iphone flaws and apple didn't pay any attention when they were posted by a researcher
Apple is arguably getting more proactive about iPhone security exploits. The iPhone OS 2.0 release fixed quite a few bugs, and last month's 2.1 update was no security slouch either. Still, in the face of Apple recruiting full-time iPhone hackers, an Israeli researcher has released details on two potentially dangerous—though seemingly innocuous—design flaws that he says the company has ignored for too long.
Explained on his blog (hat tip to MacNN), Aviv Raff says that two particular behavioral choices—but not necessarily security holes—in iPhone's Mail application can lead to phishing and spamming exploits. The first involves URL redirections due to the unique way Mail displays the actual URL of a linked portion of text. Mail will display the full text of a URL in a message, but a tap-and-hold operation on the URL will truncate its address in a popup tooltip if it's longer than ~24 characters. If a malicious attacker exploits this URL display disparity the right way. According to Raff's example, a URL in a Mail message could read "https://securelogin.facebook.com/reset.php?cc=534a556abd1006&tt=1212620963," but actually link to a page at "http://securelogin.facebook.com.avivraff.com/."
The iPhone's next security problem stems from Mail's affinity for automatically downloading images in most messages unless they are significantly large or there are too many attachments. Most e-mail clients (including Mail on the desktop) offer various safeguards around this behavior, including preferences for downloading images from contacts in an address book or simply requiring all images to be manually downloaded on a per-message basis. Since the iPhone offers no such preferences, an image in a spam message will automatically download, verifying to the spammer that the address is active and ripe for more spam.












Comments
sick!!, i knew that iphone would suck... most of the apple products are ment to show pure richness, rather style... most of the ppl believe that ipod video is amongst the best mp3/mp4 player in the world... but hardly few know that creative does make a similar type of player which has a far superior technology hard wired into it!!
when it comes to desktops and laptops, its very nice!!
creative has been rocking since it was established. yeah it had some downfall for cdroms i suppose. its cdroms are no more available i think.
Nilesh Govindrajan
Site & Server Administrator
iTech7
Post new comment