Author Archives: J. ΞPSTΞÏN

[iPhone] Baseband Downgrading Possible on 3G

We’ve recently reported that exploits can be applied to the baseband bootloader 5.8 to install any bootloader. Now a working exploit has been released via Cydia.

As we have not tested this program we strongly recommend not to try this for two reasons: first it seems this package is in violation of Apple’s copyright, as it distributes a bootloader and second the script seems to have issues. In quite a few cases downgrading did not work, although everything seems to have applied properly. Don’t use untested exploits. Sideeffects and damaged basebands might be the result.

[Virus] First Mac Zombies in iBotnet

In their latest “Virus Bulletin” Symantec employees report that obviously the first Mac OS based botnet has appeared. They call it the iBotnet. Two trojan malwares could be identified as:

  • OSX.Iservice
  • OSX.Iservice.B

Technique

The trojans aim at gaining the user password or the root password – depending on what configuration you’re running. By default the “root” account is disabled on OS X and therefore user rights are getting leveled in certain situations. When having gained the user or root password the system is compromised and gets added to the botnet.

Distribution

Both these files are getting distributed currently via peer2peer networks like bittorrent. The trojans are included in illegal copies of

  • iWork09 and
  • Adobe Photoshop CS 4

Dissemination

It is estimated that some thousand Macs are already infected.

Behaviour

There is strong revealing that the botnet already has been used for Distributed-Denial-of-Service (DDoS) attacks using a PHP script.

Conclusion

From analyzing the trojans the Symantec guys reason that there might also be other versions already in the wild, since it seems to be a kinda flexible and expandable technique. Our recommendation: get yourself a virus scanner for your Mac, asap.

[News] Pirate Bay Case: Court rules Jail Sentence

In yesterday’s court rules the four people behind the Pirate Bay BitTorrent tracker were convicted to jail sentence and to compensate about 2.8mio euros. Although this might have been a day for the media industry to party, the Pirate Bay guys already said they will definitely appeal.

One of the Pirate Bay guys – Peter Sunde – compared the trial with the Karate Kid. You lose the first fight but there will be a happy ending.

To reach the final verdict by the supreme court could take many years. In the meantime the Pirate Bay platform is still operating. The Pirate Bay guys even started a new service called iPredator, that is basically a VPN service for peer2peer users without logging anything.

For legal reasons, we cannot link those services from Germanistan. You will find them anyhow.

Watch the Pirate Bay’s press conference:

[Laptop] Prolong Life Span and Capacity of your Battery

Have you ever wondered why the rechargeable battery in your laptop is covered by a shorter warranty period than the rest of your laptop? The reason is very simple. The life span of a laptop battery is much shorter. After only one year many batteries provide half the capacity they had in the beginning.

What is the reason?

The reason is fairly simple. When having been turned off, the laptop wastes a little bit of energy of the battery. Almost for nothing. When turning on your laptop the battery gets recharged again. But even if it’s only 1% or 2% that needed to be recharged, this reloading process is counted as a whole recharging cycle. Thus after having turned on and off your laptop twice a day for a period of 365 days, the battery has undergone most likely more than 700 recharging cycles. And the more recharging cycles it has undergone the worse its capacity becomes.

What can I do about it?

Althought the performance will become worse after some time, there are certainly some things to try:

  • If you use the laptop as a desktop PC substrate: you can remove the battery
  • Reduce the amount of reloading cycles: have your battery used until it’s almost empty, then recharge

Some more hints

Remember, that Li-Ion batteries lose capacity even if they are not used at all. Some people reported losses in capacity of up to 50% in two years. So the impact of using or not using may be big or just little in your case. Anyway, it’s worth a try.

[Windows] Office 2010 to be Available as 32bit and 64bit versions

It seems like Microsoft Office is the main topic during the last few days. Office 2008 for Mac is available for trial download, while Office 2007 Ultimate for Windows is available at a special discount to german students and now ArsTechnica.com even got information about the upcoming Office 2010 (Office 14).

According to them Office 2010 will be available as 32bit and as 64bit versions. The beta testing program is rumored to begin in May 2009. Some screenshots have been leaked already.

Screenshots are courtesy of ArsTechnica.com, find more at their place…

[iPhone] Firmware 3.0 beta 3 Seeded to Devs

As of today Apple seeds firmware and SDK in version 3 beta 3. A changelist is not available. As a non-developer we strongly recommend not to install it on your iPhones.

[MacOS] Microsoft Office 2008 Available for Trial Download

Microsoft Office 2008 has been made available for trial download. The trial will cease to run after 30 days. The trial download seems to be a part of Microsoft’s strategy to address the competition with the open source freeware OpenOffice.org. Microsoft also offers Office 2007 Ultimate at a special discount offer for students in Germany as of today.

» Download Microsoft Office 2008 for Mac

[Windows] Vista and Office 2007 Special Offer for Students in Germany

As of today Microsoft allows to purchase Windows Vista Ultimate and Office 2007 Ultimate at a special discount price. The offer is restricted to students from german universities. Prices vary between 52€ (Office 2007) and 56€ (Vista Ultimate). Both products are available for immediate download only. A backup DVD is available for additional surcharge of 13€ per disk.

When registering with a valid eMail address of a german university (i.e. john.doe@fu-berlin.de) it seems it is not necessary to provide a certificate of enrollment.

» http://www.daswahreoffice.de

[Pre] Palm Pre’s Release Date

According to phonenews.com the US american carrier Sprint will be the official distributor of Palm’s new flagship “Pre”. phonenews.com is referring to internal Sprint memos that there are two possible launch dates.

If Palm can deliver enough units the launch might be on May 17th, 2009 or if not the release will be delayed until June 29th, 2009. The end of june has also been mentioned by Palm when referring to the iPhone. At the end of June, the first iPhone subscribtions will be finished and people might want to search for an alternative.

In our opinion the Pre is a very strong contender to the iPhone. Its Linux based WebOS looks also very interesting to developers and hackers. Moreover the Pre supports multi-tasking. Let’s see what the new iPhone models will feature.

[iPhone] iPhone 3G Bootloader 5.8 Compromised

George Hotz – well known to the iPhone scene as GeoHot – has put some efforts into analyzing the  behaviour of the bootloader 5.8 that is running in many iPhone 3G’s. He found the signature checking of the bootloader is buggy. By exploiting this bug we are now able to up- and downgrade the bootloader. Sadly many of nowadays iPhone 3G’s contain bootloader 5.91. which added an RSA check that GeoHot could not circumvent yet. Read his whole article here.

By the way: this seems to be the same exploit the iPhone Dev Team used and released to be able to be used for manipulating (read our news here). Anyway GeoHot did standing work again. Kudos to you, dude.