FacebookInstagramTwitterContact

 

South Korea: World Scout Jamboree Disaster Blamed On Government           >>           Ben-Gvir, Israeli Far-Right Minister, In Car Accident           >>           Pentagon To 'Rush' Patriot Missiles To Ukraine In $6bn Package           >>           Major Gaza Protests At US Universities           >>           Burkina Faso Suspends BBC Over HRW Report On Alleged Mass Killings           >>           AIPA-FAO-IISD Joint Workshop           >>           Tesla Autopilot Recall To Be Probed By US Regulator           >>           ISO 9001:2015 Certificate Award           >>           Why Green Steam Is A Hot Issue For Business           >>           Use a Plot of Land for Planting           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Apple Attack Sidesteps Safeguards To Threaten Iphones


Don't walk into a trap that attacks your iPhone, no matter how stylish your hat.

 


 April 1st, 2016  |  10:53 AM  |   3048 views

Security And Privacy

 

The SideStepper attack requires you to participate in your own hacking. That could happen.

A new attack on iPhones requires theft, deception and the planning of a chess grandmaster.

 

Check Point, a cybersecurity firm, says it's found an attack that could trick iPhone users into downloading a malicious app. The attack, which they're calling SideStepper, takes advantage of specialized corporate software known as enterprise apps.

 

It also needs thievery, a setup and poor decision-making by the iPhone user, said Check Point researcher Avi Rembaum. "What we've seen, however, is that the enterprise program has nevertheless become a target for attacks."

 

That said, there's no indication this exact attack has been carried out by hackers.

 

SideStepper, which Check Point will present at the Black Hat cybersecurity conference in Singapore on Friday, relies on attackers getting hold of a stolen enterprise certificate. Those certificates are bits of software on enterprise apps -- you know, your company's annoying corporate benefits or sales apps -- that prove they're legitimate.

 

To get a malicious enterprise app on your phone, an attacker would sign a malicious app with a stolen or otherwise illegitimate enterprise certificate. The attacker would text or email you a link and try to convince you to click on it and go to a website to create an account from your phone.

 

You might think only someone clueless would do that. But imagine if the hacker spoofed your boss's email account and told you to set up the new account. You might do it without thinking if you're blasting through your email on the train before your morning coffee.

 

Once you've created the account, the attacker can install the malicious app on your phone.

 

Apple says the attack doesn't count as a flaw in iOS, the software that runs iPhones.

 

"We've built safeguards into iOS to help warn users of potentially harmful content like this," an Apple spokesman said in a statement. Apple also encourages iPhone users to only download from a trusted source, like the App Store.

 

Check Point's Rembaum says Apple's system has a lot of safeguards, but it's still vulnerable.

 


 

Source:
courtesy of CNET

by Laura Hautala

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

South Korea: World Scout Jamboree Disaster Blamed On Government

 2024-04-27 02:37:15

Tesla Autopilot Recall To Be Probed By US Regulator

 2024-04-27 01:55:10