Apple Already fixed Comex's new exploit?

  • Thread starter Thread starter iFish
  • Start date Start date
  • Views Views 4,351
  • Replies Replies 36

iFish

Slower than a 90s modem
Member
Joined
Jul 11, 2009
Messages
4,234
Solutions
2
Reaction score
217
Trophies
3
Age
31
Location
Montreal, QC
XP
671
Country
Canada
QUOTE said:
JailbreakMe brought root to the iPhone 4-wielding masses, but also unearthed a nasty exploit in a PDF font. Thankfully for the rooted and those who never intended to root, Cupertino claims it has already patched the hole. "We're aware of the reported issue, we have already developed a fix and it will be available to customers in an upcoming software update," an Apple spokeswoman told CNET. We're not sure exactly when it will arrive, but we'd lay odds on soon -- in the meantime, don't open any PDFs you don't trust, don't do anything illegal or immoral, and hit up Comex's hack ASAP if your heart's still set on that shiny new unlock.

This exploit was just released sunday... and it's will already be fixed. i knew it was easy to patch... but.. whatever

Source
 
thank god the guys working at apple don't work for nintendo
laugh.gif
 
ball2012003 said:
QUOTE said:
in the meantime, don't open any PDFs you don't trust, don't do anything illegal or immoral
i thought jailbreaking was leagal

It is, but we all know what most people use it for, and Apple is worried about the site breaking into the firmware.
 
Jailbreaking is legal... but it still breaks Apple's EULA.
----------------
GameSoul said:
ball2012003 said:
QUOTE said:
in the meantime, don't open any PDFs you don't trust, don't do anything illegal or immoral
i thought jailbreaking was leagal

It is, but we all know what most people use it for, and Apple is worried about the site breaking into the firmware.

No? people already de-code the firmware..... that's not the problem
 
The problem is that Comex's his exploit could potentionally be used to brick iPhones all over the world just by letting them visit a scam site or a hacked website.
 
so i could make a pdf with a virus in it to kill the iphone and disguise it as something

interesting...
 
Seeing as it was a browser exploit, it must've been considerably easy to fix it.
Curious, does it work before IOS 4.0 or not? If it doesn't then those who didn't update yet are screwed.
 
RupeeClock said:
Seeing as it was a browser exploit, it must've been considerably easy to fix it.
Curious, does it work before IOS 4.0 or not? If it doesn't then those who didn't update yet are screwed.
Why would they be? They could always update to 4.0 and jailbreak.. or am I missing something here?
 
madridi4ever said:
RupeeClock said:
Seeing as it was a browser exploit, it must've been considerably easy to fix it.
Curious, does it work before IOS 4.0 or not? If it doesn't then those who didn't update yet are screwed.
Why would they be? They could always update to 4.0 and jailbreak.. or am I missing something here?
When they update, they will by-pass 4.0 and go to 4.0.1 or whatever the fix is. Updates are handled by Apple.

Unless you do the Shift-Restore in iTunes. That requires DFU mode, though.
 
wait, did they do a quiet update... ie it auto updates safari... or do they have a 4.0.2 firmware... totally dont understand... prob didnt read it propper
 
overlord00 said:
wait, did they do a quiet update... ie it auto updates safari... or do they have a 4.0.2 firmware... totally dont understand... prob didnt read it propper
No, I think it's in the next software update, like 4.0.2, like you said.
 
yeah, just read this and resolved my confusion;

QUOTE said:
On Wednesday an Apple spokeswoman said in a statement, "We're aware of this reported issue, we have already developed a fix and it will be available to customers in an upcoming software update."
 
Neko said:
The problem is that Comex's his exploit could potentionally be used to brick iPhones all over the world just by letting them visit a scam site or a hacked website.

Bricking is the least of their worries tbh. AFAIK, there is nothing they could do that couldn't be fixed by a simple restore (perhaps from DFU mode if necessary). Much worse would be if they silently installed some software to steal all your contacts and other personal information, texts, emails etc. and send them back to a remote server. Think of the havoc that would cause. And it'd probably be possible to make it that the user never even realises.


mezut360 said:
so i could make a pdf with a virus in it to kill the iphone and disguise it as something

interesting...

TBH, I doubt you could (no offence
tongue.gif
), but in theory, yeah its possible, but it would be more beneficial to a malicious hacker to steal contact info etc. to sell on.


madridi4ever said:
QUOTE(RupeeClock @ Aug 5 2010, 03:39 PM)
Seeing as it was a browser exploit, it must've been considerably easy to fix it.
Curious, does it work before IOS 4.0 or not? If it doesn't then those who didn't update yet are screwed.
Why would they be? They could always update to 4.0 and jailbreak.. or am I missing something here?

Yeah, you're right, they can just download the 4.0 IPSW and restore it in iTunes, by Shift+Clicking restore and selecting the 4.0 IPSW. DFU mode may be necessary.
 

Site & Scene News

Popular threads in this forum