West Technology Limited’s Weblog

October 6, 2008

iPhone exposed security vulnerabilities

Filed under: news, Internet news


This Internet news is provided from the West Technology Limited

October 6, security researchers Aviv Raff last Thursday (October 2) revealed two iPhone security vulnerabilities. These vulnerabilities could allow users unwittingly to visit a malicious Web site. The security researchers Apple these vulnerabilities reported to Apple in this Junly, but Apple did not patches and repaired these vulnerabilities.
 
As a result, he has no other option open smart these vulnerabilities.

The first vulnerability exists in the iPhone’s e-mail application and Safari browser. Safari browser display in a long URL address to general time to be amputated part of the address. In this way, malicious people will be able to disguise a malicious URL addresses, so users do not see the opportunity to address this.

Raff explained that hackers can use this vulnerability to fake a trusted legitimate Web site address at the beginning of a long URL address. In fact this point to address a totally different site. iphone users can only see that they are familiar with that part of the domain name, it is vulnerable to deception to click on a malicious link.

Raff said, iPhone’s e-mail application also has a security hole. This automatically download security vulnerabilities in HTML format e-mail links to the images.

Most of all e-mail application that allows users to download images, but each time the user needs to download before approval. This option will help set up e-mail users to protect themselves against spam by the interference, because if the recipient to open junk e-mail or download images, spammers will know.

Raff said that this was not a small security vulnerability. This is actually a design loophole in the security. Other e-mail client software makers repaired the security vulnerabilities a few years ago.

Comments »

The URI to TrackBack this entry is: http://itnews168.blogsome.com/2008/10/06/iphone-exposed-security-vulnerabilities/trackback/

No comments yet.

RSS feed for comments on this post.

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>



Anti-spam measure: please retype the above text into the box provided.

Get free blog up and running in minutes with Blogsome
Theme designed by Gary Rogers