Holiday Gift Guide »

Apple iPhone phishing vulnerability revealed – Fortify Software warns of embedded links

By: , IntoMobile
Friday, July 20th, 2007 at 12:14 PM

iPhone targetThey’re out to get you. Hackers the world over are gunning for the iPhone – and not all of them are working for the good guys (unlocking the iPhone to work on non-AT&T networks is a good thing). Security firm Fortify Software reveals a couple things about the iPhone that make a hacker’s job a little easier. We’re using the term “hacker” a bit loosely here – these securtiy holes are really more like phishing vulnerabilities.

For one thing, your iPhone won’t display the URL of a link embedded into an email, making it easier to trick you into pointing your Safari browser to a scam-a-licious website. Which brings us to our next security flaw. The address bar in Safari displays only a partial URL, making it even easier to hide disguise said scam-a-licious site.

And then there’s the integration of Safari into the iPhone. Brian Chess explains that, “you can embed a telephone number in a web page like this:

<a id=”phone_home” href=”tel:1-900-867-5309″>call me!</a>
You can also write JavaScript that causes the iPhone to initiate the dialing process:<script>
window.document.url = “tel:1-900-867-5309″
</script>”

Now that’s a sobering thought – to think that the iPhone’s dialing function can be hijacked via JavaScript. But then again, you are prompted to initiate the call.  We’re gonna say that the iPhone is still a fairly secure platform.

[Via: Tech.co.uk]

About The Author

Will Park

Will hails from The City of Angels - Los Angeles, California. He spends his time playing with his numerous gadgets and looking forward to seeing what future holds for mobile technology. An avid promoter of a fully "digital" life, he promotes the widespread adoption of truly mobile, paper-less living. He dreams of the day when he can go completely digital. No more snail mail, paper receipts, bound books, notepads/spiral notebooks, credit cards, hard currency. He's a digital warrior - fighting for the converged life. He is an idealist and a realist - he has a perfect view of what the world should be but knows that the world is not perfect. Can we ever hope to see Will's dream become reality? We'll see...

  • Trance

    You wrote:
    “For one thing, your iPhone won’t display the URL of a link embedded into an email,”

    But actually, pressing and holding a URL in mail will show you the link, just as it does in Safari.