WWDC rumor roundup: Retina display Macs, iCloud photo sharing, new iOS Maps

  • Filing details Apple's plans for Retina-ready resolution-independent OS X

  • Apple said to be ordering 4" screens for next iPhone

  • Apple television could double US household spending on Apple products

  • Free Overnight Shipping on all Macs. Save up to $612 on MacBook Pros: Mac Price Guide updated May 22nd. (Find the best prices on Macs)
    Monday, June 14, 2010

    Hackers fire back at AT&T, say all iPads at risk to Safari hole

    By AppleInsider Staff

    Published: 04:00 PM EST (01:00 PM PST)


    Disgruntled at having been characterized as 'malicious' by AT&T, the group of hackers who exploited a hole in the wireless operator's website last week have fired back by accusing both AT&T and Apple of acting irresponsibly in regard to iPad security.

    In a blog post Monday, Goatse Security attested that its manipulation of an AT&T web server that spit out the email addresses of over 114,000 iPad 3G subscribers -- including many top government and corporate officials -- was done as a public service, objecting allegations in AT&T's apology to customers that it acted "maliciously" and went to "great efforts" to perform the hack.

    "AT&T had plenty of time to inform the public before our disclosure. It was not done," the group said. "If not for our firm talking about the exploit to third parties who subsequently notified them, they would have never fixed it and it would likely be exploited by […] some other criminal organization or government."

    "[The] finder of the AT&T email leak spent just over a single hour of labor total (not counting the time the script ran with no human intervention) to scrape the 114,000 emails," it added.

    Escher Auernheimer, a member of Goatse Security, said the group disclosed the data it extruded from AT&T's server to just one journalist and then destroyed the original copy. He went on to accuse AT&T of dragging its feet on alerting customers and being dishonest bout the potential for harm.

    "Post-patch, disclosure should be immediate– within the hour," he wrote. "Days afterward is not acceptable. It is theoretically possible that in the span of a day (particularly after a hole was closed) that a criminal organization might decide to use an old dataset to exploit users before the users could be enlightened about the vulnerability."

    Separately, Auernheimer took both Apple and AT&T to task for failing correct and alert users to a semantic integer overflow exploit in Safari for the iPad that it discovered and publicized back in March.

    "It was patched on Apple’s desktop Safari but has yet to be patched on the iPad," he said. "This bug we crafted allows the viewer of a webpage to become a proxy (behind corporate and government firewalls!) for spamming, exploit payloads, password bruteforce attacks and other undesirables."

    A more detailed explanation of the hack posted by Goatse's explains how Safari on the iPad fails to block off access to some nonexistent ports which fall outside the 65536 different values representable in a number of 16 binary digits, also known as a 'short' integer.



    Once implemented, the hack can reportedly allow hackers to steal someone else's email identity, reflash network devices with firmware, or trick Safari into doing "pretty much anything on any TCP port and not have any current IDS/IPS in existence be any wiser for it."

    "The potential for this sort of attack and the number of iPad users on the list we saw who were stewards of major public and commercial infrastructure necessitated our public disclosure," Auernheimer said. "People in critical positions have a right to completely understand the scope of vulnerability immediately."

    Filed under : iPad 58 Comments ] 
    Story topics: AT&T, Security, Safari   Print ] [ Story Link ] 


    RSS
    RSS
    Mac Connection End of Summer Sale
    Early 2011 MacBook Pro Model
    Apple
    Price
    Discount
    2.2GHz quad 15" MacBook Pro $2,199.00 $1718.83* $480.17
    2.2GHz quad 17" MacBook Pro $2,499.00 $1,503.49* $559.01
    2.3GHz quad 17" MacBook Pro $2,649.00 $2,036.99* $612.01
    MacBook Pro Model
    Apple
    Price
    Discount
    2.4GHz dual 13" MacBook Pro $1,199.00 $1,086.34 $112.66
    2.8GHz dual 13" MacBook Pro $1,499.00 $1,382.19* $116.81
    2.2GHz quad 15" MacBook Pro $1,799.00 $1,629.54* $196.46
    2.4GHz quad 15" MacBook Pro $2,199.00 $1,971.54* $227.46
    2.4GHz quad 17" MacBook Pro $2,499.00 $2,250.39* $248.61
    *Instant 3% AppleInsider Reader Discount Applied With Coupon code:
    APPINSDRMWB32657

    AppleInsider Features
    Hot Forum Topics

    Recent Articles
    AT&T reportedly unlocking iPhones for deployed military personnel
    Analyst cuts AAPL rating on iPhone subsidy backlash, estimates $1B earnings miss
    AT&T to spend $150M on Lumia launch, more than it did with iPhone
    As 'iPad' becomes synonymous with 'tablet,' Apple must protect brand
    Facebook acquires Instagram for $1 billion
    Apple's Tim Cook awarded $378M in 2011, won't see most of it for years
    Apple's next iPhone predicted to have redesigned 'sleek' unibody case
    AT&T's iPhone unlock process accomplished through Apple's iTunes
    Foxconn employee says Apple placing orders for next iPhone to debut in October
    Most of estimated 21M iOS devices in China concentrated in urban areas
    Universal Pictures now available to re-download on Apple's iCloud
    New aerial images of Apple's planned NC fuel cell, solar farms emerge
    UK ad authority moves closer to '4G' iPad investigation
    Apple unlikely to get Samsung device injunction from US court
    Two more top execs exit RIM as company weighs options
    Apple's Ivy Bridge-powered iMacs rumored to debut in June
    Google rumored to launch sub-$250 7-inch tablet in July
    AT&T will allow out-of-contract customers to unlock their iPhone
    Security issue in Facebook, Dropbox iOS apps requires physical access
    HTC profits collapse 70% in face of competition from Apple, Samsung
    Facebook expected to join Apple, Google & Microsoft on Nasdaq
    Users report 3G connection issues with Apple's new iPad
    Samsung announces estimated $40B in revenue, $5B in profit for Q1 2012
    Apple issues second OS X Java update this week
    Qualcomm, Intel provide Apple with source code in patent battle with Samsung
    Apple share price exceeds Google's as its market cap reaches $590 billion
    Intel sinks 'hundreds of millions' of dollars into Ultrabook ad campaign
    Wikipedia joins Apple in migrating from Google Maps to OpenStreetMaps
    Mac shipments slow on absence of new hardware
    Apple may get 80% tax break to build new Texas campus
    Apple may soon begin selling iPad 2 units built in Brazil
    Apple's 'iPanel' called 'far more than a TV,' expected to launch in 2012
    Biographer says Steve Jobs was legitimately infuriated by Android
    Apple exploring face detection to unlock, customize & interact with iOS devices
    Apple interested in wireless power to charge devices on store shelves
    Briefly: iPad refunds; HonHai raising wages; Nokia Lumia estimates
    'Flashback' trojan estimated to have infected 600K Macs worldwide
    Claim construction tilts toward Apple in US patent lawsuit against Samsung
    Apple reportedly 'noodling with' 7.85-inch iPad prototype
    Apple reluctant to settle e-book pricing probe as antitrust specter looms








    AppleInsider RSS Feed
    AppleInsider © 1997-2011
    Please review our Privacy Policy.
    Written/Edited/Compiled by the AppleInsider Staff.