iPhone backdoor app warning (1 Viewer)

MacDara

Well-Known Member
Contributor
Joined
Mar 15, 2011
Messages
2,013
Location
Dundalk via Dublin
Website
macdaraconroy.com
So if anyone here follows me on Twitter, you'd know that someone hacked my iPhone 5S yesterday morning, or tried to anyway. They were able to play a video (I don't remember what, it woke me up, no idea what app either, there was nothing in YouTube or the Videos app) and I could see them right there on the screen accessing a few apps, activating the keyboard - and if that wasn't scary enough, trying to get into 1Password, so they knew what they were doing.

This happened just after 8am yesterday, and I regained control around 25 past (after trying to turn off the phone, I got to the screen with the 'swipe to turn off' bit but it wouldn't swipe). Believing they'd got my Apple ID or iCloud somehow to get in, I was able to reset my password on my laptop (connected via iCloud for bookmark syncing, but unaffected by any of this).

Then I called Apple when the lines opened at 10am (like, the worst possible day to get hacked, right?) and they confirmed that no one had socially engineered them to get at my ID. That made sense as they weren't able to reset anything, only add weird random bookmarks and do a search in my Safari, visit random pages in Chrome, and add world clocks to my Clocks app (and use the map function in Breeze). Those are all apps that were running at the time (as in, windows open when you access the task manager). Nothing was deleted or otherwise changed, thankfully.

Apple also confirmed to me that it's impossible to gain that kind of access unless it was through an app, or app vulnerability, that let them. My iPhone is not jailbroken, every app on it was downloaded via the App Store, and the security hole could be in any one of them - but most likely, I'd say, an ad supported one (there was at least one I hadn't closed out of fully, I've removed it now).

Apple told me they'd never before heard of such a thing happening to an un-modded phone that's been in the owner's possession 24/7. So I thought it worth outlining what happened to me here, in case anyone else has had the same happen, or has any ideas of solutions or future precautions. Maybe I just got lucky (or unlucky)?
 
Aren't all iOS apps meant to be sandboxed to prevent this sort of thing happening? Could be your phone was rooted and someone's got vnc style remote access - have you been sticking it somewhere you shouldn't to charge it? Unlikely, but it could have been randomly jailbroken without you even knowing.
 
Aren't all iOS apps meant to be sandboxed to prevent this sort of thing happening? Could be your phone was rooted and someone's got vnc style remote access - have you been sticking it somewhere you shouldn't to charge it? Unlikely, but it could have been randomly jailbroken without you even knowing.

How would I ever find out? I've only ever charged it with my own cable (I did stay at a hotel last weekend, but my own cable in the socket) and I only ever access my home WiFi network when I'm not on 3G/4G.
 
If it was me I'd do a factory reset and start from scratch. What were the bookmarks they set anyway?
 
Here's a screengrab from Safari:

2014-11-02 08.31.52.png
 
The Siri Funding Bill is passed. The system goes on-line August 4th, 1997. Human decisions are removed from strategic defense. Siri begins to learn at a geometric rate. It becomes self-aware at 2:14 a.m. Eastern time, August 29th.
 

Users who are viewing this thread

Activity
So far there's no one here
Old Thread: Hello . There have been no replies in this thread for 365 days.
Content in this thread may no longer be relevant.
Perhaps it would be better to start a new thread instead.

21 Day Calendar

Lau (Unplugged)
The Sugar Club
8 Leeson Street Lower, Saint Kevin's, Dublin 2, D02 ET97, Ireland

Support thumped.com

Support thumped.com and upgrade your account

Upgrade your account now to disable all ads...

Upgrade now

Latest threads

Latest Activity

Loading…
Back
Top