Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
A leading Firefox developer has discovered a new phishing attack method. The attack, dubbed “tabnabbing” preys on browser tabs and the fact that users generally don't keep track of all the tabs they have open at one time, said Aza Raskin, creative lead for Mozilla's Firefox web browser, who discovered and publicised the technique. In this type of phish, a user must be tricked into visiting a maliciously crafted tabbed page containing JavaScript, Raskin said. This allows the attacker to surreptitiously change the contents of a separately tabbed page, in addition to the name and logo on that tab. When a user eventually returns to the tab, they see the spoofed page for a site, for example, Gmail or Facebook. The attack is different from most phishing ploys, which rely on deception alone, Raskin said. This tacic relies on the “perceived immutability of tabs." “What we don't expect is that a page we've been looking at will change behind our backs, when we aren't looking,” Raskin wrote. “That'll catch us by surprise.” An attacker could make the phishing ruse even more cunning by creating a targeted attack that takes advantage of a user's web browsing history file, Raskin warned. In addition, instead of simply displaying a login screen on the spoofed page, an attacker could display a message that the user's session has timed out, thereby adding legitimacy to the attack. Raskin provided a proof-of-concept of the attack, in which a bogus Gmail page is displayed. According to researchers at Mac security vendor Intego, the proof-of-concept works on Firefox and Safari. “For now, there's no way to indicate that the page has changed, and users should be extremely careful before logging into any webmail, bank or online commerce site page,” Intego researchers wrote in a blog post. In addition, they said users should check the URL of a site carefully if an unexpected login screen appears.To further protect themselves, users can consider running the NoScript add-on for Firefox, Mike Rothman of security consultancy Securosis said in a blog post. Or they can deploy a password management tool, which should not make saved logins available for use at malicious sites.See original article on scmagazineus.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.