<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://blog.intelius.com"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Intelius - Raskin</title>
 <link>http://blog.intelius.com/taxonomy/term/95/0</link>
 <description></description>
 <language>en</language>
<item>
 <title>The latest scam YOU need to be aware of: &#039;tabnabbing&#039;</title>
 <link>http://blog.intelius.com/latest-scam-you-need-be-aware-tabnabbing</link>
 <description>&lt;p&gt;Think ‘tabnabbing’ sounds like the latest prank involving filing 
supplies and the office clown? Think again.&amp;nbsp; Tabnabbing (also referred 
to as tabnapping) is a new type of phishing attack that is sweeping the 
internet.&amp;nbsp; Most phishing scams rely on you clicking on an imbedded link 
or downloading a file you find in a suspect email, sketchy website or a 
pop up window.&amp;nbsp; Tabnabbing occurs in the background after your focus 
shifts away from a malicious or compromised site.&amp;nbsp; &amp;nbsp;&lt;/p&gt;&lt;p&gt;“What we 
don’t expect is that a page we’ve been looking at will change behind our
 backs, when we aren’t looking. That’ll catch us by surprise,” Said Aza 
Raskin, Firefox&#039;s creative lead who identified the attack.&amp;nbsp; “Most people
 keep multiple tabs open, often for long periods.” &lt;/p&gt;&lt;p&gt;This 
attack uses JavaScript to discretely change the contents of an open but 
not active tab in your browser to look like the log-in screen of a bank,
 credit card company, popular retail site, social networking site or 
email provider.&amp;nbsp; This page transformation only occurs after the page 
becomes “inactive” while a victim moves to another tab or open program. 
The scammers are relying on users thinking they left a login page tab 
open.&amp;nbsp; &amp;nbsp;&lt;/p&gt;&lt;p&gt;&quot;When they click back to the fake tab, they&#039;ll see 
the standard Gmail log-in page, assume they&#039;ve been logged out, and 
provide their credentials to log in,&quot; says Raskin. &lt;/p&gt;&lt;p&gt;Raskin was
 able to recreate “tabnabbing” on his own blog to show users what to 
look for.&amp;nbsp; You can try it &lt;a href=&quot;http://www.azarask.in/blog/post/a-new-type-of-phishing-attack/&quot; target=&quot;_new&quot;&gt;here&lt;/a&gt;.
 After clicking the link, open a new tab, or simply click away from the 
page for a few seconds and then go back to the original tab.&amp;nbsp; While the 
URL hasn’t changed, the original blog content you saw only moments ago 
has been replaced with what appears to be a Gmail login page.&amp;nbsp; In this 
case the Gmail login page is just an image; however, in the case of an 
actual tabnabbing attack the page will be a functional login form. &lt;/p&gt;&lt;p&gt;In
 an actual attack after the user enters their login information, it’s 
sent it back to the attacker, and then the victim redirected back to the
 site they think they are logging into. This often goes completely &lt;br /&gt;undetected
 because often the victim was never logged out in the first place, and 
it will simply appear as if the login was successful, never realizing 
that they just handed over the all credentials the attacker needed to 
access their account.&amp;nbsp; &amp;nbsp;&lt;/p&gt;&lt;p&gt;It is even possible for attackers to 
detect which sites are in your history as well as what sites you are 
currently logged into and then customize the fake page to resemble a 
site you often use or are currently logged into, making this form of 
attack extremely effective and difficult to detect.&amp;nbsp; All major browsers 
are susceptible to this attack. &amp;nbsp;&lt;/p&gt;&lt;p&gt;Here’s what to watch for and
 how to avoid a potential tabnabbing attack and keep your identity, 
information, and login credentials safe:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Don&#039;t log-in on a
 tab that you haven&#039;t opened yourself.&lt;/strong&gt; Since the tabnabbing tactic 
banks on you trusting that you opened the tab -- and that the site 
simply timed out -- the best defense is this offensive move. In other 
words, if you see a tab that contains a seemingly-legit log-in form, 
close it, then head to the site yourself in a new tab. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Enable
 browser settings and filters that will alert you to potential attacks.&lt;/strong&gt;
 For Internet Explorer (IE) use SmartScreen. In Firefox and Chrome it&#039;s 
called &quot;Phishing and Malware Protection;&quot; Safari doesn&#039;t give it a name,
 but offers a setting that reads, &quot;Warn when visiting a fraudulent 
website&quot; in the Security section of its Preferences settings. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Look
 at the URL in your browser&#039;s address bar before filing in any&lt;/strong&gt; form 
or giving out any personal information and verify the URL matches the 
login page. If there’s a discrepancy, close the tab &lt;br /&gt;immediately. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Use
 a password manager.&lt;/strong&gt; Third-party browser password managers like &lt;a href=&quot;http://www.roboform.com/&quot; target=&quot;_new&quot;&gt;RoboForm&lt;/a&gt; for Windows or &lt;a href=&quot;http://agilewebsolutions.com/products/1Password&quot; target=&quot;_new&quot;&gt;1Password&lt;/a&gt;
 for Mac link saved log-in usernames and passwords to a specific URL. 
When you save the username and password on the log-in page of the 
legitimate site, the password manager won&#039;t auto enter the username and 
password into a non-matching URL which should alert you to a possible 
tabnabbing attempt. &lt;/p&gt;&lt;p&gt;For more info on avoiding Tabnapping read 
ComputerWorld’s &lt;a href=&quot;http://www.computerworld.com/s/article/9177398/How_to_foil_Web_browser_tabnapping_&quot; target=&quot;_new&quot;&gt;How
 to Foil Web Browser Tabnapping. &lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;comment-link&quot;&gt;&lt;a href=&quot;/latest-scam-you-need-be-aware-tabnabbing#comments&quot;&gt;2 comments&lt;/a&gt; &amp;ndash; &lt;a href=&quot;/latest-scam-you-need-be-aware-tabnabbing#comments&quot;&gt;Read/add comments&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;service-links&quot;&gt;&lt;div class=&quot;service-label&quot;&gt;Bookmark/Search this post with: &lt;/div&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li class=&quot;service_links_delicious first&quot;&gt;&lt;a href=&quot;http://del.icio.us/post?url=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;title=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Bookmark this post on del.icio.us.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/delicious.png&quot; alt=&quot;Delicious&quot; /&gt; Delicious&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_digg&quot;&gt;&lt;a href=&quot;http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;title=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Digg this post on digg.com.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/digg.png&quot; alt=&quot;Digg&quot; /&gt; Digg&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_stumbleupon&quot;&gt;&lt;a href=&quot;http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;title=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Thumb this up at StumbleUpon.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/stumbleit.png&quot; alt=&quot;StumbleUpon&quot; /&gt; StumbleUpon&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_propeller&quot;&gt;&lt;a href=&quot;http://www.propeller.com/submit/?U=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;T=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Submit to Propeller.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/propeller.png&quot; alt=&quot;Propeller&quot; /&gt; Propeller&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_reddit&quot;&gt;&lt;a href=&quot;http://reddit.com/submit?url=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;title=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Submit this post on reddit.com.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/reddit.png&quot; alt=&quot;Reddit&quot; /&gt; Reddit&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_magnoliacom&quot;&gt;&lt;a href=&quot;http://ma.gnolia.com/bookmarklet/add?url=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;title=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Submit this post on ma.gnolia.com.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/magnoliacom.png&quot; alt=&quot;Magnoliacom&quot; /&gt; Magnoliacom&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_furl&quot;&gt;&lt;a href=&quot;http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;t=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Submit this post on furl.net.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/furl.png&quot; alt=&quot;Furl&quot; /&gt; Furl&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_facebook&quot;&gt;&lt;a href=&quot;http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;t=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Share on Facebook.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/facebook.png&quot; alt=&quot;Facebook&quot; /&gt; Facebook&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_google&quot;&gt;&lt;a href=&quot;http://www.google.com/bookmarks/mark?op=add&amp;amp;bkmk=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;title=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Bookmark this post on Google.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/google.png&quot; alt=&quot;Google&quot; /&gt; Google&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_yahoo&quot;&gt;&lt;a href=&quot;http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&amp;amp;t=The+latest+scam+YOU+need+to+be+aware+of%3A+%27tabnabbing%27&quot; title=&quot;Bookmark this post on Yahoo.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/yahoo.png&quot; alt=&quot;Yahoo&quot; /&gt; Yahoo&lt;/a&gt;&lt;/li&gt;
&lt;li class=&quot;service_links_technorati last&quot;&gt;&lt;a href=&quot;http://technorati.com/cosmos/search.html?url=http%3A%2F%2Fblog.intelius.com%2Flatest-scam-you-need-be-aware-tabnabbing&quot; title=&quot;Search Technorati for links to this post.&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;/sites/all/modules/contrib/service_links/images/technorati.png&quot; alt=&quot;Technorati&quot; /&gt; Technorati&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://blog.intelius.com/latest-scam-you-need-be-aware-tabnabbing&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://blog.intelius.com/latest-scam-you-need-be-aware-tabnabbing#comments</comments>
 <category domain="http://blog.intelius.com/category/tags/cyber-crimes">Cyber Crimes</category>
 <category domain="http://blog.intelius.com/category/tags/cyber-safety">Cyber Safety</category>
 <category domain="http://blog.intelius.com/category/tags/cyber-security">Cyber Security</category>
 <category domain="http://blog.intelius.com/category/tags/hacking">hacking</category>
 <category domain="http://blog.intelius.com/category/tags/identity-theft">identity theft</category>
 <category domain="http://blog.intelius.com/category/tags/intelius">Intelius</category>
 <category domain="http://blog.intelius.com/category/tags/phishing">phishing</category>
 <category domain="http://blog.intelius.com/category/tags/raskin">Raskin</category>
 <category domain="http://blog.intelius.com/category/tags/scam">Scam</category>
 <category domain="http://blog.intelius.com/category/tags/tabnabbing">tabnabbing</category>
 <category domain="http://blog.intelius.com/category/tags/tabnapping">tabnapping</category>
 <pubDate>Fri, 11 Jun 2010 01:55:00 +0000</pubDate>
 <dc:creator>drupal_admin</dc:creator>
 <guid isPermaLink="false">247 at http://blog.intelius.com</guid>
</item>
</channel>
</rss>
