Quantcast
New iPhone/iPad iOS 0 day exploits - Beyond.ca - Car Forums
Results 1 to 10 of 10

Thread: New iPhone/iPad iOS 0 day exploits

  1. #1
    Join Date
    Jan 1970
    Location
    YYC
    My Ride
    1 x E Class Benz
    Posts
    23,619
    Rep Power
    101

    Default New iPhone/iPad iOS 0 day exploits

    Patch your iOS devices! Pretty sophisticated shit for the tech/security nerds. Attack looks to be used on high value targets, but with the public disclosures, expect to see variations in the wild in the near future. Good read for us nerds:

    https://citizenlab.org/2016/08/milli...nso-group-uae/
    Originally posted by SEANBANERJEE
    I have gone above and beyond what I should rightfully have to do to protect my good name

  2. #2
    Join Date
    Jan 2004
    Location
    Calgary, Alberta
    My Ride
    Bicycle
    Posts
    9,290
    Rep Power
    49

    Default

    At least not remote exploit and you have to hit a site. Been reading it all morning.

    Still took them 3 months to fix it after being reported in May.

  3. #3
    Join Date
    Oct 2009
    Location
    Calgary
    My Ride
    rally pig
    Posts
    2,466
    Rep Power
    22

    Default

    the scary and sad part though is that a lot of users just click any links sent from an unknown person

  4. #4
    Join Date
    Jan 1970
    Location
    YYC
    My Ride
    1 x E Class Benz
    Posts
    23,619
    Rep Power
    101

    Default

    Originally posted by Xtrema
    At least not remote exploit and you have to hit a site. Been reading it all morning.

    Still took them 3 months to fix it after being reported in May.
    It was remotely exploitable back in July via MMS through the TIFF exploit. That flaw was patched in 9.3.3.

    This wasn't reported in May. The messages were sent to the victim 10 days ago, although the 2 privilege escalation bugs have been around for a long time, as far back as iOS 7 from the looks of things.
    Originally posted by SEANBANERJEE
    I have gone above and beyond what I should rightfully have to do to protect my good name

  5. #5
    Join Date
    Jun 2003
    Location
    Alaska
    My Ride
    Model S
    Posts
    2,034
    Rep Power
    26

    Default

    Originally posted by Xtrema
    At least not remote exploit and you have to hit a site. Been reading it all morning.

    Still took them 3 months to fix it after being reported in May.
    You will hit a site. There is no sound security strategy that involves avoiding potentially bad sites. The main reason is because legitimate sites and ad networks get hacked and those get used to host the malicious content.

    The way they targeted this guy that reported it was lazy and dumb, and there are way more sneaky ways to ensure that users are hit by it.

    I don't think this one will get re-used in mass-exploitation, but it could, and the time when that kind of thing will happen to random users is definitely getting close.

    These are so expensive to find/make though that nobody would burn them on the general public, so staying up to date should minimize your risk unless you're an enemy of the state. If they get used en masse, it'll be because some lower tier group analyzed it long after it was public and patched, and they'll just go for the percentage of users that didn't bother updating. Sucks for jailbreakers!

  6. #6
    Join Date
    Jul 2008
    Location
    Pallet Town
    Posts
    817
    Rep Power
    0

    Default

    Ouch. With this and "touch disease" hardware problems, Apple could be having a rough year.
    Cocoa $8,000 per tonne.

  7. #7
    Join Date
    May 2008
    Location
    Wildflower Ranch
    My Ride
    Neo-Liberal Anarchist Mobile
    Posts
    2,245
    Rep Power
    38

    Default

    Originally posted by taemo
    the scary and sad part though is that a lot of users just click any links sent from an unknown person
    How else would you get to know said unknown person?

  8. #8
    Join Date
    Jan 1970
    Location
    YYC
    My Ride
    1 x E Class Benz
    Posts
    23,619
    Rep Power
    101

    Default

    Originally posted by ZenOps
    Ouch. With this and "touch disease" hardware problems, Apple could be having a rough year.
    This was patched in 10 days on all devices, so like googe says unless you're a high value target you have nothing to worry about if you're patched. Analysts are still touting Apple as the most secure smartphone platform compared to its competitors.
    Originally posted by SEANBANERJEE
    I have gone above and beyond what I should rightfully have to do to protect my good name

  9. #9
    Join Date
    Jul 2010
    Location
    Calgary
    My Ride
    01 i30
    Posts
    19
    Rep Power
    0

    Default

    It still boggles my mind how many Android phones are still affected by stagefright. Granted no high profile targets would be running anything lower then Lollipop most likely.

    This is one of the reasons I don't mind paying Apple's premium.

  10. #10
    Join Date
    Jan 2004
    Location
    Calgary, Alberta
    My Ride
    Bicycle
    Posts
    9,290
    Rep Power
    49

    Default

    Originally posted by Aaaaaron
    It still boggles my mind how many Android phones are still affected by stagefright. Granted no high profile targets would be running anything lower then Lollipop most likely.

    This is one of the reasons I don't mind paying Apple's premium.
    Other than Nexus line which get more steady updates, all Android phones are horrible security wise.
    Last edited by Xtrema; 08-27-2016 at 12:17 PM.

Similar Threads

  1. Conservative Government exploits Ottawa tragedy.

    By Toma in forum Society / Law / Current Events / Politics
    Replies: 14
    Latest Threads: 10-31-2014, 01:39 PM
  2. FS Brand New Maroo Moko New Ipad / Ipad 2 Leather Case *SOLD*

    By BensonTT in forum Miscellaneous Buy/Sell/Trade
    Replies: 2
    Latest Threads: 09-25-2012, 02:13 PM
  3. FS: Fido White iPhone 3GS 32 GB, iOS 4.0.1

    By hs2000 in forum Cellular Products
    Replies: 4
    Latest Threads: 08-02-2010, 12:47 AM
  4. iPhone 3GS upgrade to iOS 4 worth it?

    By Godfuader in forum Computers, Consoles, and other Electronics
    Replies: 6
    Latest Threads: 07-30-2010, 09:24 PM
  5. Downgrading iphone 3g 4.0 iOS to 3.1.3

    By eb0i in forum Computers, Consoles, and other Electronics
    Replies: 51
    Latest Threads: 07-08-2010, 11:14 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •