Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

 Change your iPhone root password, A friendly reminder from CrunchGear to a

views
     
TSkokyun
post Oct 7 2008, 07:48 PM, updated 18y ago

Enthusiast
*****
Senior Member
770 posts

Joined: Mar 2005


user posted image

QUOTE
Dear iPhone Users:

Change your iPhone root password. If you have jailbroken your iPhone, your default root password is “alpine.” This puts you at a distinct security disadvantage when connected to open networks as it allows the nefarious to browse your entire iPhone with impunity.

To change your password, first runt his perl command:

openssl passwd -crypt -salt /s [password]

Where [password] is your new password. The script will return a number of random characters followed by “.io” The characters before “.io” is your encrypted password. Here is a full How-To.

The edit the file /etc/master.passwd line that gives the information for root on the iPhone. This means you need to ssh into your iPhone and run vi. If you don’t know how to do this, restore your iPhone immediately and leave it unjailbroken until you figure out the command line.

root:[encrypted password]:0:0::0:0:System Administrator:/var/root:/bin/sh

Where [encrypted password] is the password returned above. Failure to do this will result in someone looking at your stuff.


http://www.crunchgear.com/2008/10/06/a-fri...l-iphone-users/
TeK_KeN
post Oct 7 2008, 08:12 PM

rcctl
******
Senior Member
1,540 posts

Joined: Aug 2008
From: Your Dream
oh my, really don't realize this.

alpine is a simple word to remember wink.gif
Shock
post Oct 7 2008, 09:00 PM

On my way
****
Senior Member
518 posts

Joined: Jan 2003
not necessary for me.. as i disable everything, only on when i wanted to use.
nokia2003
post Oct 7 2008, 10:00 PM

Look at all my stars!!
*******
Senior Member
5,786 posts

Joined: Nov 2007
From: VIC - The Place To Be


QUOTE(TeK_KeN @ Oct 7 2008, 08:12 PM)
oh my, really don't realize this.

alpine is a simple word to remember wink.gif
*
it is not as simple as remembering the "alpine" word my friend.


let me give you a possible scenario to illustrate this situation better.


imagine you walked into starbucks on fine day and decide to use its wifi service whilst enjoying a cup of coffee. like many of us here (and 99.999% of first generation users), our iphones are probably jailbroken and have SHH pre-installed (by your respective seller) or perhaps by yourself.


and one fine day, you have forgotten to turn off the SHH feature via bosspref or probably do not have this feature, an unscrupulous person with a laptop (using the very same timezone starbucks wifi service) decides to try his/her luck. if he/she succeeds (given the conditions above satisfied) he/she can happily accessing all the contents of your beloved iphone seamlessly.


any SHH users will obviously know this these two facts; you can still access the iphone via SHH even though you have some password coded locked apps that you have (may it be from cydia/installer or app store) and you cannot possibly tell that someone is actually lurking inside your iphone.


hence, it is important that you have the default SHH password changes (or of course opt for the boss pref method)







This post has been edited by nokia2003: Oct 7 2008, 10:05 PM
Clarencerx
post Oct 7 2008, 10:15 PM

Apple. The only perfection.
*****
Senior Member
971 posts

Joined: Nov 2005
From: Perth, Australia



hmm...then i better change.

thanks for the info bro
TSkokyun
post Oct 7 2008, 10:55 PM

Enthusiast
*****
Senior Member
770 posts

Joined: Mar 2005


QUOTE(Clarencerx @ Oct 7 2008, 10:15 PM)
hmm...then i better change.

thanks for the info bro
*
You're most welcome.

Fighteden
post Oct 8 2008, 01:09 AM

Stark Industries
*****
Senior Member
977 posts

Joined: May 2008
From: My Chair


If i turn off SSH then no one is able to view anything inside my phone right?
frozzbyte
post Oct 8 2008, 01:19 AM

Feeling butthurt lately? Like I care
*******
Senior Member
3,657 posts

Joined: May 2005
In Terminal @ PuTTY, make sure you are root i.e Frozzbyte:/ root#
If you're in mobile, it will display the $ instead of # symbol. To got to root, type "su root" (without the quotes).

type:

passwd root (example Frozzbyte:/ root# passwd root)

Change to anything you want. By this, you no need to worry about people snooping into your phone or forgot turning off SSH (btw SSH will not drain your battery if its running in the background unless your making a connection to it, so leaving it to "ON" in BossPref is ok).



Fighteden
post Oct 8 2008, 01:25 AM

Stark Industries
*****
Senior Member
977 posts

Joined: May 2008
From: My Chair


SSH is just like cmd in Windows right?
nokia2003
post Oct 8 2008, 01:46 AM

Look at all my stars!!
*******
Senior Member
5,786 posts

Joined: Nov 2007
From: VIC - The Place To Be


WHAT???!!! NO ONE IS THANKING ME FOR MY GOOD ELABORATION? shakehead.gif shakehead.gif shakehead.gif
Fighteden
post Oct 8 2008, 01:51 AM

Stark Industries
*****
Senior Member
977 posts

Joined: May 2008
From: My Chair


Ooops .. tongue.gif

Kam siah nokia2003 for the good and detail explainations ..
nokia2003
post Oct 8 2008, 02:01 AM

Look at all my stars!!
*******
Senior Member
5,786 posts

Joined: Nov 2007
From: VIC - The Place To Be


blush.gif blush.gif blush.gif
frozzbyte
post Oct 8 2008, 02:17 AM

Feeling butthurt lately? Like I care
*******
Senior Member
3,657 posts

Joined: May 2005
@Fighteden
SSH is not like cmd in Windows. PuTTY/Terminal is like cmd, SSH is just the protocol. SSH = Secure SHell
TeK_KeN
post Oct 8 2008, 02:36 AM

rcctl
******
Senior Member
1,540 posts

Joined: Aug 2008
From: Your Dream
QUOTE(nokia2003 @ Oct 7 2008, 10:00 PM)
it is not as simple as remembering the "alpine" word my friend.
let me give you a possible scenario to illustrate this situation better.
imagine you walked into starbucks on fine day and decide to use its wifi service whilst enjoying a cup of coffee. like many of us here (and 99.999% of first generation users), our iphones are probably jailbroken and have SHH pre-installed (by your respective seller) or perhaps by yourself.
and one fine day, you have forgotten to turn off the SHH feature via bosspref or probably do not have this feature, an unscrupulous person with a laptop (using the very same timezone starbucks wifi service) decides to try his/her luck. if he/she succeeds (given the conditions above satisfied) he/she can happily accessing all the contents of your beloved iphone seamlessly.
any SHH users will obviously know this these two facts; you can still access the iphone via SHH even though you have some password coded locked apps that you have (may it be from cydia/installer or app store) and you cannot possibly tell that someone is actually lurking inside your iphone.
hence, it is important that you have the default SHH password changes (or of course opt for the boss pref method)
*
ok ok I appreciate this.Thanks nokia2003 notworthy.gif
it's time to change.
Fighteden
post Oct 8 2008, 02:44 AM

Stark Industries
*****
Senior Member
977 posts

Joined: May 2008
From: My Chair


QUOTE(frozzbyte @ Oct 8 2008, 02:17 AM)
@Fighteden
SSH is not like cmd in Windows. PuTTY/Terminal is like cmd, SSH is just the protocol. SSH = Secure SHell
*
Oh .. so it's something that enabling the remote usage of terminal eh?
5w33
post Oct 8 2008, 03:12 AM

On my way
****
Senior Member
638 posts

Joined: Apr 2007
From: Johor Bahru


So after all, it doesn't matter if I haven't JB my iphone right?
tinkerbel
post Oct 8 2008, 06:34 AM

Fanaddict!
Group Icon
VIP
13,495 posts

Joined: Dec 2006
From: KL, Malaysia


Adding onto 5w33's question; is there a even a 'default' password for non jailbreaked iPhones?! *grins*

I tried AirSharing once but I've never tried connecting to my iPhone 'remotely' via my laptop.

Damn.... I'm seriously under-utilising my iPhone 3G!

@kokyun,
That picture U posted... *heart breaking*!
wilsoncvt
post Oct 9 2008, 08:24 PM

Casual
***
Junior Member
341 posts

Joined: May 2006


I'll add this for the Windows users:
(This is assuming you're working with openSSH on your iPhone and thus already have Cydia installed.)

1. Search for MobileTerminal on Cydia and install it.

2. Open "Terminal" (look for the icon) on your iPhone.

3. You will see a DOS like console. Go ahead and type in "su root" and tap on return.

4. Now type in the default password "alpine" and tap on return. Note that the text will be masked so you should still tap on return although you don't see any text forming as you type.

5. On the next line, type in "passwd" and tap on return.

6. Ok, now you need to type in a new password and again tap on return.

7. Type in your new password again for verification and tap on return. And you're done! Simply type in "clear" if you want to clean up your terminal screen.

Check to see whether your password works by connecting using your pc. I am using WinSCP myself.

This post has been edited by wilsoncvt: Oct 9 2008, 08:25 PM
gengstapo
post Oct 9 2008, 08:52 PM

Retired enthusiast
********
All Stars
10,688 posts

Joined: Jan 2005
heh, i only turn ON ssh when i need to access my phone
others than that, it always turn off

anyway, thanks for the infos
chrisf
post Oct 12 2008, 01:55 AM

Getting Started
**
Junior Member
52 posts

Joined: Feb 2007
From: Johor Bahru
good simple guide wilsoncvt! but one should not necessarily be afraid if the default password remain unchanged. because many public wireless internet has blocked certain networking features such as device to device on the local network, so the intruder might not be able to gain access to someone's else iPhone thru its WIFI connection. but it's better changed to have peace of mind.
kayent
post Oct 12 2008, 02:14 AM

Getting Started
**
Junior Member
213 posts

Joined: Aug 2007


heck...i didn't know the seriousness & dangers of it till this post came up.

Appreciate the info there TS!

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0204sec    1.04    5 queries    GZIP Disabled
Time is now: 16th December 2025 - 07:15 PM