Mobility Today & Mobile Electronics News

    Home Hardware Store Software Forums News Reviews Podcasts Advertise Contact Us XML Feed
Login or register, it's free!
Recent Mobility Discussions
Instant lock 212 when turned...
Someone has to have figured this out but that someone ain'tn't me... I want my 212 to require a password to access it once I turn it off...
by kennyd, 3 days ago
Recent Mobility Reviews
Recent Mobility News
Mobility Today Store
Mobility Today Forums
Mobility Today Podcasts
Mobility Today Links

Security firm: Don't use iPhone Web dialer


The feature was created to give iPhone users a simple way to dial phone numbers listed on Web pages, but according to SPI, the feature could be misused.

Attackers could exploit a bug in this feature to trick a victim into making phone calls to expensive "900" numbers or even keep track of phone calls made by the victim over the Web, said Billy Hoffman, lead researcher with SPI Labs. The iPhone could even be stopped from dialing out, or set to dial out endlessly, he said.

"Because this vulnerability can be launched from Web sites, everybody who has an iPhone has the potential to get exploited," Hoffman said

In order for the attack to work, the bad guys would have to either trick iPhone users into visiting a malicious Web site or make a legitimate Web site send untrustworthy information to the iPhone using what's known as a cross-site scripting attack. "Any time someone could control the content that's getting sent to the iPhone [the possibility of an attack] exists," Hoffman said.

SPI is not releasing detailed information on how the Web dialing feature could be exploited, but the company contacted Apple on July 6 and is working with the iPhone maker to prevent these types of attacks, Hoffman said. Apple could not be reached immediately for comment.

Because Apple is encouraging software developers to write Web applications for the iPhone that use Safari, the browser has come under particular scrutiny from iPhone hackers.

Researchers had previously noted that Safari could be used to misdial numbers, but Hoffman's post suggests that this could be done more easily than previously thought.

Not everybody thought the SPI findings were groundbreaking, including Dave Aitel, CTO with Immunity Inc. "If you can make calls from the Web browser, you can make fake calls from the Web browser," he said.

So should iPhone users stop using the Web to place calls? "Yes," said Aitel. "If they know a lot of hackers and are a special target."

Via Yahoo

Technorati Tags: , ,

Post your comments
A long time ago I heard this Microsoft joke:

Question: What to you call a Microsoft beta tester?

Answer: A customer.

It would be a shame if this joke now applied to Apple as well.
In lieu of the findings by SPI and Errata Security, I would recommend that no one bother getting in the habit of using the Phone Dialer feature until Apple fixes the flaw.

It is evident that unknowingly (the way most people access a compromised site) accessing a compromised site will allow them to be attacked.
Login or Register to post a comment!