Quantcast iPhone OS 3.0 Mail Security Hole Revealed - iPhone Alley Forums

iPhone OS 3.0 Mail Security Hole Revealed
Reply
Chris Barylick
Rocks the Board
 
Join Date: Jul 2007
Posts: 518
Thanks: 0
Thanked 0 Times in 0 Posts
Send a message via AIM to Chris Barylick
iPhone OS 3.0 Mail Security Hole Revealed -    #1


A potential security hole in the iPhone OS 3.0 and 3.0.1 firmware has just surfaced via a YouTube video in which the host describes how, by searching for the title of a deleted message, the resulting screen displays two copies of the message; when either is selected for the first time, Mail crashes. According to MacNN, when the messages are selected a second time however, an iPhone will either display the original text, or a warning saying "This message cannot be displayed because of the way it is formatted."

The copied message also warns that it is "only partially downloaded," and presents a malfunctioning button to download the remaining part of the e-mail. The bug further displays opened messages in either the Deleted Messages folder or the Inbox as "1 of 0."

The poster of the video says he suspects the device is reaching back to an e-mail server, but was able to disprove this by completely emptying his POP account. The bug is believed to be long-standing, as a result of finding e-mails deleted months ago:





Apple has yet to offer an official comment on this issue.
Chris Barylick is offline   Reply With Quote
iPhown
Forum Ninja
 
Join Date: Apr 2009
Posts: 116
Thanks: 2
Thanked 0 Times in 0 Posts
  #2
Just tried on my 3GS on 3.0 and didn't see the message in Spotlight. Maybe it's just an iPod thing.

EDIT: It does find my deleted messages but it doesn't crash Mail. And even though there were only 6 emails in my Hotmail inbox, it said 7 of 7 when I opened the message, not 7 of 6.

Last edited by iPhown; August 17th, 2009 at 04:28 PM.
iPhown is offline   Reply With Quote
foamysking
Forum Ninja
 
foamysking's Avatar
 
Join Date: Dec 2008
Location: midwest
Posts: 125
Thanks: 2
Thanked 2 Times in 2 Posts
  #3
well ive had som experience with this bug on my iphone since 3.0 launched and the only email account type that is immune is exchange because the messages are not stored localy so when there gone from the server they are gone for good
(it dosent crash for me)

another way to crush the bug is turn off mail searching in Settings > Gerenal > Home > Search Results > and tap mail to turn it off(unchecked) and that kinda fixes it to the point where it wont be searched

i have confirmed issue on two diffrent pop accounts, mobile me, yahoo, gmail, and aol accounts
__________________

About my iPhone:
iPhone & Color: 8gb iphone 3g
iPhone Version: 3.1
Computer & OS: lepoard, xp, vista, win 7

http://www.iphonehelper.net
foamysking is offline   Reply With Quote
 
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT -5. The time now is 05:11 AM.
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.