Skip to content

Latest commit

 

History

History
21 lines (18 loc) · 918 Bytes

2010-05-01-tab_nabbing.md

File metadata and controls

21 lines (18 loc) · 918 Bytes
layout title permalink tags
post
Tab nabbing attack
/tab_nabbing/
web security
phishing

An ingenious phishing vector: Aza Raskin found a clever way to phish users' credentials. The idea consits of waiting until a visitor switches tabs to replace the favicon and page content with a fake site.

Proof of concept

You can try the attack by visiting http://www.azarask.in/blog/post/a-new-type-of-phishing-attack/. After loading the page, switch tabs for a few seconds and then go back to Aza's site.

Mitigation

You can avoid falling for this attack by:

  • Always checking the URL before entering a password.
  • Closing tabs you no longer need.
  • Using your browser's account manager.
  • Opening shady websites in a dedicated window, browser or laptop.