iPhone vulnerable to phishing attacks

By Robert Vamosi, CNET News.com
Thursday, July 24, 2008 10:48 AM

Security researcher Aviv Raff said on Wednesday that the iPhone's Mail and Safari applications are prone to URL spoofing and could allow phishing attacks against iPhone users.

The alert was anticipated. Prior to the release of the iPhone on July 11, Raff was one of a few security researchers who indicated they had found vulnerabilities but were waiting to see the final iPhone 2.0 release.

By crafting a specially designed URL, Raff says an attacker could create an e-mail link that appears in Mail to be from a trusted site, such as a financial institution or social network. By clicking the link, Safari will open to the phishing site. The issue affects users of iPhone 1.1.4 and 2.0.

Raff, who has informed Apple of the vulnerability, declined on his blog to offer more details until a patch is available.

Until then, Raff suggests iPhone users "avoid clicking on links in the Mail application which refers to trusted Web sites (e.g. bank, PayPal, social networks, etc.). Instead, a user should enter the URL of the Web site manually in the Safari application".

This article was first published as a blog on CNET News.com.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Employ smoke tests at the start of your testing process

Web Development

The most basic tests any software developer must run are smoke tests, which are a set of written, non-exhaustive tests that only deal with the most functional aspects of a software application or process.


Read more »



Making the case for Filipino IT entrepreneurship

Blog thumbnail

Filipinos are again over the moon with the masterful performance of boxing icon Manny Pacquiao in yesterday’s bout against Ghana native Joshua Clottey. This guy never ceases to give his..... by Melvin G. Calimag

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. microsoft windows
  11. network
  12. network security
  13. pc security
  14. researcher
  15. security
  16. security management
  17. software
  18. spam and phishing
  19. viruses and worms
  20. web