New iPhone worm steals online banking codes, builds botnet
Nick | Nov 24, 2009 | Comments 0
Hackers have borrowed a tactic from the world’s first iPhone worm to build a botnet that steals data, including online banking credentials, from jailbroken Apple smartphones.
A new worm, dubbed “Duh” by U.K.-based security firm Sophos, is related to the “ikee” worm released earlier this month only in its approach, not in its code, said Chester Wisniewski, a senior security advisory with Sophos.
“It’s different code, but the same conceptually,” Wisniewski said today.
Both ikee and the new Duh worms take advantage of the default password used by the SSH (secure shell) Unix utility, which is installed by some users after they’ve “jailbroken” their iPhones. That term refers to the process of modifying an iPhone so its owner can download and install software outside Apple’s official App Store channel. SSH lets users connect to their iPhone remotely over the Internet via an encrypted channel.
Duh changes the default SSH password of “alpine” to its own “ohshit” password, Wisniewski said.
Two weeks ago, noted iPhone and Mac vulnerability researcher Charlie Miller warned users that jailbreaking their iPhone puts them at greater risk from attack.
The Duh worm uses
One task of Duh is to steal SMS-based authentication codes that some banks use to protect customers who are conducting financial transactions from their iPhones.
“Historically, hackers haven’t been able to defeat the mTAN technology,” said Wisniewski, talking about the mobile transaction authentication numbers that some banks send to customers as a second layer of authentication. When a user logs into a bank that supports mTAN, he or she receives a six-digit code that must be entered within the next 90 seconds to prove ownership of the account.
Last month, a variant of the Zbot Trojan watched for TANs on hijacked PCs, and used silent instant messaging to transmit the codes to waiting hackers, who then had a short window during which they could preempt the legitimate account owner to access funds. “Duh is using a similar concept,” said Wisniewski. “It’s looking for incoming SMS with mTANs, capturing those mTANs in real-time and sending them to the command-and-control server. That gives the criminals time to log on using the mTAN.”
source: pcworld.idg
|Filed Under: Mobile News
The T-Mobile G1 is now officially available
iPhone 4G IV could support 802.11n
Britain's Got Talent's topless dancer sparks dozens of complaints
Weblogs, Inc. Three Years Later: Impressive Page View And Revenue Growth
Joost Continues Fight For Relevancy, Teams Up With Social Network Netlog
Fallout 3: The Pitt DLC
SlingPlayer Mobile for BlackBerry coming on December 30th
Netflix Hires Exec To Head Up Streaming Gadget Deals (NFLX)
Tumblr Helps You Find Wacky Photos Faster, Meet Your Neighbors
CircuitCity.com morphs into an info page
Yahoo Is Counting on Apex
Samsung to debut 12 megapixel beast at MWC ‘09?
Terrorists used BlackBerrys to cause horror
LinkedIn launches German site to take the fight to Xing
Facebook Connect + Facebook Ads = A Social Ad Network
PhoneBook Arranges Your iPhone Contacts For You