Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


1024kb

1197 posts

Uber Geek
+1 received by user: 519

ID Verified
Lifetime subscriber

#322610 4-Sep-2025 14:00
Send private message

Here's one for ya. Operation Humbug reveals a critical vulnerability in Apple's activation process. This is about as horrific as it gets - Apple's activation server does not require authentication. Any old xml data sent is accepted. Apple haven't responded to the disclosure which already has a published Proof of Concept.

 

Operation Humbug full diclosure here.

 

Proof Of Concept  here.

 

NB: This is not a crafted attack, Humbug is the discovery of an incredibly insecure method of making a vital transaction.

*Edit - correct my links.





Megabyte - so geek it megahertz

Create new topic
matthew234
1 post

Wannabe Geek
+1 received by user: 2


  #3411518 5-Sep-2025 11:45
Send private message

I would take it with a grain of salt - Reddit discussions suspect the vulnerability is an AI hallucination. 

 


https://www.reddit.com/r/sysadmin/comments/1l1wzna/unpatched_ios_activation_vulnerability_allows/

 

https://www.reddit.com/r/cybersecurity/comments/1l1wx97/comment/mvraxcf/

 

 




Behodar
11093 posts

Uber Geek
+1 received by user: 6070

Trusted
Lifetime subscriber

  #3411519 5-Sep-2025 11:47
Send private message

Reddit: There's not actually anything here. You've noted that a HTTP endpoint always responds with a 200 and then the rest is pure speculation. You haven't even attempted to show that any of this speculation might be valid.

 

If there is a vulnerability here then it's not demonstrated by anything that you've written.

 

That's exactly what I was thinking when I was first reading the thing. "We found an HTTP endpoint" is not (necessarily) a vulnerability, and there were no further details.


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.