Thread: Computer news
View Single Post
Old 11-15-2010   #231
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default

Malicious Websites Can Initiate Skype Calls On iOS

"In this article, security researcher Nitesh Dhanjani
shows how iOS insecurely launches third-party apps via registered URL handlers.
Malicious websites can abuse this to launch arbitrary applications, such as
getting the Skype.app to make arbitrary phone calls without asking the user.
Dhanjani 'contacted Apple's security team to discuss this behavior, and their
stance is that the onus is on the third-party applications (such as Skype in
this case) to ask the user for authorization before performing the transaction.'
He also discusses what developers of iOS apps can do to design their software
securely and what Apple can do to help out."
__________________

Google is offline   Reply With Quote