Devious New Phishing Tactic Targets Tabs

Corrine

Account closed
Local time
12:21 AM
Messages
2,303
Location
Upstate NY
Consider the following scenario: Bob has six or seven tabs open, and one of the sites he has open (but not the tab currently being viewed) contains a script that waits for a few minutes or hours, and then the script quietly changes the both the content of the page and the icon and descriptor in the tab itself so that it appears to be the login page for Gmail.

In this attack, the phisher need not even change the Web address displayed in the browser’s navigation toolbar. Rather, this particular phishing attack takes advantage of user trust and inattention to detail, or what Raskin calls “the perceived immutability of tabs.” Then, as the user scans their many open tabs, the favicon and title act as a strong visual cue, and the user will most likely simply think they left a Gmail tab open.

“When they click back to the fake Gmail tab, they’ll see the standard Gmail login page, assume they’ve been logged out, and provide their credentials to log in. The attack prays on the perceived immutability of tabs,” Raskin explained. “After the user has enter they have entered their login information and sent it back your your server, you redirect them to Gmail. Because they were never logged out in the first place, it will appear as if the login was successful.”
See the complete article by Brian Krebs at Devious New Phishing Tactic Targets Tabs — Krebs on Security
 

My Computer My Computer

OS
Windows 7 & Windows Vista Ultimate
Something that might have even tricked me. Thanks for the heads up.
 

My Computer My Computer

OS
Arch Linux 64-bit
Good thing I use outlook. So I know whats up if this were to ever happen to me
 

My Computer My Computer

Computer Manufacturer/Model Number
custom build
OS
Windows 7 Pro X64
CPU
AMD Phenom II X4 975 Black Edition
Motherboard
MSI 870A-G54 (FX)
Memory
CORSAIR Vengeance 8GB (2 x 4GB) 240-Pin DDR3 SDRAM DDR3 1600
Graphics Card(s)
ASUS EN9800GT HB/HTDI/512M GeForce 9800 GT 512MB 256-bit GDD
Sound Card
Realtek ALC892
Monitor(s) Displays
Viewsonic 19' 16:10
Screen Resolution
1680X1050
Hard Drives
Western Digital Caviar Black WD6401AALS 640GB 7200 RPM SATA,
Western Digital Caviar Black 1TB 7200RPM SATA
PSU
Thermaltake Purepower W0100RU 500W ATX 12V
Case
COOLER MASTER Elite RC-331-KKN1-GP Black SECC ATX Mid Tower
Cooling
Nothing beyond what etch part came with
Keyboard
Logitech G11
Mouse
USB Logitech gaming mouse
Internet Speed
Cable
Other Info
New CPU, Motherboard, and Ram installed 02/2012

Logitech G35 Headset
I rarely use gmail. Unless there's a fake Yahoo mail.. I'm gonna be cautious
 

My Computer My Computer

OS
window's 7
CPU
core 2 quad
Motherboard
gigabyte
Memory
2gb corsair
Graphics Card(s)
ati hd4850
Monitor(s) Displays
lg
Screen Resolution
1600 X 900
Case
power logic
Other Info
none of the spec above is accurate
I rarely use gmail. Unless there's a fake Yahoo mail.. I'm gonna be cautious


Quote from link: "It’s important to keep in mind that this attack could be used against any site, not just Gmail. "

Edit: reiteration: This could be any site...not just email....

I would be cautious.... Although the javascript is ran from the attack-site so you would need to be surfing in dangerous waters first. Just be on Gaurd or change surfing habits to close pages and re-open from bookmarks whenever logging in.


Thanks Corrine for info!
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2
I guess i've missed that.. Thanks for the heads up thorsen ;)
 

My Computer My Computer

OS
window's 7
CPU
core 2 quad
Motherboard
gigabyte
Memory
2gb corsair
Graphics Card(s)
ati hd4850
Monitor(s) Displays
lg
Screen Resolution
1600 X 900
Case
power logic
Other Info
none of the spec above is accurate
This is a classic social engineering trick, you have to be aware of this. If you had a open tab that was logged into whatever and it suddenly shows you to be logged out that should be a big red flag. using explorer is less protection as well you need a flash blocker for the best safety, and FF provides some of the best addons for overall safety, if set up correctly.
 

My Computer My Computer

Computer Manufacturer/Model Number
ACER aspire one
OS
XP/W7/Lucid/Arch
Memory
2 gigs
Back
Top