Your iPhone is about to be Rickrolled.
Owners of jailbroken iPhones in Australia reported a worm that appeared to have broken out late last week that uses the default SSH setup to gain access to the phone. The terrifying result? Your background picture is changed to a photo of Rick Astley of “Never Gonna Give You Up” and Rickrolling fame.
The worm infects iPhones that have been jailbroken and have had SSH installed without the default password (“alpine”) being changed. While this particular worm appears to have only humor programmed in, the exploit could obviously be used by hackers with more malicious intent.
Security firm Sophos has reported the following:
SophosLabs is analysing the worm’s code, which suggests that at least four variants have been written so far. One of the attributes of the latest variant (labelled the “D” version) is that it tries to hide its presence by using a filepath suggestive of the Cydia application.
The source code is littered with comments from the author suggesting the worm has been written as an experiment. One of the comments berates affected users for not following instructions when installing SSH, because if they had changed the default password the worm would not have been able to infect them.
Owners of jailbroken iPhones are encouraged to inspect their phone’s security level, including changing that default SSH password when necessary.

