{"id":2203,"date":"2010-11-30T11:56:25","date_gmt":"2010-11-30T10:56:25","guid":{"rendered":"http:\/\/blog.intego.com\/?p=2203"},"modified":"2012-12-12T13:48:58","modified_gmt":"2012-12-12T21:48:58","slug":"researcher-points-out-url-hiding-trick-on-iphone","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/","title":{"rendered":"Researcher Points Out URL Hiding Trick on iPhone"},"content":{"rendered":"<p>Security researcher Nitesh Dhanjani has discovered a way that hackers could trick users into visiting fake websites by hiding their URLs. In a <a href=\"http:\/\/blogs.sans.org\/appsecstreetfighter\/2010\/11\/29\/ui-spoofing-safari-iphone\/\">proof of concept example<\/a>, Dhanjani shows users that a web page can display a graphic of a Safari browser window, showing a fake URL. After this page has loaded, Safari&#8217;s address bar disappears, leading users to believe that the URL they see in the graphic of the web page is the correct one. Phishing sites could create &#8220;pages&#8221; like this easily, leading users to believe that they are on valid web sites, and possibly convincing them to enter personal data such as passwords, credit card numbers or more.<\/p>\n<p><center><br \/>\n<img loading=\"lazy\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png\" alt=\"\" title=\"iphone-ui-spoofing-resized\" width=\"446\" height=\"430\" class=\"alignnone size-full wp-image-2204\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png 446w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized-300x289.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized-100x96.png 100w\" sizes=\"(max-width: 446px) 100vw, 446px\" \/><br \/>\n<\/center><\/p>\n<p>One of the main reasons for this activity is the limited amount of screen space on mobile phones such as the iPhone. Safari scrolls up, hiding the address bar after a page has loaded, so users can see the content of web pages, but this activity can mislead users in cases such as the one demonstrated here.<\/p>\n<p>iPhone users should be especially careful when loading pages for banks, web sites where they make purchases, and others where they enter sensitive information, if they have gotten to those sites by tapping a link. When in doubt, swipe up to see the address bar and check that you&#8217;re on the site you think you&#8217;re on.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researcher Nitesh Dhanjani has discovered a way that hackers could trick users into visiting fake websites by hiding their URLs. In a proof of concept example, Dhanjani shows users that a web page can display a graphic of a Safari browser window, showing a fake URL. After this page has loaded, Safari&#8217;s address bar [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[7,13],"tags":[9,102],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Security researcher Nitesh Dhanjani has discovered a way that hackers could trick users into visiting fake websites by hiding their URLs. In a proof of\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Researcher Points Out URL Hiding Trick on iPhone  - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Security researcher Nitesh Dhanjani has discovered a way that hackers could trick users into visiting fake websites by hiding their URLs. In a proof of\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2010-11-30T10:56:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2012-12-12T21:48:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png\",\"width\":\"446\",\"height\":\"430\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/\",\"name\":\"Researcher Points Out URL Hiding Trick on iPhone - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#primaryimage\"},\"datePublished\":\"2010-11-30T10:56:25+00:00\",\"dateModified\":\"2012-12-12T21:48:58+00:00\",\"description\":\"Security researcher Nitesh Dhanjani has discovered a way that hackers could trick users into visiting fake websites by hiding their URLs. In a proof of\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Researcher Points Out URL Hiding Trick on iPhone\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"Researcher Points Out URL Hiding Trick on iPhone\",\"datePublished\":\"2010-11-30T10:56:25+00:00\",\"dateModified\":\"2012-12-12T21:48:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#webpage\"},\"wordCount\":232,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png\",\"keywords\":[\"iPhone\",\"Phishing\"],\"articleSection\":[\"Apple\",\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Security researcher Nitesh Dhanjani has discovered a way that hackers could trick users into visiting fake websites by hiding their URLs. In a proof of","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/","og_locale":"en_US","og_type":"article","og_title":"Researcher Points Out URL Hiding Trick on iPhone  - The Mac Security Blog","og_description":"Security researcher Nitesh Dhanjani has discovered a way that hackers could trick users into visiting fake websites by hiding their URLs. In a proof of","og_url":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/","og_site_name":"The Mac Security Blog","article_published_time":"2010-11-30T10:56:25+00:00","article_modified_time":"2012-12-12T21:48:58+00:00","og_image":[{"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png","width":"446","height":"430"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/","name":"Researcher Points Out URL Hiding Trick on iPhone - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#primaryimage"},"datePublished":"2010-11-30T10:56:25+00:00","dateModified":"2012-12-12T21:48:58+00:00","description":"Security researcher Nitesh Dhanjani has discovered a way that hackers could trick users into visiting fake websites by hiding their URLs. In a proof of","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Researcher Points Out URL Hiding Trick on iPhone"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"Researcher Points Out URL Hiding Trick on iPhone","datePublished":"2010-11-30T10:56:25+00:00","dateModified":"2012-12-12T21:48:58+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#webpage"},"wordCount":232,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/researcher-points-out-url-hiding-trick-on-iphone\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/11\/iphone-ui-spoofing-resized.png","keywords":["iPhone","Phishing"],"articleSection":["Apple","Security &amp; Privacy"],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-zx","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/2203"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=2203"}],"version-history":[{"count":0,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/2203\/revisions"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=2203"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=2203"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=2203"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}