Feeds

Tabnapping attack baits phishing trawl

Hook, link and stinker

5 things you didn’t know about cloud backup

A leading developer of Firefox has warned of a sneaky potential new form of phishing attack.

Aza Raskin, the creative lead for Firefox, explains that the approach exploits the fact that most surfers keep many tabs open during a browsing session, without really keeping track of what sites they have visited.

The so-called tabnapping attack works by using JavaScript to switch the destination page in a tab after a few seconds of inactivity. This might be done using attack script planted in an otherwise legitimate website, for example.

If a surfer has only one tab open he is likely to get suspicious if a browser seems to be pointing at Gmail or other potential target rather than a news site, for example, and double check. But this is far less likely to happen if a user has multiple tabs open and where he might easily be induced to log in again, handing over login credentials to an attacker in the process.

The potential attack might be customised using a surfer's browser history file, Raskin warns. "Using my CSS history miner you can detect which site a visitor uses and then attack that. For example, you can detect if a visitor is a Facebook user, Citibank user, Twitter user, etc, and then switch the page to the appropriate login screen and favicon on demand," he explains.

Raskin has posted an explanation of the attack in a blog post here (watch what happens after you leave the page for a few seconds) and in a video explanation uploaded to Vimeo (below).

He suggests that improving browser technology that remembers login credentials for websites is one approach to help combat the problem. At best this is a partial solution, though, since many users avoid using password management in general; and saving passwords is an extremely bad idea when using computers in libraries or even at work that are shared by multiple users. ®

A New Type of Phishing Attack from Aza Raskin on Vimeo

Next gen security for virtualised datacentres

More from The Register

next story
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.