How iCloud was hacked and the nudes were leaked
So as you all know iCloud was allegedly hacked and all those celebs who stored nudes in the cloud are all fucked.
So here's what happened.
Apple released a find my iphone API and one function allowed users to login. Pretty straight forward. The only problem with this is that it didn't lock you out for too many failed login attempts making it vulnerable to a brute-force attack. So all that was needed was the celebs emails and some nice password lists.
This is now patched, but anyone who wants to learn more can check out the PoC here:
[Hidden content]