Do you have a question? Post it now! No Registration Necessary. Now with pictures!
- Posted on
- Tab + Kidnapping = 'Tabnabbing"
- The Real Truth MVP
July 1, 2010, 10:34 pm
rate this thread
on users' inattention to which tabs they have open in their browsers. The
users have several tabs open and are not viewing the site with the malicious
code, the code surreptitiously changes the destination page after several
minutes of inactivity; the favicon and title of the page are changed as
well. The attack can be made more personal by perusing users' browsing
histories and making the page appear to be one that the user frequents, such
as Facebook or a banking login page. When the user goes back to the tab,
there is a sign-on screen asking for login credentials. The vulnerability
affects all major browsers that run on Mac OS X and Windows.
How the Attack Works
1.A user navigates to your normal looking site.
2.You detect when the page has lost its focus and hasn't been interacted
with for a while.
3.Replace the favicon with the Gmail favicon, the title with "Gmail: Email
from Google", and the page with a Gmail login look-a-like. This can all be
4.As the user scans their many open tabs, the favicon and title act as a
strong visual cue-memory is malleable and moldable and the user will most
likely simply think they left a Gmail tab open. When they click back to the
fake Gmail tab, they'll see the standard Gmail login page, assume they've
been logged out, and provide their credentials to log in. The attack preys
on the perceived immutability of tabs.
5.After the user has entered their login information and you've sent it back
to your server, you redirect them to Gmail. Because they were never logged
out in the first place, it will appear as if the login was successful.
The referenced article below gives more details and methods of avoiding
being tabnabbed. Primarily, if an open tab requests a login when you return
to it close the tab and go directly to the site.
The Real Truth http://pcbutts1-therealtruth.blogspot.com /
*WARNING* Please Do NOT follow any advice given by the Trolls listed
below. Trolls CAN NOT help you. They latch on to my posts like leeches.
David H Lipman, Peter Foldes, Barry Schwarz, PA Bear, Leythos.
Re: Tab + Kidnapping = 'Tabnabbing"
You stupid stupid little man. You now proved for the umpteenth time that you
brains or a backbone. You friggin 2 faced thief,liar and Troll
Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.