Frustrated researcher details iPhone security bugs
Pushes Apple to patch by revealing more about phishing, spamming flaws
Computerworld - Tired of getting the brushoff from Apple Inc., Israeli researcher Aviv Raff today disclosed technical details about a pair of iPhone security flaws that he first reported more than two months ago.
Raff, best known as a browser vulnerability researcher, told Apple in July that he had uncovered bugs in the iPhone's Mail application as well as in its version of Safari that could be used to trick users into clicking on malicious links and boost the amount of spam they face.
But after Apple continued to defer patching and declined to set a date for fixing the flaws, Raff decided to go public. "Two and a half months later, and still there is no patch for those vulnerabilities," he complained in a post to his blog. "I've asked Apple several times for a schedule, but they have refused to provide the fix date. Three versions (v2.0.1, v2.02, v2.1) have been released since I provided them with the details, and they are still 'working on it.'"
In an interview today, Raff said that although he's used this tactic before to pressure a vendor into patching, he's reserved it for companies that "act irresponsibly, as Apple did this time and other vendors have done other times." Raff said he last contacted Apple a week ago.
Apple last patched the iPhone on Sept. 12, when it issued fixes for eight security vulnerabilities as part of the v2.1 update.
Both Mail and Safari truncate URLs to accommodate the iPhone's small screen, said Raff, a bug that hackers could exploit by feeding malicious links via HTML messages. Because Mail cuts out the middle portion of a long URL, the attacker could spoof a legitimate domain by using a legitimate service such as Facebook to provide the first bits of the address but tuck the malicious part of the URL after the iPhone's cutoff.
Raff demonstrated a possible exploit by creating a link that, at least to an iPhone owner, appeared to be a URL to Facebook's sign-in site, but was actually a link to an image he'd posted on his own domain.
"The user will have to look carefully at all links that he clicks," said Raff when asked for advice on deflecting such attacks. "But this takes a lot of effort as Safari automatically jumps to the end of the URL when clicking on the address bar."
He called the other iPhone bug "a pretty dumb design flaw" that made it easier for spammers to identify valid e-mail accounts, and thus mark them for more spam.
Because the iPhone automatically downloads images attachments, it would be a cinch for spammers to identify a working e-mail account. "The spammer who controls the remote server will know that you have read the message and will mark your mail account as active in order to send you more spam," said Raff. Since there is no way to disable auto-image download on the iPhone, he recommended that iPhone users refrain from using Mail until Apple patches the problem.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Macintosh White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Macintosh Webcasts