Safari hack?
I have Javascript disabled on my IPad. When I browse through certain web pages (89.140.253.190, for example) Javascript switch turns on in my IPad configuration!. Has anybody noticed this odd behaviour?
Other OS
I have Javascript disabled on my IPad. When I browse through certain web pages (89.140.253.190, for example) Javascript switch turns on in my IPad configuration!. Has anybody noticed this odd behaviour?
Other OS
I can confirm it happened to me too. As a matter of fact the first time I did it I went back to the settings App, and actually saw how the slider turned on.
It seems to only be happening with this site though as I can't reproduce it in any others.
Odd.
EDIT: Interesting bug, Seems that the precence of an APP banner causes it, probably to make sure tapping on it brings up the App download correctly in iTunes.
Still scary due to its implications, but at least it confirms there is no hack.
Thanks Jim for the link.
There is a bug in iOS 6 Safari which can cause this to happen.
I've made a video of the hack. You can see it at: http://youtu.be/IYC9B3aSzYo .
The web page isn't suspicious (http://www.20minutos.es). It's a well known spanish newspaper. My ipad has resolved this web to IP address 89.140.253.190, which I don't know if it's correct or not (maybe I'm a victim of an DNS spoofing attack with web redirection, or I have some trigger on my ipad that fires on certain web pages).
Due to the sandboxed nature of the OS, hacking into an iPad is extremely unlikely. That is they may gain entry to Safari (though in all likelyhood that won't happen either), but since the Apps in iOS are completely cut off from each other and the rest of the system there is pretty much no chance of moving past it. That is the hack would need to be sever enough to not only break Safari, but the entire Operating system.
If you were being hacked you would totally know as the entire OS would start to fall apart. It would be be a total system failure if any type of hack were to occurr. Which again given the tight sandboxed nature of the OS is extremely unlikely if not nearly impossible.
That was one of the web pages that I was directed to when I copied and pasted the numbers into the address field in Safari. I turned JavaScript off before I wen there and then checked and JavaScript was still set to off in my settings.
However, after some further experimentation, it is happening to me as well now - but not with regularity. One time it doesn't turn on JavaScript and the next time that I try is will turn it on. Odd... I am no expert on how these things work, but I don't think we are being hacked.
I get two different websites when I enter that into the Safari URL field and in neither case did navigating to the website turn JavaScript on - after I turned it off in the settings.
Phil0124 wrote:
I can confirm it happened to me too. As a matter of fact the first time I did it I went back to the settings App, and actually saw how the slider turned on.
Yeah ... I saw the same thing, really weird!
In my case, I've noticed other strange behaviours (like Spotify becoming irresponsive or some apps closing for no reason) on my ipad until I restored it yesterday. Now this is the only odd thing that remains. What matters me is that it may be an entry point (Safari or ipad vulnerability) for further hacking my ipad again.
Well, I think you're right. I consider more likely my ipad could have been hacked through my PC. When you connect an ipad to iTunes in an untrusted PC using an USB cable you're exposed to trojans/rootkits that may exist in the computer. Too bad it doesn't exist a Live CD with iTunes preinstalled. I think Apple should make a port so iTunes could be included in Ubuntu Live CDs. Another option could be an iTunes Live Cd for PC (maybe a small Mac Os Live CD able to be booted from PCs).
Wow. Never saw this before. Thanks for the heads up!
Safari hack?