TECH.BLORGE.com
VISTA.BLORGE.com
MAC.BLORGE.com
GAMER.BLORGE.com

July 17, 2007 |

iPhone flaw allows attackers to steal victim’s money

By George Gardner





iPhone flaw allows attackers to steal victim's money Apple’s iPhone has a built in function that allows users to dial numbers from within its Safari web browser; a neat little function, yes, until a flaw leaves your phone open to attackers, allowing them to steal your minutes and possibly your money.

The flaw was recently discovered by Security research firm, SPI Labs, that allows Safari’s access to the iPhone’s functions to be exploited by attackers to perform various attacks such as tracking a users phone calls, placing calls from the victims phone without knowledge, redirecting calls placed by the user, preventing the phone from dialing, and even locking the iPhone up by putting it into an infinite loop of attempting calls.

SPI Labs warns on its blog:

 ”these types of attacks can be launched from a malicious website, from a legitimate website that has Cross-Site Scripting vulnerabilities, or as part of a payload of a web application worm.”

An attacker could potentially steal money from iPhone owners by forcing their phone to dial 900 numbers that are owned by the assailant. SPI Labs notes that users could also get blackmailed into dialing a 900 to prevent other people from knowing about an embarrassing phone call.

SPI Labs contacted Apple on July 6 and have been working with them ever since to resolve the problem.

SPI Labs recognizes the unique urgency of these issues and the large number of people that could be affected. As such, SPI Labs recommends that iPhone users do not use the built-in Safari browser to dial telephone numbers until Apple resolves these issues.

There have currently been no reports of users’ iPhones being hacked, but now the information has been made public, it surely won’t be long.

Related:

  • Analyst: iPhone will fall victim to serious attack in ‘08
  • Apple’s Quick Time flaw enables hackers to steal Linden dollars in Second Life
  • Microsoft confirms serious design flaw in Windows including Vista
  • Photoshop flaw allows hackers to access your PC
  • Apple has suggestions for longer iPhone battery life




  • Sign up for the BLORGE daily email newsletter

    2 Responses to “iPhone flaw allows attackers to steal victim’s money”

    1. University Update - Apple iPhone - iPhone flaw allows attackers to steal victim's money:

      [...] Link to Article apple iphone iPhone flaw allows attackers to steal victim’s money » Posted at [...]

    2. Harrison Bergeron:

      More reason for me not to get an iPhone. Look how many bugs and issues have come to the forefront with it so far…no thanks. I get what I need from my Treo, including my digital music wirelessly through the “M” app from Mercora. No need to get anything new.

    Leave a Reply:

    Copyright © 2008 Engaging and compelling blogs that entertain and inform