<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AllTechRelated &#187; SSH</title>
	<atom:link href="http://blog.alltechrelated.com/tag/ssh/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.alltechrelated.com</link>
	<description></description>
	<lastBuildDate>Tue, 16 Mar 2010 17:42:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Hacker who Causes Worms on iPhone gets Rewarded with a Job</title>
		<link>http://blog.alltechrelated.com/2009/11/26/hacker-who-causes-worms-on-iphone-gets-rewarded-with-a-job/</link>
		<comments>http://blog.alltechrelated.com/2009/11/26/hacker-who-causes-worms-on-iphone-gets-rewarded-with-a-job/#comments</comments>
		<pubDate>Thu, 26 Nov 2009 18:36:46 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone News]]></category>
		<category><![CDATA[Ikee]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[jailbroken]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=7104</guid>
		<description><![CDATA[The hacker called Ashley Towns who created the Ikee worm for the iPhone has been approached by Australian firm of Mogeneration and been offered a job as iPhone application developer for them.
In other words, Ikee is being rewarded for creating the first worm for the iPhone which has lead to other worms being created which [...]]]></description>
			<content:encoded><![CDATA[<p>The hacker called Ashley Towns who created the Ikee worm for the iPhone has been approached by Australian firm of Mogeneration and been offered a job as iPhone application developer for them.</p>
<p>In other words, Ikee is being rewarded for creating the first worm for the iPhone which has lead to other worms being created which are more malicious such as the <a href="http://blog.alltechrelated.com/2009/11/23/iphone-worm-x2-ikees-not-the-only-one/">Dutch one which steals the bank details</a> of users who use the ING Dutch bank.<span id="more-7104"></span></p>
<p>The Ikee worm itself was not malicious as it only changed the background of your device to the face of Rick Astley but the worm was also a show-and-tell for other hackers to start hacking the iPhone.</p>
<p>So far there have been two more worms after Ikee. The first being <a href="../2009/11/23/iphone-worm-x2-ikees-not-the-only-one/" target="_blank">iPhone/Privacy.A</a> which redirect users to a phishing site when they do online banking on their devices through the dutch bank ING.</p>
<p>The second called <a href="http://blog.alltechrelated.com/2009/11/25/ibotnet-the-third-worm-to-infect-the-iphone/" target="_blank">iBotnet.A</a> takes over your device and starts using as a Botnet, much like a hacker would take over your computer for a botnet.</p>
<p>However as I have mentioned in all the worm related posts, the fix for the exploit in jailbroken iPhone is very easy. <a href="http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/">HERE IS A GUIDE TO DO IT.</a></p>
<p>What do you guys think? Do you think Ikee should be rewarded for what he did? Is it wrong?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/11/26/hacker-who-causes-worms-on-iphone-gets-rewarded-with-a-job/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iBotnet: The Third Worm to Infect the iPhone</title>
		<link>http://blog.alltechrelated.com/2009/11/25/ibotnet-the-third-worm-to-infect-the-iphone/</link>
		<comments>http://blog.alltechrelated.com/2009/11/25/ibotnet-the-third-worm-to-infect-the-iphone/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 16:58:11 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone News]]></category>
		<category><![CDATA[Ikee]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=7090</guid>
		<description><![CDATA[iBotnet is the third worm to infect the iPhone and iPod Touch using an exploit with the SSH password that most people don&#8217;t bother to change from &#8216;alpine&#8217;. The other instances of worms on the iPhone were called Ikee and the iPhone/Privacy.A. The Ikee worm was a harmless one which changed the background of your [...]]]></description>
			<content:encoded><![CDATA[<p>iBotnet is the third worm to infect the iPhone and iPod Touch using an exploit with the SSH password that most people don&#8217;t bother to change from &#8216;alpine&#8217;. The other instances of worms on the iPhone were called Ikee and the <a href="http://blog.alltechrelated.com/2009/11/23/iphone-worm-x2-ikees-not-the-only-one/" target="_blank">iPhone/Privacy.A.</a> The Ikee worm was a harmless one which changed the background of your lockscreen to a photo of Rick Astley. However the second one (and this one) are more harmful.<span id="more-7090"></span></p>
<p>The second one, called <a href="../2009/11/23/iphone-worm-x2-ikees-not-the-only-one/" target="_blank">iPhone/Privacy.A</a> attacked users who did online banking with the Dutch bank ING by redirecting them to a phishing site to try and trick them into giving up their bank details.</p>
<p>This virus, called iBotnet.A is also a malicious one. It has the same purpose as botnets on the computer. Once a device is taken over, the hacker can use it to perform attacks on websites by overloading or other such reasons.</p>
<p>The worms only infect jaibroken iPhones and iPod Touchs which have SSH installed and haven&#8217;t changed their SSH passwords.</p>
<p>The worms are starting to spread world wide as they are made to duplicated autmatically. There are reports of the worms in Netherlands, Portugal, Hungary and Australia (where Ikke originated from).</p>
<p>Luckily there is an easy fix. It is simply to change the SSH password for your device. If you have not done this you are VERY LIABLE to worms on your device which could end up with hackers stealing sensitive data such as your credit card details.</p>
<p>I cannot stress enough have important it is that you change you SSH password. Not only are you a victim but you will also be spreading the worm.</p>
<p><a href="http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/" target="_blank"><strong>We have posted a guide on how to change your SSH password here. If you have not done it, do it now!</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/11/25/ibotnet-the-third-worm-to-infect-the-iphone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone Worm X2 &#8211; Ikee&#8217;s not the only one!</title>
		<link>http://blog.alltechrelated.com/2009/11/23/iphone-worm-x2-ikees-not-the-only-one/</link>
		<comments>http://blog.alltechrelated.com/2009/11/23/iphone-worm-x2-ikees-not-the-only-one/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 17:44:39 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone News]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Ikee]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=7078</guid>
		<description><![CDATA[In the end it was to be expected after news of the Ikee worm spreading through iPhone&#8217;s that a more malicious worm was coming soon to the iPhone.
This worm is targetting Dutch users who user their devices to do eBanking with the Dutch online bank ING. What it does is redirects the ING login page [...]]]></description>
			<content:encoded><![CDATA[<p>In the end it was to be expected after news of the <a href="http://blog.alltechrelated.com/2009/11/08/more-hackers-taking-advantage-of-the-ssh-problem/" target="_blank">Ikee worm spreading through iPhone&#8217;s</a> that a more malicious worm was coming soon to the iPhone.</p>
<p>This worm is targetting Dutch users who user their devices to do eBanking with the Dutch online bank ING. What it does is redirects the ING login page to a phishing site which then steals your data and eventually, your money.<span id="more-7078"></span></p>
<p>Again this only affects jailbroken devices who use SSH and haven&#8217;t changed their default password from &#8216;Alpine&#8217;.</p>
<p>The solution to this problem is actually very simple. To ensure you are not affected by this worm, Ikee&#8217;s worm or any other worms that use this exploit, change the default password of your device. <a href="http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/" target="_blank">HERE IS A GUIDE</a>.</p>
<p>F-Secure have posted all the information they have on the virus and will keep it updated on <a href="http://www.f-secure.com/weblog/archives/00001822.html" target="_blank">this page</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/11/23/iphone-worm-x2-ikees-not-the-only-one/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Charlie Miller: New Worms coming to the iPhone</title>
		<link>http://blog.alltechrelated.com/2009/11/11/charlie-miller-new-worms-coming-to-the-iphone/</link>
		<comments>http://blog.alltechrelated.com/2009/11/11/charlie-miller-new-worms-coming-to-the-iphone/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 17:15:39 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Charlie Miller]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=6918</guid>
		<description><![CDATA[After all the hype of the two hacks that have accured in Australia and Germany where users will access the filesystem of a jailbroken iPhone or iPod Touch through SSH and change stuff on the phone.
As of now, the hacks have been harmless because they simply changed the background of the device but this exploit [...]]]></description>
			<content:encoded><![CDATA[<p>After all the <a href="http://blog.alltechrelated.com/2009/11/08/more-hackers-taking-advantage-of-the-ssh-problem/" target="_blank">hype of the two hacks that have accured in Australia and Germany</a> where users will access the filesystem of a jailbroken iPhone or iPod Touch through SSH and change stuff on the phone.</p>
<p>As of now, the hacks have been harmless because they simply changed the background of the device but this exploit has the potential to add worms and viruses to your device which could then be used to infect your computer once you have synced it.<span id="more-6918"></span></p>
<p>Even Charlie Miller, a very well known cyber security expert, has expressed his worry over the exploit.</p>
<p>As he says Apple have their devices very well protected but once users jailbreak them, these protection become less powerful. He is sure that in the next few months, users who do NOT change their SSH password will be vulnerable to a rising number of attacks targetting jailbroken iPhones.</p>
<p>He STRONGLY recommend you to change your SSH password to make sure this does not happen to you. <a href="http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/" target="_blank">For a guide on how to do that, go HERE</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/11/11/charlie-miller-new-worms-coming-to-the-iphone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Change your Default SSH Password</title>
		<link>http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/</link>
		<comments>http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 16:03:00 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone Guides]]></category>
		<category><![CDATA[cydia]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[MobileTerminal]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=6881</guid>
		<description><![CDATA[After all the scare with the SSH hackers going on, many people have finally realized the importance on changing your default SSH password. Therefore, to aid these people, we have decided to post this guide teaching users how to change their default SSH password.
How to change the default SSH Password:
For this guide, you are going [...]]]></description>
			<content:encoded><![CDATA[<p>After all the scare with the <a href="http://blog.alltechrelated.com/2009/11/08/more-hackers-taking-advantage-of-the-ssh-problem/" target="_blank">SSH hackers going </a>on, many people have finally realized the importance on changing your default SSH password. Therefore, to aid these people, we have decided to post this guide teaching users how to change their default SSH password.<span id="more-6881"></span></p>
<p><strong>How to change the default SSH Password:</strong></p>
<p>For this guide, you are going to need MobileTerminal (download it from Cydia):</p>
<ol>
<li>Open the MobileTerminal Application on your device:<br />
<a href="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0383.png"><img class="alignnone size-full wp-image-6884" title="IMG_0383" src="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0383.png" alt="IMG_0383" width="320" height="480" /></a></li>
<li>Type in &#8217;su root&#8217; and click enter:<br />
<a href="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0387.png"><img class="alignnone size-full wp-image-6885" title="IMG_0387" src="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0387.png" alt="IMG_0387" width="320" height="480" /></a></li>
<li>It will ask for the password so type in &#8216;alpine&#8217; which is the default password:<br />
<a href="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0388.png"><img class="alignnone size-full wp-image-6886" title="IMG_0388" src="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0388.png" alt="IMG_0388" width="320" height="480" /></a></li>
<li>Type in &#8216;passwd&#8217; and click enter:<br />
<a href="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0389.png"><img class="alignnone size-full wp-image-6887" title="IMG_0389" src="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0389.png" alt="IMG_0389" width="320" height="480" /></a></li>
<li>It will ask for a new password (more than 5 characters) so type it in:<br />
<a href="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0390.png"><img class="alignnone size-full wp-image-6888" title="IMG_0390" src="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0390.png" alt="IMG_0390" width="320" height="480" /></a></li>
<li>It wil ask your to retype the password:<br />
<a href="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0391.png"><img class="alignnone size-full wp-image-6889" title="IMG_0391" src="http://blog.alltechrelated.com/wp-content/uploads/2009/11/IMG_0391.png" alt="IMG_0391" width="320" height="480" /></a></li>
</ol>
<p>You have now changed your SSH password and protected your iPhone from the <a href="../2009/11/08/more-hackers-taking-advantage-of-the-ssh-problem/" target="_blank">SSH hackers</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>More Hackers Taking Advantage of the SSH Problem</title>
		<link>http://blog.alltechrelated.com/2009/11/08/more-hackers-taking-advantage-of-the-ssh-problem/</link>
		<comments>http://blog.alltechrelated.com/2009/11/08/more-hackers-taking-advantage-of-the-ssh-problem/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 15:44:29 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone News]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=6878</guid>
		<description><![CDATA[After news of the Dutch hacker changing your background making it as if he has taken over your device and demands 5 euros in exchange for regaining the control of your device, more people have decided to take advantage of this hole is jailbroken devices and spreading worms throughout the community.

This time, it&#8217;s a guy [...]]]></description>
			<content:encoded><![CDATA[<p>After news of the <a href="http://blog.alltechrelated.com/2009/11/03/dutch-hackers-takes-over-your-iphone-and-then-demands-e5-to-fix/" target="_blank">Dutch hacker changing your background making it as if he has taken over your device and demands 5 euros in exchange for regaining the control of your device</a>, more people have decided to take advantage of this hole is jailbroken devices and spreading worms throughout the community.</p>
<p style="text-align: center;"><a href="http://blog.alltechrelated.com/wp-content/uploads/2009/11/img0122-1257646906.png"><img class="size-full wp-image-6879 aligncenter" title="img0122-1257646906" src="http://blog.alltechrelated.com/wp-content/uploads/2009/11/img0122-1257646906.png" alt="img0122-1257646906" width="320" height="495" /></a></p>
<p>This time, it&#8217;s a guy called Ikee who spreads the worm and &#8216;rickrolls&#8217; users by changing their background as well.</p>
<p>Plus we have posted an interview with the hacker who explains why and how he did it.<span id="more-6878"></span></p>
<p>The instructions on how to get rid of it is included in the below interview (<a href="http://blog.jeltel.com.au/2009/11/interview-with-ikee-iphone-virus.html" target="_blank">via</a>):</p>
<blockquote><p><span style="font-family: Arial; font-size: small;"><span style="background-color: white; font-size: 13px;">[09:02] &lt;JD&gt; Hi ikee <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  Thanks for joining me<br />
[09:02] &lt;ikee&gt; nps<br />
[09:03] &lt;JD&gt; Now, as you&#8217;re well aware, you wrote a virus that is infecting many iPhones in Australia. I guess the real question to start with is why?<br />
[09:04] &lt;ikee&gt; First i was curious to how far something like this would actually spread, i think what most people were unaware of is the fact it IS a worm and every phone that got infected with it was spreading it (I initially only infected 3 phones when I woke up i checked google and found out a fair few people were hit with it)<br />
[09:05] &lt;ikee&gt; Secondly i was quite amazed by the number of people who didn&#8217;t RTFM and change their default passwords.<br />
[09:07] &lt;JD&gt; How far did you expect it to spread, exactly?<br />
[09:08] &lt;ikee&gt; Well i didn&#8217;t think that many people would have not changed their passwords I was expecting to see maybe 10~ or so people, at first I was not even going to add the replicate/worm code but it was a learning experience and i got a tad carried away <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[09:11] &lt;JD&gt; Are you aware that it has even started to replicate itself overseas?<br />
[09:13] &lt;ikee&gt; I heard a few stories about it, that would have been sheer luck, the code itself is set to firstly scan the 3G IP range the phone is on, then Optus/Vodafone/Telstra&#8217;s IP Ranges (I think the reason Optus got hit so hard is because the other 2 are NAT&#8217;d) then a random 20 IP ranges. I&#8217;m guessing a few phones hit a range that another vulnerable phone was on.<br />
[09:14] &lt;ikee&gt; (From another country)<br />
[09:15] &lt;JD&gt; Well that was my next question: Why does it only seem to be hitting Optus here and Overseas (I was presuming from screenshots I&#8217;ve seen)&#8230; So you&#8217;re saying the Optus network is more vulnerable due to it not using NAT?<br />
[09:17] &lt;ikee&gt; I don&#8217;t think it was an Optus fault (Being an Optus user I quite like the fact i can access my iPhone services from the outside world), I think it was mainly the fault of people being to lazy to change their passwords (It only takes a couple of seconds guys) and I hope this taught a few people that.<br />
[09:18] &lt;JD&gt; So do you know exactly how many people are currently infected with the &#8220;ikee virus&#8221;?<br />
[09:20] &lt;ikee&gt; I can only confirm how many my phone infected alone, which was 100+ phones. I think most of them fixed it (AND I&#8217;M HOPING THEY CHANGED THEIR PASSWORDS.)<br />
[09:21] &lt;JD&gt; So your major defense seems to be that people left themselves vulnerable, Do you steal stuff from people&#8217;s houses if they leave the backdoor open?<br />
[09:24] &lt;ikee&gt; I&#8217;ll answer your question with two questions, Have you ever used unprotected Wifi? and Technically I did not steal anything, have you ever littered on someone else&#8217;s property? (Smokers will definitely associate <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> )<br />
[09:25] &lt;JD&gt; Ok, I suppose I can personally admit to both of them, but it seems alot more to me like vandalism than littering, which isn&#8217;t something I would do<br />
[09:27] &lt;ikee&gt; Personally I would class littering as vandalism (They definitely don&#8217;t want your rubbish there). I admit I probably pissed of a few people, but it was all in good fun (well ok for me anyway)<br />
[09:30] &lt;JD&gt; So that explains why you decided to use Rick Astley. In my research, I&#8217;ve been reading about a similar virus (it seems) that contains a picture of an &#8216;asian child&#8217; &#8211; I havn&#8217;t seen screenshots of this, but that&#8217;s how it is described. Are you also responsible for the &#8220;Asian Child virus&#8221;?<br />
[09:32] &lt;ikee&gt; Ahh that was a quirk of my bad coding, the &#8216;virus&#8217; itself has 4 variations and the first variation would resend its LockBackground.jpg to the victim. I did not comprehend that the infector might have not rebooted their phone after changing the LockBackground to something else (Causing them to send their changed lockbackground instead of Mr Astley)<br />
[09:36] &lt;JD&gt; So it&#8217;s the same virus, but now containing a picture of someone&#8217;s loved one?<br />
[09:37] &lt;ikee&gt; Yeah, that was definitely not the intended effect.<br />
[09:39] &lt;JD&gt; Are you aware of the possible legal consequences of this (the ikee virus)? Are you concerned?<br />
[09:40] &lt;ikee&gt; I&#8217;d like to think I&#8217;m aware, and also I highly doubt I&#8217;m in any real trouble (So no not concerned)<br />
[09:43] &lt;JD&gt; James01 on Whirlpool asks: at least one person has reported being affected without a jailbreak â€“ seems unlikely given the nature of the phone and what I have garned about the &#8220;virus&#8221; &#8211; is this possible, or are the reports unreliable/mistaken?<br />
[09:44] &lt;ikee&gt; It only affects jailbroken phones, so people probably just got a little confused<br />
[09:45] &lt;JD&gt; vanquish777 on Whirlpool says: What I want to know is, how did I get infected when I had SSH toggled off<br />
[09:46] &lt;ikee&gt; You didn&#8217;t <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> , My guess is you had it on and when the &#8216;virus&#8217; hit, it disabled sshd so when you checked it afterwards it appeared to be off<br />
[09:47] &lt;JD&gt; Which reminds me, many people have said they are no longer able to disable SSH, is this intended to make sure you can do more damage to users?<br />
[09:50] &lt;ikee&gt; This was a hard bit for me to do, until i hit this the virus was not destructive at all. My first intention was to change the root/mobile password to random strings, then embed the strings into the LockBackground. Unfortunately passwd uses a tty (and not stdin) for its new password:request (similar to ssh logins, which is why you might find sshpass in /bin/, i had to port it) so to stop the phone getting infected over and over again (and<br />
[09:50] &lt;ikee&gt; someone else catching on and having mischief with peoples phones) I removed SSHD (cydia reinstall will rememdy the problem)<br />
[09:51] &lt;ikee&gt; (Cydia reinstall of SSH not reinstall Cydia itself)<br />
[09:53] &lt;JD&gt; So you&#8217;re saying that the only harm this virus causes is the removal of the SSH Daemon, which effectively, disables the initial problem?<br />
[09:53] &lt;ikee&gt; Well that and the pretty background yes <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[09:54] &lt;JD&gt; You mentioned that there are four versions/variants, what are the differences between them?<br />
[09:55] &lt;ikee&gt; Variants A-C were quite similar and the ones most people have bought up. Variant D is fair bit different, it stores its files in a completely different place and hides itself a lot more (No random plists in LaunchDaemons)<br />
[09:56] &lt;JD&gt; So you&#8217;re saying that the newest variant is more hidden, is it more malicious?<br />
[09:57] &lt;ikee&gt; It is a lot more hidden, a think most phones tend to be more secured now so it should die pretty fast. It is a little more malicious it tampers with some Cydia files.<br />
[10:01] &lt;JD&gt; Do Android users risk being infected? I&#8217;m guessing that the virus would only log in as root:alpine (the default root username and password for the iPhone OS IIRC)<br />
[10:02] &lt;ikee&gt; AFAIK no unless a user decided to use the same passwords, Although there is a weird quirk I read about dropbear in Android allowing any password (A bug with libcrypt I believe) but I could be very wrong.<br />
[10:03] &lt;ikee&gt; But even if an android phone was attacked the platform differences would not allow the code to be run <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[10:04] &lt;JD&gt; Just out of curiousity, what do you call what i&#8217;ve named the &#8220;ikee virus&#8221;?<br />
[10:05] &lt;ikee&gt; Its in a folder called POC-iWorm (Proof Of Concept) but I never named it (ikee virus works!)<br />
[10:09] &lt;JD&gt; You yesterday agreed to send me the source code (and removal instructions), what variant will it contain?<br />
[10:10] &lt;ikee&gt; C/D whatever version you want <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[10:11] &lt;JD&gt; How about all four? I&#8217;ll obviously be placing them online &#8211; probably Google Code or similar<br />
[10:13] &lt;ikee&gt; A-C was updated so I don&#8217;t have the first 2, I forked D from C. (I don&#8217;t know if its so wise posting the code online, nefarious people that otherwise would not have had the chance could modify it to be quite destructive)<br />
[10:14] &lt;JD&gt; Perhaps, But it has become quite clear that there&#8217;s a load of people that are unsecure, and if anyone wants to do anything bad enough, they are already going to know how.<br />
[10:15] &lt;JD&gt; I guess i&#8217;m hoping that the jailbreak software will soon have a &#8220;enter new root password&#8221; prompt for those users that are un-aware.<br />
[10:15] &lt;ikee&gt; I&#8217;ll leave the choice up to you <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[10:15] &lt;ikee&gt; I&#8217;d love to see that<br />
[10:16] &lt;ikee&gt; or even a random password generated and displayed for the user to write down<br />
[10:17] &lt;JD&gt; Yes, it would be very good. I had an iPod Touch a while ago, which I &#8220;jailbroke&#8221; &#8211; admittedly I didn&#8217;t change the default password. I guess i&#8217;m just glad it&#8217;s not me.<br />
[10:17] &lt;JD&gt; Do you plan on making any further variants? If so, why?<br />
[10:18] &lt;ikee&gt; No, I think the point has been made<br />
[10:18] &lt;JD&gt; Have you developed anything PRODUCTIVE in the iPhone world?<br />
[10:21] &lt;ikee&gt; I&#8217;m not too sure what others would class productive. I do not own a MAC or run OSX (Using a linux cross compile toolchain) so it makes it abit of a challenge to develop any applications utilising the UI (I have tho -.-). I think the best program ive developed for it for me was a remote debugging library that sends debug information over the network (Using MCAST)<br />
[10:23] &lt;JD&gt; Do you have anything further to add (I&#8217;m having a mental blank on questions to ask right now)<br />
[10:26] &lt;ikee&gt; I hope I did not piss off many people, this was a very simple problem and has an even simplier solution. I thought it was quite funny and I hope others did too <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[10:27] &lt;JD&gt; You mentioned infecting only three iPhones to being with, when did that happen?<br />
[10:28] &lt;ikee&gt; Around 4am November 6th (Yeah I have no life)<br />
[10:31] &lt;JD&gt; To confirm, other than replicating itself, adding the picture of Rick Astley, and removing the SSH Daemon, are we likely to find anything else it does?<br />
[10:32] &lt;ikee&gt; Nothing, and if you&#8217;re releasing the source code people will be able to see that <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[10:33] &lt;JD&gt; Can you please explain to me, how an infected user would remove the different versions correctly?<br />
[10:33] &lt;JD&gt; by correctly, I mean completely.<br />
[10:33] &lt;ikee&gt; Sure, variants A-C store files in these directories<br />
[10:34] &lt;ikee&gt; /bin/poc-bbot<br />
[10:34] &lt;ikee&gt; /bin/sshpass<br />
[10:34] &lt;ikee&gt; /var/log/youcanbeclosertogod.jpg<br />
[10:34] &lt;ikee&gt; /var/mobile/LockBackground.jpg<br />
[10:35] &lt;ikee&gt; /System/Library/LaunchDaemons/com.ikey.bbot.plist<br />
[10:35] &lt;ikee&gt; /var/lock/bbot.lock<br />
[10:35] &lt;ikee&gt; using an rm (in SSH or mobile-terminal on those files will remove it)<br />
[10:36] &lt;ikee&gt; then reboot the phone, change your password and reinstall SSH<br />
[10:36] &lt;ikee&gt; For variant D its abit different<br />
[10:36] &lt;ikee&gt; The locations are<br />
[10:37] &lt;ikee&gt; /usr/libexec/cydia/startup<br />
[10:37] &lt;ikee&gt; /usr/libexec/cydia/startup.so<br />
[10:37] &lt;ikee&gt; /usr/libexec/cydia/startup-helper<br />
[10:37] &lt;ikee&gt; /System/Library/LaunchDaemons/com.saurik.Cydia.Startup.plist<br />
[10:38] &lt;ikee&gt; Of course cydia used these files previously so you may need to reinstall it after deleting this files<br />
[10:38] &lt;ikee&gt; *these<br />
[10:38] &lt;JD&gt; So the D variant overwrites system files?<br />
[10:39] &lt;ikee&gt; Overwrits cydia&#8217;s files<br />
[10:39] &lt;ikee&gt; *Overwrites<br />
[10:39] &lt;JD&gt; Sorry, I&#8217;m not an expert at the iPhone OS <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /><br />
[10:39] &lt;ikee&gt; Neither <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /><br />
[10:40] &lt;JD&gt; So none of your versions do contain any password changing commands?<br />
[10:40] &lt;JD&gt; I mean, so when I provide uninstall instructions, I can tell them to use alpine as the password ?<br />
[10:41] &lt;ikee&gt; None of the code changes passwords<br />
[10:42] &lt;JD&gt; Thanks for your time ikee, and I really hope you do get into developing things that are productive sometime soon.<br />
[10:42] &lt;ikee&gt; me too <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  and no problems<br />
[10:42] &lt;JD&gt; Perhaps on the Android platform (Yes, I know, I&#8217;m a fanboy)<br />
[10:42] &lt;ikee&gt; I just downloaded the x86 iso, so maybe <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /><br />
[10:43] &lt;JD&gt; I&#8217;ll ask you more about that after I end this logging session, Cheers <img src='http://blog.alltechrelated.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
[10:43] &lt;ikee&gt; Ciaoo<br />
End of #Interview_Room buffer    Sun Nov 08 10:43:58 2009</span></span></p></blockquote>
<p><span style="font-family: Arial; font-size: small;"><span style="background-color: white; font-size: 13px;"><strong>Preventation:</strong></span></span></p>
<p><span style="font-family: Arial; font-size: small;"><span style="background-color: white; font-size: 13px;">The only way to prevent these attacks is to change the default password of SSH after you install it. Eventually hackers will find a worse way to attack devices using this exploit so change your passwords now!</span></span></p>
<p><span style="font-family: Arial; font-size: small;"><span style="background-color: white; font-size: 13px;"><a href="http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/" target="_blank">HERE is a guide showing how!</a><br />
</span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/11/08/more-hackers-taking-advantage-of-the-ssh-problem/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Dutch Hackers Takes over your iPhone and then Demands €5 to Fix</title>
		<link>http://blog.alltechrelated.com/2009/11/03/dutch-hackers-takes-over-your-iphone-and-then-demands-e5-to-fix/</link>
		<comments>http://blog.alltechrelated.com/2009/11/03/dutch-hackers-takes-over-your-iphone-and-then-demands-e5-to-fix/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 16:50:17 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone News]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=6809</guid>
		<description><![CDATA[
A dutch hacker has come up with a cunning plan on how to make some extra euros using his hacking skills. What he does it take over you iPhone and then demand a €5 donation and then he will give you iPhone back under your control.
He&#8217;s done it by scanning for all the iPhone users [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://blog.alltechrelated.com/wp-content/uploads/2009/11/21494.jpg"><img class="size-full wp-image-6810 aligncenter" title="21494" src="http://blog.alltechrelated.com/wp-content/uploads/2009/11/21494.jpg" alt="21494" width="300" height="450" /></a></p>
<p style="text-align: left;">A dutch hacker has come up with a cunning plan on how to make some extra euros using his hacking skills. What he does it take over you iPhone and then demand a <span>€5 donation and then he will give you iPhone back under your control.<span id="more-6809"></span></span></p>
<p style="text-align: left;"><span>He&#8217;s done it by scanning for all the iPhone users who had SSH enabled on their phones and then changed some files in the system making the following message come up on their phone:</span></p>
<blockquote><p>Your iPhone’s been hacked because it’s really insecure! Please visit doiop.com/iHacked and secure your iPhone right now! Right now, I can access all your files.</p></blockquote>
<p>The link (taken down now) brought you to his Paypal account were he asked for <span>€5 in return for instructions on how to fix and &#8217;secure&#8217; your device once again. </span></p>
<blockquote><p>If you don’t pay, it’s fine by me, but remember, the way I got access to your iPhone can be used by thousands of others-they can send text messages from your number (like I did), use it to call or record your calls, and actually whatever they want, even use it for their hacking activities! I can assure you, I have no intention of harming you or whatever, but, some hackers do! It’s just my advice to secure your phone.</p></blockquote>
<p>The website has now been taken down and he is offering the intructions for free. Here are the instructions for anyone who was affected by this:</p>
<blockquote><p>Ok plan&#8217;s changed. Here&#8217;s what to do, good luck and contact me if you have any questions</p>
<p>1. Get an SSH program like putty for windows.<br />
2. SSH to your iPhone. (If you haven&#8217;t done that before it may take a while, and after that there might come a warning about a key fingerprint. You can just accept that). Login using username &#8220;root&#8221; and password &#8220;alpine&#8221;. (this is the default password)<br />
3. There&#8217;s a few commands you have to execute, best is to just copy them:<br />
rm /System/Library/LaunchDaemons/com.apple.syslog.plist<br />
chown mobile /private/var/mobile/Library/LockBackground.jpg<br />
chmod 666 /private/var/mobile/Library/LockBackground.jpg<br />
mv /private/var/mobile/Documents/LockBackground.backup.jpg /private/var/mobile/Library/LockBackground.jpg<br />
4. That&#8217;s everything to remove my stuff. Now there&#8217;s one command left to make sure this won&#8217;t happen again! (-; Again in putty or any ssh client type: &#8220;passwd&#8221;. You&#8217;ll then be asked for a new password, you can change this into anything you want. The safer the better of course (:</p>
<p>The reason you have to change this password is that it&#8217;s default is alpine at ALL iPhones. So if anyone knows that (and all hackers do) they can access your iPhone. Now you&#8217;ve changed it this isn&#8217;t possible anymore!</p>
<p>If you have any questions or something, mail me and I&#8217;ll try to answer them!</p>
<p>PureInfinity92@mailinator.com (oh and btw the program is designed to remove itself so you should already be clear)</p></blockquote>
<p>The best way to stay safe from a problem like this is to change your SSH password away from the default one. To learn how to <a href="http://blog.alltechrelated.com/2009/11/08/how-to-change-your-default-ssh-password/" target="_blank">click HERE</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/11/03/dutch-hackers-takes-over-your-iphone-and-then-demands-e5-to-fix/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to Access your FileSystem on OS 3.0</title>
		<link>http://blog.alltechrelated.com/2009/07/16/how-to-access-your-filesystem-on-os-3-0/</link>
		<comments>http://blog.alltechrelated.com/2009/07/16/how-to-access-your-filesystem-on-os-3-0/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 14:43:16 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone Guides]]></category>
		<category><![CDATA[3.0]]></category>
		<category><![CDATA[Access]]></category>
		<category><![CDATA[FileSystem]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[OS]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[T-pOt]]></category>
		<category><![CDATA[Total Commander]]></category>
		<category><![CDATA[Tpot]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=5164</guid>
		<description><![CDATA[Since the beginning I have never used SSH because originally I could never get it to work. So I search and searched around for an equivalent and I found one that it not really known by a lot of people. I think everyone should use it because it is more reliable that SSH because simply, [...]]]></description>
			<content:encoded><![CDATA[<p>Since the beginning I have never used SSH because originally I could never get it to work. So I search and searched around for an equivalent and I found one that it not really known by a lot of people. I think everyone should use it because it is more reliable that SSH because simply, it uses USB cable rather than over the air. Plus it has worked with every firmware I have been on from 1.1.1 to 3.0. It&#8217;s called Total Commander. <span id="more-5164"></span></p>
<p>Total Commander with an extra plugin called T-Pot is the perfect equivalent to the SSH.I will host the plugin but for Total Commander, you should get it from the creators so you guys always get the newest version.</p>
<p>For Total Commander: <a class="downloadlink" href="http://blog.alltechrelated.com/files/download.htm" title=" downloaded 1265 times" >Total Commander (EXTERNAL LINK) (1265)</a><br />
For T-Pot Plugin: <a class="downloadlink" href="http://blog.alltechrelated.com/files/T-PoT.1.1.zip" title=" downloaded 1174 times" >T-Pot (1174)</a></p>
<ol>
<li>Firstly you will need to install the Total Commander program.</li>
<li>Download the T-Pot plugin from above. You do not need to extract it.</li>
<li>Open the Total Commander program. Because this program is free, you will need to press a certain number to start the program.</li>
<li>Then all you need to do is locate the T-Pot plugin you downloaded and double click on it IN THE TOTAL COMMANDER PROGRAM.</li>
<li>It should then say something about that this directory contains a plugin and it asks if you want to install it or not. Click yes to install.</li>
<li>Once it has finished, on the third row down from the top on the left beside where it says [preload] it says [-c-]. Click on that and change it to [-\-].</li>
<li>On the topÂ  it should say T-PoT. Click on it and you are now in the filesystems of your iPhone/iPod Touch.</li>
</ol>
<p><a href="http://blog.alltechrelated.com/wp-content/uploads/2009/07/t-pot.JPG"><img class="aligncenter size-full wp-image-5165" title="t-pot" src="http://blog.alltechrelated.com/wp-content/uploads/2009/07/t-pot.JPG" alt="t-pot" width="397" height="530" /></a>To me it&#8217;s a simply way that SSH. Hope you guys find this guide useful.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/07/16/how-to-access-your-filesystem-on-os-3-0/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>iUSB Tunnel &#8211; SSH and Tethered your iPhone With Ease</title>
		<link>http://blog.alltechrelated.com/2009/05/11/iusb-tunnel-ssh-and-tethered-your-iphone-with-ease/</link>
		<comments>http://blog.alltechrelated.com/2009/05/11/iusb-tunnel-ssh-and-tethered-your-iphone-with-ease/#comments</comments>
		<pubDate>Mon, 11 May 2009 18:42:44 +0000</pubDate>
		<dc:creator>psp2468</dc:creator>
				<category><![CDATA[iPod Touch/ iPhone Releases]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iPod Touch]]></category>
		<category><![CDATA[iUSB]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[Tether]]></category>
		<category><![CDATA[Tunnel]]></category>
		<category><![CDATA[VNC]]></category>

		<guid isPermaLink="false">http://blog.alltechrelated.com/?p=3519</guid>
		<description><![CDATA[A new application called iUSB Tunnel has been released by NukJon. It is an application that allows you SSH your iPhone, tether your iPhone and use VNC (see the iPhone screen on the computer) with ease using a simple and easy to use interface.


Here is who the creator, NukJon, describes his app:
iUSB Tunnel is a [...]]]></description>
			<content:encoded><![CDATA[<p>A new application called iUSB Tunnel has been released by NukJon. It is an application that allows you SSH your iPhone, tether your iPhone and use VNC (see the iPhone screen on the computer) with ease using a simple and easy to use interface.</p>
<p><a href="http://blog.alltechrelated.com/wp-content/uploads/2009/05/iusbtunnel.png"><img class="aligncenter size-full wp-image-3520" title="iusbtunnel" src="http://blog.alltechrelated.com/wp-content/uploads/2009/05/iusbtunnel.png" alt="iusbtunnel" width="408" height="299" /></a></p>
<p><span id="more-3519"></span></p>
<p>Here is who the creator, NukJon, describes his app:</p>
<blockquote><p>iUSB Tunnel is a simple gui that makes it easy to use SSH, VNC and Tethering with your iPhone over usb on a Windows machine. Itâ€™s a free liteweight program and portable so you can run it from a usb stick if you want. It comes loaded with WinSCP, Putty, Firefox Portable, iTunnel, TightVNC and UltraVNC so you donâ€™t have to download those programs.</p></blockquote>
<p>For the download, there are two different options for you:</p>
<ul>
<li>(Download&#8217;s removed): .EXE file for easy installation.</li>
<li>(Download&#8217;s removed): This is all the files packed into a .rar file.</li>
</ul>
<p>What do you guys think of the app? Post in the comments below!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.alltechrelated.com/2009/05/11/iusb-tunnel-ssh-and-tethered-your-iphone-with-ease/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->