|
|
|
You are here: News > News > New form of phishing attack is unveiled
| » IT Security NEWS |
| » 25 May 2010 |
| New form of phishing attack is unveiled |
According to the Firefox’s chief developer, there is actually a newly-invented phishing attack process discovered just recently.
Users are responsible for their own protection
As said by the creative lead for Firefox, Aza Raskin, the online assault takes advantage of the users’ habit of opening just too many tabs whenever they are surfing the web. And, with this, the individuals are unconscious of the type of websites they are visiting.
This is considered as a tab-napping assault and this operates just by utilizing JavaScript in order to change the target webpage of the user in a specific tab during short moments of idleness. Most commonly, an attack can be launched by making use of an attack script that is incorporated in a valid website.
Safety can still be assured
However, one will be safer if he or she leaves just a single tab open when browsing. The online user will then easily notice if there is a sudden change in the page from a news site to Gmail or other websites that are usually the aim of attacks.
Origin of attacks comes from the system itself
As said by Raskin, the attack can most probably occur when the history file of the web user’s browser is accessed. The CSS history miner may be utilized in order to determine the websites that the user usually visits. Hence, the online assault on the said site will eventually ensue.
Using the application, it can easily be determined if one uses Facebook, Citibank, Twitter, and other websites. And then, the individual will be redirected to another page, which is a log-in screen and favicon.
Prevent attacks through necessary upgrades
One way to avoid encountering this kind of attack is through an upgrade of the browser technology, which retains the log-in information for the different websites. This is only one of the many methods that may be utilized in order to resolve the problem because many of today’s web users do not approve of the utilization of password management.
A person should also remember that it is dangerous to save their passwords when using public computers or even the machines at workplaces since these are used by many people.
See more valuable information by clicking the given links: About SecPoint, SecPoint Press, and SecPoint Awards. |