Subscribe via RSS ... Subscribe via e-mail ... Follow me on Twitter ... Follow me on Facebook ...

newspaperDennis Fisher has the skinny on a new iPhone app that is capable of harvesting huge amounts of personal data from stock iPhones, including geolocation data, passwords, address book entries and email account information, all using just the public API.

The app, called SpyPhone, is the handiwork of Nicolas Seriot, a Swiss iPhone app developer who found a way to abuse the public iPhone API that Apple made available for application developers. Fisher reports that SpyPhone does not need any exploits or hardware attacks in order to access the iPhone’s data.

Instead, SpyPhone relies on using the iPhone’s usability and depth of features to its advantage. Once an application is on an iPhone, it has unfettered access to much of the data and settings on the device, a circumstance that SpyPhone’s developer, Nicolas Seriot, exploited.

The developer has posted the source code for SpyPhone online and gave a talk about SpyPhone’s capabilities at a security conference this week.

Original article can be found here.

3 responses to “SpyPhone app harvests personal data from stock iPhones”

  1. Xcenter says:

    So, why is this even posted here? Iphone OS API enables you to use data on the phone, but why even bother with it if you can’t ever get it on any non-jailbroken “stock” phones? If this was about a method to remote install apps on iphones, now that would be news.

  2. carrumba says:

    it’s nice to know such a thing exists. combine it with the existing iphone worms and it would attract even more attention.

    btw most of the tools here on MP do the same thing. they only collect data and nothing more. if you want to transfer the data to the drop zone you have to combine them with the SMTP dropzone thing.

  3. Wulfhart says:

    The reason for news is that it would be simple for an unethical advertising agency or spammer to slip these API calls into programs that double as spyware. It isn’t that hard to get an Iphone app into the app store. Convincing people to install is slightly harder, but look how many sales the IBeer or even the IFart apps have.

Leave a comment


But please respect the commenting rules. Critizism is appreciated and also general comments of course. If you're rude, I have to delete your comment. Also use your personal/nick name but avoid using business names. Have fun and thanks for participating the discussion.