{"id":176418,"date":"2013-06-04T17:00:00","date_gmt":"2013-06-04T15:00:00","guid":{"rendered":"https:\/\/cms.galaxiemedia.fr\/tomshardware\/2013\/06\/04\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/"},"modified":"2023-06-22T16:18:56","modified_gmt":"2023-06-22T14:18:56","slug":"exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions","status":"publish","type":"post","link":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/","title":{"rendered":"Exclu : une faille iOS permet une attaque en force brute sur les restrictions"},"content":{"rendered":"

Il y a quelques jours, lors d’un petit test<\/a>, nous avons d\u00e9couvert une faille dans iOS<\/strong>, utilisable sur l’iPad et l’iPhone. Elle permet d’effectuer une attaque en force brute contre le code utilis\u00e9 pour mettre en place les restrictions (le contr\u00f4le parental) sous iOS, malgr\u00e9 les protections d’Apple.<\/p>\n\n

<\/p>\n\n

Une protection inefficace<\/h4>\n\n

<\/p>\n\n

iOS propose de mettre un code pour restreindre l’acc\u00e8s \u00e0 certaines fonctions (la cam\u00e9ra, l’installation d’applications, etc.). Ce code est constitu\u00e9 de 4 chiffres, ce qui donne seulement 10 000 possibilit\u00e9s. Il est donc envisageable de tester toutes les combinaisons pour d\u00e9couvrir le code, et Apple s’en rend bien compte : par d\u00e9faut, le clavier virtuel est rendu inop\u00e9rant apr\u00e8s un certain nombre d’essais rat\u00e9s. Apr\u00e8s 6 essais, il est bloqu\u00e9 pendant 1 minute, puis chaque mauvais code ajoute du temps : 5, 15 puis 60 minutes entre chaque essai. Mais il y a une faille<\/strong>.<\/p>\n\n

<\/p>\n\n

Un clavier physique<\/h4>\n\n

<\/p>\n\n

Elle est assez simple : il suffit d’utiliser un clavier physique. En effet, les claviers physiques restent fonctionnels m\u00eame si le clavier virtuel est bloqu\u00e9. On peut donc utiliser un clavier Bluetooth sur iPad, iPhone ou iPod touch, le dock \u00e9quip\u00e9 d’un clavier sur un iPad ou m\u00eame un clavier USB classique avec l’adaptateur pour appareils photo sur l’iPad.<\/p>\n\n

<\/p>\n\n

Syst\u00e9matiser l’attaque<\/h4>\n\n

<\/p>\n\n

\"ImageLa carte Teensy 3.0<\/span><\/span><\/span>S’il est possible de tester toutes les possibilit\u00e9s manuellement, c’est assez fastidieux. Nous avons donc utilis\u00e9 une carte de d\u00e9veloppement Teensy 3.0<\/strong>. Cette petite carte permet en effet d’\u00e9muler un clavier USB et avec un peu de code, il est possible de syst\u00e9matiser l’attaque. Concr\u00e8tement, il suffit de brancher la carte \u00e0 un iPad avec l’adaptateur USB et de la laisser tester toutes les possibilit\u00e9s. Nous l’avons programm\u00e9 pour tester une combinaison toutes les 3 secondes environ, ce qui permet de trouver le code en un peu plus de 8 heures dans le pire des cas.<\/p>\n\n

<\/p>\n\n

La vid\u00e9o montre un court exemple, avec le code 0015 : si l’interface indique qu’il faut attendre, notre carte teste tout de m\u00eame toutes les possibilit\u00e9s. Nous avons test\u00e9 sur un iPad 3 et un iPad 1 avec succ\u00e8s, mais l’attaque fonctionne aussi sur l’iPhone en Bluetooth.<\/p>\n\n

<\/p>\n\n<\/p>\n\n

\n\t\n\t\n\t
Attaque en force brute contre iOS<\/div>\n<\/div>\n\n

\n\n\n

<\/p>\n\n

Notons que nous avons bien \u00e9videmment pr\u00e9venu Apple, que la faille est fonctionnelle dans la derni\u00e8re version d’iOS (6.1.3) et le code demand\u00e9 sur l’\u00e9cran d’accueil n’est par contre pas touch\u00e9 par cette faille : l’appareil est bien bloqu\u00e9 apr\u00e8s plusieurs codes erron\u00e9s.<\/p> ","protected":false},"excerpt":{"rendered":"

Il y a quelques jours, lors d'un petit test, nous avons d\u00e9couvert une faille dans iOS, utilisable sur l'iPad et l'iPhone.<\/p>","protected":false},"author":36,"featured_media":176419,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"footnotes":""},"categories":[487,4112],"tags":[576],"hubs":[],"acf":{"post_show_excerpt":false,"post_source":{"title":"Tom's Hardware FR","url":"https:\/\/www.tomshardware.fr\/","target":""}},"yoast_head":"\nExclu : une faille iOS permet une attaque en force brute sur les restrictions<\/title>\n<meta name=\"description\" content=\"Il y a quelques jours, lors d'un petit test, nous avons d\u00e9couvert une faille dans iOS, utilisable sur l'iPad et l'iPhone.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Exclu : une faille iOS permet une attaque en force brute sur les restrictions\" \/>\n<meta property=\"og:description\" content=\"Il y a quelques jours, lors d'un petit test, nous avons d\u00e9couvert une faille dans iOS, utilisable sur l'iPad et l'iPhone.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/\" \/>\n<meta property=\"og:site_name\" content=\"Tom\u2019s Hardware\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/TomsHardwareFrance\/\" \/>\n<meta property=\"article:published_time\" content=\"2013-06-04T15:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-22T14:18:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"549\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Pierre Dandumont\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@tomshardware_fr\" \/>\n<meta name=\"twitter:site\" content=\"@tomshardware_fr\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/\"},\"author\":{\"name\":\"Pierre Dandumont\",\"@id\":\"https:\/\/www.tomshardware.fr\/#\/schema\/person\/17966383cb6059d95d48bbdb852df076\"},\"headline\":\"Exclu : une faille iOS permet une attaque en force brute sur les restrictions\",\"datePublished\":\"2013-06-04T15:00:00+00:00\",\"dateModified\":\"2023-06-22T14:18:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/\"},\"wordCount\":454,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.tomshardware.fr\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg\",\"keywords\":[\"Apple\"],\"articleSection\":[\"Actualit\u00e9\",\"S\u00e9curit\u00e9\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/\",\"url\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/\",\"name\":\"Exclu : une faille iOS permet une attaque en force brute sur les restrictions\",\"isPartOf\":{\"@id\":\"https:\/\/www.tomshardware.fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg\",\"datePublished\":\"2013-06-04T15:00:00+00:00\",\"dateModified\":\"2023-06-22T14:18:56+00:00\",\"description\":\"Il y a quelques jours, lors d'un petit test, nous avons d\u00e9couvert une faille dans iOS, utilisable sur l'iPad et l'iPhone.\",\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#primaryimage\",\"url\":\"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg\",\"contentUrl\":\"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg\",\"width\":800,\"height\":549},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.tomshardware.fr\/#website\",\"url\":\"https:\/\/www.tomshardware.fr\/\",\"name\":\"Tom\u2019s Hardware\",\"description\":\"Toute l'info hardware et gaming !\",\"publisher\":{\"@id\":\"https:\/\/www.tomshardware.fr\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.tomshardware.fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.tomshardware.fr\/#organization\",\"name\":\"Tom\u2019s Hardware\",\"url\":\"https:\/\/www.tomshardware.fr\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.tomshardware.fr\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2023\/06\/th.png\",\"contentUrl\":\"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2023\/06\/th.png\",\"width\":1000,\"height\":1000,\"caption\":\"Tom\u2019s Hardware\"},\"image\":{\"@id\":\"https:\/\/www.tomshardware.fr\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/TomsHardwareFrance\/\",\"https:\/\/x.com\/tomshardware_fr\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.tomshardware.fr\/#\/schema\/person\/17966383cb6059d95d48bbdb852df076\",\"name\":\"Pierre Dandumont\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.tomshardware.fr\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a08bb358c2a9fc36265e8f3225c5de08?s=64&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a08bb358c2a9fc36265e8f3225c5de08?s=64&d=mm&r=g\",\"caption\":\"Pierre Dandumont\"},\"url\":\"https:\/\/www.tomshardware.fr\/author\/pierre-dandumont\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Exclu : une faille iOS permet une attaque en force brute sur les restrictions","description":"Il y a quelques jours, lors d'un petit test, nous avons d\u00e9couvert une faille dans iOS, utilisable sur l'iPad et l'iPhone.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/","og_locale":"fr_FR","og_type":"article","og_title":"Exclu : une faille iOS permet une attaque en force brute sur les restrictions","og_description":"Il y a quelques jours, lors d'un petit test, nous avons d\u00e9couvert une faille dans iOS, utilisable sur l'iPad et l'iPhone.","og_url":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/","og_site_name":"Tom\u2019s Hardware","article_publisher":"https:\/\/www.facebook.com\/TomsHardwareFrance\/","article_published_time":"2013-06-04T15:00:00+00:00","article_modified_time":"2023-06-22T14:18:56+00:00","og_image":[{"width":800,"height":549,"url":"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg","type":"image\/jpeg"}],"author":"Pierre Dandumont","twitter_card":"summary_large_image","twitter_creator":"@tomshardware_fr","twitter_site":"@tomshardware_fr","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#article","isPartOf":{"@id":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/"},"author":{"name":"Pierre Dandumont","@id":"https:\/\/www.tomshardware.fr\/#\/schema\/person\/17966383cb6059d95d48bbdb852df076"},"headline":"Exclu : une faille iOS permet une attaque en force brute sur les restrictions","datePublished":"2013-06-04T15:00:00+00:00","dateModified":"2023-06-22T14:18:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/"},"wordCount":454,"commentCount":0,"publisher":{"@id":"https:\/\/www.tomshardware.fr\/#organization"},"image":{"@id":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#primaryimage"},"thumbnailUrl":"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg","keywords":["Apple"],"articleSection":["Actualit\u00e9","S\u00e9curit\u00e9"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/","url":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/","name":"Exclu : une faille iOS permet une attaque en force brute sur les restrictions","isPartOf":{"@id":"https:\/\/www.tomshardware.fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#primaryimage"},"image":{"@id":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#primaryimage"},"thumbnailUrl":"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg","datePublished":"2013-06-04T15:00:00+00:00","dateModified":"2023-06-22T14:18:56+00:00","description":"Il y a quelques jours, lors d'un petit test, nous avons d\u00e9couvert une faille dans iOS, utilisable sur l'iPad et l'iPhone.","inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.tomshardware.fr\/exclu-une-faille-ios-permet-une-attaque-en-force-brute-sur-les-restrictions\/#primaryimage","url":"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg","contentUrl":"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2013\/06\/dsc02750.jpg","width":800,"height":549},{"@type":"WebSite","@id":"https:\/\/www.tomshardware.fr\/#website","url":"https:\/\/www.tomshardware.fr\/","name":"Tom\u2019s Hardware","description":"Toute l'info hardware et gaming !","publisher":{"@id":"https:\/\/www.tomshardware.fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.tomshardware.fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/www.tomshardware.fr\/#organization","name":"Tom\u2019s Hardware","url":"https:\/\/www.tomshardware.fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.tomshardware.fr\/#\/schema\/logo\/image\/","url":"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2023\/06\/th.png","contentUrl":"https:\/\/www.tomshardware.fr\/content\/uploads\/sites\/3\/2023\/06\/th.png","width":1000,"height":1000,"caption":"Tom\u2019s Hardware"},"image":{"@id":"https:\/\/www.tomshardware.fr\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/TomsHardwareFrance\/","https:\/\/x.com\/tomshardware_fr"]},{"@type":"Person","@id":"https:\/\/www.tomshardware.fr\/#\/schema\/person\/17966383cb6059d95d48bbdb852df076","name":"Pierre Dandumont","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.tomshardware.fr\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a08bb358c2a9fc36265e8f3225c5de08?s=64&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a08bb358c2a9fc36265e8f3225c5de08?s=64&d=mm&r=g","caption":"Pierre Dandumont"},"url":"https:\/\/www.tomshardware.fr\/author\/pierre-dandumont\/"}]}},"_links":{"self":[{"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/posts\/176418"}],"collection":[{"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/users\/36"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/comments?post=176418"}],"version-history":[{"count":0,"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/posts\/176418\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/media\/176419"}],"wp:attachment":[{"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/media?parent=176418"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/categories?post=176418"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/tags?post=176418"},{"taxonomy":"hubs","embeddable":true,"href":"https:\/\/www.tomshardware.fr\/wp-json\/wp\/v2\/hubs?post=176418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}