathan Zdziarski) that he has developed something for use by police to bypass the passcode on the 3GS and other models by simply uploading a custom hybrid of purplera1n and redsn0w. However, he will not release it to the pubic. I am sure with the heads we have out here at MMi we too could develop such a tool which in turn would benefit a lot of us. Below is the information I have gathered so far including the videos he has posted as well.
Lets see what we can all do together!
Andrew Hoog, Chief Investigative Officer at Via Forensics, has put together an iPhone Forensics Whitepaper summarizing the available forensic techniques for recovering data from the iPhone. Depending on what kind of information you want to get, there are a number of different techniques you can use.

Download the iPhone Forensics Whitepaper here:
http://www.megaupload.com/?d=3GB0AILF

July 24, 2009: The Simplicity Of Bypassing iPhone 3G[s] Passcode and Encryption
Bypassing Passcode and Backup Encryption:
These YouTube videos, courtesy of security researcher Jonathan Zdziarski, demonsrate just how easy it is to bypass the passcode and backup encryption in an iPhone 3G[s] within only a couple of minutes' time. A second video shows how easily tools can pull an unencrypted raw disk image from the device. The seriousness of the iPhone 3G[s]' vulnerabilities may make enterprises and government agencies think twice before allowing these devices to contain confidential data. Apple has been alerted to and aware of these vulnerabilities for many years, across all three models of iPhone, but has failed to address them. Jonathan adds:

The 3G[s] has penetrated the government/military markets as well as top fortune-100s, possibly under the misleading marketing term "hardware encryption", which many have taken at face value. Serious vulnerabilities such as these threaten to put our country's national security at risk. Unfortunately, the only way Apple seems to listen is through addressing such problems publicly, as all previous attempts to talk with them have failed. I sincerely hope they fix these issues before a breach occurs..

Quote:
Many of you use such iPhone function, as “Protection by password”.
But very few people knows, that this protection is easy enough to bypass.
Famous Jonathan Zdziarski, has published today a way how to bypass this protection:
1. Prepare custom Apple iPhone RAM disk. Internet has tons of FAQs how to make it (for example with help of iLiberty+). Mount your RAM disk /dev/rdisk0s2 and delete file /mnt/mobile/Library/Preferences/com.apple.springboard.plist. This is a config which tells Springboard “passcode: on”.
2. Using any utility get your iPhone into “Recovery Mode” and after that upload RAM disk using something like this:

(iPHUC Recovery) #: filecopytophone Bypass_Passcode.bin
(iPHUC Recovery) #: cmd setenvboot-argsrd=md0-x-spmd0=0×9340000.0xA00000
(iPHUC Recovery) #: cmd saveenv
(iPHUC Recovery) #: cmd bootx

3. Then reboot your iPhone and that’s it: protection by the password are not present anymore.
Here is the information from the class he offers teaching his method:
Quote:
Advanced iPhone Forensics L-1
Recovering Evidence, Personal Data, and Corporate Assets

The iPhone has become America's #1 mobile device, and is increasingly being used in business, personal activities, and also crime. The iPhone stores an enormous amount of information useful to corporate security professionals and law enforcement agents. Enterprises must adequately manage sensitive data which may put their company at risk. Law enforcement agencies and freelance forensic examiners must process the iPhone for evidence linking its owner to crimes.

Host a course for your department and provide these crucial skills to your personnel. Jonathan Zdziarski, original iPhone hacker and author of many iPhone books including iPhone Forensics and iPhone SDK Application Development, will lead your organization's security professionals through the delicate process of recovering and processing evidence stored on the iPhone. This full two-day course will guide you, hands on, through forensic recovery and electronic discovery of an iPhone, iPhone 3G, and iPhone 3G[s] and cover iPhone firmware up to and including the new v3.1. Attendees will receive a 170pp white paper containing Zdziarski's latest methods, the tools they can use in the field, and a certificate of completion to certify their skillset. All of the tools and demo content used in the classroom will also be provided so attendees can learn and follow hands-on. Have Jonathan train your personnel hands-on to learn:
What kind of evidence is stored on an iPhone, and what can be recovered through desktop trace
Raw disk recovery of a v1.x, v2.x, and v3.x iPhone user disk partition, preserving and recovering the entire raw user disk. Recovery over USB cable or Wi-Fi.
Making commercial tools, such as Encase, recognize an iPhone disk image
Bypassing passcode protection and device encryption to gain access to the device's user interface for compatibility with third-party triage tools, or for time-sensitive cases where preservation of life is priority.
Interrupting the iPhone 3G's "secure wipe" process
Recovering deleted voicemail, images, email, and other personal data using data carving techniques
Recovering geotagged metadata from camera photos (GPS coordinates taken at the time the photo was taken)
Electronic discovery of Google map lookups, WiFi connect records, keyboard typing cache, and other sensitive data stored on the live file system
Extracting contact information and other data from the iPhone's database
Collecting desktop trace and establishing trusted relationships to owners' desktops
Different recovery strategies based on case needs
Using the tools and know-how provided in this course, you'll work hands-on to recover stored and deleted information from the iPhone including:
Keyboard caches containing usernames, passwords, search terms, and historical fragments of typed communication.
Screenshots preserved from the last state of an application, taken whenever the home button is pressed, or when 3D zoom effects are used.
Deleted images from the suspect's photo library, camera roll, and browsing cache.
Deleted address book entries, contacts, calendar events, and other personal data.
Exhaustive call history, beyond that displayed.
Reconstructing record fragments from corrupt databases
Map tile images from the iPhone's Google Maps application, lookups and longitude/latitude coordinates of previous map searches, and coordinates of the last GPS fix.
Browser cache and deleted browser objects, which identify the web sites a user has visited.
Cached and deleted email messages, SMS messages, and other communication with corresponding time stamps.
Deleted voicemail recordings stored on the device.
Pairing records establishing trusted relationships between the device and one or more desktop computers.
Sources:
http://gizmodo.com/5046050/hacker-to...september-11th
http://www.wired.com/gadgetlab/2009/...ne-encryption/

Thursday, November 5, 2009

Secure Your Jailbroken iPhone and Change your Default Password

Recently A Dutch hacker, managed to break into jailbroken iPhone & tried to extort € 5 from the victim. Later it was discovered hacker attacked a number of vulnerable phones on T-mobile Netherlands and tried to extort €5 from them. Here is the original Dutch Forum from where all the incidences comes in to light. Arstechnia added “ It appears one enterprising Dutch hacker used port scanning to identify jailbroken iPhones on T-mobile Netherlands with SSH running. Enabling SSH is a common procedure for jailbroken iPhones, allowing a user to log in via Terminal and run standard UNIX commands. Unfortunately, iPhones all have a default root password that many forget to change after jailbreaking”.


In this instance, the hacker changed the wallpaper (see above) on compromised iPhones so they displayed the following message:


Important Warning
Your iPhone’s been hacked because it’s really insecure! Please visit doiop.com/iHacked and dsecure your iPhone right now!
Right now, I can access all your files.. This message won’t disappear until your iPhone’s secure
And when he visited the mentioned site another threatening message.
If you don’t pay, it’s fine by me, but remember, the way I got access to your iPhone can be used by thousands of others-they can send text messages from your number (like I did), use it to call or record your calls, and actually whatever they want, even use it for their hacking activities! I can assure you, I have no intention of harming you or whatever, but, some hackers do! It’s just my advice to secure your phone.
_____________________________________________________________________________________
How to Secure your iPhone from these kind of threats


Step 1: Go to Cydia and search for MobileTerminal app and then install it on your iPhone. Once you have successfully installed MobileTerminal, Reboot your iPhone.




Step 2: Now start MobileTerminal app and type the following command:
passwd





Step 3: You’ll now be asked for your old password which should be ‘alpine’ (without the quotes), followed by a new one of your choice (twice). Simply enter your old and new password and you are done!



Note: the instruction in Step 2 will change your mobile password only. In order to change root password, type ‘login’ command (without quotes) and then press enter. Now type ‘root’ (without quotes) as your login and ‘alpine’ as your current root password. Once you have logged in as root, type ‘passwd’ command (without quotes) again and press enter. It will now prompt you to enter a new password (twice). Simply enter your desired new password again as you did in Step 3 (for changing mobile password) and you should be all fine. It is highly recommended that you change, both your mobile and root passwords to make sure you are completely safe from any outside SSH attack.
or 
Change the Root Password of iPhone : it’s the most easiest way all you need is to install Mobile Terminal if you haven’t installed and then change the root password.   Note that the text between >> << aren’t commands that text is for your reference only.
  • su root                                                 >> << login root with all access >> <<
  • alpine                                                  >> <<  it’s your default password >> <<
  • passwd root                                       >> <<To change your default password >> <<


Turn of SSH when not required : Install SBSettings from Cydia so you can turn it off or on when you really required this.
If you have any question we’ll love to hear back from you on twitter via @iTune2iPhone and keep your self updated with the latest of iPhone community.


Source: ihackintoshredmondpie


Update: How to recover your Hacked iPhone. Follow the step by step instructions.
1. Get an SSH program like putty for windows.

2. SSH to your iPhone. (If you haven't done that before it may take a while, and after that there might come a warning about a key fingerprint. You can just accept that). Login using username "root" and password "alpine". (this is the default password)
3. There's a few commands you have to execute, best is to just copy them:

rm /System/Library/LaunchDaemons/com.apple.syslog.plist
chown mobile /private/var/mobile/Library/LockBackground.jpg
chmod 666 /private/var/mobile/Library/LockBackground.jpg
mv /private/var/mobile/Documents/LockBackground.backup.jpg /private/var/mobile/Library/LockBackground.jpg
4. That's everything to remove the stuff. Now there's one command left to make sure this won't happen again! Again in putty or any SSH client type: "passwd". You'll then be asked for a new password, you can change this into anything you want. The safer the better of course (:

The reason you have to change this password is that it's default is "alpine" at ALL iPhones. So if anyone knows that (and all hackers do) they can access your iPhone. Now you've changed it this isn't possible anymore!



Source: From Hacker's site