rhu: (Default)
[personal profile] rhu
"Tabnapping" is a new phishing technique. All you need to know in one sentence: If you go to a browser tab and it looks like Google or some other site has signed you out after inactivity, DON'T SIGN BACK IN ON THAT PAGE, but close that tab and open a FRESH one to sign in.

Details for the technically inclined are at http://www.azarask.in/blog/post/a-new-type-of-phishing-attack/ along with a proof-of-concept implementation.

This is real, it's clever, and while I haven't heard of it being used for real yet, it was announced yesterday so by now I'm sure it's out there. Spread the word.

(no subject)

Date: 2010-05-27 04:19 pm (UTC)
desireearmfeldt: (Default)
From: [personal profile] desireearmfeldt
Bah, I think this has been happening to me for a week or more...since I had gmail windows open, I assumed it was gmail changing its settings on when to time you out. More password changing for me.

(no subject)

Date: 2010-05-27 08:31 pm (UTC)
desireearmfeldt: (Default)
From: [personal profile] desireearmfeldt
Or, perhaps gmail really has changed its system as well, since typing in the url still seems to get me the login screen.

(no subject)

Date: 2010-05-27 04:58 pm (UTC)
From: [identity profile] goldsquare.livejournal.com
It is worth noting that his web page (that you linked to) can exhibit the behavior of tab-napping, for demonstration purposes only.

You may want to EMPHASIZE THAT A LITTLE. :-)

The normal Internet defenses I use forced his exploit to fail. :-)

(no subject)

Date: 2010-05-28 03:24 am (UTC)
cellio: (avatar-face)
From: [personal profile] cellio
Clever.

My usual settings prevented it from working for me with his site, but that doesn't mean someone couldn't pull it off anyway. Good to have the warning. (I watched the video rather than lowering my defenses. :-) )

Profile

rhu: (Default)
Andrew M. Greene

January 2013

S M T W T F S
  12345
6789101112
13141516171819
20212223242526
2728293031  

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags