Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > Projects and Hacks > iPhone > General > General

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-04-2007, 01:09 AM
Locked's Avatar
Locked
Status: Offline
Respected Member
 
Join Date: Aug 2007
Location: 127.0.0.1
Posts: 900
Rep Power: 49
Locked is on a distinguished road
Thumbs up A new exploit discovered, might help in cracking 1.1.1 soon

It looks like the dev team is up to something. I have been following them over at IRC and it looks like Mobile Safari on both the touch and the iPhone are suffering from a one year old TIFF exploit.

Basically, opening a carefully crafted TIFF image will crash mobile safari, causing a buffer overflow and allow for arbitrary code execution. This same exploit was used more than 1.5 years ago to crack the PSP firmware.


EDIT: Stop posting retarded questions on the irc dev channel. The dev channel is only for iPhone developers/hackers. Post generic iphone/unlocking questions to #iphone or #iphone-tards

EDIT 2: The exploit wasn't discovered by the Dev team. It was discovered by PSP hacker Niacin. It was posted in the dev channel though.

EDIT 3: See page 10 for updates from Niacin.

Last edited by Locked; 10-07-2007 at 09:34 PM. Reason: updates
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 10-04-2007, 01:12 AM
mjban
Status: Offline
Junior Member
 
Join Date: Sep 2007
Posts: 17
Rep Power: 0
mjban is on a distinguished road
Default

Good news!!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 10-04-2007, 01:28 AM
tetsu's Avatar
tetsu
Status: Offline
Senior Member
 
Join Date: Sep 2007
Posts: 387
Rep Power: 23
tetsu is on a distinguished road
Default

great.. hope we can get somewhere soon!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #4 (permalink)  
Old 10-04-2007, 01:28 AM
wel914
Status: Offline
Junior Member
 
Join Date: Sep 2007
Posts: 18
Rep Power: 0
wel914 is on a distinguished road
Default

Nice!!!!!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 10-04-2007, 01:29 AM
bigD
Status: Offline
Member
 
Join Date: Aug 2007
Posts: 76
Rep Power: 6
bigD is on a distinguished road
Default

You can do it Dev Team.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 10-04-2007, 01:44 AM
Fraggle007's Avatar
Fraggle007
Status: Offline
Member
 
Join Date: Sep 2007
Posts: 35
Rep Power: 0
Fraggle007 is on a distinguished road
Default

Watch this wiki for updates on this specific proposal

http://www.touchdev.net/wiki/Decrypt...uffer_Overflow
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #7 (permalink)  
Old 10-04-2007, 01:46 AM
mr_
Status: Offline
Senior Member
 
Join Date: Sep 2007
Posts: 100
Rep Power: 8
mr_ is on a distinguished road
Default

that could be big! upgrading leaves the /var partition alone, so you could install a whole BSD subsystem and ssh/sftp in the /var partition, upgrade, and employ this exploit to copy everything to /bin and run it... even if 1.1.1 will only run signed applications, you can write code through the exploit to peek and see what's there. If this works, 1.2.1 MobileSafari will run as a contained process with very few permissions .

Last edited by mr_; 10-04-2007 at 02:02 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 10-04-2007, 01:52 AM
Locked's Avatar
Locked
Status: Offline
Respected Member
 
Join Date: Aug 2007
Location: 127.0.0.1
Posts: 900
Rep Power: 49
Locked is on a distinguished road
Default

Quote:
Originally Posted by mr_ View Post
that would be huge news! upgrading leaves the /var partition alone, so you could install a whole BSD subsystem and ssh/sftp in the /var partition, upgrade, employ this exploit to copy everything to /bin, and we are in business!!!
Exactly! Let's wait and see. The next few hours are going to be exciting !!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9 (permalink)  
Old 10-04-2007, 01:56 AM
jmcallister
Status: Offline
Senior Member
 
Join Date: Sep 2007
Posts: 159
Rep Power: 10
jmcallister is on a distinguished road
Default

This is great news...... Go dev team
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #10 (permalink)  
Old 10-04-2007, 02:19 AM
Dimsum's Avatar
Dimsum
Status: Offline
Senior Member
 
Join Date: Sep 2007
Posts: 162
Rep Power: 11
Dimsum is on a distinguished road
Default

wow - thats a great find!!!

i only wish Dark_AleX / M33 of PSP firmware cracking fame was an iPhone user! lol
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +2. The time now is 05:24 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105