<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tej Kohli Notes &#187; FUTURE TECH</title>
	<atom:link href="http://www.tej-kohli.com/category/future-tech/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tej-kohli.com</link>
	<description></description>
	<lastBuildDate>Fri, 23 Sep 2011 06:33:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>ALERT: An iPHONE Hacked in 20 seconds</title>
		<link>http://www.tej-kohli.com/alert-an-iphone-hacked-in-20-seconds.html</link>
		<comments>http://www.tej-kohli.com/alert-an-iphone-hacked-in-20-seconds.html#comments</comments>
		<pubDate>Tue, 06 Jul 2010 10:06:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[FUTURE TECH]]></category>
		<category><![CDATA[GADGETS]]></category>

		<guid isPermaLink="false">http://www.tej-kohli.com/?p=42</guid>
		<description><![CDATA[VANCOUVER, BC — A pair of European researchers used the spotlight of the CanSecWest Pwn2Own hacking contest here to break into a fully patched iPhone and hijack the entire SMS database, including text messages that had already been deleted.
Using an exploit against a previously unknown vulnerability, the duo — Vincenzo Iozzo and Ralf Philipp Weinmann [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-105" title="shapeimage_18" src="http://www.tej-kohli.com/images/iphone.jpg" alt="" hspace="10" vspace="10" width="189" height="126" />VANCOUVER, BC — A pair of European researchers used the spotlight of the CanSecWest Pwn2Own hacking contest here to break into a fully patched iPhone and hijack the entire SMS database, including text messages that had already been deleted.</p>
<p>Using an exploit against a previously unknown vulnerability, the duo — Vincenzo Iozzo and Ralf Philipp Weinmann — lured the target iPhone to a rigged Web site and exfiltrated the SMS database in about 20 seconds</p>
<p>The exploit crashed the iPhone’s browser session but Weinmann said that, with some additional effort, he could have a successful attack with the browser running.</p>
<p>“Basically, every page that the user visits on our [rigged] site will grab the SMS database and upload it to a server we control,” Weinmann explained.  Iozzo, who had flight problems, was not on hand to enjoy the glory of being the first to hijack an iPhone at the Pwn2Own challenge.</p>
<p>Weinmann, a 32-year-old from the University of Luxembourg, collaborated with Iozzo (a 22-year-old Italian researcher from Zynamics) on the entire process — from finding the vulnerability to writing the exploit. The entire process took about two weeks, Weinmann said.</p>
<p>Halvar Flake, a renowned security researcher who assisted with the winning exploit, said the biggest hiccup was bypassing the code-signing mitigation implemented by Apple on its flagship mobile device.</p>
<p>“This exploit doesn’t get out of the iPhone sandbox,” Flake explained, noting that an attacker can do enough damage without escaping from the sandbox.</p>
<p>“Apple has pretty good counter-measures but they are clearly not enough.  The way they implement code-signing is too lenient,” Flake added.</p>
<p>On the Zynamics blog, Flake celebrated:</p>
<p>The payload used chained return-into-libc (“return oriented programming”) on ARM to execute in spite of code signing. As far as we know, this is the first public demonstration of chainged return-into-libc on thre ARM platform.</p>
<p>In addition to hijacking the SMS database, Weinmann said the winning Pwn2Own exploit could have exfiltrated the phone contact list, the email database, photographs and iTunes music files.</p>
<p>In the iPhone sandbox, Weinmann said there’s a non-root user called ‘mobile’ with certain user privileges.  “With this exploit, I can do anything that ‘mobile’ can do.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tej-kohli.com/alert-an-iphone-hacked-in-20-seconds.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Future Technology Predictions</title>
		<link>http://www.tej-kohli.com/future-technology-predictions.html</link>
		<comments>http://www.tej-kohli.com/future-technology-predictions.html#comments</comments>
		<pubDate>Tue, 06 Jul 2010 10:03:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[FUTURE TECH]]></category>

		<guid isPermaLink="false">http://www.tej-kohli.com/?p=40</guid>
		<description><![CDATA[
How far will technology advance in 20, 30, even 50 years from now? How will future technology affect society?
Here are some scenarios predicted by science fiction writers, futurists, technology experts and you. A wide away of topics are covered, including extended lifespans, robotic innovations, medical advancements. Of course, computers are involved. The folks at Future [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-105" title="shapeimage_18" src="http://www.tej-kohli.com/images/shapeimage_18.png" alt="" hspace="10" vspace="10" width="189" height="126" /></p>
<p>How far will technology advance in 20, 30, even 50 years from now? How will future technology affect society?</p>
<p>Here are some scenarios predicted by science fiction writers, futurists, technology experts and you. A wide away of topics are covered, including extended lifespans, robotic innovations, medical advancements. Of course, computers are involved. The folks at Future For All realize some interesting truths.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tej-kohli.com/future-technology-predictions.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

