The iOS 4.3.1 update released yesterday does not fix the Pwn2Own exploit discovered by Charlie Miller.
iOS 4.3.1 does not fix the pwn2own bug. It's weird they fixed it in the next os x update after the contest, but not the next iPhone update.
More time for the bad guys to get their bindiff->iPhone exploit workflow going.
The attack simply required that the target iPhone surfs to a rigged web site. On first attempt at the drive-by exploit, the iPhone browser crashed but once it was relaunched, Miller was able to hijack the entire address book.
It's unclear why Apple didn't fix the widely publicized exploit.
i just found out about this https://www.iclarified.com/entries/index.php?caid=1&scid=25
but i don't know if that works, and i don't want do anything that can damage my new ipad2
do you think that is legit.?
Charlie Miller is awesome! This dude finds the weirdest exploits and doesn't take advantage of them like everyone else would. Props to you Charlie Miller!
This exploit never worked on 4.3 and still doesn't. Charlie Miller needs to work around ASLR (which is designed specifically to make this kind of attack difficult) or he needs to STFU.
"It's unclear why Apple didn't fix the widely publicized exploit.' maybe because no one will deliver the solution.. maybe apple is more worried about other things instead worried about some hackers that will not deliver it... Why finding exploits, that will never be used or distributed...