Security - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Cisco Small Business Advantage
  • Register for WES 2010 by February 19 and save $400.
  • up.time Easily Monitors Virtual/Physical/Cloud. Free Trial.
  • Seagate® Barracuda® drives fit every desktop need.
  • MSP Partners helps solution providers stay competitive.
  • Learn more about EnterpriseDB @ the Postgres Center
  • Earn 40-50% margins. Zenith open houses show how.
  • CDW Healthcare offers the IT solutions you need.
  • One number. One voicemail. Sprint Mobile Integration.
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily.
  • Give your customers more with LSI 6Gb/s solutions.






  • Channel Insider conferred 75 awards to vendor, distribution, solution provider and industry groups for performance excellence. Check out all the winners in the 28 Bull’s Eye Award categories.
    >> Bull’s Eye Central


     

    Hackers Unleash New iPhone Virus

    in Security


    Article Rating:starstarstarstarstar / 1
    Article Views: 1668

    Rate This Article:
    Add This Article To:
    When an iPhone user tries to access a bank website, the Duh Worm directs the browser to a look-a-like site controlled by the hackers.

    (Reuters) - Hackers have built a virus that attacks Apple Inc's iPhone by secretly taking control of the devices via their Internet connections, security experts said.

    The virus has been detected in the Netherlands and can only attack iPhones whose users have disabled some pre-installed security features, according to analysts monitoring the progress of the virus.

    The hackers are trying to use the virus to obtain passwords to banking sites, according to Graham Cluley, a researcher with anti-virus software maker Sophos. When an iPhone user tries to access a bank website, the Duh Worm directs the browser to a look-a-like site controlled by the hackers, Cluley said.

    A spokeswoman for ING Group said the Dutch banking giant discovered a criminal network that attempted to steal banking credentials via hacked iPhones. Dutch clients of ING have been targeted, but there was no indication that clients outside the Netherlands have to worry, she said.

    ING has not received any reports from clients that their credentials have been lost, but the bank was monitoring client accounts for suspicious transactions, the spokeswoman said.
    Resource Library:

    The only iPhones that are vulnerable to the Duh Worm are "jail broken" phones, where users disable key Apple security features to get around the terms of usage agreement that they are designed to enforce, analysts said.

    For example, Apple prevents users from switching service providers to unauthorized carriers and limits users to the approximately 100,000 programs that the company has vetted for installation on the device. There are thousands of unauthorized programs covering areas including Internet phone calls, WiFi access and pornography.

    "The vast majority of customers do not jailbreak their iPhones, and for good reason. These hacks not only violate the warranty, they will also cause the iPhone to become unstable and not work reliably," said Apple spokeswoman Natalie Harrison.

    Three independent security experts said that it is best for iPhone users not to jail break their devices because the security risks are greater than the benefits.

    "They're leaving their back door open. Every one else knows what the key is to open that door," Cluley said.

    The ING spokeswoman said: "People who use their iPhones in a regular way have nothing to fear."

    The case, which was widely reported by security experts on Monday, is the first in which iPhones have been recruited into a "botnet," or army of infected devices that hackers can control from a central "command and control center."

    Early this year an unknown criminal gang built a botnet with millions of PCs using a worm known as Conficker. Security researchers feared that it might wreak havoc on April 1 based on code in the worm's software, but that date passed with little fanfare.

    Since then, security researchers say that a limited number of Conficker-infected PCs have been used to spread spam, sell fake anti-virus software and perpetrate identity theft.

    Mikko Hypponen, an expert on Conficker and chief research officer for security software maker F-Secure, said that Duh could spread from the Netherlands to other countries.

    Like the authors of Conficker, the hackers who wrote Duh are motivated to spread the worm because they too are looking for a payoff from their work, he said.

    "It's clearly written to make money. That's a first on the mobile side," Hypponen said.

    To be sure, iPhones that have not been jail broken face their own security challenges. Yet so far Apple has been able to stay ahead of the hackers.

    In July the company issued a software patch to fix a critical bug uncovered by two researchers that made the device susceptible to secret attacks using the SMS system, which mobile devices use to send text messages.

    Apple shares rose 3 percent on Monday to $205.88 on the Nasdaq.

    (Additional reporting by Harro ten Wolde in Amsterdam; Editing by Phil Berlowitz and Steve Orlofsky)





    Discuss Hackers Unleash New iPhone Virus
     
    I advocate removing the hands of individuals who unleash viruses and worms on the...
    >>> Post your comment now!
     

     
     
    >>> More Security Articles          >>> More By Reuters
     



     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    How much time do you spend hunting for enterprise IT content?
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com
     
    Should You Be Using “up.time”?
    Easily Monitor Virtual, Physical, and Cloud based assets, applications and services from a unified Dashboard with up.time. Deep Monitoring across platforms and along with best-of-breed reporting. Over 700 enterprise customers in 32 countries.
    Free Trial Download Here (Virtual Appliance available)
    Managed service providers are using regulatory compliance and industry standards to win business and give customers peace of mind. Join host Larry Walsh of Ziff Davis Enterprise and his guests on Friday, February 19, 2010, at 1:00 pm ET for a discussion of “Compliance as a Service.”
    Register Today