| New phishing attack exploits tabbed browsing |
| Source: H Security - Posted by Alex | ||
|
Raskin suggests a number of ways the attack could be improved, for example by using CSS history mining to present fake pages and favicons that the user might regularly visit, detecting if a user is logged into a service or modifying the presented page to suggest that the user has been timed out by a service. The attack is described by Raskin in a blog posting that includes a safe example of the attack. In the post he suggests that this type of attack could be mitigated by developments such as Firefox Account Manager where the browser takes a more active role in protecting the users identity and credentials. [All of article]
Read this full article at H Security
Only registered users can write comments. Powered by AkoComment! |
||