Tabnabbing: phishing via forgotten browser tabs
Summary
Aza Raskin shows how an unattended browser page changes its appearance and title and poses as a familiar login service when the user returns. Phishing exploits memory and attention just as deliberately as technical vulnerabilities. Security indicators help little if people do not check the origin of an old tab again.
Ideas
- The attack waits until the user no longer remembers the tab's original content.
- Favicon, title and form imitate a known service without a new pop-up.
- A redirect after the input can additionally conceal the fraud afterwards.
Recommendations
- Use password managers, because they only offer credentials for the matching domain.
- Check the address and TLS origin before logging in again in an old tab.
References
Links to the original source and the Web Archive open in a new tab.