25 November 2009 0 Comments

Protecting Your Jailbroken iPhone Against Duh virus & Ikee.B Worm

Advertisements

iPhoneWorm

Just got back from a two weeks vacation in India and I have leared there is a Ikee.B virus/worm running around that could turn your iPhones into botnet/zombies and has already infected thousands of iPhones users in different countries including Australia, Netherlands, Hungary, Portugal and Brazil. As per latest information shared by Mashable the malicious virus is spreading fast and also being referred as Ikee.B or Duh virus. The virus gives hacker complete access of content/information present on victim’s iPhone, it then initiates a search for other vulnerable iPhone’s on the same network to spread itself further.
The only way to protect/secure your iPhone from Ikee.B virus now is to disable SSH or change default root password of your iPhones, the virus is only effecting those jailbroked iPhones which have SSH enabled with default username/password combination, so if you have a jailbroked iPhone, follow this step-by-step procedure given here to disable SSH/change default password of your iPhone.

If you are one of the unlucky ones who has already been infected or want to know if you might be a victim have a look below.

To disinfect your iPhone, you should login as root with the password ohshit and remove at least the following files:
  • /private/var/mobile/home/sshd
  • /private/var/mobile/home/cydia.tgz
  • /private/var/mobile/home/inst
  • /private/var/mobile/home/syslog
  • /private/var/mobile/home/duh

However, since the directory /private/var/mobile/home does not exist on regular, uninfected iPhones, you may as well remove the entire directory and any subdirectories. Remove the file /etc/rel while you are about it.

Advertisements

Advertisements

Leave a Reply