Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 42955
  • Total Topics: 16151
  • Online Today: 4651
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: [Video] iPhone password revealing bug (steal passwords)  (Read 6775 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7528
  • KARMA: 322
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
[Video] iPhone password revealing bug (steal passwords)
« on: 14. September 2009., 06:11:49 »


A user on Twitter has posted a message about a potentially nasty bug found on the iPhone and iPod touch firmware. This user, rpetrich: http://twitter.com/rpetrich/status/3795384559 , discovered the exploit, which can reveal users passwords on the devices, according to ModMyi.com.

The bug only works in certain scenarios and doesn't pose a risk to users everywhere, unless somebody within arm reach gets a hold of your iPhone or iPod touch. The bug can be exploited in almost every available application that stores passwords; this includes your saved email account passwords.

The bug can reveal all characters, except the very first character in the password field. That is unless a user places a random character at the beginning of the password, than all characters can be revealed. The trick works when a password field is present with a saved password in it, a user can delete one character at a time, starting from right to left and shake the phone, press "undo typing" to reveal the hidden character.

This trick seems to only be present in firmware 2.0 and 3.0, but is apparently patched in the recently released 3.1 firmware.

This video demonstrated how the trick is possible:

iPhone Password Reveal

(NeoWin)

Samker's Computer Forum - SCforum.info

[Video] iPhone password revealing bug (steal passwords)
« on: 14. September 2009., 06:11:49 »

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising