| 1 posts found | |
|---|---|
|
http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/ The gist is that the attack changes the Title, the icon on the tab, and the appearance of the page so that everything perfectly mimics the targeted website. In this example they use Gmail, but this can be used to steal your information for anywebsite, including gaming sites. The attack works against all browsers, including against Firefox in "paranoid mode" with the NoScript add-on. There is an update for the NoScript add-on that is supposed to help protect against this style of attack so check for updates to Firefox and its add-ons, but don't rely on it entirely. The visual reproduction is perfect. The only flaw that I see is that - at least in the proof of concept that's provided - the URL does not change to match the attacked site. Still, it would be very easy to miss that and there's no gurantee that future versions of this phishing attack will not find a way to mask the URL as well. oh hai this is not a sig |
|