ghacks Technology News

Interesting Phishing Concept Tabjacking

By now most Internet users know what phishing stands for, or so they think. If you ask them to define phishing most will likely mention that it is about fake email links that lead to look-a-like copies of popular websites. What most users do not know is that their definition of phishing is not entirely correct. Phishing, which stands for Password fISHING, is not exclusive to email. The term hints at that little known fact. Phishing can occur everywhere including Instant Messengers, forums, by social engineering and on plain websites.

Aza Raskin just posted an interesting article on his blog detailing a new phishing attack that he calls Tabjacking. The concept of this new attack is ingenious.

It basically refers to a website that is changing its look and feels to a fake website after some time of inactivity. Here is how it works.

The web user visits a harmless looking site and decides to keep it open in a tab for the time being. A JavaScript code on the page notices that and replaces the site’s favicon and title with a popular site’s one. This could be Facebook, Gmail or any other popular website that the user likely uses.

The website itself will also change its contents so that it looks like the website that the attacker wants to steal login credentials for.

Many users identify websites in tabs by their favicon and title. This could lead to the user believing that the site is indeed the real website. Clicking on the tab displays what the user expects to see as the copy looks exactly like the original.

For Gmail it would for instance be the Gmail login form. Users who enter their login credentials into the form will send them right to the attacker. The script on the website will redirect the user to the real website in the end.

A New Type of Phishing Attack from Aza Raskin on Vimeo.

There are obviously a few elements left that the user can use to identify the attack. The url for instance will not reflect the website that is displayed to the user. It is also likely that the site will not make use of https.

Take a look at Aza’s blog post for additional information about the attack including codes, fixes and lots of user comments.

Enjoyed the article?: Then sign-up for our free newsletter or RSS feed to kick off your day with the latest technology news and tips, or share the article with your friends and contacts on Facebook or Twitter.

Related Articles:

Test The Phishing Protection In Firefox
Fix Slow Internet Explorer 7 Phishing Filter Response Times
Amazon Phishing page
Phishing Protection Tips
Introduction to new phishing techniques



About the Author:Martin Brinkmann is a journalist from Germany who founded Ghacks Technology News Back in 2005. He is passionate about all things tech and knows the Internet and computers like the back of his hand. You can follow Martin on Facebook or Twitter.

Author: , Tuesday May 25, 2010 -
Tags:, , , , ,


Responses so far:

  1. kalmly says:

    Aza’s blog post link gave me 403 error:
    Forbidden
    You don’t have permission to access /blog/posta-new-type-if-phishing-attack/ on this server.

  2. Tobey says:

    Ingeniously dangerous concept indeed. Thanks for the heads up.

Leave a Reply   Follow Ghacks   Subscribe To Comment Rss

Subscribe without commenting

© 2005-2012 Ghacks.net. All Rights Reserved. Privacy Policy - About Us