Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

In-session phishing

From Wikipedia, the free encyclopedia
This article needs to beupdated. Please help update this article to reflect recent events or newly available information.(July 2024)
Type of phishing attack

In-session phishing is a form of potentialphishing attack which relies on oneweb browsing session being able to detect the presence of another session (such as a visit to anonline banking website) on the sameweb browser, and to then launch apop-up window that pretends to have been opened from the targeted session.[1] This pop-up window, which the user now believes to be part of the targeted session, is then used to steal user data in the same way as with other phishing attacks.[2]

The advantage of in-session phishing to the attacker is that it does not need the targeted website to be compromised in any way, relying instead on a combination of data leakage within the web browser, the capacity of web browsers to run active content, the ability of modern web browsers to support more than one session at a time, andsocial engineering of the user.[3]

The technique, which exploited a vulnerability in theJavaScript handling of major browsers, was found by Amit Klein, CTO of security vendorTrusteer, Ltd.[4][5] Subsequent security updates to browsers may have made the technique impossible.

References

[edit]
  1. ^Cert-IST."Publication content".Cert-IST (in French). Archived fromthe original on 2024-07-18. Retrieved2024-07-18.
  2. ^Hruska, Joel (2009-01-13)."New in-session phishing attack could fool experienced users".Ars Technica. Retrieved2024-04-16.
  3. ^Arellano, Nestor; McMillan, Robert (6 February 2009). "In-session phishing a new threat to online businesses".Network World Canada.25 (3).ProQuest 198831313.
  4. ^Kaplan, Dan (14 January 2009)."New phishing ploy exploits secure sessions to hijack data".iTnews.
  5. ^"Archived copy"(PDF). Archived fromthe original(PDF) on 2009-01-22. Retrieved2009-01-20.{{cite web}}: CS1 maint: archived copy as title (link)[full citation needed]

External links

[edit]


Stub icon

ThisWorld Wide Web–related article is astub. You can help Wikipedia byadding missing information.

Retrieved from "https://en.wikipedia.org/w/index.php?title=In-session_phishing&oldid=1243884666"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp