It’s hard to think of a higher-profile device than Apple’s iPhone or one that has had more attention from hackers. In 2007, hackers broke Apple’s security system by exploiting several vulnerabilities. Now, security researchers at Arbor Networks are predicting that the iPhone will be subject to “serious attack” in 2008.
The attacks, they say, will likely take the form of malware embedded in photos or video. Until its latest update, the iPhone was vulnerable to such attacks through a bug in its handling of TIFF images. Previous versions of Apple’s firmware used a version of the libtiff library that was susceptible to buffer-overflow attacks.
Security researcher and hacker HD Moore in October revealed that the TIFF exploit would allow malicious hackers access to the phone’s root level. All of the iPhone’s key applications run as root processes, Moore found, so exploiting the TIFF bug provided the ability for hackers to take control of the phone.
Enticed by the iPhone
Arbor Networks predicted that hackers will be enticed by the possibility of attacking Apple users and the opportunity to be the first to hack a new platform.
“2007 was the year of the browser exploit, the data breach, spyware, and the storm worm,” the Arbor report said. “We expect 2008 to be the year of the iPhone attack, the Chinese Hacker, P2P network spammers, and the hijacking of the Storm botnet.”
The prediction is hardly a risky one, said Andrew Storms, director of security operations for nCircle Security. “Predicting a higher rate of attacks on the iPhone is like saying there will be more people trying to hack Leopard in 2008,” he wrote in an e-mail.
“This is an obvious direction for the hacking community,” he added. “Those who hack for good or bad are always interested in the newest target and even better…