Register

To become a member of ITProPortal Register here.

Already a member? Login here

Please register below. All we need is a valid email address and a password.

Please use a real email address as we need to email you to confirm your account.
Must be at least 6 characters long.

Benefits of joining ITProPortal:

  • Unlimited Access to Special Reports and White Papers
  • Exclusive offers and discounts
  • Free entry to all competitions
  • Access to beta sections of ITProPortal.com

Login to your account



Forgot your password?


Apple's iPhone Still Has Two Serious Vulnearbilities Says Security Researcher

Apple's iPhone Still Has Two Serious Vulnearbilities Says Security Researcher
  • Digg del.icio.us reddit Facebook

Aviv Raff is a (very) smart guy and when back in July, he informed Apple of two serious security flaws that affected the iPhone, he did the right thing, expecting the Cupertino company to act swiftly to close the vulnerabilities.

Sad to say that nearly three months afterwards, Apple has yet to act on the data that Raff provided to them. He wrote on his blog  that he has "disclosed the technical details to Apple few weeks before that post, in a hope to get those security issues fixed as soon as possible. Unfortunately, two and a half months later, and still there is no patch for those vulnerabilities."

Adding that he asked Apple several times for a schedule, but "they have refused to provide the fix date". He continued "Three versions (v2.0.1, v2.02, v2.1) have been released since I provided them with the details, and they are still "working on it". Therefore, I've decided to publicly disclose the technical details. Both issues are pretty trivial, and can be easily fixed by Apple."

What does that mean? The two vulnerabilities can lead to more phishing and spamming and now that Aviv has decided to go public with them, iPhone owners can expect to become the targets of "social engineering" experts. 

The Phishing vulnerability is potentially the more damaging o ne since ti would allow phishing URLs to be implemented in URLs quite easily by using long subdomains (more than 24 characters).

The second one has to do with the fact that Apple's mail application automatically downloads images, a "feature" that cannot be disabled. Obviously, spammers would certainly like this as it confirms that an email inbox is active.

Desire Athow

Posted by Desire Athow on 06 Oct. 2008

Désiré Athow is the Content Editor for ITProportal.com and has been writing tech articles for nearly a decade. You can follow him on Twitter.

Tags: Phishing, Spamming, Vulnerabilities, apple, iphone