Results 1 to 7 of 7

Thread: Tab Napping, a real threat?

  1. #1
    radix lecti dave87's Avatar
    Join Date
    Sep 2005
    Location
    England
    Posts
    12,806
    Thanks
    657
    Thanked
    931 times in 634 posts
    • dave87's system
      • Motherboard:
      • Asus
      • CPU:
      • i5 3470k under Corsair H80 WC
      • Memory:
      • 8gb DDR3
      • Storage:
      • 240gb SSD + 120gb SSD
      • Graphics card(s):
      • Asus HD7950
      • PSU:
      • XFX 600w Modular
      • Case:
      • Lian Li PC-A05FNB + Acoustipack
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2x Dell S2309W (1920x1080)
      • Internet:
      • BT Infinity Option 2

    Tab Napping, a real threat?

    http://uk.biz.yahoo.com/07062010/389...line-scam.html


    I'm not convinced, surely you would have to open a dodgy window or have something installed on your PC without your knowledge for this to work?

    What do we think?

  2. #2
    WEEEEEEEEEEEEE! MadduckUK's Avatar
    Join Date
    May 2006
    Location
    Lytham St. Annes
    Posts
    17,297
    Thanks
    653
    Thanked
    1,579 times in 1,005 posts
    • MadduckUK's system
      • Motherboard:
      • MSI B450M Mortar
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • 32GB 3200 DDR4
      • Storage:
      • 1x480GB SSD, 1x 2TB Hybrid, 1x 3TB Rust Spinner
      • Graphics card(s):
      • Radeon 5700XT
      • PSU:
      • Corsair TX750w
      • Case:
      • Phanteks Enthoo Evolv mATX
      • Operating System:
      • Windows 10 x64
      • Monitor(s):
      • Samsung SJ55W, DELL S2409W
      • Internet:
      • Plusnet 80

    Re: Tab Napping, a real threat?

    i think tap nabbing is worse
    Quote Originally Posted by Ephesians
    Do not be drunk with wine, which will ruin you, but be filled with the Spirit
    Vodka

  3. #3
    jim
    jim is offline
    HEXUS.clueless jim's Avatar
    Join Date
    Sep 2008
    Location
    Location: Location:
    Posts
    11,464
    Thanks
    614
    Thanked
    1,648 times in 1,309 posts
    • jim's system
      • Motherboard:
      • Asus Maximus IV Gene-Z
      • CPU:
      • i5 2500K @ 4.5GHz
      • Memory:
      • 8GB Corsair Vengeance LP
      • Storage:
      • 1TB Sandisk SSD
      • Graphics card(s):
      • ASUS GTX 970
      • PSU:
      • Corsair AX650
      • Case:
      • Silverstone Fortress FT03
      • Operating System:
      • 8.1 Pro
      • Monitor(s):
      • Dell S2716DG
      • Internet:
      • 10 Mbps ADSL

    Re: Tab Napping, a real threat?

    Yeah, you'd have to have something dodgy installed.

    To be honest though, it would catch me out. I don't check the address bar when I go back to a previous opened tab. And I routinely leave tabs open for upwards of 20 minutes before using them.

    The obvious answer to me though is for banks and so on to use sessions as soon as you go to the login page. Have a countdown on the page which shows how long you've got before you're redirected away from the login back to the main site.

    That way, a fake would either have to replicate the countdown, and thus prove that it's false because they work on the basis that you've left the tab open for ages, or miss it out and thereby look unrealistic.

    At the end of the day it's not that sophisticated... it's no more than simple page redirection... but the idea of using 30 minute old tabs is very sensible, since you probably wouldn't even notice the change. That's why a more visual protection system would probably work, imo.

  4. #4
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Tab Napping, a real threat?

    Quote Originally Posted by snootyjim View Post
    Yeah, you'd have to have something dodgy installed.
    No, no you wouldn't.

    Most browser give up your history if people query for a specific URL, this is via a styling attack that remains 'controversial' to say the least.

    then you simply set the content.

    But given that you would have to not look at the URL bar for this to work, that should limit the impact a bit.

    Also as most online banks explicitly tell you to use a clean 'session' its hardly going to be an issue for those following the good advice there either.
    throw new ArgumentException (String, String, Exception)

  5. #5
    Senior Member
    Join Date
    Aug 2004
    Location
    W Yorkshire
    Posts
    5,691
    Thanks
    85
    Thanked
    15 times in 13 posts
    • XA04's system
      • Motherboard:
      • MSI X570-A Pro
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • Corsair 2x 8gb DDR 4 3200
      • Storage:
      • 1TB Serpent M.2 SSD & 4TB HDD
      • Graphics card(s):
      • Palit RTX 2060
      • PSU:
      • Antec Truepower 650W
      • Case:
      • Fractcal Meshify C
      • Operating System:
      • Windows 10
      • Monitor(s):
      • iiyama 34" Curved UWQHD
      • Internet:
      • Virgin 100mb Fibre

    Re: Tab Napping, a real threat?

    I posted this on my facebook the other week...

    http://digg.com/security/New_Type_of..._Tabs?OTC-fbc8

    EXAMPLE http://www.azarask.in/blog/post/a-ne...ishing-attack/


    I think it could be quite a serious threat really. It doesn't totally work in chrome as the favicon doesn't change.

  6. #6
    jim
    jim is offline
    HEXUS.clueless jim's Avatar
    Join Date
    Sep 2008
    Location
    Location: Location:
    Posts
    11,464
    Thanks
    614
    Thanked
    1,648 times in 1,309 posts
    • jim's system
      • Motherboard:
      • Asus Maximus IV Gene-Z
      • CPU:
      • i5 2500K @ 4.5GHz
      • Memory:
      • 8GB Corsair Vengeance LP
      • Storage:
      • 1TB Sandisk SSD
      • Graphics card(s):
      • ASUS GTX 970
      • PSU:
      • Corsair AX650
      • Case:
      • Silverstone Fortress FT03
      • Operating System:
      • 8.1 Pro
      • Monitor(s):
      • Dell S2716DG
      • Internet:
      • 10 Mbps ADSL

    Re: Tab Napping, a real threat?

    Quote Originally Posted by TheAnimus View Post
    No, no you wouldn't.

    Most browser give up your history if people query for a specific URL, this is via a styling attack that remains 'controversial' to say the least.

    then you simply set the content.

    But given that you would have to not look at the URL bar for this to work, that should limit the impact a bit.

    Also as most online banks explicitly tell you to use a clean 'session' its hardly going to be an issue for those following the good advice there either.
    Analysing a tab, seeing that it's been open for 30 minutes, and then redirect it to a site of your choosing? Surely that can't be done via your method.

  7. #7
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Tab Napping, a real threat?

    ah no the idea is that you already 'own' that tab via a cross site scripting or something. But rather than just re-direct to any kind of phishing scam, you check their history, using the "has user visted known url via css bug", then you can go one step further, see if they are currently logged in to facebuck, and generate a very convincing phishing scam that the user dosen't remember opening.

    its not really going to be a big one imho.
    throw new ArgumentException (String, String, Exception)

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Memory bandwidth tests... any real differences (PC4300 vs. PC7100)
    By graysky in forum PC Hardware and Components
    Replies: 0
    Last Post: 30-10-2007, 10:18 PM
  2. Real audio to MP3
    By stytagm in forum Software
    Replies: 5
    Last Post: 31-05-2006, 10:11 AM
  3. Is Windows XP-Pro "64 bit" real?
    By Artic_Kid in forum Software
    Replies: 11
    Last Post: 12-12-2005, 06:21 PM
  4. Terrorism - Is the threat real?
    By Zedmeister in forum Question Time
    Replies: 27
    Last Post: 06-11-2004, 09:56 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •