Support Our Site
Get Better Gear!
- Notability For iPad: Much More Than A Note Taking App from Ginger Labs, Inc, US$0.99
- Scosche’s RH656m Headphones With Microphone Are Wonderful from Scosche, US$129.99
- IPEVO’s Typi Folio Case & Keyboard for iPad is First-rate from IPEVO, US$79.99
- Scosche’s boomSTREAM BT Speaker: Features & Compromises from Scosche, US$99.95
- FX Photo Studio HD: iPad Painting of Effects Made Easy from MacPhun LLC, US1.99
Top 5 Free Apps
iTunes New Music Releases
Top 5 Paid Apps
Discover New Music
- Cake
Pressure Chief, Cake's latest album, didn't immediately grab me. In fact, it took perhaps half a dozen listens before I started truly enjoying it. Any
- Ladytron
- Goldfrapp
On their latest CD, Supernature, Goldfrapp has put together a successful mix of 1980-era New Romanticism, German cabaret, and T. Rex glam that leaves you riveted even through the album's lulls. It's a great amalgam that sounds current without sounding at all dated.
- The Who
Quadrophenia is everything that Tommy wanted to be, a rock opera that told a story, but one where every song could still stand alone. It was also Pete Townshend's farewell tribute to the Mod
- The Stooges
Another pillar of my musical foundations, The Stooges' first album is one those records whose influence far outweighed its popularity. Like The Velvet Underground & Nico, hordes of people wh
Reader Specials
Visit Deals On The Web for the best deals on all consumer electronics, iPods, and more!
News
Safari Exploit Allows Hacker to Call 1-900 Numbers
Wednesday, November 19th, 2008 at 3:00 PM - by Bryan Chaffin
An exploit has been discovered in the Safari Web browser on iPhone that could allow a maliciously-crafted Web page take control of your iPhone and force it to dial any phone number, for instance a nice, expensive 1-900 number that could cost the user dearly.
The exploit was discovered by the Institute for Fraunhofer for Safe Information Technology (SIT) in Germany last month. According to the SIT, they immediately informed Apple, and a fix will be released on November 21st, 2008. Apples usual corporate policy is to not announce or discuss vulnerabilities until they release a patch.
The exploit involves tricking an iPhone user into clicking on a link, say in piece of e-mail, an SMS text message, or even from another Web page. That link would take the user to a Web page with as few as three lines of code that trigger the exploit. The iPhones screen then blanks out, a dialog that cant be interacted with shows that the phone is dialing, and the deed is done.
SIT has posted a video demonstration of the exploit that merely dials another cell phone sitting next to the iPhone. Any number could be dialed, but a 1-900 number would be a likely choice for hackers, as it would allow them collect money merely by having received the call at their 1-900 "service."
SITs announcement was first reported by German magazine Der Spiegel, and pointed out to us by Matthis Drolet (thanks for the head sup, Matthis!) SIT released the following images demonstrating the process:
The bad guy sends an e-mail or SMS text message with a URL
The iPhone switches over to Safari, and shows (in this case) what looks like a blank page
Surprise! Your iPhone is dialing a number!
Now your iPhone appears to be locked up while the call goes through...
Recent Headlines
- Reading, Writing, & Saving the World
- Free Retro Gaming for iOS - Activision’s Kaboom!
- Apple Adds Chomp Bits to iOS 6 App Store Discovery
- Notability For iPad: Much More Than A Note Taking App
- Scosche’s RH656m Headphones With Microphone Are Wonderful
- Tim Cook & Larry Page Reportedly Discuss Patents
- Analysis: Amazon Kindle Fire Sold Out, Kindle Fire 2 Pic Leaked
Post Your Comments