Please wait while the page is being loaded Skip this advertisement >
Thursday | 4 December, 2008
Frustrated researcher details iPhone security bugs
One of the bugs could be used to trick users into clicking on malicious links to deliver spam.
Gregg Keizer (Computerworld (US)) 03/10/2008 08:47:00

Tired of getting the brush-off from Apple, Israeli researcher Aviv Raff Thursday disclosed technical details about a pair of iPhone security flaws that he first reported more than two months ago.

Raff, best known as a browser vulnerability researcher, told Apple in July that he had uncovered bugs in the iPhone's Mail application as well as in its version of Safari that could be used to trick users into clicking on malicious links and boost the amount of spam they face.

But after Apple continued to defer patching and declined to set a date for fixing the flaws, Raff decided to go public. "Two and a half months later, and still there is no patch for those vulnerabilities," he complained in a post to his blog. "I've asked Apple several times for a schedule, but they have refused to provide the fix date. Three versions (v2.0.1, v2.02, v2.1) have been released since I provided them with the details, and they are still 'working on it.'"

In an interview Thursday, Raff said that while he's used this tactic before to pressure a vendor into patching, he's reserved it for companies that "act irresponsibly, as Apple did this time and other vendors have done other times." Raff said he last contacted Apple a week ago.

Apple last patched the iPhone on September 12, when it issued fixes for eight security vulnerabilities as part of the v2.1 update.

Both Mail and Safari truncate URLs to accommodate the iPhone's small screen, said Raff, a bug that hackers could exploit by feeding malicious links via HTML messages. Because Mail cuts out the middle portion of a long URL, the attacker could spoof a legitimate domain by using a legitimate service such as Facebook to provide the first bits of the address but tuck the malicious part of the URL after the iPhone's cut-off.

Raff demonstrated a possible exploit by creating a link that, at least to an iPhone owner, appeared to be a URL to Facebook's sign-in site, but was actually a link to an image he'd posted on his own domain.

"The user will have to look carefully at all links that he clicks," said Raff when asked for advice on deflecting such attacks. "But this takes a lot of effort as Safari automatically jumps to the end of the URL when clicking on the address bar."

He called the other iPhone bug "a pretty dumb design flaw" that made it easier for spammers to identify valid e-mail accounts, and thus mark them for more spam.

Because the iPhone automatically downloads images attachments, it would be a cinch for spammers to identify a working e-mail account. "The spammer who controls the remote server will know that you have read the message, and will mark your mail account as active, in order to send you more spam," said Raff. Since there is no way to disable auto-image download on the iPhone, he recommended that iPhone users refrain from using Mail until Apple patches the problem.

The same bug has surfaced before in other versions of Apple's Mail software -- the company bundles a much brawnier edition with Mac OS X -- but those versions have long been patched.

Claiming that the flaws were easily fixed, Raff called on Apple to get on the stick. "It's only a matter of time until the bad guys will find these problems," he said.

Raff isn't the first security researcher to knock Apple's patching process. Last month, two other researchers, including Charlie Miller, who is even better known than Raff in the Mac and iPhone vulnerability arena, took Apple to task for dumping several updates on users in a short time, and without warning.

Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 
D-Link Networking Knowledge Centre

D-Link Australia & New Zealand

D-Link is the global leader in connectivity for small, medium and large enterprise business networking. The company is an award-winning designer, developer and manufacturer of networking, broadband, digital electronics, voice and video communication.

To Find out more about D-Link solutions visit www.dlink.com.au

D-Link Networking Knowledge Centre

D-Link Australia & New Zealand

Featured Products

  • IP BASED PHONE SYSTEM
    D-Link VoiceCenter

    D-Link VoiceCenter is an IP based phone system designed to meet the needs of small businesses. D-Link have solely partnered with Microsoft to package Microsoft’s Response Point software to bring you VoiceCenter. For more info on VoiceCenter's products and events please visit: http://voicecenter.dlink.com.au
  • AWARD WINNING STORAGE
    DNS-343 4-Bay NAS Enclosure

    D-Links new 4-bay network attached storage enclosure has just received ZDNet's Editor's Choice award and a rating of 9 out of 10 by Craig Simms from CNET See the review here. The DNS-343 release followed the great success of its smaller sibling the 2-bay DNS-323. Targeted at both the home IT enthusiast and commercial users needing a flexible storage solution the DNS-343 is showing good market performance.
  • EVERY BUSINESS NEEDS ONE
    DSA-3600 Multi-Service Gateway

    Any business that’s serious about networking must consider installing this gateway. Feature rich the DSA-3600 multi-service business gateway is a complete network solution that delivers reliable and cost-effective services to SMB and enterprise branch offices. Perfect for setting up a commercial grade wireless connection for the office the unit is simple and easy to manage.
  • WI-FI FOR MOBILE WORK SITES
    DIR-451 Mobile 3G Router

    Perfect for mobile and temporary work-sites the mobile 3G router quickly and easily can connect your site back to the office. Recently the United States Air Force has used D-Link Mobile 3G routers on its remote base camps to connect soldiers with other Air Force departments, local agencies, friends and families. To see the complete case study click here.

New Products

  • XTREME N DUO ROUTER - DIR-855
    The highly anticipated simultaneous broadcasting dual band wireless N router has arrived. The DIR-855 is set to make massive waves and take home/SOHO wireless networking to a new generation. Unlike other networking manufacturers who promote dual band the new DIR-855 will provide users simultaneous dual band wireless networks, opening up another range of opportunities for wireless networking.
  • DUAL BAND USB ADAPTER
    DWA-160 Xtreme N USB Wi-Fi

    The new dual band wireless N USB adapter is ideal for simultaneous dual band environments. For example in apartment buildings where there are heavily congested 2.4GHz Wi-Fi or at the home stream HD video over the network and making VoIP calls at the same time.

Coming Soon

  • WI-FI ACCESS POINT/BRIDGE
    DAP-1522 Xtreme N Duo

    A new addition to the Xtreme N family this wireless N access point/bridge effectively doubles available wireless bandwidth. Designed for users looking to get a true wireless connection that can handle multiple High-Definition video streaming throughout the house it can take the home network to a new level.
  • GOT NAKED DSL
    DVA-G3670B ADSL2+ Wireless G VoIP Modem Router

    Naked DSL customers now have the perfect feature rich product solution the DVA-G3670B to take advantage of naked DSL features. This ADSL2+ (naked DSL compatible) modem Wireless G router comes with 2 VoIP phone connections and is ideal for the growing market who don't want to pay the unnecessary line rental fee. Ultimately this unit is an ideal all-in-one home network solution and even SOHO small business solution.

Download

Case Studies

Whitepapers

D-Link TV

Watch videos about D-Link products and much more
http://www.dlinktv.com

D-Link Training

Find out more about D-Link products trainings and certification program
http://training.dlink.com.au
Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links