iPhone phishing - What you see, isn't what you get
Across at our sister site, the SANS Security Institute the Application Security Street Fighter Blog brings us proof that what you see, isn't what you get. Or at least with the latest in phishing techniques on a mobile platform.
With many financials pushing to have their customers able to access their accounts via mobile devices, they should be away of this technique for spoofing site identification. The threat? The URI bar at the top of the browser page. Fair game it would appear.
Steve Hall
ISC Handler
×
Diary Archives
Comments
tbroset
Nov 29th 2010
1 decade ago
Note this could be launched on any browser that doesn't keep the URL bar in view, you can disable this view on FireFox and Safari on your desktop (few probably do though). This may be more of a user training issue to address as screen real estate is just too valuable on a 3-4 inch screen to keep something static up like that.
bcave
Nov 29th 2010
1 decade ago
I actually did think that this "feature" of safari on the iphone was a bit of a worry when I first scored one from work, seems that it's only taken 3 years to see some mention.
pd
Nov 30th 2010
1 decade ago
It's time to focus on new ways to authenticate a site for normal folks, because the techie, geeky ways (digital certificates, domain name verification, green address bars, etc.) definitely don't work...
bodoleclodo
Nov 30th 2010
1 decade ago