Affichage des articles dont le libellé est Tabnapping. Afficher tous les articles
Affichage des articles dont le libellé est Tabnapping. Afficher tous les articles

Tabnapping Tutorial- Social Engineering Toolkit Backtrack 5

Social engineering toolkit is complete toolkit that contain relevant tools that will really help penetration tester and ethical hacker in the process of auditing and penetration testing. As discussed before about different aspect of social engineering toolkit on backtrack 5 like, credential harvester attack method and others. For this article I will discuss the famous attack called tab-nabbing (tabnapping).



What Is Tabnapping ?

Tab-nabbing (tabnapping) is a browser side attack in which an attacker takes an advantage of a browser tabs. Now a days most famous browser has a feature called tabs we can open multiple tabs on a same window.

Tabnapping attack is not a new attack and we have discussed this before with video demonstration and with tabnapping protection tips.

Tabnapping Tutorial on SET – Backtrack


The tutorial is very easy for all of the learners, instead of providing images and text we have a created a video tutorial so that you can easily understand these type of attack method.
Requirement
  • Operating system (Backtrack 5 used in video)
  • SET (social engineering toolkit)
  • Mind
  • Browser










Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ lundi 26 septembre 2011 0 commentaires

Web Browser Attack-TabNapping

We are living in the jungle of web, we have different web-browser to view internet websites. Different vulnerability on browser's arising every day and you have to be aware these new attack to protect your infrastructure.

As you know in the phishing attacker send a URL to the victim and victim has to click on URL to go on phishing page, now the thing is change a new term has been discovered that is TabNapping, tabnapping is a web-browser attack and the new way of phishing attack in which victim not require to click any URL.


In this attack one of you browser tab replace with another page without your knowledge and permission, for example in one of your browser tab you have opened any website it will automatically replaced with the phishing side and the normal user's does not look to the URL.

Instead of explain all the stuff here on text format i want to share a video demonstration of tabnapping.






Is this the owner and admin of a particular website responsible for this attack? i think no an attacker can find any bug on any website like a cross site scripting and after this an attacker can enter their script to perform Tabnapping attack.



Protection
  • Do not login on any tab, that you have not open it by yourself.
  • Look around the URL before login to any website.
  • If you find any suspicious than close the tab and open new one.
  • Update your browser.
  • Do not open many tab while you are working on your secure website or important websites.


Note: If you enjoyed this post, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ vendredi 28 janvier 2011 0 commentaires