Discuss Touchfree is DANGEROUS [(REALLY) ULTIMATE GUIDE] leaves SSH open at the iPhone "2G" (Rev. 1) - Hackint0sh.org; ATTENTION: The correct title should be: "Touchfree installs a SSH server on your iPhone with ...
-
Touchfree is DANGEROUS [(REALLY) ULTIMATE GUIDE] leaves SSH open
ATTENTION: The correct title should be: "Touchfree installs a SSH server on your iPhone with public passwords - Leaving SSH (OpenSSH/DropBear) open on your iphone with default password is Dangerous"
Did you use the ULTIMATE GUIDE or the REALLY ULTMATE GUIDE ?
Dropbear allows anyone to connect via SSH to the phone if the IP address is accessable. ANYONE on the internet can wipe your phone clean, put some virus on it, convert your iPhone into an SMS Spamdevice, make plenty of calls, whatever.
So you must either change the root password or disable dropbear after using touchfree, or even better: DO BOTH. Disabling the dropbear process is in any case recommended as it may drain the battery.
To change the root password:
- install BSD Subsystem with Installer
- install Term-vt100
- start Term-vt100
- type: passwd
- change your password
- close Term-vt100
- uninstall BSD Subsystem with Installer
To disable dropbear:
- install with the installer the UIctl application (if UIctl doesnt show up in the installable applications then install community sources first)
- start UIctl
- click on the ....dropbear process, a menu pops up
(make absolutely sure that you didnt click anything else otherwise you may brick your phone)
- click unload -w and confirm, the dropbear process should now be red
- shutdown phone and restart
(try to log into your phone with winscp to check whether the phone is really not accessible by SSH)
- uninstall UIctl with the installer application
Finally: Sleep much better
Cheers
GeeJay
Last edited by geejay101; 10-29-2007 at 08:47 PM.
-
-
I used the alpha touch free version and I do not have drop bear running..
-
-

Originally Posted by
Marwanie
I used the alpha touch free version and I do not have drop bear running..
I havent tried the alpha version but I read that it uses openssh instead of dropbear.
So the same what I wrote above regarding dropbear applies also to openssh. Change passwords and disable openssh when not needed anymore.
-
Senior Professional
Array
Or you can just install services.app and activate/deactivate SSH from there at will.
iPhone 4 GB running 1.1.1 (virginized from 1.0.2) on Vodafone Greece
Activated/Jailbroken/Unlocked via Safari Exploit/TouchFree/Anysim
Calls in/out YES/YES
SMS in/out YES/YES
EDGE Probably yes, havent tried yet
Wifi/YouTube/Wireless iTunes YES/YES/YES
-
-
Respected Professional
Array

Originally Posted by
geejay101
Moderators please make sticky until ULTMATE guide authors have ammended their guides.
ATTENTION: touchfree opens iPhone publicly by installing dropbear SSH server with public passwords.
Did you use the ULTIMATE GUIDE or the REALLY ULTMATE GUIDE ?
Dropbear allows anyone to connect via SSH to the phone if the IP address is accessable. ANYONE on the internet can wipe your phone clean, put some virus on it, convert your iPhone into an SMS Spamdevice, make plenty of calls, whatever.
So you must either change the root password or disable dropbear after using touchfree, or even better: DO BOTH. Disabling the dropbear process is in any case recommended as it may drain the battery.
To change the root password:
- install BSD Subsystem with Installer
- install Term-vt100
- start Term-vt100
- type: passwd
- change your password
- close Term-vt100
- uninstall BSD Subsystem with Installer
To disable dropbear:
- install with the installer the UIctl application (if UIctl doesnt show up in the installable applications then install community sources first)
- start UIctl
- click on the ....dropbear process, a menu pops up
(make absolutely sure that you didnt click anything else otherwise you may brick your phone)
- click unload -w and confirm, the dropbear process should now be red
- shutdown phone and restart
(try to log into your phone with winscp to check whether the phone is really not accessible by SSH)
- uninstall UIctl with the installer application
Finally: Sleep much better
Cheers
GeeJay
How do you propose some one would do that???
maybe i should install some antivirus software on my iphone for the 100's of viruses and keyloggers and spyware that are there for the iphone
fear psycosis- don't you love it
Last edited by fallenczar; 10-28-2007 at 08:05 PM.
-
Senior Professional
Array
from the get go touchfree has ben plagued with bugs and erratic behavior.. STAY AWAY FROM IT!...
use carnaval with the tiff exploit in order to jailbrake and unlock your iphone
Best jailbreak solution Carnaval by brasuco! Keep on the great work iphone dev team!
now at version 0.7 download it
here or
here
my blog
http://blog.sposito.org
-
-
Amazingly Knowledgeable
Array
can you not just uninstall ssh from installer???
-

Originally Posted by
shodanjr_gr
Or you can just install services.app and activate/deactivate SSH from there at will.
That's what I thought. This works right?
-
-
Senior Professional
Array
Last edited by juanpa74; 10-29-2007 at 05:27 PM.
-
woe unto you
I also believe this is just paranoia, btw I used touchfree alpha and am experiencing no errors. I'm with the guy who said not to worry about things and stop promoting other methods based on unfactual information.
-
Similar Threads
-
By hackint0sh in forum Latest Headlines
Replies: 0
Last Post: 05-06-2008, 06:00 AM
-
By beerglass007 in forum iPhone "2G" (Rev. 1)
Replies: 11
Last Post: 12-11-2007, 11:33 PM
-
By newkid in forum iPhone "2G" (Rev. 1)
Replies: 2
Last Post: 10-28-2007, 08:35 PM
-
By tetsu in forum iPhone "2G" (Rev. 1)
Replies: 3
Last Post: 10-24-2007, 04:57 PM
-
By dragonaut in forum iPhone "2G" (Rev. 1)
Replies: 2
Last Post: 10-23-2007, 11:17 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
Bookmarks