Re: A new type of phishing attack
Mike Stay <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAAvuwX8uQmQEg-P5UWUKVdDK=z+GudwydSCwv-mTz_+sx3D62A@mail.gmail.com> |
There's a variant where the site pops open a new tab with the legitimate site in it, e.g. when opening gmail you click on what appears to be a mailto: link. But the originating site gave the window a name and can therefore redirect the site after a time to a malicious one, particularly since the attacker can tell when you're looking at his site and not gmail. On Fri, Sep 12, 2014 at 8:01 AM, Karp, Alan H <[email protected]> wrote: > He would have gotten me, and SitePassword wouldn't have helped. I haven't been using it for gmail, because until recently I could only get my passwords from IE. Now that I have SitePassword, I'm going to change that. > > ________________________ > Alan Karp > Principal Scientist > Enterprise Services, Office of the CTO > Hewlett-Packard Company > 1501 Page Mill Road > Palo Alto, CA 94304 > (650) 857-3967, fax (650) 857-7029 > http://www.hpl.hp.com/personal/Alan_Karp > > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk -- Mike Stay [email protected]