Log In

Your email is not your username

Register

If you were a member of the old Bodybuilding.com forums and would like to reuse your previous username, you can request it below. We use your email only for registration and do not store it. For more information, please see our Privacy Policy.

Confirm your email

A registration code was sent to your email. Enter it here.

Welcome

You have successfully setup your account.

Sign in

Quick Navigation Bottom Misc
Forum
» Applecels: Security failure by Apple allows total remote control of iPhone via WiFi
  1. Results 1 to 5 of 5
post 1624361321 12-03-2020, 07:27 AM
-
#1
  1. mvitz
  2. Registered User
  1. mvitz
  2. Registered User
  3. Join Date: Aug 2020
  4. Posts: 2,898
  5. Rep Power: 12613

Applecels: Security failure by Apple allows total remote control of iPhone via WiFi

Applecels please make sure your iPhone is upgraded to the latest version of iOS. The normal person is not capable of doing this but hackers can easily do this in a public place.

You have been warned.

=================

https://9to5mac.com/2020/12/02/remot...security-fail/

A massive security failing by Apple allowed an attacker to take total remote control of iPhones within WiFi range. They would be able to download all the data on the phone, and even activate the iPhone’s cameras and microphones to provide real-time spying capabilities.

The vulnerability was not just a theoretical risk: a noted Google security researcher was able to demonstrate the capabilities by taking full remote control of an iPhone in another room …

The jaw-dropping exploit was demonstrated by Google Project Zero security researcher Ian Beer. The project is designed to identify vulnerabilities and notify companies before the bad guys can discover and exploit them. Project Zero founder Chris Evans told ArsTechnica that the scary thing about this one is that it works without any user interaction at all, and leaves no clue that their privacy was violated.

This attack is just you’re walking along, the phone is in your pocket, and over Wi-Fi someone just worms in with some dodgy Wi-Fi packets.

There is some good news in the mix. Beer said he hasn’t found any evidence that it was ever exploited in the wild by hackers, and he of course allowed Apple time to patch the issues before he shared the details. But it is still incredible that such a massive security hole ever existed.
post 1624361661 12-03-2020, 07:31 AM
-
#2
  1. W1LLW
  2. Enlightened Miscer
  1. W1LLW
  2. Enlightened Miscer
  3. Join Date: Jan 2011
  4. Posts: 27,700
  5. Rep Power: 229291
"Once he Googled and discovered what AWDL was, he knew what his line of attack was going to be. He was eventually able to generate fake AWDL data which would lead any iPhone within WiFi range to respond.

The work this required was itself quite staggering. to overcome each of the barriers he hit along the way.By the end of it, though, he was able to successfully demonstrate this by taking over an iPhone 11 Pro in the room next door...


...Back in 2018, he accused Apple of making a poor job of fixing the many vulnerabilities he had reported to the company – but the iPhone maker did fix this one, as you’d expect, sometime prior to iOS 13.5."







yawn. the life of androidTimothys constantly grabbing at straws to prove they aren't plebs.
Kobe Forever
Black Crew
Bucks N 6
post 1624361791 12-03-2020, 07:33 AM
-
#3
  1. TomWanks
  2. vocaroo.com/18BduFIdv7YR
  1. TomWanks
  2. vocaroo.com/18BduFIdv7YR
  3. Join Date: Sep 2020
  4. Posts: 21,621
  5. Rep Power: 202087
A major exploit using that AWDL protocol like this was going to be discovered at some point. That chit is just too convenient.

brb any Apple device in range
brb push notification confirmation which can be bypassed
brb full system access
post 1624361801 12-03-2020, 07:33 AM
-
#4
  1. mvitz
  2. Registered User
  1. mvitz
  2. Registered User
  3. Join Date: Aug 2020
  4. Posts: 2,898
  5. Rep Power: 12613
Originally Posted By W1LLW
"Once he Googled and discovered what AWDL was, he knew what his line of attack was going to be. He was eventually able to generate fake AWDL data which would lead any iPhone within WiFi range to respond.

The work this required was itself quite staggering. to overcome each of the barriers he hit along the way.By the end of it, though, he was able to successfully demonstrate this by taking over an iPhone 11 Pro in the room next door...


...Back in 2018, he accused Apple of making a poor job of fixing the many vulnerabilities he had reported to the company – but the iPhone maker did fix this one, as you’d expect, sometime prior to iOS 13.5."







yawn. the life of androidTimothys constantly grabbing at straws to prove they aren't plebs.
Agreed but it doenst mean you should ignore it. Once clowns like this publish stuff the hackers use it.
post 1624362111 12-03-2020, 07:37 AM
-
#5
  1. BraneyGumble
  2. Registered User
  1. BraneyGumble
  2. Registered User
  3. Join Date: May 2013
  4. Age: 41
  5. Posts: 25,426
  6. Rep Power: 248871
Sigh. Guy contacted Apple, who then fixed it before the dude released his findings.


There is some good news in the mix. Beer said he hasn’t found any evidence that it was ever exploited in the wild by hackers, and he of course allowed Apple time to patch the issues before he shared the details. But it is still incredible that such a massive security hole ever existed.


From original blog post:


This specific issue was fixed before the launch of Privacy-Preserving Contact Tracing in iOS 13.5 in May 2020.
Quick Navigation Top Misc
Bookmarks
Digg.com
Digg
del.icio.us
del.icio.us
Stumbleupon.com
StumbleUpon
Google.com
Google
Facebook.com
Facebook
Posting Permissions
  1. You may not post new threads
  2. You may not post replies
  3. You may not post attachments
  4. You may not edit your posts