The document summarizes a security audit performed on an iPhone. The researcher was able to gain root access to the iPhone using a default password for OpenSSH. They then analyzed over 2000 property list files, converting them to XML and searching for personal information like names, phone numbers, emails and call logs. The researcher extracted a significant amount of private data and notes that with malicious intent, data could also have been deleted or erased without a trace. Recommendations include changing default passwords, limiting app access to data, and not leaving wireless connections active when not in use.
Related topics: