Top NEWS

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, July 27, 2013

Apple Developer site hack: doubts cast on Turkish hacker's claims

Posted on 3:31 AM by Unknown

A Guardian investigation has cast doubt on claims by a UK-based
Turkish researcher that he hacked into Apple's Developer portal, which
has been offline for more than a week.

Ibrahim Balic, who describes himself as a security consultant, claimed
on Sunday that he had discovered a number of weaknesses in the site at
developer.apple.com which allowed him to grab email addresses of
registered developers.

Apple took its developer portal offline on Thursday 18 July. On Sunday
it emailed developers warning that the site had been hacked and that
some of their details might have been stolen. It has not given any
more details of how the hack was carried out.

In all, Balic said he had been able to grab the details of 100,000
people registered on the site, and that he included 73 of them in a
bug report to Apple. He claimed that he exploited a cross-site
scripting (XSS) bug in the site, and noted 13 issues in a bug report
to Apple between 16 and 20 July.

However XSS attacks generally require the attacker — which in this
case would be Balic — to "infect" a page, in this case Apple's, with a
malicious piece of Javascript or HTML which would then be used to
extract data from a visiting user. If Balic's claim is correct, he
seems to have used the XSS exploits against his own system.

Balic offered to provide proof of his hack by sharing some details of
the file with the Guardian, and provided the emails for 19 people; the
Guardian also extracted another 10 from an email Balic put on YouTube
in which he apparently showed how he hacked the site. (He has since
made the video private.)

But attempts by the Guardian two days ago to contact 29 of the group
whose details Balic claims to have acquired found that seven of the
emails bounced — because the email is no longer operational — and not
a single one of the others has responded to a request to say whether
they are registered with Apple. Nor could any of the emails or names
be discovered online — which would be unusual for any active
developer.

Many of the emails also belong to defunct services such as Freeserve,
Demon and SBC Global — which makes it unlikely that they would have
signed up as developers, as that only became possible in 2008.

Graham Cluley, an independent security consultant, commented: "Many of
the names and email addresses either don't look like they would belong
to Apple developers, or appear to have left no footprints anywhere
else on the net." Of the set of 10 emails which appeared in the video,
he said: "It's almost as though these are long-discarded ghost email
addresses from years ago or have been used by Balic in his video for
reasons best known to himself."

Balic told iMore that the user information that he showed in a video
came not from an exploit against a developer portal, but from Apple's
iAd Workbench, for targeting advertising campaigns to users. He said
that a malformed web request to those servers containing just a first
name or last name meant he could get more data — including a full
name, username and email address for those users.

He then said that he wrote a script that generated "random" users to
get more account information wherever there was a match of some sort,
and used that to acquire the user details.

Balic did not respond to a request by the Guardian to explain why the
emails he had apparently collected were defunct or apparently
inoperational.

Apple refused to comment on the method used to hack into its site. It
would not comment on whether it has called in law enforcement over the
hack, or whether it has identified any suspects.

Even if the hack was not carried out by Balic, Apple has still been
the target of a significant attack. However, standard iTunes Store and
App Store accounts belonging to non-developers have not been affected.

The increasing delay in bringing its developer portal back online may
also create problems for Apple in its preparation for the launch of
iOS 7, the updated version of its iPhone and iPad software. It
released the third beta for the software on 8 July, and has generally
aimed for a fortnightly cycle of releases. That would imply that the
fourth beta should have been released last Monday 22 July – although a
year ago there was a three-week delay, from 16 July to 6 August,
between the releases of the third and fourth betas for iOS 6, the
current iPhone software.

The company meanwhile has set up a new "system status" page, which on
Friday morning showed that only two of its 15 developer systems — for
updating apps, and reporting bugs — are online.
Copyright http://www.guardian.co.uk/
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • לא כשר? החרדים אוחזים בסמארטפון בסתר
    " גרושה, חסידת גור, ברחה לקנדה כשהיא בהיריון בחודש שמיני מעבריין נשוי ומוכר, שנולד לו בן לפני חודש". הודעה זו, שהופצה ככתבה וכלשו...
  • Jewish Billionaire Helly Nahmad In $100 Mil Russian Mob Gambling Case
                                      Helly Nahmad and his attorney, Ben Brafman    When you’re sitting at an arraignment– squeezed shoulder-to-...
  • Tennyson Jacobson, Fatally stabs home invader as he wrestles her husband
    A young woman who had just finished celebrating her first Mother's Day stabbed an intruder to death as her husband desperately grappled ...
  • NY - Jewish Couple Sued by Housing Board for Charging for Shabbat Parties
    NY - A Central Park West condo board has filed a lawsuit against a Jewish Australian couple for violating condo rules by renting out their t...
  • הקופאת במאפיית "שובע" בבני ברק לקחה מקליינט את האייפון ולא רוצה להחזיר לו אותו מפני שהוא לא כשר
    זו הקופאית שגנבה את האייפון לא יאומן עד להיכן זה מרחיק. איני יודע אם זה בא מפאנאטיות או מרשעות או מכל דחף אחר, משהו חולה בחברה החרדית, לנגוע...
  • NY - Judicial license-plate parking, traffic ticket abuse not a problem
    A state commission looking at whether judicial license plates help judges dodge parking and traffic tickets declared Wednesday there was no ...
  • Yeshiva Bochur Who Was Imprsioned In Japan Becomes a Chosson
    Mazel tov to Yaakov Yosef Grunewald , one of the bochrim who was imprisoned in Japan on becoming a chosson. His kallah is a daughter of R’ Y...
  • Monsey - Orthodox Jews to rally about the Internet at Provident Bank Park
    Rockland County, NY - Town officials are expecting thousands of ultra-Orthodox Jews at a rally scheduled for Thursday night at the Rockland ...
  • Holocaust survivor dies, leaving $40M to no one
    Holocaust survivor and New York property developer Roman Blum left no heirs, no surviving family members — and $40 million. Now, in the abs...
  • Daniel Schwartz, East Ramapo school board president resigns
    The East Ramapo Board of Education president has announced his resignation, a district official said. Daniel Schwartz , who was serving his ...

Blog Archive

  • ▼  2013 (589)
    • ▼  July (89)
      • Rihanna victorious in Topshop T-shirt court battle.
      • Egad! Could Samsung be CHEATING in Galaxy benchmar...
      • Office Mobile for Android smartphones looks great ...
      • Zimbabweans head for polls amid rigging claims.
      • Barclays Plans to Raise Up to $12 Billion in New C...
      • Manning Acquitted of Aiding the Enemy.
      • Ashes 2013: James Taylor says he is now ready to t...
      • Major label bidding war... for David Brent.
      • Barclays issues £5.8bn new shares in bid to plug £...
      • Kym Lomas keeps her head down as she arrives at wo...
      • Kym Lomas keeps her head down as she arrives at wo...
      • Close play goes against Red Sox in loss to Rays.
      • Deloitte loses MG Rover conflict-of-interest appeal.
      • Report Reveals Apple Is Working on a Cheaper, Plas...
      • JPMorgan to settle over power rigging charge.
      • 15 missing in Blue Rhino propane plant explosion i...
      • Taylor Swift The 1940s Bikini Guys HATE It, Girls ...
      • Radio Host Kidd Kraddick Died
      • Microsoft prices Xbox One controller at $60, heads...
      • Low-cost iPhone named in China Labor Watch report
      • Low-cost iPhone named in China Labor Watch report
      • 150 arrested, 105 children rescued from prostituti...
      • Cyclospora Outbreak: What You Need To Know
      • Japan Inc. Cashes In on Abenomics as Toyota to Son...
      • 2013 Gold Cup: With Win Over Honduras and Mexico L...
      • Danica McKellar, aka Winnie Cooper, Reveals Killer...
      • Rick Warren returns to pulpit after son's suicide
      • 'The Wolverine' review: Looking sharp
      • After 75 years of marriage, couple die one day apa...
      • Miami hostage standoff leaves 7 people dead
      • New Android, new Chromecast, old marketing tricks:...
      • Europe and China Agree to Settle Solar Panel Fight
      • Google Asks Glass Developers To Start Working On A...
      • -Singer-songwriter JJ Cale dead at 74 after heart ...
      • Apple Developer site hack: doubts cast on Turkish ...
      • T-Mobile Announces “Unprecedented Deal” This Summe...
      • Hacker Barnaby Jack dies in San Francisco aged 35
      • 'The Wolverine:' A Howling Good Time
      • Egypt: dozens killed in clashes between security f...
      • Lea Michele Has ‘Horrible Anxiety Attacks’ over Co...
      • Lady Gaga's Return To The VMAs: A Comeback And A C...
      • Hot posters of Poonam Pandey's Nasha
      • Aubrey Plaza talks awkward sexual scene in new mov...
      • Apple Earnings Tops Estimates on iPhone Sales, See...
      • Google takes another stab at the living room with ...
      • Google Unveils New Nexus 7
      • Prince of Wales accepts £10 from well-wisher to bu...
      • Spitzer asked about prostitutes amid Weiner scandal
      • How a terror attack backfired on Hezbollah
      • 6 Die in Egypt as Morsi Supporters Continue Protests
      • Amanda Bynes forced to undergo mental health evalu...
      • Nicki Minaj turns #throwback into #thong
      • Batman/Superman teamup movie coming in 2015
      • Judge delays hearing on Detroit bankruptcy, pensions
      • Apple Said to Buy HopStop, Pushing Deeper Into Maps
      • Google's Moto X phone coming Aug. 1?
      • Ex-Priest Seeks $450,000 From Wis. Archdiocese
      • The Hunger Games: Catching Fire
      • Ghosts beat minions as 'Conjuring' horror flick le...
      • Search widens for Ohio killer's victims
      • Stellar cast gives 'Red 2' all its color
      • GE posts small gain in profit, sees U.S. pickup
      • Stocks drop on weak tech earnings, oil
      • New photos show Boston bomb suspect's capture
      • Army: Radioactivity found in Cold War-era bunker a...
      • Suicide bomber kills 20 in Iraqi Sunni mosque
      • Microsoft Craters on the Surface
      • Apple, Google, Facebook, Microsoft, Twitter call f...
      • Nelson Mandela spends 95th birthday in hospital
      • Dell Adjourns Vote on Sale as Some Big Investors S...
      • Thousands flee wildfire in California mountains
      • IDBI Bank net dips 28% in Q1 as provisioning for b...
      • TCS logs 15.5 pc jump in June qtr Net on strong vo...
      • Reliance Communications-RCom cuts 3G data rates by...
      • Reliance Communications-RCom cuts 3G data rates by...
      • Rupee defence dented as Rs. 12,000 crore RBI bond ...
      • Emma Roberts arrested for domestic violence in Canada
      • Adam Levine Engaged-to-Victorias-secret-model
      • iPhone 6 and Samsung: Not much in common
      • Tennis star dropped by Catholic youth group after ...
      • Europe Wants More Concessions From Google
      • Bank of America reports 63% profit increase
      • Senate agrees to stop 'nuclear' option
      • Google Maps 2.0 for iOS includes iPad support, liv...
      • Google Said to Weigh Supplying TV Channels
      • Microsoft puffs cheeks, gets ready to blow whistle...
      • B37's fellow jurors in Trayvon Martin trial bash h...
      • Mandela granddaughter expresses hurt at family dis...
      • Calif. wildfire destroys 7 homes, threatens more
    • ►  May (201)
    • ►  April (299)
Powered by Blogger.

About Me

Unknown
View my complete profile