iPhone Security Flaw Lets Hackers Access All of Your Personal Data on iPhone   - 2,489 Views,

Summary: An independent security research outfit has found a gaping security hole in the iPhone. They have found that someone needs only embed the correct malicious code on a web page, and when an iPhone visits the web page, it will essentially cooperate with any instruction given to it through the code.

Previous Article « Website Gives You Cash for Old Cell Phones! The Perfect Answer to “What to Do with an Old Cell Phone?”!
Read Next Article » How to Whitelist in Gmail

  Follow Anne on Twitter     Friend Anne on Facebook

An independent security research outfit has found a gaping security hole in the iPhone. They have found that someone needs only embed the correct malicious code on a web page, and when an iPhone visits the web page, it will essentially cooperate with any instruction given to it through the code.

The researchers at Independent Security Evaluators (ISE) were easily able to get the iPhones to give up “the log of SMS messages, the address book, the call history, and the voicemail data,” which the iPhones readily transmitted to them.

According to ISE, “this code could be replaced with code that does anything that the iPhone can do. It could send the user’s mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.”

ISE’s report goes on to explain that “The exploit is delivered via a malicious web page opened in the Safari browser on the iPhone. There are several delivery vectors that an attacker might utilize to get a victim to open such a web page. For example:

* An attacker controlled wireless access point: Because the iPhone learns access points by name (SSID), if a user ever gets near an attacker-controlled access point with the same name (and encryption type) as an access point previously trusted by the user, the iPhone will automatically use the malicious access point. This allows the attacker to add the exploit to any web page browsed by the user by replacing the requested page with a page containing the exploit.
* A misconfigured forum website: If a web forum’s software is not configured to prevent users from including potentially dangerous data in their posts, an attacker could cause the exploit to run in any iPhone browser that viewed the thread. (This would require some slight changes in our proof of concept exploit, however.)
* A link delivered via e-mail or SMS: If an attacker can trick a user into opening a website that the attacker controls, the attacker can easily embed the exploit into the main page of the website.”

You can read the entire report here: Security Evaluator’s report of iPhone security flaw

iPhone Security Flaw Lets Hackers Access All of Your Personal Data on iPhone

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « Website Gives You Cash for Old Cell Phones! The Perfect Answer to “What to Do with an Old Cell Phone?”!
Read Next Article » How to Whitelist in Gmail

Read more:

»  Jailbroken iPhones All at Risk for Same Hack - Fortunately the Fix is Easy

»  FlexiSpy Announces Cell Phone Tapping Software for iPhone

»  The Hot Question of the Month is “Can I Tether My Laptop with an iPhone?”, and the Answer is…

»  iPhone Users Sucking the Very Life Energy Out of AT and T Network

For additional similar stories check out our archives on Apple & Mac, Cell Phones, Security

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 7/23/2007
The Internet Patrol
Patrolling the Internet for You!