Cell Phone News

Apple iPhone phishing vulnerability revealed – Fortify Software warns of embedded links

By Will Park on Friday, July 20th, 2007 at 12:14 PM PST In Announcements, Apple, Security, iPhone, iPhone OS

iPhone targetThey’re out to get you. Hackers the world over are gunning for the iPhone – and not all of them are working for the good guys (unlocking the iPhone to work on non-AT&T (NYSE: T) networks is a good thing). Security firm Fortify Software reveals a couple things about the iPhone that make a hacker’s job a little easier. We’re using the term “hacker” a bit loosely here – these securtiy holes are really more like phishing vulnerabilities.

For one thing, your iPhone won’t display the URL of a link embedded into an email, making it easier to trick you into pointing your Safari browser to a scam-a-licious website. Which brings us to our next security flaw. The address bar in Safari displays only a partial URL, making it even easier to hide disguise said scam-a-licious site.

And then there’s the integration of Safari into the iPhone. Brian Chess explains that, “you can embed a telephone number in a web page like this:

<a id=”phone_home” href=”tel:1-900-867-5309″>call me!</a>
You can also write JavaScript that causes the iPhone to initiate the dialing process:<script>
window.document.url = “tel:1-900-867-5309″
</script>”

Now that’s a sobering thought – to think that the iPhone’s dialing function can be hijacked via JavaScript. But then again, you are prompted to initiate the call.  We’re gonna say that the iPhone is still a fairly secure platform.

[Via: Tech.co.uk]

Share this:
  • Digg
  • Facebook
  • StumbleUpon

Related News from IntoMobile

One Comment on “Apple iPhone phishing vulnerability revealed – Fortify Software warns of embedded links”

  1. Trance says:

    You wrote:
    “For one thing, your iPhone won’t display the URL of a link embedded into an email,”

    But actually, pressing and holding a URL in mail will show you the link, just as it does in Safari.

What are your thoughts? Leave a comment...

How do I change my avatar?
Go to gravatar.com and upload your preferred avatar



Sign in with Twitter: