Security Management
Published on Security Management (http://www.securitymanagement.com)
iPhone Security Flaws Exposed
Posted by Matthew Harwood, Web Editor
Created 07/24/2007 - 17:24



    
Wrap-Up?: 
Yes
Weight: 
100
Lead Headline?: 
No
Date: 
07/24/2007
By Line: 
Posted by Matthew Harwood, Web Editor
Teaser: 

A team of computer security consultants, according to The New York Times, has found a significant security flaw in one of the hottest items this summer: Apple's iPhone.

A team of computer security consultants, according to The New York Times, has found a significant security flaw [1] in one of the hottest items this summer: Apple's iPhone.

According to consultants working for Baltimore-based Independent Security Evaluators, a computer security firm, the iPhone was susceptible to being hacked when the phone's user connected to the Internet over a WiFi connection or surfing onto a bogus site where malicious code was installed. Once inside the phone, the invader has access to whatever personal information is stored in the phone.

A demonstration showed what a hacker can do when he commandeers an iPhone:

The phone promptly followed instructions to transmit a set of files to the attacking computer that included recent text messages - including one that had been sent to the reporter’s cellphone moments before - as well as telephone contacts and e-mail addresses.

"We can get any file we want," [Charles Miller, chief security analyst for ISE] said. Potentially, he added, the attack could be used to program the phone to make calls, running up large bills or even turning it into a portable bugging device.

For the Website and related technical paper explaining the iPhone's vulnerabilities more fully, click here [2] and here [3].

Related Resources: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/iphone-security-flaws-exposed

Links:
[1] http://www.nytimes.com/2007/07/23/technology/23iphone.html?ex=1342843200&en=36460b41095f0664&ei=5090&partner=rssuserland&emc=rss
[2] http://www.securityevaluators.com/iphone/
[3] http://www.securityevaluators.com/iphone/exploitingiphone.pdf