Security flaw allows full access to locked iPhones


[greenmymac] on the MacRumors forums recently exposed a security flaw that allows anyone full access to a locked iPhone running firmware version 2.0.2. The flaw works by entering the emergency call menu of a locked iPhone, and double tapping the home button. This opens the iPhone's Favorites menu, allowing anyone in your Favorites to be called. From here, an attacker has access to your SMS messages and potentially your email or Safari browser. While we are sure that Apple has a patch for this flaw on the way in the next firmware update, there is a temporary way to secure your locked iPhone. Simply enter the Settings menu on your iPhone and enter General > Home Button and select "Home" or "iPod". Now when you double tap your home button, it will navigate to either your home screen or the iPod screen. While this fix might be annoying for some, as of right now it seems like the only way to secure your locked iPhone.

[photo: Refracted Moments™]

[via Gizmodo]

Ubiquity, a browser command line


During the last day the web has been abuzz about Mozilla Labs' Ubiquity. It's an addon for Firefox that can help you streamline how you get things done on the web. In the example above, they show constructing an email with a map and reviews using mostly keyboard driven input. The addon is quick to install and we think you'll find it saving you a lot of time on tasks you'd normally hit the search box for. In the popup, you can do quick Wikipedia lookups, define words, translate, perform calculations, and many other operations. You can email a page to someone by just typing three words. The best part is: anyone can write a command that will expand Ubiquity's function. Greasemonkey helped fix broken websites and we think Ubiquity will help make interactions between sites much easier. We can't wait to see what clever uses people come up with.

Quick AVR


[Kyle Stewart] sent us this quick AVR project. He designed it to sit vertically on his breadboard to take up less space. It doesn't use any surface mount components, to make the assembly easier. You can download the schematic, parts list, and eagle files for the project on his blog.

High school students hacking electronic tests


[Alex Papadimoulis] wrote about ingenuity and hacking in high school. Immediately after the teacher's installed a new electronic note taking and test giving software, the students began hacking. They managed to find several ways to ace their tests, none of which involved studying hard the night before. Ultimately, the teachers went back to the old system to prevent such shenanigans.

[photo: COCOEN]

Create your own playlist hosting service with Opentape


While Muxtape takes a breather to resolve an issue with the RIAA, Lifehacker has a step by step guide on installing and running Opentape, an open source PHP web application that's similar to Muxtape. Take matters into your own hands and create your own version of playlist hosting heaven. Since Opentape is open source, you can adapt it and make it an even better application. Maybe your creation will be even more popular than Muxtape... and will lead to the same problems with the RIAA.

Testing IR camera blocking

[randy] from F.A.T. tested the theory that infrared LEDs can actually hide you from the prying eyes of surveillance cameras. We've previously covered camouflage, IR, and other suggestions for eluding the cameras, but haven't taken to sewing stuff onto our clothes yet. [randy] lined his hoodie with high-intensity infrared LEDs, hoping to create a halo effect that would hide his head, and tested his results. Unfortunately, his efforts were unsuccessful. He tested many many different combinations and we're confident in his conclusion that it would be very hard to make this work.

RC plane sequence caller


Reader [Kelly Regan] flies large scale RC planes, but would often need someone call out flight sequences while rehearsing. Not wanting to impose on fellow club members, [Kelly] built a sequencer caller from a cheap MP3 player. It just required extending the FWD key to a pin header. Those pins are connected to a custom switch on the back of the controller. Each maneuver is recorded with 30 seconds of padding and then added to a playlist. Once the maneuver is complete, a quick press of the button moves on to the next track. It's always nice to see people building devices that the consumer electronics industry probably wouldn't.

Key features cut out of Android API


Google has decided that its initial release of the Android SDK will not include formal Bluetooth support or Google Talk. Bluetooth headsets will still work, but developers will not have access to the Bluetooth portion of the API. Google's security researchers have announced that Google Talk was left out because of multiple security concerns. Bluetooth, on the other hand, was left out because the development team ran out of time.

Out of these two features, we think users are going to be most disappointed by the omission of Google Talk. Chatting has become one of the most useful features of new smart phones. The ability to just chat instead of sending a text message is one of the main attractions to phones like the iPhone, which has support for AIM.

[photo: dreamside]

IBM sees influx in zero-day exploits


IBM's X-Force security team has released a mid-year report(PDF) stating that the number of zero-day exploits is growing at an alarming rate. For those of you unfamiliar with the term, a zero-day exploit is a program that is created and implemented within 24 hours of the disclosure of a security flaw. These exploits usually affect users before they even know the vulnerability exists and long before a patch is made available. The researchers also found that many of these exploits were targeted at browser plug-ins, which most users utilize on a daily basis.

[Kris Lamb], X-Force operations manager, is blaming the problem on a lack of a unified process for disclosing vulnerabilities. He also claims that the long-held practice of publishing example code of vulnerabilities should be frowned upon.

[via Liquidmatrix]

Coyote-1 guitar pedal available now


OpenStomp's Coyote-1 is now available for $349. The guitar effects pedal lets users design and upload their own effects to the device. It has two stomp switches with LEDs, an LCD display, and four user assignable knobs. The back has 1/4" in/out and one selectable 1/4". It also features NTSC composite out, a headphone jack, mini-USB for uploading, and an RJ11 I2C bus for expansion. The processor is a Parallax Propeller Chip. While the OS on the pedal is open source, the hardware design and effect design software are not. You can check out the source and product manual on their forum. If you're more interested in breadboarding hardware, you might like the Beavis Board we covered earlier.

[via Create Digital Music]

Large Hadron Collider user manual online


If you've got a few hours (or weeks) of spare time, you could learn how to run the Large Hadron Collider, located at CERN in Switzerland. CERN published the full technical details of the collider and detectors online, and anyone with some curiosity and patience can read all 1,589 pages. Tell us if you got through all of it, and if you're planning to make your own particle accelerator.

[via MetaFilter]

Customers make VoIP calls on American Airlines flights


Less than a week after American Airlines introduced in-flight internet, hackers have already figured out how to use the system to make VoIP calls in a few easy steps with Phweet, a Twitter application. While the network blocks most VoIP services, Phweet can connect two people using a Flash app. Aircell, the company responsible for the system, is aware of the oversight, but it remains to be seen whether this little loophole will be fixed in a timely manner. Meanwhile, we encourage those of you who do fly on American Airlines to avoid making those phone calls; your neighbor would probably appreciate it.

[via Digg]

World Of Warcraft on a treadmill


[Aaron Rasmussen] and his friend [Eli] slapped together this setup to see what it would be like to run as much as their World of Warcraft characters. They used a couple old treadmills to spin some tires with makeshift mouse sensors on them. As their speed increased, so did their character. There was a decent amount of math done to figure the average speed of a World of Warcraft character, and ultimately they settled on 12 miles per hour. Not surprisingly, they found that too difficult due to the resistance in the rig as well as being out of shape. They ended up lowering the speed required to make their character go full sprint to 6 miles per hour.

Their final conclusion was that they could never run as much as their digital counterparts. Even if they were in really good shape. [Aaron] does say that it was fun enough to consider doing it regularly as a workout plan. He should wear the costume every time he uses it.

Monster truck lawn mower


It's no secret that we're gear heads at heart. Our transportation hacks category is full of unfortunate machinery like [Steven Laurie]'s motor art, weed whacker bikes, and electric motorcycles of all types. Even we have trouble justifying the existence of this monster truck style lawn tractor though. We haven't found a project site for it and can't help but wonder what kind of person would build such a thing? It's obviously the type that would own a car sized American flag. We just need to realize with the popularity of lawn mower racing, this sort of thing was bound to happen.

[via Toolmonger]

James Powderly released


Graffiti Research Lab's [James Powderly] along with 9 other Tibet supporters were deported from China during the Olympic's closing ceremonies. Detained on the 19th, the activists were to serve a 10 day sentence, but the Chinese government buckled under international pressure and deported them early. This brings the total number of deported activists to 53 since the start of the games.

Graffiti Research Lab is well known for its laser tagging research.

Next Page >

hack a day serves up a fresh hack each day, every day from around the web and a special how-to hack each week.

send us your hacks

have a hack you'd like to see here? tell us about it

Hacks
aibo hacks (1)
cellphones hacks (79)
cons (78)
contests (28)
daily (112)
digital audio hacks (15)
digital cameras hacks (71)
downloads hacks (16)
gameboy hacks (34)
google hacks (5)
gps hacks (35)
HackIt (20)
handhelds hacks (59)
home entertainment hacks (146)
home hacks (21)
how-to (16)
ipod hacks (75)
laptops hacks (51)
laser hacks (32)
macs hacks (40)
misc hacks (819)
news (187)
pcs hacks (145)
peripherals hacks (184)
playstation hacks (52)
podcasts (8)
portable audio hacks (43)
portable video hacks (27)
robots hacks (108)
roundup (3)
security hacks (55)
solar hacks (1)
tablet pcs hacks (6)
tivo hacks (6)
tool-hacks (10)
transportation hacks (90)
wii hacks (18)
wireless hacks (84)
xbox hacks (51)

resources

rss newsfeeds

Powered by Blogsmith