<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gadget Cracker &#187; security</title>
	<atom:link href="http://www.gadgetcracker.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gadgetcracker.com</link>
	<description>Take Your Gadgets To The Next Level!</description>
	<lastBuildDate>Wed, 20 Jan 2010 18:00:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>UDID causes security compromise? Tapulous products&#8217; users in danger!</title>
		<link>http://www.gadgetcracker.com/2009/07/udid-causes-security-compromise-tapulous-products-users-in-danger/</link>
		<comments>http://www.gadgetcracker.com/2009/07/udid-causes-security-compromise-tapulous-products-users-in-danger/#comments</comments>
		<pubDate>Sat, 11 Jul 2009 18:01:17 +0000</pubDate>
		<dc:creator>RagnaParadise</dc:creator>
				<category><![CDATA[Music]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[cydia]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[phone hacks]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[tapulous]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.gadgetcracker.com/?p=238</guid>
		<description><![CDATA[
			
				
			
		
Thanks to the guys at iPod touch Fans and their post here!
People out there who have a Tapulous account, beware. If you don&#8217;t know what a Tapulous account is, basically it&#8217;s the profile generated from the UDID (unique device identifier) of your iPhone/iPod touch. Tapulous&#8217; authorization system is COMPLETELY dependent on your UDID, as practically [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin: 4px 16px 8px 0;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.gadgetcracker.com%2F2009%2F07%2Fudid-causes-security-compromise-tapulous-products-users-in-danger%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.gadgetcracker.com%2F2009%2F07%2Fudid-causes-security-compromise-tapulous-products-users-in-danger%2F&amp;source=gadgetcracker&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<div class="wp-caption aligncenter" style="width: 330px"><img src="http://img359.imageshack.us/img359/3028/quickshottrc.png" alt="" width="320" height="480" /><p class="wp-caption-text">Revenge, indeed.</p></div>
<p><em>Thanks to the guys at </em><a href="http://www.ipodtouchfans.com"><em><span style="text-decoration: none"><strong>iPod touch Fans</strong></span></em></a><em> and their post </em><a href="http://www.ipodtouchfans.com/forums/showthread.php?t=214415"><em><span style="text-decoration: none"><strong>here</strong></span></em></a><em>!</em></p>
<p>People out there who have a <strong>Tapulous account</strong>, beware. If you don&#8217;t know what a Tapulous account is, basically it&#8217;s the profile generated from the <strong>UDID (unique device identifier)</strong> of your iPhone/iPod touch. Tapulous&#8217; authorization system is COMPLETELY dependent on your UDID, as practically speaking, you&#8217;re the only one with the number. It&#8217;s called UNIQUE for a reason, right?</p>
<p>Apparently that can be abused, with the UDID Changer app from Cydia. What&#8217;s detrimental is that your Facebook and Twitter information is stored on Tapulous&#8217; servers as well. Of course it&#8217;s encoded, but when a malicious user changes their UDID to yours, Facebook and Twitter account data is immediately stored into their iPod touches/iPhones.</p>
<p>So what does this mean? It means that people can now <span style="text-decoration: underline">access your Twitter and Facebook accounts, as well as anything else they store in their servers</span>. Applications produced by Tapulous are: <strong>Tap Tap Revenge (and all its variants), Twinkle, Fortune, Collage and FriendBook.</strong></p>
<p>Your next question that comes into mind must be: &#8220;But how the *insert profanity here* can they get my UDID?&#8221; There are PLENTY of ways noted by iPod touch Fans, including, but not limited to:</p>
<ul>
<li><em>The malicious user may just ask you, and you may give it to them.</em></li>
<li><em>The malicious user may give you screenshots for a fantastic application they are making and offer you a beta. Of course, they need your UDID for you to beta test.</em></li>
<li><em>The malicious user may be someone you know that actually has access to your device.</em></li>
<li><em>Installer applications, such as Installer and Cydia send requests to the server with the UDID in the request. The maicious user may set up a repo to collect UDIDs.</em></li>
<li><em>Etc. There are so many ways, it&#8217;s ridiculous.</em></li>
</ul>
<p>Tapulous is aware of the exploit and are working on a fix to it, but meanwhile, unless you want someone posting the unthinkable on whatever accounts compromised, delete your Tapulous account. Change your Facebook and Twitter password as well, if you&#8217;re the &#8220;better safe than sorry&#8221; type of person.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gadgetcracker.com/2009/07/udid-causes-security-compromise-tapulous-products-users-in-danger/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>New Apple iPhone Exploit Gives Attacker Root Access</title>
		<link>http://www.gadgetcracker.com/2009/07/new-apple-iphone-exploit-gives-attacker-root-access/</link>
		<comments>http://www.gadgetcracker.com/2009/07/new-apple-iphone-exploit-gives-attacker-root-access/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 12:50:12 +0000</pubDate>
		<dc:creator>Gadget Cracker</dc:creator>
				<category><![CDATA[Cell Phone]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hole]]></category>
		<category><![CDATA[issue]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vunerability]]></category>

		<guid isPermaLink="false">http://www.gadgetcracker.com/?p=222</guid>
		<description><![CDATA[
			
				
			
		
It was bound to happen&#8230; Apple users have long enjoyed a relatively smooth ride with regard to virus&#8217; and malicious attacks, but this morning xaminer.com posted info on this serious iPhone expoit, discovered Charlie Miller:
It’s well-known that binary code can be sent to mobile devices using SMS. Normally the sent code isn’t executed, but Miller [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin: 4px 16px 8px 0;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.gadgetcracker.com%2F2009%2F07%2Fnew-apple-iphone-exploit-gives-attacker-root-access%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.gadgetcracker.com%2F2009%2F07%2Fnew-apple-iphone-exploit-gives-attacker-root-access%2F&amp;source=gadgetcracker&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="alignright size-thumbnail wp-image-223" title="apple-rotten" src="http://www.gadgetcracker.com/wp-content/uploads/2009/07/apple-rotten-150x150.jpg" alt="apple-rotten" width="150" height="150" />It was bound to happen&#8230; Apple users have long enjoyed a relatively smooth ride with regard to virus&#8217; and malicious attacks, but this morning <a href="http://www.examiner.com/">xaminer.com</a> posted info on this serious iPhone expoit, discovered <a href="http://securityevaluators.com/" target="_blank">Charlie Miller</a>:</p>
<p style="padding-left: 30px;"><em>It’s well-known that binary code can be sent to mobile devices using SMS. Normally the sent code isn’t executed, but Miller found that the iPhone operating system automatically processes the code without any user intervention. Not good. Knowing this, Miller developed code using the principle of Sulley Fuzzing, a method of injecting random data into program after first forcing the operating system to trust the new code.</em></p>
<p>And they go on to confirm the worst:</p>
<p style="padding-left: 30px;"><em>Another vulnerability that Miller found was the ability to use the SMS function to gain root access to the iPhone, more or less giving an attacker the “keys to the kingdom”.</em></p>
<p>On a positive note, Apple appears to already be working on a patch for this serious security vulnerability. We all know Apple&#8217;s history with timely updates though, so don&#8217;t hold your breath.</p>
<p>Get the full scoop here: <a href="http://www.examiner.com/x-14651-Minneapolis-Information-Technology-Examiner~y2009m7d3-Apple-iPhone-SMS-exploit-allows-attacker-to-control-phone" target="_blank">http://www.examiner.com/x-14651-Minneapolis-Information-Technology-Examiner~y2009m7d3-Apple-iPhone-SMS-exploit-allows-attacker-to-control-phone</a></p>
<p>So&#8230; who&#8217;s gonna beat Apple to the punch with a security patch that jail broken iPhone users can apply? :)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gadgetcracker.com/2009/07/new-apple-iphone-exploit-gives-attacker-root-access/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
