5% Off Powermat

Join The Community

Showing posts with label SSH. Show all posts
Showing posts with label SSH. Show all posts
Tuesday, November 24, 2009

SSHServices : Fix Problem with the SSH Connection Cydia


SSHServices is a new Tweak available in Cydia, SSHServices aims to solve a problem that occurs only on some Jailbroken iPhone. If you are facing SSH timeout errors constantly this fix is for you. It must be installed only on devices that return a specific error when you try to establish a connection via SSH. The error in question is a sentence like: “Your Device is not Jailbroken, and SSH client shows only the files in the folder” mobile “without access to the” root “root.
SSHServices
Needn’t to mention again but: Install this tweak only if you are facing such kind of problems.
We’ll continue to update you all with more details with new hacks on Cydia as they release. Till then stick with us on Twitter @iTune2iPhone to keep yourself updated on every news about iPhone.
Source: ihackintosh

Tuesday, November 17, 2009

iREB V3.1.2 With SHSH Restore Server, iRecovery for iPhone 3GS

iH8sn0w is about to release the next update to iREB, This is the fourth version and has some new updates. The latest version Includes new and more clean interface.The SHSH files may help you to continue to downgrade your iPhone back to 3.1.2 when Apple releases a new firmware. The SHSH grabber is updated for the ipt2g (OTB users), ipt3, and the 3GS firmware 3.1.2, I hope all the 3GS user now familiar with the SHSH thingy, if not read the following explanation.
Why i need ECID SHSH Dump
Apple added a new piece of security called ECID, The nature of the 3GS hardware allows Apple to stop IPSWs from being usable unless you’ve already gotten the signed chunks they send to you based on your ECID (a unique chip ID). Actually Apple applies ECID so the iPhone will refuse to accept the ipsw file while downgrading because of a bad signature. It will treat it as a custom ipsw without having the apple server sign the ipsw specifically for your phone id before flashing.
main
SHSH Restore Server in iREB
New SHSH restore server is able to select the Saurik Server or your locally saved files so you can bypass the Apple signature server restriction. We’ll cover a new how to after the release.
cydiamouseovershshidle
filemouseovercydiashsh
Bonus : iRecovery now included in iREB
iRecovery is a libusb-based command line utility for Mac OS X and Linux (perhaps Windows too). It is able to talk to the iBoot/iBSS in Apple’s iPhone/iPod touch via USB. If you are on Windows then you need to install LibUsb-Win32 in order to run iRecovery.LibUsb-Win32 is a port of the USB library libusb the Windowsoperating system. The library allows user space applications to access any USB device on Windows. iH8sn0w implemented the iRecovery to the iREB and now it’s very easy to use iRecovery to get rid of iPhone from recovery mode loop on restart, or sending other commands.
irecovery
We’ll cover a useful article on how to use the iRecovery after the release so stay tuned. You can follow us on twitter to make sure yourself to not miss any buzz of the iPhone community.
Source: ihackintosh





Thursday, November 12, 2009

Australian admits creating first iPhone virus / iPhone/Privacy.A Virus Hits Jailbroken iPhone


A 21-year-old Australian man has admitted creating what is thought to be the first virus to infect Apple iPhones.
The virus, which can spread from phone to phone, changes the iPhone's wallpaper to a photograph of 1980s singer Rick Astley - best known for his hit Never Gonna Give You Up.
The wallpaper features the words "Ikee is never gonna give you up".
However, the virus can only infect phones which have been jailbroken by their owners. Jailbreaking allows the owners to run non-Apple approved applications on their phones.
Ashley Towns, a 21-year-old TAFE student who lives with his family in Wollongong, south of Sydney, told ABC News Online he created the virus to raise the issue of security.
"When people jailbreak their phone, it allows them to install a service on their phone called SSH," he said.
"Generally you should always change your password after setting up on the iPhone as all iPhones use the same password.
"This virus pretty much exploits people's laziness to change their password."

He says his efforts prove that anyone could easily hack into an iPhone.
"I think to raise awareness for one, somebody with more malicious intent could have done anything - read your SMSs, go through your emails, view your contacts, photos - anything," he said.
Mr Towns says he is unaware if he is breaking any law by starting the virus.
"I've been informed that I may have broken some, but not being a lawyer I do not know," he said.
"The virus itself is not malicious and is not out to hurt people. It's just poking fun and hoping waking people up a little."
He says it is the first virus of its kind.
"Yes, especially the first that spreads from phone to phone," he said.
Mr Towns says he does not know how many people the virus could affect.
"Due to the nature of it, it's kind of hard to tell, I know my phone hit about 100 alone but from there I have no idea," he said.
But he says apart from changing the wallpaper on a user's phone, the virus is not harmful and quite easy to get rid of.
"[It does] nothing malicious at all, it basically only changes their wallpaper to Rick Astley," he said.
He says it takes a couple of minutes to remove by simply changing the phone's password and deleting a few files from the phone.
Mr Towns says he can prove that he created the virus by postings on Twitter made by him under the same name that was in the source code.
He says the original source code also had his email in it, but Google code removed it.
Source: abc.net.au

iPhone/Privacy.A Virus Hits Jailbroken iPhone


November has proved tough for jailbroken iPhone users as they twice came under attack by hackers. First one which we did warned you about was when a Dutch hacker tried to access jailbroken iPhones through SSH in his native country Netherlands. He was successful in sending totally off guarded users a message that read, "Your iPhone’s been hacked because it’s really insecure! Please visit doiop.com/iHacked and secure your iPhone right now! Right now, I can access all your files.". The second development was an attempt by an Australian who successfully injected a worm called “ikee” into jailbroken iPhones whose users forgot to change their root password for SSH. Victims of ikee virus were astonished to find their home screen background automatically changed to that of Rick Astley. ikee virus spread like a chain reaction from iPhones on one cellular network, to iPhones on other.


In the first case, the Dutch hacker regretted his action and reverted everything back, whereas in the second case, it was simply an experiment by the young Aussie whose worm ikee did not do any harm to the victims iPhone. All these attacks had one thing in common, they were targeted towards jailbroken iPhone users who were using the default root:alpine username/password combination. In our earlier post we had already recommended you all on how to secure and how to protect your iPhone against such vulnerabilities.
Previous attacks did not do much harm but this new one which is identified as iPhone/Privacy.A virus carries alot more risk. As reported by MobileCrunch, the computer security firm Intego has identified the truly malicious malware named iPhone/Privacy.A that targets jailbroken iPhones with default user/password combo and is probably the first harmful one of its kind. The virus in question gives a hacker complete access on the victim’s iPhone. The hacker can access and copy any user data from the jailbroken device, including emails, contacts, calendars, photos, SMSs, videos, in fact any data the hacker wants.
Intego explains iPhone/Privacy.A Virus in more detail as follows:

Hackers using this tool will install it on a computer – Mac, PC, Unix or Linux – then let it work. It scans the network accessible to it, and when it finds a jailbroken iPhone, breaks into it, then steals data and records it.
This hacker tool could easily be installed, for example, on a computer on display in a retail store, which could then scan all iPhones that pass within the reach of its network. Or, a hacker could sit in an Internet café and let his computer scan all iPhones that come within the range of the wifi network in search of data. Hackers could even install this tool on their own iPhones, and use it to scan for jailbroken phones as they go about their daily business.

It is highly recommended that you change your iPhone’s default SSH mobile and root password now. A complete step by step guide on how to change your jailbroken iPhone’s SSH password can be found here.
You can follow us on twitter to keep yourself updated on all the latest jailbreaking and unlocking releases.

Source: redmondpie




Thursday, November 5, 2009

Secure Your Jailbroken iPhone and Change your Default Password

Recently A Dutch hacker, managed to break into jailbroken iPhone & tried to extort € 5 from the victim. Later it was discovered hacker attacked a number of vulnerable phones on T-mobile Netherlands and tried to extort €5 from them. Here is the original Dutch Forum from where all the incidences comes in to light. Arstechnia added “ It appears one enterprising Dutch hacker used port scanning to identify jailbroken iPhones on T-mobile Netherlands with SSH running. Enabling SSH is a common procedure for jailbroken iPhones, allowing a user to log in via Terminal and run standard UNIX commands. Unfortunately, iPhones all have a default root password that many forget to change after jailbreaking”.


In this instance, the hacker changed the wallpaper (see above) on compromised iPhones so they displayed the following message:


Important Warning
Your iPhone’s been hacked because it’s really insecure! Please visit doiop.com/iHacked and dsecure your iPhone right now!
Right now, I can access all your files.. This message won’t disappear until your iPhone’s secure
And when he visited the mentioned site another threatening message.
If you don’t pay, it’s fine by me, but remember, the way I got access to your iPhone can be used by thousands of others-they can send text messages from your number (like I did), use it to call or record your calls, and actually whatever they want, even use it for their hacking activities! I can assure you, I have no intention of harming you or whatever, but, some hackers do! It’s just my advice to secure your phone.
_____________________________________________________________________________________
How to Secure your iPhone from these kind of threats


Step 1: Go to Cydia and search for MobileTerminal app and then install it on your iPhone. Once you have successfully installed MobileTerminal, Reboot your iPhone.




Step 2: Now start MobileTerminal app and type the following command:
passwd





Step 3: You’ll now be asked for your old password which should be ‘alpine’ (without the quotes), followed by a new one of your choice (twice). Simply enter your old and new password and you are done!



Note: the instruction in Step 2 will change your mobile password only. In order to change root password, type ‘login’ command (without quotes) and then press enter. Now type ‘root’ (without quotes) as your login and ‘alpine’ as your current root password. Once you have logged in as root, type ‘passwd’ command (without quotes) again and press enter. It will now prompt you to enter a new password (twice). Simply enter your desired new password again as you did in Step 3 (for changing mobile password) and you should be all fine. It is highly recommended that you change, both your mobile and root passwords to make sure you are completely safe from any outside SSH attack.
or 
Change the Root Password of iPhone : it’s the most easiest way all you need is to install Mobile Terminal if you haven’t installed and then change the root password.   Note that the text between >> << aren’t commands that text is for your reference only.
  • su root                                                 >> << login root with all access >> <<
  • alpine                                                  >> <<  it’s your default password >> <<
  • passwd root                                       >> <<To change your default password >> <<


Turn of SSH when not required : Install SBSettings from Cydia so you can turn it off or on when you really required this.
If you have any question we’ll love to hear back from you on twitter via @iTune2iPhone and keep your self updated with the latest of iPhone community.


Source: ihackintoshredmondpie


Update: How to recover your Hacked iPhone. Follow the step by step instructions.
1. Get an SSH program like putty for windows.

2. SSH to your iPhone. (If you haven't done that before it may take a while, and after that there might come a warning about a key fingerprint. You can just accept that). Login using username "root" and password "alpine". (this is the default password)
3. There's a few commands you have to execute, best is to just copy them:

rm /System/Library/LaunchDaemons/com.apple.syslog.plist
chown mobile /private/var/mobile/Library/LockBackground.jpg
chmod 666 /private/var/mobile/Library/LockBackground.jpg
mv /private/var/mobile/Documents/LockBackground.backup.jpg /private/var/mobile/Library/LockBackground.jpg
4. That's everything to remove the stuff. Now there's one command left to make sure this won't happen again! Again in putty or any SSH client type: "passwd". You'll then be asked for a new password, you can change this into anything you want. The safer the better of course (:

The reason you have to change this password is that it's default is "alpine" at ALL iPhones. So if anyone knows that (and all hackers do) they can access your iPhone. Now you've changed it this isn't possible anymore!



Source: From Hacker's site