bk99.de entertain the web since 1997

Tabnabbing: phishing via forgotten browser tabs

Summary

Aza Raskin shows how an unattended browser page changes its appearance and title and poses as a familiar login service when the user returns. Phishing exploits memory and attention just as deliberately as technical vulnerabilities. Security indicators help little if people do not check the origin of an old tab again.

Ideas

  • The attack waits until the user no longer remembers the tab's original content.
  • Favicon, title and form imitate a known service without a new pop-up.
  • A redirect after the input can additionally conceal the fraud afterwards.

Recommendations

  • Use password managers, because they only offer credentials for the matching domain.
  • Check the address and TLS origin before logging in again in an old tab.

References

Read the original post

Search the Web Archive