Showing posts with label vulnerability. Show all posts
Showing posts with label vulnerability. Show all posts

Wednesday, 27 March 2013

iPhone is The More Vulnerable Smartphone Compared to Windows Phone, BlackBerry and Even Android a Study Shows


The Apple iPhone is decorated and revered in the smartphone industry as one of the safest devices around. Thanks to its closed-off ecosystem, its record for malware and intrusion is unparalleled, with Google’s Android soaking up the vast majority of the negative press in this area. However, it is this strictly-moderated infrastructure, allied to continued popularity, which makes the iPhone a lucrative target to criminals, and according to a latest research from SourceFire, the number of vulnerabilities discovered on iPhone over the years far outweigh the combined number found within Windows Phone, Android, and BlackBerry.
Compiled in a study and published earlier this month entitled "25 Years of Vulnerabilities", which looked at vulnerabilities from the Common Vulnerabilities and Exposures (CVE) data and National Vulnerability Database (NVD). Having collated all the data, it was discovered that the overwhelming majority of vulnerabilities were specific to the Apple iPhone.


The 220 vulnerabilities equate to a total of  81 percent of the smartphone vulnerability market share – not a particularly coveted feat by any stretch of the imagination. As you can see from the chart, that number is more than four times higher than the collective number of Android, Windows Phone and BlackBerry-based smartphones combined, which accounted for a comparatively meager 19 percent.


Speaking to ZDNet Asia, SourceFire’s Yves Younan described the findings as "surprising", especially considering how much emphasis Apple places on improving security with each new version. His explanation as to why the iPhone appears disproportionately more vulnerable than its counterparts, points to iOS’s closed-source nature. Whereas Android is open source and thus a relatively soft target for malicious apps, iOS is so safe that, once a cyber criminal does manage to infiltrate the inner circle, the potential rewards are much greater.


The report also noted that the total number of vulnerabilities with a "high severity" rating continued increasing up until 2007, when it hit a peak of 3,159. Since that point, it has fallen down to a low of 1,760, although with an increase one again, it would seem vulnerabilities aren’t going anywhere.
Certainly a very intriguing tidbit of news, and it just goes to show that, despite Android commanding the lion’s share of bad press when it comes to malware, all vendors and software makers need to be on red alert in order to protect the consumer. [Source]

You can follow me on Twitter, add me to your circles on Google+ or Subscribe to me on facebook or YouTube. You can also check my website and blog to keep yourself updated with what is happening in the ever changing world of technology






Thursday, 21 March 2013

Another iPhone Security Vulnerability Discovered in iOS 6.1.3


Following yesterday's release of iOS 6.1.3, which fixed two bugs allowing the iPhone's passcode lock to be bypassed, another passcode security flaw has been discovered.

The vulnerability, which only affects the iPhone 4, involves the Voice Dial command, as demonstrated in the video below from YouTube user videosdebarraquito.

iPhoneinCanada tested the method in the video using an iPhone 4 running iOS 6.1.3 and found that the security flaw does indeed exist, giving a potential intruder access to both contacts and photos.

Like the previous passcode vulnerability, the current hack involves a complicated set of steps that includes initiating Voice Dial command and quickly ejecting the phone's SIM card.



When the SIM card is removed, the phone opens the recent call log, which gives access to the contact list. In the contact list, adding a photo also gives access to all of the pictures on the device.

The previous passcode vulnerability was discovered in mid-February, and it took Apple more than a month to push a fix. An update for the current bypass could follow a similar timeline, but the vulnerability can be fixed by disabling Voice Dial from the Passcode Lock menu.

At this time, the vulnerability has only been shown to work with the iPhone 4. We were unable to reproduce the results with an iPhone 5 with Siri disabled, though the bug may potentially affect the pre-Siri iPhone 3GS as well.

Update 1:07 PM: iPhoneblog.de reports that it has reproduced the issue on an iPhone 5 with Siri disabled, although we have still been unable to do


You can follow me on Twitter, add me to your circles on Google+ or Subscribe to me on facebook or YouTube. You can also check my website and blog to keep yourself updated with what is happening in the ever changing world of technology