Newsletter:

Skip Navigation LinksHome > News > Security > iPhone security flaws disclosed

iPhone security flaws disclosed

By Egan Orion
5 October 2008 11:26PM
Tags: iphone | security | flaws | disclosed

Security researcher Aviv Raff disclosed two iPhone security flaws Thursday that could allow attackers to trick people into unknowingly surfing to malicious destinations.

He had brought both vulnerabilities to Apple's attention way back in July but the company failed to address them with patches, so he had no choice but to publicly disclose the flaws.

The first flaw exists in iPhone's Mail application and its Safari web browser, which tend to truncate parts of long URLs when they're displayed. That can allow evil-doers to disguise malicious URLs without the user having a chance to view them.

"In most mail clients... you can just hover [over] the link and get a tooltip [showing] you the actual URL that you are about to click," explained Raff. "In iPhone it's a bit different. You need to click the link for a few seconds in order to get the tooltip. Now, because the iPhone screen is small, long URLs are automatically cut off in the middle."

He explained that it's possible for a blackhat to devise a long URL beginning with a trusted domain name but which actually point to an entirely different location. The Iphone user would only see the familiar-looking part of the domain name and therefore might easily be tricked into clicking on a malicious link.

Raff said iPhone Mail is also vulnerable because it automatically downloads images linked in HTML-formatted emails.

Most email client software allows users to make downloading of images require approval in each instance. Setting that option helps email users protect themselves against spammers, because spammers can learn when they've reached an active email account if the recipient opens a spam email and downloads images.

"This one is not just a trivial bug," Raff said. "It's actually a pretty dumb design flaw, which was already fixed by all other mail clients ages ago."

theinquirer.net (c) 2008 Incisive Media

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch



Product Reviews

Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Star Rating
The Symark PowerBroker is a policy-driven, privileged access control application.
Star Rating
The Symark PowerKeeper is a hardened appliance. It comes with a sealed operating system that provides a...
iTnews 2009 Job Survey

TopTopics
(7264) -  top
(3132) -  microsoft
(2311) -  broadband
(2210) -  content
(2150) -  company
(2120) -  data
(1927) -  terria
(1863) -  isp
(1811) -  nbn
(1720) -  telstra
(1712) -  filtering
(1581) -  internode
(1538) -  voip
(1441) -  centre
(1148) -  consumers