thisisNOTnassauotb

This blog is not affiliated or endorsed, by Nassau OTB, a public benefit corporation, subject to the New York Freedom of Information Law, NY Pub Off Law Sec 84 et seq.

Wednesday, December 13, 2017

unlock your total wireless se i phone

target sales of the locked total wireless se i pjone on blavk friday would have been astronomical if the below article had been published sooner? better late than never for those who bought the $99
dollar total wireless i phone




Award-winning computer security news
  • Twitter
  •  
  • Facebook
  •  
  • Google+
  •  
  • LinkedIn
  •  
  • Feed



iOS jailbreak exploit published by Google

12 DEC 2017 9Apple, Google
Previous: Ransom email scam from ‘hitman’ demands: pay up or die
Next: Apple plugs IoT HomeKit hole
by Paul Ducklin
  • 0Share on Facebook
  •  
  • Share on Twitter
  •  
  • Share on Google+
  •  
  • Share on LinkedIn
  •  
  • Share on Reddit
The story’s not quite as bad as it sounds at first – a bang-up-to-date iPhone is already safe against this exploit.
But it’s still an interesting tale, so here goes.
Google Project Zero bug-hunting expert Ian Beer recently registered an account on Twitter, and his first tweet, back on 5 December 2017, has already clocked up 752 retweets and more than 1800 likes. [2017-12-12T12:38Z]
Beer said:
If you’re interested in bootstrapping iOS 11 kernel security research keep a research-only device on iOS 11.1.2 or below. Part I (tfp0) release soon.
It turns out he was referring to exploit code that takes advantage of a vulnerability dubbed CVE-2017-13861, patched by Apple in its recent iOS 11.2 update, published on 2 December 2017.
That was the update in which Apple fixed the KRACK Wi-Fi vulnerability for users of older iPhones, having managed to patch it only for the iPhone 7 and later to start with.
It turns out, however, that KRACK wasn’t the only reason to apply the iOS 11.2 patches.
Apple wasn’t joking when it described CVE-2017-13861 in the iOS 11.2 security bulletin with these words:
Impact: An application may be able to execute arbitrary code with kernel privilege.
Description: A memory corruption issue was addressed with improved memory handling.
Beer has now gifted to the jailbreaking community a proof-of-concept for this very bug, proving that it’s not just a theoretically-exploitable vulnerability.
Of course, if you’ve already updated to iOS 11.2, you’ve closed this particular hole, so you’re safe against Beer’s attack code.

Sophos Home

Free home computer security software for all the family
Learn More

Jailbreakers often run a few versions behind the bleeding edge, specifically to leave known vulnerabilities open in the hope that exploits will later be found – with Apple’s strict walled garden approach to the iOS ecosystem, updates are designed to be a one-way street so that you can never later downgrade.
So, if you keep bang up to date with Apple’s patches, you’ll be more secure in general, but at the cost of future flexibility if you suddenly decide you want to join the jailbreaking scene, in a bit of a security Catch 22.
Jailbreaking has a bad name, because it’s associated not only with freedom but also with piracy, unlawful copying and the purposeful bypassing of security that was originally put in place to protect intellectual property.
For the record, we don’t recommend jailbreaking, at least for phones you use in a work environment, and indeed our Sophos Mobile Control product provides a way to keep jailbroken and otherwise non-compliant devices off your organisation’s network.
For a busy system administrator, jailbroken iPhones (and their countercultural cousins, rooted Android phones) are yet another layer of security uncertainty that’s easier to live without, especially in a world where Europe’s new GDPR framework is fast approaching.
Having said that, there are numerous perfectly good reasons for jailbreaking, such as:
  • Repurposing an old device after Apple stops supporting it.
  • Applying a third-party security fix if independent researchers get to it before Apple.
  • Enjoying yourself because, hey, it’s your phone and you paid for it out of your own after-tax income.
  • Conducting security research – like the work Ian Beer does – that requires debugging access that Apple won’t give you out of the box.
So, although we advise against jailbreaking in general, we’ll repeat what we’ve said before:
As always[…], “Patch early, patch often.”
But we nevertheless wish that Apple would come to the jailbreaking party, even though we’d continue to recommend that you avoid untrusted, off-market apps.
We suspect that Apple would benefit both the community and itself by offering an official route to jailbreaking – a route which could form the basis of independent invention and innovation in iDevice security by an interested minority.

What to do?

We said it above: patch early, patch often.
Don’t hang back in the hope of later jailbreaks unless you have a well-formed reason for doing so.
There’s also the intriguing question, “Should Google Project Zero have dropped this exploit so soon after the update?”
Ironically, keeping up to date on Apple’s iOS platform is much easier than in Google’s Android world, where hundreds of different phone vendors, suppliers and carriers all need to knit their own updates once the Android source code is patched.
Not every iOS user is up-to-date, however.
So, even though Ian Beer has done the jailbreaking and the research community a favour, Google’s proof of concept exploit could also be seen as a bit of a Christmas present to the crooks out there, giving them a vector to attack the 30%-40% of Apple iOS users who aren’t up-to-date yet.
Where do you stand on this? Let us know below…
(You may post anonymously by leaving the name and email address details blank when you submit your comment.)

  • Exploit
  • Google Project Zero
  • ios
  • jailbreak

Free tools

Sophos Home

Sophos Home
for Windows and Mac

XG Firewall Home Edition

XG Firewall
Home Edition

Mobile Security for Android

Mobile Security
for Android

Virus Removal Tool

Virus Removal Tool

Antivirus for Linux

Antivirus
for Linux

Previous: Ransom email scam from ‘hitman’ demands: pay up or die
Next: Apple plugs IoT HomeKit hole
Posted by leonardeuler at 9:20 AM
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Followers

Blog Archive

  • ►  2023 (57)
    • ►  March (6)
    • ►  February (9)
    • ►  January (42)
  • ►  2022 (929)
    • ►  December (23)
    • ►  November (29)
    • ►  October (34)
    • ►  September (30)
    • ►  August (50)
    • ►  July (61)
    • ►  June (87)
    • ►  May (109)
    • ►  April (123)
    • ►  March (220)
    • ►  February (74)
    • ►  January (89)
  • ►  2021 (1369)
    • ►  December (83)
    • ►  November (78)
    • ►  October (132)
    • ►  September (120)
    • ►  August (128)
    • ►  July (81)
    • ►  June (136)
    • ►  May (80)
    • ►  April (110)
    • ►  March (209)
    • ►  February (91)
    • ►  January (121)
  • ►  2020 (2134)
    • ►  December (36)
    • ►  November (25)
    • ►  October (40)
    • ►  September (109)
    • ►  August (116)
    • ►  July (138)
    • ►  June (214)
    • ►  May (201)
    • ►  April (448)
    • ►  March (353)
    • ►  February (201)
    • ►  January (253)
  • ►  2019 (2855)
    • ►  December (162)
    • ►  November (144)
    • ►  October (169)
    • ►  September (237)
    • ►  August (260)
    • ►  July (310)
    • ►  June (269)
    • ►  May (200)
    • ►  April (232)
    • ►  March (267)
    • ►  February (333)
    • ►  January (272)
  • ►  2018 (2607)
    • ►  December (181)
    • ►  November (209)
    • ►  October (193)
    • ►  September (196)
    • ►  August (255)
    • ►  July (267)
    • ►  June (220)
    • ►  May (189)
    • ►  April (202)
    • ►  March (265)
    • ►  February (192)
    • ►  January (238)
  • ▼  2017 (1700)
    • ▼  December (115)
      • No title
      • No title
      • bet the tax plan with laura gillen
      • No title
      • No title
      • rank and file workers remind her
      • No title
      • another hoffa henchman who helps see that the
      • burn baby burn
      • No title
      • colnel jupiter of the mossad did tell my friend
      • No title
      • resurrection bagman
      • educate a lawyer regarding brain splatter etc
      • Claude Solnik (631) 913-4244 Long Island Busine...
      • the high priced errand boy
      • take the lsura curran test
      • No title
      • Claude Solnik (631) 913-4244 Long Island Busine...
      • Claude Solnik (631) 913-4244 Long Island Busine...
      • Registration Number:4361713    JARED ANDREW KA...
      • No title
      • baldwin bigots for beech
      • chair manufactureres up in ....
      • Janus v. American Federation of State, Count...
      • heavy lifting ahead
      • bet the white girl to beat el pico
      • drive american companies out of india with murder
      • No title
      • earthquake shifts nassau county, ny & albany
      • No title
      • brian benjamin and thomas dinapoli
      • No title
      • president cuomo tells congresswoman that he can
      • No title
      • No title
      • No title
      • soup or salad?
      • bet the bomb with peter king boom or dud
      • No title
      • No title
      • No title
      • pretlow fears loss of undercover income
      • No title
      • No title
      • No title
      • dear irad
      • No title
      • the cake eater andrew cuomo
      • No title
      • No title
      • yes but https://m.youtube.com/watch?v=c-zvNnFjk3Q
      • No title
      • No title
      • No title
      • No title
      • john marzulli dines with jerry bossert at poco locos
      • No title
      • suffolk county legislator kevin mccaffrey breaches
      • dear laura popper
      • dear modernlove@nytimes.com
      • lee zeldin wins nobel peace prize
      • No title
      • dear gretchen,
      • No title
      • No title
      • No title
      • eric schneiderman stands on the see saw
      • she should study faustman's patents
      • remember when a cuny law student sued he dean for
      • yawn
      • No title
      • do you read, think, and talk to others?
      • No title
      • as undeucated as the bangladeshi and killing more
      • unlock your total wireless se i phone
      • No title
      • business or.....
      • albany, us congress, cuomo, moore, solages,
      • No title
      • No title
      • No title
      • el pico
      • No title
      • Claude Solnik (631) 913-4244 Long Island Busin...
      • the dead shall arise despite andrew cumo
      • No title
      • No title
      • trump endorses Andrew cuomo's service to rome
      • erdogan is puffed up by failure to beat andrew cuomo
      • No title
      • No title
      • No title
      • No title
      • erin misapprehends what is important to many
      • No title
      • No title
      • david cole does not like your kind
      • No title
      • No title
    • ►  November (173)
    • ►  October (219)
    • ►  September (191)
    • ►  August (191)
    • ►  July (182)
    • ►  June (102)
    • ►  May (139)
    • ►  April (93)
    • ►  March (90)
    • ►  February (84)
    • ►  January (121)
  • ►  2016 (1004)
    • ►  December (64)
    • ►  November (121)
    • ►  October (100)
    • ►  September (78)
    • ►  August (130)
    • ►  July (138)
    • ►  June (92)
    • ►  May (98)
    • ►  April (76)
    • ►  March (61)
    • ►  February (43)
    • ►  January (3)
  • ►  2015 (625)
    • ►  December (20)
    • ►  November (13)
    • ►  October (7)
    • ►  September (21)
    • ►  August (27)
    • ►  July (104)
    • ►  June (79)
    • ►  May (126)
    • ►  April (62)
    • ►  March (46)
    • ►  February (60)
    • ►  January (60)
  • ►  2014 (487)
    • ►  December (49)
    • ►  November (36)
    • ►  October (33)
    • ►  September (28)
    • ►  August (38)
    • ►  July (54)
    • ►  June (30)
    • ►  May (52)
    • ►  April (37)
    • ►  March (11)
    • ►  February (32)
    • ►  January (87)
  • ►  2013 (543)
    • ►  December (74)
    • ►  November (49)
    • ►  October (46)
    • ►  September (28)
    • ►  August (39)
    • ►  July (28)
    • ►  June (60)
    • ►  May (57)
    • ►  April (44)
    • ►  March (51)
    • ►  February (32)
    • ►  January (35)
  • ►  2012 (470)
    • ►  December (32)
    • ►  November (25)
    • ►  October (18)
    • ►  September (29)
    • ►  August (23)
    • ►  July (32)
    • ►  June (58)
    • ►  May (30)
    • ►  April (86)
    • ►  March (56)
    • ►  February (38)
    • ►  January (43)
  • ►  2011 (151)
    • ►  December (50)
    • ►  November (29)
    • ►  October (29)
    • ►  September (43)

About Me

leonardeuler
View my complete profile
Simple theme. Powered by Blogger.