tabnapping hitting the internet now

For discussions about security.
Post Reply
Message
Author
labbe5
Posts: 2159
Joined: Wed 13 Nov 2013, 14:26
Location: Canada

tabnapping hitting the internet now

#1 Post by labbe5 »

http://www.hackersonlineclub.com/tab-napping/

Tab napping is more sophisticated than the phishing scams we’ve seen so far, and it no longer relies on persuading you to click on a dodgy link. Instead it targets internet users who open lots of tabs on their browser at the same time.

if you have multiple tabs open and you are reading the page on your current active tab, any of the other inactive browser tabs could be replaced with a fake web page that is set up to obtain your personal data, the web page will look exactly the same as the page you opened in the tab, you probably wont even even know it has been replaced with a fake page.




How can you protect yourself against tab napping?

Here are five simple ways you can prevent yourself from falling victim:
• Make sure you always check the URL in the browser address page is correct before you enter any login details. A fake tabbed page will have a different URL to the website you think you’re using.
• Always check the URL has a secure https:// address even if you don’t have tabs open on the browser.
• If the URL looks suspicious in any way, close the tab and reopen it by entering the correct URL again.
• Avoid leaving tabs open which require you to type in secure login details. Don't open any tabs while doing online banking - open new windows instead (CTRL + N).

spup
Posts: 2
Joined: Sun 09 Aug 2015, 14:01

#2 Post by spup »

You should be ok if you use No script, they had developed a block against this in about 2010/11,
roundabout the time this exploit was first discovered.

Post Reply