webdevRefinery Forum: iOS 5.1 Safari bug - webdevRefinery Forum

Jump to content

  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

User is offline arronhunt 

  • I'm a httpster
  • Group: Moderators
  • Posts: 3398
  • Joined: 09-March 10
  • LocationLos Angeles, CA
  • Expertise:HTML,CSS,Javascript,Graphics,Flash

Posted 22 March 2012 - 07:06 PM (#1)

iOS 5.1 Safari bug


Bad bad bad
Disclaimer: The link I provided is 100% safe and only shows you how the bug works

Pull out your iDevice running iOS 5.1 and navigate to this link with mobile safari http://arronhunt.com/facebook/ (must be on an iOS device running 5.1) Click the "connect with facebook" button. When facebook opens, attempt to login. You'll see what happens.

Pretty bad bug if you ask me. Definitely opens the gates for extremely easy phishing attacks. It allows you to hijack the URL and title of a new window and make it become whatever you'd like. In my example I used facebook. I would then create a facebook login mimicker and wait for people to input their credentials. I could then store credentials, forward them to the real mobile facebook and they wouldn't know anything happened.
DO NOT OPEN THIS

Spoiler
0


User is offline Lemon 

  • I have a dream...
  • Group: Members
  • Posts: 687
  • Joined: 24-February 11
  • Expertise:HTML,CSS,PHP,Javascript,Node.js,SQL

Posted 22 March 2012 - 07:32 PM (#2)

Saw this earlier, definitely pretty bad and also a bit worrying that Apple has had 3 weeks to get a fix out for this. I'm still using iOS 3.1.3, so I imagine I am also susceptible to this bug too, although I rarely ever use browser for sites I need to login to, most things have an app nowadays.

Just earlier, this also made me consider how mobile operating systems should really begin to move to the sort of update schedule we see from browsers such as Chrome, so rather than ship a big package with lots of bug fixes every few months, just instead apply bug patches right when they are ready as a small delta update instead.
Posted Image
In the end, it's not the years in your life that count. It's the life in your years
0


User is offline Quinn 

  • More pew-pew, less QQ
  • Group: Members
  • Posts: 1307
  • Joined: 08-March 10
  • LocationPalmyra, PA, USA
  • Expertise:HTML,PHP,Javascript

Posted 22 March 2012 - 07:49 PM (#3)

What's supposed to happen? I'm not on 5.1 so I don't know if it's different considering that you stressed iOS 5.1
<Imp> [F3ar 40]  [PWNbear 17]  [magik 15]  [dissident 10]  [mark 7]

View PostKyek, on 07 February 2011 - 07:11 AM, said:

Though anyone who thinks Europe is a country should be smacked in the face. By a train.
0


User is offline Hyde 

  • Group: Members
  • Posts: 1562
  • Joined: 08-March 10

Posted 22 March 2012 - 07:50 PM (#4)

Let's hope they fix it.
Hyde | HTML & CSS | PHP & SQL | Objective-C | Java | Basic JavaScript
0


User is online Mack 

  • http://mackgoodstein.com/
  • Group: Members
  • Posts: 2070
  • Joined: 08-March 10
  • Expertise:HTML,CSS,PHP,Javascript

Posted 22 March 2012 - 07:52 PM (#5)

It works on 5.0.1 too, but the second I do anything on the page (click the link, try to scroll, or zoom) the address bar goes back to what it should be.
0


User is offline TheEmpty 

  • I say words in sequences.
  • Group: Members
  • Posts: 5154
  • Joined: 02-October 10
  • Expertise:HTML,CSS,PHP,Java,Javascript,Python,Ruby on Rails,SQL

Posted 22 March 2012 - 08:23 PM (#6)

View PostQuinn, on 22 March 2012 - 07:49 PM, said:

What's supposed to happen? I'm not on 5.1 so I don't know if it's different considering that you stressed iOS 5.1

Address bar would read "facebook.com" but is actually something like "myphishingwebsite.com"
Reserved.
0


User is offline DarkCoder 

  • Group: Members
  • Posts: 1463
  • Joined: 08-March 10
  • LocationEngland, United Kingdom
  • Expertise:HTML,CSS,PHP,Javascript,SQL

Posted 23 March 2012 - 03:44 PM (#7)

That's a pretty huge bug...
0


User is offline callumacrae 

  • {{ post.author }}
  • Group: Members
  • Posts: 2862
  • Joined: 20-January 11
  • LocationWarwickshire, England
  • Expertise:HTML,CSS,PHP,Javascript,Node.js,SQL

Posted 23 March 2012 - 04:08 PM (#8)

:o
Front-end developer and writer
Twitter | GitHub | phpBB Contributor and Website Team Member | lynxphp
0


User is offline Fike 

  • Group: Members
  • Posts: 340
  • Joined: 26-October 10
  • LocationIreland
  • Expertise:PHP,Javascript,Python,SQL

Posted 23 March 2012 - 06:27 PM (#9)

Works on iOS 4.2.1. Just tried it. That's a huge bug...
web developer :: HTML, CSS, JavaScript (node), Python, PHP, MySQL, Mongo.
server admin :: experience with debian (and debian based distros), Gentoo, FreeBSD, OpenBSD.
social :: @nixhead (Twitter), Fudge (IRC), Github (FionnK), Personal Blog.
0


User is offline Lemon 

  • I have a dream...
  • Group: Members
  • Posts: 687
  • Joined: 24-February 11
  • Expertise:HTML,CSS,PHP,Javascript,Node.js,SQL

Posted 23 March 2012 - 06:41 PM (#10)

Unfortunately for people stuck on older devices without updates, that'll likely remain a permanent bug and hence a permanent security flaw unless Apple decides to issue an update to them too, which I incredibly highly doubt.
Posted Image
In the end, it's not the years in your life that count. It's the life in your years
0


User is offline TheEmpty 

  • I say words in sequences.
  • Group: Members
  • Posts: 5154
  • Joined: 02-October 10
  • Expertise:HTML,CSS,PHP,Java,Javascript,Python,Ruby on Rails,SQL

Posted 23 March 2012 - 06:58 PM (#11)

View PostLemon, on 23 March 2012 - 06:41 PM, said:

Unfortunately for people stuck on older devices without updates, that'll likely remain a permanent bug and hence a permanent security flaw unless Apple decides to issue an update to them too, which I incredibly highly doubt.

Jailbreak. Cydia generally gets fixes faster then iOS updates.
Reserved.
0


User is offline Daniel15 

  • dan.cx
  • Group: Moderators
  • Posts: 3415
  • Joined: 17-April 10
  • LocationMelbourne, Australia
  • Expertise:HTML,CSS,PHP,Java,Javascript,Node.js,SQL

Posted 23 March 2012 - 07:37 PM (#12)

Safari has lots of bugs - Look in any JavaScript library and you'll probably find about as many Safari hacks as there are IE hacks. :P
Daniel15! :D
Posted Image

Repeat after me: jQuery is not JavaScript. It is not the answer to every JavaScript-related question. When you have to write some JavaScript, do not instantly react with "Oh, I'll do that with jQuery!"

Spoiler
0


User is online Mack 

  • http://mackgoodstein.com/
  • Group: Members
  • Posts: 2070
  • Joined: 08-March 10
  • Expertise:HTML,CSS,PHP,Javascript

Posted 24 March 2012 - 12:01 PM (#13)

View PostDaniel15, on 23 March 2012 - 07:37 PM, said:

Safari has lots of bugs - Look in any JavaScript library and you'll probably find about as many Safari hacks as there are IE hacks. :P


As much as I like Safari, that's the problem with it being made by the same company as the OS. It, like IE, get updated much less frequently than Firefox/Chrome/Opera do.
0


User is offline Daniel15 

  • dan.cx
  • Group: Moderators
  • Posts: 3415
  • Joined: 17-April 10
  • LocationMelbourne, Australia
  • Expertise:HTML,CSS,PHP,Java,Javascript,Node.js,SQL

Posted 24 March 2012 - 07:55 PM (#14)

A lot of these would have been fixed by now, but check out how long this list is: http://www.quirksmod...ari/index.html. It's had way more issues than other browsers (maybe with the exception of IE). There's still 8 occurrences of "Safari" in the jQuery source which leads me to believe there's still issues with it.
Daniel15! :D
Posted Image

Repeat after me: jQuery is not JavaScript. It is not the answer to every JavaScript-related question. When you have to write some JavaScript, do not instantly react with "Oh, I'll do that with jQuery!"

Spoiler
0


User is offline Cocoa 

  • Group: Members
  • Posts: 418
  • Joined: 30-November 10
  • LocationEngland

Posted 26 March 2012 - 02:15 PM (#15)

Apple not looking so good now, huh? ;)
Dan || HTML || CSS || Web & Graphic Designer

Oh, there's no place like 127.0.0.1


Portfolio | Forrst (6 Invites) | Dribbble

MY FIRST TUTORIAL - HOW TO CREATE THE IRON MAN LOGO
1


User is offline arronhunt 

  • I'm a httpster
  • Group: Moderators
  • Posts: 3398
  • Joined: 09-March 10
  • LocationLos Angeles, CA
  • Expertise:HTML,CSS,Javascript,Graphics,Flash

Posted 26 March 2012 - 02:19 PM (#16)

View PostCocoa, on 26 March 2012 - 02:15 PM, said:

Apple not looking so good now, huh? ;)


I don't think Apple's mobile browser is the only one with bugs my friend.
DO NOT OPEN THIS

Spoiler
0


User is offline JustinP 

  • Group: Members
  • Posts: 311
  • Joined: 26-February 11
  • LocationEarth!

Posted 26 March 2012 - 02:22 PM (#17)

View Postarronhunt, on 26 March 2012 - 02:19 PM, said:

I don't think Apple's mobile browser is the only one with bugs my friend.


Mobile safari is actually the best (fastest, least buggy) mobile browser I've ever used... It's advantages make up for a few bugs. I'd like to note that while safari has a few bugs, other browsers have many more.

Edit: ninja'd!
0


User is offline Cocoa 

  • Group: Members
  • Posts: 418
  • Joined: 30-November 10
  • LocationEngland

Posted 26 March 2012 - 03:51 PM (#18)

View Postarronhunt, on 26 March 2012 - 02:19 PM, said:

I don't think Apple's mobile browser is the only one with bugs my friend.


Oh I know, but this is a very severe bug that hasn't been fixed.
Dan || HTML || CSS || Web & Graphic Designer

Oh, there's no place like 127.0.0.1


Portfolio | Forrst (6 Invites) | Dribbble

MY FIRST TUTORIAL - HOW TO CREATE THE IRON MAN LOGO
0


User is offline DarkCoder 

  • Group: Members
  • Posts: 1463
  • Joined: 08-March 10
  • LocationEngland, United Kingdom
  • Expertise:HTML,CSS,PHP,Javascript,SQL

Posted 03 April 2012 - 11:35 AM (#19)

View PostJustinP, on 26 March 2012 - 02:22 PM, said:

Mobile safari is actually the best (fastest, least buggy) mobile browser I've ever used...

You should try Opera Mini or Opera Mobile - not sure which one. It is great.
0


User is offline arronhunt 

  • I'm a httpster
  • Group: Moderators
  • Posts: 3398
  • Joined: 09-March 10
  • LocationLos Angeles, CA
  • Expertise:HTML,CSS,Javascript,Graphics,Flash

Posted 07 May 2012 - 05:57 PM (#20)

Update: the 5.1.1 update this morning has fixed this bug. But this still sucks http://www.cultofmac...sed-to-hackers/
DO NOT OPEN THIS

Spoiler
0


Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users


Enter your sign in name and password


Sign in options
  Or sign in with these services