You're viewing an article in iPO's historic archive vault. Here, we've preserved the comments and how the site looked along with the article. Use this link to view the article on our current site: Safari Exploit Allows Hacker to Call 1-900 Numbers
News
Safari Exploit Allows Hacker to Call 1-900 Numbers
Thursday, November 20th, 2008 at 5:40 PM - by
An exploit has been discovered in the Safari Web browser on iPhone that could allow a maliciously-crafted Web page take control of your iPhone and force it to dial any phone number, for instance a nice, expensive 1-900 number that could cost the user dearly.
The exploit was discovered by the Institute for Fraunhofer for Safe Information Technology (SIT) in Germany last month. According to the SIT, they immediately informed Apple, and a fix will be released on November 21st, 2008. Apple's usual corporate policy is to not announce or discuss vulnerabilities until they release a patch.
The exploit involves tricking an iPhone user into clicking on a link, say in piece of e-mail, an SMS text message, or even from another Web page. That link would take the user to a Web page with as few as three lines of code that trigger the exploit. The iPhone's screen then blanks out, a dialog that can't be interacted with shows that the phone is dialing, and the deed is done.
SIT has posted a video demonstration of the exploit that merely dials another cell phone sitting next to the iPhone. Any number could be dialed, but a 1-900 number would be a likely choice for hackers, as it would allow them collect money merely by having received the call at their 1-900 "service."
SIT's announcement was first reported by German magazine Der Spiegel, and pointed out to us by Matthis Drolet (thanks for the head sup, Matthis!) SIT released the following images demonstrating the process:

The bad guy sends an e-mail or SMS text message with a URL

The iPhone switches over to Safari, and shows (in this case) what looks like a blank page

Surprise! Your iPhone is dialing a number!

Now your iPhone appears to be locked up while the call goes through...
Recent Articles
- Editorial - It's Time for the Promised, Unlocked iPhone 3Gs
- Wal-Mart Employees Confirm iPhone Rumors
- The RIAA vs. 19 Year Old Cancer Patient
- Mac Gaming News - Gameloft Brings Hero of Sparta to the iPhone
- Free on iTunes - Return to the Moon, JPL, Stranger Things And More
- Apple Claims 300 Million App Store Downloads, 10,000 Apps Available


1 comments from the community.
You can post your own below.
+ show options
Your current settings, click to change: Sort Oldest First, Show Guest Posts, Hide Community Stats
jimothy said:
member since 04 Jun 2004 with 612 posts,
, send him a message or view his profile
Quote this post ↓
Post Your Comments