Hot on HuffPost Tech:

See More Stories
AOL Tech

'Tabnapping' Is a Terrifying New Phishing Attack

We talk up the security of Firefox quite a bit around here, but don't misunderstand; Firefox is not impenetrable. In fact, a new, particularly devious phishing attack that manipulates browser tabs works best against the second most popular browser in the world.

The attack, dubbed "tabnapping" by Firefox creative lead Aza Raskin, uses Javascript to replace the contents of a tab and its label. The malicious code waits until you switch to view another tab. Then, when you're not paying attention, it quietly changes its contents to resemble the Gmail log-in screen (or some other information-collecting site). Between the convincing fake page and the Gmail favicon in the tab bar, it's likely that many will simply assume they left the tab open and were logged out. After collecting your log-in credentials, it simply forwards you to the correct page (in this case Gmail), because you were never actually logged out. The attack script can be triggered on a delay so that it will only change the page if it has not been touched for several minutes, or hours, preying on the inaccuracy of a user's memory. It can even mine your browser history to target the sites you're currently logged-into without special coding.

The attack works best against Firefox, but other browsers are not completely immune. Chrome, Safari and Internet Explorer can be made to load the fake page in the background, but the favicon and text in the tab don't always change. You can see the video of Raskin's proof of concept in action below, or you can visit his blog here. After opening his page, switch to another tab for at least five seconds. When you return you'll notice the favicon has changed, and a perfect copy of the Gmail log-in screen has replaced the post you were just reading. Terrifying.

This is just one more reason to pay extra attention to that address bar. [From: Aza Raskin, via: Krebs on Security]

Tags: aza raskin, AzaRaskin, browsers, firefox, google chrome, GoogleChrome, internet explorer, InternetExplorer, phishing, security, tabnapping, top

Comments

3