Clear iSpot gets easy web-based ‘jailbreak’

For hackers, Clear must have known that its iSpot mobile hotspot would be hard to resist — $100 for the device contract-free plus unlimited WiMAX for $25 a month is a pretty insane deal, after all, and the only catch is that they try to lock non-iOS devices out of the action. Indeed, it took mere hours for unlocks to start coming out of the woodwork, but now it’s easier than ever: the developer of one of the original iSpot hacks has circled back to create a new unlock that requires nothing more than a couple link clicks while you’re on a machine connected to the hotspot. How is that possible? Turns out there’s a vulnerability that makes it possible to execute arbitrary commands on the iSpot through web code, and Clear hasn’t yet updated the firmware to patch it. On that note, the developer tells us that there are actually some iPads that aren’t able to connect to the iSpot without the hack, ostensibly because Apple is using some MAC addresses that the iSpot’s current firmware isn’t expecting — so ironically, you might need this “jailbreak” just to use the thing the way Clear intended. As always with these sorts of things, proceed with caution — we don’t have an iSpot lying around to try this ourselves, so let us know how it goes.

Clear iSpot gets easy web-based ‘jailbreak’ originally appeared on Engadget on Mon, 13 Dec 2010 13:46:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceiSpot Unrestricted, seclists.org  | Email this | Comments

Apple mysteriously kills jailbreak detection API while hacker boosts iOS security, irony restored

It’s no secret that Apple’s been keen to monitor the lot of naughty jailbreakers, but it turns out the company has recently shelved iOS 4.0’s jailbreak detection API with no explanation given. While this has little effect on the average user, Network World explains that this is bad news for enterprise IT and MDM (mobile device management) vendors, who will now have one fewer channel for checking whether a user’s iOS device has been jailbroken and thus become vulnerable to attacks. That said, apparently this isn’t a huge loss for the MDM vendors, anyway; but the real question is why drop the API now? Could its presence alone be a threat? We’ll probably never know.

Fear not, though, as some folks have put jailbreaking to good use. The Register reports that come Tuesday, Stefan Esser of Sektion Eins will demonstrate a tool called antid0te, which reportedly adds ASLR (address space layout randomization) onto jailbroken iOS devices. In a nutshell, ASLR randomizes key memory locations to make it more difficult for certain attacks to locate their target data. According to the famed white hat hacker Charlie Miller, this technique is already present on Windows Phone 7 and desktop Windows since Vista, but Apple’s only dabbled with it on OS X and not on iOS. Now, this doesn’t mean that jailbroken devices will be fully safeguarded, but some protection is better than no protection, right?

[Thanks, wooba]

Apple mysteriously kills jailbreak detection API while hacker boosts iOS security, irony restored originally appeared on Engadget on Sun, 12 Dec 2010 23:59:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceNetwork World, The Register  | Email this | Comments

aTV Flash (black) now in beta, ready to equip your new Apple TV with a browser

It’s always a bit of a funny business paying for hacks, but Fire Core’s aTV Flash is a serious product and we can’t blame them for trying to make a buck off the back of it. Now the sequel, aTV Flash (black), is here in beta form, bringing a subset of the aTV Flash’s functionality to the brand new Apple TV, which runs that fancy new iOS-based 4.0 software. Most importantly, Fire Core brings a HTML5-compatible browser, but the Last.fm app and Plex Client are welcome tag alongs. “Coming soon” features include expanded media format support and networked storage support. The pre-order beta price is $20, while the final hack will retail for $30. For existing users, (black) is a free upgrade.

[Thanks, Gustavo]

aTV Flash (black) now in beta, ready to equip your new Apple TV with a browser originally appeared on Engadget on Wed, 01 Dec 2010 18:46:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceFire Core  | Email this | Comments

iPhone 3G, 3GS get iOS 4.2.1 unlock, using risky ultrasn0w workaround

Can’t wait another minute for your iPhone 3G or iPhone 3GS to be carrier-unlocked once more? If and only if you’re already running the latest firmware, you can actually pilfer a bit of iPad code to pick the requisite locks — though there are some serious risks in doing so. The iPhone Dev Team has a new version of PwnageTool that uses the 6.15.00 baseband from iPad firmware 3.2.2, which just so happens to run perfectly on the iPhone 3G and 3GS since both phones and tablets of that era use the same Infineon radio chip. If you know your way around an IPSW and regularly bench-press SHSH blobs, you can download all the software you need right now — but if you don’t, you might want to steer clear of the proceedings for the time being. We spoke about risks a moment ago, and in this case there are quite a few — like the inability to downgrade from baseband 6.15 or ever do a full restore unless Apple relations improve, and it’s fairly likely that Cupertino won’t look kindly on your warranty if they find you running iPad software. Them’s the breaks, kid.

iPhone 3G, 3GS get iOS 4.2.1 unlock, using risky ultrasn0w workaround originally appeared on Engadget on Sun, 28 Nov 2010 17:41:00 EDT. Please see our terms for use of feeds.

Permalink @MuscleNerd (Twitter)  |  sourceDev-Team Blog  | Email this | Comments

Microsoft: we figured people would hack Windows Phone 7, would suggest that they don’t

Hot on the heels of the release of a utility for bypassing the Windows Marketplace and sideloading your own apps, Microsoft has released a brief statement on the state of the Windows Phone 7 hacking community… and we wouldn’t exactly say they’re too worked up about it:

“We anticipated that people would attempt to unlock the phones and explore the underlying operating system. We encourage people to use their Windows Phone as supplied by the manufacturer to ensure the best possible user experience. Attempting to unlock a device could void the warranty, disable phone functionality, interrupt access to Windows Phone 7 services or render the phone permanently unusable.”

So yeah, we’d say this is more or less a boilerplate quote: “we figured you’d hack this thing, we’d prefer it if you didn’t, and here’s a laundry list of things that could (but probably won’t) happen if you fail to heed our meek warning.” Over the long term, we wouldn’t be surprised if Redmond ended up playing an Apple-style cat-and-mouse game with these folks, breaking hacks with firmware updates only to have them re-hacked within a few days’ time. Considering the lack of spitfire in the statement here, we don’t see them coming down too hard unless legitimate, card-carrying, fee-paying developers throw a fit — and granted, ChevronWP7 could be a step on the road to piracy, so that could very well happen.

Microsoft: we figured people would hack Windows Phone 7, would suggest that they don’t originally appeared on Engadget on Fri, 26 Nov 2010 16:49:00 EDT. Please see our terms for use of feeds.

Permalink Electronista  |  sourceWinRumors  | Email this | Comments

AirVideoEnabler hack brings AirPlay video to the rest of your apps

Apple’s new AirPlay video streaming functionality is great… unless you want to use it in a non-Apple app. For whatever reason, Apple is restricting AirPlay video to just its first party apps right now, and not even all of those (Safari is left out, for instance). Interestingly, Apple actually built the functionality in, it’s just not enabled. Thanks to some “spelunking” work by TUAW’s Erica Sadun, it was discovered that a single line of code is all that’s necessary to spread the feature to any app that relies on Apple’s MediaPlayer framework, including VLC, AirVideo, and even Safari. Now Zone-MR has built a hack called AirVideoEnabler and put it on Cydia, allowing you to bring this functionality to your own jailbroken iPad. For the hack-averse, let’s hope Apple catches up in functionality soon. Check out a video of AirVideoEnabler and Erica’s original hack in action after the break.

AirVideoEnabler hack brings AirPlay video to the rest of your apps originally appeared on Engadget on Fri, 26 Nov 2010 15:40:00 EDT. Please see our terms for use of feeds.

Permalink   |  source9 to 5 Mac, TUAW  | Email this | Comments

OpenVizsla hopes to bring USB sniffing to the everyhacker

Remember that Kinect hack how-to? A key figure in the story was the use of a USB analyzer that was plugged in-between the Kinect and the Xbox to pick up on USB traffic and pull out a log that could be used for hacking. Well, there’s a new ‘OpenVizsla’ project on KickStarter that’s aiming to build open source hardware that can put this typically expensive tech ($1,400+) in the hands of more hackers, who use the hardware for anything from jailbreaking locked-down devices to building Linux drivers for hardware. The project was actually started by hackers “bushing” and “pytey,” who have worked on hacking the Wii and the iPhone, respectively. They’ve already raised a good chunk of change for the project in pledges, with backing from folks like Stephen Fry and DVD Jon helping out the momentum, and hopefully we’ll be seeing the next generation of hacks enabled by OpenVizsla and its brood before too long.

Continue reading OpenVizsla hopes to bring USB sniffing to the everyhacker

OpenVizsla hopes to bring USB sniffing to the everyhacker originally appeared on Engadget on Fri, 26 Nov 2010 13:44:00 EDT. Please see our terms for use of feeds.

Permalink Slashdot  |  sourceOpenVizsla (KickStarter)  | Email this | Comments

NoMute reclaims iPad orientation lock in iOS 4.2, but only if you jailbreak

If you’ve yet to upgrade your iPad to iOS 4.2.1, and you’re head-over-heels with your orientation lock, you’ve got two options: upgrade and lose that functionality altogether, or upgrade / jailbreak and get it back. Naturally, we’d recommend the latter. In what can only be described as “so typically Apple,” the software engineers at Cupertino figured that they’d convert the perfectly acceptable orientation lock switch into a mute switch. We lamented this fact in our review of the update, but rather than Apple creating (non-fiddly) alternatives within its software, we’re left to look for a solution in the jailbreaker’s app store. NoMute has just emerged under the BigBoss repository in Cydia, promising to reclaim the switch you’ve already become accustomed to using. It’s available now for absolutely nothing, but users are encouraged to cast a wicked glare in Steve’s direction as the download ensues.

Update: After installing the tweak and doing our own testing, we came one minor issue. Some apps decided to mute when the physical orientation (er, mute) switch is flicked on. So, when we played Angry Birds and physically locked the orientation, we lost sound. However, the sound remained when we locked our screen and tested videos on YouTube via Safari.

NoMute reclaims iPad orientation lock in iOS 4.2, but only if you jailbreak originally appeared on Engadget on Fri, 26 Nov 2010 09:27:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceDownload Squad, CoveringWeb  | Email this | Comments

iOS 4.2.1 Jailbreak hits with updated redsn0w

The Dev-Team Blog was just updated with a new redsn0w version 0.9.6b4 jailbreak (based on Geohot’s Limera1n bootrom exploit) for iOS 4.2.1. Unfortunately, iOS device owners won’t find jailbreaking as easy as navigating to a website. And the 4.2.1 jailbreak is currently “tethered” so owners of the iPhone 4, iPad, and newer iPhone 3GS and iPod touch models will have to reattach to a PC or Mac to boot into a jailbroken state each time your device loses power or needs a reboot. Those of you who rely on the ultrasn0w unlock should hold off for now — good advice for anyone not comfortable with terms like “SHSH blobs” or “Cydia.” Everyone else can hit up the link below with a detailed how-to provided by Redmond Pie.

iOS 4.2.1 Jailbreak hits with updated redsn0w originally appeared on Engadget on Tue, 23 Nov 2010 05:55:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceDev-Team Blog  | Email this | Comments

Jailbroken Apple TVs getting Last.fm and a browser, for a price

There’s something deep down inside of us that makes us want to believe Apple has some sort of app plan for Apple TV, and by “deep down inside” we mean “jailbreaking.” Fire Core, the people behind the aTV Flash software package for older Apple TVs, has just shown off its work on aTV Flash (black), a port of its hackery to the new Apple TV. Basically, aTV Flash converts your Apple TV into most of the interesting parts of the Boxee Box, and we’re particularly interested in the “Couch Surfer” browser aspect — at least as far as it can fend off encroaching jealousy for Boxee and Google TV. Unfortunately, the current version of aTV Flash costs $50, and while $50 + $100 is less than a Boxee Box, you don’t have to hack the Boxee to make it work. Hopefully Fire Core will reconsider that price by the time it launches aTV Flash (black), and in the meantime maybe some white knight hacker will get something like this working on Apple TVs gratis. Check out a video of the browser and Last.fm in action after the break.

Continue reading Jailbroken Apple TVs getting Last.fm and a browser, for a price

Jailbroken Apple TVs getting Last.fm and a browser, for a price originally appeared on Engadget on Thu, 18 Nov 2010 12:00:00 EDT. Please see our terms for use of feeds.

Permalink DVICE, 9 to 5 Mac  |  sourceFire Core  | Email this | Comments