A Text Message Can Crash An iPhone and Force It To Reboot
DavidGilbert99 writes with news that a bug in iOS has made it so anyone can crash an iPhone by simply sending it a text message containing certain characters. "When the text message is displayed by a banner alert or notification on the lockscreen, the system attempts to abbreviate the text with an ellipsis. If the ellipsis is placed in the middle of a set of non-Latin script characters, including Arabic, Marathi and Chinese, it causes the system to crash and the phone to reboot." The text string is specific enough that it's unlikely to happen by accident, and users can disable text notification banners to protect themselves from being affected. However, if a user receives the crash-inducing text, they won't be able to access the Messages app without causing another crash. A similar bug crashed applications in OS X a few years ago.
Thank you for being a friend
Traveled down the road and back again
Your heart is true, you're a pal and a cosmonaut.
And if you threw a party
Invited everyone you knew
You would see the biggest gift would be from me
And the card attached would say, thank you for being a friend.
For enabling video inside html without flash. Welcome to the modern web!
Seriously, stop it. You're pissing off your long-term readers and they won't be replaced.
This is why you always sanitize user input.
Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways
Simple text can execute a program?
“He’s not deformed, he’s just drunk!”
I'm genuinely confused as to why people keep buying Apple stuff. I can get the same performance for half the price and twice the battery life from a lot of different brands.
Liberty - Security - Laziness - Pick any two.
https://xkcd.com/327/
I still laugh at this... am I an idiot? Don't answer that.
Getting notifications on an Apple Watch also protects the iPhone from the bug.
They have to push sales of the iWatch some ways...
It not a bug, it's a feature.
They do not publish it in TFA.
This story feels familiar...maybe one of the best reasons to avoid iOS devices. https://www.youtube.com/watch?...
"The bug is being used as a prank, with users taking to Twitter to vent their frustration after crashes. As with any glitch like this, it is that possible hackers could turn the bug into a method of attack beyond simple pranks." Seems to me if you can crash a device, you can perhaps "root" a device. Sounds like this is a test to see what can be done to an iOS device both now and in the future.
Trying around the office.
For example:
(in a non-Western language)
We know what we have to do next...
Crash!
An sms that uploads the recipient's email and photos on bittorrent, or on top of a blockchain. That should be a trend setter...
Years ago, I had a number of Nokia flip phones. I also converted emails to text messages and sent them to the phone (actually, probably MMS, not SMS), so that I could read my emails on a dumb phone.
However, every now and again, I would receive a "text of death". The phone would receive a text message, crash, reboot, attempt to download text messages again, crash .... etc.. It continued to do this until the network would decide to give up attempting to send that MMS message.
I had several phones of the same model and they all did this.
The real "Libtards" are the Libertarians!
You can't crash my iphone: 214 289 9974...
Power h
I mean seriously, why is it Apple again screwing up with Unicode? It's the third example of such crash that I recall, and probably there were more.
"Android is a superior OS"
"I think my iPhone has a bug"
AOL!
So when your phone receives a very specific text in Arabic it... blows itself up?
Shit like this are the artefacts from the steam age of computing.
As a web guy I deal with this every day. If I ever get around to building an OS and/plattform (Harhar) I'll force one text format and one only for all glyphs in existance (UTF seems like a good candidate).
Controll characters will be completely seperate.
We suffer more in our imagination than in reality. - Seneca
"You're reading it the wrong way."
Welcome to the Panopticon. Used to be a prison, now it's your home.
Did Apple already fix this? I immediately tried to crash every phone of every coworker who has an iPhone within earshot of me and it didn't work. Much to my disappointment. I'm now having to save face by harassing them with Pictures of Steve Job's license plateless car parked in multiple handicapped spots.
https://www.reddit.com/r/iphon...
"If any question why we died, Tell them because our fathers lied."
Is this any relation to the way SMS messages from (some) iPhones appear on the Treo message screen as a single non-ASCII garbage character?
It's unpredictable, but once someone's iPhone starts they can never again send me a SMS.
And as a dinosaur, I only started using SMS last year.
No, I don't want a new telephone, I'm happy with my Treo 650....
"Because nobody uses hosts files for security" - by bouldin (828821) on Thursday May 21, 2015 @05:53PM (#49746865)
FROM -> http://it.slashdot.org/comment...
SpyBot S&D does dimwit
(you FAIL #1)!
You LATER deny it's spybot's forums http://it.slashdot.org/comment...
Anyone can use it + see they do & MANY use that program stupid!
(you FAIL #2)!
---
NOD32/ESET's says hosts = valuable security http://slashdot.org/comments.p... as I also "overturned a SECURITY expert" on a "false positive" on my Hosts program RIGHT there & he gave in!
(YOU FAIL #3)!
(Had to - MalwareBytes' employees VETTED my code & even host + HIGHLY RECOMMEND it for me near top of -> http://hosts-file.net/?s=Downl...
---
Mr. Oliver Day of Symantec/Norton/SecurityFocus does too http://www.securityfocus.com/c...
(you FAIL #4)!
YOU ALSO TRIED TO DENY it & it's there in PLAIN Black & White with his NAME on it!
"I don't see Oliver Day of SecurityFocus on there. Weren't you going to cite him?" - by bouldin (828821) on Thursday May 21, 2015 @08:43PM (#49747763)
FROM-> http://it.slashdot.org/comment...
(you FAIL #5)!
---
WHOSE INITIALS ARE ON THIS - WINNER IN 2008 (added proof of paid for good layered security article):
http://forums.pcpitstop.com/in...
(YOU FAIL #7)!
Via the layered security/defense in depth methods my security guide extolls? I've COMPLETELY shut down your "desperation" RARE edge cases you tried too!
(You FAIL #8)!
Do YOU have *ANYTHING* like it to YOUR name/credit? No.
(YOU FAIL #9)!
---
Do you write a ware that noted security pros even seconded me on?? No.
(You FAIL #10)!
A ware that not only secures you but ALSO SPEEDS YOU UP (e.g. unlike antivirus which is not as effective anymore vs. online modern threats, mine is, stopping sources of infestation BEFORE they can get into you, & IF in you, stopping their communications BACK to C&C servers too!)
APK
P.S.=> LMAO: "Bouldin's GOLDEN top 10 'greatest hits'" (fails vs. me)... apk
"Because nobody uses hosts files for security" - by bouldin (828821) on Thursday May 21, 2015 @05:53PM (#49746865)
FROM -> http://it.slashdot.org/comment...
SpyBot S&D does dimwit
(you FAIL #1)!
You LATER deny it's spybot's forums http://it.slashdot.org/comment...
Anyone can use it + see they do & MANY use that program stupid!
(you FAIL #2)!
---
NOD32/ESET's says hosts = valuable security http://slashdot.org/comments.p... as I also "overturned a SECURITY expert" on a "false positive" on my Hosts program RIGHT there & he gave in!
(YOU FAIL #3)!
(Had to - MalwareBytes' employees VETTED my code & even host + HIGHLY RECOMMEND it for me near top of -> http://hosts-file.net/?s=Downl...
---
Mr. Oliver Day of Symantec/Norton/SecurityFocus does too http://www.securityfocus.com/c...
(you FAIL #4)!
YOU ALSO TRIED TO DENY it & it's there in PLAIN Black & White with his NAME on it!
"I don't see Oliver Day of SecurityFocus on there. Weren't you going to cite him?" - by bouldin (828821) on Thursday May 21, 2015 @08:43PM (#49747763)
FROM-> http://it.slashdot.org/comment...
(you FAIL #5)!
---
WHOSE INITIALS ARE ON THIS - WINNER IN 2008 (added proof of paid for good layered security article):
http://forums.pcpitstop.com/in...
(YOU FAIL #7)!
Via the layered security/defense in depth methods my security guide extolls? I've COMPLETELY shut down your "desperation" RARE edge cases you tried too!
(You FAIL #8)!
Do YOU have *ANYTHING* like it to YOUR name/credit? No.
(YOU FAIL #9)!
---
Do you write a ware that noted security pros even seconded me on?? No.
(You FAIL #10)!
A ware that not only secures you but ALSO SPEEDS YOU UP (e.g. unlike antivirus which is not as effective anymore vs. online modern threats, mine is, stopping sources of infestation BEFORE they can get into you, & IF in you, stopping their communications BACK to C&C servers too!)
APK
P.S.=> LMAO: "Bouldin's GOLDEN top 10 'greatest hits'" (fails vs. me)... apk
"Nobody uses hosts files for security" - by bouldin (828821) on Thursday May 21, 2015 @05:53PM (#49746865)
FROM -> http://it.slashdot.org/comment...
SpyBot S&D does dimwit
(you FAIL #1)!
Anyone can use it + see they do & MANY use that program stupid!
(you FAIL #2)!
---
NOD32/ESET's says hosts = valuable security http://slashdot.org/comments.p... as I also "overturned a SECURITY expert" on a "false positive" on my Hosts program RIGHT there & he gave in!
(YOU FAIL #3)!
(Had to - MalwareBytes' employees VETTED my code & even host + HIGHLY RECOMMEND it for me near top of -> http://hosts-file.net/?s=Downl...
---
Mr. Oliver Day of Symantec/Norton/SecurityFocus does too http://www.securityfocus.com/c...
(you FAIL #4)!
YOU ALSO TRIED TO DENY it & it's there in PLAIN Black & White with his NAME on it!
"I don't see Oliver Day of SecurityFocus on there. Weren't you going to cite him?" - by bouldin (828821) on Thursday May 21, 2015 @08:43PM (#49747763)
FROM-> http://it.slashdot.org/comment...
(you FAIL #5)!
---
WHOSE INITIALS ARE ON THIS - WINNER IN 2008 (added proof of paid for good layered security article):
http://forums.pcpitstop.com/in...
(YOU FAIL #7)!
Via the layered security/defense in depth methods my security guide extolls? I've COMPLETELY shut down your "desperation" RARE edge cases you tried too!
(You FAIL #8)!
Do YOU have *ANYTHING* like it to YOUR name/credit? No.
(YOU FAIL #9)!
---
Do you write a ware that noted security pros even seconded me on?? No.
(You FAIL #10)!
A ware that not only secures you but ALSO SPEEDS YOU UP (e.g. unlike antivirus which is not as effective anymore vs. online modern threats, mine is, stopping sources of infestation BEFORE they can get into you, & IF in you, stopping their communications BACK to C&C servers too!)
APK
P.S.=> LMAO: "Bouldin's GOLDEN top 10 'greatest hits'" (fails vs. me) - & you're a "security-engineer"after the above? LOL, not... apk
"Nobody uses hosts files for security" - by bouldin (828821) on Thursday May 21, 2015 @05:53PM (#49746865)
FROM -> http://it.slashdot.org/comment...
SpyBot S&D does dimwit
(you FAIL #1)!
Anyone can use it + see they do & MANY use that program stupid!
(you FAIL #2)!
---
NOD32/ESET's says hosts = valuable security http://slashdot.org/comments.p... as I also "overturned a SECURITY expert" on a "false positive" on my Hosts program RIGHT there & he gave in!
(YOU FAIL #3)!
(Had to - MalwareBytes' employees VETTED my code & even host + HIGHLY RECOMMEND it for me near top of -> http://hosts-file.net/?s=Downl...
---
Mr. Oliver Day of Symantec/Norton/SecurityFocus does too http://www.securityfocus.com/c...
(you FAIL #4)!
YOU ALSO TRIED TO DENY it & it's there in PLAIN Black & White with his NAME on it!
"I don't see Oliver Day of SecurityFocus on there. Weren't you going to cite him?" - by bouldin (828821) on Thursday May 21, 2015 @08:43PM (#49747763)
FROM-> http://it.slashdot.org/comment...
(you FAIL #5)!
---
WHOSE INITIALS ARE ON THIS - WINNER IN 2008 (added proof of paid for good layered security article):
http://forums.pcpitstop.com/in...
(YOU FAIL #7)!
Via the layered security/defense in depth methods my security guide extolls? I've COMPLETELY shut down your "desperation" RARE edge cases you tried too!
(You FAIL #8)!
Do YOU have *ANYTHING* like it to YOUR name/credit? No.
(YOU FAIL #9)!
---
Do you write a ware that noted security pros even seconded me on?? No.
(You FAIL #10)!
A ware that not only secures you but ALSO SPEEDS YOU UP (e.g. unlike antivirus which is not as effective anymore vs. online modern threats, mine is, stopping sources of infestation BEFORE they can get into you, & IF in you, stopping their communications BACK to C&C servers too!)
APK
P.S.=> LMAO: "Bouldin's GOLDEN top 10 'greatest hits'" (fails vs. me) - & you're a "security-engineer"after the above? LOL, not... apk
I'm having flashbacks of 90's Yahoo boot wars. Malicious text strings, sound bytes, bots, flooding, invite spamming, account locking, and illegal account name trading. Man those were some fun times.
Duh.
-- Tigger warning: This post may contain tiggers! --
I came here to say exactly this!
Why is everyone misusing the mantra of "always sanitize user input"? This is a generic messaging app. There is no invalid input!
If the application crashes because of assumptions about how to truncate messages (or because of assumptions that truncated messages will always contain complete multibyte sequences) then fix the assumptions!
it's a parsing bug
Yes! correct!
what difference would sanitizing user input make...
I'm glad you asked! It might make a huge difference to Apple's revenue stream. Clearly Apple hasn't sufficiently monetized SMS/iMessage. Once "sanitization" is allowed -- once content is subject to being modified for conformity -- a whole new world will be within their reach.
"hey, bring some soda for the party" INVALID
"hey, bring some Coke for the party" SANITIZED
</tinfoilcynic>
Maybe this will also crash the NSA sniffing programs.
I'm a satanic clam.
YOU brought it on YOURSELF: "eat your words" http://slashdot.org/comments.p... and You're JUST like that OTHER "pseudo security engineer" raymorris I tore to SHREDS here http://it.slashdot.org/comment... with concrete, reputable & reliable, UNDENIABLE sources + facts & truth...
APK
P.S.=> Shouldn't have "tried me" Bouldin - I warned you, way, Way, WAY AHEAD OF TIME what the outcome would be... you FAIL, boy! apk
C++ has UTF-8 string literals nowadays, you write them as u8"Text"
"Nobody uses hosts files for security" - by bouldin (828821) on Thursday May 21, 2015 @05:53PM (#49746865)
FROM -> http://it.slashdot.org/comment...
SpyBot S&D does dimwit
(you FAIL #1)!
Anyone can use it + see they do & MANY use that program stupid!
(you FAIL #2)!
---
NOD32/ESET's says hosts = valuable security http://slashdot.org/comments.p... as I also "overturned a SECURITY expert" on a "false positive" on my Hosts program RIGHT there & he gave in!
(YOU FAIL #3)!
(Had to - MalwareBytes' employees VETTED my code & even host + HIGHLY RECOMMEND it for me near top of -> http://hosts-file.net/?s=Downl...
---
Mr. Oliver Day of Symantec/Norton/SecurityFocus does too http://www.securityfocus.com/c...
(you FAIL #4)!
YOU ALSO TRIED TO DENY it & it's there in PLAIN Black & White with his NAME on it!
"I don't see Oliver Day of SecurityFocus on there. Weren't you going to cite him?" - by bouldin (828821) on Thursday May 21, 2015 @08:43PM (#49747763)
FROM-> http://it.slashdot.org/comment...
(you FAIL #5)!
---
WHOSE INITIALS ARE ON THIS - WINNER IN 2008 (added proof of paid for good layered security article):
http://forums.pcpitstop.com/in...
(YOU FAIL #7)!
Via the layered security/defense in depth methods my security guide extolls? I've COMPLETELY shut down your "desperation" RARE edge cases you tried too!
(You FAIL #8)!
Do YOU have *ANYTHING* like it to YOUR name/credit? No.
(YOU FAIL #9)!
---
Do you write a ware that noted security pros even seconded me on?? No.
(You FAIL #10)!
A ware that not only secures you but ALSO SPEEDS YOU UP (e.g. unlike antivirus which is not as effective anymore vs. online modern threats, mine is, stopping sources of infestation BEFORE they can get into you, & IF in you, stopping their communications BACK to C&C servers too!)
APK
P.S.=> LMAO: "Bouldin's GOLDEN top 10 'greatest hits'" (fails vs. me) - & you're a "security-engineer"after the above? LOL, not... apk
The next time an Apple-head tells you that their walled garden is there to protect the user and improved their experience and make the device more dependable just laugh in their face.
The resolution to the problem, until Apple comes up with a fix, is to turn off Preview and Banners in Messages,
Go to Settings > Notifications > Messages
set "Alert Style" to "none' and turn off the switch for "Show Previews".
This will prevent the malicious text from being sent to the screen, which then fails to be able to complete the subroutine, causing a respring that then causes the iPhone to reboot and occasionally crash Messages.
You will still know when you are getting an incoming text from the "ding" [or what ever other noise you have assigned it} and the icon badge showing a new text message has come in... you just won't see a preview of it.
When Apple gets the fix distributed you can turn the setting back on.
"Nobody uses hosts files for security" - by bouldin (828821) on Thursday May 21, 2015 @05:53PM (#49746865)
FROM -> http://it.slashdot.org/comment...
SpyBot S&D does dimwit
(you FAIL #1)!
Anyone can use it + see they do & MANY use that program stupid!
(you FAIL #2)!
---
NOD32/ESET's says hosts = valuable security http://slashdot.org/comments.p... as I also "overturned a SECURITY expert" on a "false positive" on my Hosts program RIGHT there & he gave in!
(YOU FAIL #3)!
(Had to - MalwareBytes' employees VETTED my code & even host + HIGHLY RECOMMEND it for me near top of -> http://hosts-file.net/?s=Downl...
---
Mr. Oliver Day of Symantec/Norton/SecurityFocus does too http://www.securityfocus.com/c...
(you FAIL #4)!
YOU ALSO TRIED TO DENY it & it's there in PLAIN Black & White with his NAME on it!
"I don't see Oliver Day of SecurityFocus on there. Weren't you going to cite him?" - by bouldin (828821) on Thursday May 21, 2015 @08:43PM (#49747763)
FROM-> http://it.slashdot.org/comment...
(you FAIL #5)!
---
WHOSE INITIALS ARE ON THIS - WINNER IN 2008 (added proof of paid for good layered security article):
http://forums.pcpitstop.com/in...
(YOU FAIL #7)!
Via the layered security/defense in depth methods my security guide extolls? I've COMPLETELY shut down your "desperation" RARE edge cases you tried too!
(You FAIL #8)!
Do YOU have *ANYTHING* like it to YOUR name/credit? No.
(YOU FAIL #9)!
---
Do you write a ware that noted security pros even seconded me on?? No.
(You FAIL #10)!
A ware that not only secures you but ALSO SPEEDS YOU UP (e.g. unlike antivirus which is not as effective anymore vs. online modern threats, mine is, stopping sources of infestation BEFORE they can get into you, & IF in you, stopping their communications BACK to C&C servers too!)
APK
P.S.=> LMAO: "Bouldin's GOLDEN top 10 'greatest hits'" (fails vs. me) - & you're a "security-engineer"after the above? LOL, not... apk
"ILLOGIC logic" + ad hominem attacks != a defense vs. http://slashdot.org/comments.p... showing your MASSIVE blunders on SECURITY Bouldin IN YOUR OWN WORDS QUOTED as UNDENIABLE PROOF thereof! as to my statement of FACT on that very account, lol!
(Man - after THAT debacle you brought on YOURSELF? Hey - there's NO WAY you can be a 'security engineer' & educated @ a GOOD school for it - lmao, no way, OR you just SUCK @ the field & are a green, wet-behind-the-ears ROOKIE NOOB... take your pick, either way? YOU FAIL!)
APK
P.S.=> You brought it on yourself vs. "The LORD of HOSTS"... apk
MalwareBytes' hpHosts Admin (MalwareBytes TOP employee) hosts & recommends it -> http://hosts-file.net/?s=Downl... & MalwareBytes = BEST antivirus http://www.av-test.org/en/news... UNDER THE SUN!
(Clue: The ,b>man's SEEN & VERIFIED 100% that my sourcecode & program ARE SAFE, even has a copy he keeps for me...)
APK Hosts File Engine 9.0++ SR-2 32/64-bit -> http://start64.com/index.php?o...
Yes - He's a GOOD man & checked it, even helping me disprove SEVERAL false positives (since he knows the major antivirus companies' guys too)
So far, the ones I've turned over "false positives" on are:
Qihoo360
EmsiSoft
ArcaVir
ESET/NOD32 (see below)
Comodo
McAfee
Sophos
* So much for "security engineers" & "experts" like Bouldin especially vs. the likes of them "going MY way", fool...
APK
P.S.=> Bouldin, are YOU senile too? YOU KNOW THIS from Aryeh Goretsky of NOD32/ESET an enterprise class widely recognized GOOD antivirus (he posts on /. too, mind you): He was one I overturned (good guy though on it & FAIR) & HE TOLD YOU "hosts are a GOOD effective defense vs. malware"!
Refresh your FAILING fail memory -> http://slashdot.org/comments.p... , dolt... lol & "EAT YOUR WORDS"...
... apk
See subject: You project you care after this http://slashdot.org/comments.p...
* The "unidentifiable ac posts" too? Please... talk about OBVIOUS that's "the best ya got" vs. "The LORD of Hosts" in myself, Bouldin...
APK
P.S.=> Once more: YOU brought all this ON YOURSELF & the Score = APK 16, Bouldin 0 since you can't prove my points on hosts wrong validly & technically AT ALL, lol... some 'security engineer' YOU are (not, no way, not after the above MESS you made of things)... apk
Completely possible to keep a phone restarting. Sending the message every 8 seconds results in a reboot loop. The only thing you can do at that point is find a place with no cell service to add the sender to the block list, or from a mac machine running continuity...
Nice job Apple, you have screwed up worse than Windows ever did. You made it possible for non-technical people to take down a system.
http://pages.telemessage.com/acton/fs/blocks/