<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Devious New Phishing Tactic Targets Tabs</title>
	<atom:link href="http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 04 Feb 2012 04:48:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Mitchell Allen</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-24166</link>
		<dc:creator>Mitchell Allen</dc:creator>
		<pubDate>Thu, 14 Jul 2011 10:00:42 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-24166</guid>
		<description>Same thing happened to me. Rest assured, though, if it can be figured out, the bad guys will do it.

Raskin admitted he was being lazy. Imagine if he devoted a bit more energy to it.

Cheers,

Mitch</description>
		<content:encoded><![CDATA[<p>Same thing happened to me. Rest assured, though, if it can be figured out, the bad guys will do it.</p>
<p>Raskin admitted he was being lazy. Imagine if he devoted a bit more energy to it.</p>
<p>Cheers,</p>
<p>Mitch</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-24166" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('24166', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-24166-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-24166" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('24166', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-24166-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Tony Smit</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-22833</link>
		<dc:creator>Tony Smit</dc:creator>
		<pubDate>Sat, 04 Jun 2011 01:38:47 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-22833</guid>
		<description>I am running Firefox from an Ubuntu Live CD and the webpage transitioned to the fake Google page - with no warning from Firefox that the webpage had changed, and I had already set that option to warn me before I had begun browsing.

Edit &gt; Preferences &gt; Advanced &gt; Warn me when websites try to redirect or reload the page

And I know that setting works because it has reported on two of my favorite websites.

This tells me all the data for the webpage is already loaded, and one set of data-to-be-displayed is exchanged for another set in the tab.

The only option is to close the tab if I ever see a log in page on an old tab or window.</description>
		<content:encoded><![CDATA[<p>I am running Firefox from an Ubuntu Live CD and the webpage transitioned to the fake Google page &#8211; with no warning from Firefox that the webpage had changed, and I had already set that option to warn me before I had begun browsing.</p>
<p>Edit &gt; Preferences &gt; Advanced &gt; Warn me when websites try to redirect or reload the page</p>
<p>And I know that setting works because it has reported on two of my favorite websites.</p>
<p>This tells me all the data for the webpage is already loaded, and one set of data-to-be-displayed is exchanged for another set in the tab.</p>
<p>The only option is to close the tab if I ever see a log in page on an old tab or window.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-22833" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('22833', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-22833-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-22833" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('22833', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-22833-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: nemo</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-22397</link>
		<dc:creator>nemo</dc:creator>
		<pubDate>Mon, 23 May 2011 18:24:46 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-22397</guid>
		<description>I think you misunderstand.
It isn&#039;t one tab modifying another tab, it is one tab modifying itself.

The non-javascript version is just a delayed redirect.

Something like.
Load innocent blog w/ fun article.  Go somewhere else.
Blog redirects itself much later to gmail look-alike page, including favicon.  You forget you were reading the blog, assume it was a gmail tab you left open, and don&#039;t bother looking at the url line.</description>
		<content:encoded><![CDATA[<p>I think you misunderstand.<br />
It isn&#8217;t one tab modifying another tab, it is one tab modifying itself.</p>
<p>The non-javascript version is just a delayed redirect.</p>
<p>Something like.<br />
Load innocent blog w/ fun article.  Go somewhere else.<br />
Blog redirects itself much later to gmail look-alike page, including favicon.  You forget you were reading the blog, assume it was a gmail tab you left open, and don&#8217;t bother looking at the url line.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-22397" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('22397', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-22397-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-22397" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('22397', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-22397-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Blah Blue</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-21606</link>
		<dc:creator>Blah Blue</dc:creator>
		<pubDate>Thu, 05 May 2011 22:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-21606</guid>
		<description>Doesn&#039;t work 100% as well as it does without NoScript seeing as i just tried it and it wouldn&#039;t change to the gmail image until the 2nd time i open a new tab to the Proof of Concept link or while i was still looking at the page making it practically useless to fool someone</description>
		<content:encoded><![CDATA[<p>Doesn&#8217;t work 100% as well as it does without NoScript seeing as i just tried it and it wouldn&#8217;t change to the gmail image until the 2nd time i open a new tab to the Proof of Concept link or while i was still looking at the page making it practically useless to fool someone</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-21606" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('21606', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-21606-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-21606" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('21606', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-21606-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Alf Igel</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-21370</link>
		<dc:creator>Alf Igel</dc:creator>
		<pubDate>Sat, 30 Apr 2011 20:30:07 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-21370</guid>
		<description>Who is implementing code into Firefox to enable a page to alter anything on an other tab? And why are they doing this?
One main reason for attacks happening is software allowing attacks due to functions that 99.9% of all user would never miss. Same for Word, Excel and all the other software that has functions that pose more danger and threat than any use.</description>
		<content:encoded><![CDATA[<p>Who is implementing code into Firefox to enable a page to alter anything on an other tab? And why are they doing this?<br />
One main reason for attacks happening is software allowing attacks due to functions that 99.9% of all user would never miss. Same for Word, Excel and all the other software that has functions that pose more danger and threat than any use.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-21370" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('21370', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-21370-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-21370" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('21370', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-21370-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: omar nabi</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-20007</link>
		<dc:creator>omar nabi</dc:creator>
		<pubDate>Thu, 31 Mar 2011 00:33:45 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-20007</guid>
		<description>je suis omar un amis sur le face book  pirate moi svp donne moi
un email  spare  physhing ou une autre méthode pour pirat cette personne</description>
		<content:encoded><![CDATA[<p>Hidden due to low comment rating. <a href="javascript:crSwitchDisplay('ckhide-20007');" title="Click to see comment">Click here to see</a>.</p><div id='ckhide-20007' style="display:none; opacity:0.6;filter:alpha(opacity=60) !important;"><p>je suis omar un amis sur le face book  pirate moi svp donne moi<br />
un email  spare  physhing ou une autre méthode pour pirat cette personne</p>
</div><div class="CommentRating">Poorly-rated. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-20007" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('20007', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-20007-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-20007" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('20007', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-20007-down" style="font-size:14px; color:#990033;">7</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: ZVRichard</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-18411</link>
		<dc:creator>ZVRichard</dc:creator>
		<pubDate>Sat, 19 Feb 2011 19:45:30 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-18411</guid>
		<description>I have a money market account, but can&#039;t seem to get enough information on how it all works.  
Answer:  
A &lt;a href=&quot;http://expertisemoney.ru/index.php?key=i&quot; rel=&quot;nofollow&quot;&gt; money market &lt;/a&gt; account is basically a savings account with check writing privileges. It typically earns 4%-5% rate of return. It&#039;s great to use as a emergency fund, but not great as a investment vehicle. I would recommend good, growth stock mutual funds as an investment.</description>
		<content:encoded><![CDATA[<p>Hidden due to low comment rating. <a href="javascript:crSwitchDisplay('ckhide-18411');" title="Click to see comment">Click here to see</a>.</p><div id='ckhide-18411' style="display:none; opacity:0.6;filter:alpha(opacity=60) !important;"><p>I have a money market account, but can&#8217;t seem to get enough information on how it all works.<br />
Answer:<br />
A <a href="http://expertisemoney.ru/index.php?key=i" rel="nofollow"> money market </a> account is basically a savings account with check writing privileges. It typically earns 4%-5% rate of return. It&#8217;s great to use as a emergency fund, but not great as a investment vehicle. I would recommend good, growth stock mutual funds as an investment.</p>
</div><div class="CommentRating">Poorly-rated. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-18411" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('18411', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-18411-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-18411" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('18411', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-18411-down" style="font-size:14px; color:#990033;">16</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Fuzzy</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-17697</link>
		<dc:creator>Fuzzy</dc:creator>
		<pubDate>Tue, 08 Feb 2011 17:05:18 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-17697</guid>
		<description>I opt to calling it Tabtaping</description>
		<content:encoded><![CDATA[<p>I opt to calling it Tabtaping</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-17697" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('17697', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-17697-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-17697" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('17697', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-17697-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Shyloh Jacobs</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-16723</link>
		<dc:creator>Shyloh Jacobs</dc:creator>
		<pubDate>Wed, 12 Jan 2011 17:35:57 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-16723</guid>
		<description>Oh the world is getting more devious every day! Thank you for this article I found it helpful. I am currently considering hiring a virtual cfo but I think I will just stick to the person to person relations. I think computers may be taking things a little to far soon we won&#039;t even need to leave the house for anything!</description>
		<content:encoded><![CDATA[<p>Oh the world is getting more devious every day! Thank you for this article I found it helpful. I am currently considering hiring a virtual cfo but I think I will just stick to the person to person relations. I think computers may be taking things a little to far soon we won&#8217;t even need to leave the house for anything!</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-16723" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('16723', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-16723-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-16723" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('16723', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-16723-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon Bachman</title>
		<link>http://krebsonsecurity.com/2010/05/devious-new-phishing-tactic-targets-tabs/comment-page-3/#comment-12470</link>
		<dc:creator>Brandon Bachman</dc:creator>
		<pubDate>Sat, 13 Nov 2010 16:45:56 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3205#comment-12470</guid>
		<description>Why redefine what nabbing even means?

My vote goes to tabjacking. Tab hijacking.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>Why redefine what nabbing even means?</p>
<p>My vote goes to tabjacking. Tab hijacking.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12470" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12470', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-12470-up" style="font-size:14px; color:#009933;">8</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12470" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12470', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-12470-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 5/19 queries in 0.010 seconds using memcached
Object Caching 949/959 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-04 02:36:53 -->
