Today I want to give a little review about the latest app released by
SektionEins called “System and Security Info” due to its recent media
appearance. So first of all the app can be obtained via the Apple App store for
0,99€ at the time this article was written. This article will try to answer two
basic questions: for whom (or “which groups of people”) is this app helpful, and
which security features does this app actually has. The design of the app is
straight forward and pretty minimalistic with a clean and modern design. The
first page of the Application called “Overview” provides nothing more than the
current CPU usage of the device, with detailed subdivision in User, Idle, Total
and Load. The next section provides an overview about the used RAM divided into
Wire, Active RAM usage, Inactive RAM usage, “other”, free and the total amount
of the device’s ram. The next option shows the used and unused part of the
devices available storage, with “used”, “free” and total amount of space. While
these features can be handled with several other (free and open source)
applications I won’t write a comment wether it these components make sense.
At the 16th of September Apple released its new version of the mobile operating
system iOS 9. As several versions before, this new iteration suffers from a
weakness that makes it possible to bypass the lockscreen without entering the
respective PIN code. Exploiting this flaw requires Siri to be enabled and
phyiscal access to the phone. A successful exploitation results in a major loss
of confidentiality as all photos and contacts in the phonebook can be accessed
by the attacker. The following steps lead to the lockscreen bypass:
Over the past few weeks, multiple news sites have covered some mystical approach
to bruteforce PINs on Apple iOS devices. All articles cover a black box called
IP Box, the fact that PINs can be broken and that sometimes the automatic wipe
after 10 failed tries can be circumvented. Sadly, as often, the what is
described but not the how……
This blog post will give you a simple overview of both the practical attacks and
the vulnerabilities behind them. Although the Headings don’t quite give away the
content, the post starts with a simple PIN bruteforce against iOS 7.x and then
goes over to a more advanced attack on iOS 8.x and a few technical details on
the “black box”.
Once again a vulnerability in Apples mobile operating system iOS was found by
some guys of the Jailbreak Nation. The newest version of this operating system
suffers from a weakness that makes it possible to unlock the lockscreen of all
iPhones that use iOS version 6.1. In this case it does not matter whether a PIN
or a password is used to unlock the phone. After successful exploitation an
attacker is able to see and edit contact-information, to add new contacts to the
phonebook, to view all pictures, to call the inbox or any of the contacts and to
see and delete the list of recent calls or parts of it.