Blog Archive
-
▼
2010
(38)
-
▼
November
(20)
- iOS 4.2 Brings Accelerometer & WebSockets Support ...
- Apple Planning To Release iOS 4.3 In Mid-December
- iPad 2
- ReverseCamera 1.6 for iPhone and iPod touch
- Healthy Apple iPhone Apps
- Sonos wireless dock review
- Apple To Release iOS 4.2 For iPhone, iPad And iPod...
- Find My iPhone Now Free For All iPhone 4, iPad And...
- Up until now, if you wanted to change the default ...
- T.J Maxx And Marshalls Selling 16GB Wi-Fi iPad For...
- White iPhone 4s Being Sold In China?
- iPhone can dial phone numbers without user interve...
- You can now install Android 2.1 on iPhone 3G and 2G
- On November 16th, this pass Tuesday, EA added anot...
- LargeViewer 1.0 for iOS Displays Documents Up to 1...
- The Economist
- HTC Desire HD
- 3 Network Guarantee iPhone 4 16GB Stock Through No...
- Built-in SIM card
- No title
-
▼
November
(20)
About Me
- stylemobiles
Powered by Blogger.
Followers
Sunday, 21 November 2010
iPhone can dial phone numbers without user intervention
12:47 | Posted by
stylemobiles |
Edit Post
The independent expert on information security Itesh Dhanjani says in his blog that the decision of Apple allowing the built in Safari browser to handle requests from third applications is a bad idea because it allows to conduct attacks as a result of which the smartphone can be done dialing without the user’s knowledge.
According to him, the site visited by the Safari browser of the iPhone, it is possible to embed malicious iFrame, which will install malicious code hidden in an application. Alternatively, malicious code can not be embedded in the iFrame, but a hyperlink. However, a user who clicked on a dangerous link will see the start of recruitment and will be able to break it manually.
Dhanjani informed Apple about the problem and the company stated that all certified applications for the iPhone seek permission before launching a procedure of this kind. However, in this case, applications seeking authorization only after the user has entered and exclude or limit Safari, he retorts.
According to independent IT professionals, decision in this case can be built of special URL-schemes, which is disabled in your browser implementation or activation, which can be done only with the consent of the user.
Subscribe to:
Post Comments (Atom)

0 comments:
Post a Comment