Thursday, March 22, 2012

iPhone in Canada Blog - Canada's #1 iPhone Resource: Mobile Safari Found Vulnerable To Address Bar Spoofing Exploit In iOS 5.1

iPhone in Canada Blog - Canada's #1 iPhone Resource
iPhone News and Tips for Canadian iPhone Users // via fulltextrssfeed.com
Mobile Safari Found Vulnerable To Address Bar Spoofing Exploit In iOS 5.1
Mar 22nd 2012, 18:16

By Usman on March 22nd, 2012 0

WP Greet Box icon
Hello there! If you are new here, you might want to subscribe to the RSS feed for updates on this topic.

Today, David Vieira-Kurz of MajorSecurity has uncovered a security issue with Apple's Mobile Safari in iOS 5.1 (via TNW). The vulnerability can make Safari browser on iOS 5.1 spoof fake website addresses, something that can be used to display a different URL to that of the actual website you are visiting. According to the source, the vulnerability has been reproduced on the iPhone 4, iPhone 4S, iPad 2 and new iPad running iOS 5.1. As a result, the Dutch Ministry of Security and Justice has issued a warning about it.

Viera-Kurz has offered a demonstration of the code, so if you own an iOS device and want to reproduce the bug follow these steps:

Step 1:

Visit http://majorsecurity.net/html5/ios51-demo.html with Safari on iOS 5.1.

Step 2:

Click the "Demo" button.

Step 3:

Safari will open a new window with "http://www.apple.com" in the address bar, but in fact "http://www.apple.com" is being displayed inside an iframe within the host http://www.majorsecurity.net

Step 4:

Safari's address bar is showing "http://www.apple.com" which makes the user believe he/she is currently visiting Apple.com while he's still on the attacker's website.

Apple has already been notified about the vulnerability, meaning an iOS firmware update to resolve the issue should be coming up shortly!

A Technology Enthusiast, A Blogger & A Doctor (specialized in Diagnostic Radiology). Love: F1, Gadgets, Console Games, Movies, Music & Designer Clothes! Follow me on Twitter @DrUsmanQ

You are receiving this email because you subscribed to this feed at blogtrottr.com.

If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions

No comments:

Post a Comment