There’s been a serious iOS vulnerability uncovered recently by security research company, Skycure that you should know about.
This bug is exploited by means of just a WiFi connection and will put your iOS device into a never-ending bootloop for as long as you are in range of the malicious WiFi connection. -nice going, Apple-
“It puts the victim’s device in an unusable state for as long as the attack impacts a device. Even if victims understand that the attack comes from a Wi-Fi network, they can’t disable the Wi-Fi interface in the repeated restart state.” -Skycure
Attackers can fairly easily weaponize a WiFi network through use of a modified SSH certificate which, when your iOS device attempts to parse it, starts the bootloop.
So, the only way that iOS device owners would be able to stop the bootloop would be to get out of range of the malicios WiFi network.
How To Protect Against The No iOS Zone
Below, you’ll find the advise that the original discoveres of the vulnerability have given for avoiding the problem alltogether.
1. In general, everyone should be avoiding connecting to any suspicious “FREE” Wi-Fi network.
2. Update your iOS device to 8.1.3, as the attack is sometimes not as effective on this version.
3. If you are able to get to the WiFi settings toggle before the next crash, try to disconnect from the WiFi network or just turn your phone to airplane mode altogether.
Ultimately Apple are the ones that need to come up with a fix quickly, and as of the time of this posting, they have yet to disclose when this will be patched.
'Security_News > 해외보안소식' 카테고리의 다른 글
NSA 퀀텀 인서트 공격 탐지방법 (0) | 2015.04.26 |
---|---|
Wi-Fi SSID names could allow to crash or hack mobile devices (0) | 2015.04.24 |
美정부, 사이버 전문인력 확보에 어려움 (0) | 2015.04.23 |
IBM, 위협정보공유 플랫폼 출시 (0) | 2015.04.23 |
항공기 보안문제 트윗한 연구원 탑승금지당해 (0) | 2015.04.23 |