The iPad was the target of a brute-force attack that harvested 114,000 e-mail addresses of iPad customers. High-level execs, military personnel, and politicians were among those affected.
On Wednesday, AT&T admitted to a security hole in its web site that exposed iPad users to the breach. “This issue was escalated to the highest levels of the company and was corrected by Tuesday; and we have essentially turned off the feature that provided the e-mail addresses,” the company said.
The good news for AT&T customers, if there is any, is that it wasn’t a malicious hacker trying to steal their personal identities. Goatse Security, a nine-person hacking group, is claiming responsibility for the brute-force intrusion.
Inside the Brute-Force Attack
“Effectively the hackers found a vulnerability on AT&T’s web site which allowed them to bombard the site with requests, posing as iPad users,” explained Graham Cluley, a senior security consultant at Sophos. “By changing the code that they sent each time, they were eventually able to find some legitimate codes and get AT&T’s web site to reveal the associated e-mail address.”
Apple hasn’t publicly commented, but Cluley said the blame lies squarely on of AT&T. He’s glad to hear that the carrier has fixed the problem. As he sees it, Apple will be “annoyed” that the story received so much attention in the media. But Apple could not have prevented the hack.
Praetorian Security Group obtained a copy of the PHP script Goatse used to gather the e-mail addresses from AT&T servers. The company said the brute-force attack worked because AT&T used poorly designed software.
“There’s no hack, no infiltration, and no breach, just a really poorly designed web application that returns an e-mail address when ICC-ID is passed to it,” Praetorian said in a blog post. An ICC-ID, or Integrated Circuit Card Identifier, is a unique number assigned…