Jump to content

New iPhone jailbreak(web based from iPhone!)


Recommended Posts

http://www.jailbreakme.com/

I was reading ars today and came across this article:

Web-based jailbreak relies on unpatched iOS PDF flaw

By Chris Foresman | Last updated about 3 hours agoA new Web-based jailbreak was released recently for iPhones and iPads running the latest versions of iOS. Users merely need to visit jailbreakme.com from an iPhone or iPad to automatically jailbreak the device, allowing them to install apps and hacks that have not been approved by Apple. However, the process relies on a vulnerability in Mobile Safari that could be likewise exploited by more nefarious hackers to access all the data on your device.

Jailbreaking has been around since the iPhone was first released—it was the only way to develop apps before iPhone OS 2.0 and the App Store appeared in 2008. It has also been used to install apps that aren't approved for the App Store, access iOS's underlying UNIX features, enable FaceTime chat over 3G and other carrier-unsupported features, or change settings that are otherwise unaccessible from the standard iOS interface. And, the Library of Congress recently ruled that defeating Apple's DRM to jailbreak an iPhone is a justified "fair use."

There are a variety of automated tools to jailbreak an iOS device, most of which require plugging a device in restore mode to a computer and running an application that performs the necessary steps to remove Apple's software locks. Jailbreakme.com, on the other hand, exploits a vulnerability in Mobile Safari to run the code necessary to jailbreak. "I wonder how long until someone figures out the actual bug I'm exploiting," the developer of jailbreakme.com wrote on Sunday via Twitter.

Not long, it seems. VUPEN Security today identified an issue in PDF handling as the flaw being exploited. A "memory corruption error" can occur when processing font data stored within a PDF file. The memory corruption can then trigger a kernel error that allows elevated privileges, bypassing the sandbox within which iPhone apps typically run. The vulnerability "could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page using Mobile Safari," which is exactly what jailbreakme.com does. The flaw is handy for easy jailbreaking, but not so good for unsuspecting users who might end up having their personal data pilfered.

The vulnerability has been identified as existing in iOS 3.x, 4.0, and 4.01, and affects iPhones, iPads, and iPod touches.

McAfee security researcher David Marcus noted that the exploit is so far only being used for jailbreaking, but could be used for many more—and far less savory—things. "This should serve as a wake-up call for anyone with a mobile device: Remote exploitation is real and here to stay," he wrote.

http://arstechnica.com/apple/news/2010/08/web-based-jailbreak-relies-on-unpatched-mobile-safari-flaw.ars

Just did it to my 3gs and it is great to have cydia back!!!!

-Installer for Duke's Car Stereo

2000 Pontiac Grand Prix - Ported Eaton M90 S/C, 3.5" pulley, XS Power Headers, 1.9 Rockers, FWI, Poly Motor Mounts, Custom Tune.

RF T1000-1bdCP and T400-4

Boston Acoustics SPG 555

Kenwood eXcelon 995

RF Punch 6.5" components and MB Quart Premium 6x9"s

Powermaster Alternator, YellowTop D34, Vmax CT1000

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Who's Online   1 Member, 0 Anonymous, 1438 Guests (See full list)

×
×
  • Create New...