Quantcast URL Spoofing Vulnerability Found In Mail, Safari - iPhone Alley Forums

URL Spoofing Vulnerability Found In Mail, Safari
Reply
Edward Kirk
WrAdminterizer
 
Edward Kirk's Avatar
 
Join Date: Apr 2007
Location: Illinois, USA
Posts: 3,088
Thanks: 19
Thanked 26 Times in 25 Posts
URL Spoofing Vulnerability Found In Mail, Safari -    #1
Security researcher Aviv Raff claims that the iPhone and iPod touch versions of Mail and Safari are both vulnerable to a URL Spoofing vulnerability that could allow attackers to conduct phishing attacks to iPhone users. According to Raff, a hacker could create a specially crafted URL that, when sent via an email, he could convince came from a trusted domain like a bank, PayPal, a social network, etc. Then, when clicked and opened in Safari, the URL showed in Safari's URL bar would still appear to the victim that it is from the trusted domain.

He says the exploit works in Mail and Safari on both 1.1.4 and 2.0, and that earlier versions may also be affected. He is currently withholding the technical details of the exploit until Apple releases a patch to fix it.

He also says that the Mail app is "spammable", which he says Apple has acknowledged as a security issue. He recommends that iPhone users refrain from using the Mail app until a patch is issued for that as well to avoid being spammed.

[via Aviv Raff's site]
__________________

About my iPhone:
iPhone & Color: iPhone 3G 16GB White
iPhone Version: 3.0
Computer & OS: MacBook Pro 15", Mac OS X 10.5.4

Twitter
Edward Kirk is offline   Reply With Quote
Stephen007
Rocks the Board
 
Stephen007's Avatar
 
Join Date: Dec 2007
Location: Milwaukee WI
Posts: 347
Thanks: 20
Thanked 3 Times in 3 Posts
  #2
What does "the iPhone's Mail application is also "spammable" mean?
Stephen007 is offline   Reply With Quote
Edward Kirk
WrAdminterizer
 
Edward Kirk's Avatar
 
Join Date: Apr 2007
Location: Illinois, USA
Posts: 3,088
Thanks: 19
Thanked 26 Times in 25 Posts
  #3
Quote:
Originally Posted by Stephen007 View Post
What does "the iPhone's Mail application is also "spammable" mean?
To be honest I have no idea, other than maybe it does certain things in ways that make it easy for you to be targeted by spammers. I'll keep looking for info and let you know what I find.
__________________

About my iPhone:
iPhone & Color: iPhone 3G 16GB White
iPhone Version: 3.0
Computer & OS: MacBook Pro 15", Mac OS X 10.5.4

Twitter
Edward Kirk is offline   Reply With Quote
Terry Time
Guest
 
Posts: n/a
  #4
Quote:
Originally Posted by Edward Kirk View Post
To be honest I have no idea, other than maybe it does certain things in ways that make it easy for you to be targeted by spammers. I'll keep looking for info and let you know what I find.
So he doesnt want me to access my email because I might end up getting spam mail?

Ha ha ha!

I've been getting spam and Nigerian scam emails loooooooooooong before my iPhone came around
  Reply With Quote
Andres Susarret
Guest
 
Posts: n/a
Spam images -    #5
Well, I for one am concerned that I cannot prevent image loading when I open an email with the Mail app on the iPhone. That strikes me as a "spammable" feature. Sure, most spam is obvious and I can delete it without opening it, but once in a while you get that tricky case that needs to be opened to be sure.

-andres
  Reply With Quote
 
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT -5. The time now is 03:36 AM.
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.