Dutch Attacker Hijacked iPhones, Demanded Ransom
A Dutch teenager has backed away from an extortion scheme targeting Apple iPhone users. The scheme was uncovered Nov. 2 when reports surfaced that an attacker was compromising iPhones and holding them for ransom. After using port scanning and OS fingerprinting to find iPhones in T-Mobile's 3G IP range, the attacker took advantage of the default root passwords of iPhones jail-broken through OpenSSH. According to reports, the owners of the phones received a message on their screens that the attacker had control of their devices. To get it back, they were told to visit a Website, where they were told to send about $5 in euros to a PayPal account in exchange for instructions on how to remedy the situation. The message on the Website reportedly read as follows: "Your iPhone is not secure. That's the reason your visiting this page, isn't it? Well you can pay me $4,95 at my paypal account PureInfinity92@mailinator.com, and I'll mail you very easy instructions on how to secure your iPhone. You can also contact me at PureInfinity92@gmail.com In a twist of fate for victims, the attacker for what ever reason changed his or her tune and posted instructions for changing the phone's SSH password. Users who changed the default password were not subject to the attack. |

![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=2b448194-7f2c-4829-a569-2c5a647d3939)
