iOS WiFi Bug Allows Remote Reboot of All Devices In Area
New submitter BronsCon writes: A recently disclosed flaw in iOS 8 dubbed "No iOS Zone" allows an attacker to create a WiFi hot spot that will cause iOS devices to become unstable, crash, and reboot, even when in offline mode. Adi Sharabani and Yair Amit of Skycure are working with Apple for a fix; but, for now, the only workaround is to simply not be in range of such a malicious network.
So I can get a seat at my local coffee house.
...of Microsoft-free Fridays?
Do not look into laser with remaining eye.
Exactly how does that work if the wifi is turned off?
“He’s not deformed, he’s just drunk!”
Seriously. the fact that offline mode is not offline is a bigger issue that this exploit.
That's a literal "work around".
Heh.
I'll get my coat.
Mod me down with all of your hatred and your journey towards the dark side will be complete!
You're being somewhere wrong
So offline mode isn't offline? This sounds like a bigger problem, than incorrect handling of a corrupt certificate.
I thought I was going to get First Post, but then this iPhone kept constantly rebooting.
#DeleteChrome
Actually, at my school, the reverse happens; the students develop sophisticated attacks for _fun_. I'm pretty sure the students will see their iOS devices _played_ with in a tomorrow.
You don't go to Capitol College (I'm sorry, Capitol Technology University), do you? Because I'm sure they're doing it there now.
I'm starting to think GNU is the problem with "GNU/Linux" these days.
no
If you have your phone set to connect to any available network, re-connect to wifi networks you have joined before, and to continually broadcast those SSIDs one by one until it receives a response, then don't be surprised to get owned every now and then you're following the 802.11 standard correctly.
If your phone is set to connect to networks with names like "attwifi" or "xfinitiwifi", then... well, that's what it will do.
So my Android device can act an an AP, is there an app for this yet?
even in "offline mode"? iPhone doesnt have an offline mode but an airplane mode and the story is 100% bullshit if he is claiming it can do this to a phone that is in airplane mode
That's not what they are saying... IF you have the phone in Airplane mode, you will have no problem. HOWEVER, if you don't and your phone tries to connect to the rouge AP then it crashes and reboots. At that point you are sunk because when your phone boots and it wasn't previously in Airplane mode, it will connect to the rouge AP and crash before you can get the phone into Airplane mode to stop the cycle.
So if your WiFi is actually turned off, nothing will happen. The problem is that once you get into this cycle, you cannot turn off the WiFi before the phone crashes and boots again. The only way to recover is to get out of range of the rouge AP so you can stop the crash, boot, crash cycle.
"File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
So theaters don't have to build an illegal cell phone jammer. Just put up a WiFi network to nothing, and crash every iPhone in the theater for you.
It was a misunderstanding after my first reading of the article. The actual issue is that the reboot cycle happens so rapidly that you never actually have an opportunity to interact with the phone to turn WiFi off once it starts, until you're out of range of the malicious AP.
APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
But what if it tries to connect to the mascara AP?
I bet you play lots of rouge-like games. And back in the day, you played Rainbow 6: Rouge Spear. (That one always just sounds naughty to me.) And when you go to Louisiana, you visit Baton Rogue, just because.
Conceptually, it sounds an awful lot like Woz' TV jammer.
Carry a Faraday cage with you, put your phone in it, reboot, and once it's rebooted, unlock the phone and turn off the WiFi.
You'll need to make it big enough to cover your hand and phone and transparent enough to see what you are doing.
It won't be complete because unless the Faraday cage covers your entire body (including your feet), the malicious WiFi signal could theoretically come through where your arm is. But unless the signal is really strong or bouncing off the wall behind you, you should be able to orient yourself so that the signal is too weak to be picked up by your phone.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
So, basically an anti-hipster device? I want one.
I am a brother to dragons, and a companion to owls.
Testing seems to show that iPhones on 8.3 don't connect to wifi immediately after a reboot. They wait until you login.
Herp derp. You could take the same approach to literally every security vulnerability ever. Remote exploit in the Linux kernel? Workaround: don’t use Linux! Malicious web pages? Workaround: don’t use the WWW!
Together with the other exploits for Gatekeeper in OSX that just came out, this goes on to prove a very simple point. iOS and OSX are not fundamentally safer than Android or Windows, they where just protected because the installed user base was not enough to catch hackers attention on the desktop platform. That it's clearly changing.
I so have an IPhone but I also have a couple Windows Phones and several Android phones. My favorite is the Note 3, even better now that AT&T finally upgraded it to Lollipop. Gotta have an extra couple phone with you just in case.
Paul E. Bahre