You are currently browsing Marwan.com's articles.
A move by legislators in the US state of Maine to require brain-cancer warnings on mobile phones is expected to trigger a worldwide response, the Australian industry has said.
A Democrat state representative, Andrea Boland, wants new mobile phones to carry health warnings like those on cigarettes and is pushing ahead with the legislation despite a lack of scientific consensus.
Read more here:
http://www.watoday.com.au/digital-life/mobiles/push-for-cigarettelike-warnings-on-mobiles-20100104-lnvo.html
A presentation and paper on Reverse engineering JTAG at the 26th Chaos Communication Congress is now available to download here:
http://events.ccc.de/congress/2009/Fahrplan/track/Hacking/3670.en.html
Other Hacking and reverse engineering papers and talks from the conference can be found here:
http://events.ccc.de/congress/2009/Fahrplan/index.en.html
The hacking track is here:
http://events.ccc.de/congress/2009/Fahrplan/track/Hacking/index.en.html
More on the story here:
This report concerns the theoretical and practical issues with automatically populating mobile devices with reference test data for use as reference materials in validation of forensic tools.
It describes an application and data set developed to populate identity modules and highlights subtleties involved in the process. Intriguing results attained by recent versions of commonly-used forensic tools when used to recover the populated data are also discussed. The results indicate that reference materials can be used to identify a variety of inaccuracies that exist in present-day forensic tools.
The Paper can be downloaded in PDF format from here:
http://csrc.nist.gov/publications/nistir/ir7617/nistir-7617.pdf
More on the paper here:
http://www.testandmeasurement.com/article.mvc/NIST-Develops-Experimental-Validation-Tool-0001?VNETCOOKIE=NO
The tool itself can be downloaded from here:
http://csrc.nist.gov/groups/SNS/mobile_security/mobile_forensics_software.html
The tool is called SIMfill, and it’s a java application that populates Subscriber Identity Modules (SIMs) with reference data and can be used to assess the data recovery capabilities of forensic SIM tools. The package includes an initial set of reference data for use with SIMfill, the source and compiled code, a readme file, a user’s guide, and a video demonstration. It can be downloaded free from:
http://csrc.nist.gov/groups/SNS/mobile_security/mobile_forensics_software.html
For more information please visit:
http://www.marcotempest.com/
Created by Chris O’Shea for the BBC. The billboard is called “Hand from Above”. It is an augmented reality billboard that pokes, lifts, and squeezes bystanders.
Hand from Above from Chris O'Shea on Vimeo.
For the official website, go here:
http://www.chrisoshea.org/projects/hand-from-above/
More on Augmented reality here:
http://thomaskcarpenter.com/
http://augmented-reality.alltop.com/
CNN Coverage:
Georgia Institute of Technology Video:
More information and Paper:
http://www.cc.gatech.edu/cpl/projects/augearth/
The report features attack data from TippingPoint intrusion prevention systems protecting 6,000 organizations, vulnerability data from 9,000,000 systems compiled by Qualys, and additional analysis and tutorial by the Internet Storm Center and key SANS faculty members. Two risks dwarf all others, but organizations fail to mitigate them. The full report is found in the link below:

Palm is going to release a new mobile phone in addition to the WebOS Platform based Palm Pre. The new mobile phone will be smaller and in candy bar form as opposed to the Pre’s slider form. For complete coverage and list of differences and similarities between the Palm Pre and the Pixi, please visit The Unofficial Palm Pixi Blog:
There is little research done on the forensics for Google’s Android mobile phone platform. This presentation by Andrew Hoog covers some background information about the platform and some history of how it came about. It also provides some technical aspects of the platform. The presentation focused on the rootable RC29 firmware and manual updates of it. Their technique involves using dd or cat to perform the forensic acquisition.
The paper also mentions the forensic software that support or plan to support Android in the future and some theoretical approaches to acquire android based devices.
ViaForensics has performed extensive research and development and will soon release a book on Android Forensics. Here is the paper:
For more information, please contact Via Forensics:
http://viaforensics.com
A new tools evaluation paper is out from Via Forensics. The paper examines and rates commercial tools as well as Jonathan Zdziarski’s technique. The paper is written by Andrew Hoog and Kyle Gaffaney.
Tools covered are:
- WOLF
- Cellbrite
- Device Seizure
- MacLock Pick
- MDBackup Extract
- .XRY
- CellDEK
The paper concludes that each vendor has a unique place in the market. It also concluded that Zdziarski’s technique is the only one poviding bit-wise copy of the user data and gave it the highest score.
http://viaforensics.com/wpinstall/wp-content/uploads/2009/03/iPhone-Forensics-2009.pdf
1- Astrid: a to do list app
2- SnapPhoto Free: a camera app
3- ACast: podcast client
4-Toggle Widgets: A widget app that has five separate one-square widgets that simply turn Wi-Fi, Bluetooth, GPS, and your phone ringer on or off, and change your screen brightness with every tap.
5- Sherpa: GPS based, find what’s “Around Me” kind of app
6- Sound Manager: manages volume of sounds on your android. you can set schedules for different levels of sound. pretty neat.
7- PdaNet: tethering for the android
8- Amazon: take a picture of an item, it is mailed to Amazon and an email is sent to you back from amazon with more details on the price of the item or a similar one.
9- Astro File Manager: a serious file browser, one that can download (nearly) any file you find a URL for, pass files on your SD card along to the Gmail client for attaching, find the files that your music or movie player can’t seem to find on their own.
10- Retro Defense: a Tower-Defense-like action game with Tron-style graphics.
Link for more information from Life Hacker:
http://lifehacker.com/5331710/ten-more-neat-and-productive-android-apps/
We have successfully registered the domain name iPhoneForensic.com for future use. We will keep you posted on any developments with it.

According to a survey by the Australian Communications and Media Authority, about 75% of Australians are either “very satisfied” or “somewhat satisfied” with their telecommunications services. I was surprised to see that there wasn’t a massive difference between metropolitan and rural areas, despite rural areas having a much less options and less bandwidth as metro areas. Those users who weren’t happy largely focused on price, customer service and poor mobile reception.
Read more here:
http://www.acma.gov.au/WEB/STANDARD/pc=PC_311777
Hackers claim to have stolen all T-Mobile US’s corporate data, customer accounts and network infrastructure. More information from the Register can be found below:
Three individuals who allegedly hacked into telephone systems in the United States and abroad and sold information about the compromised telephone systems to Pakistani nationals residing in Italy. Italian law enforcement arrested the financiers of the hacking activity. Those financiers allegedly used the information to transmit over 12 million minutes of telephone calls valued at more than $55 million over the hacked networks of victim corporations in the United States alone. Read more below:
http://www.net-security.org/secworld.php?id=7645
Here is an article about the security of the newly released iPhone 3.0 software for both iPhone 3G and iPhone 3G S:
http://www.net-security.org/secworld.php?id=7647

oFono is a Linux-based mobile OS for GSM handsets. The project combines people from both Intel’s Moblin initiative and Nokia’s Maemo project. It sounds like something big is in the works
Medialets created the world’s first shakable advertisement for Dockers, together with agencies OMD and Razorfish. Users shake their iPhone to make the Dockers guy dance. This ad utilizes the iPhone’s accelerometer as well as audio capabilities and appears in targeted, free iPhone applications.
A research team from Ben Gurion University in Beer-Sheba, Israel, found that talking on a cellular phone harms the mental abilities of the user.
The influence of cellular phones on brain functions and general health has been widely researched in recent years. Most of the experiments try to understand whether electromagnetic radiation is cancerous or not. Researchers from Ben Gurion University and Soreq Research Center for Nuclear Energy have decided to take a closer look at the effect mobile phones have on people’s cognitive functions.
Read more here:
http://thefutureofthings.com/pod/7033/cell-phone-usage-damages-memory.html
The research team, which included Edith Cowan University of Australia and BT, revealed some early results yesterday in news reports by the BBC and British television affiliates.
To read more about the research go here:
http://news.bbc.co.uk/2/hi/uk_news/wales/8036324.stm
and here:
http://www.darkreading.com/security/storage/showArticle.jhtml?articleID=217400054&cid=nl_DR_DAILY_H
A forensics toolkit for the Xbox gaming console is described by US researchers in the International Journal of Electronic Security and Digital Forensics. The toolkit could allow law enforcement agencies to scour the inbuilt hard disk of such devices and find illicit hidden materials easily.
Link:
http://www.sciencedaily.com/releases/2009/04/090430101445.htm

Having a rooted phone means you can do tricks like setting up a 3g/wifi bridge. The process starts by using a rooting app to revert the phone to the rc29 build. then using the “android stupidly executes everything you type” exploit to launch telnetd and upgrade the bootloader. After that, the upgrade process is fairly easy. Just flash a new baseband and build. once you’ve got your new custom firmware, you can do future updates using an app from the android market.
Read More here:
You might know some of them but most of them are just an inside code and some can raise red flags.
Here are some of them:
D46 - “Do you want to have sex?”
LG6 - “Let’s have sex”
GNOC - “Get naked on camera”
TDTM - “Talk dirty to me”
LMIRL - “Let’s meet in real life”
See the link below wich includes a video:
The video talks about a couple of people who’s lives are ruled by harrasing calls and threats. They claim that their phones are tapped with special software.
Rick Mislan talks about the software and how easy it is to be placed on mobile phones.
Software such as:
- http://www.mobile-spy.com/
- http://www.world-tracker.com/
- http://www.flexispy.com/
- http://www.e-stealth.com/
- http://www.fonefunshop.co.uk/spyphone/
- http://www.thespyphone.com/allinone.html
Link to Video on YouTube:
http://www.youtube.com/watch?v=uCyKcoDaofg
Learn more here:
http://news.bbc.co.uk/2/hi/programmes/click_online/7991777.stm
It looks and functions like a Blackberry 8830 but it sure is NOT a regular Blackberry. It is locked down by NSA. I am not really sure if it is a good idea at all. NSA is installing the SecurVoice software on it for both voice and messaging as one of the ways to secure the phone. I am sure that there is a whole infrastructure that is required to run his handset services. Even considering all that, I Still believe that a mobile-phone-carrying president opens so many doors for hackers.
Can NSA and Obama get away with using a (persumably) secure mobile phone service and handset? That is the question of the day!
Read more here:
http://blog.wired.com/gadgets/2009/04/obama-to-get-ba.html

It is persumed that the phones can be modified and used in receiving SMS verification codes sent from banks:
criminals have already collected thousands of login details for online bank accounts in countries such as Germany and Holland where banks send a transaction authentication number (TAN) code by SMS to a person’s mobile phone in order to complete transactions.
Read the original post byUltraScan here:
http://www.ultrascan.nl/html/press_room.html#25.000%20Euro%20for%20your%208%20years%20old%20Nokia%201100
Read more about it here:
http://www.arabianbusiness.com/553344-hackers-pay-top-dollar-for-old-nokia-1100-handsets
and here:
http://www.dialaphone.co.uk/blog/?p=2922

Having downloaded the latest beta of the iPhone yesterday (seen above), I started using it today and when a friend of mine asked to use it to dial a phone number, all they saw was this:

I restarted the phone and I got the proper dial screen shown below.

This happened to me again today… So I decided to post it on the inter web
Many gay and lesbian books on Amazon.com were incorrectly being flagged as adult due to a cataloging error which made the books hard to find in searches.
Twitters got angry about the issue and started a discussion called #AmazonFail. Thousands of people were angry that gay-themed books had disappeared from Amazon’s sales rankings and search algorithms. The number of Tweets on that easter sunday afternoon that had the term “AmazonFail” surpassed even those with the words “Easter” or “Jesus.”
This led Amazon.com to quickly fix the cataloging error.
Read more here:
http://www.nytimes.com/2009/04/14/technology/internet/14amazon.html?_r=1&src=twt&twt=nytimes
http://blog.seattlepi.com/amazon/archives/166384.asp?from=blog_last3
Read the discussion here:
http://search.twitter.com/search?q=%23AmazonFail
Poken is a hardware device that connects the web 2.0 social networking virtual world to your real world contacts and people you meet in conferences, coffee shops and elsewhere.
How does it work and when was it released?
It was released in March as far as I could tell. Here is how it works
Here are more links on it:
http://technology.timesonline.co.uk/tol/news/tech_and_web/article5987575.ece
http://www.guardian.co.uk/media/pda/2009/mar/17/sxswi-startups1
http://blogs.telegraph.co.uk/dan_monsieurle/blog/2009/03/30/who_am_i__a_panda_or_a_chimp
If you want to buy a poken, then use the following coupon code for a 10% discount:
PUTUPYPAJFAZTSD3PEHM
Watch the 46 minute long Google TechTalk about Poken here:
http://www.pokenpokes.com/2009/03/08/poken-extending-online-social-networking-into-the-real-world/
The hardware details are here:
http://ameblo.jp/hfo/entry-10224130228.html
and here:
http://ameblo.jp/hfo/theme-10011686327.html
A blog about pokens:
http://www.pokenpokes.com/
Blog post about the release in Japan:
http://nthambazale.com/2009/03/tokyo-cgm-night-episode-poken-launched-in-japan/
Let me know if you have any questions about Pokens
A man accused of raping a university student was cleared because of the mobile phone footage showing the woman ‘actively’ having sex with him. The jurors voted to acquit the man, who’d been charged with four counts of rape, including two of rape by oral penetration.
Read more here:
http://www.dailymail.co.uk/news/article-1166466/Man-cleared-rape-court-shown-phone-footage-woman-actively-taking-sex.html
It might not be because they are secure, but simply because the ROI is just a mere phone handset! Add to that the device, OS, and carrier variations.
Read more here:
http://mobile.slashdot.org/article.pl?sid=09/03/25/1238246&from=rss
and here:
http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=Mobile+and+Wireless&articleId=9130346&taxonomyId=15&pageNumber=1
Chris Ogle (29) from Whangerei, New Zealand has stumbled across the sensitive military details of U.S. military personnel after purchasing a secondhand MP3 player in Oklahoma, USA. He discovered around 60 sensitive military files dating from 2005 on the used music player. The files were clearly marked as ’secret’ and contained the phone numbers of numerous soldiers serving in Afghanistan and Iraq.
For more on the story visit:

Growth projection for the mobile sector does not look good
Read More Here:
http://www.iphonestalk.com/new-survey-results-bring-good-and-bad-news-for-the-mobile-sector/
We acquired the domain names AndroidForensics.com and AndroidHack.com . Both domain names should take you to MySecured.com for now. We might dedicate the Android Forensics domain in the future to a website catering specifically to the Forensics of Android-Based Cellular Phones. The Android Hack domain name will be probably dedicated to the Hacks and Mods for the Android Based mobile phones and other devices such as netbooks and laptops.
Try the domain names now:
http://www.androidforensics.com
http://www.androidhack.com
An interesting article about pedophilia and ’sexting’ in the mobile age. Sexting means sending nude or semi-nude pictures of oneself on mobile phones to others. Two cases are discussed in the article.
In my opinion, lawmakers should consider the changes in technology and evolve the laws to deal with the new issues emerging from the proliferation of cell phones in our societies and changes to the ways mobile phones are used.

A guy at the US Airways crash took a picture of the Airplane and used Twitter to stream it to the Internet. Here is his account of the incident:
http://twitpic.com/135xa - There’s a plane in the Hudson. I’m on the ferry going to pick up the people. Crazy. 12:36 PM Jan 15th from TwitPic
Robert Scoble aka Mr. Twitter talk to Larry Magid at CES. Robert has 48,000 people who follow him (read his Twitter posts which are called “tweets”) but he follows nearly 21,000 people. How he does that? Tweetdecks is one way! They also talk about the Palm Pre Surprise. Listen to the whole podcast here:
http://news.cnet.com/8301-19518_3-10141183-238.html
This is starting to be like citizen reporting via tweets again. This time it has help from tweet decks. Can this be the beggining of a new way for us to get news from the inside of conflicts, disaster areas and maybe even anonymous news tips? Rumors?
A new site dedicated to the Palm Pre Mobile Phone and its WebOS operating system and Application Catalog. Visit it at:
http://www.PreMobilePhone.com
I don’t know if this is true or not yet but here it goes! There seems to be a vulnerability that affects Nokia Series 60 phones, including N95 and N73 handsets that blocks all SMS and MMS from reaching the phone, hense the name “Curse of Silence”. attacker in this case sends a specially designed SMS message to the target phone. What’s worrying is that the recipient will receive no indication that they got the message.
The only way to get the target phone to recieve messages again is to factory reset it. Even after the factory recet, the phone still remains vulnerable to future silent curses. The attack will only work on phones running version 2.6, 2.8, 3.0 or 3.1 of Symbian S60.
It can be done!
An in-depth look at the new Palm Pre Mobile Phone:
I love how fast it is and how they allow you to have “pages’ of applications running at once… Look at the videos to see what I mean. What I hate is the numbers on the keyboard are Orange just like punctuation marks on the T-Mobile G1… I can’t see them at all! But that’s just me…

Related:
Plam stocks are up.
Google Finance on Palm, Inc.
Is it going to be the iPhone killer? or will it suck like the Google Android did before it? Give it six months and we’ll see
Watch in on Fora.tv to see the whole transcript as in the Pouge video in the previous post.
The video is Long (32 Minutes!).
- It starts with a parody song (as usual!).
- 3:35 Trends for 2009
- 4:30 VoIP cell phones
- 6:40 VoIP on Mobile Phones with T-Mobile (By the way BT has it too!)
- 10:40 Grand Central: A service that rings all your phone numbers at once at the same time on a single number! Watch the demo
- 12:50 Google Cellular: Free SMS and Voice initiated 411 directory enquiry service
- 16:25 1800 Cha Cha: Ask any question by voice and get answer by text
- 18:00 Voice Messagase by email or SMS services e.g. spinvox, PhoneTag and CallWave
- 21:00 More on Callwave and a feature demo
- 22:35 Popularity Dialer .com
- 23:50 iPhone beginings. How iPhone changed US carriers
- 25:00 iPhone with internet all the time
- 26:30 iPhone shuffle and App Store apps demos like: Midomi, Pandora, Urban Spoon
- 28:30 T-Mobile G1 and Verizon
- 29:30 End with a Song: The iPhone Song
Modding Education for iPhone users AKA ModEdiPhone.com is a new website for all iPhone users who would like to jailbreak their iPhones or SIM unlock them whether they are using a first generation iPhone or the 3G iPhone. It provides guides and step-by-step videos and advice on how to do each hack or mod without any complications. It includes software, firmware, and hardware mods and hacks. It also contains the last five posts from the most popular iPhone blogs and news sites. It is a must visit and subscribe-to website so make sure you add it to your favourites
Here is the link:
http://www.modediphone.com/
Attached with and armband, it is a portable and multi-purpose tool:
http://www.gizmodo.com.au/2008/12/the_us_armys_secret_weapon_the_ipod_touch-2.html
Cellphone Gun:
Pen Gun:

Windows will run soon on the iPhone using Citrix Receiver, a remote screen software that connects to a PC and enables you to run Microsoft’s Windows Apps remotely over the wi-fi or 3g network.
More info here:
http://community.citrix.com/pages/viewpage.action?pageId=51937665
Yes you can
Watch this:
Get your gadgets coated with this micro polymer here:
http://www.golden-shellback.com/
for more information go here:
http://www.electronics-au.com.au/blog/computers/apple-iphone-underwater/
A man in the United States used his mobile phone and the social networking service Twitter to inform the world even as he was trying to escape a burning 737. Read or hear more from the ABC:
http://www.abc.net.au/am/content/2008/s2453641.htm
I have previously heard of a case where a man used the twitter service to let people know he was arrested by Egyption authorities:
http://www.cnn.com/2008/TECH/04/25/twitter.buck/index.html
Both stories might be looked at as extreme uses of the twitter service or other micro-blogging and social services. As mobile phones become more location-aware, social networking services such as twitter are tapping into this capability of mobile phones making them even more usable in distress situations or even to report crime. Coupled with cameras, these services in addition to location-aware devices can become effective crime fighting tools.

As predicted, it did take a long time to unlock the 3G version of the iPhone as compared to the 1st generation iPhone. It is never the less a great achievement for the Dev-Team. So, if you are still using a SIM proxy to unlock you iPhone 3G, then this unlock is for you. For all others, this makes no difference at all
For those who do require the SIM unlock I give you this warning: never upgrade you phone to 2.2 as it will unpgrade your modem software making it impossible to unlock with the SIM unlocking solution from the dev-team.
So: NEVER UPGRADE OR RESTORE YOUR IPHONE IN ITUNES
For more information, please visit the dev-team’s website at:
http://blog.iphone-dev.org/
For more information on the harmless totally-reversable hack, go to:
http://www.engadget.com/2008/12/10/video-android-rocking-on-the-htc-touch/
Get the hack and instructions directly from xda developers here:
http://forum.xda-developers.com/showthread.php?t=382265
GadgetTrack software was used to track and arrest a thief in Anchorage, Alaska. For more details visit the site below:
http://www.usbhacks.com/2008/11/24/mobile-phone-thief-captured-with-tracking-software/
![]()
You can pre-order the Kogan Android phone AKA The “KOGAN AGORA” and “KOGAN AGORA PRO” for 299 and 399 respectively. The pro model has added features such as GPS, Camera and Wi-Fi.
SPECIFICATIONS:
Operating System
Android™
Google Mobile Functions
Google Search™, Gmail™, YouTube™, Google Maps™, Google Talk™, Google Calendar™.
Display
2.5-inch TFT-LCD flat touch-sensitive screen with 262K QVGA (320 X 240 pixel) resolution
Device Control
Central Navigation Key
Keyboard
QWERTY keyboard
Keyboard backlighting
GPS
GPS navigation capability (included with Kogan Agora Pro)
Connectivity
Bluetooth® 2.0 with Enhanced Data Rate
Wi-Fi®: IEEE 802.11b/g (included with Kogan Agora Pro)
Camera
2.0 megapixel colour camera (included with Kogan Agora Pro)
Audio
Built-in microphone and speaker
Headphone jack
Ring tone formats:
· MIDI, MP3, WMA, AAC, WAV, PCM
Video
Video formats supported:
· MPEG2 H263, H264, MPEG4, AVI
Mail attachment support
Viewable document types:
· JPEG, GIF, WBMP, MIDI, AMR, MP3, WAV
Dimensions (HxWxD)
108 mm x 64 mm x 14.8 mm
Weight
130g
Battery
Rechargeable Lithium-ion battery
Capacity: 1300 mAh
Talk Time
Up to approximately 400 minutes
Standby Time
Up to approximately 300 hours
Processor MHz
624 MHz
Memory
ROM:
256 MB
RAM:
128 MB
microSD™ card expansion slot
Network
UMTS/HSDPA (850, 1900, 2100 MHz)
GSM/EDGE (850, 900, 1800, 1900 MHz)
The official site is Here.
If you were waiting for the Arabic to be ready for the 2.2 version of the iPhone then your wait is over
it is now ready from iPhone Islam
Just go here for the guide to upgrade from 2.1 to 2.2 and then read more information about the new upgrade here.
PLEASE NOTE: If you use a SIM card proxy (a small SIM-shaped electoronic circuit that goes behind your SIM card) then NEVER upgrade your phone to 2.2! You will not be able to use your phone if you upgrade.
The iPhone user manual and user guide for the iPhone 3G and 2G is now available in Arabic as the iPhone is introduced in Egypt and will be introduced in other Arabic countries such as Qatar.
Here is the link to the pdf file:
http://manuals.info.apple.com/ar_EG/iPhone_User_Guide_ARA.pdf
You can customize the color of your T-Mobile G1, the Google Android based phone at Colorware Custom. This is the design I did with custom Metallic Paints for all colors except for the yellow which is a solid color called “Caution”:
http://www.colorwarepc.com/p-170-tmobile-g1.aspx?2081=candy_apple&2082=alpine&2083=caution&2084=midnight
BTW, the phones are unlocked which means that they can be used with any carrier and not only T-Mobile.
As far as I know, this is the first Chinese made Android based phone apart from T-Mobile G1. There is an Australian company that is planning to release their own Android Based mobile phone by xmas. The link for that is here.

It does not have a physical keyboard!
The official site:
http://mysciphone.com/G2Specia.asp
I found a phone on ebay.
According to Gartner, Through 2010, 40% of application failures will be usability-related, rather than functionality-related.Join Sybase iAnywhere’s usability and human factors expert for a complimentary webcast designed to help you conquer usability issues with building mobile applications. The webcast will provide tips and techniques to help ensure your mobile application supports and impresses your end users.
Date: Thursday, December 4, 2008
Time: 2 p.m. EST
Register now to learn how to make your mobile applications more usable. There is no cost to attend these webcasts, but registration is required.
Enterprise Mobile Applications: A Study of Strategies and Adoption Trends - Webcast.
AKA Ben Stein vs. The Man on the Street:
Geography:
It’s the two hottest touch-screen phones duking it out. Can the new kid on the block take down the champ?

Want to learn how to upgrade your Android to RC30 and get root access on it? get a step-by-step guide here:
http://modmygphone.com/wiki/index.php/Main_Page
On October 6th AccessData sent a letter to Guidance Software expressing its interest to acquire all of the outstanding stock of Guidance Software at $4.50 a Share. Read more below:
http://www.itbusinessnet.com/articles/viewarticle.jsp?id=569441
Here is a sample video of Noise Alert:
For more videos visit the website:
http://www.androidapps.com/
For Apple iPhone App reviews, visit AppVee’s iPhone website at:
http://www.appvee.com/
The iPhone will decide for you
Just shake it!

Your iPhone can not delete or forward SMS Messages? Yes it can! Use MySMS to do that!
Your iPhone can not forward a contact number to another one? Now it can! Just use MySMS
You want more options such as:
- landscape typing
- punctuation keys at the right side of typing window
- sms forwarding (even conversations)
- single / individual sms or conversation deletion
- character counter (to know if your text will be sent as one or multiple SMS messages)
- send contacts through sms
- Use message templates
- set password on app loading/launch
- Easy contact list search!
- disable auto correction in SMS typing (very useful if you are typing in other languages)
- skins (downloaded from the dev’s repo: isoftru.ru/repo/)
- set mySMS as the default SMS app
- Option to Tap return key twice to send message
For more information go to:
MySMS
and to see more screen shots and instructions on how to downlad the application from Cydia, go to:
http://iphonehelp.in/2008/11/13/mysms-ultimate-sms-app-for-the-iphone-3g-2x-via-cydia/
A good start is Google’s own documentation page:
http://code.google.com/android/documentation.html
Books are another good source for step-by-step development. One Andoid book that I read is:
ANDROID A PROGRAMMERS GUIDE (Paperback)
It guides you through installing Eclipse, Android SDK and all the different steps that lead you into developing a “Friend Finder” application.
Other books of interest that i found on Amazon include:
I love David Pogue… He gave us the iPhone Music Video when the iPhone first came out
See it again here:
http://au.youtube.com/watch?v=vniMR6Ez9cE
Just watch
A Friend of mine asked me for this as he has an X SIM II Unlocked and Jailbroken iPhone and didn’t want to risk loosing the space or jailbroken apps on his phone or un-activate his phone. He has 2.0.2 and wanted to upgrade to 2.1.
For him and for all of you out there, here is the guide:
Sleepers.net
Mobile Virtualization Platform (MVP) will enable Enterprise users who pick a phone with embedded support for virtualization to run multiple operating systems or multiple profiles — for example, one for personal use and one for work use — on the same phone.
The IT department will able to set up one profile that follows all the policies necessary to keep the enterprise secure, but at the same time end users can run anything they like on their personal profile, according to Sjöstedt.
Users will also be able to more easily move personal data and files — including applications, pictures, videos, music and e-mail — to a new device, making the upgrade to a new phone less painful.
Read More Here:

Even though Android OS is open source, it does not allow root access. Without full access to the phone’s software and hardware, a lot isn’t possible, notably video recording: “there’s no way in hell you could do video compression fully in software fully on dalvik” according to Jay Freeman the guy who jailbroke the G1 and installed Debian on it. This modification will also allow users to theme and skin the OS and Applications on it.
For more information and complete instructions and links to required downloads, please visit:
http://modmygphone.com/forums/showthread.php?t=5191
We have secured the domain name Securify.Me and we are in the process of forwarding it to MySecured.com. MySecured.com has been getting positive feedback from visitors and the financial gain from Google Ads is great. So, we are investing the money form the advertisements into buying cool domain names! Our overhead for the website is very low, so getting traffic through clever web domains has served us well so far
If the domain name sounds familiar, it is because of two parts of the domain:
- Securify: Packet Storm Security’s domain name used to be http://packetstorm.securify.com . Takes you back ages ago doesn’t it!
In fact, this is how it used to look like from 1999-2001:
http://web.archive.org/web/*/http://packetstorm.securify.com
Thanks to the Way Back Machine
- Me: It is the new Top Level domain name. It is also a previous version of Windows: Windows Me. More recently, Apple Computers used it for the replacement of the .MAC Cloud Computing service. It is now known as MobileMe or Mobile Me.
Keep visiting the websites and keep those suggestions coming
Visit our sponsors while you are at it… it is what keeps us going after all….
contribute (at) My Secured DOt Com!
BTW: If you are interested in ANY of our domains, let us know… We might just sell it to you for the right price
The founders of google missing around with the Android and writing their own applications for it. This includes an application that uses the hardware sensors on the phone. This is an invite to all geeks to hack their Android phones. It’s not like you needed an invite or anything… but it is a good thing to have nevertheless.
Fun Fact: Notice that one of them calls “Android Market” the “App Store”…! I guess one of them was using the iPhone too much

A new book with companion DVD by Jesse Varsalone. Expected retail price is AUD 79.00.
Key Features include:
- Companion DVD Contains Custom Materials That Can Be Used in a Real Digital Forensic Investigation
- Includes Unique Information about Mac OS X, iPod, iMac, and iPhone Forensic Analysis Unavailable Anywhere Else
- Authors Are Pioneering Researchers in the Field of Macintosh Forensics, with Combined Experience in Law Enforcement, Military, and Corporate Forensics
Sounds good? Then for more information go to:
http://www.elsevierdirect.com/product.jsp?isbn=9781597492973
A video file by ZiPhone Maker crashes the iPhone:
Forbes.com
Call it “on-demand computing”, “grid computing” or “software as a service”, cloud computing is the wave of the future whether people like it or not. When it comes to smartphones both iPhone and the Android platform are betting their success on cloud computing. Apple’s MobileMe and Google through its Google Apps on G1 did not get a great start but they are improving their acts with fixes and updates. Microsoft announced lately that they are getting into the cloud computing arena with cloud based servers that target both smartphones and sub-laptop devices called “netbooks”. There are too many news articles to list here to support this post and new articles on the subject seem to pop up every singe hour of the day. So, I am going to leave all the searching for cloud computing articles to you! Here is a google search for smartphone and “cloud computing” to get you started:
Intersting article involving a child porn case:
People living in Australia can get their hands on a T-Mobile G1 via eBay.com. They will be able to use the 3G HSDPA fuctionality on Carriers other than Telstra though. For 3G connectivity, the G1 will work only if the carrier’s network uses the 2100MHz frequency band. Currently those carriers include Vodafone, Optus and Three. Telstra’s Next G network runs on the 850MHz frequency so it’s not supported.
For more information, read on:
http://www.theage.com.au/news/technology/biztech/google-phone-hits-australia-via-ebay/2008/10/29/1224956120782.html
Get more information about this application and much more on Android’s Developer blog.
Also, visit Google Code Pages for Android.
Google Marketplace is where developers can easily publish and distribute their applications directly to users of Android-compatible phones including the T-Mobile G1.
In an article in The Register, Google defends limiting accress to Non-Marketplace applications to the following:
At this point, we think it is too dangerous to give a third party application blanket access to install applications without the user being involved. That may change in the future, but for now that is the way it is.
Read more about it in the article.
The first ever Android was released in the USA in November but as in the previous post here on Mysecured.com, there were no people linening up outside of shops there!… The T-Mobile G1 was released in the UK yesterday (October 30th), with about the same results as the US launch… No one seems to be interested in it so far.
The week the same still holds even after reports show that the phone has been unlocked as shown in the video below:
Is this about to change here in Australia? Well, I’ve asked around and it seems like people were holding back on buying the US version of the G1 because they though it was using different 3G bands than the ones Australian telecoms use. But they thought that UK version will use the same frequencies as the Ausie carriers but so far there are no UK version T-Mobile G1s on sale on eBay UK.
Buyers here in Australia might be more interested in buying the UK version of the G1 but for now they have no choice but to wait for some of them to be either available on eBay. There is another choice however which is to buy an proprietary Android phone from an Australian technology company Kogan Technologies which will start selling their in house Chinese manufactured Android based phones that will go on sale on December 15 for $199 AUD.
For more details on that story go to:
The Age.
In other reports, people just don’t see that the G1 is either open source nor ground breaking. Wired Magazine notes that the phone has restricted use of VOIP technology as in this article:
http://blog.wired.com/gadgets/2008/09/g1-android-phon.html
On the G1, T-Mobile customers will be the first to check out about 50 available applications. T-Mobile says that all apps are free until 2009. Here is a look at the top 15 out of those.
The one that scares me is the sex offender warning application. It tells you where your G1-carrying daughter or grandma are and how far and in which direction is the nearest registered sex offender to them!

See what I mean by watching the demo here:
http://www.freefamilywatch.com/demo.html
Follow the link for the story and pictures:
http://www.pcworld.com/article/152384/in_pictures_15_killer_android_apps_for_the_g1.html
As you might know, the iPhone 3G comes either on a contract which means that it is locked to the provider or Unlocked via iTunes on pre-paid plans or through a special arrangement with the service provider for a small fee. Locked phones however can be unlocked via hardware SIM attacments such as TurboSIM (discussed in detail in my paper) or other cheaper alternatives such as Universial SIM. What you might not know is that some sellers sell iPhones as if they are officially or leagally unlocked but in actuallity they are unlocked with alternative SIM attachments as shown in the pictures below:

SIM insertion slot showing extension wires

The actual Universal SIM attachment
To find out if the iPhone you are buying is unlockable by its carrier or not, ask the seller for the phone’s serial number and then visit:
http://support.apple.com/kb/HT1937
Buying a fake-unlocked iPhone could mean that your phone might be illegal to use in some countries because it violates usage laws. Also, it means a degration and sometimes the denial of service when it comes to data services and the quality of phone calls.
Pictures and Story from the Arabic source iPhone Islam. The only source for Arabisation of iPhone.
The beggest selling points for the Android and the G1 in my openion are the simultanious execution of applications and street level on google maps. Who needs any of these?!
You can run applications in the background on iPhone by using the Cydia app Backgrounder and you can use google earth for now to get street level pictures and wait for 2.2 iPhone software for full street view capabilities
I am sticking to my iPhone for now
Gotta love the big screen and the safari browser responsiveness and page browsing speed.
The people behind modmyi.com have an Android Forum but it doesn’t seem to have as much interest as the iPhone:
http://www.modmygphone.com/forums/index.php
I won’t judge the Android Platform yet though, I’ll give it six months
app.ifonetec.com: http://app.ifonetec.com/cydia/
cake.mapleidea.com: http://cake.mapleidea.com/cydia/
BigBoss & Planet-iPhones: http://apt.bigboss.us.com/repofiles/cydia/
Hack&Dev.org: http://iphone.hackndev.org/apt/
Hackers.nl: http://apt.hackers.nl/
iClarified: http://cydia.iclarified.com/
iPhone-notes.de Repo: http://apt.iphone-storage.de/
ispaziorepo.com: http://ispaziorepo.com/cydia/apt/
ModMyiFone.com: http://apt.modmyifone.com/
Niklas Schroder: http://apt.paperclipsandscrambledeggs.com/
RichCreations: http://www.richcreations.com/iphone/apt/
SaladSoft: http://nickplee.com/cydiasource/
Ste Packaging: http://repo.smxy.org/cydia/apt/
Steffwiz: http://steffwiz.webs.com/iphone/repo
Telesphoreo Tangelo: http://apt.saurik.com/
urbanfanatics.com: http://urbanfanatics.com/cydia/
WeHo.ru: http://weho.ru/iphone/
www.iacces.com: http://www.iacces.com/apt/
ZodTTD: http://www.zodttd.com/repo/cydia/
NEW Cydia Language Sources
comcute&gecko (Estonian): http://gecko.pri.ee/cydia/
CZ&SK: http://csid. tym.cs/repo/
iPhone-patch (Bulgarian): http://mspasov.com/
iphone.freecoder.org (Chinese): iphone.freecoder.org/apt/
iphonehe.com (Hebrew): http://iphonehe.com/iphone
Marcin Laber (Polish?): http://cydia.i-apps.pl/
Sources for Installer 4.0
Big Boss: http://apptapp.thebigboss.org/repofiles/installer4/
iPhone-notes.de: http://i.phone-storage.de/
iSpazio: http://repo.neolinus.org/ispazio/
ModMyiFone.com: http://i.modmyifone.com/
Rip Dev: http://i.ripdev.com
Ste Packaging: http://repo.smxy.org/installer4/
German: http://sendowski.de/iphone
Sources for Installer 3.1
Community Sources for Installer 3.11
iSpazio Official: http://repo.ispazio.net
ModMyiFone.com: modmyifone.com/installer.xml
RiP Dev (Kate, formerly Caterpillar): http://repository.ripdev.com/
Ste Packaging:http://repo.smxy.org/iphone-apps/ (make sure you include the last /)
Other Sources for Installer 3.11
aka.Repository: akamatsu.org/repo.xml
AlliPodHax Source: ihacks.us/index.xml or allipodhax.3host.biz/index.xml
AlohaSoft 1.0.2 - homepage.mac.com/reinholdpenner/102.xml
AlohaSoft 1.1.1: homepage.mac.com/reinholdpenner/111.xml
AlohaSoft 1.1.2: homepage.mac.com/reinholdpenner/112.xml
Apple (not really Apple): applerepo.com
Apple Daily Times: www.appledailytimes.com/installer
AppTapp Official: repository.apptapp.com
Apogee LTD: apogeeltd.com
Blaze Official: blazecompany.googlepages.com/
BigBoss Beta: sleepers.net/iphonerepobeta
BlackWolf: m8an.de/ownrisk.xml (Extended Preferences)
Byooi Digicide: byooi.com/iphone/digicide.plist (Jiggy Apps)
CedSoft (iSnake/Bounce): prog.cedsoft.free.fr
Chris Miles Repository (iSolitare): iphone.rustyredwagon.com/repo
Conceited Software Beta: http://conceitedsoftware.com/iphone/beta/
Conceited Software: http://www.macminicolo.net/conceited/iphone/cache.plist
CopyCoders: homepage.mac.com/hartsteins/copycoders/copycoders.xml (Network Apps)
dajavax: dajavax.googlepages.com/repo.xml
databinge: repo.databinge.com
DavTeam: davteam.com/repo.xml
Death to Design: iphone.deathtodesign.com
Digital Agua: repo.digitalagua.com
Dlubbat’s Apps: www.dlubbat.com/iphone.xml
Ettore Software Ltd: ettoresoftware.com/iphone/beta/ty.iphone
Fight Club: dezign999.com/repo
FreeMyiPhone: pxl.freemyiphone.com/
Fring: fring.com/iphone.xml
Gogosoft Source: www.blackblack.org/gogobeta.plist
GravyTrain ’s Vault: iiispace.com/installer2.xml (Includes user submitted themes)
Hijinks Inc.: hijinksinc.com/i/installer.xml
hitoriblog Experimental Pack: hpcgi3.nifty.com/moyashi/ipodtouch/repository.cgi
HighTymes: hightymes.org/iphone/plist/index.xml
iApp-a-Day: iappaday.com/install
Imagine09: home.twcny.rr.com/imagine09/Imagine09.xml
iBlackjack: iphonefanclub.com/native
iClarified: installer.iclarified.com
iFoneTech: app.ifonetec.com
Intelliborn: intelliborn.com/repo
Intelliborn (Cydia Source): intelliborn.com/cydia
iPhone Cake: iphonecake.com/src/all
iPhoneDevDocs: idevdocs.com/install
iPhone For Taiwan (SummberBoard Themes): iphone4.tw/showme
iPhoneFreakz: iphonefreakz.com/repo.xml
iPhoneIslam: apps.iphoneislam.com
iPlayful: iplayful.com/r
i.Marine Software (Caissa): caissa.us
imimux Repository (Real Artist): imimux.com
iPod Touch Fans: www.touchrepo.com/repo.xml
iPod Touched: ipodtouched.net/repo.xml
iPod-Touch-Themes.de: www.ipod-touch-themes.de/installer/repo.xml
iSwitcher (old): web.mac.com/iswitcher2/list.xml
iSwitcher (new) = MeachWare: meachware.com/list.xml
Jeremie Engel: rep.visuaweb.com
Jiggy Main Repository (Jiggy): jiggyapp.com/i
lazyasada: lazyasada.xeterdesign.com/repo.xml
Limited Edition iPhone: limitededitioniphone.com/lei.xml
Loring Studios: loringstudios.com/iPhone-schnapps/index.xml
McAfeeMobile Dev Repository: ipkg.mcafeemobile.com
MarcoGiorgini.com: marcogiorgini.com/iPhone/plist.xml
Makayama Software (CameraPro): tinyurl.com/2t8cax
MaomaLand: maomaland.com/iphone/repo.xml
Mateo (BeatPhone): bblk.net/iphone
McCarron’s Repo: patrickmccarron.com/irepo
MeachWare (new iSwitcher): www.meachware.com/list.xml
Mkv iPhone Repository: repo.mkv.mobi
Mobile Stacks: mobilestack.googlecode.com/svn/repository/internal.plist
ModMyApple.it (iBirthday): www.serverasp.net/chiafa/MMA/repo.xml
Moyashi: hpcgi3.nifty.com/moyashi/ipodtouch/repository.cgi
MTL Repository: home.mike.tl/iphone
MyApple.pl: i.myapple.pl
newATTiPhone.com: newattiphone.com/repo.xml
NPike.net: http://apps.npike.net/repo.xml
Nuclear Design: nucleardesign.net/repository
Planet-iPhones: planet-iphones.com/repository
Polar Bear Farm: www.polarbearfarm.com/repo/
Polleo Limited: source.polleo.no
Private Indistury: brandonsgames.com/chriss/index.xml
Pyrofer’s Projects: pyrofersprojects.com/repos/repos.xml
R4m0n (iPhysics): iphone.r4m0n.net/repos
Robota Softwarehouse: iphone.robota.nl
Sanoodi Repository: sanoodi.com/iphone
Saurik’s Coding Toolbox (Cydia): apptapp.saurik.com
ScoresPro: www.scorespro.com/iphone/repo.xml
scummVM: urbanfanatics.com/scummvm.xml
sendowski.de (MobileChat)sendowski.de/iphone
Shai’s Apps: ride4.org/shai.xml
Simek’s Graphic: simek.ddl2.pl
sipgate repository: iphone.sipgate.com
Skrew: i.danstaface.net
Slezak’s Stuff: www.spencerslezak.com
Smart-Mobil: www.smart-mobile.com/beta
Soneso Repository: soneso.com/iphone
SOS iPhone (ContactFlow): rep.sosiphone.com
Spiffyware: spiffyware.net/iphone
Studded: studded.net/installer/index.xml
Surge: iphonesurge.com/iphonesurge.xml
Swell: lyndellwiggins.com/installer/Swell
Swirlyspace: swirlyspace.com/SwirlySpace.xml
Touchmod Team: touchmods.net/rep.xml
Trejan: trejan.com/irepo
Trivialware: mazinger.cs.yale.edu/iphone-apps/index.xml
Unlock.no: i.unlock.no
weiPhone (weTools/weDict): app.weiphone.com/installer
Wiki2Touch: 168weedon.com/i/
Wizdom on Wheels (Common Website Links): iphoneapps.wizdomonwheels.com
XK72 Repository: http://xk72.com/iphone/repos/
ZodTTD.com Releases: zodttd.com/repo
Language Sources for Installer 3.11
Arabic: apps.iphoneislam.com
Czech: repo.iphone.cz
Chinese: iphone.org.hk/repository.plist
Danish: iphone.vildmedmac.dk/install
French: rep.sosiphone.com
FrenchIphone: rep.frenchiphone.com
German: sendowski.de/iphone
German aXP: lostsoul.aeroxp.org/iphone/index.xml
Greek: greekrepo.com
Hebrew ?????: ihebrew.net
Hungarian: ifhone.hu/install.xml
Norwegian - iFon: install.ifon.no
Polish - iPolish: krzak.net/iphone
Polish - iPolish(1.1.2): wakoman.ovh.org/iphone
Português-Brasil(1.1.2): iphonemod.com.br/forum/repo/installer.xml
Russian iPhone.RU: iphones.ru/r
Russian iPhone ??-??????: russianiphone.ru/beta
Russian Tools (in English): russianiphone.ru/beta/en
Spanish Phyros iPhone-ES: iphone.frickr.es/index.xml
Swedish iFun.se: ifun.se/swe
Taiwanese: iphone4.tw/unlock
Thai: pradt.net/iphone
Turkish: niffob.com/triphone.xml
Vietnamese: iphone.billydragon.net
———————————-
Source:
http://sleepers.net/2008/10/23/compiled-source-list-for-2xfw-1xfw-cydia-installer/
OLDER LIST FOUND HERE:
http://www.mysecured.com/?p=201
The LayerOne 2008 talk by David Hulton titled: Intercepting Mobile Phone/GSM
Visit the GSM Hakcing WIKI at:
http://wiki.thc.org/gsm
The USRP is available at: http://www.ettus.com
Learn more about the GNU RADIO project at: http://www.gnu.org/software/gnuradio
David is the Chairman of Toorcon
An interesting news article about the work of BT (formerly British Telecom), Glamorgan University, Australia’s Edith Cowan University and Sim Lifecycle Services where researchers recovered data from handsets from mobile phone recycling companies:
Mobile phones can never be totally wiped clean of data
To get more information on the research at Edith Cowan University and its upcoming conferences please visit SECAU Security Research Centre’s website:
Here are some published refereed journal and conference papers to give you an idea of what to expect for the Edith Cowan University conferences in December:
- Valli, C. and A. Jones (2008). A study of 2nd Hand Blackberry for sale - World class security foiled by humans. Proceedings of the 2008 World Congress in Computer Science, Computer Engineering, and Applied Computing - SAM 2008 - The 2008 International Conference on Security & Management., Las Vegas, USA.
- Al-Zarouni, M. (2007, 3rd December, 2007). Introduction to Mobile Phone Flasher Devices and Considerations for their Use in Mobile Phone Forensics. Paper presented at the The 5th Australian Digital Forensics Conference, Edith Cowan University, Mount Lawley Campus, Western Australia.
- Yap, L. F., & Jones, A. (2007, 3rd December, 2007). Profiling Through a Digital Mobile Device. Paper presented at the The 5th Australian Digital Forensics Conference, Edith Cowan University, Mount Lawley Campus, Western Australia.
- Yap, L. F., & Jones, A. (2007). Deleted Mobile Device’s Evidence Recovery:. Paper presented at the Media and Information-War Conference 2007, Kaula Lumpur, Malaysia.
You can register to attend Edith Cowan University’s conferences here:
http://conferences.scis.ecu.edu.au/
Hope to see you there
According to the article below, iPhone 2.2 beta which was provided to developers contained an Android-like Street View capability within the Google Maps App.
I Don’t know about you, but to me, it seemed like the street view feature was one of the most attractive features that Google used in selling the Android platform to consumers. I personally see a great potential in Android for app development but I still think that the iPhone will keep on keeping on especially after the dropped the NDA requirement for app developers

I’ve had my iPhone 3G with MobileMe for a while now but it didn’t seem like the push service from mobile me was working at all. This changed starting from yesterday though
It is working now and I am happy with it so far.
Here is a link to the T-Mobile G1 website where you can play around with a basic emulator without having to download the SDK. You can also get a basic guide on features here:
http://tmobile.modeaondemand.com/htc/g1/
A more functional emulator can be downloaded with the Android SDK here:
http://code.google.com/android/reference/emulator.html
Finally here is a good video Introduction on Android OS for Developers. A must see if you have anything to do with the Android Platform(WARNING: 52 MINUTES LONG!):
More demo videos on user interface and applications can be found on the Android developer site:
http://code.google.com/android/index.html
Here is one of them to get you started:
These are some of the prototype Mobile Phones on show.
3D Navigation and Situational Awareness in a Mobile Phone:
Separatable mobile phone:
Projector Mobile Phone:
Ideally the emergency dial screen should allow ONLY EMERGENCY NUMBERS to be dialed out on a passcode locked phone. The iPhone however allows for ANY NUMBER to be dialed when it is passcode locked! This bug is not new, it was present in iPhone 2.0.2 as well!
Here is a video demonstrating the issue:
I discovered this bug in 2.0.2 just a couple of days before 2.1 came out. So, it was too late for me to give a heads up to Apple. So, I waited for 2.1 to come along to see if it was fixed. I did that today and found out that it wasn’t fixed.
This of course could be an Auatralia-only issue or even an Optus-only issue. Nevertheless it is a security issue with the iPhone and should be addressed.
UPDATE 18 Sep 08:
There is some debate on whether it is a bug or feature! Look at the following link for some more information on the issue:
http://www.macrumors.com/iphone/2008/09/17/iphone-2-1-emergency-call-anyone-bug-or-feature/
–
About the author:
Marwan Al-Zarouni CISSP is currently pursuing a Doctor of Information Technology award at Edith Cowan University. He is a member of the Security Research Centre at Edith Cowan University in Perth, Western Australia.
The features include: live rss feeds, live TV streaming channels, TV guide while watching TV, credit card and transport card functions on the phone, biometric fingerprint reader, 3+Mbps speed 3g data speeds… etc.
It has street view

The CSI Stick is a portable USB stick kind of device that can be connected to a mobile phone to conduct a copy of some sort of memory from the mobile phone device without the need for a computer to be connected to the mobile phone. The type of data collected form the mobile phone can be chosen through a slider switch. The device currently supports certain Motorola and Samsung phone models with more manufacturer support coming soon. The data collected by the device can then be interpreted via the use of Paraben’s Device Seizure or DS Lite. The cost is $199 USD.
For more information, please visit:
http://www.physorg.com/news139460365.html
and
http://computing.in.msn.com/safe/article.aspx?cp-documentid=1658902
or the device’s official website:
http://csistick.com/

Even though the iPhone doesn’t officially support Arabic yet, Google Translator includes it in 24 languages it supports for the web based software. You can use it by pointing the iPhone browser to: http://translate.google.com.
WOLF claims to forensically extract the information from the internal memory of the iPhone without altering the device.
-
WOLF claims it can obtain the following information from devices:
The price, training and other information can be obtained from Sixth Legion LLC, a division of IDFS LLC on:
http://www.hex-dump.com/wolftest/index.html
or
http://sixthlegion.com.
PwnageTool 2.0 MACOSX version is released.
For more details, please visit:
rlslog.net
also see:
UPDATE: Don’t have a Mac? You can do it in Windows as well. For instractions, go here:
Step-by-Step Guide to Pwn first generation iPhone running firmware 2.0 using Windows
In a previous post http://www.mysecured.com/?p=202 I showed that your data is not wiped when you do a normal restore. So in this post I will show you some of the ways you can wipe your phone with some degree of certainty that the information on it is wiped.

If you want to wipe your iPhone before you sell it on eBay or give it back to Apple because the touch screen stopped working all of a sudden! Then here are the different ways you can wipe it:
- Jonathan Zdziarski’s method:
http://www.zdziarski.com/papers/wipe.html
It involves jailbreaking and command line access. It is best suited for people with jailbroken iPhones and are really paranoid and control freaks!
- Rich Mogull’s (securosis.com) method:
http://securosis.com/2008/05/20/formatting-an-iphone-to-wipe-data/Which is an easy to do 2 restores and 3 overwrites of the iPhone device’s user data area. Look at this video from CNET on youtube:
- BigBoss Wipe App Method:
http://sleepers.net/news/?p=174
This needs the iPhone to be jailbroken as well. It does a zero out wipe on the device, so it will require a restore afterwards.
The basic idea of all of the methods is to overwrite the data in the user area. Be it by overwriting it with music as in Mogull’s method or by using a wipe tool as with BigBoss or by overwriting it with zeros as in Jonathan’s method. I prefer the latter two methods as overwriting with music might leave some of the data intact (call me paranoid!). But on the other hand it could be the only option for people who do not want to jailbreak their iPhone or do not have the technical expertise to do so.
UPDATE (28 August 2008):
iPhone software 2.0 and above comes with an erase all feature that was not available in previous versions of the iPhone and therefore this feature can be used to completely wipe the iPhone. This can be done on the iPhone itself without needing to connect it to iTunes.
So, on the iPhone tap Settings -> General -> Reset and then select the “Erase All Content and Settings” option from the buttons shown. Users must note that under the 1.x iPhone software, invoking this setting erased the iPhone’s obvious data, but not did NOT PERFORM A ‘bit-by-bit’ WIPE. Under the 2.0 software however, you get a much more thorough wipe (bit-by-bit). which can take an hour or two to complete depending on the storage size of the iPhone being wiped.
According to Jonathan Zdziarski:
So, if you have to return your iPhone to an Apple or AT&T store and they offer to replace it with a new one, make sure that you wipe your data properly first. A proper bit level wipe is needed here and NOT a system restore!
UPDATED LIST IS FOUND HERE: http://www.mysecured.com/?p=221
Sources for downloading iPhone third party apps. Here is a list:
Community Sources:
BigBoss: thebigboss.org/repo.xml
Conceited Software: http://www.macminicolo.net/conceited/iphone/cache.plist
ModMyiFone.com: modmyifone.com/installer.xml
Ste Packaging:http://repo.smxy.org/iphone-apps/ (make sure you include the last /)
iPod Touch Fans: www.touchrepo.com/repo.xml
Other Sources:
aka.Repository: akamatsu.org/repo.xml
AlliPodHax Source: ihacks.us/index.xml or allipodhax.3host.biz/index.xml
AlohaSoft 1.0.2 - homepage.mac.com/reinholdpenner/102.xml
AlohaSoft 1.1.1: homepage.mac.com/reinholdpenner/111.xml
AlohaSoft 1.1.2: homepage.mac.com/reinholdpenner/112.xml
Apple (not really Apple): applerepo.com
AppTapp Official: repository.apptapp.com
Apogee LTD: apogeeltd.com
Blaze Official: blazecompany.googlepages.com/
BigBoss Beta: sleepers.net/iphonerepobeta
BlackWolf: m8an.de/ownrisk.xml (Extended Preferences)
Byooi Digicide: byooi.com/iphone/digicide.plist (Jiggy Apps)
CedSoft (iSnake/Bounce): prog.cedsoft.free.fr
Chris Miles Repository (iSolitare): iphone.rustyredwagon.com/repo
Conceited Software Beta: http://conceitedsoftware.com/iphone/beta/
CopyCoders: homepage.mac.com/hartsteins/copycoders/copycoders.xml (Network Apps)
dajavax: dajavax.googlepages.com/repo.xml
databinge: repo.databinge.com
Death to Design: iphone.deathtodesign.com
Digital Agua: repo.digitalagua.com
Dlubbat’s Apps: www.dlubbat.com/iphone.xml
Fight Club: dezign999.com/repo
FreeMyiPhone: pxl.freemyiphone.com/
Gogosoft Source: www.blackblack.org/gogobeta.plist
GravyTrain ’s Vault: iiispace.com/installer2.xml (Includes user submitted themes)
hitoriblog Experimental Pack: hpcgi3.nifty.com/moyashi/ipodtouch/repository.cgi
HighTymes: hightymes.org/iphone/plist/index.xml
iApp-a-Day: iappaday.com/install
Imagine09: home.twcny.rr.com/imagine09/Imagine09.xml
iBlackjack: iphonefanclub.com/native
iClarified: installer.iclarified.com
iPhone Cake: iphonecake.com/src/all
iPhoneDevDocs: idevdocs.com/install
iPhone For Taiwan (SummberBoard Themes): iphone4.tw/showme
i.Marine Software (Caissa): caissa.us
imimux Repository (Real Artist): imimux.com
iPhoneIslam: apps.iphoneislam.com
iPod Touched: ipodtouched.net/repo.xml
iPod-Touch-Themes.de: www.ipod-touch-themes.de/installer/repo.xml
iSpazio: http://repo.ispazio.net
iSwitcher (old): web.mac.com/iswitcher2/list.xml
iSwitcher (new) = MeachWare: meachware.com/list.xml
Jeremie Engel: rep.visuaweb.com
Jiggy Main Repository (Jiggy): jiggyapp.com/i
lazyasada: lazyasada.xeterdesign.com/repo.xml
Limited Edition iPhone: limitededitioniphone.com/lei.xml
Loring Studios: loringstudios.com/iPhone-schnapps/index.xml
MarcoGiorgini.com: marcogiorgini.com/iPhone/plist.xml
Makayama Software (CameraPro): tinyurl.com/2t8cax
MaomaLand: maomaland.com/iphone/repo.xml
Mateo (BeatPhone): bblk.net/iphone
McCarron’s Repo: patrickmccarron.com/irepo
MeachWare (new iSwitcher): www.meachware.com/list.xml
Mobile Stacks: mobilestack.googlecode.com/svn/repository/internal.plist
ModMyApple.it (iBirthday): www.serverasp.net/chiafa/MMA/repo.xml
Moyashi: hpcgi3.nifty.com/moyashi/ipodtouch/repository.cgi
MTL Repository: home.mike.tl/iphone
MyApple.pl: i.myapple.pl
newATTiPhone.com: newattiphone.com/repo.xml
NPike.net: http://apps.npike.net/repo.xml
Nuclear Design: nucleardesign.net/repository
Polar Bear Farm: www.polarbearfarm.com/repo/
Polleo Limited: source.polleo.no
Private Indistury: brandonsgames.com/chriss/index.xml
Pyrofer’s Projects: pyrofersprojects.com/repos/repos.xml
R4m0n (iPhysics): iphone.r4m0n.net/repos
RiP Dev (Caterpillar): http://repository.ripdev.com/
Robota Softwarehouse: iphone.robota.nl
Sanoodi Repository: sanoodi.com/iphone
Saurik’s Coding Toolbox (Cydia): apptapp.saurik.com
ScoresPro: www.scorespro.com/iphone/repo.xml
scummVM: urbanfanatics.com/scummvm.xml
sendowski.de (MobileChat)sendowski.de/iphone
Shai’s Apps: ride4.org/shai.xml
Simek’s Graphic: simek.ddl2.pl
Skrew: i.danstaface.net
Slezak’s Stuff: www.spencerslezak.com
Soneso Repository: soneso.com/iphone
SOS iPhone (ContactFlow): rep.sosiphone.com
Spiffyware: spiffyware.net/iphone
Studded: studded.net/installer/index.xml
Surge: iphonesurge.com/iphonesurge.xml
Swell: lyndellwiggins.com/installer/Swell
Swirlyspace: swirlyspace.com/SwirlySpace.xml
Touchmod Team: touchmods.net/rep.xml
Trejan: trejan.com/irepo
Trivialware: mazinger.cs.yale.edu/iphone-apps/index.xml
Unlock.no: i.unlock.no
weiPhone (weTools/weDict): app.weiphone.com/installer
Wizdom on Wheels (Common Website Links): iphoneapps.wizdomonwheels.com
ZodTTD.com Releases: zodttd.com/repo
Language Sources:
Arabic: apps.iphoneislam.com
Chinese: iphone.org.hk/repository.plist
Danish: iphone.vildmedmac.dk/install
French: rep.sosiphone.com
FrenchIphone: rep.frenchiphone.com
German: sendowski.de/iphone
German aXP: lostsoul.aeroxp.org/iphone/index.xml
Greek: www.greek-iphone.com/grloc
Hebrew ?????: ihebrew.net
Hungarian: ifhone.hu/install.xml
Norwegian - iFon: install.ifon.no
Polish - iPolish: krzak.net/iphone
Polish - iPolish(1.1.2): wakoman.ovh.org/iphone
Português-Brasil(1.1.2): iphonemod.com.br/forum/repo/installer.xml
Russian iPhone.RU: iphones.ru/r
Russian iPhone ??-??????: russianiphone.ru/beta
Russian Tools (in English): russianiphone.ru/beta/en
Spanish Phyros iPhone-ES: iphone.frickr.es/index.xml
Swedish iFun.se: ifun.se/swe
Taiwanese: iphone4.tw/unlock
Thai: pradt.net/iphone
Turkish: niffob.com/triphone.xml
Vietnamese: iphone.billydragon.net
More Sources here:
http://www.ipodtouchfans.com/wiki/index.php?title=IPod_touch_Installer_source_list
According to tuaw:
A half dozen different firms are actively hunting for developers who can assist law enforcement in reading data off unjailbroken iPhones
When: April 17, 2008 at 17:00 GMT
Who: Jonathan A. Zdziarski.
Details: While some of a suspect’s data can be viewed using the direct GUI interfaces in the iPhone’s software, much hidden and deleted data is available as well, which may provide for more thorough evidence gathering. Existing commercial forensic tools are sadly lacking their ability to perform deep raw disk level recovery, and so Jonathan will demonstrate how to install his custom forensics toolkit on any existing model iPhone and send a raw disk image to a desktop machine. He will also show you how to recover files specific to the iPhone including deleted keyboard caches, photos, web objects, and much more. Jonathan’s custom forensics toolkit and his accompanying forensic manual will be available free to forensic investigators in law enforcement.
Read More here:
http://www.oreillynet.com/pub/e/949?CMP=ILC-orm_webinars&ATT=iphone-forensics

I know that you’ll love this as a research tool. I love the visulization part and not so much the cover-flow type interface. It is still in beta, so I am expecting more GUI improvements
Get it here:
http://www.yourergo.com/
Here is a link to a Video demo shown on CNET News.com. It shows the potential of software-as-a-service (SaaS) applications like Basecamp or Salesforce.com on the iPhone. This could boost the sales of the iPhone and at the same time provide another dimention to information accessable to the iPhone mobile device.
Get them here:
http://www.macworld.com/article/60232/2007/10/nov07mobilemac.html?t=213
Thanks to Macworld magazine
As requested by Haitham. The Hard drive is not actually a hard drive. It is a Samsung 65 Nanometer NAND flash part number “K9HBG08U1M” the same one used earlier in the 8GB iPod Nano.
Data sheet can be found here:
http://www.datasheet4u.com/download.php?id=604473
More information and other links can be found here:
http://www.iphonefreak.com/2007/07/iphone-componen.html
Good news for iPhone forensics:
Paraben’s Device Seizure can get a variety of data depending on the operating system version as well as whether or not the phone has been unlocked (often called Jailbreaking). The following is a general guide to what data can be acquired from the different versions, however, our testing shows that different Jailbreaking methods unlock different portions of the phone (for instance, one method allowed Device Seizure to acquire most media files but did not allow access to phone records, contacts, or images uploaded to the phone):
Firmware 1.0, 1.0.1 and 1.0.2: Most logical data can be acquired from the phone Firmware 1.1.1, 1.1.2, 1.1.3, and 1.1.4: Only the /var/root/Media folder will be acquired Firmware Unlocked by a Jailbreaking Utility: Should
acquire most logical data depending on the unlocking software used. This is our first release for the Apple iPhone and we expect to see many more additions to this technology in the future. Keep your subscription
current to make sure you get all the new updates.
As quoted from Paraben. For more information please visit Paraben.
Instructions in Arabic can be found here:
http://www.iphoneislam.com/?p=62
Instructions and download in English can be found here:
If you get error “The application failed to initialize properly (0xc0000135)” you need to install .NET Framework 2.0. The executable unzips the GUI executable to “Program Files\ziphone”
Now you can unlock new iphones that are OTB 1.1.2 and 1.1.3 (bootloader version 4.6) with just software and no need for special microchips that go behind your SIM card. Here is a link to the guide:
http://iphone.unlock.no/OTB112unlock.htm
To see it in action, check out this youtube video:
Gear Live has a cool gallery of pictures of the new additions to the iPhone interface in its 1.1.3 release. The most impressive feature for me was the locate-me feature for the google maps application. Other features include dragging and dropping icons on the springboard and bookmarks icon on the springboard. Another much-needed feature is the multiple-people SMS capability.
To see some screen shots of the changes please follow the link below:
An Arabic keyboard has been developed for the iPhone. Now you can write Arabic SMS messages on you iphone
For more information and to update you iphone to support arabic typing please visit:
http://www.iphoneislam.com/?p=20
Also, make sure to bookmark their site for the latest islamic and Arabic related links and stories about the iPhone:
All you have to do is place a font file in the direcotry:
system/library/fonts/cache
It can be downloaded from here:
http://rapidshare.com/files/70430782/arialuni.ttf.html
And your safari browser will be able to ready arabic in the correct direction this time! As shown below

Credit for this one goes to Mishary.
Thanks

Boise State University is working on research to power a D-size battery by walking motion. Here are the details:
http://www.news.com/8301-11128_3-9818487-54.html?tag=nefd.top
Finally, someone did something for the iPhone and the iPod touch that enables users to get full disk level access with read/write prevliges on the iPhone’s disk via AFP. The AppleTalk Filing Protocol makes the iPhone show up on the Mac desktop as a disk with full read/write access. For more from the “Core” click the link:

This is a stand-alone hard disk wiper! No computer needed. Wiebetech’s pocket-sized eRazer erases at a rate of 35MB/s, effectively wiping a 250GB hard drive in under two hours. The eRazer meets the DoD erasing standerds and sells in two versions one for $99 and the Pro which supports SATA and Multi-pass sells for $150… Cheap!
Also called “An Open Handset Alliance Project”. Here are some screen shots and a video preview of it from Gizmodo:
and video Preview:
The SDK can be downloaded from here:
http://www.oissg.org/certification-training-new-/index.php
These certification workshops fund the Open Information Systems Security Group (OISSG) research and development of the ISSAF.
You can also download ISSAF for free! (9.59MB, 1264 pages)
The following new features are available for all enterprise and individual customers:
- Performance on flash drives is improved.
- MojoPac can be used on a host with limited mode login with MojoPac Usher (Beta) installed on the host.
- MojoPac can be installed to a directory on the host computer.
- For our Enterprise customers, MojoPac 1.8 has many enhanced management, provisioning and deployment capabilities.
- Active Directory authentication is now available.
- Image creation and deployment have been made easier.
- New configuration options are available to enforce data protection and security policies.
- MojoPac can perform a security check on host computers.
If you are an IT administrator, please contact sales-at-ringcube dot com for updated documentation and management tools.
If you have automatic updates enabled, your MojoPac will update in the next few days.
If you are not using MojoPac, please download it. MojoPac Freedom is *free* for non-commercial personal use.
For more information and to download Mojopac, please visit them at:
Where: Chicago, Illinois, USA.
When: 8-10 May 2008
What: World’s first conference to be dedicated to performing Mobile Device Forensics.
How much: Registration prior to March 1, 2008: $250 and after $300USD
More details can be found on the official website:
http://mobileforensicsworld.com/
Speakers include:
Rick Ayers, NIST
Sam Brothers, CBP
Michael Harrington, MSP
Wayne Jansen, NIST
Gary Kessler, Champlain College
Ben LeMere, USCG
Kyle Lutes, Purdue University
Agents from Matrix Solutions
Kevin Mansell, Control-F
Rick Mislan, Purdue University
Lee Reiber, MFI
Amber Schroader, Paraben
Greg Smith, TrewMTE
Workshop Sessions in:
Cellebrite UME36
Cellular Data Resources
Control-F
CSurv Cell Site Analysis
DataPilot
Pandora’s Box
Paraben Forensics
Project-A-Phone
It is like a SecureID token but for your Mobile Phone. It is based on Java and provides 1024bit RSA encryption and GrIDsure’s ID technology. Want to learn more, then head to:
http://www.itsecurityportal.com/itsecurity_news.asp?articleid=260033
I have to admit, I thought this is like CommonWealth Bank’s NetCode SMS but it is clearly nothing like it. For more information on that go to:
It is finally here
Now you can safely update your 1.0.2 to the new 1.1.1 and have it work like a charm
Make sure you know what you’re doing though
Here are the detailed instructions:
http://www.tuaw.com/2007/10/29/instant-jailbreak-for-iphone-and-ipod-touch/
Remember, if you brick your iPhone, don’t blame us!
Do you live in the United Arab Emirates? Are you a hacker? Then this site is made for you! Get the latest hacking news, exploits, links, pod casts and more through this easy to use website.
Feel like you want to contribute to the site? Then drop us a line at: (hackers) at {marwan} dot [com].
برنامج لقراءة الرسائل العربية على الـ آيفون

For more information please visit:
http://mem9.net/iphone/
Thanks also for the following people who contibuted to bringing us one step closer to an Arabic iPhone
If you have a USB Flash Disk (thumb drive ) then this software is a must have. It transforms your USB drive into a full featured Windows XP PC! A PC you can take with you anywhere you can take the flash disk to. Best of all, now it is available for free! Get it now!
Now if someone can write a forensics paper on this
From Intel! crack the clues and win!
you could win a fortnight for two in San Francisco (including a trip to Alcatraz), or a host of other great prizes.
As you play, you’ll learn how we’ve boosted PC security at the hardware level with Intel® vPro™ and Intel® Centrino® Pro processor technologies. Now go ahead and flex those security muscles!
Metasploit for hacking iPhones:
http://www.pcworld.com/article/id,137741-c,iphone/article.html
Apple releases an update to Patch 10 flaws with the iPhone:
http://www.news.com/8301-10784_3-9786507-7.html?tag=nefd.blgs
The patch also Bricks unlocked iPhones
Apparently, it is easier than you think. A penetration tester said “It turned out to be one of the easiest penetration tests I’d ever done!”
To read more about it go to:

Read about it at Engadget then follow the easy instructions here: http://iphone.unlock.no/
Easy!
http://www.iphonealley.com/news/anysim-released-free-gui-iphone-unlock
The First International Conference on Forensic Applications and Techniques in Telecommunications, Information and Multimedia will be held in Adelaide, South Australia from January 21st to 24th 2008. Call for Papers closes on September 28th 2007. Topics include data mining, multimedia source identification, image tamper detection and data carving. For more information please visit the conference website.
Here are two guides to SIM unlock your iPhone for free:
Here is a simple guide to install Arabic fonts on your iPhone. You still can not connect the Arabic letters but at least this one is right to left
Thanks to Nawaf Alsabhan for the guide. Any help in this area is greatly appreciated. So, if you know anything about Arabic font support for OSX or iPhone please contribute
Also, look at:
For instructions in Arabic

This time it is by the iPhone Dev team
iPhone is finally free from its AT&T ball and chain!
For more information and to download the needed files, head to Gizmodo. Instructions are not out yet. So, if you are one of those people that never RTFM, then download it and wing it!
Thanks again for EVERYONE on the Hackint0sh forums for all their efforts and all the good times we had with the iPhone
Otherwise, (if you’ve got money to burn) then go for the commercial unlock software found here:
http://www.iphonesimfree.com/cgi-bin/iphonesimfree/engine.pl?page=buy
Got questions? We got answers! Don’t be hatin’ start participatin’! Head to Hackint0sh.org!
Image above is from: http://blog.scifi.com/
There are so many iPhone clones that some online shops have a special category for them! Check out IPMart for example:
http://www.ipmart.com/main/browse.php?cat=1758&cat=2308
The De Say M888 shown below is the most impressive of them all but at USD 251.25 plus shipping fees won’t you rather buy an original 4GB iPhone at 299 USD including shipping?
A simple idea that resulted in big fireworks! Just take the IP address information from wiki posts and cross it with DNS information from IP range owners and walla!
Still don’t know what this means? It means you can now find out if someone is editing their own wiki information (like deleting the bad stuff!… For shame!).
Good on you Virgil Griffith. I hope that you don’t edit your own wiki entry either
Here are the links:
- An MP3 interview with Virgil: http://www.abc.net.au/melbourne/stories/s2017196.htm?backyard
- http://virgil.gr/ his website
- WikiScanner http://wikiscanner.virgil.gr/
This tool answers the question: who really edits wikis? Now you know!
Here is something to get your appetite going. WIRED Magazine’s list of salacious edits:
According to WIRED Magazine:
http://www.wired.com/gadgets/wireless/news/2007/08/iphone_forensics
It quotes an expert from Paraben and Blackbag saying that it is a challange.
After the Super SIM and Turbo SIM methods, we have a hardware unlock method. Follow the links below for more details:
- http://www.reghardware.co.uk/2007/08/24/iphone_unlocked/ Contains the video
- http://iphonejtag.blogspot.com/ The instructions site
- http://www.tech.co.uk/gadgets/phones/mobile-phones/news/new-instructions-for-iphone-hardware-unlock?articleid=1348296214
- http://blogs.pcworld.com/staffblog/archives/005210.html
I would not try this at home… Super Sim simply works and it is CHEAP! Why bother with anything else, it is simply not worth the time or effort. Not to mention the risk of damaging the phone!
Whould you attempt this on your phone?
It is STILL NOT a software hack! This one revolves around something called TurboSIM. It supports all kinds of SIMs not just V1 SIMs. For more information go to:
http://www.iphonestalk.com/iphone-unlocked-for-all-use-any-sim-card-in-your-iphone/
and here is how to do it:
http://www.hackint0sh.org/forum/showthread.php?t=2619
or
http://www.jasonmadigan.com/2007/08/13/turbo-sim-iphone-unlock-confirmed-working/
Enjoy
and this time, no need for SIM card programmer devices or Silvercards!
At least this is a SIM fabrication hack that works. For instructions, please follow one of the links below:
http://www.hackint0sh.org/forum/showthread.php?t=2215
or
http://www.myitablet.com/iphone-unlocked-for-european-use-061341.php
Enjoy your new unlocked iPhone
Now, if only they can come up with the software hack before the 45 day deadline
Update: Rumor has it that the unlocked iPhones are already being sold in Hong Kong!
http://www.gearfuse.com/hong-kong-is-selling-fully-unlocked-iphones-now/
Take the poll on marwan.com:
http://www.marwan.com/2007/08/will-iphone-be-unlocked-within-45-days.php
I Predicted 45 days for the iPhone to work with other than AT&T! Have your say at marwan.com
Download and read it! It is not small though about 8-10MB. News, articles, intreviews, book releases, software walk-throughs, and more.
Well, so far we have three choices. They are:
- M300 : Sold by IPMart
![]()
- M500 : Sold by SMS Technology Australia (to be released at the end of August)

- Cect Mobile Wrest watch: A Chinese prototype announce by CECT
Picture from mobilemag.com
The software detects installed software and categorises them as either Insecure, End-of-Life, or Up-To-Date. Effectively enabling you to focus your attention on software installations where more secure versions are available from the vendors. Sounds good to you? Then head to:
Here are the details on How to do it (according to the hacker) :
1. Get the required hardware and softwares: (these are the ones I have used): An Infinity USB unlimited SIM reader/writer, a silvercard, SIM-EMU 6.01, and WoronScan 1.09
2. Get the IMSI, Ki of your carrier using WoronScan (I will call them IMSI-b, Ki-b)
3. Use SIM-EMU and create 2 files (1 Flash and 1 EEPROM) using the ICCID of the AT&T sim (ICCID-a), IMSI-b and Ki-b
4. Then use these 2 files to create a sim using the infinity usb unlimited reader/writer
5. Put this sim into a normal unlocked phone and make some calls/receive calls/data services
6. Then use SIM-EMU to change the IMSI of the original Flash file to IMSI of AT&T sim (IMSI-a)
7. Again write the silvercard with the new flash and eeprom files
8. Put this sim into the iphone
9. Activate using the Cingular method as descirbe in Hacktheiphone.com
This is not a true unlock. It is a hack that enables you to make calls with the iphone but does not enable you to recieve calls or use Telstra’s network to browse the Internet. At least not yet
Links:
http://www.smh.com.au/news/phones–pdas/iphone-hacked-for-australia/2007/07/30/1185647803146.html
For more information go to the MSN Video:
http://ninemsn.video.msn.com/v/en-au/v.htm?g=7386e8dd-6f00-4c67-931b-cea66739a91e&f=&fg=copy
Read the following articles for more details on the case:
I’ve been searching for iPhone unlocking sites and so far I found the sites below. I would like to emphasize that it is only a matter of time until a workaround can be found to use the iPhone with other providers other than AT&T. So, here are the two sites:
- The following blog post claims that it will send you an email with information about unlocking the iPhone once it is available for a small fee:
- The following company mentioned in this “the register” article claims that it is close to unlocking the iPhone and that once it is able to do that, it will provide iPhone users with a $50 software that will unlock their phones for them:
It is also worth noting that unlocking phones was ruled to be legal by the US copyright office last year.
If you don’t already have this one, please download and read this Computer Security Division NIST Interagency Report (IR). It was published in March 2007:
- http://csrc.nist.gov/publications/nistir/nistir-7387.pdf
- Zipped version of the pdf: http://csrc.nist.gov/publications/nistir/nistir-7387-pdf.zip
It is an update and complement to NIST Reports:
- Guidelines on Cell Phone Forensics (Special Publication 800-101):
- Cell Phone Forensic Tools: An Overview and Analysis (NISTIR 7250):
Here are two of them:
Duke University’s Wi-Fi network has a problem — the iPhone. Built-in Internet wireless adapters on AAPLthe new iPhone are crashing Wi-Fi access points by sending 18,000 data requests per second. Although other “smart phones” have similar capabilities, only the iPhone has shown to be able to overwhelm the campus’ network. Neither Duke, Cisco nor Apple know why it’s happening, but the school said if it occurs in the fall when students return, it would be a disaster. Source: http://money.cnn.com/news/newsfeeds/articles/newstex/IBD-0001-18205063.htm
The second problem is:
The iPhone’s web dialer is vaulnrable to exploits! to find out more, go to: http://www.tgdaily.com/content/view/32936/108/
If you were wondering if there are any hacks for the iPhone, well here are two of them for you:
- The Activation Hack: http://nanocr.eu/2007/07/03/iphone-without-att/
This lets you access features of the iPhone without activiting it with your service provider.
This provices shell access the the iPhone. Here is a command list:
http://iphone.fiveforty.net/geohot/cmdlist.txt
Enjoy! If you’ve got more hacks, please let us know by commenting on this post
Among the prizes to be awarded to the most thorough beta testers will be three gaming consoles including a Sony Playstation 3, a Microsoft Xbox360 and a Nintendo Wii. Other prizes include a Nokia N90 device, 30 PC games (either World of Warcraft or Command & Conquer 3), as well as free licenses for BitDefender’s 2008 consumer product line.
BitDefender Total Security 2008 Beta will be made available to download for free through BitDefender’s corporate website http://www.BitDefender.com starting June 19, 2007. Registration and further information about the BitDefender Total Security 2008 Beta testing contest can be found online at:
http://beta.bitdefender.com. The contest will end on July 20 and winners will be announced on August 30, 2007.
For an interesting look at the cellphones of the future, watch this short video from cnet:
Where: Liverpool Library, U.K.
When: 5pm on 25th June 2007.
What: read the pdf brochure.
For more information, follow the link:
http://www.criminalsolicitor.net/forum/forum_posts.asp?TID=2450

“Hitchhiker helps you to connect your Pocket PC to the wireless Internet. Simply click “Connect” and it will try all nearby public access points. Hitchhiker will handle all settings for you and perform complicated tests to ensure you can connect to the Internet in no time.”
The software can be downloaded from here:
http://www.kasuei.com/hitchhiker/
The site also has other useful freeware, so check it out.
Preliminary Call for Papers
The First ACM Conference on Wireless Network Security (WiSec ‘08)
When: March 31 - April 2, 2008, Alexandria, Virginia, USA.
WiSec aims at exploring attacks on wireless networks as well as techniques to thwart them.
Topics include:
- Naming and addressing vulnerabilities
- Key management in wireless/mobile environments
- Secure neighbor discovery
- Secure PHY and MAC protocols
- Trust establishment
- Intrusion detection, detection of malicious behavior
- Revocation of malicious parties
- Denial of service
- User privacy, location privacy
- Anonymity, prevention of traffic analysis
- Identity theft and phishing in mobile networks
- Charging
- Cooperation and prevention of non-cooperative behavior
- Economics of wireless security
- Vulnerability and attacker modeling
- Incentive-aware secure protocol design
- Jamming
- Cross-layer design for security
- Monitoring and surveillance
- Computationally efficient cryptographic primitives
The considered wireless networks encompass cellular, metropolitan,
local area, vehicular, ad hoc, satellite, underwater, and sensor
networks as well as RFID.
Important dates:
Paper submissions due: September 15, 2007
Notification of acceptance: December 10, 2007
Camera-ready version due: January 15, 2008
Conference: March 31 - April 2, 2008
WiSec results from the merger of three workshops:
- ESAS (European Workshop on the Security of Ad Hoc and Sensor
Networks)
- SASN (ACM Workshop on the Security of Ad Hoc and Sensor Networks)
- WiSe (ACM Workshop on Wireless Security)
For more information, go to:
I have received many visits to this site searching for “Nokia Hidden Codes”. So, I decided to include some more
Here is a list of codes and some links to get some more codes:
*#06# Gets you the Serial Number/IMEI.
*#0000# Gives you the software version (e.g. V 5.27.0 / 28-06-04 / NHL-10) The NHL-10 is important and makes your life easier when you try to use flashers!
*#2820# Gives you the Bluetooth device address
xx# - Quick contact access (xx = location number, e.g. : 17#)
*#62209526# Gives you the MAC address of the WLAN adapter, this information is only available on the new models (S60 3rd edition) which have wireless connectivity.
To get some more codes (some of which can do damage to your phone and/or data residing on it, approach the codes on these sites with caution:
- N-Gage codes: http://www.gamefaqs.com/portable/ngage/code/915353.html
- In polish (Patryk, please translate!): http://www.eplay.yoyo.pl/viewpage.php?page_id=79
- From GSM-Hacks: http://www.gsmhacks.com/forums/mobile-technologies/1429-codes-s60.html
Again, please exercise caution.
Linux on Windows Free Alternative to VMWare! From Microsoft itself! Here is a link on what you can run on it and what changes you need to make in order to install virtual machines under it. Also, some notes on performance:
http://vpc.visualwin.com/index.aspx
Download Virtual PC 2007 For Free from here:
http://www.microsoft.com/windows/products/winfamily/virtualpc/default.mspx
RIM announced that it is going to release a “Virtual BlackBerry” for selected Windows Mobile 6 devices. Now you CAN have the best of both worlds after all
Read more at I4U.
4 days after I posted the “Must Have Applications for your Windows Pocket PC” I received an email saying that I should post the link from xda-developer wiki. Somebody sent it to me… I am not gonna say who, … Somebody
So here it is:
http://wiki.xda-developers.com/index.php?pagename=Must_have_tools
Enjoy
If you have just bought yourself a Windows Mobile 5 or Windows Mobile 6 device and wanted to abuse it right away, then you came to the right place! As you know, nowadays these devices come with wi-fi, bluetooth, hsdpa… etc… Unfortunately though, they do not come bundled with security toys to use these facilities! So, I went searching for you and I found this site that has exactly what you need “Top 10 (free) Security Tools for Windows Mobile”:
http://www.justinclarke.com/archives/2007/04/top_10_free_sec.html
Note the following though:
1. Cain: No matter how fast you think your Pocket PC is, cracking hashes on it is not a good idea
2. btCrawler: You need to change tow registry values (at least) to be able to use the snarfing and bluetab exploits. See: http://msmobiles.com/news.php/5507.html
3. VxUtil: The program creates a directory called “Communications” under the “Programs” directory.
4. WiFiFoFum: Careful! You could drain the battery quickly if you use the bluetooth GPS and the Aggressive mode of scanning.
5. Spybot: It’s good to be prepared!
6. NetCat: Make sure you download the windows and linux versions and keep them on your storage card
netcat tutorials.
7. NbtstatCE: unzip on your pc then copy the exe file to your PPC and run it with the file explorer.
- PocketPutty: Must have of course
Thanks Justin!
Some of the topics discussed in the site might not be legal in some places! So, you’ve been warned. It has tips and tricks for mobile phones of all makes and models with a community supported hacks and forum discussions:
I know many people will look at this and go “We’ve seen this before… Cellular phone spying is not new” but I have to say that the technology is now more readily available than before. To understand what I am talking about, please read the following from zone labs:
- http://blog.zonelabs.com/blog/2007/04/they_can_hear_y.html
- http://blog.zonelabs.com/blog/2007/03/warning_this_ce_1.html
Also, visit this site:
Beware of cellphones left in your office, on your table at a coffee shop and in meetings. The FBI has been doing cell phone spying apparently:
http://www.youtube.com/watch?v=O61YfvPZGJs
On Demand Webcast “Compliance in the Mobile Enterprise” by James Wilcox CISSP. This session will include detailed information about:
- Security considerations for mobile devices, including laptops and handhelds
- An overview of key government regulations and how they apply to mobile deployments
- Strategies to achieve mobile compliance
You can watch the webcast by going here: http://viavid.net/dce.aspx?sid=00003DD7 and filling up your details.
Picture from MobileFanatic
The article below discusses issues that law enforcement agencies have with intercepting VOIP calls on Mobile phone networks and whether traces are left on the devices about the phone calls taking place.
Link: The Australian Newspaper.
A very helpful pdf documents from SEARCH : The National Consortium for Justice Information and Statistics. It highlights some of the hardware and software solutions that can be added to the investigator’s arsenal along with how much each of them costs. The document can be found here:
http://www.search.org/files/pdf/CellphoneInvestToolkit-0806.pdf
A site with links onganized according to different categories in small digital device forensics. It could be a place holder for a future more in-depth site.

The “Cryptography, Law Enforcement, and Mobile Communications ” article in IEEE’s Security and Privacy magazine sheds some light on the use of flashers in mobile forensics as well as the use of tools such as XRY. The article also mentions the use and importance of Faraday cages.
Here is a link to the full article:
Link.
Thanks to Mike for the following two part series of documents on working with flashers:
Part 1:
http://mobileforensics.files.wordpress.com/2007/04/hex-primer-pt-1.pdf
Part 2:
http://mobileforensics.files.wordpress.com/2007/04/hex-primer-pt-ii.pdf
Make sure that you visit his blog to learn more about advanced mobile device forensics:
http://mobileforensics.wordpress.com/
Read what Prof. Rick Mislan said about the use of Phone Flasher Technologies and their role in the acquisition stage of mobile phone forensics and their use by students in digital forensics courses at Purdue University in the US.
The official site for Western Australia’s Digital Forensics Practitioner Interest Group (DFPIG) is now active. If you live in Western Australia and you are interested in Digital forensics, then you should come to our meetings in Edith Cowan University. For times and dates, please visit the official site at:

Matt’s Blog is not frequently updated but his site crypto.com is an excelent resource for all kinds of information. Make sure you check it out.

A dual phone with GSM and VOIP and running Windows Mobile Smartphone Edition. Sounds like it is going to run Windows Mobile 6 by the time it’s going to be released. Find out more on:
http://www.engadgetmobile.com/2007/03/28/zyxel-launches-the-v660-smartphone/

Ever wanted to show your mobile screen on a computer screen or a projector? You can now with Project-A-Phone! A picture is worth a thousand words.
Some interesting research topics from Purdue Uni. related to mobile phone forensics under Prof. Rick Mislan:
Click here to visit the site.
Otherwise, their main pages are found here:
http://www.cyberforensics.purdue.edu/DNN/
The Mobile Forensics blog by Michael Harrington has useful information on: SMS forensics, phone flashers, Faraday cages, forensics seizure procedures and much more. The site also includes posts on the forensic examination of BlackBerry devices. The blog was created in February 2007.
You can visit the blog here:
http://mobileforensics.wordpress.com/
The blog is frequently updated and links to Michael’s http://www.mobile-examiner.com/ website. This site has online training and on-location training and it also has mobile forensic tools and a forum.

CellDEK™ is a portable handset data extraction kit designed for use at the scene of a crime and all working environments associated with on-going investigations. The kit is fully integrated within a ruggedised briefcase. It has approximately 10 hours of battery life and can be recharged through a vehicle, or mains electrical source. The website for the product is here:
http://www.celldek.com
More information is also available through logicube:
http://www.logicubeforensics.com/products/hd_duplication/celldek.asp
It is privided in the UK by the Forensic Science Service® (FSS) a provider of forensic supplies to police forces in England and Wales. The FSS is also a source of training, consultancy and scientific support. FSS can be reached here:
http://www.forensic.gov.uk/
Visit the google-translated Japanese website below to see the Internet from a Japanese prespective. http://64.233.179.104/translate_c?hl=en&u=http://internet.watch.impress.co.jp/&prev=/search%3Fq%3Dmarwan%2Bal-zarouni%26start%3D40%26hl%3Den%26rls%3DGGLJ,GGLJ:2006-50,GGLJ:en%26sa%3DN

News, exploits, papers, views, and releases from information security enthusiasts. Has links to major hacker related security events as well. http://www.thc.org/
The project is looking for smart people (like you) to join in the fun. They are trying to build a cheap GSM scanner/receiver by using an ettus hardware board and the gnu-radio software. The reason the project got started is because GSM scanners cost a heap of money and that the builders of the site believe that the price is exaggerated and they could build a scanner/receiver for under a $1000 USD. This project’s aim is to help researchers learn more about GSM traffic or at least we hope so!
Need more info? Go here:
The project is looking for smart people (like you) to join in the fun. They are trying to build a cheap GSM scanner/receiver by using an ettus hardware board and the gnu-radio software. The reason the project got started is because GSM scanners cost a heap of money and that the builders of the site believe that the price is exaggerated and they could build a scanner/receiver for under a $1000 USD. This project’s aim is to help researchers learn more about GSM traffic or at least we hope so!
Need more info? Go here:
http://scratchpad.wikia.com/wiki/Gsm
The agent files are installed in the root of a USB mass storage devices, such as a USB flash drives, digital cameras and iPods. The agent prompts the user to “install USB Device Driver” which is social engineering the thief into running the agent’s IP tracking and sending code! For more details visit their how it works section on:
Yet another clever use of The pop-up window of USB devices. Best of all, the basic service is currently free
Check it out:
http://www.wireshark.org/
Same developers, same code, different name. Reason: copyright issues I guess!
Venue: Sheraton by the Creek,Dubai, UAE.
Duration: 2-5 April 2007
Details:
Date: 2nd April 2007
Time: 0900 - 1800
Item: 4-tracks Hands-On Technical Training (Day 1)
Date: 3rd April 2007
Time: 0900 - 1800
Item: 4-tracks Hands-On Technical Training (Day 2)
Date: 4th April 2007
Time: 0800 - 1600
Item: Dual Track Security Conference & Capture The Flag ‘Live Hacking’ Competition (Day 1)
Date: 5th April 2007
Time: 0800 - 1600
Item: Dual Track Security Conference & Capture The Flag ‘Live Hacking’ Competition (Day 2)
Hands-On Technical Training
TECH TRAINING 1 - Advanced Web Application & Services Hacking
Trainer: Shreeraj Shah (Director, Net-Square)
TECH TRAINING 2 - Tactical VoIP : Applied VoIPhreaking
Trainer: The Grugq (Independent Network Security Researcher)
TECH TRAINING 3 -Structured Network Threat Analysis and Forensics
Trainer: Meling Mudin (spoonfork) and Lee Chin Shing (geek00l)
TECH TRAINING 4 - Packetmastering the Monkey Way
Trainers: Dr. Jose Nazario (Senior Software Engineer, Arbor Networks)
Keynote Speakers
1.) Mikko Hypponen (Chief Research Officer, F-Secure Corp)
2.) Lance Spitzner (Founder, Honeynet Project.)
Invited Speakers (alphabetical order)
1.) Anthony Zboralski (Founder, HERT & PT. Bellua Asia Pacific)
2.) Emmanuel Gadaix (Founder, Telecom Security Task Force, TSTF)
3.) Fabrice Marie (Manager, FMA-RMS Singapore/Malaysia)
4.) Jim Geovedi (Member of HERT & Security Consultant, PT Bellua Asia Pacific)
5.) Dr. Jose Nazario (Senior Software Engineer, Arbor Networks)
6.) Raoul Chiesa (Board of Directors Member@ Mediaservice.net ISECOM Group & TSTF)
7.) Roberto Preatoni (Founder, Zone-H Defacement Mirror)
8.) Shreeraj Shah (Director, Net-Square)
9.) The Grugq (Independent Network Security Researcher)
10.) Window Snyder (Chief Security Something-or-Other, Mozilla Foundation)
Links:
http://conference.hitb.org/hitbsecconf2007dubai/
http://conference.hackinthebox.org/hitbsecconf2007dubai/?p=56
News Links:
http://star-techcentral.com/tech/story.asp?file=/2007/2/5/corpit/20070205183948&sec=corpit
http://www.itp.net/news/details.php?id=23403&category=
Thanks David for the heads up

Important dates:
- Submissions deadline: February 10, 2007 (early submissions are
welcome)
- Decisions communicated: March 1, 2007
The site provides a unique insight and commentary on the information security marketplace. It brings together some of the top minds from a variety of risk-based disciplines. Please visit the site for more information.

Takes place 11th-12th December 2006. In Sheikh Rashid Hall, Dubai International Convention Centre, Dubai, UAE.
Visit their website at: http://www.hackerhalted.ae

What’s this:
- A USB Memory stick.
- A solar powered device.
- An MP3 Player.
- A VoIP device.
- All of the above
- 1,2, and 4 only.
For the answer, go to:
http://www.engadget.com/2006/11/29/a-datas-solar-disk-and-voip-disk/
Read more about it in Engadget Mobile:
Link
Just when you thought mobile phones, USB storage devices, wireless access, and ADSL modems were a threat to your corporate data, here comes a story to make you even more paranoid!
A researcher released a paper describing a way to hide malicious code (rootkits) on graphics and network cards. The paper basically shows how to use Advanced Configuration and Power Interface (ACPI) functions available on almost all motherboards to store and run a rootkit. Sceptical? read the full story and download the PDF here.

Need we say more? My only comment is that I have seen many ATMs with telephone cables in plain sight just begging for a bugging device!
The question of the day is: When will banks understand the importance of ATM device security? (please don’t answer
).
Many thanks to Times Online for the story.
Please read it in full by visiting:
http://www.timesonline.co.uk/article/0,,29389-2453590,00.html
It takes place from August 13 to 15, 2007 in Pittsburgh, USA. Call for Papers is open untill April 6, 2007. For more information, please go to:
http://computer.forensikblog.de/en/2006/10/dfrws_2007.html
As I said before, it’s about time! Now a proof of concept has been released for this DoS attack. Here is the link:
http://www.darknet.org.uk/2006/10/new-firefox-vulnerability-dos-and-remote-code-execution/
To read the bugtrack entry on this issue, go here:
http://seclists.org/bugtraq/2006/Oct/0523.html
The forum is organized by the Dubai School of Government, in partnership with the Ash Institute for Democratic Governance and Innovation, at the Kennedy School of Government - Harvard University. The objective is to facilitate the development of capacity for innovation in the Arab public sector, creating a knowledge base of innovations, and establishing a network of Arab innovators. The purpose of the Forum is to bring together ‘theory’ and ‘practice’ and to create a meeting space for policy makers, governance innovators, academics, social activists, representatives of the media, and all those concerned with improving governance.
Link:
http://www.dsg.ae/iig/conference.htm
Thanks Dr. Bigdeli
At least for now, FireFox 2 is vulnerability free. More on IE7 flaw here:
It is only a matter of time until someone finds the bugs in the new Firefox. People are already blogging about IE7 vs FF2. Here are some links for you:
http://www.chron.com/disp/story.mpl/headline/biz/4282263.html
http://www.webpronews.com/blogtalk/blogtalk/wpn-58-20061019IE7vsFirefoxIE7havingtroublewithGooglesites.html
http://www.chron.com/disp/story.mpl/headline/biz/4282263.html
More information on IE7 on Fahad.com:
http://www.fahad.com/2006/10/microsoft-releases-windows-internet.html
You can download IE7 From here:
http://www.microsoft.com/windows/ie/downloads/default.mspx
and FireFox 2 from here:
http://www.getfirefox.com
Bruce Schneier is a happy man today and so is BT
Read why here:
http://www.btplc.com/News/Articles/Showarticle.cfm?ArticleID=386c1b2f-0860-4afc-8f4a-26a066c12d10
CertMag has releaed their latest reveiw of certifications. They rated certifications from 1-10 according to certian criterias. To read the article go here:
http://www.certmag.com/articles/templates/CM_gen_Article_template.asp?articleid=2401&zoneid=1
Thanks again Clement and Nathalie from http://www.cccure.org/ :)
The guide was written by Karen Kent, Suzanne Chevalier, Tim Grance, and Hung Dang.
The guide presents forensics from an IT view, not a law enforcement view. It is written for incident response teams; forensic analysts; system, network, and security administrators; and computer security program managers who are responsible for performing forensics for investigative, incident response, or troubleshooting purposes.
It also has a wide array of resources for further reading. Highly recommended read and reference for IT professionals.
Download it here:
http://csrc.ncsl.nist.gov/publications/nistpubs/800-86/SP800-86.pdf
Read more about it in here:
http://www.cccure.org/modules.php?name=News&file=article&sid=1023
NIST also released the following four security related guides:
- Guidance for Securing Microsoft Windows XP Home Edition: A NIST Security Configuration Checklist
- Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
- Assessment of Access Control Systems
- Guide to Computer Security Log Management
Read more about them here:
http://www.govtech.net/magazine/channel_story.php/101708
Last but not least, it is worth mentioning that last month, NIST released a document about RFID. Read about it here:
http://www.fcw.com/article96300-10-03-06-Web
Thanks Clement
In August, the IEEE released IEEE.tv, its Internet broadcasting network, which features coverage of IEEE conferences, interviews with IEEE book authors, primers on technology-related careers, and overviews of IEEE products and services.
IEEE.tv comes in two formats: the Member/Basic format, available only to members, can be accessed through the myIEE









