SMS vulnerability “patch” for jailbroken iPhones

by Justin Horn on Jul 30th, 2009 @ 7:07 pm

The SMS vulnerability is going to be public knowledge any minute now and Apple has yet to patch or even comment on it. If you are jailbroken you are in luck though, you can “patch” your phone by disabling your messages app. Not an ideal solution, but for the paranoid it might not be a bad option. Keep in mind that this may not actually prevent the attack. The exploit works by sending over a hundred text to your iPhone which you only see one of in your messages app.

QuickPwn has posted the steps needed to accomplish this:

  1. Jailbreak your iPhone using either redsn0w or purplera1n
  2. Go to Cydia, search for OpenSSH and install it
  3. Download an SSH client (WinSCP for Windows users and Cyberduck for Mac)
  4. Make sure WiFi is turned on, go to Settings -> WiFi. Select your network and check your iPhone’s IP. SSH in to your iPhone using the iPhone’s IP. Login with the Username: root and Password: alpine.
  5. Navigate to the Applications directory
  6. Locate the directory named MobileSMS.app. Right-click and click on properties. Where it says Permissions uncheck all the options.
  7. Click OK.
  8. To test if you did this right, tap the SMS app on your iPhone and it should crash when you launch it!

Follow me on Twitter @justin_horn



View 3 Comments
Apple vs ?, at&t, iPhone

Comments

    1.
  1. Mystical
    July 31st, 2009 7:02 am

    How does asking someone to turn off a program become a patch?

  2. 2.
  3. spong
    July 31st, 2009 11:51 am

    what use is a phone with no SMS?

    Especially considering the caveat “Keep in mind that this may not actually prevent the attack. ”

    might as well be an itouch. Useless info.

  4. 3.
  5. Justin
    July 31st, 2009 12:05 pm

    Mystical, I put “patch” in quotes as it isn’t a fix, but a temp work around.

    spong, I added the caveat since I can’t confirm the QuickPwn workaround, but wanted to share it anyway as it might work and be a good fit for the ultra paranoid. I’m not worried and will keep my SMS running.

Sorry, the comment form is closed at this time.