November 9th, 2009 by ahoog                              

First iPhone worm discovered – ikee changes wallpaper to Rick Astley photo | Graham Cluley’s blog

With 10′s of millions of iPhone, rife with personal data and always connected to the Internet, it will be (is) an irresistible target for malware, spyware, identity thieves and more (you get the idea):

Apple iPhone owners in Australia have reported that their smartphones have been infected by a worm that has changed their wallpaper to [...]

  • Share/Bookmark
November 9th, 2009 by ahoog                               1 comment

Backdoor in top iPhone games stole user data, suit claims • The Register

As more and more consumers use smart phones and the thousands of apps in the various market places, I am very concerned about an increase in identity theft, spyware, malware, etc.  I understand Apple’s code review process is rigorous but as with any highly competitive market, everything happens fast.  Will Apple, Google and others do [...]

  • Share/Bookmark
July 30th, 2009 by ahoog                              

iPhone SMS exploit makes all iPhone vulnerable to complete takeover

Details of the SMS exploit for the iPhone will be released today at the Black Hat conference.  Apparently, Apple was notified 1 month ago but no word yet.  Android was also vulnerable but had been patched but apparently Windows Mobile is still vulnerable.

There will be a paradigm shift in the near future as people realize [...]

  • Share/Bookmark
February 6th, 2009 by ahoog                              

3rd party web browsers allowed in App Store

It looks like Apple is going to start approving 3rd party web browsers in the App Store. Today when performing a forensic acquisition of an iPhone, you basically only have worry about one browser. So, this development is probably good for the users but will begin to add more complexity to the forensic analysis of [...]

  • Share/Bookmark
February 6th, 2009 by ahoog                               2 comments - ()

Trojan in pirated version of iWorks '09

The other day, a friend new to Mac told me they did not need anti-virus on the Mac since there are no viruses. Well, not exactly true. Anyway, for those that try to get a pirated copy of iWorks ’09 instead of just paying the $79 to upgrade, they may get something extra.

(Note: while a [...]

  • Share/Bookmark
February 6th, 2009 by ahoog                              

New iPhone firmware 2.2.1 (5H11A) released

Apple released the latest version of iPhone firmware yesterday. 2.2.1 does not appear to contain major updates but seems to cause problems with previously jailbroken phones. ZDNet Blog has a nice entry describing the update, lamenting the lack of progress in key areas (i.e. cut and paste) and makes a good point that if the [...]

  • Share/Bookmark
January 3rd, 2009 by ahoog                               1 comment - ()

How to mount a .dmg file (Mac Disk Image) in Linux

Doing Mac/iPhone forensics, you will eventually need to examine the contents of a disk image which Apple stores in a .dmg file. Here’s some information on the files and how you can mount them.

.dmg file information

The two types of .dmg files I have come across are a uncompressed file and a compressed one. [...]

  • Share/Bookmark
January 2nd, 2009 by ahoog                              

How to mount Mac OS X hsf+ partition (rw) in Linux

Update: Posted follow up article to mount HFS+ dd images

The first time I tried to mount a Mac OS X partition in Linux, I ran into several issues. Here were the problems I had and the resolution.

HFS+ partition structure

Man computer forensic jobs are on Windows or even Linux computer which use the [...]

  • Share/Bookmark