Technical Discussion
  >> Security Related Issues


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
  Print Thread
Standard User Deadbeat
(knowledge is power) Fri 11-Jun-10 10:11:47
Print Post

Tabnapping


[link to this post]
 
To see it in action, click here.
It's completely safe.
Standard User Pipexer
(eat-sleep-adslguide) Fri 11-Jun-10 18:47:16
Print Post

Re: Tabnapping


[re: Deadbeat] [link to this post]
 
Intresting concept, but again, complete user foolishness to blame.

______________
Zen 8000 Active
Standard User Deadbeat
(knowledge is power) Fri 11-Jun-10 20:35:57
Print Post

Re: Tabnapping


[re: Pipexer] [link to this post]
 
It's not a concept.... It's in widespread use and it's very easy to be tricked by it.


Register (or login) on our website and you will not see this ad.

Standard User Pipexer
(eat-sleep-adslguide) Fri 11-Jun-10 21:04:43
Print Post

Re: Tabnapping


[re: Deadbeat] [link to this post]
 
In reply to a post by Deadbeat:
It's in widespread use and it's very easy to be tricked by it.

I am not sure I agree it is widespread, as I've not seen much/any mention of it in security blogs. But I disagree it is easy to be tricked by it - only perhaps if you are a fool!

People should pay more attention and stop being ignorant when using computers, otherwise they deserve what ramifications they get. I don't have any sympathy for facebook users in the first place tongue

______________
Zen 8000 Active
Standard User deleted
(deleted) Fri 11-Jun-10 21:11:05
Print Post

Re: Tabnapping


[re: Deadbeat] [link to this post]
 
a lot of these sort of exploits require people to drop their guard momentarily, which does happen, of course.

it's interesting, and a very good working demo




Thanks for posting

Edited by deleted (Fri 11-Jun-10 22:03:22)

Standard User deleted
(deleted) Fri 11-Jun-10 21:12:10
Print Post

Re: Tabnapping


[re: Pipexer] [link to this post]
 
smile

Edited by deleted (Fri 11-Jun-10 22:10:58)

Standard User Deadbeat
(knowledge is power) Fri 11-Jun-10 21:48:59
Print Post

Re: Tabnapping


[re: Pipexer] [link to this post]
 
In reply to a post by Pipexer:
.... I am not sure I agree it is widespread, as I've not seen much/any mention of it in security blogs. But I disagree it is easy to be tricked by it - only perhaps if you are a fool!

You need to look at both sides of the fence where security bulletins are concerned - The shaded side of the garden is usually the most informative.
For obvious reasons I won't list any links here to such resources but they're fairly easy to find.
Nobody is infallable and we're all fools at some time or other which is why I posted this.

In reply to a post by Pipexer:
.... People should pay more attention and stop being ignorant when using computers, otherwise they deserve what ramifications they get....

And if there were no vehicles there would be no road accidents.
You know that's an impossibility to achieve but my hope is that warnings such as this go some way to achieving a little piece of Nirvana.
Standard User Pipexer
(eat-sleep-adslguide) Sat 12-Jun-10 00:21:27
Print Post

Re: Tabnapping


[re: Deadbeat] [link to this post]
 
In reply to a post by Deadbeat:
In reply to a post by Pipexer:
.... I am not sure I agree it is widespread, as I've not seen much/any mention of it in security blogs. But I disagree it is easy to be tricked by it - only perhaps if you are a fool!

You need to look at both sides of the fence where security bulletins are concerned - The shaded side of the garden is usually the most informative.
For obvious reasons I won't list any links here to such resources but they're fairly easy to find.
Nobody is infallable and we're all fools at some time or other which is why I posted this.

In reply to a post by Pipexer:
.... People should pay more attention and stop being ignorant when using computers, otherwise they deserve what ramifications they get....

And if there were no vehicles there would be no road accidents.
You know that's an impossibility to achieve but my hope is that warnings such as this go some way to achieving a little piece of Nirvana.

By all means I am not sweepingly generalising all security issues as user fault but this one in particular pretty much comes down to them. The trouble is no doubt MS have already been blamed for this security problem in some shape or another

There is a point where computer user ignorance is so great that they just should not use a computer.

And it's getting worse - as new OSs simplify things more and more computer users are less inclined to understand this "model" of how things work, they don't understand basic concepts like files and folders, let alone anything else, their expectations they have are nothing short of asking computers to read their minds.

People have gone through life and learnt how to do many things, they have a good job and have qualifications, yet they simply cannot be bothered to learn the basics of using a computer - this is just complete ignorance (either that or they have a mental problem and are incapable of learning?) and very often when you even try and explain things to them, they don't listen to you anyway.

Now I don't use facebook but presume I do
-First of all, why have I left a tab open which I have no idea what it is
-Secondly, if I then go to facebook, I will log in (that is if it does not auto login), I will not leave it at the homepage and get distracted,
-When I come back I should know I was logged in and not be fooled by a dodgy web tab I had open which will be showing the homepage to which I am not logged into.
-I would have remembered what position the tab was in to further reinforce the point above, and realised the phishing site has magically turned into facebook.
-I should know that I only had one facebook tab open, therefore why are there two anyway?
-Lets say I have then been extremely foolish and entered my details into the phishing site, assume after I've done this it takes me to some bogus website or does not respond, then surely by now you realise what has happened and go and change your facebook password.

There are so many foolish things you would have to do to get caught out by this imho, it is possible luck is not going your way that day however, however, but we are talking very small probability....

Just some thoughts and ramblings on the matter of security for you, thank god it is friday eh?! (actually it's saturday now) smile

Perhaps it is time to go back to something like Microsoft Bob for the complete novices with fully locked down applications and "paperclip" help and walkthroughs everywhere, and start to seperate things a bit, if people are not prepared to learn. (a contrast to my initial point re simplifying things but this would be on the principle that as the underlying OS is fully locked down from the user cocking it up, the simplification does no harm as stupidity can do no damage)

______________
Zen 8000 Active

Edited by Pipexer (Sat 12-Jun-10 00:25:51)

Standard User Deadbeat
(knowledge is power) Sat 12-Jun-10 00:40:37
Print Post

Re: Tabnapping


[re: Pipexer] [link to this post]
 
I sympathise fully with those views but unfortunately, out there in the real world, more and more users will be less savvy. I've long considered that a "driving test" should be passed and a level of competence achieved before computer users are allowed access to public networks.
However, I have a relatively long history in security matters and occasionally, probably because of the way things are "made so simple" these days rather than my advancing years (My story and I'm sticking to it!), I sometimes find myself on the verge of doing something stupid. With the advanced speed of everything, there's less time to think and it's so easy to get sucked in these days..... Even when you know that the candy shop laid in front of your eyes is actually an obstacle course constructed of razor wire.

Where I do draw a very definite line is where users have already been victims and have been given extensive tuition because of that but still take a cavalier attitude.
  Print Thread

Jump to