Tabjacking: A New Type of Phishing Attack

A new form of hijacking which makes use of the browser tabs, could be exploited to obtain confidential user information.

Aza Raskin is a renowned interface designer that works in Mozilla and who shows us a video in which this method named as Tabjacking could be used to modify the contents of one of our tabs, so someone with little experience can be fooled.

In the video we can see how a website changes completely when a user visits a harmless website and keep it open in one of the opened tabs. Jscript on that website notices this situation and replaces content and website favorite icon with most popular websites like Gmail, Facebook, and Yahoo etc. When a user enter their login credentials, that information is directly sent to hacker and after some time script on that page will re-direct the user to the original website.

Users should keep in mind some aspects, for example the URL that will not reflect the website that is opened and also that this type of connection will not make a HTTPS connection.

A New Type of Phishing Attack from Aza Raskin on Vimeo.

  1. No comments yet.

  1. No trackbacks yet.

 

 
Content Protected Using Blog Protector By: PcDrome.