{"id":6411,"date":"2019-09-12T13:50:14","date_gmt":"2019-09-12T10:50:14","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=6411"},"modified":"2019-11-15T14:24:32","modified_gmt":"2019-11-15T11:24:32","slug":"malicious-websites-infect-iphones","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/malicious-websites-infect-iphones\/6411\/","title":{"rendered":"K\u00f6t\u00fc ama\u00e7l\u0131 bir internet sitesinden iPhone&#8217;uma vir\u00fcs bula\u015fabilir. Do\u011fru mu yanl\u0131\u015f m\u0131?"},"content":{"rendered":"<p>iPhone telefonlar\u0131n tehditlere kar\u015f\u0131 tamamen ba\u011f\u0131\u015f\u0131k oldu\u011fu fikri <a href=\"https:\/\/www.kaspersky.com\/blog\/iphone-vulnerabilites\/12009\/\" target=\"_blank\" rel=\"noopener nofollow\">defalarca \u00e7\u00fcr\u00fct\u00fclm\u00fc\u015ft\u00fcr<\/a>. Do\u011frusu, her ne kadar Apple marka ak\u0131ll\u0131 telefonlar Android cihazlara k\u0131yasla daha k\u00fc\u00e7\u00fck bir hedef te\u015fkil etse de, sadece tehlikeli bir internet sitesi a\u00e7arak her t\u00fcrl\u00fc k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 haberiniz olmadan indirip y\u00fckleyebilece\u011finiz s\u00f6ylenir. Bu g\u00f6nderide bunun do\u011frulu\u011funu ara\u015ft\u0131raca\u011f\u0131z.<\/p>\n<h2>Ger\u00e7ek: K\u00f6t\u00fc ama\u00e7l\u0131 internet siteleri, iPhone\u2019un g\u00fcvenlik mekanizmalar\u0131n\u0131 iki y\u0131ldan uzun s\u00fcredir k\u0131rmaktad\u0131r<\/h2>\n<p>Google\u2019\u0131n Zero Projesinde \u00e7al\u0131\u015fan ara\u015ft\u0131rmac\u0131lar, en az iki y\u0131ld\u0131r iPhone telefonlara sald\u0131ran birtak\u0131m <a href=\"https:\/\/googleprojectzero.blogspot.com\/2019\/08\/a-very-deep-dive-into-ios-exploit.html\" target=\"_blank\" rel=\"noopener nofollow\">hacklenmi\u015f internet siteleri ke\u015ffetti<\/a>. Bunun i\u00e7in sald\u0131rganlar, yedisi iPhone kullan\u0131c\u0131lar\u0131n\u0131n b\u00fcy\u00fck \u00e7o\u011funlu\u011funun taray\u0131c\u0131s\u0131 olan Safari\u2019de bulunan 14 adet yaz\u0131l\u0131m a\u00e7\u0131\u011f\u0131ndan yararland\u0131.<\/p>\n<p>Kalan yaz\u0131l\u0131m a\u00e7\u0131klar\u0131ndan ikisi, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n iOS\u2019un bir uygulaman\u0131n di\u011fer uygulamalar\u0131n verilerine eri\u015fmesini (ve tabii ki de\u011fi\u015ftirmesini) \u00f6nlemek i\u00e7in kulland\u0131\u011f\u0131 sandbox\u2019tan ka\u00e7mas\u0131na izin verdi. Di\u011fer be\u015fi de, iOS i\u015fletim sisteminin merkezi bile\u015feni olan \u00e7ekirde\u011fini etkiledi. \u00c7ekirde\u011fin k\u0131r\u0131lmas\u0131, sald\u0131rgana iPhone sahibinde dahi bulunmayan k\u00f6k eri\u015fim ayr\u0131cal\u0131klar\u0131 verir.<\/p>\n<p>S\u00f6z konusu k\u00f6t\u00fc ama\u00e7l\u0131 internet siteleri, iOS 10\u2019dan iOS 12\u2019ye kadar Apple\u2019\u0131n mobil i\u015fletim sisteminin t\u00fcm g\u00fcncel s\u00fcr\u00fcmlerine sald\u0131rabiliyordu. Sald\u0131rganlar, g\u00fcncellemeler kar\u015f\u0131s\u0131nda stratejilerini de\u011fi\u015ftirerek, \u00e7abalar\u0131n\u0131 tamamen yeni sistem a\u00e7\u0131klar\u0131na y\u00f6neltti.<\/p>\n<h3>Etkilenen iPhone telefonlara ne t\u00fcr k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m y\u00fcklenmi\u015f<\/h3>\n<p>Vir\u00fcsl\u00fc internet siteleri, ma\u011fdurlar\u0131n cihazlar\u0131na casus yaz\u0131l\u0131m y\u00fckleyebilmi\u015f, b\u00f6ylelikle s\u0131n\u0131rs\u0131z eri\u015fim ayr\u0131cal\u0131klar\u0131 elde etmi\u015f ve kullan\u0131c\u0131lar\u0131n fark etmeyece\u011fi \u015fekilde arka planda \u00e7al\u0131\u015fm\u0131\u015ft\u0131r. Bunun \u00fczerine, abart\u0131s\u0131z her dakika, cihazdan veri ay\u0131klar bir komut denetim sunucusuna g\u00f6nderirdi. Casus yaz\u0131l\u0131m, a\u011f\u0131rl\u0131kl\u0131 olarak a\u015fa\u011f\u0131dakilerle ilgilenmi\u015ftir:<\/p>\n<ul>\n<li>iCloud Keychain\u2019de kay\u0131tl\u0131 parolalar ve \u015fifre \u00fcrete\u00e7leri Sald\u0131rganlar, bu kimlik bilgilerini kullanarak ma\u011fdurlar\u0131n hesaplar\u0131na s\u00fcrekli eri\u015fim kazanabilmi\u015f ve casus yaz\u0131l\u0131m cihazdan silindikten sonra dahi onlardan veri \u00e7alabilmi\u015flerdir;<\/li>\n<li>iMessage, Hangouts, Telegram, Skype, Voxer, Viber ve WhatsApp programlar\u0131ndaki mesajlar K\u00f6t\u00fc ama\u00e7lu yaz\u0131l\u0131mlar, t\u00fcm mesajlar\u0131n \u015fifrelenmeden sakland\u0131\u011f\u0131 uygulama veri tabanlar\u0131ndan bilgi \u00e7alm\u0131\u015ft\u0131r;<\/li>\n<li>Gmail, Yahoo, Outlook, QQmail ve MailMaster e-posta uygulamalar\u0131ndaki mesajlar Casus yaz\u0131l\u0131mlar, ilgili uygulama veri tabanlar\u0131ndan da veri elde edebilmi\u015ftir;<\/li>\n<li>Arama ge\u00e7mi\u015fi ve k\u0131sa mesajlar;<\/li>\n<li>GPS etkinse cihaz\u0131n konumu hakk\u0131nda ger\u00e7ek zamanl\u0131 bilgi;<\/li>\n<li>Adres defteri;<\/li>\n<li>Foto\u011fraflar;<\/li>\n<li>Notlar;<\/li>\n<li>Sesli notlar.<\/li>\n<\/ul>\n<p>Ayr\u0131ca, komut denetim sunucusu istedi\u011finde k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, sahiplerine cihazdaki uygulamalar\u0131n listesini de g\u00f6ndermi\u015f ve istedi\u011fi uygulamadan verileri takip edebilmi\u015ftir. Daha da k\u00f6t\u00fcs\u00fc, t\u00fcm bilgileri d\u00fcz metin olarak g\u00f6ndermi\u015ftir. Ba\u015fka bir deyi\u015fle, \u015fayet vir\u00fcs bula\u015fm\u0131\u015f bir iPhone halka a\u00e7\u0131k bir Wi-Fi a\u011f\u0131na ba\u011fland\u0131\u011f\u0131nda, sadece casus yaz\u0131l\u0131m\u0131n sahipleri de\u011fil herkes, ma\u011fdura ait olan ve casus yaz\u0131l\u0131m taraf\u0131ndan g\u00f6nderilen parolalar\u0131, mesajlar\u0131 ve di\u011fer bilgileri g\u00f6rebilmekteydi.<\/p>\n<p>Casus yaz\u0131l\u0131m\u0131 geli\u015ftirenlerin, yaz\u0131l\u0131m\u0131n sistemde sa\u011flam bir tutunma noktas\u0131 bulup bulmamas\u0131n\u0131 umursamad\u0131\u011f\u0131, nas\u0131l olsa sistem yeniden ba\u015flat\u0131ld\u0131\u011f\u0131nda ak\u0131ll\u0131 telefondan silindi\u011fi de dikkate al\u0131nmal\u0131d\u0131r. Ancak, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n bir kerede ne kadar bilgi \u00e7alabildi\u011fi g\u00f6z \u00f6n\u00fcnde tutuldu\u011funda, silinmesi k\u00fc\u00e7\u00fck bir avuntudan \u00f6teye gitmemektedir.<\/p>\n<h3>Tehdidi atlatt\u0131k \u2026 m\u0131?<\/h3>\n<p>Apple geli\u015ftiricileri, siber su\u00e7lular\u0131n bu \u00e7er\u00e7evede k\u00f6t\u00fcye kullanabildikleri son sistem a\u00e7\u0131klar\u0131n\u0131 da 2019 y\u0131l\u0131 \u015eubat ba\u015f\u0131nda \u00e7\u0131kard\u0131\u011f\u0131 iOS s\u00fcr\u00fcm\u00fc 12.1.4 ile giderdi. Dolay\u0131s\u0131yla, i\u015fletim sisteminin son s\u00fcr\u00fcmleri s\u00f6z konusu sald\u0131r\u0131lara kar\u015f\u0131 korumal\u0131d\u0131r.<\/p>\n<p>Yine de, uzmanlara g\u00f6re her hafta birka\u00e7 bin kullan\u0131c\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 internet sitelerine giriyor. Bu da, b\u00fcy\u00fck bir olas\u0131l\u0131kla \u00e7ok say\u0131da ma\u011fdur oldu\u011fu anlam\u0131na geliyor. Ayr\u0131ca, etkisiz hale getirilmi\u015f internet sayfalar\u0131n\u0131n yerini hen\u00fcz ke\u015ffedilmemi\u015f sistem a\u00e7\u0131klar\u0131ndan yararlanan ba\u015fka internet siteleri alabilir.<\/p>\n<h3>iPhone\u2019unuza k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m girmesini nas\u0131l \u00f6nlersiniz<\/h3>\n<p>G\u00f6rd\u00fc\u011f\u00fcn\u00fcz gibi Apple marka ak\u0131ll\u0131 telefonunuza k\u00f6t\u00fc ama\u00e7l\u0131 bir internet sitesinden vir\u00fcs girebilir ve \u00e7ok ciddi sonu\u00e7larla kar\u015f\u0131la\u015fabilirsiniz. Bu y\u00fczden, cihaz\u0131n\u0131z\u0131 tehdit eden bir \u015fey olmad\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcnseniz bile dikkatli davranman\u0131z\u0131 tavsiye ederiz.<\/p>\n<ul>\n<li>iPhone\u2019unuzda daima en son iOS s\u00fcr\u00fcm\u00fcn\u00fcn y\u00fckl\u00fc oldu\u011fundan emin olun. G\u00fcncellemeleri \u00e7\u0131kar \u00e7\u0131kmaz indirin. Geli\u015ftiriciler, siber su\u00e7lular\u0131n kullanabilece\u011fi (ve g\u00f6rd\u00fc\u011f\u00fcn\u00fcz gibi bu tehdit hi\u00e7 de teoride kalmamaktad\u0131r) sistem a\u00e7\u0131klar\u0131n\u0131 yeni iOS s\u00fcr\u00fcmlerinde giderir.<\/li>\n<li>Tan\u0131mad\u0131klar\u0131n\u0131zdan gelen e-posta, mesaj ve reklamlardaki ba\u011flant\u0131lara t\u0131klamay\u0131n. Arama sonu\u00e7lar\u0131na da dikkatle yakla\u015fmal\u0131s\u0131n\u0131z: Belli bir kayna\u011f\u0131n d\u00fcr\u00fcstl\u00fc\u011f\u00fcnden \u015f\u00fcpheye d\u00fc\u015ferseniz, en iyisi hi\u00e7 a\u00e7mamaktad\u0131r.<\/li>\n<\/ul>\n<p>\u00d6nceden bilinmeyen tehhditleri bile \u00f6nleyebilen davran\u0131\u015f analizi teknolojisinin kullan\u0131ld\u0131\u011f\u0131 bir g\u00fcvenlik \u00fcr\u00fcn\u00fc ile iPhone\u2019unuz i\u00e7in koruma sa\u011flayabilirsiniz. Ancak ne yaz\u0131k ki, <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/ios-security-explainer\/5269\/\" target=\"_blank\" rel=\"noopener\">iOS i\u00e7in eksiksiz bir antivir\u00fcs \u00e7\u00f6z\u00fcm\u00fc mevcut de\u011fildir<\/a>.<\/p>\n<p><strong>\u00d6zet olarak: iPhone telefonlar\u0131n sadece k\u00f6t\u00fc ama\u00e7l\u0131 bir internet sitesine girerek etkilenebilece\u011fi ger\u00e7ek mi yoksa efsane mi?<\/strong><\/p>\n<p><strong>Ger\u00e7ek. K\u00f6t\u00fc ama\u00e7l\u0131 internet siteleri, mobil taray\u0131c\u0131daki ve iOS i\u015fletim sistemindeki a\u00e7\u0131klar\u0131 her t\u00fcrl\u00fc k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 y\u00fcklemek i\u00e7in kullanabilir. Google\u2019un Zero Projesi ara\u015ft\u0131rmac\u0131lar\u0131n\u0131n bahsetti\u011fi kaynaklar art\u0131k tehlike arz etmiyor olsa da, her an yenileri \u00e7\u0131kabilir.<\/strong><\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksc\">\n","protected":false},"excerpt":{"rendered":"<p>Baz\u0131lar\u0131, sadece tehlikeli bir internet sayfas\u0131na girerek bile iPhone&#8217;nunuza k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m girebilece\u011fini s\u00f6yl\u00fcyor. Ger\u00e7e\u011fi ortaya \u00e7\u0131karmak bu s\u00f6ylentiyi masaya yat\u0131r\u0131yoruz.<\/p>\n","protected":false},"author":2509,"featured_media":6412,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[555,14,1900,2006,750,26,2005,537],"class_list":{"0":"post-6411","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-akilli-telefonlar","9":"tag-apple","10":"tag-casus-yazilim","11":"tag-dogru-yanlis","12":"tag-ios","13":"tag-iphone","14":"tag-kotuye-kullanma","15":"tag-tehditler"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/malicious-websites-infect-iphones\/6411\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/malicious-websites-infect-iphones\/16611\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/malicious-websites-infect-iphones\/14003\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/malicious-websites-infect-iphones\/6498\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/malicious-websites-infect-iphones\/18573\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/malicious-websites-infect-iphones\/16646\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/malicious-websites-infect-iphones\/15365\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/malicious-websites-infect-iphones\/19232\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/malicious-websites-infect-iphones\/17915\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/malicious-websites-infect-iphones\/23537\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/malicious-websites-infect-iphones\/28493\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/malicious-websites-infect-iphones\/12266\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/malicious-websites-infect-iphones\/12285\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/malicious-websites-infect-iphones\/11165\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/malicious-websites-infect-iphones\/20119\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/malicious-websites-infect-iphones\/24057\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/malicious-websites-infect-iphones\/24252\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/malicious-websites-infect-iphones\/19039\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/malicious-websites-infect-iphones\/23332\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/malicious-websites-infect-iphones\/23243\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/ios\/","name":"iOS"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2509"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=6411"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6411\/revisions"}],"predecessor-version":[{"id":6731,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6411\/revisions\/6731"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/6412"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=6411"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=6411"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=6411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}