We were all waiting for it and it's finally happened. The first iPhone
trojan has been discovered.
Targeting only "jailbroken" iPhones (which have been modified to allow the installation of third-party applications), this trojan masquerades as an update Erica's Utilities and is named "113 prep." Simply running the application causes no harm - it simply prints the word "shoes" to the screen. Uninstalling the application, however, removes certain files from the iPhone's /bin directory, making it impossible for various applications to function correctly.
Security research firm F-Secure, who confirmed that early user reports were indeed the result of a malicious application, hopes this serves as sobering news to iPhone users eager to jailbreak their devices.
"Hopefully this serves as a warning for those who have opened their iPhones using a security hole in the system and then installing unverified software without a second thought to what they are doing."
It's particularly interesting to note that the author of the trojan is an 11-year-old child who merely toyed with various XML files to create the malicious app. Obviously more savvy developers could exploit jailbroken iPhones to a much greater degree.
Apple is very
near to releasing an official iPhone development kit to third-party developers which will bring "authorized" third-party applications which can be installed on standard, non-jailbroken iPhone and iPod touch units.
[ via
Macworld UK ]