📅 July 11, 2009     🕐 1 minute read

Automatic Login to WiFi Networks Includes a New Safety Problem in iPhone OS 3.0

iPhone OS 3.0 has a bad “feature” which let karmetasploit attack you without user interaction. Be careful what you join.

All you will know that the Firmware 3.0 introduces a new feature that covers the auto-login to the WiFi HotSpot public, which also involves the automatic opening of the Safari. This beautiful novelty, however, could jeopardize our security. Let us look for the good functioning of this feature and understand what is the problem:

In an attempt to connect to a Wi-Fi network, the iPhone perform 2 steps:

  • Create a DNS query to the Apple site
  • Try to open an HTML file in the site itself

If the HotSpot prompts you for a password, Safari will open with a login form to be filled, otherwise, if the network is completely free and public, the iPhone will launch Safari and you can start surfing the www.

Because of this, theoretically, anyone could achieve misrepresentation of WiFi network with the name “FREE WiFi” rather than “Public WiFi” and, taking advantage of remote exploits that could draw from Safari valuable information stored in the cookies, such as logins for numerous websites.

So, just be careful when you choose to join a WiFi network.

SUPPORT

FSM has no ads or affiliate links. Your support would simply pay for our servers, domain and maintanance. If there's any leftover change, we'll get some coffee and a slice of pizza. ​

Merch   FSM Goodies ( Alpha release )
PayPal  
Monero (XMR) 43GnqUNJrTi9QyL7kEH8vM8pgWGCE6bjv1FSRipeNMM4TTeNnUVsRBb6MfMpQYxtLE7ReonxVVSXz2rFCEdW5H11LC3x73b
Bitcoin (BTC) 1Hfuq77gKKFJeNcq4EP4dQK3yDRWrFEwJR
Bitcoin Cash (BCH) qzmdm6e6q5wf2p6sxz2mst7cenz60newwc5m4e9js8
Ether (ETH) 0x5f02869278C24A6579d3820f52AD15936D6F9d69
Stellar (XLM) GDWT2QU2CI3GZ5XH5DTSU3IUAHZMTB6VQKKRHBYWS5YCCQOAG6OKG2OB
More content?