main

Security firm: Don't use iPhone Web dialer

Daniel Fleshbourne   on 17 July 2007 - 12:03 · 9 comments & 3720 views

Advertisement (Why?)
Security researchers at SPI Labs are warning iPhone users not to use a special feature that lets them dial telephone numbers over the Web using the iPhone's Safari browser. The feature was created to give iPhone users a simple way to dial phone numbers listed on Web pages, but according to SPI, the feature could be misused. Attackers could exploit a bug in this feature to trick a victim into making phone calls to expensive "900" numbers or even keep track of phone calls made by the victim over the Web, said Billy Hoffman, lead researcher with SPI Labs. The iPhone could even be stopped from dialing out, or set to dial out endlessly, he said.

"Because this vulnerability can be launched from Web sites, everybody who has an iPhone has the potential to get exploited," Hoffman said. In order for the attack to work, the bad guys would have to either trick iPhone users into visiting a malicious Web site or make a legitimate Web site send untrustworthy information to the iPhone using what's known as a cross-site scripting attack. "Any time someone could control the content that's getting sent to the iPhone [the possibility of an attack] exists," Hoffman said.

View: The full story
News source: InfoWorld

Post a comment · Send to friend Comments · There are 9 additional comments
#1 RAID 0 on 17 Jul 2007 - 15:53
So, is this worse than the other exploit? "Secure from day one."
#2 xMorpheousx416 on 17 Jul 2007 - 16:25
Ha.....the more pipes ya use in the building, the more chances ya take with a clogged system.
#3 Croquant on 17 Jul 2007 - 22:03
Hey look: Yet another reason not to buy an iPhone.
#4 ichi on 17 Jul 2007 - 23:14
huh dialing over the web... because there's no way anything web-related can go wrong

#5 noleafclover on 18 Jul 2007 - 00:02
ROFL... Using JavaScript to auto-click a link, nice one. And Apple didn't think to have a prompt before *actually* dialing the number?
#6 whocares78 on 18 Jul 2007 - 00:57
but, but it is so pretty and easy to use

Just wanted to get in before all the mac lovers.

Is there anything this phone can do, because the browsing the internet feature just got crossed off the list.

I do feel sorry for the bleeding edge users that jumped on the bandwagon and are now left with a phone that has the features of a phone from 10 years ago.
(1 reply) #7 +ispamforfood on 18 Jul 2007 - 02:02
What a surprise.... wait, no its not.
#7.1 The Gunslinger on 18 Jul 2007 - 06:55
Quote - (ispamforfood said @ #7)
What a surprise.... wait, no its not.


LMAO...
#8 xtravgnt on 18 Jul 2007 - 23:36
Oh noees, don't use the internets on da iPhone or someone may waste the time to make a site that one in a million idiots might visit and might click on a number to dial, and then oh the humanity it might keep on dialing with NO way to stop it.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)