Among the amenities that iPhone jailbreak provides to its owners, it is often noted that files can be transferred from iPhone to computer and vice versa using SSH protocol. However, it has its drawback: in hacked smartphones in which the corresponding client is installed, many users do not change the default password for accessing files from the outside. As a result, information from their phone can be accessed by any person who is more or less versed in this matter.
This flaw (combined with the carelessness of many owners of communicators) was used by a Dutch hacker, and in a very original way. Having gained access to the iPhone, he sends an SMS message to its owner, in which he informs about the penetration into the phone system and asks to go to his website and secure the smartphone. However, in order to find out how to protect a vulnerable iPhone, a person must pay a hacker €5 using the PayPal payment system. After receiving the payment, the hacker sends the owner of the smartphone an email with the information, and it turns out that all you need is to change the password to access the SSH protocol.
The Dutchman later, however, returned the money and published instructions on how to secure the phone, for free. But he informs his victims that other hackers may not be so kind and use hacked iPhones for their criminal purposes.
This situation proves that jailbreaking makes the iPhone more vulnerable to various kinds of scammers. And the way out of this situation is for the user to ensure the security of his smartphone – either by changing the standard password, or by simply refusing to hack in principle. In addition, there are programs for iPhone to disable SSH access to the phone. For example, there is such a possibility in SBSettings. In addition, it is not necessary to install an SSH client into the phone after jailbreaking, and if there is no corresponding software, then there is no access to the device from the outside.
Updated. Our reader Rodion Baskakov sent a useful link: how to change your iPhone password