Jailbreakers Who Don’t Change SSH Password — There’s a Rickroll for That

img0122-1257646906

For iPhone Jailbreakers using SSH to access their devices — without changing the default password — getting Rickrolled by a worm may be annoying (no worse than getting held for ransom by a hacker) but it’s a sign that far more insidious and malicious attacks are possible — so change those passwords now!

Back to the Rickroll. TUAW reports:

A hacker, going by the name “ikee,” created a worm that changes the home screen background on jailbroken iPhones whose owners failed to change the default password after installing SSH.

And the new background is, of course, Rick Astley. While removal details are included in an interview with the hacker, it’s better to be safe than sorry. So, check our iMuggle’s tutorial on how to change your SSH password, and change it right away.


You might like these related TiPb stories:

23 Responses to “Jailbreakers Who Don’t Change SSH Password — There’s a Rickroll for That”

  1. Stephman Says:

    You’re just as lame as getting Rickrolled!

  2. Joe McG Says:

    Why would a developer waste their time doing this. Sad little loser…

  3. Justin Says:

    @Joe

    Why would you waste your time commenting on a “sad little loser”? Its basically just promoting security, and informing those that susceptible to fix their hole.

  4. Rob Says:

    @ Joe mcg cause it’s effing hilarious. If that happened to me, and I just suddenly had Rick Astly as my background, I would die laughing………and then immediatly change my password

  5. Ben Gillam Says:

    Congrats Pablo, your a jerk!

    On topic, this is quite scary and as JD says it would be beest if pwnagetool/redsn0w/blackrain or hell even cydia forced a password reset.

  6. Waffles Says:

    I think it’s great that the hackers currently exploiting this lack of security seem to have a great sense of humor about it. @Ben Gillam that isn’t a bad idea, Cydia would be in a great position to vocally recommend people to change their passwords. I know that while I always have my SSH off, I never changed it’s default password until the hijack was reported last week. The awareness is working!

  7. fastlane Says:

    Cool, I’ve been searching all over for a good Rick Astley wallpaper. I’m changing my password back to alpine now.

  8. Oboewan Says:

    Speaking of root passwords, I installed Ubuntu the other day using Wubi, and Wubi refuses to allow you to install without setting up a root password.

  9. BeeRad Says:

    So does this mean you guys need an anti-virus suite installed? Hehehe

  10. RON JEREMY Says:

    RON JEREMY SAYS ALL YOU QUEENS HATING ON PABLO ARE JUST JEALOUS. RON JEREMY SAYS STOP THE HATE.

  11. Michael Denney Says:

    Pretty funny if you ask me… I think it’s a good way to point out the issue without causing any real damage.

    Realistically the person could have done much more insidious things.

  12. Mange Says:

    MADNESS! Iphone sends personel information to the developers of certain apps.

    Click my name and check the full story!!!!!

  13. Joseph Says:

    Sorry for asking… What is SSH??

    TIA

  14. Joseph Says:

    Ok. Found this on tiib

    So, what’s SSH?

    The first thing you would like to know is what SSH is. SSH stands for secure shell that is commonly used in Unix/Linux environment. You can use SSH to access a remote a computer and execute commands from another machine that may be miles away. Additionally, you can use it to transfer files to the remote computer, just like FTP. I’m not going to dig deep and throw out all the technical details about SSH. But just remember, SSH is a tool that lets you access machine or devices remotely. Here, the device is your iPhone.

  15. G Says:

    Count me in as thinking it’s hilarious. But I wonder, why has it taken people so long to decide to do this crazy simple hack? Jailbreak has been around for over 2 years! Maybe it’s just certain European providers where the 3G smartphones all show up in a particular IP range accepting incoming SSH connections?

  16. icebike Says:

    One wonders if Apple isn’t silently cheering. Maybe sending money.

  17. Thor e Says:

    Wow. The iphone weaknesses keep coming out of the woodwork. I’d just avoid the thing all together. Too much suckage.

    Congrats on being the first smartphone with a virus.

  18. Greyscale Says:

    iPhone isn’t the first smartphone to have a virus, Symbian has had them ages.

  19. Therealtruth Says:

    @Thor E

    how is this an iPhone weakness? This affects people who jailbreak their devices, something apple clearly does not endorse.

  20. PhorZ Says:

    At least ikee didnt change everyones ring tone to ‘Never Gonna Give You Up’…. Now THAT would have been a horrible hack.

  21. Mark Bergman Says:

    Will changing the SSH PW impact future Jailbreaking or installation of any JB apps? Do any of these need the root PW to install? Simple tutorial and very easy to change by the way.

  22. Joffa Says:

    Ok, so i’ve been rickrolled! Not funny when it happens to you. So can anyone point me in the right direction to get this removed, I have changed my root PW and it is still there, need help pls.

  23. iPhone Apps Developer Says:

    Me pointing out that mobileterminal doesnt work on 3.1.2 serves the purpose to let others know who are running that firmware not to think there is a problem. I tried to boot up MT a dozen times and it would always crash and made the effort to find a fix to realize it doesnt work on 3.1.2.

Leave a Reply