Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

Sunday, July 20, 2008

Upgrade your iPod touch to 2.0 for Free

The iPhone Software 2.0 update is free for iPhone users, but is $10 for those who have iPod touch. I found out you can get it for free.


Upgrade your iPod Touch to 2.0 for Free
Apple released their newest software update for both iPhone and iPod touch just about a week ago, July 11. It includes bug fixes and the anticipated App Store, which allows you to purchase and download third-party applications right to your iPhone or iPod. The update is free for iPhone users, but is $10 for those who own an iPod touch.

But I recently came across this method of upgrading your iPod to the latest version of the software (firmware, too). It involves tricking iTunes into restoring your iPod to software 2.0. However, it also involves wiping out your music and video collection in your iPod. Hence, the word 'restoring' your iPod. If you don't mind this, or if you have complete backup of your music collection in your PC, then this won't be an issue for you.

For this to work, you need a legitimate iPod Software 2.0 Restore file. Back in July 11 or 12, a link that directly points to an unrestricted Apple Phobos site leaked on the internet. A backdoor to the Apple Software server was available, which allowed the free download (and fast, too, as the file sharing sites give you a measly 5 kbps download rate) of the restore file. However, it's now currenly patched (as well as the link I used to get the file) and locked, and the only way to get the software restore file, iPod1,1_2.0_5A347_Restore.ipsw, is through torrents or file sharing sites. I got one from the Apple server itself, so I'm sure it's legit. I'm not so sure about those circulating in torrents and file sharing sites.

When you plug in your iPod, the little iPod window appears in iTunes. That's where the device info is shown - the iPod model, how much space it has, and how your music, videos, and photos take up that space, shown as a bar at the bottom. You'll also see two buttons - the Check for Updates and the Restore button. We're interested in the Restore button, since the Check for Update only prompts us to buy the update. We don't. We want it free!

If you hold Shift on your keyboard while clicking on Restore, a little window will appear that allows you to select which Restore file iTunes will use to restore your iPod to. Get it now? By selecting the Software 2.0 version (iPod1,1_2.0_5A347_Restore.ipsw) as a restore file, iTunes inadvertently updated your firmware version to version 2.0.

It will take a long time to prep your iPod for the restore, so be patient. There won't be any disk activity or CPU usage for that matter - just a window telling you that it's preparing your iPod for restore. Be patient.

After that, the restore (or upgrade) will happen - your iPod will reboot, and an Apple logo with a spinning throbber will appear. Wait until it's finished, and your done!

Reboot your iPod, and viola! An App Store icon right on the Home screen! Check the firmware version by going to Settings > General > About. Mine says Version 2.0 (5A347). It's only a matter of restoring your music and video files back to the iPod (as well as a restore from a backup) and you're good to go.

If you have an iTunes account, you can now purchase or download free applications for your iPod touch. Just go to the iTunes Store and download those applications.

Great! I just feel bad that Apple is forcing you to buy an upgrade now. Before (think iPod mini and nano), the updates for the firmware is free. And the discrimination between the iPhone and the iPod touch (remember, the update is free for the iPhone, original and the 3G version) is just wrong. But then again, it's just $10.

Monday, March 31, 2008

Vista Hack Up for Bidding

The winner of a recent hacking contest is offering the laptop he broke into on eBay, likely with the Vista attack code intact.

Laptop With Vista Attack Code Listed on eBay

The winner of a recent hacking contest is offering the computer he broke into for sale on eBay, possibly with the Microsoft Vista attack code he used intact.

In a Monday listing, Shane Macaulay is selling the Fujitsu U810 laptop he won last Friday during the CanSecWest PWN 2 OWN contest. His listing claims that exploit code could probably still be extracted from the machine. Although he make no guarantees, he wrote, "My successfull [sic] exploitation of Vista SP1 remotely, is most likely still present."

"This laptop is a good case study for any forensics group/company/individual that wants to prove how cool they are, and a live example, not canned of what a typical incident responce sitchiation [sic] would look like."

Starting bid? $0.01.

Macaulay, a researcher with the Security Objectives consultancy, claims that his Adobe Flash exploit will affect 90 percent of computers worldwide.

He was one of two hackers to claim laptops and cash prizes for penetrating systems during last week's contest. Organizers offered Vista, Mac OS, and Linux-based laptops for the taking, along with prizes that varied from $5,000 to $20,000, depending on the difficulty of the exploit. By Friday, however, only the Linux laptop remained unbreached.

Although he listed his laptop just hours before April 1, a date that is usually met with widespread Internet pranking, Macaulay said the listing is no joke. According to him, he's simply looking to see what an unpatched exploit might fetch in the open market."I figure this is a good way to see... [what] an exploit for something that only a limited amount of people know about, is worth," he said in an e-mail interview.

"The system was delivered to me as my prize. I'm free to use it as I see fit," he added.

One hacker who knows Macaulay said that the April 1 listing is "a bit coincidental," but that he may not be worried about forfeiting the $5,000 in prize money TippingPoint paid him for his hack. "He makes good money," said Marc Maiffret, an independent security researcher, in an instant message interview. "It's all just funny to him."

If he's not playing an April Fool's joke, Macaulay may be running afoul of both the PWN 2 OWN contest rules, which prohibit disclosure of bug information prior to a patch. He may also be violating eBay's user agreement, which say that users may not "distribute viruses or any other technologies that may harm eBay, or the interests or property of eBay users."

Macaulay had some funny answers when asked about these issues.

On the eBay terms of service problem, he said that he knew "some highups," at the company and was "confident, when I speak with eBay they will grant me a waiver."

And does TippingPoint know about what he's doing? "I believe at some level," he answered. "I'm sure things might change as the word percolates to the executives. Maybe I shouldn't have sold the [TippingPoint] bag with the laptop!!"

Monday, January 14, 2008

iPhone's First Trojan

The Trojan specifically targets users that have modded their iPhone so they can install third-party applications.

First Trojan Reported for the iPhone

While not a huge risk, the first Trojan for the iPhone has been discovered. The first reports came from iPhone enthusiast site Modmyifone.com and were later confirmed by security research company F-Secure.

The Trojan specifically targets users that have modded their iPhone so they can install third-party applications. The application masks itself as an update to Erica's Utilities and is labeled as "113 prep."According to Modmyifone.com all the app does is say "shoes."

However, when uninstalled, the application removes files from the /bin directory on the iPhone, breaking valid apps like Sendfile and Erica's Utilities.The Web site hosting the application was taken offline soon after it was discovered, reports F-Secure.

"Hopefully this serves as a warning for those who have opened their iPhones using a security hole in the system and then installing unverified software without a second thought to what they are doing," said F-Secure on its Web site.F-Secure reported that it was an 11-year-old kid playing with XML files who created the Trojan. "Next time it might be someone else with more skills and with specific target," they said.

Wednesday, October 31, 2007

The Hackintosh

The spanking new version of Apple OS X, the Leopard, has been released this October 26, and already, it's been hacked to run on PCs


Leopard Hacked to Run on PCs

The newest version of Apple's OS X is not immune to hacks, as already it has been hacked to run on PCs. News that Leopard has been successfully installed on a Windows PC spread across the Internet, particularly in forums.

The OSx86 Scene forum released the instructions on how to install OS X to a Windows machine, along with the details on how to migrate from Windows to Apple new OS, without investing on new hardware. The forum also shows screenshots of the installation process.

However, not all features of Leopard is compatible with PCs. For example, the Wi Fi connection will not work. Also, don't be surprised if your sound and network is inoperable.

Apple's next move will likely be to track down and act against those who are behind the hack. This has been Apple's problem every time they release a new version of their operating system. People want their software, but not necessarily the hardware. Consumers want to be able to install any operating system they like on their machine.

Installing any Apple OS on any machine other than a licensed hardware is illegal and will violate the Apple's terms and conditions.

iPhones and iPods are also vulnerable to hacks. JailBreak Me is a hack that can be installed on an iPhone and iPod Touch to allow third-party software to be installed, as this was impossible without the hack. It also allows the user to choose other wireless carriers besides AT&T for the iPhone. Apple countered this move by releasing an update that disables any iPhones that was hacked. The update rendered the hacked phone inoperable, even if the sim card inserted was the original AT&T sim card.

Story:
Copyright 2007 Sonicsoft Corporation
All Rights Reserved