Guide To Building a Cable That Improves iOS Exploits
mask.of.sanity writes "An Aussie network engineer has published a guide to building a serial cable connector that allows access to a secret kernel debugger hidden within Apple iOS. The debugger was a dormant iOS feature carried over from Apple OS, and seems to serves no function other than to allow hackers to build better exploits. The cable needs an external power source and a jailbroken device to access the debugger." We've mentioned Pollock's serial adapter kit before, modulo the kernel debugging abilities.
So this is again one of these "exploits" that Epple took care of but the jailbreaking community didn't. I guess everyone is going to blame Apple again.
Yet another way to build better exploits: decompile the kernel. I guess Apple should prevent that as well or they'll be found guilty.
Write boring code, not shiny code!
Wait... so in order to use the cable to find exploits, you need a jailbroken device. But in order to jailbreak your device, you need to first find an exploit.
* Yes, I do know that there are other ways to find exploits...
I remember the days when apple play commercials claiming their OS don't get virus's, malware, etc. Now we see these story's weekly proving that all the load of bull apple claimed about their OS was nothing more them a lot of S
It's amazing that Apple and Jobs in it are so shortsighted that they don't provide official tools that people want. Of-course they have contracts with AT&T and who knows what else, that's most likely why they don't want to let people use these devices as general purpose computers, so that normal apps could be executed (and then you can use Skype or whatever to go around long distance phone charges obviously). But still, this is just so screwed up that a company would not see that it is in its best interest to sell the phone with the maximum possible features in it. OK, have an official Apple utility to so called "jail break" the thing and enter another lucrative market of various adapters and gadgets that could be then used together with the phone.
These devices are general purpose computers with wireless access and an odd phone application installed on them. Let the people use them the way they want to.
Of-course the unwillingness of Apple to allow people to use their own freaking product the way they want to provides HUGE market for all the other types of phones (Android) to fill that gap. It's just the short-sightedness of Apple is amazing in this instance.
You can't handle the truth.
Steps are :
# circumvent Apple security features* (aka jailbreak) your iPhone using currently known security holes and gain root level access
# uses this tool to find new security holes and keep silent about them, hoping neither Apple nor hackers with malicious intend find them too
# when Apple plugs already found security holes, hope it didn't plug the ones you just found so you can repeat step 1 on the newly released (hopefully) more secure firmware
PS : I know that the App stores ALSO introduces censorship but for MOST users and applications, it first and foremost blocks buggy/malicious/infringing applications (this is such a troll bait that I preferred to be an anonymous coward).
Forget IOS and consider the after market stuff you can buy for your car.
- Big bore exhaust - Tick
- 30Kw Sound System - Tick
- 6.5ltr Supercharged engine - Tick
You do all of that and then the back axle falls apart. So you go to the manufacturer and claim on the warranty.
When theyhave finished laughing they will tell you to get lost. You made changes to the item that was sold. That affected the operation.
You are So Out Of Luck
Now return to the IOS issue.
You bought an IOS device. YOU modified it and now you get malware.
Just how is this Apple's problem?
...exists in pretty much all phones (amongst other devices) although most would require some soldering on the PCBs, they are also used for forensic investigations -- or have completely separate circuits used just for forensics.
I don't remember much to be honest (like protocols etc) but I remember it from a forensics class I took.
The only surprising thing here is that they allow access to that circuitry via the normal device ports.
What is it with /. these days?
Stefan Esser showed how to make an iDev serial cable in April at SyScan'11, and making the cable is trivial.
Does it create tighter, faster code or increase the success of exploits?
Really, all those terrible efforts an Apple drone should do to get some very basic freedom on the devices he payed so much for.. how pathetic.
We want the schematics for the "hacker cable". /dev/tty.iap but the bootloader won't send anything on those pins at startup.
The schematic from the link in the TFA, ( http://www.ionetworks.com.au/files/serial_port.pdf ) using pins 12 & 13 of the dock connector is for a "accessory connection" cable and can be used from a jailbroken iPhone with
1% APY, No fees, Online Bank https://captl1.co/2uIErYq Don't let your $$$ sit in a no-interest acct.
Perhaps I don't understand the context, but it appears to me TFA uses the word "modulo" where it means "minus".
Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
However saying that because Apple has excellent profits now with the phones locked doesn't at all mean that they couldn't have even more profits if they allowed an option (maybe for some extra money) to those who wanted this option to remove any sort of protection against USER using the device the way they wanted to
Apple already offers this option. It costs $649 to buy a Mac mini if you don't already own a Mac, and then $99 per year to join the iOS developer program.
The back button on the HTC is unbelievably broken
Back on an Android-powered device always closes the frontmost window. It's not unlike Alt+F4 on a PC running Windows. Maybe you haven't picked up on it because web pages are treated as windows in the back stack.
And unless I'm refilling the wiper fluid, I never want to open the hood.
To continue the analogy, some companies' products don't even let you do that. You have to use the company's own brand of fluid, or the reservoir won't refill.
Hm, what am I missing here?
It requires an already jailbroken device. So you need to be root already. What additional functions does this allow you to access that you don't already can?
Assorted stuff I do sometimes: Lemuria.org
Man, call me old school, but wiring up a max232 to serial lines isn't really something I'd call a major development. He managed to wire it to an Apple docking connector? He's sucking 3.3V from the interface and wired in an actual resistor? Wow.
The magic in this is knowing what the iPhone is going to do and how to get it in a debug mode where a serial port might be handy. That's useful.
I am surprised that it doesn't take much to impress this community. God forbid anyone ever had to do any hardware work. This is a serial port for crissake. BFD.
The hacking is for fun.
Back when Slashdot had "news for nerds" instead of a bunch of fanboys living in their basement, people would be excited about hacks like this. Instead, we get a back and forth by who haven't written a line of code in their life and know absolutely nothing about security. I don't know why I still read this crap.
They do if you're on AT&T.
Did, past tense. Due to customer demand for Amazon Appstore, AT&T has been unhiding "Unknown sources". Besides, AT&T phones have always supported adb install; Google won't let the manufacturer use Android Market without it.
All iPods/iPhones using the standard 30 pin connector (and some earlier on the headphone jack as well) have a serial port as two of the pins on the dock connector. It is there for accessories to communicate with the device. You need to have an NDA in place with Apple to get the protocol commands, which are a PITA and very limited in function.
Jailbreaking just opens up the serial port for use as a general-use port, by running different software on the device.
I cant count the numerous number of times I have taken my HTC out of my pocket to find my penis or keys
I dunno what to think about the parent post.
On the one hand, he sounds smart, reasoned, and passionate about his tech experiences, so he sounds like a geek.
On the other hand, a real geek surely would obsessively COUNT how many times they took an HTC out of their pocket to find their penis.