MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

Deal of the Day

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Fri, Nov 20, 2009 - 07:35 PM EST  —  AAPL: 199.92 (-0.59, -0.29%)  |  NASDAQ: 2146.04 (-10.78, -0.5%)

Worm rickrolls jail-broken iPhones
Monday, November 09, 2009 - 09:18 AM EST

"The first worm to infect the Apple iPhone has been discovered spreading 'in the wild' in Australia," BBC News reports.

"The self-propagating program changes the phone's wallpaper to a picture of 80s singer Rick Astley with the message 'ikee is never going to give you up,'" The Beeb reports. "The worm, known as ikee, only affects 'jail-broken' phones, where a user has removed Apple's protection mechanisms to allow the phone to run any software."

The Beeb reports, "Experts say the worm is not harmful but more malicious variants could follow. 'The creator of the worm has released full source code of the four existing variants of this worm,' wrote Mikko Hypponen of security firm F-secure."

Full article here.

MacDailyNews Take: Jailbreak at your own risk. Check out this video of a jailbroken iPhone being taken over by "ikee" via YouTube here.

[Thanks to MacDailyNews Reader "JMS in TX" for the heads up.]

Bookmark and Share

Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: = registered.
Unregistered users: Feedback from multiple usernames are subject to deletion. Off-topic and posts from suspected astroturfers will be removed.

Nov 09, 09 - 09:22 am Comment from: no!

Ahhh! I fell for it!

Nov 09, 09 - 09:23 am Comment from: Scott

Damn you MDN!

Nov 09, 09 - 09:24 am Comment from: Jarrettdailynews

There is always a reward. Could be a good reward or a bad reward, I always tell my kids, you will always be reward for an action.

Nov 09, 09 - 09:25 am Comment from: Jarrettdailynews

I know spelling nazi's, should be rewarded towards the end.

Nov 09, 09 - 09:29 am Comment from: ping

This is yet another example of people biting off more than they can chew.

The jailbreak as such is actually not the problem, but blindly installing the ssh daemon in the process and then letting it run with unchanged default passwords (which are never used nor even accessible in a non-jailbroken iPhone) opens a huge barn door with a blinking neon sign on top: "Rape me, please!"

One would also need to know that updating a jailbroken iPhone will reset the passwords to the universally known defaults again, so any user with a running sshd will need to keep a keen eye on the state of his or her sshd and the respective passwords in order to stay mostly safe...

Removing most of the iPhone's safety barriers is a really bad idea if you don't know very precisely what you are doing – and quite possibly even then.

So unless you really understand all the implications, please don't alter your iPhone in unsupported ways – you may live to regret it.

Stay safe!

Nov 09, 09 - 09:33 am Comment from: silverwarloc

To all the Jailbreakers:

You get what you paid for...in this case...a big worm. I hope it s long one. Welcome to the social.

Nov 09, 09 - 09:34 am Comment from: NCIceman

LOL it got me too! Fished in!

Nov 09, 09 - 09:43 am Comment from: Maul

That video should be banned under the Geneva Convention.

Nov 09, 09 - 09:46 am Comment from: Jamie

Wonder what all the people saying Apple are too closed are thinking now Rick Astley is all over their iPhones?

I think I hear a waaahmbulance coming for them all grin

iPhone 3G, not jailbroken, working fine.

Nov 09, 09 - 09:54 am Comment from: Regular Reader

You never think you can happen to you. The other people were just foolish. But then one day, just another ordinary day, and WHAM...RickRoll'd.

They say the therapy will help...

Nov 09, 09 - 09:56 am Comment from: Jerry

I still don't see any benefits to jail breaking. Except for a few customising tweaks (which apple will allow eventually anyway) whats the real benefits?

Nov 09, 09 - 10:01 am Comment from: x

These guys at F-secure are baiting lying ass dogs. I've seen this before from these asshole Finns. Baiters, trying to sell their shit software via scare tactics. Whores of the worst kind.

They go around like the whores they are saying iPhones have a worm now. They don't. If someone removes the security mechanisms they cannot claim iPhone has a worm. Only Finnish asswhores do that.

I expect this scum shit from Microsoft's fools, but I guess it has infected these Finnish whores now just the same.

Nov 09, 09 - 10:05 am Comment from: Peter North

Whoooaa x, who crawled up your shorts?

Nov 09, 09 - 10:19 am Comment from: x

@Peter North

The whore Finns at F-secure did. Hows the acting going ... though you were dead!

Nov 09, 09 - 10:37 am Comment from: TowerTone

That's odd. I've had that same picture on my screen for years....

Nov 09, 09 - 10:45 am Comment from: ping

TowerTone: That's odd. I've had that same picture on my screen for years....

Ah, patient zero...! wink

Nov 09, 09 - 10:48 am Comment from: TheConfuzed1

To those of you who say there is no benefit from jailbreaking, great; don't jailbreak.

For those of us who do see the value though, we will continue to do so.

Clearly, if the value wasn't there, we wouldn't be doing it.

You keep it though--Keep playing in Apple's sandbox, and we'll keep going to the beach.

After all, Apple will eventually (never) open this stuff up to us out of the box anyway, right?

I'm not going to extole the virtues of jailbreaking here in this post. Clearly you're not the target demographic.

Nov 09, 09 - 10:52 am Comment from: Fat Basterd

So let me get this straight.... the iPhone... jailbroken iPhones in particular... now has more malware for it than any other phone on the market? Even though jailbroken iPhones account for, what, less than 3% perhaps, of all phones in the world?

This alone should be proof enough that security by obscurity is NOT what is keeping malware off Mac OS X. Sadly, it won't be.

Nov 09, 09 - 10:55 am Comment from: tt

and I freaking lost the game!!

now is this news real?

this is just one of the reasons I havnt hacked my ipod touch yet...

Nov 09, 09 - 10:58 am Comment from: ApplePi

I've been looking for this video forever! Thanks MDN!

Nov 09, 09 - 11:00 am Comment from: Fat Basterd

@Jerry

Early on with jailbreaking, there were some considerable benefits. Access to some apps for additional functionality that didn't exist on the iPhone thanks to the non-existence of the Apps Store. Even now, there are a few apps that do things that nothing in the Apps Store can do thanks to restrictions imposed by Apple. I still jailbreak mine for a couple apps, one of which is a ringtone randomizer to cycle through my growing collection of ringtones.

Nov 09, 09 - 11:01 am Comment from: Original Shiva

Can a jail broken iPhone be restored by resetting it on iTunes?

Nov 09, 09 - 11:29 am Comment from: Gabriel

@ Fat Basterd - This worm only affects jailbroken iPhones. Non-jailbroken iPhones remain secure, despite what it may appear from attention-seeking headlines on other "news" sites.

Your comment on "security by obscurity" does indeed hold true. Jailbroken iPhones comprise a minority of all iPhones in the world, and yet they've fallen to this worm, while non-jailbroken iPhones (which comprise the vast majority) are safe. Which does indeed prove that it's the presence of vulnerabilities which result in exploits - not merely the sheer number of users.

Nov 09, 09 - 11:32 am Comment from: alansky

@Fat Basterd:

The absence of tethering on the iPhone is sorely missed by many. This particular restriction comes from AT&T;, not Apple. I would think that the desire to tether the iPhone would tempt many people to jailbreak their iPhones.

Nov 09, 09 - 12:02 pm Comment from: MacRaven

Don't mess with what Apple has created. It's that simple.

Nov 09, 09 - 12:25 pm Comment from: Buster

You buncha suckers......

Sob...I fell for it tooo...damnit

Nov 09, 09 - 12:40 pm Comment from: @ x

are you finnished?

Nov 09, 09 - 01:21 pm Comment from: Giles

My neighbor told me this morning (he's "a PC") and he's positive the worm is present on every iPhone.

Nov 09, 09 - 01:24 pm Comment from: Fat Basterd

@ alansky

That in fact would be a good reason. There are plenty of good reasons still to jailbreak the iPhone... I never disputed that. But there are fewer than there used to be early on.

Nov 09, 09 - 01:37 pm Comment from: Fat Basterd

@Gabriel

I'm well aware that this exploit only affects jailbroken iPhones, thus my qualifier "jailbroken iPhones in particular". Perhaps that wasn't worded as clearly as it could have been. *shrug* But yes.. security by obscurity is utter hogwash. If someone did things to compromise the security of their Mac OS X, like jailbreaking the iPhone without taking the simple measure of changing their root password has shown, it certainly would fall prey.

I can't wait to see if/how the Droid gets compromised due to its "openness". I would say it would totally undermine all confidence in the platform, but then all the sheeple who buy into it to begin with are probably used to that sort of thing and expect it.

Nov 09, 09 - 01:38 pm Comment from: Dave

FatBastard: "more malware for it than any other phone on the market?" Where did you pull that statistic from?

Nov 09, 09 - 01:48 pm Comment from: BlackWolf

Thanks MDN I needed a chuckle.

Nov 09, 09 - 01:56 pm Comment from: Bob L

Damn You All MDN, you got me too! Ugh!!!!!!

Nov 09, 09 - 02:13 pm Comment from: papasmack

That guy ROCKS!!!!

Nov 09, 09 - 02:14 pm Comment from: DeRS

MDN absolutely got me, thanks. wink))

Nov 09, 09 - 03:42 pm Comment from: Fat Basterd

@Dave

Out of my buttocks actually. Do you have hard numbers or anecdotal evidence to the contrary? I don't ever recall having read of any malware infecting any other cell phone in the past, though I won't discount the possibility entirely. I didn't claim it was true anyway... I asked if I "got it right". wink

Nov 09, 09 - 04:13 pm Comment from: ping

TheConfuzed1: You keep it though--Keep playing in Apple's sandbox, and we'll keep going to the beach.

That's one way to put it.

On the other hand, I appreciate not having to worry about sharks or tsunamis. And that's me being a pretty good swimmer myself, in staying with the metaphor.

But please don't come crying with your bloody stump when your appetite for risk may have outdone your capability to secure your hacked iPhone on your own.

Your competence as a Unix admin may not be as substantial as you're thinking, and the jailbreak hackers on the internet may not be as trustworthy as you've believed them to be either.

Nov 09, 09 - 05:51 pm Comment from: derekcurrie

"changes the phone's wallpaper to a picture of 80s singer Rick Astley"

Good gawd!

Just watch kids. TROLLS will infiltrate and BLAME APPLE! Like this worm has anything to do with Apple security. I can hardly wait to pound them into troll mush.

Conclusion: You jailbreak, you take responsibility.

Nov 09, 09 - 08:40 pm Comment from: Rocky

TheConfuzed1... You are clearly a Windows user with an iphone.

Any Apple people with an iphone know what the difference is besides being able to change your wall paper and squeeze more than four onto the lower dash care to comment?

Nov 10, 09 - 04:13 pm Comment from: ipp0

Worldwide turn-by-turn navigation with xGPS. Upcoming events on the lock screen. USB mass storage mode. Skype over 3G. Putting apps to the background while allowing them to keep running. Adblock for Safari. Changing settings without closing the current app. Tweets and status updates in the middle of a game.

I'm sure there are others.

Nov 12, 09 - 01:06 am Comment from: Rocky

Thanks Ipp0... The fact you can have apps running in the background makes it worth while for me. Didn't realise it was so locked down.

Nov 12, 09 - 03:38 pm Comment from: ipp0

Just be careful not to enable SSH, or at least change the default pass wink

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my info   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: