As naked celebrity photos flood the internet since the past weekend, responsibility for the scandal was shifted from the hackers who stole them to a researcher who released the tool that was used to breach the victims' passwords on Apple's iCloud, whose security gaps were exploited by the thieves.
However, one more step in the process used by the perpetrators has been overlooked: a program designed to allow law enforcement authorities and intelligence services to collect data from iPhones, but instead’ of that ended up being used by the criminals themselves.
On the online forum Anon-IB, one of the most popular sites used for anonymously posting nude photos, hackers openly discuss using this software, called EPPB or Elcomsoft Phone Password Breaker, when intercepting victims' data from iCloud backups (backups).
The software is sold by the company Elcomsoft, based in Moscow, and is intended for government security services. In combination with the interception of iCloud passwords via iBrute, the iCloud password cracking application (by the way, it was released on the Github website over the weekend), EPPB allows anyone to mimic the victim's iPhone and download full backups of the phone's files, not just the more limited data from iCloud.com. And already since Tuesday, it continues to be used for the interception of revealing photos, which are posted on the Anon-IB forum.
“Use the script to hack the passwd … use eppb to download the backup”, wrote an anonymous user on Anon-IB, explaining the process to less experienced hackers, “Post your successes here ;-)”.
The Apple nightmare started over the weekend, when hackers began leaking naked photos, including those of Jennifer Lawrence, Kate Upton and Kirsten Dunst. The computer security community quickly “pointed” to iBrute software as responsible, a tool released by security researcher Alexey Troshichev that exploits a flaw in Apple's smart phone tracking application “Find My iPhone” to “break” users' iCloud passwords.
If a hacker can obtain a user's iCloud username and password with iBrute, he can log into the victim's account on iCloud.com and steal the photos. However, if he mimics the user's device with Elcomsoft's tool, then he can download all the iPhone or iPad files as a single folder, as security consultant Jonathan Zdziarski explains in Wired magazine. This gives intruders access to much more data, he says, including videos, apps, contacts, and text messages.
On Tuesday afternoon, Apple issued a statement calling the security breach a “highly targeted attack on usernames, passwords and security issues”, and added that “none of the cases investigated have resulted from any breach in any of Apple’s systems, including iCloud or Find my iPhone.
However, the discussions on Anon-IB make it clear that the attacks are not limited to a few celebrities. And Zdziarski disagrees with Apple's claim about the security of iBrute. Based on the analysis of metadata from Kate Upton's photos, he states confidently that the photos originated from a backup, with a process that aligns with the above, i.e., using EPPB as a breach tool.
If this police tool hadn't existed, we might not have had the leaks we had, adds Zdziarski.
Elcomsoft is one of several software security companies (such as Oxygen and Cellebrite) that analyze smartphone software using reverse engineering methods, to allow law enforcement authorities to collect device data. However, Elcomsoft's program appears to be the most popular on Anon-IB, where it seems to have been used for months before the recent leaks, possibly in cases where hackers were able to steal passwords by other means, aside from iBrute.
Many hackers on Anon-IB offer to steal naked photos on behalf of any other user, who may know the target's Apple ID and password. “Always free, fast and discreet. It will be much easier if you have the password,” writes one of them. Elcomsoft's program does not require credentials and costs 399 dollars, while cracked copies are freely available on bittorrent file‑sharing sites.
Source: directnews.gr

